Welcome to MalwareRemoval.com,
What if we told you that you could get malware removal help from experts, and that it was 100% free? MalwareRemoval.com provides free support for people with infected computers. Our help, and the tools we use are always 100% free. No hidden catch. We simply enjoy helping others. You enjoy a clean, safe computer.

Malware Removal Instructions

Please help with Google search malware

MalwareRemoval.com provides free support for people with infected computers. Using plain language that anyone can understand, our community of volunteer experts will walk you through each step.

Please help with Google search malware

Unread postby smurph » September 22nd, 2011, 9:04 pm

Hi,
I'm here for the first time. When I do a search in Google I get the following...
"Our systems have detected unusual traffic from your computer network"
The error page displays a CAPTCHA. To continue using Google, type the squiggly word into the box -- it's how we know you're a human, not a robot.
Maybe you have heard of this? Could you take a look and check for anything unusual please.
Thanks so much, Sean.

DDS.txt

.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 7.0.6002.18005 BrowserJavaVersion: 1.6.0_24
Run by sean at 17:47:55 on 2011-09-22
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.4090.844 [GMT -7:00]
.
AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\SYSTEM32\WISPTIS.EXE
C:\Program Files\Tablet\Pen\Pen_TouchService.exe
C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\SYSTEM32\WISPTIS.EXE
C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
C:\Windows\system32\taskeng.exe
C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files (x86)\Common Files\Autodesk Shared\Service\AdskScSrv.exe
C:\Program Files (x86)\Bonjour\mDNSResponder.exe
C:\Program Files\GATEWAY\Gateway Recovery Management\Service\ETService.exe
C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe
C:\IDrive\IDriveE Service.exe
C:\Program Files (x86)\Autodesk\3ds Max 2010\mentalray\satellite\raysat_3dsmax2010_32server.exe
C:\Program Files\Autodesk\3ds Max 2010\mentalray\satellite\raysat_3dsmax2010_64server.exe
C:\Program Files (x86)\Blockbuster\BLOCKBUSTERMovielink\MovielinkCore.exe
C:\Program Files (x86)\O2Micro Flash Memory Card Driver\o2flash.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\sfmgr\sfmgr.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\Pen_Tablet.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\WTablet\Pen_TabletUser.exe
C:\Windows\system32\Pen_Tablet.exe
C:\Windows\system32\DRIVERS\xaudio64.exe
C:\Windows\system32\RUNDLL32.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files (x86)\Steam\steam.exe
C:\Program Files (x86)\Citrix\GoToMeeting\457\g2mstart.exe
C:\Program Files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe
C:\Program Files\Camera Assistant Software for Gateway\traybar.exe
C:\Program Files (x86)\EarthLink TotalAccess\FastLane2\ipmon32.exe
C:\Program Files (x86)\WinZip\WZQKPICK.EXE
C:\Program Files (x86)\Blockbuster\BLOCKBUSTERMovielink\Movielink User.exe
C:\Users\sean\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Program Files (x86)\Western Digital\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
C:\Program Files (x86)\real\realplayer\Update\realsched.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
C:\Program Files\Camera Assistant Software for Gateway\CEC_MAIN.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
C:\Program Files (x86)\Citrix\GoToMeeting\457\g2mcomm.exe
C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe
C:\Program Files (x86)\Common Files\Steam\SteamService.exe
C:\Program Files (x86)\Citrix\GoToMeeting\457\g2mlauncher.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files (x86)\EarthLink TotalAccess\TaskPanl.exe
C:\Program Files (x86)\Windows Mail\WinMail.exe
C:\Program Files\Windows Mail\WinMail.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\splwow64.exe
C:\Windows\system32\taskeng.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe
C:\Program Files\Tablet\Pen\Pen_TouchUser.exe
C:\Program Files (x86)\Adobe\Adobe After Effects CS4\Support Files\AfterFX.exe
C:\Program Files (x86)\Common Files\Adobe\dynamiclink\processcoordinationserver.exe
C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\Windows\system32\taskmgr.exe
C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe
C:\Windows\SysWOW64\NOTEPAD.EXE
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\SysWOW64\cscript.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.cnn.com
uDefault_Page_URL = hxxp://my.earthlink.net
uSearch Page = hxxp://www.earthlink.net/partner/more/m ... earch.html
uDefault_Search_URL = hxxp://www.earthlink.net/partner/more/m ... earch.html
uSearch Bar = hxxp://start.earthlink.net/AL/Search
mStart Page = hxxp://homepage.gateway.com/rdr.aspx?b= ... 7805u&c=BB
mDefault_Page_URL = hxxp://homepage.gateway.com/rdr.aspx?b= ... 7805u&c=BB
uInternet Settings,ProxyOverride = *.local
mSearchAssistant = hxxp://start.earthlink.net/AL/Search
uURLSearchHooks: SrchHook Class: {44f9b173-041c-4825-a9b9-d914bd9dcbb3} - C:\Program Files (x86)\EarthLink TotalAccess\ElnIE.dll
uURLSearchHooks: H - No File
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File
BHO: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
TB: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
TB: {472734EA-242A-422B-ADF8-83D1E48CC825} - No File
uRun: [ehTray.exe] C:\Windows\ehome\ehTray.exe
uRun: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
uRun: [EA Core] "C:\Program Files (x86)\Electronic Arts\EADM\Core.exe" -silent
uRun: [Steam] "C:\Program Files (x86)\Steam\Steam.exe" -silent
uRun: [AdobeBridge]
uRun: [IDriveE Startup] "C:\IDrive\IDrvieEStartup.exe" Hide
uRun: [GoToMeeting] "C:\Program Files (x86)\Citrix\GoToMeeting\457\g2mstart.exe" "/Trigger RunAtLogon"
mRun: [Camera Assistant Software] "C:\Program Files\Camera Assistant Software for Gateway\traybar.exe"
mRun: [eRecoveryService]
mRun: [IPInSightMonitor 01] "C:\Program Files (x86)\EarthLink TotalAccess\FastLane2\IPMon32.exe"
mRun: [LoadMSvcmm] "C:\Program Files (x86)\Blockbuster\BLOCKBUSTERMovielink\Movielink User.exe"
mRun: [AdobeCS4ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
mRun: [NUSB3MON] "C:\Program Files (x86)\Western Digital\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
mRun: [avast5] C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui
mRun: [TkBellExe] "c:\program files (x86)\real\realplayer\Update\realsched.exe" -osboot
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [AdobeCS5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
mRun: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
StartupFolder: C:\Users\sean\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\Dropbox.lnk - C:\Users\sean\AppData\Roaming\Dropbox\bin\Dropbox.exe
StartupFolder: C:\Users\sean\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\IDRIVE~1.LNK - C:\IDrive\IDriveEReg2ini.exe
StartupFolder: C:\Users\sean\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\OPENOF~1.LNK - C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\MCAFEE~1.LNK - C:\Program Files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\WINZIP~1.LNK - C:\Program Files (x86)\WinZip\WZQKPICK.EXE
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Add to Google Photos Screensa&ver - C:\Windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
IE: Google Sidewiki... - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MICROS~2\Office12\ONBttnIE.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {F8EB59EC-35A8-4B59-8F67-B3E19147FED6} - hxxps://www.blockbuster.com/content/v.5 ... former.exe
TCP: Interfaces\{0B3F27C9-B9D9-42D6-9893-4D145E057DD2} : DhcpNameServer = 192.168.1.1
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64: AcroIEHelperStub - No File
BHO-X64: {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File
BHO-X64: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll
BHO-X64: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
BHO-X64: Skype Browser Helper: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
BHO-X64: SkypeIEPluginBHO - No File
BHO-X64: Google Toolbar Notifier BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll
BHO-X64: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
TB-X64: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll
TB-X64: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
TB-X64: {472734EA-242A-422B-ADF8-83D1E48CC825} - No File
mRun-x64: [Camera Assistant Software] "C:\Program Files\Camera Assistant Software for Gateway\traybar.exe"
mRun-x64: [eRecoveryService]
mRun-x64: [IPInSightMonitor 01] "C:\Program Files (x86)\EarthLink TotalAccess\FastLane2\IPMon32.exe"
mRun-x64: [LoadMSvcmm] "C:\Program Files (x86)\Blockbuster\BLOCKBUSTERMovielink\Movielink User.exe"
mRun-x64: [AdobeCS4ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
mRun-x64: [NUSB3MON] "C:\Program Files (x86)\Western Digital\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
mRun-x64: [avast5] C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui
mRun-x64: [TkBellExe] "c:\program files (x86)\real\realplayer\Update\realsched.exe" -osboot
mRun-x64: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun-x64: [AdobeCS5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
mRun-x64: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
mRun-x64: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun-x64: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\sean\AppData\Roaming\Mozilla\Firefox\Profiles\uzfwrv2c.default\
FF - prefs.js: browser.search.defaulturl - hxxp://aim.search.aol.com/aol/search?query={searchTerms}&invocationType=tb50-ff-aim-chromesbox-en-us&tb_uuid=20101208204951870&tb_oid=08-12-2010&tb_mrud=08-12-2010
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.cnn.com
FF - prefs.js: keyword.URL - hxxp://slirsredirect.search.aol.com/red ... 010&query=
FF - component: C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}\components\SkypeFfComponent.dll
FF - component: C:\Users\sean\AppData\Roaming\Mozilla\Firefox\Profiles\uzfwrv2c.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - component: C:\Users\sean\AppData\Roaming\Mozilla\Firefox\Profiles\uzfwrv2c.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbar-ff3.dll
FF - component: C:\Users\sean\AppData\Roaming\Mozilla\Firefox\Profiles\uzfwrv2c.default\extensions\{c2f863cd-0429-48c7-bb54-db756a951760}\components\MailUtil.dll
FF - plugin: C:\Program Files (x86)\Canon\ZoomBrowser EX\Program\NPCIG.dll
FF - plugin: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll
FF - plugin: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.69\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npdnu.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npdnupdater2.dll
FF - plugin: C:\Program Files (x86)\TabletPlugins\npwacom.dll
FF - plugin: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
FF - plugin: C:\Users\sean\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll
FF - plugin: C:\Users\sean\AppData\Roaming\Mozilla\Firefox\Profiles\uzfwrv2c.default\extensions\widevinemediatransformer@widevine\plugins\npwidevinemediatransformer.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
.
---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - true);user_pref(network.protocol-handler.warn-external.dnupdate, false);user_pref(network.protocol-handler.warn-external.dnupdate, false
FF - user.js: browser.sessionstore.resume_from_crash - false
.
============= SERVICES / DRIVERS ===============
.
R0 PxHlpa64;PxHlpa64;C:\Windows\system32\Drivers\PxHlpa64.sys --> C:\Windows\system32\Drivers\PxHlpa64.sys [?]
R1 aswSnx;aswSnx;C:\Windows\system32\drivers\aswSnx.sys --> C:\Windows\system32\drivers\aswSnx.sys [?]
R1 aswSP;aswSP;C:\Windows\system32\drivers\aswSP.sys --> C:\Windows\system32\drivers\aswSP.sys [?]
R2 aswFsBlk;aswFsBlk;C:\Windows\system32\drivers\aswFsBlk.sys --> C:\Windows\system32\drivers\aswFsBlk.sys [?]
R2 aswMonFlt;aswMonFlt;\??\C:\Windows\system32\drivers\aswMonFlt.sys --> C:\Windows\system32\drivers\aswMonFlt.sys [?]
R2 avast! Antivirus;avast! Antivirus;C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-7-23 44768]
R2 ETService;Empowering Technology Service;C:\Program Files\GATEWAY\Gateway Recovery Management\Service\ETService.exe [2008-12-17 24576]
R2 IDriveE Service;IDriveE Service;C:\IDrive\IDriveE Service.exe [2011-1-17 148936]
R2 mi-raysat_3dsmax2010_32;mental ray 3.7 Satellite for Autodesk 3ds Max 2010 32-bit 32-bit;C:\Program Files (x86)\Autodesk\3ds Max 2010\mentalray\satellite\raysat_3dsmax2010_32server.exe [2009-3-12 86016]
R2 mi-raysat_3dsmax2010_64;mental ray 3.7 Satellite for Autodesk 3ds Max 2010 64-bit 64-bit;C:\Program Files\Autodesk\3ds Max 2010\mentalray\satellite\raysat_3dsmax2010_64server.exe [2009-3-12 86016]
R2 sfmgr;SplutterFish License Mgr 2.1.12;C:\sfmgr\sfmgr.exe [2011-5-30 208896]
R2 TabletServicePen;TabletServicePen;C:\Windows\system32\Pen_Tablet.exe --> C:\Windows\system32\Pen_Tablet.exe [?]
R2 TouchServicePen;Wacom Consumer Touch Service;C:\Program Files\Tablet\Pen\Pen_TouchService.exe [2010-9-28 484720]
R2 yksvc;Marvell Yukon Service;RUNDLL32.EXE ykx64coinst,serviceStartProc --> RUNDLL32.EXE ykx64coinst,serviceStartProc [?]
R3 CAXHWAZL;CAXHWAZL;C:\Windows\system32\DRIVERS\CAXHWAZL.sys --> C:\Windows\system32\DRIVERS\CAXHWAZL.sys [?]
R3 NETw5v64;Intel(R) Wireless WiFi Link Adapter Driver for Windows Vista 64 Bit ;C:\Windows\system32\DRIVERS\NETw5v64.sys --> C:\Windows\system32\DRIVERS\NETw5v64.sys [?]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;C:\Windows\system32\drivers\nvhda64v.sys --> C:\Windows\system32\drivers\nvhda64v.sys [?]
R3 O2MDRDR;O2MDRDR;C:\Windows\system32\DRIVERS\o2mdx64.sys --> C:\Windows\system32\DRIVERS\o2mdx64.sys [?]
R3 O2SDRDR;O2SDRDR;C:\Windows\system32\DRIVERS\o2sdx64.sys --> C:\Windows\system32\DRIVERS\o2sdx64.sys [?]
R3 yukonx64;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\system32\DRIVERS\yk60x64.sys --> C:\Windows\system32\DRIVERS\yk60x64.sys [?]
S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-2-14 135664]
S3 clr_optimization_v2.0.50727_64;Microsoft .NET Framework NGEN v2.0.50727_X64;C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe [2011-6-26 89920]
S3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [2009-11-2 1436424]
S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-2-14 135664]
S3 McComponentHostService;McAfee Security Scan Component Host Service;C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe [2010-1-15 227232]
S3 PerfHost;Performance Counter DLL Host;C:\Windows\SysWOW64\perfhost.exe [2008-1-20 19968]
S3 wacmoumonitor;Wacom Mode Helper;C:\Windows\system32\DRIVERS\wacmoumonitor.sys --> C:\Windows\system32\DRIVERS\wacmoumonitor.sys [?]
.
=============== Created Last 30 ================
.
2011-09-23 00:48:05 0 ----a-w- C:\Windows\SysWow64\sfmgr.tmp
2011-09-23 00:26:13 388096 ----a-r- C:\Users\sean\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-09-23 00:26:10 -------- d-----w- C:\Program Files (x86)\Trend Micro
2011-08-30 00:54:57 -------- d-----w- C:\Music
2011-08-24 23:57:14 151552 ----a-w- C:\Windows\SysWow64\nvRegDev.dll
2011-08-24 23:57:00 61440 ----a-w- C:\Windows\SysWow64\nvPhotoshopUtil.dll
2011-08-24 23:57:00 40960 ----a-w- C:\Windows\SysWow64\nvISWOW64.dll
2011-08-24 22:41:16 -------- d-----w- C:\Users\sean\AppData\Roaming\Unity
2011-08-24 22:38:06 -------- d-----w- C:\Users\sean\AppData\Roaming\PACE Anti-Piracy
2011-08-24 22:38:06 -------- d-----w- C:\Users\sean\AppData\Local\PACE Anti-Piracy
2011-08-24 22:38:06 -------- d-----w- C:\ProgramData\PACE Anti-Piracy
2011-08-24 22:37:47 -------- d-----w- C:\Users\sean\AppData\Local\Unity
2011-08-24 22:34:02 -------- d-----w- C:\Program Files (x86)\Unity
.
==================== Find3M ====================
.
2011-09-22 02:35:58 59 ----a-w- C:\Windows\wpd99.drv
2011-09-22 01:33:51 404640 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2011-09-06 20:45:29 41184 ----a-w- C:\Windows\avastSS.scr
2011-09-06 20:38:18 601944 ----a-w- C:\Windows\System32\drivers\aswSnx.sys
2011-09-06 20:36:30 65368 ----a-w- C:\Windows\System32\drivers\aswMonFlt.sys
2011-08-18 21:37:43 72 ----a-w- C:\Windows\Vue 7.5 xStream.reg
2011-08-18 21:37:43 70 ----a-w- C:\Windows\Vue 7 xStream.reg
2011-08-18 21:37:43 70 ----a-w- C:\Windows\Vue 6 xStream.reg
2011-08-12 18:57:31 47616 ----a-w- C:\Windows\SysWow64\pdf995mon64.dll
.
============= FINISH: 17:52:02.29 ===============



