Removed a fake Anti-Virus but iexplorer.exe*32 and google redirects are still happening and nothing I run/scan seems to find it.
Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org
Database version: 8039
Windows 6.1.7601 Service Pack 1
Internet Explorer 9.0.8112.16421
10/29/2011 8:03:22 AM
mbam-log-2011-10-29 (08-03-22).txt
Scan type: Quick scan
Objects scanned: 195192
Time elapsed: 1 minute(s), 45 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2011-10-29 07:51:17
Windows 6.1.7601 Service Pack 1
Running: 8igsdzwt.exe
---- Files - GMER 1.0.15 ----
File C:\Users\$ean-\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HNQZQPUW\down[2] 0 bytes
File C:\Users\$ean-\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HNQZQPUW\errorPageStrings[1] 0 bytes
File C:\Users\$ean-\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HNQZQPUW\set[1].gif 0 bytes
File C:\Users\$ean-\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HNQZQPUW\4232512637[1].htm 0 bytes
File C:\Users\$ean-\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PNTWH74G\get[1].js 0 bytes
File C:\Users\$ean-\AppData\Roaming\Microsoft\Windows\Cookies\I32FVP0V.txt 0 bytes
File C:\Users\$ean-\AppData\Roaming\Microsoft\Windows\Cookies\IGDVS5SM.txt 91 bytes
File C:\Users\$ean-\AppData\Roaming\Microsoft\Windows\Cookies\J6CU9I75.txt 0 bytes
File C:\Users\$ean-\AppData\Roaming\Microsoft\Windows\Cookies\0O80KOAJ.txt 0 bytes
File C:\Users\$ean-\AppData\Roaming\Microsoft\Windows\Cookies\1GEGF8LB.txt 0 bytes
File C:\Users\$ean-\AppData\Roaming\Microsoft\Windows\Cookies\22D7Y2W8.txt 716 bytes
File C:\Users\$ean-\AppData\Roaming\Microsoft\Windows\Cookies\BV3UP8L3.txt 0 bytes
File C:\Users\$ean-\AppData\Roaming\Microsoft\Windows\Cookies\DE4LC8FM.txt 0 bytes
File C:\Users\$ean-\AppData\Roaming\Microsoft\Windows\Cookies\G06JAH48.txt 242 bytes
File C:\Users\$ean-\AppData\Roaming\Microsoft\Windows\Cookies\N15T3UFE.txt 248 bytes
File C:\Users\$ean-\AppData\Roaming\Microsoft\Windows\Cookies\ODNJD4JH.txt 0 bytes
File C:\Users\$ean-\AppData\Roaming\Microsoft\Windows\Cookies\S8FAYCJW.txt 0 bytes
File C:\Users\$ean-\AppData\Roaming\Microsoft\Windows\Cookies\U8RPEBU5.txt 0 bytes
File C:\Users\$ean-\AppData\Roaming\Microsoft\Windows\Cookies\W251FXSE.txt 0 bytes
---- EOF - GMER 1.0.15 ----
.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_29
Run by $ean- at 7:51:29 on 2011-10-29
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.9207.6621 [GMT -7:00]
.
