So a few days ago i get 2 emails saying I have bought 11000 microsoft points on my windows live account. I hadn't (and its a very large amount of points) so i knew my pc had been compromised. After getting the account into the right channels at microsoft and passwords changed etc I ran a virus scan with my paid antivirus ESET smart security and nothing was found. Knowing that there must be something I went on this forum and read some posts and found one saying malwarebytes was a good thing to run too so I did and it found these two files :
c:\FPipe.exe (PUP.FPipe) -> Quarantined and deleted successfully.
c:\sl.exe (HackTool.Scanline) -> Quarantined and deleted successfully.
throughout this whole ordeal eset has regulaly been popping up firewall warnings that have said a remote computer is trying to access your computer and the advanced settings listed the file they were accessing as "system" here is a tiny part the log from ESET (tried to post the whole thing but your forum has a character limit on posts sorry):
25/06/2011 15:29:19 Detected covert channel exploit in ICMP packet 192.168.1.5 202.129.206.232 ICMP
25/06/2011 15:29:19 Detected covert channel exploit in ICMP packet 192.168.1.5 83.169.156.154 ICMP
25/06/2011 15:29:19 Detected covert channel exploit in ICMP packet 192.168.1.5 208.115.227.122 ICMP
25/06/2011 15:29:19 Detected covert channel exploit in ICMP packet 192.168.1.5 91.5.25.32 ICMP
25/06/2011 15:29:19 Detected covert channel exploit in ICMP packet 192.168.1.5 68.10.8.58 ICMP
so it started on the 25th of june it seems. After malwarebytes found the two files mentioned earlier I thought it would be ok, but since then i have had another 2 or 3 attempts to access my computer pop up on my firewall so I've come to you !
.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_24
Run by [removed] at 9:48:38 on 2011-09-08
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.44.1033.18.4030.1373 [GMT 1:00]
.
AV: ESET Smart Security 4.2 *Enabled/Updated* {77DEAFED-8149-104B-25A1-21771CA47CD1}
SP: ESET Smart Security 4.2 *Enabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: ESET Personal firewall *Enabled* {4FE52EC8-CB26-1113-0EFE-8842E2773BAA}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\IObit\Advanced SystemCare 4\ASCService.exe
C:\Windows\system32\svchost.exe -k apphost
C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
C:\Windows\system32\svchost.exe -k ftpsvc
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
C:\Windows\system32\STacSV64.exe
C:\Windows\system32\svchost.exe -k iissvcs
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskhost.exe
C:\Program Files\SigmaTel\C-Major Audio\WDM\sttray64.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\Saitek\SD6\Software\ProfilerU.exe
C:\Program Files\Saitek\SD6\Software\SaiMfd.exe
C:\Program Files (x86)\IObit\Advanced SystemCare 4\ASCTray.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Windows\system32\taskhost.exe
C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\notepad.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Windows\system32\NOTEPAD.EXE
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\calc.exe
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\Dwm.exe
C:\Program Files\Synergy\qsynergy.exe
C:\Program Files\Synergy\synergys.exe
C:\Program Files (x86)\TeamSpeak 3 Client\ts3client_win64.exe
C:\Program Files (x86)\EVEMon\EVEMon.exe
C:\Windows\system32\notepad.exe
C:\Windows\system32\calc.exe
C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
C:\Program Files (x86)\TeamSpeak 3 Client\ts3client_win64.exe
C:\Program Files (x86)\Steam\steam.exe
C:\Windows\SysWOW64\PnkBstrA.exe
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Program Files (x86)\IObit\Game Booster\gbtray.exe
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Program Files\NetLimiter 3\nlsvc.exe
C:\Program Files (x86)\IObit\Advanced SystemCare 4\Asc.exe
C:\Program Files (x86)\Mozilla Firefox 4.0 Beta 10\firefox.exe
C:\Program Files (x86)\Mozilla Firefox 4.0 Beta 10\plugin-container.exe
C:\PROGRA~2\Java\jre6\bin\jp2launcher.exe
C:\Program Files (x86)\Java\jre6\bin\java.exe
C:\Windows\system32\conhost.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe
C:\League of Legends\RADS\system\rads_user_kernel.exe
C:\League of Legends\RADS\projects\lol_launcher\releases\0.0.0.30\deploy\LoLLauncher.exe
C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe
C:\Windows\system32\svchost.exe -k SDRSVC
C:\Windows\SysWOW64\NOTEPAD.EXE
C:\Program Files (x86)\Mozilla Firefox 4.0 Beta 10\plugin-container.exe
C:\Program Files (x86)\VideoLAN\VLC\vlc.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uInternet Settings,ProxyOverride = *.local
mWinlogon: Userinit=userinit.exe,
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
uRun: [Advanced SystemCare 4] "C:\Program Files (x86)\IObit\Advanced SystemCare 4\ASCTray.exe"
uRun: [Google Update] "C:\Users\Sam Byard\AppData\Local\Google\Update\GoogleUpdate.exe" /c
uRun: [Facebook Update] "C:\Users\Sam Byard\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
uRun: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /nosplash /minimized
uRunOnce: [FlashPlayerUpdate] C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10p_Plugin.exe -update plugin
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun: [VirtualCloneDrive] "C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
mRun: [amd_dc_opt] C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe
mRun: [Malwarebytes' Anti-Malware (reboot)] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
mRunOnce: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
StartupFolder: C:\Users\SAMBYA~1\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\Bitcoin.lnk - C:\Program Files (x86)\Bitcoin\bitcoin.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\GAMERS~1.LNK - C:\Program Files (x86)\GamersFirst\LIVE!\Live.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
TCP: DhcpNameServer = 8.8.8.8 8.8.4.4
TCP: Interfaces\{3A462397-8C90-45B9-A551-61DF25626E96} : DhcpNameServer = 10.203.129.68 10.203.129.68
TCP: Interfaces\{B78E9E1B-9758-4EE3-827C-947214C7C1BF} : DhcpNameServer = 8.8.8.8 8.8.4.4
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Overwolf\SKYPE4~1.DLL
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64: AcroIEHelperStub - No File
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: Skype Browser Helper: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
BHO-X64: SkypeIEPluginBHO - No File
BHO-X64: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
mRun-x64: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun-x64: [VirtualCloneDrive] "C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
mRun-x64: [amd_dc_opt] C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe
mRun-x64: [Malwarebytes' Anti-Malware (reboot)] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
mRunOnce-x64: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Sam Byard\AppData\Roaming\Mozilla\Firefox\Profiles\jr85emb2.Samsb\
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
FF - plugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
FF - plugin: C:\Users\Sam Byard\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll
FF - plugin: C:\Users\Sam Byard\AppData\Local\Google\Update\1.3.21.65\npGoogleUpdate3.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
.