Attach.txt
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft® Windows Vista™ Home Premium
Boot Device: \Device\HarddiskVolume2
Install Date: 12/17/2008 11:32:43 AM
System Uptime: 9/22/2011 2:28:44 AM (15 hours ago)
.
Motherboard: Gateway | |
Processor: Intel(R) Core(TM)2 Duo CPU P8400 @ 2.26GHz | U2E1 | 1600/266mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 288 GiB total, 38.919 GiB free.
D: is CDROM ()
G: is FIXED (FAT32) - 466 GiB total, 205.057 GiB free.
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
.
==== Installed Programs ======================
.
2007 Microsoft Office Suite Service Pack 1 (SP1)
3ds max 7
3ivx MPEG-4 5.0.3 (remove only)
Acrobat.com
Adobe After Effects CS4
Adobe After Effects CS4 Presets
Adobe After Effects CS4 Template Projects & Footage
Adobe After Effects CS4 Third Party Content
Adobe AIR
Adobe Anchor Service CS4
Adobe Bridge CS4
Adobe CMaps CS4
Adobe Color - Photoshop Specific CS4
Adobe Color EU Extra Settings CS4
Adobe Color JA Extra Settings CS4
Adobe Color NA Recommended Settings CS4
Adobe Color Video Profiles AE CS4
Adobe Color Video Profiles CS CS4
Adobe Community Help
Adobe CS4 American English Speech Analysis Models
Adobe CS4 French Speech Analysis Models
Adobe CS4 German Speech Analysis Models
Adobe CS4 International English Speech Analysis Models
Adobe CS4 Italian Speech Analysis Models
Adobe CS4 Japanese Speech Analysis Models
Adobe CS4 Korean Speech Analysis Models
Adobe CS4 Spanish Speech Analysis Models
Adobe CSI CS4
Adobe Default Language CS4
Adobe Device Central CS4
Adobe Drive CS4
Adobe Dynamiclink Support
Adobe Encore CS4
Adobe Encore CS4 Codecs
Adobe Encore CS4 Library
Adobe ExtendScript Toolkit CS4
Adobe Extension Manager CS4
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Fonts All
Adobe Illustrator CS5
Adobe Linguistics CS4
Adobe Media Encoder CS4
Adobe Media Encoder CS4 Additional Exporter
Adobe Media Encoder CS4 Dolby
Adobe Media Encoder CS4 Exporter
Adobe Media Encoder CS4 Importer
Adobe Media Player
Adobe MotionPicture Color Files CS4
Adobe OnLocation CS4
Adobe Output Module
Adobe PDF Library Files CS4
Adobe Photoshop CS4
Adobe Photoshop CS4 Support
Adobe Premiere Pro CS4
Adobe Premiere Pro CS4 Functional Content
Adobe Premiere Pro CS4 Third Party Content
Adobe Reader 9.4.3
Adobe Search for Help
Adobe Service Manager Extension
Adobe Setup
Adobe Type Support CS4
Adobe Update Manager CS4
Adobe WinSoft Linguistics Plugin
Adobe XMP Panels CS4
AdobeColorCommonSetCMYK
AdobeColorCommonSetRGB
Apple Application Support
Apple Software Update
Autodesk 3ds Max 2010 32-bit
Autodesk 3ds Max 2010 32-bit Components
Autodesk 3ds Max 2010 Tutorials Files
Autodesk Backburner 2008.1
Autodesk FBX Plugin 2009.4 - 3ds Max 2010
avast! Free Antivirus
Battlefield 2(TM)
BLOCKBUSTER Movielink
Call of Duty: Modern Warfare 2
Call of Duty: Modern Warfare 2 - Multiplayer
Camera Assistant Software for Gateway
CamStudio
CANON iMAGE GATEWAY Task for ZoomBrowser EX
Canon Internet Library for ZoomBrowser EX
Canon MOV Decoder
Canon MOV Encoder
Canon MovieEdit Task for ZoomBrowser EX
Canon PhotoRecord
Canon Utilities Digital Photo Professional 3.8
Canon Utilities EOS Utility
Canon Utilities PhotoStitch
Canon Utilities Picture Style Editor
Canon Utilities RAW Image Converter
Canon Utilities RemoteCapture 2.2
Canon Utilities ZoomBrowser EX
Canon ZoomBrowser EX Memory Card Utility
Click to Call with Skype
Compatibility Pack for the 2007 Office system
Connect
CyberLink LabelPrint
CyberLink Power2Go
Deal Info
Diner Dash
DivX Setup
Download Updater (AOL LLC)
Dropbox
DVDFab 7.0.7.0 (08/06/2010)
EA Download Manager
EA Download Manager UI
EarthLink FastLane
EarthLink Software
eMule
EPSON TWAIN 5
Express Burn Disc Burning Software
Gateway Games
Gateway Recovery Management
GearDrvs
Google Chrome
Google SketchUp 8
Google Toolbar for Internet Explorer
Google Update Helper
GoToMeeting 4.5.0.457
Handbrake 0.9.4
headus UVLayout v2 Professional
HiJackThis
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
IDrive version 3.3.4 January 13, 2011
Java Auto Updater
Java(TM) 6 Update 24
jZip
kuler
Malwarebytes' Anti-Malware
McAfee Security Scan Plus
MediaCoder 0.7.3.4685
Messaging API and Collaboration Data Objects 1.2.1
Microsoft Money Essentials
Microsoft Money Shared Libraries
Microsoft Office Excel MUI (English) 2007
Microsoft Office Home and Student 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office PowerPoint Viewer 2007 (English)
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Suite Activation Assistant
Microsoft Office Word MUI (English) 2007
Microsoft Silverlight
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Works
Microsoft_VC80_CRT_x86
Microsoft_VC80_MFC_x86
Microsoft_VC80_MFCLOC_x86
Microsoft_VC90_ATL_x86
Microsoft_VC90_CRT_x86
Microsoft_VC90_MFC_x86
Miro
Movie Outline 3.1.1
Mozilla Firefox 6.0.2 (x86 en-US)
Napster
Napster Burn Engine
NVIDIA Photoshop Plug-ins 64 bit
NVIDIA PhysX
Octoshape add-in for Adobe Flash Player
OpenOffice.org 3.2
PDF Settings CS4
PDF Settings CS5
Pdf995
Pen Tablet
Photoshop Camera Raw
Picasa 3
Pidgin
Pixel Bender Toolkit
QuickTime
RealNetworks - Microsoft Visual C++ 2008 Runtime
RealPlayer
RealUpgrade 1.1
Redistributed Files
Skype™ 5.5
SmallTown
Spelling Dictionaries Support For Adobe Reader 9
SplutterFish Brazil 2 for 3ds Max (Design) 2010 (64bit)
Steam
Suite Shared Configuration CS4
Super Material Uninstall
Switch Sound File Converter
System Requirements Lab
TotalAccess Core Applications
Unity
Unity Web Player
Update for Office 2007 (KB946691)
VC80CRTRedist - 8.0.50727.4053
Vue 9.5 xStream PLE 64bit
WavePad Sound Editor
WebTablet IE Plugin
WebTablet Netscape Plugin
Western Digital USB 3.0 Host Controller Driver
Widevine Media Transformer Plugin 4.5.0
Windows Live Messenger
WinZip 12.0
ZBrush 4
.
==== Event Viewer Messages From Past Week ========
.
9/21/2011 6:36:27 PM, Error: Service Control Manager [7022] - The Windows Update service hung on starting.
9/21/2011 6:31:12 PM, Error: Service Control Manager [7000] - The Intel(R) PRO/1000 NDIS 6 Adapter Driver service failed to start due to the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
9/21/2011 10:43:20 PM, Error: Microsoft-Windows-Dhcp-Client [1001] - Your computer was not assigned an address from the network (by the DHCP Server) for the Network Card with network address 00216B0A2DEA. The following error occurred: The operation was canceled by the user.. Your computer will continue to try and obtain an address on its own from the network address (DHCP) server.
9/21/2011 10:32:40 PM, Error: Microsoft-Windows-Dhcp-Client [1001] - Your computer was not assigned an address from the network (by the DHCP Server) for the Network Card with network address 00216B0A2DEA. The following error occurred: The semaphore timeout period has expired.. Your computer will continue to try and obtain an address on its own from the network address (DHCP) server.
9/19/2011 9:04:06 AM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the TouchServicePen service.
.
==== End Of File ===========================
smurph
Active Member
 