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\LSI SoftModem\agr64svc.exe
C:\Windows\SysWOW64\svchost.exe -k Akamai
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Core Temp\Core Temp.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Microsoft LifeCam\MSCamS64.exe
C:\Program Files (x86)\NVIDIA Corporation\nTune\nTuneService.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\NVIDIA Corporation\System Update\UpdateCenterService.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files (x86)\Linksys\Linksys Wireless Manager\LinksysWirelessManager64.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\WUDFHost.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\nmctxth.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\system32\DllHost.exe
C:\Users\$ean-\Desktop\TaskAssign.exe
C:\Program Files (x86)\Steam\Steam.exe
C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\taskhost.exe
C:\Users\$ean-\Desktop\Dungeon Defenders - Auto Fire.exe
C:\Windows\system32\svchost.exe -k SDRSVC
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe
C:\Windows\system32\REGSVR32.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.free-tv-video-online.me/internet/the_big_bang_theory/index.html
mWinlogon: Shell=explorer.exe
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
uRun: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
mRun: [amd_dc_opt] C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe
mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun: [nmctxth] "C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\nmctxth.exe"
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun: [LifeCam] "C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe"
mRun: [TkBellExe] "C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe" -osboot
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRunOnce: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: DhcpNameServer = 192.168.1.1
TCP: Interfaces\{43925531-C801-4D0D-81C4-EFF1E6227543} : DhcpNameServer = 192.168.1.1 68.87.76.182 68.87.78.134
TCP: Interfaces\{43925531-C801-4D0D-81C4-EFF1E6227543}\425616E6D2 : DhcpNameServer = 192.168.1.1 68.87.76.182 68.87.78.134
TCP: Interfaces\{46C0B5B8-D6E1-41DA-B196-FFCB61822923} : DhcpNameServer = 192.168.1.1 68.87.76.182 68.87.78.134
TCP: Interfaces\{8B3367B7-F7B6-424D-9A05-643E0AD7EC39} : DhcpNameServer = 192.168.1.1
Handler: pure-go - {4746C79A-2042-4332-8650-48966E44ABA8} - C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\puresp4.dll
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64: AcroIEHelperStub - No File
BHO-X64: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
mRun-x64: [amd_dc_opt] C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe
mRun-x64: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun-x64: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun-x64: [nmctxth] "C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\nmctxth.exe"
mRun-x64: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun-x64: [LifeCam] "C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe"
mRun-x64: [TkBellExe] "C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe" -osboot
mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRunOnce-x64: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
.
================= FIREFOX ===================
.
FF - ProfilePath -
.
============= SERVICES / DRIVERS ===============
.
R2 Akamai;Akamai NetSession Interface;C:\Windows\System32\svchost.exe -k Akamai [2009-7-13 20992]
R2 nvUpdatusService;NVIDIA Update Service Daemon;C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-4-29 2255464]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-8-3 379496]
R3 e1yexpress;Intel(R) Gigabit Network Connections Driver;C:\Windows\system32\DRIVERS\e1y60x64.sys --> C:\Windows\system32\DRIVERS\e1y60x64.sys [?]
R3 gwfilt64;gwfilt64;C:\Windows\system32\drivers\gwfilt64.sys --> C:\Windows\system32\drivers\gwfilt64.sys [?]
R3 MSHUSBVideo;NX6000/NX3000/VX2000/VX5000/VX5500/VX7000/Cinema Filter Driver;C:\Windows\system32\Drivers\nx6000.sys --> C:\Windows\system32\Drivers\nx6000.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S3 netr28ux;Linksys USB Wireless LAN Card Driver for Vista;C:\Windows\system32\DRIVERS\netr28ux.sys --> C:\Windows\system32\DRIVERS\netr28ux.sys [?]
