This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Start up problems

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Recently my computer has been giving me alot of problems starting up. It will freeze half way through the process and eventually I have to shut it down manually which is something I really hate to do. I've run MBAM scans, Avira premium scans, and Kaspersky scans with nothing showing up. I use RUbotted to check for bots and that is clear. Online Armor scans show nothing also but there is defenately something very wrong with my system. Here is the Hijack this log for you to see.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:12:37 PM, on 3/6/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Tall Emu\Online Armor\oasrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\Avira Premium Security Suite\sched.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Intel\PROSetWired\NCS\PROSet\PRONoMgr.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\Returnil\Returnil.exe
C:\Program Files\Trend Micro\RUBotted\TMRUBottedTray.exe
C:\Program Files\Avira\Avira Premium Security Suite\avgnt.exe
C:\Program Files\Tall Emu\Online Armor\oaui.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Sandboxie\SbieCtrl.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Calibrize\CalibrizeResume.exe
C:\PROGRA~1\TITANB~1\TITANB~2.EXE
C:\Program Files\filehippo.com\UpdateChecker.exe
C:\Program Files\Secunia\PSI\psi.exe
C:\Program Files\Avira\Avira Premium Security Suite\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Avira\Avira Premium Security Suite\avesvc.exe
C:\Program Files\PrevxCSI\prevxcsi.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Tall Emu\Online Armor\oahlp.exe
C:\Program Files\Tall Emu\Online Armor\oacat.exe
C:\Program Files\PrevxCSI\prevxcsi.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Trend Micro\RUBotted\TMRUBotted.exe
C:\Program Files\Sandboxie\SbieSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Avira\Avira Premium Security Suite\avmailc.exe
C:\Program Files\Avira\Avira Premium Security Suite\AVWEBGRD.EXE
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: PDF-XChange Viewer IE-Plugin - {C5D07EB6-BBCE-4DAE-ACBB-D13A8D28CB1F} - C:\Program Files\Tracker Software\PDF-XChange Viewer\pdf-viewer\PDFXCviewIEPlugin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [PRONoMgrWired] "C:\Program Files\Intel\PROSetWired\NCS\PROSet\PRONoMgr.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [Rvsystem] C:\PROGRA~1\Returnil\Returnil.exe
O4 - HKLM\..\Run: [TMRUBottedTray] "C:\Program Files\Trend Micro\RUBotted\TMRUBottedTray.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\Avira Premium Security Suite\avgnt.exe" /min
O4 - HKLM\..\Run: [@OnlineArmor GUI] "C:\Program Files\Tall Emu\Online Armor\oaui.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [SandboxieControl] "C:\Program Files\Sandboxie\SbieCtrl.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [CGFLoader] C:\Program Files\Calibrize\CalibrizeLoader.exe
O4 - HKCU\..\Run: [CalibrizeResume] C:\Program Files\Calibrize\CalibrizeResume.exe
O4 - HKCU\..\Run: [Titan Backup] "C:\PROGRA~1\TITANB~1\TITANB~2.EXE" /startup
O4 - HKCU\..\Run: [filehippo.com] "C:\Program Files\filehippo.com\UpdateChecker.exe" /background
O4 - Startup: Secunia PSI.lnk = C:\Program Files\Secunia\PSI\psi.exe
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/betapit/PCPitStop.CAB
O16 - DPF: {1A1F56AA-3401-46F9-B277-D57F3421F821} (FunGamesLoader Object) - http://www.worldwinner.com/games/v47/share…GamesLoader.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w3/pr01/resources/MSNPUpld.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {6824D897-F7E1-4E41-B84B-B1D3FA4BF1BD} (PCPitstop AntiVirus) - http://utilities.pcpitstop.com/Exterminate…opAntiVirus.dll
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1233020848406
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab
O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} (PCPitstop Exam) - http://utilities.pcpitstop.com/optimize2/pcpitstop2.dll
O23 - Service: Avira Premium Security Suite Firewall (AntiVirFirewallService) - Avira GmbH - C:\Program Files\Avira\Avira Premium Security Suite\avfwsvc.exe
O23 - Service: Avira Premium Security Suite MailGuard (AntiVirMailService) - Avira GmbH - C:\Program Files\Avira\Avira Premium Security Suite\avmailc.exe
O23 - Service: Avira Premium Security Suite Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\Avira Premium Security Suite\sched.exe
O23 - Service: Avira Premium Security Suite Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\Avira Premium Security Suite\avguard.exe
O23 - Service: Avira Premium Security Suite WebGuard (antivirwebservice) - Avira GmbH - C:\Program Files\Avira\Avira Premium Security Suite\AVWEBGRD.EXE
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Avira Premium Security Suite MailGuard helper service (AVEService) - Avira GmbH - C:\Program Files\Avira\Avira Premium Security Suite\avesvc.exe
O23 - Service: CSIScanner - Prevx - C:\Program Files\PrevxCSI\prevxcsi.exe
O23 - Service: Google Update Service (gupdate1c99626ec36037a) (gupdate1c99626ec36037a) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Online Armor Helper Service (OAcat) - Tall Emu - C:\Program Files\Tall Emu\Online Armor\oacat.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Trend Micro RUBotted Service (RUBotted) - Trend Micro Inc. - C:\Program Files\Trend Micro\RUBotted\TMRUBotted.exe
O23 - Service: Sandboxie Service (SbieSvc) - tzuk - C:\Program Files\Sandboxie\SbieSvc.exe
O23 - Service: Online Armor (SvcOnlineArmor) - Tall Emu - C:\Program Files\Tall Emu\Online Armor\oasrv.exe