Posts: 2
Joined: September 22nd, 2011, 8:38 pm
Advertisement
Register to Remove

Re: Please help with Google search malware

Unread postby deltalima » September 25th, 2011, 3:47 pm

Checking your log - back soon.
User avatar
deltalima
Admin/Teacher
Admin/Teacher
 
Posts: 7614
Joined: February 28th, 2009, 4:38 pm
Location: UK

Re: Please help with Google search malware

Unread postby deltalima » September 25th, 2011, 3:53 pm

Hi smurph,

Welcome to the forum.

Please be aware that removing Malware is a potentially hazardous undertaking. I will take care not to knowingly suggest courses of action that might damage your computer. However it is impossible for me to foresee all interactions that may happen between the software on your computer and those we'll use to clear you of infection, and I cannot guarantee the safety of your system. It is possible that we might encounter situations where the only recourse is to re-format and re-install your operating system, or to necessitate you taking your computer to a repair shop.

Please note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for this issue on this machine.
  • Please do not run any scans or make any changes to the system unless I ask you too.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • If after 3 days you have not responded to this topic, it will be closed, and you will need to start a new one.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

Please Note:
The programs I ask you to run need to be run in Administrator Mode by... Right clicking the program file and selecting: Run as Administrator.
Additionally, the built-in User Account Control (UAC) utility, if enabled, may prompt you for permission to run the program.
When prompted, please select: Allow. Reference: User Account Control (UAC) and Running as Administrator

Remove P2P Programs

  • I notice there are signs of one or more P2P (Peer to Peer) File Sharing Programs on your computer.

    eMule


  • Please read the Guidelines for P2P Programs where we explain why it's not a good idea to have them.
  • Note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares.

  • Click on start
  • Then Run
  • In the open text entry box please copy/paste appwiz.cpl Then click enter.
  • Press the "Remove" or "Change/Remove"...button to uninstall the programs listed above (in red) and any other P2P you have installed NOW.
  • Take care when answering any questions posed by an uninstaller. Some questions may be worded to deceive you into keeping the program.

CKScanner

  • Please download CKScanner from here to your Desktop.
  • Make sure that CKScanner.exe is on the your Desktop before running the application!
  • Right click on CKScanner.exe and select: Run as Administrator then click Search For Files.
  • After a very short time, when the cursor hourglass disappears, click Save List To File.
  • A message box will verify the file saved
  • Double-click on the CKFiles.txt icon on your Desktop and copy/paste the contents in your next reply.

Next

  • Please download this tool from Microsoft.
  • Right click on MGADiag.exe and select: Run as Administrator.
  • Click Continue.
  • The program will run. It takes a while to finish the diagnosis, please be patient.
  • Once done, click on Copy.
  • Open Notepad and paste the contents in the window.
  • Save this file and copy/paste it in your next reply.