S3 npggsvc;nProtect GameGuard Service;C:\Windows\system32\GameMon.des -service --> C:\Windows\system32\GameMon.des -service [?]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys --> C:\Windows\system32\Drivers\usbaapl64.sys [?]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
.
=============== Created Last 30 ================
.
2011-10-29 14:51:24 41272 ----a-w- C:\Windows\SysWow64\drivers\mbamswissarmy.sys
2011-10-29 05:49:20 25416 ----a-w- C:\Windows\System32\drivers\mbam.sys
2011-10-29 05:21:12 -------- d-----w- C:\Users\$ean-\AppData\Local\G DATA
2011-10-29 02:57:47 69000 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{589F25AC-2FE5-48C0-B06B-78012C39A2BF}\offreg.dll
2011-10-29 02:57:46 8570192 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{589F25AC-2FE5-48C0-B06B-78012C39A2BF}\mpengine.dll
2011-10-27 04:57:47 -------- d-----w- C:\Program Files\CCleaner
2011-10-27 04:44:38 -------- d-----w- C:\_OTL
2011-10-27 04:33:31 -------- d-----w- C:\Program Files (x86)\SecurityXploded
2011-10-27 03:06:03 -------- d-----w- C:\$WINDOWS.~LS
2011-10-16 18:35:51 -------- d-----w- C:\$RECYCLE.BIN
2011-10-16 17:51:06 -------- d-----w- C:\ComboFix
2011-10-16 17:16:11 98816 ----a-w- C:\Windows\sed.exe
2011-10-16 17:16:11 518144 ----a-w- C:\Windows\SWREG.exe
2011-10-16 17:16:11 256000 ----a-w- C:\Windows\PEV.exe
2011-10-16 17:16:11 208896 ----a-w- C:\Windows\MBR.exe
2011-10-15 17:34:38 39870 ----a-w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Riot Games\League of Legends\Updater.exe
2011-10-15 17:34:38 36864 ----a-w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Riot Games\League of Legends\Enigma Item Changer.exe
2011-10-15 14:54:31 3138048 ----a-w- C:\Windows\System32\win32k.sys
2011-10-15 14:53:46 75776 ----a-w- C:\Windows\SysWow64\psisrndr.ax
2011-10-15 14:53:46 613888 ----a-w- C:\Windows\System32\psisdecd.dll
2011-10-15 14:53:46 465408 ----a-w- C:\Windows\SysWow64\psisdecd.dll
2011-10-15 14:53:45 108032 ----a-w- C:\Windows\System32\psisrndr.ax
2011-10-15 14:52:54 861696 ----a-w- C:\Windows\System32\oleaut32.dll
2011-10-15 14:52:54 571904 ----a-w- C:\Windows\SysWow64\oleaut32.dll
2011-10-15 14:52:54 331776 ----a-w- C:\Windows\System32\oleacc.dll
2011-10-15 14:52:54 233472 ----a-w- C:\Windows\SysWow64\oleacc.dll
2011-10-04 05:14:07 -------- d-----w- C:\Users\$ean-\.frostwire5
.
==================== Find3M ====================
.
2011-10-18 14:07:03 414368 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2011-10-03 12:06:03 472808 ----a-w- C:\Windows\SysWow64\deployJava1.dll
2011-09-28 02:39:18 499712 ----a-w- C:\Windows\SysWow64\msvcp71.dll
2011-09-28 02:39:18 348160 ----a-w- C:\Windows\SysWow64\msvcr71.dll
2011-08-03 10:31:54 311912 ----a-w- C:\Windows\SysWow64\nvStreaming.exe
.
============= FINISH: 7:58:22.67 ===============
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft Windows 7 Home Premium
Boot Device: \Device\HarddiskVolume2
Install Date: 7/16/2010 7:59:39 AM
System Uptime: 10/28/2011 7:25:16 PM (12 hours ago)
.
Motherboard: Gateway | | TBGM01
Processor: Intel(R) Core(TM) i7 CPU 950 @ 3.07GHz | CPU 1 | 3068/133mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 917 GiB total, 634.705 GiB free.
D: is CDROM ()
E: is Removable
F: is Removable
G: is Removable
H: is Removable
.
==== Disabled Device Manager Items =============
.
Class GUID: {4d36e96f-e325-11ce-bfc1-08002be10318}
Description: Microsoft PS/2 Mouse
Device ID: ACPI\PNP0F03\4&6730480&0
Manufacturer: Microsoft
Name: Microsoft PS/2 Mouse
PNP Device ID: ACPI\PNP0F03\4&6730480&0
Service: i8042prt
.
==== System Restore Points ===================
.
RP220: 10/22/2011 8:05:44 AM - Windows Update
RP221: 10/26/2011 7:54:54 AM - Windows Update
RP222: 10/26/2011 8:11:38 AM - Windows Update
RP223: 10/26/2011 8:30:23 PM - Restore Operation
RP224: 10/26/2011 9:08:16 PM - Windows Modules Installer
RP225: 10/26/2011 9:24:14 PM - Windows Update
RP226: 10/26/2011 10:15:03 PM - Removed Bonjour
RP227: 10/26/2011 10:22:52 PM - Windows Update
RP228: 10/28/2011 7:39:48 AM - Installed Java(TM) 6 Update 29
RP229: 10/28/2011 8:06:50 PM - Installed DirectX
.
==== Installed Programs ======================
.