–
End of file - 9156 bytes
Hi,

Let's see if we can find out what's wrong.

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.


Please download DDS and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.scr to run the tool.
  • When done two logs should open:
  • DDS.txt
  • Attach.txt
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scrolling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.
Thanks.
Hi, I want to thank you for your time and expertise in helping me out here. Following will be the scan results you asked for: DDS (Ver_09-02-01.01) - NTFSx86 Run by [removed] at 12:14:39.20 on Mon 03/09/2009 Internet Explorer: 7.0.5730.13 Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.2543.1923 [GMT -7:00] AV: avast! antivirus 4.8.1335 [VPS 090308-0] *On-access scanning enabled* (Updated) FW: Online Armor Firewall *enabled* ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch C:\WINDOWS\system32\svchost -k rpcss C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k NetworkService C:\WINDOWS\system32\svchost.exe -k LocalService C:\Program Files\Tall Emu\Online Armor\oasrv.exe C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Intel\PROSetWired\NCS\PROSet\PRONoMgr.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\PROGRA~1\Returnil\Returnil.exe C:\Program Files\Trend Micro\RUBotted\TMRUBottedTray.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\Tall Emu\Online Armor\oaui.exe C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe C:\Program Files\Sandboxie\SbieCtrl.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Calibrize\CalibrizeResume.exe C:\PROGRA~1\TITANB~1\TITANB~2.EXE C:\Program Files\filehippo.com\UpdateChecker.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\PrevxCSI\prevxcsi.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Google\Update\GoogleUpdate.exe C:\WINDOWS\system32\HPZipm12.exe C:\Program Files\Trend Micro\RUBotted\TMRUBotted.exe C:\Program Files\Sandboxie\SbieSvc.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\WINDOWS\system32\SearchIndexer.exe C:\Program Files\PrevxCSI\prevxcsi.exe C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe C:\Program Files\Alwil Software\Avast4\ashWebSv.exe C:\WINDOWS\System32\alg.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\WINDOWS\system32\SearchProtocolHost.exe C:\WINDOWS\system32\SearchFilterHost.exe C:\Documents and Settings\Bryan.JETS-F7DC2E7385\Desktop\dds.scr C:\WINDOWS\system32\wbem\wmiprvse.exe ============== Pseudo HJT Report =============== uStart Page = hxxp://google.com/ mDefault_Page_URL = hxxp://www.yahoo.com uInternet Settings,ProxyOverride = *.local BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File BHO: NoExplorer - No File BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll BHO: PDF-XChange Viewer IE-Plugin: {c5d07eb6-bbce-4dae-acbb-d13a8d28cb1f} - c:\program files\tracker software\pdf-xchange viewer\pdf-viewer\PDFXCviewIEPlugin.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: {968631B6-4729-440D-9BF4-251F5593EC9A} - No File TB: Ask Toolbar: {f0d4b239-da4b-4daf-81e4-dfee4931a4aa} - c:\program files\asksbar\bar\1.bin\ASKSBAR.DLL uRun: [SandboxieControl] "c:\program files\sandboxie\SbieCtrl.exe" uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [CGFLoader] c:\program files\calibrize\CalibrizeLoader.exe uRun: [CalibrizeResume] c:\program files\calibrize\CalibrizeResume.exe uRun: [DriverMax] uRun: [Titan Backup] "c:\progra~1\titanb~1\TITANB~2.EXE" /startup uRun: [filehippo.com] "c:\program files\filehippo.com\UpdateChecker.exe" /background mRun: [PRONoMgrWired] "c:\program files\intel\prosetwired\ncs\proset\PRONoMgr.exe" mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot mRun: [Logitech Utility] Logi_MwX.Exe mRun: [Rvsystem] c:\progra~1\returnil\Returnil.exe