Please let me know if the computer is used for home or for business use.
User avatar
deltalima
Admin/Teacher
Admin/Teacher
 
Posts: 7614
Joined: February 28th, 2009, 4:38 pm
Location: UK

Re: Please help with Google search malware

Unread postby smurph » September 25th, 2011, 4:42 pm

Thanks for the reply. The computer is used for home.
Here is the ckfiles.txt

CKScanner - Additional Security Risks - These are not necessarily bad
c:\program files\autodesk\maya2011\brushes\fun\cracks.mel
c:\program files\autodesk\maya2011\brushes\fun\cracks.mel.icon
c:\program files\autodesk\maya2011\docs\maya2011\en_us\files\uv_texture_mapping_creating_a_cracker_box_model.htm
c:\program files\autodesk\maya2011\presets\nparticles\examples\crackegg.ma
c:\program files\autodesk\maya2011\presets\nparticles\examples\.mayaswatches\crackegg.ma.swatch
c:\program files\autodesk\maya2011\resources\l10n\ja_jp\scripts\crackshatter.res.mel
c:\program files\autodesk\maya2011\scripts\others\crackshatter.mel
c:\program files\autodesk\maya2011\scripts\others\crackshatter.res.mel
c:\program files (x86)\adobe\adobe premiere pro cs4\plug-ins\en_us\vstplugins\decrackler1.dll
c:\program files (x86)\adobe\adobe premiere pro cs4\plug-ins\en_us\vstplugins\decrackler2.dll
c:\program files (x86)\adobe\adobe premiere pro cs4\plug-ins\en_us\vstplugins\decrackler6.dll
c:\program files (x86)\gateway games\bejeweled 2 deluxe\sounds\firecrackle.ogg
c:\users\sean\documents\battlefield 2\mods\bf2\cache\{d7b71e3e-456c-11cf-306e-9d2601c2ca35}_2442_2\rashaderstmbasedetailcrack.cfx
c:\users\sean\documents\battlefield 2\mods\bf2\cache\{d7b71e3e-456c-11cf-306e-9d2601c2ca35}_2442_2\rashaderstmbasedetailcrackalphatest.cfx
c:\users\sean\documents\battlefield 2\mods\bf2\cache\{d7b71e3e-456c-11cf-306e-9d2601c2ca35}_2442_2\rashaderstmbasedetailcrackalphatestlightmap.cfx
c:\users\sean\documents\battlefield 2\mods\bf2\cache\{d7b71e3e-456c-11cf-306e-9d2601c2ca35}_2442_2\rashaderstmbasedetailcrackalphatestlightmapshadow.cfx
c:\users\sean\documents\battlefield 2\mods\bf2\cache\{d7b71e3e-456c-11cf-306e-9d2601c2ca35}_2442_2\rashaderstmbasedetailcrackalphatestpointlight.cfx
c:\users\sean\documents\battlefield 2\mods\bf2\cache\{d7b71e3e-456c-11cf-306e-9d2601c2ca35}_2442_2\rashaderstmbasedetailcrackalphatestshadow.cfx
c:\users\sean\documents\battlefield 2\mods\bf2\cache\{d7b71e3e-456c-11cf-306e-9d2601c2ca35}_2442_2\rashaderstmbasedetailcracklightmap.cfx
c:\users\sean\documents\battlefield 2\mods\bf2\cache\{d7b71e3e-456c-11cf-306e-9d2601c2ca35}_2442_2\rashaderstmbasedetailcracklightmapshadow.cfx
c:\users\sean\documents\battlefield 2\mods\bf2\cache\{d7b71e3e-456c-11cf-306e-9d2601c2ca35}_2442_2\rashaderstmbasedetailcrackndetailncrack.cfx
c:\users\sean\documents\battlefield 2\mods\bf2\cache\{d7b71e3e-456c-11cf-306e-9d2601c2ca35}_2442_2\rashaderstmbasedetailcrackndetailncrackalphatest.cfx
c:\users\sean\documents\battlefield 2\mods\bf2\cache\{d7b71e3e-456c-11cf-306e-9d2601c2ca35}_2442_2\rashaderstmbasedetailcrackndetailncrackalphatestlightmap.cfx
c:\users\sean\documents\battlefield 2\mods\bf2\cache\{d7b71e3e-456c-11cf-306e-9d2601c2ca35}_2442_2\rashaderstmbasedetailcrackndetailncrackalphatestlightmapshadow.cfx
c:\users\sean\documents\battlefield 2\mods\bf2\cache\{d7b71e3e-456c-11cf-306e-9d2601c2ca35}_2442_2\rashaderstmbasedetailcrackndetailncrackalphatestpointlight.cfx
c:\users\sean\documents\battlefield 2\mods\bf2\cache\{d7b71e3e-456c-11cf-306e-9d2601c2ca35}_2442_2\rashaderstmbasedetailcrackndetailncrackalphatestshadow.cfx
c:\users\sean\documents\battlefield 2\mods\bf2\cache\{d7b71e3e-456c-11cf-306e-9d2601c2ca35}_2442_2\rashaderstmbasedetailcrackndetailncracklightmap.cfx
c:\users\sean\documents\battlefield 2\mods\bf2\cache\{d7b71e3e-456c-11cf-306e-9d2601c2ca35}_2442_2\rashaderstmbasedetailcrackndetailncracklightmapshadow.cfx
c:\users\sean\documents\battlefield 2\mods\bf2\cache\{d7b71e3e-456c-11cf-306e-9d2601c2ca35}_2442_2\rashaderstmbasedetailcrackndetailncrackpointlight.cfx
c:\users\sean\documents\battlefield 2\mods\bf2\cache\{d7b71e3e-456c-11cf-306e-9d2601c2ca35}_2442_2\rashaderstmbasedetailcrackndetailncrackshadow.cfx
c:\users\sean\documents\battlefield 2\mods\bf2\cache\{d7b71e3e-456c-11cf-306e-9d2601c2ca35}_2442_2\rashaderstmbasedetailcrackpointlight.cfx
c:\users\sean\documents\battlefield 2\mods\bf2\cache\{d7b71e3e-456c-11cf-306e-9d2601c2ca35}_2442_2\rashaderstmbasedetailcrackshadow.cfx
c:\users\sean\documents\battlefield 2\mods\bf2\cache\{d7b71e3e-456c-11cf-306e-9d2601c2ca35}_2442_2\rashaderstmbasedetaildirtcrack.cfx
c:\users\sean\documents\battlefield 2\mods\bf2\cache\{d7b71e3e-456c-11cf-306e-9d2601c2ca35}_2442_2\rashaderstmbasedetaildirtcrackalphatest.cfx
c:\users\sean\documents\battlefield 2\mods\bf2\cache\{d7b71e3e-456c-11cf-306e-9d2601c2ca35}_2442_2\rashaderstmbasedetaildirtcrackalphatestlightmap.cfx
c:\users\sean\documents\battlefield 2\mods\bf2\cache\{d7b71e3e-456c-11cf-306e-9d2601c2ca35}_2442_2\rashaderstmbasedetaildirtcrackalphatestlightmapshadow.cfx
c:\users\sean\documents\battlefield 2\mods\bf2\cache\{d7b71e3e-456c-11cf-306e-9d2601c2ca35}_2442_2\rashaderstmbasedetaildirtcrackalphatestpointlight.cfx
c:\users\sean\documents\battlefield 2\mods\bf2\cache\{d7b71e3e-456c-11cf-306e-9d2601c2ca35}_2442_2\rashaderstmbasedetaildirtcrackalphatestshadow.cfx
c:\users\sean\documents\battlefield 2\mods\bf2\cache\{d7b71e3e-456c-11cf-306e-9d2601c2ca35}_2442_2\rashaderstmbasedetaildirtcracklightmap.cfx
c:\users\sean\documents\battlefield 2\mods\bf2\cache\{d7b71e3e-456c-11cf-306e-9d2601c2ca35}_2442_2\rashaderstmbasedetaildirtcracklightmapshadow.cfx
c:\users\sean\documents\battlefield 2\mods\bf2\cache\{d7b71e3e-456c-11cf-306e-9d2601c2ca35}_2442_2\rashaderstmbasedetaildirtcrackndetailncrack.cfx
c:\users\sean\documents\battlefield 2\mods\bf2\cache\{d7b71e3e-456c-11cf-306e-9d2601c2ca35}_2442_2\rashaderstmbasedetaildirtcrackndetailncrackalphatest.cfx
c:\users\sean\documents\battlefield 2\mods\bf2\cache\{d7b71e3e-456c-11cf-306e-9d2601c2ca35}_2442_2\rashaderstmbasedetaildirtcrackndetailncrackalphatestlightmap.cfx
c:\users\sean\documents\battlefield 2\mods\bf2\cache\{d7b71e3e-456c-11cf-306e-9d2601c2ca35}_2442_2\rashaderstmbasedetaildirtcrackndetailncrackalphatestlightmapshadow.cfx
c:\users\sean\documents\battlefield 2\mods\bf2\cache\{d7b71e3e-456c-11cf-306e-9d2601c2ca35}_2442_2\rashaderstmbasedetaildirtcrackndetailncrackalphatestpointlight.cfx
c:\users\sean\documents\battlefield 2\mods\bf2\cache\{d7b71e3e-456c-11cf-306e-9d2601c2ca35}_2442_2\rashaderstmbasedetaildirtcrackndetailncrackalphatestshadow.cfx
c:\users\sean\documents\battlefield 2\mods\bf2\cache\{d7b71e3e-456c-11cf-306e-9d2601c2ca35}_2442_2\rashaderstmbasedetaildirtcrackndetailncracklightmap.cfx
c:\users\sean\documents\battlefield 2\mods\bf2\cache\{d7b71e3e-456c-11cf-306e-9d2601c2ca35}_2442_2\rashaderstmbasedetaildirtcrackndetailncracklightmapshadow.cfx
c:\users\sean\documents\battlefield 2\mods\bf2\cache\{d7b71e3e-456c-11cf-306e-9d2601c2ca35}_2442_2\rashaderstmbasedetaildirtcrackndetailncrackpointlight.cfx
c:\users\sean\documents\battlefield 2\mods\bf2\cache\{d7b71e3e-456c-11cf-306e-9d2601c2ca35}_2442_2\rashaderstmbasedetaildirtcrackndetailncrackshadow.cfx
c:\users\sean\documents\battlefield 2\mods\bf2\cache\{d7b71e3e-456c-11cf-306e-9d2601c2ca35}_2442_2\rashaderstmbasedetaildirtcrackpointlight.cfx
c:\users\sean\documents\battlefield 2\mods\bf2\cache\{d7b71e3e-456c-11cf-306e-9d2601c2ca35}_2442_2\rashaderstmbasedetaildirtcrackshadow.cfx