Adobe AIR
Adobe Flash Player 10 Plugin
Adobe Flash Player 11 ActiveX
Adobe Reader 9.4.6
Akamai NetSession Interface
Apple Application Support
Apple Software Update
Bandisoft MPEG-1 Decoder
Curse Client
Dragon Saga
DragonNest
Dual-Core Optimizer
Dungeon Defenders
EverQuest II
EverQuest: Escape to Norrath
Free Easy Burner V 4.1
Global Agenda
Guild Wars
Heroes of Newerth
Java Auto Updater
Java(TM) 6 Update 29
jZip
League of Legends
Left 4 Dead 2
Magicka - Demo
Malwarebytes' Anti-Malware version 1.51.2.1300
Microsoft Corporation
Microsoft Games for Windows - LIVE Redistributable
Microsoft Games for Windows Marketplace
Microsoft Silverlight
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2005 Redistributable - KB2467175
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30411
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft XNA Framework Redistributable 3.1
Mozilla Firefox (3.6.23)
Neverwinter Nights 2: Platinum
Nexon Game Manager
NVIDIA 3D Vision Controller Driver
NVIDIA Performance
NVIDIA PhysX
NVIDIA Stereoscopic 3D Driver
NVIDIA System Monitor
NVIDIA System Update
Pando Media Booster
Pure Networks Platform
QuickTime
RealNetworks - Microsoft Visual C++ 2008 Runtime
RealPlayer
Realtek High Definition Audio Driver
RealUpgrade 1.1
Security Update for Microsoft .NET Framework 4 Client Profile (KB2160841)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
Security Update for Microsoft .NET Framework 4 Extended (KB2416472)
Security Update for Microsoft .NET Framework 4 Extended (KB2487367)
Spotify
Steam
System Requirements Lab
Torchlight
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2473228)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft .NET Framework 4 Extended (KB2468871)
Update for Microsoft .NET Framework 4 Extended (KB2533523)
Upgrade Kit
VideoLAN VLC media player 0.8.6f
Warhammer® 40,000™: Dawn of War® II
Warhammer® 40,000™: Dawn of War® II – Chaos Rising™
World of Warcraft
.
==== Event Viewer Messages From Past Week ========
.
10/26/2011 9:47:25 PM, Error: Microsoft Antimalware [3002] -
10/26/2011 9:44:39 PM, Error: Service Control Manager [7034] - The NVIDIA Stereoscopic 3D Driver Service service terminated unexpectedly. It has done this 1 time(s).
10/26/2011 9:03:02 PM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Pure Networks Platform Service service to connect.
10/26/2011 9:03:02 PM, Error: Service Control Manager [7000] - The Pure Networks Platform Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
.
==== End Of File ===========================
Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org
Database version: 8039
Windows 6.1.7601 Service Pack 1
Internet Explorer 9.0.8112.16421
10/29/2011 8:03:22 AM
mbam-log-2011-10-29 (08-03-22).txt
Scan type: Quick scan
Objects scanned: 195192
Time elapsed: 1 minute(s), 45 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2011-10-29 07:51:17
Windows 6.1.7601 Service Pack 1
Running: 8igsdzwt.exe
---- Files - GMER 1.0.15 ----
File C:\Users\$ean-\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HNQZQPUW\down[2] 0 bytes
File C:\Users\$ean-\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HNQZQPUW\errorPageStrings[1] 0 bytes
File C:\Users\$ean-\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HNQZQPUW\set[1].gif 0 bytes
File C:\Users\$ean-\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HNQZQPUW\4232512637[1].htm 0 bytes
File C:\Users\$ean-\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PNTWH74G\get[1].js 0 bytes
File C:\Users\$ean-\AppData\Roaming\Microsoft\Windows\Cookies\I32FVP0V.txt 0 bytes
File C:\Users\$ean-\AppData\Roaming\Microsoft\Windows\Cookies\IGDVS5SM.txt 91 bytes
File C:\Users\$ean-\AppData\Roaming\Microsoft\Windows\Cookies\J6CU9I75.txt 0 bytes
File C:\Users\$ean-\AppData\Roaming\Microsoft\Windows\Cookies\0O80KOAJ.txt 0 bytes
File C:\Users\$ean-\AppData\Roaming\Microsoft\Windows\Cookies\1GEGF8LB.txt 0 bytes
File C:\Users\$ean-\AppData\Roaming\Microsoft\Windows\Cookies\22D7Y2W8.txt 716 bytes
File C:\Users\$ean-\AppData\Roaming\Microsoft\Windows\Cookies\BV3UP8L3.txt 0 bytes
File C:\Users\$ean-\AppData\Roaming\Microsoft\Windows\Cookies\DE4LC8FM.txt 0 bytes
File C:\Users\$ean-\AppData\Roaming\Microsoft\Windows\Cookies\G06JAH48.txt 242 bytes
File C:\Users\$ean-\AppData\Roaming\Microsoft\Windows\Cookies\N15T3UFE.txt 248 bytes
File C:\Users\$ean-\AppData\Roaming\Microsoft\Windows\Cookies\ODNJD4JH.txt 0 bytes
File C:\Users\$ean-\AppData\Roaming\Microsoft\Windows\Cookies\S8FAYCJW.txt 0 bytes
File C:\Users\$ean-\AppData\Roaming\Microsoft\Windows\Cookies\U8RPEBU5.txt 0 bytes
File C:\Users\$ean-\AppData\Roaming\Microsoft\Windows\Cookies\W251FXSE.txt 0 bytes
---- EOF - GMER 1.0.15 ----
.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_29
Run by $ean- at 7:51:29 on 2011-10-29
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.9207.6621 [GMT -7:00]
.