---- FIREFOX POLICIES ----
FF - user.js: browser.cache.memory.capacity - 65536
FF - user.js: browser.chrome.favicons - false
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.urlbar.autofill - true
FF - user.js: browser.xul.error_pages.enabled - true
FF - user.js: content.interrupt.parsing - true
FF - user.js: content.max.tokenizing.time - 3000000
FF - user.js: content.maxtextrun - 8191
FF - user.js: content.notify.backoffcount - 5
FF - user.js: content.notify.interval - 750000
FF - user.js: content.notify.ontimer - true
FF - user.js: content.notify.ontimer - true
FF - user.js: content.switch.threshold - 750000
FF - user.js: network.http.max-connections - 32
FF - user.js: network.http.max-connections-per-server - 8
FF - user.js: network.http.max-persistent-connections-per-proxy - 8
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: network.http.pipelining - true
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.proxy.pipelining - true
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: nglayout.initialpaint.delay - 0
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
.
============= SERVICES / DRIVERS ===============
.
R0 SmartDefragDriver;SmartDefragDriver;C:\Windows\system32\Drivers\SmartDefragDriver.sys --> C:\Windows\system32\Drivers\SmartDefragDriver.sys [?]
R1 nltdi;nltdi;C:\Program Files\NetLimiter 3\nltdi.sys [2011-3-21 88200]
R2 eamonm;eamonm;C:\Windows\system32\DRIVERS\eamonm.sys --> C:\Windows\system32\DRIVERS\eamonm.sys [?]
R2 epfwwfp;epfwwfp;C:\Windows\system32\DRIVERS\epfwwfp.sys --> C:\Windows\system32\DRIVERS\epfwwfp.sys [?]
R3 EuMusDesignVirtualAudioCableWdm;Virtual Audio Cable (WDM);C:\Windows\system32\DRIVERS\vrtaucbl.sys --> C:\Windows\system32\DRIVERS\vrtaucbl.sys [?]
R3 NLNdisMP;NLNdisMP;C:\Windows\system32\DRIVERS\nlndis.sys --> C:\Windows\system32\DRIVERS\nlndis.sys [?]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;C:\Windows\system32\drivers\nvhda64v.sys --> C:\Windows\system32\drivers\nvhda64v.sys [?]
R3 SaiK0728;SaiK0728;C:\Windows\system32\DRIVERS\SaiK0728.sys --> C:\Windows\system32\DRIVERS\SaiK0728.sys [?]
R3 SaiK0CFA;SaiK0CFA;C:\Windows\system32\DRIVERS\SaiK0CFA.sys --> C:\Windows\system32\DRIVERS\SaiK0CFA.sys [?]
R3 SaiU0CFA;SaiU0CFA;C:\Windows\system32\DRIVERS\SaiU0CFA.sys --> C:\Windows\system32\DRIVERS\SaiU0CFA.sys [?]
S3 jumi;%Jumi%;C:\Windows\system32\DRIVERS\jumi.sys --> C:\Windows\system32\DRIVERS\jumi.sys [?]
S3 Netaapl;Apple Mobile Device Ethernet Service;C:\Windows\system32\DRIVERS\netaapl64.sys --> C:\Windows\system32\DRIVERS\netaapl64.sys [?]
S3 NLNdisPT;NetLimiter Ndis Protocol Service;C:\Windows\system32\DRIVERS\nlndis.sys --> C:\Windows\system32\DRIVERS\nlndis.sys [?]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\system32\drivers\rdpvideominiport.sys --> C:\Windows\system32\drivers\rdpvideominiport.sys [?]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys --> C:\Windows\system32\Drivers\usbaapl64.sys [?]
S3 USBPNPA;USB PnP Sound Device Interface;C:\Windows\system32\drivers\CM10864.sys --> C:\Windows\system32\drivers\CM10864.sys [?]
.
=============== Created Last 30 ================
.
2011-09-07 19:05:40 -------- d-----w- C:\Users\Sam Byard\AppData\Roaming\Malwarebytes
2011-09-07 19:04:43 41272 ----a-w- C:\Windows\SysWow64\drivers\mbamswissarmy.sys
2011-09-07 19:04:42 -------- d-----w- C:\ProgramData\Malwarebytes
2011-09-07 19:04:39 25912 ----a-w- C:\Windows\System32\drivers\mbam.sys
2011-09-07 19:04:39 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2011-09-07 03:04:21 -------- d-----w- C:\Users\Sam Byard\AppData\Local\Chromium
2011-09-07 03:00:19 -------- d-----w- C:\Program Files (x86)\Overwolf
2011-09-07 02:49:54 -------- d-----w- C:\Users\Sam Byard\AppData\Local\Overwolf
2011-09-06 14:30:22 8862544 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{2A8B09EA-00AF-43DC-A617-62B576926352}\mpengine.dll
2011-09-05 23:59:52 -------- d-----w- C:\Program Files (x86)\Three Rings Design
2011-08-29 01:55:02 -------- d-----w- C:\Program Files (x86)\SystemRequirementsLab
2011-08-25 23:25:47 -------- d-----w- C:\Users\Sam Byard\AppData\Local\dxhr
2011-08-25 23:24:33 -------- d-----w- C:\Users\Sam Byard\AppData\Local\28050
2011-08-25 22:05:40 -------- d-----w- C:\Windows\SysWow64\Adobe
2011-08-24 01:42:33 2048 ----a-w- C:\Windows\SysWow64\tzres.dll
2011-08-24 01:42:33 2048 ----a-w- C:\Windows\System32\tzres.dll
2011-08-19 13:31:18 66728 ----a-w- C:\Windows\System32\drivers\vrtaucbl.sys
2011-08-19 13:31:18 -------- d-----w- C:\Program Files\Virtual Audio Cable
2011-08-19 13:06:29 -------- d-----w- C:\ProgramData\firebird
2011-08-19 13:06:26 -------- d-----w- C:\Users\Sam Byard\AppData\Local\SpacialAudio
2011-08-19 13:05:00 548864 ----a-w- C:\Windows\SysWow64\GDS32.DLL
2011-08-19 13:04:59 855552 ----a-w- C:\Windows\System32\GDS32.DLL
2011-08-19 13:04:00 -------- d-----w- C:\Program Files\Firebird
2011-08-19 13:03:35 -------- d-----w- C:\Program Files (x86)\SpacialAudio
2011-08-19 03:07:40 21073936 ----a-w- C:\vlc-1.1.11-win32.exe
2011-08-19 03:01:13 -------- d-----w- C:\Program Files (x86)\MSXML 4.0
2011-08-19 00:17:15 212992 ----a-w- C:\Windows\System32\odbctrac.dll
2011-08-19 00:17:15 163840 ----a-w- C:\Windows\System32\odbccp32.dll
2011-08-19 00:17:15 126976 ----a-w- C:\Program Files\Common Files\System\Ole DB\msdaosp.dll
2011-08-19 00:17:15 106496 ----a-w- C:\Windows\System32\odbccu32.dll
2011-08-19 00:17:15 106496 ----a-w- C:\Windows\System32\odbccr32.dll
2011-08-19 00:17:14 94208 ----a-w- C:\Program Files (x86)\Common Files\System\Ole DB\msdaosp.dll