c:\users\sean\documents\battlefield 2\mods\bf2\cache\{d7b71e3e-456c-11cf-306e-9d2601c2ca35}_2720_2\rashaderstmbasedetailcrack.cfx
c:\users\sean\documents\battlefield 2\mods\bf2\cache\{d7b71e3e-456c-11cf-306e-9d2601c2ca35}_2720_2\rashaderstmbasedetailcrackalphatest.cfx
c:\users\sean\documents\battlefield 2\mods\bf2\cache\{d7b71e3e-456c-11cf-306e-9d2601c2ca35}_2720_2\rashaderstmbasedetailcrackalphatestlightmap.cfx
c:\users\sean\documents\battlefield 2\mods\bf2\cache\{d7b71e3e-456c-11cf-306e-9d2601c2ca35}_2720_2\rashaderstmbasedetailcrackalphatestlightmapshadow.cfx
c:\users\sean\documents\battlefield 2\mods\bf2\cache\{d7b71e3e-456c-11cf-306e-9d2601c2ca35}_2720_2\rashaderstmbasedetailcrackalphatestpointlight.cfx
c:\users\sean\documents\battlefield 2\mods\bf2\cache\{d7b71e3e-456c-11cf-306e-9d2601c2ca35}_2720_2\rashaderstmbasedetailcrackalphatestshadow.cfx
c:\users\sean\documents\battlefield 2\mods\bf2\cache\{d7b71e3e-456c-11cf-306e-9d2601c2ca35}_2720_2\rashaderstmbasedetailcracklightmap.cfx
c:\users\sean\documents\battlefield 2\mods\bf2\cache\{d7b71e3e-456c-11cf-306e-9d2601c2ca35}_2720_2\rashaderstmbasedetailcracklightmapshadow.cfx
c:\users\sean\documents\battlefield 2\mods\bf2\cache\{d7b71e3e-456c-11cf-306e-9d2601c2ca35}_2720_2\rashaderstmbasedetailcrackndetailncrack.cfx
c:\users\sean\documents\battlefield 2\mods\bf2\cache\{d7b71e3e-456c-11cf-306e-9d2601c2ca35}_2720_2\rashaderstmbasedetailcrackndetailncrackalphatest.cfx
c:\users\sean\documents\battlefield 2\mods\bf2\cache\{d7b71e3e-456c-11cf-306e-9d2601c2ca35}_2720_2\rashaderstmbasedetailcrackndetailncrackalphatestlightmap.cfx
c:\users\sean\documents\battlefield 2\mods\bf2\cache\{d7b71e3e-456c-11cf-306e-9d2601c2ca35}_2720_2\rashaderstmbasedetailcrackndetailncrackalphatestlightmapshadow.cfx
c:\users\sean\documents\battlefield 2\mods\bf2\cache\{d7b71e3e-456c-11cf-306e-9d2601c2ca35}_2720_2\rashaderstmbasedetailcrackndetailncrackalphatestpointlight.cfx
c:\users\sean\documents\battlefield 2\mods\bf2\cache\{d7b71e3e-456c-11cf-306e-9d2601c2ca35}_2720_2\rashaderstmbasedetailcrackndetailncrackalphatestshadow.cfx
c:\users\sean\documents\battlefield 2\mods\bf2\cache\{d7b71e3e-456c-11cf-306e-9d2601c2ca35}_2720_2\rashaderstmbasedetailcrackndetailncracklightmap.cfx
c:\users\sean\documents\battlefield 2\mods\bf2\cache\{d7b71e3e-456c-11cf-306e-9d2601c2ca35}_2720_2\rashaderstmbasedetailcrackndetailncracklightmapshadow.cfx
c:\users\sean\documents\battlefield 2\mods\bf2\cache\{d7b71e3e-456c-11cf-306e-9d2601c2ca35}_2720_2\rashaderstmbasedetailcrackndetailncrackpointlight.cfx
c:\users\sean\documents\battlefield 2\mods\bf2\cache\{d7b71e3e-456c-11cf-306e-9d2601c2ca35}_2720_2\rashaderstmbasedetailcrackndetailncrackshadow.cfx
c:\users\sean\documents\battlefield 2\mods\bf2\cache\{d7b71e3e-456c-11cf-306e-9d2601c2ca35}_2720_2\rashaderstmbasedetailcrackpointlight.cfx
c:\users\sean\documents\battlefield 2\mods\bf2\cache\{d7b71e3e-456c-11cf-306e-9d2601c2ca35}_2720_2\rashaderstmbasedetailcrackshadow.cfx
c:\users\sean\documents\battlefield 2\mods\bf2\cache\{d7b71e3e-456c-11cf-306e-9d2601c2ca35}_2720_2\rashaderstmbasedetaildirtcrack.cfx
c:\users\sean\documents\battlefield 2\mods\bf2\cache\{d7b71e3e-456c-11cf-306e-9d2601c2ca35}_2720_2\rashaderstmbasedetaildirtcrackalphatest.cfx
c:\users\sean\documents\battlefield 2\mods\bf2\cache\{d7b71e3e-456c-11cf-306e-9d2601c2ca35}_2720_2\rashaderstmbasedetaildirtcrackalphatestlightmap.cfx
c:\users\sean\documents\battlefield 2\mods\bf2\cache\{d7b71e3e-456c-11cf-306e-9d2601c2ca35}_2720_2\rashaderstmbasedetaildirtcrackalphatestlightmapshadow.cfx
c:\users\sean\documents\battlefield 2\mods\bf2\cache\{d7b71e3e-456c-11cf-306e-9d2601c2ca35}_2720_2\rashaderstmbasedetaildirtcrackalphatestpointlight.cfx
c:\users\sean\documents\battlefield 2\mods\bf2\cache\{d7b71e3e-456c-11cf-306e-9d2601c2ca35}_2720_2\rashaderstmbasedetaildirtcrackalphatestshadow.cfx
c:\users\sean\documents\battlefield 2\mods\bf2\cache\{d7b71e3e-456c-11cf-306e-9d2601c2ca35}_2720_2\rashaderstmbasedetaildirtcracklightmap.cfx
c:\users\sean\documents\battlefield 2\mods\bf2\cache\{d7b71e3e-456c-11cf-306e-9d2601c2ca35}_2720_2\rashaderstmbasedetaildirtcracklightmapshadow.cfx
c:\users\sean\documents\battlefield 2\mods\bf2\cache\{d7b71e3e-456c-11cf-306e-9d2601c2ca35}_2720_2\rashaderstmbasedetaildirtcrackndetailncrack.cfx
c:\users\sean\documents\battlefield 2\mods\bf2\cache\{d7b71e3e-456c-11cf-306e-9d2601c2ca35}_2720_2\rashaderstmbasedetaildirtcrackndetailncrackalphatest.cfx
c:\users\sean\documents\battlefield 2\mods\bf2\cache\{d7b71e3e-456c-11cf-306e-9d2601c2ca35}_2720_2\rashaderstmbasedetaildirtcrackndetailncrackalphatestlightmap.cfx
c:\users\sean\documents\battlefield 2\mods\bf2\cache\{d7b71e3e-456c-11cf-306e-9d2601c2ca35}_2720_2\rashaderstmbasedetaildirtcrackndetailncrackalphatestlightmapshadow.cfx
c:\users\sean\documents\battlefield 2\mods\bf2\cache\{d7b71e3e-456c-11cf-306e-9d2601c2ca35}_2720_2\rashaderstmbasedetaildirtcrackndetailncrackalphatestpointlight.cfx
c:\users\sean\documents\battlefield 2\mods\bf2\cache\{d7b71e3e-456c-11cf-306e-9d2601c2ca35}_2720_2\rashaderstmbasedetaildirtcrackndetailncrackalphatestshadow.cfx
c:\users\sean\documents\battlefield 2\mods\bf2\cache\{d7b71e3e-456c-11cf-306e-9d2601c2ca35}_2720_2\rashaderstmbasedetaildirtcrackndetailncracklightmap.cfx
c:\users\sean\documents\battlefield 2\mods\bf2\cache\{d7b71e3e-456c-11cf-306e-9d2601c2ca35}_2720_2\rashaderstmbasedetaildirtcrackndetailncracklightmapshadow.cfx
c:\users\sean\documents\battlefield 2\mods\bf2\cache\{d7b71e3e-456c-11cf-306e-9d2601c2ca35}_2720_2\rashaderstmbasedetaildirtcrackndetailncrackpointlight.cfx
c:\users\sean\documents\battlefield 2\mods\bf2\cache\{d7b71e3e-456c-11cf-306e-9d2601c2ca35}_2720_2\rashaderstmbasedetaildirtcrackndetailncrackshadow.cfx
c:\users\sean\documents\battlefield 2\mods\bf2\cache\{d7b71e3e-456c-11cf-306e-9d2601c2ca35}_2720_2\rashaderstmbasedetaildirtcrackpointlight.cfx
c:\users\sean\documents\battlefield 2\mods\bf2\cache\{d7b71e3e-456c-11cf-306e-9d2601c2ca35}_2720_2\rashaderstmbasedetaildirtcrackshadow.cfx
c:\users\sean\documents\e-on software\vue 9.5 xstream ple\filters\other filters\cracks.flt
c:\users\sean\documents\e-on software\vue 9.5 xstream ple\filters\other filters\narrow crack.flt
c:\users\sean\documents\e-on software\vue 9.5 xstream ple\filters\other filters\round crack.flt
c:\users\sean\documents\e-on software\vue 9.5 xstream ple\filters\other filters\simple crack.flt
c:\users\sean\documents\e-on software\vue 9.5 xstream ple\filters\other filters\wide crack.flt
c:\users\sean\documents\e-on software\vue 9.5 xstream ple\functions\basic\cracks.fnc
c:\users\sean\documents\e-on software\vue 9.5 xstream ple\functions\basic\sparse cracks.fnc
c:\users\sean\documents\e-on software\vue 9.5 xstream ple\functions\bumps\complex cracks.fnc
c:\users\sean\documents\e-on software\vue 9.5 xstream ple\functions\bumps\multi cracked.fnc
c:\users\sean\documents\e-on software\vue 9.5 xstream ple\functions\terrain altitudes\cracked vornoi rocks.fnc
c:\users\sean\documents\e-on software\vue 9.5 xstream ple\materials\basic\31_cracked porcelaine.mat
c:\users\sean\documents\imtoo software studio\mov converter\crack.js
c:\users\sean\downloads\emule\incoming\adobe after effects cs3 keygen activation!!!.rar
c:\users\sean\downloads\emule\incoming\adobe after effects cs3 keygen.rar
scanner sequence 3.ZZ.11.SANARL
----- EOF -----
___________________________________________________________________________________________________________________________________________________________________