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\LSI SoftModem\agr64svc.exe
C:\Windows\SysWOW64\svchost.exe -k Akamai
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Core Temp\Core Temp.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Microsoft LifeCam\MSCamS64.exe
C:\Program Files (x86)\NVIDIA Corporation\nTune\nTuneService.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\NVIDIA Corporation\System Update\UpdateCenterService.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files (x86)\Linksys\Linksys Wireless Manager\LinksysWirelessManager64.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\WUDFHost.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\nmctxth.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\system32\DllHost.exe
C:\Users\$ean-\Desktop\TaskAssign.exe
C:\Program Files (x86)\Steam\Steam.exe
C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\taskhost.exe
C:\Users\$ean-\Desktop\Dungeon Defenders - Auto Fire.exe
C:\Windows\system32\svchost.exe -k SDRSVC
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe
C:\Windows\system32\REGSVR32.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.free-tv-video-online.me/internet/the_big_bang_theory/index.html
mWinlogon: Shell=explorer.exe
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
uRun: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
mRun: [amd_dc_opt] C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe
mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun: [nmctxth] "C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\nmctxth.exe"
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun: [LifeCam] "C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe"
mRun: [TkBellExe] "C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe" -osboot
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRunOnce: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: DhcpNameServer = 192.168.1.1
TCP: Interfaces\{43925531-C801-4D0D-81C4-EFF1E6227543} : DhcpNameServer = 192.168.1.1 68.87.76.182 68.87.78.134
TCP: Interfaces\{43925531-C801-4D0D-81C4-EFF1E6227543}\425616E6D2 : DhcpNameServer = 192.168.1.1 68.87.76.182 68.87.78.134
TCP: Interfaces\{46C0B5B8-D6E1-41DA-B196-FFCB61822923} : DhcpNameServer = 192.168.1.1 68.87.76.182 68.87.78.134
TCP: Interfaces\{8B3367B7-F7B6-424D-9A05-643E0AD7EC39} : DhcpNameServer = 192.168.1.1
Handler: pure-go - {4746C79A-2042-4332-8650-48966E44ABA8} - C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\puresp4.dll
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64: AcroIEHelperStub - No File
BHO-X64: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
mRun-x64: [amd_dc_opt] C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe
mRun-x64: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun-x64: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun-x64: [nmctxth] "C:\Program Files (x86)\Common Files\Pure Networks Shared\Platform\nmctxth.exe"
mRun-x64: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun-x64: [LifeCam] "C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe"
mRun-x64: [TkBellExe] "C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe" -osboot
mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRunOnce-x64: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
.
================= FIREFOX ===================
.
FF - ProfilePath -
.
============= SERVICES / DRIVERS ===============
.
R2 Akamai;Akamai NetSession Interface;C:\Windows\System32\svchost.exe -k Akamai [2009-7-13 20992]
R2 nvUpdatusService;NVIDIA Update Service Daemon;C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-4-29 2255464]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-8-3 379496]
R3 e1yexpress;Intel(R) Gigabit Network Connections Driver;C:\Windows\system32\DRIVERS\e1y60x64.sys --> C:\Windows\system32\DRIVERS\e1y60x64.sys [?]
R3 gwfilt64;gwfilt64;C:\Windows\system32\drivers\gwfilt64.sys --> C:\Windows\system32\drivers\gwfilt64.sys [?]