2011-08-19 00:17:14 86016 ----a-w- C:\Windows\SysWow64\odbccu32.dll
2011-08-19 00:17:14 81920 ----a-w- C:\Windows\SysWow64\odbccr32.dll
2011-08-19 00:17:14 319488 ----a-w- C:\Windows\SysWow64\odbcjt32.dll
2011-08-19 00:17:14 163840 ----a-w- C:\Windows\SysWow64\odbctrac.dll
2011-08-19 00:17:14 122880 ----a-w- C:\Windows\SysWow64\odbccp32.dll
2011-08-18 22:12:32 -------- d-----w- C:\Program Files (x86)\Heroes of Newerth
2011-08-18 16:18:25 51472 ----a-w- C:\Program Files (x86)\Microsoft Games\Age of Empires Online\rmdll\Final\RandomMap.dll
2011-08-18 16:18:25 19216 ----a-w- C:\Program Files (x86)\Microsoft Games\Age of Empires Online\rmdll\Final\CLRBinder.dll
2011-08-18 16:18:25 13584 ----a-w- C:\Program Files (x86)\Microsoft Games\Age of Empires Online\rmdll\Final\RandomMapBinder.dll
2011-08-18 16:14:30 81998 ----a-w- C:\Program Files (x86)\Microsoft Games\Age of Empires Online\RockallDLL.dll
2011-08-18 16:14:29 746496 ----a-w- C:\Program Files (x86)\Microsoft Games\Age of Empires Online\granny2.dll
2011-08-18 16:14:27 139536 ----a-w- C:\Program Files (x86)\Microsoft Games\Age of Empires Online\eulax.dll
2011-08-18 16:14:25 173408 ----a-w- C:\Program Files (x86)\Microsoft Games\Age of Empires Online\pw32b.dll
2011-08-18 16:11:54 -------- d-----w- C:\Program Files (x86)\Microsoft Games
2011-08-18 16:10:23 -------- d-----w- C:\Windows\SysWow64\xlive
2011-08-18 16:10:16 -------- d-----w- C:\Program Files (x86)\Microsoft Games for Windows - LIVE
2011-08-18 00:03:19 -------- d-----w- C:\Users\Sam Byard\riotsGamesLogs
2011-08-17 17:23:31 -------- d-----w- C:\Users\Sam Byard\AppData\Local\Ubisoft Game Launcher
2011-08-16 00:17:16 -------- d-----w- C:\Users\Sam Byard\AppData\Roaming\mIRC
2011-08-16 00:17:16 -------- d-----w- C:\Program Files (x86)\mIRC
2011-08-14 18:35:00 -------- d-----w- C:\NVIDIA Corporation
2011-08-14 18:26:16 61544 ----a-w- C:\Windows\System32\nvshext.dll
2011-08-14 18:26:15 980072 ----a-w- C:\Windows\System32\nvvsvc.exe
2011-08-14 18:26:15 3021416 ----a-w- C:\Windows\System32\nvsvc64.dll
2011-08-14 18:26:14 836200 ----a-w- C:\Windows\System32\easyupdatusapiu64.dll
2011-08-14 18:26:14 6136936 ----a-w- C:\Windows\System32\nvcpl.dll
2011-08-14 18:26:14 117864 ----a-w- C:\Windows\System32\nvmctray.dll
2011-08-14 18:25:36 -------- d-----w- C:\ProgramData\NVIDIA Corporation
.
==================== Find3M ====================
.
2011-09-05 15:46:20 189248 ----a-w- C:\Windows\SysWow64\PnkBstrB.exe
2011-09-05 15:46:09 75136 ----a-w- C:\Windows\SysWow64\PnkBstrA.exe
2011-09-05 15:44:00 189248 ----a-w- C:\Windows\SysWow64\PnkBstrB.ex0
2011-08-16 23:48:20 466456 ----a-w- C:\Windows\System32\wrap_oal.dll
2011-08-16 23:48:20 444952 ----a-w- C:\Windows\SysWow64\wrap_oal.dll
2011-08-16 23:48:20 122904 ----a-w- C:\Windows\System32\OpenAL32.dll
2011-08-16 23:48:19 109080 ----a-w- C:\Windows\SysWow64\OpenAL32.dll
2011-08-03 02:31:54 311912 ----a-w- C:\Windows\SysWow64\nvStreaming.exe
2011-07-31 17:26:55 281656 ----a-w- C:\Windows\SysWow64\PnkBstrB.xtr
2011-07-22 05:42:23 2303488 ----a-w- C:\Windows\System32\jscript9.dll
2011-07-22 05:36:16 1389056 ----a-w- C:\Windows\System32\wininet.dll
2011-07-22 05:32:40 2382848 ----a-w- C:\Windows\System32\mshtml.tlb
2011-07-22 02:54:43 1797632 ----a-w- C:\Windows\SysWow64\jscript9.dll
2011-07-22 02:48:26 1126912 ----a-w- C:\Windows\SysWow64\wininet.dll
2011-07-22 02:44:36 2382848 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2011-07-16 05:41:50 362496 ----a-w- C:\Windows\System32\wow64win.dll
2011-07-16 05:41:49 243200 ----a-w- C:\Windows\System32\wow64.dll
2011-07-16 05:41:49 13312 ----a-w- C:\Windows\System32\wow64cpu.dll
2011-07-16 05:39:10 16384 ----a-w- C:\Windows\System32\ntvdm64.dll
2011-07-16 05:37:12 421888 ----a-w- C:\Windows\System32\KernelBase.dll
2011-07-16 04:29:19 14336 ----a-w- C:\Windows\SysWow64\ntvdm64.dll
2011-07-16 04:26:00 44032 ----a-w- C:\Windows\apppatch\acwow64.dll
2011-07-16 04:25:37 25600 ----a-w- C:\Windows\SysWow64\setup16.exe
2011-07-16 04:24:23 5120 ----a-w- C:\Windows\SysWow64\wow32.dll
2011-07-16 04:24:22 272384 ----a-w- C:\Windows\SysWow64\KernelBase.dll
2011-07-16 02:21:44 7680 ----a-w- C:\Windows\SysWow64\instnm.exe
2011-07-16 02:21:41 2048 ----a-w- C:\Windows\SysWow64\user.exe
2011-07-16 02:17:19 6144 ---ha-w- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
2011-07-16 02:17:19 4608 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
2011-07-16 02:17:19 3584 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
2011-07-16 02:17:19 3072 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
2011-07-09 02:46:28 288768 ----a-w- C:\Windows\System32\drivers\mrxsmb10.sys
2011-06-24 05:34:53 214528 ----a-w- C:\Windows\System32\winsrv.dll
2011-06-24 05:25:49 338432 ----a-w- C:\Windows\System32\conhost.exe
2011-06-23 05:43:12 5561216 ----a-w- C:\Windows\System32\ntoskrnl.exe
2011-06-23 04:33:57 3967872 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2011-06-23 04:33:57 3912576 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
2011-06-21 06:34:00 1923968 ----a-w- C:\Windows\System32\drivers\tcpip.sys
2011-06-11 03:07:25 3137536 ----a-w- C:\Windows\System32\win32k.sys
2011-06-11 00:15:38 93008 ----a-w- C:\Windows\System32\mfcm100u.dll
.
============= FINISH: 9:50:46.47 ===============
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft Windows 7 Ultimate
Boot Device: \Device\HarddiskVolume3
Install Date: 28/11/2010 03:45:57
System Uptime: 20/08/2011 23:13:24 (442 hours ago)
.