and here is the MGADiag.exe text

Diagnostic Report (1.9.0027.0):
-----------------------------------------
Windows Validation Data-->
Validation Status: Genuine
Validation Code: 0
Cached Online Validation Code: N/A, hr = 0xc004f012
Windows Product Key: *****-*****-3RBY2-BGQ2R-DR9M6
Windows Product Key Hash: EYIpz/47G03lWRAOmk3kg+lR7Rc=
Windows Product ID: 89583-OEM-7332157-00141
Windows Product ID Type: 2
Windows License Type: OEM SLP
Windows OS version: 6.0.6002.2.00010300.2.0.003
ID: {ACF8E2D2-BACC-444C-8AB2-465FF66396C7}(1)
Is Admin: Yes
TestCab: 0x0
LegitcheckControl ActiveX: N/A, hr = 0x80070002
Signed By: N/A, hr = 0x80070002
Product Name: Windows Vista (TM) Home Premium
Architecture: 0x00000009
Build lab: 6002.lh_sp2rtm.090410-1830
TTS Error: K:20110611015020988-M:20110921183016310-
Validation Diagnostic:
Resolution Status: N/A

Vista WgaER Data-->
ThreatID(s): N/A, hr = 0x80070002
Version: N/A, hr = 0x80070002

Windows XP Notifications Data-->
Cached Result: N/A, hr = 0x80070002
File Exists: No
Version: N/A, hr = 0x80070002
WgaTray.exe Signed By: N/A, hr = 0x80070002
WgaLogon.dll Signed By: N/A, hr = 0x80070002

OGA Notifications Data-->
Cached Result: N/A, hr = 0x80070002
Version: N/A, hr = 0x80070002
OGAExec.exe Signed By: N/A, hr = 0x80070002
OGAAddin.dll Signed By: N/A, hr = 0x80070002

OGA Data-->
Office Status: 102
Microsoft Office Home and Student 2007 - 100 Genuine
OGA Version: N/A, 0x80070002
Signed By: N/A, hr = 0x80070002
Office Diagnostics: 77F760FE-153-80070002_7E90FEE8-175-80070002_025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3_B4D0AA8B-920-80070057

Browser Data-->
Proxy settings: N/A
User Agent: Mozilla/4.0 (compatible; MSIE 7.0; Win32)
Default Browser: C:\Program Files (x86)\Mozilla Firefox\firefox.exe
Download signed ActiveX controls: Prompt
Download unsigned ActiveX controls: Disabled
Run ActiveX controls and plug-ins: Allowed
Initialize and script ActiveX controls not marked as safe: Disabled
Allow scripting of Internet Explorer Webbrowser control: Disabled
Active scripting: Allowed
Script ActiveX controls marked as safe for scripting: Allowed

File Scan Data-->

Other data-->
Office Details: <GenuineResults><MachineData><UGUID>{ACF8E2D2-BACC-444C-8AB2-465FF66396C7}</UGUID><Version>1.9.0027.0</Version><OS>6.0.6002.2.00010300.2.0.003</OS><Architecture>x64</Architecture><PKey>*****-*****-*****-*****-DR9M6</PKey><PID>89583-OEM-7332157-00141</PID><PIDType>2</PIDType><SID>S-1-5-21-3960302749-1263732770-1919209823</SID><SYSTEM><Manufacturer>Gateway </Manufacturer><Model>P-7805u </Model></SYSTEM><BIOS><Manufacturer>Phoenix Technologies LTD</Manufacturer><Version>9C.11.00 </Version><SMBIOSVersion major="2" minor="5"/><Date>20080917000000.000000+000</Date></BIOS><HWID>E0313507018400F8</HWID><UserLCID>0409</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>Pacific Standard Time(GMT-08:00)</TimeZone><iJoin>0</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM><OEMID>GATEWA</OEMID><OEMTableID>SYSTEM </OEMTableID></OEM><GANotification/></MachineData><Software><Office><Result>102</Result><Products><Product GUID="{91120000-002F-0000-0000-0000000FF1CE}"><LegitResult>100</LegitResult><Name>Microsoft Office Home and Student 2007</Name><Ver>12</Ver><PidType>19</PidType></Product></Products><Applications><App Id="16" Version="12" Result="100"/><App Id="18" Version="12" Result="100"/><App Id="1B" Version="12" Result="100"/><App Id="A1" Version="12" Result="100"/></Applications></Office></Software></GenuineResults>