R3 MSHUSBVideo;NX6000/NX3000/VX2000/VX5000/VX5500/VX7000/Cinema Filter Driver;C:\Windows\system32\Drivers\nx6000.sys --> C:\Windows\system32\Drivers\nx6000.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S3 netr28ux;Linksys USB Wireless LAN Card Driver for Vista;C:\Windows\system32\DRIVERS\netr28ux.sys --> C:\Windows\system32\DRIVERS\netr28ux.sys [?]
S3 npggsvc;nProtect GameGuard Service;C:\Windows\system32\GameMon.des -service --> C:\Windows\system32\GameMon.des -service [?]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys --> C:\Windows\system32\Drivers\usbaapl64.sys [?]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
.
=============== Created Last 30 ================
.
2011-10-29 14:51:24 41272 ----a-w- C:\Windows\SysWow64\drivers\mbamswissarmy.sys
2011-10-29 05:49:20 25416 ----a-w- C:\Windows\System32\drivers\mbam.sys
2011-10-29 05:21:12 -------- d-----w- C:\Users\$ean-\AppData\Local\G DATA
2011-10-29 02:57:47 69000 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{589F25AC-2FE5-48C0-B06B-78012C39A2BF}\offreg.dll
2011-10-29 02:57:46 8570192 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{589F25AC-2FE5-48C0-B06B-78012C39A2BF}\mpengine.dll
2011-10-27 04:57:47 -------- d-----w- C:\Program Files\CCleaner
2011-10-27 04:44:38 -------- d-----w- C:\_OTL
2011-10-27 04:33:31 -------- d-----w- C:\Program Files (x86)\SecurityXploded
2011-10-27 03:06:03 -------- d-----w- C:\$WINDOWS.~LS
2011-10-16 18:35:51 -------- d-----w- C:\$RECYCLE.BIN
2011-10-16 17:51:06 -------- d-----w- C:\ComboFix
2011-10-16 17:16:11 98816 ----a-w- C:\Windows\sed.exe
2011-10-16 17:16:11 518144 ----a-w- C:\Windows\SWREG.exe
2011-10-16 17:16:11 256000 ----a-w- C:\Windows\PEV.exe
2011-10-16 17:16:11 208896 ----a-w- C:\Windows\MBR.exe
2011-10-15 17:34:38 39870 ----a-w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Riot Games\League of Legends\Updater.exe
2011-10-15 17:34:38 36864 ----a-w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Riot Games\League of Legends\Enigma Item Changer.exe
2011-10-15 14:54:31 3138048 ----a-w- C:\Windows\System32\win32k.sys
2011-10-15 14:53:46 75776 ----a-w- C:\Windows\SysWow64\psisrndr.ax
2011-10-15 14:53:46 613888 ----a-w- C:\Windows\System32\psisdecd.dll
2011-10-15 14:53:46 465408 ----a-w- C:\Windows\SysWow64\psisdecd.dll
2011-10-15 14:53:45 108032 ----a-w- C:\Windows\System32\psisrndr.ax
2011-10-15 14:52:54 861696 ----a-w- C:\Windows\System32\oleaut32.dll
2011-10-15 14:52:54 571904 ----a-w- C:\Windows\SysWow64\oleaut32.dll
2011-10-15 14:52:54 331776 ----a-w- C:\Windows\System32\oleacc.dll
2011-10-15 14:52:54 233472 ----a-w- C:\Windows\SysWow64\oleacc.dll
2011-10-04 05:14:07 -------- d-----w- C:\Users\$ean-\.frostwire5
.
==================== Find3M ====================
.
2011-10-18 14:07:03 414368 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2011-10-03 12:06:03 472808 ----a-w- C:\Windows\SysWow64\deployJava1.dll
2011-09-28 02:39:18 499712 ----a-w- C:\Windows\SysWow64\msvcp71.dll
2011-09-28 02:39:18 348160 ----a-w- C:\Windows\SysWow64\msvcr71.dll
2011-08-03 10:31:54 311912 ----a-w- C:\Windows\SysWow64\nvStreaming.exe
.
============= FINISH: 7:58:22.67 ===============
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft Windows 7 Home Premium
Boot Device: \Device\HarddiskVolume2
Install Date: 7/16/2010 7:59:39 AM
System Uptime: 10/28/2011 7:25:16 PM (12 hours ago)
.