Motherboard: Dell Inc. | | 0TP406
Processor: Intel(R) Core(TM)2 Quad CPU Q6600 @ 2.40GHz | CPU | 2394/1066mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 283 GiB total, 0.904 GiB free.
D: is FIXED (NTFS) - 15 GiB total, 3.394 GiB free.
E: is CDROM ()
F: is FIXED (NTFS) - 466 GiB total, 120.295 GiB free.
G: is CDROM ()
.
==== Disabled Device Manager Items =============
.
Class GUID: {997b5d8d-c442-4f2e-baf3-9c8e671e9e21}
Description: XPS MiniView
Device ID: USB\VID_BEEF&PID_0006\AAAAAAAAAAAAAAAAAAAA
Manufacturer: Microsoft Co
Name: XPS MiniView
PNP Device ID: USB\VID_BEEF&PID_0006\AAAAAAAAAAAAAAAAAAAA
Service: WUDFRd
.
Class GUID: {36fc9e60-c465-11cf-8056-444553540000}
Description: Intel(R) ICH9 Family USB Universal Host Controller - 2938
Device ID: PCI\VEN_8086&DEV_2938&SUBSYS_02151028&REV_02\3&172E68DD&0&D1
Manufacturer: Intel
Name: Intel(R) ICH9 Family USB Universal Host Controller - 2938
PNP Device ID: PCI\VEN_8086&DEV_2938&SUBSYS_02151028&REV_02\3&172E68DD&0&D1
Service: usbuhci
.
==== System Restore Points ===================
.
No restore point in system.
.
==== Installed Programs ======================
.
3DMark 11
Adobe AIR
Adobe Flash Media Live Encoder 3.2
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader X (10.0.1)
Adobe Shockwave Player 11.6
Advanced SystemCare 4
Age of Empires Online
AnalogX NetStat Live
APB Reloaded
Apollo 37zz
Apple Application Support
Apple Software Update
ARMA 2
ARMA 2: British Armed Forces
ARMA 2: British Armed Forces - Data cache removal
ARMA 2: Operation Arrowhead
ARMA 2: Private Military Company
ARMA 2: Private Military Company - Data cache removal
µTorrent
BattlEye for OA Uninstall
BattlEye Uninstall
Bejeweled 3
Bitcoin
BOSS
Braid
Brink
Bullet Candy
Call of Duty: Black Ops
Call of Duty: Black Ops - Multiplayer
Cheat Engine 6.0
Click to Call with Skype
Cogs
Commander Keen Complete Pack
Crayon Physics Deluxe
Crysis® 2
Curse Client
D3DX10
Defense Grid: The Awakening
Deus Ex: Human Revolution
DivX Web Player
Dual-Core Optimizer
Duke Nukem Forever
Dungeons of Dredmor
EVEMon
EverQuest
EVGA OC Scanner 1.7.0
EVGA Precision 2.0.2
Facebook Video Calling 1.0.0.8177
foobar2000 v1.1.5
Fraps (remove only)
From Dust
Frozen Synapse
Futuremark SystemInfo
Game Booster 3
GamersFirst LIVE!
GoldWave v5.58
Google Chrome
Hacker Evolution
Hacker Evolution - Untold
Hacker Evolution Duality
Hammerfight
Harvest Massive Encounter
Heroes of Newerth
Impulse
Inkscape 0.48.0
jahPlayer
Java Auto Updater
Java(TM) 6 Update 22
Java(TM) 6 Update 24
League of Legends
League of Legends - ACE Client
Legend of Fae
Little SineGen 1.00
Live 8.2.2
Machinarium
Magicka
Malwarebytes' Anti-Malware version 1.51.1.1800
Microsoft Games for Windows - LIVE Redistributable
Microsoft Games for Windows Marketplace
Microsoft Silverlight
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
Microsoft XNA Framework Redistributable 3.1
Microsoft XNA Framework Redistributable 4.0
mIRC
MozBackup 1.4.10
Mozilla Firefox (3.6.12)
Mozilla Firefox 7.0 (x86 en-GB)
Mozilla Thunderbird (3.1.6)
MSI to redistribute MS VS2005 CRT libraries
MSVCRT
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
msxml4
Mumble 1.2.3
Nmap 5.51
NVIDIA 3D Vision Controller Driver
NVIDIA Alien vs. Triangles demo
NVIDIA Endless City demo
NVIDIA PhysX
NVIDIA Stereoscopic 3D Driver
Oblivion mod manager 1.1.12
Octoshape add-in for Adobe Flash Player
OpenAL
OpenLibraries
OpenOffice.org 3.3
Origin
Osmos
Overwolf
Pando Media Booster
PCMark 7
Pinnacle VideoSpin
PlayerScore
Portal 2
Privoxy (remove only)
PunkBuster Services
Puzzle Pirates
QuickTime
RecursiveWorld
Red Orchestra 2: Heroes of Stalingrad Beta
Revenge of the Titans
SAM Broadcaster v4
Security Update for Microsoft .NET Framework 4 Client Profile (KB2160841)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
Security Update for Microsoft .NET Framework 4 Extended (KB2416472)
Security Update for Microsoft .NET Framework 4 Extended (KB2487367)
SigmaTel Audio
SimCity 4 Deluxe
Sins of a Solar Empire
Sins of a Solar Empire - Diplomacy
Sins of a Solar Empire - Entrenchment
Skype™ 5.5
Smart Defrag 2
Spiral Knights
Steel Storm: Burning Retribution
Super Meat Boy
swMSM
Synergy
System Requirements Lab CYRI
Team Fortress 2
Terraria
The Elder Scrolls IV: Oblivion
Trillian
Two Worlds II Castle Defense Lite
Ubisoft Game Launcher
Unlocker 1.9.0
Update for Microsoft .NET Framework 4 Client Profile (KB2473228)
VC80CRTRedist - 8.0.50727.762
VirtualCloneDrive
VLC media player 1.1.11
VVVVVV
WebcamMax
Windows Live Communications Platform
Windows Live Essentials
Windows Live Installer
Windows Live Messenger
Windows Live Photo Common
Windows Live PIMT Platform
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live UX Platform
Windows Live UX Platform Language Pack
WinPcap 4.1.2
WinSCP 4.3.2
World of Logs Client
XSplit
.
==== Event Viewer Messages From Past Week ========
.
08/09/2011 03:49:35, Error: volsnap [36] - The shadow copies of volume C: were aborted because the shadow copy storage could not grow due to a user imposed limit.
05/09/2011 07:47:48, Error: Service Control Manager [7001] - The HomeGroup Provider service depends on the Function Discovery Resource Publication service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
01/09/2011 01:48:39, Error: Service Control Manager [7031] - The WLAN AutoConfig service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
01/09/2011 01:48:39, Error: Service Control Manager [7031] - The Windows Driver Foundation - User-mode Driver Framework service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
01/09/2011 01:48:39, Error: Service Control Manager [7031] - The Windows Audio Endpoint Builder service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
01/09/2011 01:48:39, Error: Service Control Manager [7031] - The Superfetch service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
01/09/2011 01:48:39, Error: Service Control Manager [7031] - The Program Compatibility Assistant Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
01/09/2011 01:48:39, Error: Service Control Manager [7031] - The Network Connections service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 100 milliseconds: Restart the service.