Spsys.log Content: U1BMRwEAAAAAAQAACAAAAHgKAAAAAAAAYWECAAAAAADRNsWBid7LARhy9171jCizkdIEkQaJZ66Dl3aTjHxG7kh7q2ArWRtNBp3M6IzAS1cL8Um0mdxh2yd7IPmIgITKmLNv1wD2WLahUG+fy1PkKkZU6N8rM3fZ4DkkCd2V0+w0qMw9NW1lJIqaMVS50xsGhTiu2v3HTjLlzsauw1rN6YPtvvhlgmsO7TtXiHJbmqvzuSde4tUlmcGxBpop0WwiuBXa5HXuzs1OU5kpI4Km83cHZMn5BmY2HdKPD8tNYkwP34K9Ekif+jOQ1ifb1stzrqx+w3WNaAwzkNYn29bLc66sfsN1jWgMM5DWJ9vWy3OurH7DdY1oDDOQ1ifb1stzrqx+w3WNaAwYcvde9Ywos5HSBJEGiWeut2DiI1/YgZYTnPxwlaO3f7LGafwYkT/CZokQgMSr7t0neyD5iICEypizb9cA9li261R7XEIeHJ+I5t95BjZ5pOA5JAndldPsNKjMPTVtZSSKmjFUudMbBoU4rtr9x04y5c7GrsNazemD7b74ZYJrDu07V4hyW5qr87knXuLVJZnBsQaaKdFsIrgV2uR17s7NTlOZKSOCpvN3B2TJ+QZmNh3Sjw/LTWJMD9+CvRJIn/ozkNYn29bLc66sfsN1jWgMM5DWJ9vWy3OurH7DdY1oDDOQ1ifb1stzrqx+w3WNaAwzkNYn29bLc66sfsN1jWgMGHL3XvWMKLOR0gSRBolnruYkkclpuxeT9KdL4UT5HlK5zygG9Qrkfv1DlJFCYFHrJ3sg+YiAhMqYs2/XAPZYthcrldIRNFHip8+9CrGzMh7gOSQJ3ZXT7DSozD01bWUkipoxVLnTGwaFOK7a/cdOMuXOxq7DWs3pg+2++GWCaw7tO1eIcluaq/O5J17i1SWZwbEGminRbCK4Fdrkde7OzU5TmSkjgqbzdwdkyfkGZjYd0o8Py01iTA/fgr0SSJ/6M5DWJ9vWy3OurH7DdY1oDDOQ1ifb1stzrqx+w3WNaAwzkNYn29bLc66sfsN1jWgMM5DWJ9vWy3OurH7DdY1oDBhy9171jCizkdIEkQaJZ67DkQur4hXy7L/pZ5TJe7R2z4iUVSdOKrxxhP+PoiMAZSd7IPmIgITKmLNv1wD2WLbBB9lZPGupQ+LOq0eDXHjP4DkkCd2V0+w0qMw9NW1lJIqaMVS50xsGhTiu2v3HTjLlzsauw1rN6YPtvvhlgmsO7TtXiHJbmqvzuSde4tUlmcGxBpop0WwiuBXa5HXuzs1OU5kpI4Km83cHZMn5BmY2HdKPD8tNYkwP34K9Ekif+jOQ1ifb1stzrqx+w3WNaAwzkNYn29bLc66sfsN1jWgMM5DWJ9vWy3OurH7DdY1oDDOQ1ifb1stzrqx+w3WNaAwYcvde9Ywos5HSBJEGiWeuU+F9GcNQhiCM1cgCyeSQsAu8ppcJQj3NqTS6r/Pj2d8neyD5iICEypizb9cA9li2M67rqN0W+jV8tiigZpUnzOA5JAndldPsNKjMPTVtZSSKmjFUudMbBoU4rtr9x04y5c7GrsNazemD7b74ZYJrDu07V4hyW5qr87knXuLVJZnBsQaaKdFsIrgV2uR17s7NTlOZKSOCpvN3B2TJ+QZmNh3Sjw/LTWJMD9+CvRJIn/ozkNYn29bLc66sfsN1jWgMM5DWJ9vWy3OurH7DdY1oDDOQ1ifb1stzrqx+w3WNaAwzkNYn29bLc66sfsN1jWgMGHL3XvWMKLOR0gSRBolnrl9AtMzSPBMCWFtuM9s1YBBn5OZ4ipLiM3u+NLiyDmKAJ3sg+YiAhMqYs2/XAPZYtvMWzA6u/EMMyX8BMxvZ2+XgOSQJ3ZXT7DSozD01bWUkipoxVLnTGwaFOK7a/cdOMuXOxq7DWs3pg+2++GWCaw7tO1eIcluaq/O5J17i1SWZwbEGminRbCK4Fdrkde7OzU5TmSkjgqbzdwdkyfkGZjYd0o8Py01iTA/fgr0SSJ/6M5DWJ9vWy3OurH7DdY1oDDOQ1ifb1stzrqx+w3WNaAwzkNYn29bLc66sfsN1jWgMM5DWJ9vWy3OurH7DdY1oDBhy9171jCizkdIEkQaJZ660PRta1A+ZolQi7oFiWcxrw6T9smZXr5qFF0pMRbySbCd7IPmIgITKmLNv1wD2WLZO8BhnI10WpNWygwQRX4Sr4DkkCd2V0+w0qMw9NW1lJIqaMVS50xsGhTiu2v3HTjLlzsauw1rN6YPtvvhlgmsO7TtXiHJbmqvzuSde4tUlmcGxBpop0WwiuBXa5HXuzs1OU5kpI4Km83cHZMn5BmY2HdKPD8tNYkwP34K9Ekif+jOQ1ifb1stzrqx+w3WNaAwzkNYn29bLc66sfsN1jWgMM5DWJ9vWy3OurH7DdY1oDDOQ1ifb1stzrqx+w3WNaAwYcvde9Ywos5HSBJEGiWeuMDojdnvMfz/zvcSu6KKXK+pe6F9pFkpj43WUedN0rNYneyD5iICEypizb9cA9li2fTow8CCyum3djwK6ZRq4V+A5JAndldPsNKjMPTVtZSSKmjFUudMbBoU4rtr9x04y5c7GrsNazemD7b74ZYJrDu07V4hyW5qr87knXuLVJZnBsQaaKdFsIrgV2uR17s7NTlOZKSOCpvN3B2TJ+QZmNh3Sjw/LTWJMD9+CvRJIn/ozkNYn29bLc66sfsN1jWgMM5DWJ9vWy3OurH7DdY1oDDOQ1ifb1stzrqx+w3WNaAwzkNYn29bLc66sfsN1jWgMGHL3XvWMKLOR0gSRBolnruc+xHPU4uamOlWKv5XQfuHCnCVTn7HFs8y6bomjg7H7J3sg+YiAhMqYs2/XAPZYtiAMrfeblAgMz47J+6QSvs/gOSQJ3ZXT7DSozD01bWUkipoxVLnTGwaFOK7a/cdOMuXOxq7DWs3pg+2++GWCaw7tO1eIcluaq/O5J17i1SWZwbEGminRbCK4Fdrkde7OzU5TmSkjgqbzdwdkyfkGZjYd0o8Py01iTA/fgr0SSJ/6M5DWJ9vWy3OurH7DdY1oDDOQ1ifb1stzrqx+w3WNaAwzkNYn29bLc66sfsN1jWgMM5DWJ9vWy3OurH7DdY1oDBhy9171jCizkdIEkQaJZ65YxS2vHM0GZfeLohH1XFXZsI0J+s7g0dNSDJuLBP2exyd7IPmIgITKmLNv1wD2WLahUG+fy1PkKkZU6N8rM3fZ4DkkCd2V0+w0qMw9NW1lJIqaMVS50xsGhTiu2v3HTjLlzsauw1rN6YPtvvhlgmsO7TtXiHJbmqvzuSde4tUlmcGxBpop0WwiuBXa5HXuzs1OU5kpI4Km83cHZMn5BmY2HdKPD8tNYkwP34K9Ekif+jOQ1ifb1stzrqx+w3WNaAwzkNYn29bLc66sfsN1jWgMM5DWJ9vWy3OurH7DdY1oDDOQ1ifb1stzrqx+w3WNaAwYcvde9Ywos5HSBJEGiWeuXugZbQR4V+Yla53MXR9AerHpORg4Xx71PwVtnwjifc8neyD5iICEypizb9cA9li2OuQ/1bu3QHEB6P750oFIceA5JAndldPsNKjMPTVtZSSKmjFUudMbBoU4rtr9x04y5c7GrsNazemD7b74ZYJrDu07V4hyW5qr87knXuLVJZnBsQaaKdFsIrgV2uR17s7NTlOZKSOCpvN3B2TJ+QZmNh3Sjw/LTWJMD9+CvRJIn/ozkNYn29bLc66sfsN1jWgMM5DWJ9vWy3OurH7DdY1oDDOQ1ifb1stzrqx+w3WNaAwzkNYn29bLc66sfsN1jWgMGHL3XvWMKLOR0gSRBolnrivK8pa3tEnueCRPtg04yT67cPj0R9TfWCNXxofHwPL+J3sg+YiAhMqYs2/XAPZYtmwNkeP4hGXSBLfuPkVoUHvgOSQJ3ZXT7DSozD01bWUkipoxVLnTGwaFOK7a/cdOMuXOxq7DWs3pg+2++GWCaw7tO1eIcluaq/O5J17i1SWZwbEGminRbCK4Fdrkde7OzU5TmSkjgqbzdwdkyfkGZjYd0o8Py01iTA/fgr0SSJ/6M5DWJ9vWy3OurH7DdY1oDDOQ1ifb1stzrqx+w3WNaAwzkNYn29bLc66sfsN1jWgMM5DWJ9vWy3OurH7DdY1oDBhy9171jCizkdIEkQaJZ64/3EUSsoWtQ/dScCEh0f1VMBAUFgQ6LOOVVqqAs7324Sd7IPmIgITKmLNv1wD2WLbDXDTbq0dtb+6e9gIM4Xdz4DkkCd2V0+w0qMw9NW1lJIqaMVS50xsGhTiu2v3HTjLlzsauw1rN6YPtvvhlgmsO7TtXiHJbmqvzuSde4tUlmcGxBpop0WwiuBXa5HXuzs1OU5kpI4Km83cHZMn5BmY2HdKPD8tNYkwP34K9Ekif+jOQ1ifb1stzrqx+w3WNaAwzkNYn29bLc66sfsN1jWgMM5DWJ9vWy3OurH7DdY1oDDOQ1ifb1stzrqx+w3WNaAwYcvde9Ywos5HSBJEGiWeuQYL3a3tGlIlIan4XZJgmK3pYcfmnn+w8UwfacNjZi3MneyD5iICEypizb9cA9li2IqntsNyIhO4mg3HqfBB2CeA5JAndldPsNKjMPTVtZSSKmjFUudMbBoU4rtr9x04y5c7GrsNazemD7b74ZYJrDu07V4hyW5qr87knXuLVJZnBsQaaKdFsIrgV2uR17s7NTlOZKSOCpvN3B2TJ+QZmNh3Sjw/LTWJMD9+CvRJIn/ozkNYn29bLc66sfsN1jWgMM5DWJ9vWy3OurH7DdY1oDDOQ1ifb1stzrqx+w3WNaAwzkNYn29bLc66sfsN1jWgMGHL3XvWMKLOR0gSRBolnrnIqkreEyzS+D5m5kyI7xhVxYCaAneHf8lNNIlG3R8uxJ3sg+YiAhMqYs2/XAPZYtgp+4/lFbRgcQfrABlswcoOVtX+xoEa+5dV0YJpwpXhpipoxVLnTGwaFOK7a/cdOMuXOxq7DWs3pg+2++GWCaw7tO1eIcluaq/O5J17i1SWZwbEGminRbCK4Fdrkde7OzU5TmSkjgqbzdwdkyfkGZjYd0o8Py01iTA/fgr0SSJ/6M5DWJ9vWy3OurH7DdY1oDDOQ1ifb1stzrqx+w3WNaAwzkNYn29bLc66sfsN1jWgMM5DWJ9vWy3OurH7DdY1oDBhy9171jCizkdIEkQaJZ65D5skudH1D4w6zccJEV/eXaw2qDVa/sByB+YSd8UrczCd7IPmIgITKmLNv1wD2WLYH+QV9OxmhrziTumYm2GiLlbV/saBGvuXVdGCacKV4aYqaMVS50xsGhTiu2v3HTjLlzsauw1rN6YPtvvhlgmsO7TtXiHJbmqvzuSde4tUlmcGxBpop0WwiuBXa5HXuzs1OU5kpI4Km83cHZMn5BmY2HdKPD8tNYkwP34K9Ekif+jOQ1ifb1stzrqx+w3WNaAwzkNYn29bLc66sfsN1jWgMM5DWJ9vWy3OurH7DdY1oDDOQ1ifb1stzrqx+w3WNaAwYcvde9Ywos5HSBJEGiWeuV1iedtMR8D1B0ZnJ/URHzvFUMj3O6vz0q5aD+TKGo1sneyD5iICEypizb9cA9li2+NvJMTc11EUhS1N7RoTKPJW1f7GgRr7l1XRgmnCleGmKmjFUudMbBoU4rtr9x04y5c7GrsNazemD7b74ZYJrDu07V4hyW5qr87knXuLVJZnBsQaaKdFsIrgV2uR17s7NTlOZKSOCpvN3B2TJ+QZmNh3Sjw/LTWJMD9+CvRJIn/ozkNYn29bLc66sfsN1jWgMM5DWJ9vWy3OurH7DdY1oDDOQ1ifb1stzrqx+w3WNaAwzkNYn29bLc66sfsN1jWgMGHL3XvWMKLOR0gSRBolnrr8aJ/cdgG1IThX4BGmbADqbtP6J9u4llYQKWrDSGuEuJ3sg+YiAhMqYs2/XAPZYtmlF8hkLCbBXSqT7oVDW6uuVtX+xoEa+5dV0YJpwpXhpipoxVLnTGwaFOK7a/cdOMuXOxq7DWs3pg+2++GWCaw7tO1eIcluaq/O5J17i1SWZwbEGminRbCK4Fdrkde7OzU5TmSkjgqbzdwdkyfkGZjYd0o8Py01iTA/fgr0SSJ/6M5DWJ9vWy3OurH7DdY1oDDOQ1ifb1stzrqx+w3WNaAwzkNYn29bLc66sfsN1jWgMM5DWJ9vWy3OurH7DdY1oDBhy9171jCizkdIEkQaJZ65kaNMqKkU7lzbd1NqjDTVkIxg7LgZ+ULtKDjzuUdu6syd7IPmIgITKmLNv1wD2WLYsrUnFLqtiSNgjOn1jfqeTlbV/saBGvuXVdGCacKV4aYqaMVS50xsGhTiu2v3HTjLlzsauw1rN6YPtvvhlgmsO7TtXiHJbmqvzuSde4tUlmcGxBpop0WwiuBXa5HXuzs1OU5kpI4Km83cHZMn5BmY2HdKPD8tNYkwP34K9Ekif+jOQ1ifb1stzrqx+w3WNaAwzkNYn29bLc66sfsN1jWgMM5DWJ9vWy3OurH7DdY1oDDOQ1ifb1stzrqx+w3WNaAwYcvde9Ywos5HSBJEGiWeuPUsbUHJpKe/lZXVHxVtEhm74Vmb72GnncNd838IB3IIneyD5iICEypizb9cA9li2qFI1+HTIENAlr4LpklPRa5W1f7GgRr7l1XRgmnCleGmKmjFUudMbBoU4rtr9x04y5c7GrsNazemD7b74ZYJrDu07V4hyW5qr87knXuLVJZnBsQaaKdFsIrgV2uR17s7NTlOZKSOCpvN3B2TJ+QZmNh3Sjw/LTWJMD9+CvRJIn/ozkNYn29bLc66sfsN1jWgMM5DWJ9vWy3OurH7DdY1oDDOQ1ifb1stzrqx+w3WNaAwzkNYn29bLc66sfsN1jWgMGHL3XvWMKLOR0gSRBolnropOFExGXcWng1JHMwo/LtbAJSI4B34me3SIkgL7JegVJ3sg+YiAhMqYs2/XAPZYtuO1OnZoJ5YeTuE/Z/Vd1X+VtX+xoEa+5dV0YJpwpXhpipoxVLnTGwaFOK7a/cdOMuXOxq7DWs3pg+2++GWCaw7tO1eIcluaq/O5J17i1SWZwbEGminRbCK4Fdrkde7OzU5TmSkjgqbzdwdkyfkGZjYd0o8Py01iTA/fgr0SSJ/6M5DWJ9vWy3OurH7DdY1oDDOQ1ifb1stzrqx+w3WNaAwzkNYn29bLc66sfsN1jWgMM5DWJ9vWy3OurH7DdY1oDBhy9171jCizkdIEkQaJZ65+oBCjMao+wBCTes/nLJHxlgU2WDeG11z6tjQlEiv3gSd7IPmIgITKmLNv1wD2WLbrUFCvFjpRP0q1cVBIwQSRlbV/saBGvuXVdGCacKV4aYqaMVS50xsGhTiu2v3HTjLlzsauw1rN6YPtvvhlgmsO7TtXiHJbmqvzuSde4tUlmcGxBpop0WwiuBXa5HXuzs1OU5kpI4Km83cHZMn5BmY2HdKPD8tNYkwP34K9Ekif+jOQ1ifb1stzrqx+w3WNaAwzkNYn29bLc66sfsN1jWgMM5DWJ9vWy3OurH7DdY1oDDOQ1ifb1stzrqx+w3WNaAwYcvde9Ywos5HSBJEGiWeuEQhQaCqGtWCDXuLdbc/ppmPxa2IJjfbYDDfs1s+kvFoneyD5iICEypizb9cA9li2fTow8CCyum3djwK6ZRq4V5W1f7GgRr7l1XRgmnCleGmKmjFUudMbBoU4rtr9x04y5c7GrsNazemD7b74ZYJrDu07V4hyW5qr87knXuLVJZnBsQaaKdFsIrgV2uR17s7NTlOZKSOCpvN3B2TJ+QZmNh3Sjw/LTWJMD9+CvRJIn/ozkNYn29bLc66sfsN1jWgMM5DWJ9vWy3OurH7DdY1oDDOQ1ifb1stzrqx+w3WNaAwzkNYn29bLc66sfsN1jWgM