Motherboard: Gateway | | TBGM01
Processor: Intel(R) Core(TM) i7 CPU 950 @ 3.07GHz | CPU 1 | 3068/133mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 917 GiB total, 634.705 GiB free.
D: is CDROM ()
E: is Removable
F: is Removable
G: is Removable
H: is Removable
.
==== Disabled Device Manager Items =============
.
Class GUID: {4d36e96f-e325-11ce-bfc1-08002be10318}
Description: Microsoft PS/2 Mouse
Device ID: ACPI\PNP0F03\4&6730480&0
Manufacturer: Microsoft
Name: Microsoft PS/2 Mouse
PNP Device ID: ACPI\PNP0F03\4&6730480&0
Service: i8042prt
.
==== System Restore Points ===================
.
RP220: 10/22/2011 8:05:44 AM - Windows Update
RP221: 10/26/2011 7:54:54 AM - Windows Update
RP222: 10/26/2011 8:11:38 AM - Windows Update
RP223: 10/26/2011 8:30:23 PM - Restore Operation
RP224: 10/26/2011 9:08:16 PM - Windows Modules Installer
RP225: 10/26/2011 9:24:14 PM - Windows Update
RP226: 10/26/2011 10:15:03 PM - Removed Bonjour
RP227: 10/26/2011 10:22:52 PM - Windows Update
RP228: 10/28/2011 7:39:48 AM - Installed Java(TM) 6 Update 29
RP229: 10/28/2011 8:06:50 PM - Installed DirectX
.
==== Installed Programs ======================
.
Adobe AIR
Adobe Flash Player 10 Plugin
Adobe Flash Player 11 ActiveX
Adobe Reader 9.4.6
Akamai NetSession Interface
Apple Application Support
Apple Software Update
Bandisoft MPEG-1 Decoder
Curse Client
Dragon Saga
DragonNest
Dual-Core Optimizer
Dungeon Defenders
EverQuest II
EverQuest: Escape to Norrath
Free Easy Burner V 4.1
Global Agenda
Guild Wars
Heroes of Newerth
Java Auto Updater
Java(TM) 6 Update 29
jZip
League of Legends
Left 4 Dead 2
Magicka - Demo
Malwarebytes' Anti-Malware version 1.51.2.1300
Microsoft Corporation
Microsoft Games for Windows - LIVE Redistributable
Microsoft Games for Windows Marketplace
Microsoft Silverlight
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2005 Redistributable - KB2467175
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30411
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft XNA Framework Redistributable 3.1
Mozilla Firefox (3.6.23)
Neverwinter Nights 2: Platinum
Nexon Game Manager
NVIDIA 3D Vision Controller Driver
NVIDIA Performance
NVIDIA PhysX
NVIDIA Stereoscopic 3D Driver
NVIDIA System Monitor
NVIDIA System Update
Pando Media Booster
Pure Networks Platform
QuickTime
RealNetworks - Microsoft Visual C++ 2008 Runtime
RealPlayer
Realtek High Definition Audio Driver
RealUpgrade 1.1
Security Update for Microsoft .NET Framework 4 Client Profile (KB2160841)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
Security Update for Microsoft .NET Framework 4 Extended (KB2416472)
Security Update for Microsoft .NET Framework 4 Extended (KB2487367)
Spotify
Steam
System Requirements Lab
Torchlight
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2473228)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft .NET Framework 4 Extended (KB2468871)
Update for Microsoft .NET Framework 4 Extended (KB2533523)
Upgrade Kit
VideoLAN VLC media player 0.8.6f
Warhammer® 40,000™: Dawn of War® II
Warhammer® 40,000™: Dawn of War® II – Chaos Rising™
World of Warcraft
.
==== Event Viewer Messages From Past Week ========
.
10/26/2011 9:47:25 PM, Error: Microsoft Antimalware [3002] -
10/26/2011 9:44:39 PM, Error: Service Control Manager [7034] - The NVIDIA Stereoscopic 3D Driver Service service terminated unexpectedly. It has done this 1 time(s).
10/26/2011 9:03:02 PM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Pure Networks Platform Service service to connect.
10/26/2011 9:03:02 PM, Error: Service Control Manager [7000] - The Pure Networks Platform Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
.
==== End Of File ===========================