01/09/2011 01:48:39, Error: Service Control Manager [7031] - The Desktop Window Manager Session Manager service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
.
==== End Of File ===========================
c:\FPipe.exe (PUP.FPipe) -> Quarantined and deleted successfully.
c:\sl.exe (HackTool.Scanline) -> Quarantined and deleted successfully.
throughout this whole ordeal eset has regulaly been popping up firewall warnings that have said a remote computer is trying to access your computer and the advanced settings listed the file they were accessing as "system" here is a tiny part the log from ESET (tried to post the whole thing but your forum has a character limit on posts sorry):
25/06/2011 15:29:19 Detected covert channel exploit in ICMP packet 192.168.1.5 202.129.206.232 ICMP
25/06/2011 15:29:19 Detected covert channel exploit in ICMP packet 192.168.1.5 83.169.156.154 ICMP
25/06/2011 15:29:19 Detected covert channel exploit in ICMP packet 192.168.1.5 208.115.227.122 ICMP
25/06/2011 15:29:19 Detected covert channel exploit in ICMP packet 192.168.1.5 91.5.25.32 ICMP
25/06/2011 15:29:19 Detected covert channel exploit in ICMP packet 192.168.1.5 68.10.8.58 ICMP
so it started on the 25th of june it seems. After malwarebytes found the two files mentioned earlier I thought it would be ok, but since then i have had another 2 or 3 attempts to access my computer pop up on my firewall so I've come to you !
.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_24
Run by [removed] at 9:48:38 on 2011-09-08
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.44.1033.18.4030.1373 [GMT 1:00]
.
AV: ESET Smart Security 4.2 *Enabled/Updated* {77DEAFED-8149-104B-25A1-21771CA47CD1}
SP: ESET Smart Security 4.2 *Enabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: ESET Personal firewall *Enabled* {4FE52EC8-CB26-1113-0EFE-8842E2773BAA}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\IObit\Advanced SystemCare 4\ASCService.exe
C:\Windows\system32\svchost.exe -k apphost
C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
C:\Windows\system32\svchost.exe -k ftpsvc
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
C:\Windows\system32\STacSV64.exe
C:\Windows\system32\svchost.exe -k iissvcs
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskhost.exe
C:\Program Files\SigmaTel\C-Major Audio\WDM\sttray64.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\Saitek\SD6\Software\ProfilerU.exe
C:\Program Files\Saitek\SD6\Software\SaiMfd.exe
C:\Program Files (x86)\IObit\Advanced SystemCare 4\ASCTray.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Windows\system32\taskhost.exe
C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\notepad.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Windows\system32\NOTEPAD.EXE
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\calc.exe
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\Dwm.exe
C:\Program Files\Synergy\qsynergy.exe
C:\Program Files\Synergy\synergys.exe
C:\Program Files (x86)\TeamSpeak 3 Client\ts3client_win64.exe
C:\Program Files (x86)\EVEMon\EVEMon.exe
C:\Windows\system32\notepad.exe
C:\Windows\system32\calc.exe
C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
C:\Program Files (x86)\TeamSpeak 3 Client\ts3client_win64.exe
C:\Program Files (x86)\Steam\steam.exe
C:\Windows\SysWOW64\PnkBstrA.exe
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Program Files (x86)\IObit\Game Booster\gbtray.exe
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Program Files\NetLimiter 3\nlsvc.exe
C:\Program Files (x86)\IObit\Advanced SystemCare 4\Asc.exe
C:\Program Files (x86)\Mozilla Firefox 4.0 Beta 10\firefox.exe
C:\Program Files (x86)\Mozilla Firefox 4.0 Beta 10\plugin-container.exe
C:\PROGRA~2\Java\jre6\bin\jp2launcher.exe
C:\Program Files (x86)\Java\jre6\bin\java.exe
C:\Windows\system32\conhost.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe
C:\League of Legends\RADS\system\rads_user_kernel.exe
C:\League of Legends\RADS\projects\lol_launcher\releases\0.0.0.30\deploy\LoLLauncher.exe
C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe
C:\Windows\system32\svchost.exe -k SDRSVC
C:\Windows\SysWOW64\NOTEPAD.EXE
C:\Program Files (x86)\Mozilla Firefox 4.0 Beta 10\plugin-container.exe
C:\Program Files (x86)\VideoLAN\VLC\vlc.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uInternet Settings,ProxyOverride = *.local
mWinlogon: Userinit=userinit.exe,
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
uRun: [Advanced SystemCare 4] "C:\Program Files (x86)\IObit\Advanced SystemCare 4\ASCTray.exe"
uRun: [Google Update] "C:\Users\Sam Byard\AppData\Local\Google\Update\GoogleUpdate.exe" /c
uRun: [Facebook Update] "C:\Users\Sam Byard\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
uRun: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /nosplash /minimized
uRunOnce: [FlashPlayerUpdate] C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10p_Plugin.exe -update plugin
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun: [VirtualCloneDrive] "C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
mRun: [amd_dc_opt] C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe
mRun: [Malwarebytes' Anti-Malware (reboot)] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
mRunOnce: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
StartupFolder: C:\Users\SAMBYA~1\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\Bitcoin.lnk - C:\Program Files (x86)\Bitcoin\bitcoin.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\GAMERS~1.LNK - C:\Program Files (x86)\GamersFirst\LIVE!\Live.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
TCP: DhcpNameServer = 8.8.8.8 8.8.4.4
TCP: Interfaces\{3A462397-8C90-45B9-A551-61DF25626E96} : DhcpNameServer = 10.203.129.68 10.203.129.68
TCP: Interfaces\{B78E9E1B-9758-4EE3-827C-947214C7C1BF} : DhcpNameServer = 8.8.8.8 8.8.4.4
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Overwolf\SKYPE4~1.DLL
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64: AcroIEHelperStub - No File
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: Skype Browser Helper: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
BHO-X64: SkypeIEPluginBHO - No File
BHO-X64: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
mRun-x64: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun-x64: [VirtualCloneDrive] "C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
mRun-x64: [amd_dc_opt] C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe
mRun-x64: [Malwarebytes' Anti-Malware (reboot)] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
mRunOnce-x64: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Sam Byard\AppData\Roaming\Mozilla\Firefox\Profiles\jr85emb2.Samsb\
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
FF - plugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
FF - plugin: C:\Users\Sam Byard\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll
FF - plugin: C:\Users\Sam Byard\AppData\Local\Google\Update\1.3.21.65\npGoogleUpdate3.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
.
---- FIREFOX POLICIES ----
FF - user.js: browser.cache.memory.capacity - 65536
FF - user.js: browser.chrome.favicons - false
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.urlbar.autofill - true
FF - user.js: browser.xul.error_pages.enabled - true
FF - user.js: content.interrupt.parsing - true
FF - user.js: content.max.tokenizing.time - 3000000
FF - user.js: content.maxtextrun - 8191
FF - user.js: content.notify.backoffcount - 5
FF - user.js: content.notify.interval - 750000
FF - user.js: content.notify.ontimer - true
FF - user.js: content.notify.ontimer - true
FF - user.js: content.switch.threshold - 750000
FF - user.js: network.http.max-connections - 32
FF - user.js: network.http.max-connections-per-server - 8
FF - user.js: network.http.max-persistent-connections-per-proxy - 8
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: network.http.pipelining - true
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.proxy.pipelining - true
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: nglayout.initialpaint.delay - 0
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
.