Licensing Data-->
Software licensing service version: 6.0.6002.18005
Name: Windows(TM) Vista, HomePremium edition
Description: Windows Operating System - Vista, OEM_SLP channel
Activation ID: bffdc375-bbd5-499d-8ef1-4f37b61c895f
Application ID: 55c92734-d682-4d71-983e-d6ec3f16059f
Extended PID: 89583-00146-321-500141-02-1033-6001.0000-0572009
Installation ID: 017141611035990171085926158250806161379786912546308901
Processor Certificate URL: http://go.microsoft.com/fwlink/?LinkID=43473
Machine Certificate URL: http://go.microsoft.com/fwlink/?LinkID=43474
Use License URL: http://go.microsoft.com/fwlink/?LinkID=43476
Product Key Certificate URL: http://go.microsoft.com/fwlink/?LinkID=43475
Partial Product Key: DR9M6
License Status: Licensed

Windows Activation Technologies-->
N/A

HWID Data-->
HWID Hash Current: NgAAAAEAAQABAAEAAwACAAAAAwABAAEA6GGwXTZbXHT6WUamIgHAZfL0aBRwpm4lQB6sVkbK

OEM Activation 1.0 Data-->
N/A

OEM Activation 2.0 Data-->
BIOS valid for OA 2.0: yes
Windows marker version: 0x20000
OEMID and OEMTableID Consistent: yes
BIOS Information:
ACPI Table Name OEMID Value OEMTableID Value
APIC PTLTD APIC
FACP INTEL CRESTLNE
HPET INTEL CRESTLNE
BOOT PTLTD $SBFTBL$
MCFG INTEL CRESTLNE
SLIC GATEWA SYSTEM
SSDT PmRef CpuPm
smurph
Active Member
 
Posts: 2
Joined: September 22nd, 2011, 8:38 pm

Re: Please help with Google search malware

Unread postby deltalima » September 25th, 2011, 4:50 pm

Cracked Software

May I draw your attention to the topic: ALL USERS OF THIS FORUM MUST READ THIS FIRST, which you should have read before posting for help.

The section Use of "cracked" programs explains why we do not offer help for such computers.

This topic is now closed.
User avatar
deltalima
Admin/Teacher
Admin/Teacher
 
Posts: 7614
Joined: February 28th, 2009, 4:38 pm
Location: UK
Advertisement
Register to Remove


  • Similar Topics
    Replies
    Views
    Last post

Return to Infected? Virus, malware, adware, ransomware, oh my!



Who is online

Users browsing this forum: No registered users and 29 guests

Contact us:

Advertisements do not imply our endorsement of that product or service. Register to remove all ads. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks are the property of their respective owners.

Member site: UNITE Against Malware