mRun: [TMRUBottedTray] "c:\program files\trend micro\rubotted\TMRUBottedTray.exe" mRun: [@OnlineArmor GUI] "c:\program files\tall emu\online armor\oaui.exe" mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" mRun: [OnlineArmor GUI] "c:\program files\tall emu\online armor\oaui.exe" mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe StartupFolder: c:\docume~1\bryan~1.jet\startm~1\programs\startup\secuni~1.lnk - c:\program files\secunia\psi\psi.exe IE: &Clean Traces - c:\program files\dap\privacy package\dapcleanerie.htm IE: &Download with &DAP - c:\program files\dap\dapextie.htm IE: Download &all with DAP - c:\program files\dap\dapextie2.htm IE: {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - c:\program files\pokerstars\PokerStarsUpdate.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe Trusted Zone: secunia.com\psi DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} - hxxp://www.pcpitstop.com/betapit/PCPitStop.CAB DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {1A1F56AA-3401-46F9-B277-D57F3421F821} - hxxp://www.worldwinner.com/games/v47/shared/FunGamesLoader.cab DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} - hxxp://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://gfx1.hotmail.com/mail/w3/pr01/resources/MSNPUpld.cab DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - hxxp://download.divx.com/player/DivXBrowserPlugin.cab DPF: {6824D897-F7E1-4E41-B84B-B1D3FA4BF1BD} - hxxp://utilities.pcpitstop.com/Exterminate2/pcpitstopAntiVirus.dll DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1233020848406 DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} - hxxp://www.worldwinner.com/games/shared/wwlaunch.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} - hxxp://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} - hxxp://support.f-secure.com/ols/fscax.cab DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab DPF: {E62A8B6B-D91C-457C-B1FB-20CC2D96B4EC} - hxxp://www.personalfirewall.comodo.com/scan/ComodoAVScanner.cab DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} - hxxp://utilities.pcpitstop.com/optimize2/pcpitstop2.dll Notify: igfxcui - igfxdev.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll SEH: OA Shell Helper: {4f07da45-8170-4859-9b5f-037ef2970034} - c:\progra~1\tallem~1\online~1\oaevent.dll LSA: Notification Packages = :\windows\system32\srrstr.dll cecli scecli scecli ============= SERVICES / DRIVERS =============== R0 pxprot;pxprot;c:\windows\system32\drivers\pxprot.sys [2009-3-6 16776] R0 pxscan;pxscan;c:\windows\system32\drivers\pxscan.sys [2009-2-27 22536] R0 RVSDISK;RVSDISK;c:\windows\system32\drivers\RVSDISK.sys [2009-1-5 11904] R0 RVSYSTEM;RVSYSTEM;c:\windows\system32\drivers\RVSYSTEM.sys [2009-1-5 38272] R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-3-8 114768] R1 OADevice;OADriver;c:\windows\system32\drivers\OADriver.sys [2009-3-6 80584] R1 OAmon;OAmon;c:\windows\system32\drivers\OAmon.sys [2009-3-6 32456] R1 OAnet;OAnet;c:\windows\system32\drivers\oanet.sys [2009-3-6 28872] R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-3-8 20560] R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast4\ashServ.exe [2009-3-8 138680] R2 CSIScanner;CSIScanner;c:\program files\prevxcsi\prevxcsi.exe [2009-2-27 4150840] R2 RUBotted;Trend Micro RUBotted Service;c:\program files\trend micro\rubotted\TMRUBotted.exe [2009-1-18 582992] R2 SvcOnlineArmor;Online Armor;c:\program files\tall emu\online armor\oasrv.exe [2009-3-6 5435968] R3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast4\ashMaiSv.exe [2009-3-8 254040] R3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast4\ashWebSv.exe [2009-3-8 352920] R3 SbieDrv;SbieDrv;c:\program files\sandboxie\SbieDrv.sys [2009-1-5 103936] R3 