============= SERVICES / DRIVERS ===============
.
R0 SmartDefragDriver;SmartDefragDriver;C:\Windows\system32\Drivers\SmartDefragDriver.sys --> C:\Windows\system32\Drivers\SmartDefragDriver.sys [?]
R1 nltdi;nltdi;C:\Program Files\NetLimiter 3\nltdi.sys [2011-3-21 88200]
R2 eamonm;eamonm;C:\Windows\system32\DRIVERS\eamonm.sys --> C:\Windows\system32\DRIVERS\eamonm.sys [?]
R2 epfwwfp;epfwwfp;C:\Windows\system32\DRIVERS\epfwwfp.sys --> C:\Windows\system32\DRIVERS\epfwwfp.sys [?]
R3 EuMusDesignVirtualAudioCableWdm;Virtual Audio Cable (WDM);C:\Windows\system32\DRIVERS\vrtaucbl.sys --> C:\Windows\system32\DRIVERS\vrtaucbl.sys [?]
R3 NLNdisMP;NLNdisMP;C:\Windows\system32\DRIVERS\nlndis.sys --> C:\Windows\system32\DRIVERS\nlndis.sys [?]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;C:\Windows\system32\drivers\nvhda64v.sys --> C:\Windows\system32\drivers\nvhda64v.sys [?]
R3 SaiK0728;SaiK0728;C:\Windows\system32\DRIVERS\SaiK0728.sys --> C:\Windows\system32\DRIVERS\SaiK0728.sys [?]
R3 SaiK0CFA;SaiK0CFA;C:\Windows\system32\DRIVERS\SaiK0CFA.sys --> C:\Windows\system32\DRIVERS\SaiK0CFA.sys [?]
R3 SaiU0CFA;SaiU0CFA;C:\Windows\system32\DRIVERS\SaiU0CFA.sys --> C:\Windows\system32\DRIVERS\SaiU0CFA.sys [?]
S3 jumi;%Jumi%;C:\Windows\system32\DRIVERS\jumi.sys --> C:\Windows\system32\DRIVERS\jumi.sys [?]
S3 Netaapl;Apple Mobile Device Ethernet Service;C:\Windows\system32\DRIVERS\netaapl64.sys --> C:\Windows\system32\DRIVERS\netaapl64.sys [?]
S3 NLNdisPT;NetLimiter Ndis Protocol Service;C:\Windows\system32\DRIVERS\nlndis.sys --> C:\Windows\system32\DRIVERS\nlndis.sys [?]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\system32\drivers\rdpvideominiport.sys --> C:\Windows\system32\drivers\rdpvideominiport.sys [?]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys --> C:\Windows\system32\Drivers\usbaapl64.sys [?]
S3 USBPNPA;USB PnP Sound Device Interface;C:\Windows\system32\drivers\CM10864.sys --> C:\Windows\system32\drivers\CM10864.sys [?]
.
=============== Created Last 30 ================
.
2011-09-07 19:05:40 -------- d-----w- C:\Users\Sam Byard\AppData\Roaming\Malwarebytes
2011-09-07 19:04:43 41272 ----a-w- C:\Windows\SysWow64\drivers\mbamswissarmy.sys
2011-09-07 19:04:42 -------- d-----w- C:\ProgramData\Malwarebytes
2011-09-07 19:04:39 25912 ----a-w- C:\Windows\System32\drivers\mbam.sys
2011-09-07 19:04:39 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2011-09-07 03:04:21 -------- d-----w- C:\Users\Sam Byard\AppData\Local\Chromium
2011-09-07 03:00:19 -------- d-----w- C:\Program Files (x86)\Overwolf
2011-09-07 02:49:54 -------- d-----w- C:\Users\Sam Byard\AppData\Local\Overwolf
2011-09-06 14:30:22 8862544 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{2A8B09EA-00AF-43DC-A617-62B576926352}\mpengine.dll
2011-09-05 23:59:52 -------- d-----w- C:\Program Files (x86)\Three Rings Design
2011-08-29 01:55:02 -------- d-----w- C:\Program Files (x86)\SystemRequirementsLab
2011-08-25 23:25:47 -------- d-----w- C:\Users\Sam Byard\AppData\Local\dxhr
2011-08-25 23:24:33 -------- d-----w- C:\Users\Sam Byard\AppData\Local\28050
2011-08-25 22:05:40 -------- d-----w- C:\Windows\SysWow64\Adobe
2011-08-24 01:42:33 2048 ----a-w- C:\Windows\SysWow64\tzres.dll
2011-08-24 01:42:33 2048 ----a-w- C:\Windows\System32\tzres.dll
2011-08-19 13:31:18 66728 ----a-w- C:\Windows\System32\drivers\vrtaucbl.sys
2011-08-19 13:31:18 -------- d-----w- C:\Program Files\Virtual Audio Cable
2011-08-19 13:06:29 -------- d-----w- C:\ProgramData\firebird
2011-08-19 13:06:26 -------- d-----w- C:\Users\Sam Byard\AppData\Local\SpacialAudio
2011-08-19 13:05:00 548864 ----a-w- C:\Windows\SysWow64\GDS32.DLL
2011-08-19 13:04:59 855552 ----a-w- C:\Windows\System32\GDS32.DLL
2011-08-19 13:04:00 -------- d-----w- C:\Program Files\Firebird
2011-08-19 13:03:35 -------- d-----w- C:\Program Files (x86)\SpacialAudio
2011-08-19 03:07:40 21073936 ----a-w- C:\vlc-1.1.11-win32.exe
2011-08-19 03:01:13 -------- d-----w- C:\Program Files (x86)\MSXML 4.0
2011-08-19 00:17:15 212992 ----a-w- C:\Windows\System32\odbctrac.dll
2011-08-19 00:17:15 163840 ----a-w- C:\Windows\System32\odbccp32.dll
2011-08-19 00:17:15 126976 ----a-w- C:\Program Files\Common Files\System\Ole DB\msdaosp.dll
2011-08-19 00:17:15 106496 ----a-w- C:\Windows\System32\odbccu32.dll
2011-08-19 00:17:15 106496 ----a-w- C:\Windows\System32\odbccr32.dll
2011-08-19 00:17:14 94208 ----a-w- C:\Program Files (x86)\Common Files\System\Ole DB\msdaosp.dll
2011-08-19 00:17:14 86016 ----a-w- C:\Windows\SysWow64\odbccu32.dll
2011-08-19 00:17:14 81920 ----a-w- C:\Windows\SysWow64\odbccr32.dll
2011-08-19 00:17:14 319488 ----a-w- C:\Windows\SysWow64\odbcjt32.dll
2011-08-19 00:17:14 163840 ----a-w- C:\Windows\SysWow64\odbctrac.dll
2011-08-19 00:17:14 122880 ----a-w- C:\Windows\SysWow64\odbccp32.dll
2011-08-18 22:12:32 -------- d-----w- C:\Program Files (x86)\Heroes of Newerth
2011-08-18 16:18:25 51472 ----a-w- C:\Program Files (x86)\Microsoft Games\Age of Empires Online\rmdll\Final\RandomMap.dll
2011-08-18 16:18:25 19216 ----a-w- C:\Program Files (x86)\Microsoft Games\Age of Empires Online\rmdll\Final\CLRBinder.dll
2011-08-18 16:18:25 13584 ----a-w- C:\Program Files (x86)\Microsoft Games\Age of Empires Online\rmdll\Final\RandomMapBinder.dll
2011-08-18 16:14:30 81998 ----a-w- C:\Program Files (x86)\Microsoft Games\Age of Empires Online\RockallDLL.dll
2011-08-18 16:14:29 746496 ----a-w- C:\Program Files (x86)\Microsoft Games\Age of Empires Online\granny2.dll
2011-08-18 16:14:27 139536 ----a-w- C:\Program Files (x86)\Microsoft Games\Age of Empires Online\eulax.dll
2011-08-18 16:14:25 173408 ----a-w- C:\Program Files (x86)\Microsoft Games\Age of Empires Online\pw32b.dll
2011-08-18 16:11:54 -------- d-----w- C:\Program Files (x86)\Microsoft Games
2011-08-18 16:10:23 -------- d-----w- C:\Windows\SysWow64\xlive
2011-08-18 16:10:16 -------- d-----w- C:\Program Files (x86)\Microsoft Games for Windows - LIVE
2011-08-18 00:03:19 -------- d-----w- C:\Users\Sam Byard\riotsGamesLogs
2011-08-17 17:23:31 -------- d-----w- C:\Users\Sam Byard\AppData\Local\Ubisoft Game Launcher
2011-08-16 00:17:16 -------- d-----w- C:\Users\Sam Byard\AppData\Roaming\mIRC
2011-08-16 00:17:16 -------- d-----w- C:\Program Files (x86)\mIRC
2011-08-14 18:35:00 -------- d-----w- C:\NVIDIA Corporation
2011-08-14 18:26:16 61544 ----a-w- C:\Windows\System32\nvshext.dll
2011-08-14 18:26:15 980072 ----a-w- C:\Windows\System32\nvvsvc.exe
2011-08-14 18:26:15 3021416 ----a-w- C:\Windows\System32\nvsvc64.dll
2011-08-14 18:26:14 836200 ----a-w- C:\Windows\System32\easyupdatusapiu64.dll
2011-08-14 18:26:14 6136936 ----a-w- C:\Windows\System32\nvcpl.dll
2011-08-14 18:26:14 117864 ----a-w- C:\Windows\System32\nvmctray.dll
2011-08-14 18:25:36 -------- d-----w- C:\ProgramData\NVIDIA Corporation
.
==================== Find3M ====================
.
2011-09-05 15:46:20 189248 ----a-w- C:\Windows\SysWow64\PnkBstrB.exe
2011-09-05 15:46:09 75136 ----a-w- C:\Windows\SysWow64\PnkBstrA.exe
2011-09-05 15:44:00 189248 ----a-w- C:\Windows\SysWow64\PnkBstrB.ex0
2011-08-16 23:48:20 466456 ----a-w- C:\Windows\System32\wrap_oal.dll
2011-08-16 23:48:20 444952 ----a-w- C:\Windows\SysWow64\wrap_oal.dll
2011-08-16 23:48:20 122904 ----a-w- C:\Windows\System32\OpenAL32.dll
2011-08-16 23:48:19 109080 ----a-w- C:\Windows\SysWow64\OpenAL32.dll
2011-08-03 02:31:54 311912 ----a-w- C:\Windows\SysWow64\nvStreaming.exe
2011-07-31 17:26:55 281656 ----a-w- C:\Windows\SysWow64\PnkBstrB.xtr
2011-07-22 05:42:23 2303488 ----a-w- C:\Windows\System32\jscript9.dll
2011-07-22 05:36:16 1389056 ----a-w- C:\Windows\System32\wininet.dll
2011-07-22 05:32:40 2382848 ----a-w- C:\Windows\System32\mshtml.tlb
2011-07-22 02:54:43 1797632 ----a-w- C:\Windows\SysWow64\jscript9.dll
2011-07-22 02:48:26 1126912 ----a-w- C:\Windows\SysWow64\wininet.dll
2011-07-22 02:44:36 2382848 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2011-07-16 05:41:50 362496 ----a-w- C:\Windows\System32\wow64win.dll
2011-07-16 05:41:49 243200 ----a-w- C:\Windows\System32\wow64.dll
2011-07-16 05:41:49 13312 ----a-w- C:\Windows\System32\wow64cpu.dll
2011-07-16 05:39:10 16384 ----a-w- C:\Windows\System32\ntvdm64.dll
2011-07-16 05:37:12 421888 ----a-w- C:\Windows\System32\KernelBase.dll
2011-07-16 04:29:19 14336 ----a-w- C:\Windows\SysWow64\ntvdm64.dll
2011-07-16 04:26:00 44032 ----a-w- C:\Windows\apppatch\acwow64.dll
2011-07-16 04:25:37 25600 ----a-w- C:\Windows\SysWow64\setup16.exe
2011-07-16 04:24:23 5120 ----a-w- C:\Windows\SysWow64\wow32.dll
2011-07-16 04:24:22 272384 ----a-w- C:\Windows\SysWow64\KernelBase.dll
2011-07-16 02:21:44 7680 ----a-w- C:\Windows\SysWow64\instnm.exe
2011-07-16 02:21:41 2048 ----a-w- C:\Windows\SysWow64\user.exe
2011-07-16 02:17:19 6144 ---ha-w- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
2011-07-16 02:17:19 4608 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
2011-07-16 02:17:19 3584 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
2011-07-16 02:17:19 3072 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
2011-07-09 02:46:28 288768 ----a-w- C:\Windows\System32\drivers\mrxsmb10.sys
2011-06-24 05:34:53 214528 ----a-w- C:\Windows\System32\winsrv.dll
2011-06-24 05:25:49 338432 ----a-w- C:\Windows\System32\conhost.exe
2011-06-23 05:43:12 5561216 ----a-w- C:\Windows\System32\ntoskrnl.exe
2011-06-23 04:33:57 3967872 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2011-06-23 04:33:57 3912576 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
2011-06-21 06:34:00 1923968 ----a-w- C:\Windows\System32\drivers\tcpip.sys
2011-06-11 03:07:25 3137536 ----a-w- C:\Windows\System32\win32k.sys
2011-06-11 00:15:38 93008 ----a-w- C:\Windows\System32\mfcm100u.dll
.
============= FINISH: 9:50:46.47 ===============
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft Windows 7 Ultimate
Boot Device: \Device\HarddiskVolume3
Install Date: 28/11/2010 03:45:57
System Uptime: 20/08/2011 23:13:24 (442 hours ago)
.
Motherboard: Dell Inc. | | 0TP406
Processor: Intel(R) Core(TM)2 Quad CPU Q6600 @ 2.40GHz | CPU | 2394/1066mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 283 GiB total, 0.904 GiB free.
D: is FIXED (NTFS) - 15 GiB total, 3.394 GiB free.
E: is CDROM ()
F: is FIXED (NTFS) - 466 GiB total, 120.295 GiB free.
G: is CDROM ()
.
==== Disabled Device Manager Items =============
.
Class GUID: {997b5d8d-c442-4f2e-baf3-9c8e671e9e21}
Description: XPS MiniView
Device ID: USB\VID_BEEF&PID_0006\AAAAAAAAAAAAAAAAAAAA
Manufacturer: Microsoft Co
Name: XPS MiniView
PNP Device ID: USB\VID_BEEF&PID_0006\AAAAAAAAAAAAAAAAAAAA
Service: WUDFRd
.
Class GUID: {36fc9e60-c465-11cf-8056-444553540000}
Description: Intel(R) ICH9 Family USB Universal Host Controller - 2938
Device ID: PCI\VEN_8086&DEV_2938&SUBSYS_02151028&REV_02\3&172E68DD&0&D1
Manufacturer: Intel
Name: Intel(R) ICH9 Family USB Universal Host Controller - 2938
PNP Device ID: PCI\VEN_8086&DEV_2938&SUBSYS_02151028&REV_02\3&172E68DD&0&D1
Service: usbuhci
.
==== System Restore Points ===================
.
No restore point in system.
.
==== Installed Programs ======================
.
3DMark 11
Adobe AIR
Adobe Flash Media Live Encoder 3.2
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader X (10.0.1)
Adobe Shockwave Player 11.6
Advanced SystemCare 4
Age of Empires Online
AnalogX NetStat Live
APB Reloaded
Apollo 37zz
Apple Application Support
Apple Software Update
ARMA 2
ARMA 2: British Armed Forces
ARMA 2: British Armed Forces - Data cache removal
ARMA 2: Operation Arrowhead
ARMA 2: Private Military Company
ARMA 2: Private Military Company - Data cache removal
µTorrent
BattlEye for OA Uninstall
BattlEye Uninstall
Bejeweled 3
Bitcoin
BOSS
Braid
Brink
Bullet Candy
Call of Duty: Black Ops
Call of Duty: Black Ops - Multiplayer
Cheat Engine 6.0
Click to Call with Skype
Cogs
Commander Keen Complete Pack
Crayon Physics Deluxe
Crysis® 2
Curse Client
D3DX10
Defense Grid: The Awakening
Deus Ex: Human Revolution
DivX Web Player
Dual-Core Optimizer
Duke Nukem Forever
Dungeons of Dredmor
EVEMon
EverQuest
EVGA OC Scanner 1.7.0
EVGA Precision 2.0.2
Facebook Video Calling 1.0.0.8177
foobar2000 v1.1.5
Fraps (remove only)
From Dust
Frozen Synapse
Futuremark SystemInfo
Game Booster 3
GamersFirst LIVE!
GoldWave v5.58
Google Chrome
Hacker Evolution
Hacker Evolution - Untold
Hacker Evolution Duality
Hammerfight
Harvest Massive Encounter
Heroes of Newerth
Impulse
Inkscape 0.48.0
jahPlayer
Java Auto Updater
Java(TM) 6 Update 22
Java(TM) 6 Update 24
League of Legends
League of Legends - ACE Client
Legend of Fae
Little SineGen 1.00
Live 8.2.2
Machinarium
Magicka
Malwarebytes' Anti-Malware version 1.51.1.1800
Microsoft Games for Windows - LIVE Redistributable
Microsoft Games for Windows Marketplace
Microsoft Silverlight
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
Microsoft XNA Framework Redistributable 3.1
Microsoft XNA Framework Redistributable 4.0
mIRC
MozBackup 1.4.10
Mozilla Firefox (3.6.12)
Mozilla Firefox 7.0 (x86 en-GB)
Mozilla Thunderbird (3.1.6)
MSI to redistribute MS VS2005 CRT libraries
MSVCRT
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
msxml4
Mumble 1.2.3
Nmap 5.51
NVIDIA 3D Vision Controller Driver
NVIDIA Alien vs. Triangles demo
NVIDIA Endless City demo
NVIDIA PhysX
NVIDIA Stereoscopic 3D Driver
Oblivion mod manager 1.1.12
Octoshape add-in for Adobe Flash Player
OpenAL
OpenLibraries
OpenOffice.org 3.3
Origin
Osmos
Overwolf
Pando Media Booster
PCMark 7
Pinnacle VideoSpin
PlayerScore
Portal 2
Privoxy (remove only)
PunkBuster Services
Puzzle Pirates
QuickTime
RecursiveWorld
Red Orchestra 2: Heroes of Stalingrad Beta
Revenge of the Titans
SAM Broadcaster v4
Security Update for Microsoft .NET Framework 4 Client Profile (KB2160841)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
Security Update for Microsoft .NET Framework 4 Extended (KB2416472)
Security Update for Microsoft .NET Framework 4 Extended (KB2487367)
SigmaTel Audio
SimCity 4 Deluxe
Sins of a Solar Empire
Sins of a Solar Empire - Diplomacy
Sins of a Solar Empire - Entrenchment
Skype™ 5.5
Smart Defrag 2
Spiral Knights
Steel Storm: Burning Retribution
Super Meat Boy
swMSM
Synergy
System Requirements Lab CYRI
Team Fortress 2
Terraria
The Elder Scrolls IV: Oblivion
Trillian
Two Worlds II Castle Defense Lite
Ubisoft Game Launcher
Unlocker 1.9.0
Update for Microsoft .NET Framework 4 Client Profile (KB2473228)
VC80CRTRedist - 8.0.50727.762
VirtualCloneDrive
VLC media player 1.1.11
VVVVVV
WebcamMax
Windows Live Communications Platform
Windows Live Essentials
Windows Live Installer
Windows Live Messenger
Windows Live Photo Common
Windows Live PIMT Platform
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live UX Platform
Windows Live UX Platform Language Pack
WinPcap 4.1.2
WinSCP 4.3.2
World of Logs Client
XSplit
.
==== Event Viewer Messages From Past Week ========
.
08/09/2011 03:49:35, Error: volsnap [36] - The shadow copies of volume C: were aborted because the shadow copy storage could not grow due to a user imposed limit.
05/09/2011 07:47:48, Error: Service Control Manager [7001] - The HomeGroup Provider service depends on the Function Discovery Resource Publication service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
01/09/2011 01:48:39, Error: Service Control Manager [7031] - The WLAN AutoConfig service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
01/09/2011 01:48:39, Error: Service Control Manager [7031] - The Windows Driver Foundation - User-mode Driver Framework service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
01/09/2011 01:48:39, Error: Service Control Manager [7031] - The Windows Audio Endpoint Builder service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
01/09/2011 01:48:39, Error: Service Control Manager [7031] - The Superfetch service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
01/09/2011 01:48:39, Error: Service Control Manager [7031] - The Program Compatibility Assistant Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
01/09/2011 01:48:39, Error: Service Control Manager [7031] - The Network Connections service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 100 milliseconds: Restart the service.
01/09/2011 01:48:39, Error: Service Control Manager [7031] - The Desktop Window Manager Session Manager service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
.
==== End Of File ===========================