TMPassthruMP;TMPassthruMP;c:\windows\system32\drivers\TMPassthru.sys [2009-1-18 206608] S2 gupdate1c99626ec36037a;Google Update Service (gupdate1c99626ec36037a);c:\program files\google\update\GoogleUpdate.exe [2009-2-23 133104] S2 OAcat;Online Armor Helper Service;"c:\program files\tall emu\online armor\oacat.exe" –> c:\program files\tall emu\online armor\oacat.exe [?] S3 Alpham1;Ideazon Merc USB Human Interface Device;c:\windows\system32\drivers\Alpham1.sys [2008-7-18 42624] S3 Alpham2;Ideazon Merc MM USB Human Interface Device;c:\windows\system32\drivers\Alpham2.sys [2008-7-18 18432] S3 PSI;PSI;c:\windows\system32\drivers\psi_mf.sys [2008-12-10 7808] S3 TMPassthru;Trend Micro Passthru Ndis Service;c:\windows\system32\drivers\TMPassthru.sys [2009-1-18 206608] =============== Created Last 30 ================ 2009-03-07 21:55 –d—– c:\program files\Spybot - Search & Destroy 2009-03-07 21:55 –d—– c:\program files\filehippo.com 2009-03-07 21:55 –d—– c:\program files\DAP 2009-03-07 21:55 –d—– c:\program files\Comodo 2009-03-06 22:48 –d—– c:\docume~1\bryan~1.jet\applic~1\OnlineArmor 2009-03-06 22:48 –d—– c:\docume~1\alluse~1.win\applic~1\OnlineArmor 2009-03-06 22:48 80,584 a——- c:\windows\system32\drivers\OADriver.sys 2009-03-06 22:48 32,456 a——- c:\windows\system32\drivers\OAmon.sys 2009-03-06 22:48 28,872 a——- c:\windows\system32\drivers\oanet.sys 2009-03-06 22:27 –d—– c:\windows\system32\en 2009-03-06 22:27 –d—– c:\windows\system32\bits 2009-03-06 22:24 –d—– c:\windows\EHome 2009-03-06 22:24 –d—– c:\docume~1\alluse~1.win\applic~1\SpeedBit 2009-03-06 21:50 –d—– c:\docume~1\bryan~1.jet\applic~1\OnlineArmor(2) 2009-03-06 16:55 –d—– c:\windows\system32\CatRoot2 2009-03-06 16:52 16,776 a——- c:\windows\system32\drivers\pxprot.sys 2009-03-06 16:18 –d—– c:\windows\system32\scripting 2009-03-06 16:18 –d—– c:\windows\l2schemas 2009-03-06 16:13 1,355 a——- c:\windows\imsins.BAK 2009-03-06 16:11 743,936 a——- c:\windows\system32\dllcache\helpsvc.exe 2009-03-06 15:44 479,298 a——- c:\windows\system32\wbocx.ocx 2009-03-06 15:44 172,032 a——- c:\windows\system32\AniGIF.ocx 2009-03-06 15:44 50,688 a——- c:\windows\system32\wbhelp2.dll 2009-03-06 14:58 –d—– c:\docume~1\bryan~1.jet\applic~1\Comodo 2009-03-06 14:58 –d—– c:\documents and settings\all users.windows\Comodo 2009-03-04 13:12 73,728 a——- c:\windows\system32\javacpl.cpl 2009-02-27 23:34 –d—– c:\documents and settings\bryan.jets-f7dc2e7385\Pavark 2009-02-27 23:33 22,536 a——- c:\windows\system32\drivers\pxscan.sys 2009-02-27 23:32 70 a——- c:\windows\wininit.ini 2009-02-27 23:30 –d—– c:\program files\PrevxCSI 2009-02-27 14:51 –d—– c:\program files\Secunia 2009-02-21 19:22 –d—– c:\program files\PokerStars 2009-02-14 08:38 597,504 -c—— c:\windows\system32\dllcache\printfilterpipelinesvc.exe 2009-02-14 08:38 575,488 -c—— c:\windows\system32\dllcache\xpsshhdr.dll 2009-02-14 08:38 89,088 -c—— c:\windows\system32\dllcache\filterpipelineprintproc.dll 2009-02-14 08:38 1,676,288 -c—— c:\windows\system32\dllcache\xpssvcs.dll 2009-02-14 08:38 –d—– C:\f9bf3aea6fb500cde48c 2009-02-11 19:15 –d—– c:\program files\Altura 2009-02-10 20:31 –d—– c:\documents and settings\bryan.jets-f7dc2e7385\.SunDownloadManager ==================== Find3M ==================== 2009-03-07 12:10 76,487 a——- c:\windows\pchealth\helpctr\offlinecache\index.dat 2009-03-04 13:12 410,984 a——- c:\windows\system32\deploytk.dll 2009-02-11 11:19 38,496 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-02-11 11:19 15,504 a——- c:\windows\system32\drivers\mbam.sys 2008-12-20 16:15 826,368 a——- c:\windows\system32\wininet.dll 2008-12-11 04:57 333,184 a——- c:\windows\system32\dllcache\srv.sys 2008-10-28 22:11 3,762,208 a–sh— c:\windows\system32\drivers\fidbox.dat ============= FINISH: 12:17:12.54 =============== Here is the other report you requested:

Attachments:

Hi,

Not a lot showing. Uninstall this old version of Java in Add/Remove Programs:
J2SE Runtime Environment 5.0 Update 6

Let's check for system file problems. Click Start >> Run… and copy/paste the following into the Run box:
sfc /scannow
Close all Windows and Browsers and hit Enter. Your system files will now be checked for problems.

Let me know if any of this is helping.

Thanks.
I have tried multiple times to install and run the sfc /scannow It has always asked me for my xp professional 2 disc. I run xp home but in the past when I've tried this I could never get it to work and run succesfully. I've tried all the windows help files on the subject but nothing seems to work.
OK. There doesn't seem to be any Malware involved so if these problems remain I may well send you over to our Tech Team who will be much more able to help you.

There is just one more scan we can do to check for hidden Malware. If SFC is no good try this one.

Download the GMER Rootkit Scanner. Unzip it to your Desktop.

Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.

Double-click gmer.exe. The program will begin to run.

**Caution**
These types of scans can produce false positives. Do NOT take any action on any
"<— ROOKIT" entries unless advised!

If possible rootkit activity is found, you will be asked if you would like to perform a full scan.
  • Click NO
  • In the right panel, you will see a bunch of boxes that have been checked … leave everything checked and ensure the Show all box is un-checked.
  • Now click the Scan button.
    Once the scan is complete, you may receive another notice about rootkit activity.
  • Click OK.
  • GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "GMER.txt"
  • Save it where you can easily find it, such as your desktop.
Post the contents of GMER.txt in your next reply.

Thanks.
Idon't know what it is with me and directions I did exactly as you asked and when I hit OK the entire file just disappeared and I couldn't find it anywhere. So I ran through the process again but instead of hitting ok I just saved the file as you said and here it is:

GMER 1.0.15.14878 - http://www.gmer.net
Rootkit scan 2009-03-10 08:59:35
Windows 5.1.2600 Service Pack 2


—- System - GMER 1.0.15 —-

SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwAllocateVirtualMemory [0xB2757C90]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwAssignProcessToJobObject [0xB27580C0]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwClose [0xB26C36B8]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwConnectPort [0xB2757580]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwCreateFile [0xB27595D0]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateKey [0xB26C3574]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwCreatePort [0xB2757440]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwCreateProcess [0xB27581F0]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwCreateProcessEx [0xB2755FD0]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwCreateSection [0xB2755BD0]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwCreateThread [0xB2756580]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwDebugActiveProcess [0xB2756E10]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwDeleteFile [0xB2759C30]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwDeleteKey [0xB2759050]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDeleteValueKey [0xB26C3A52]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDuplicateObject [0xB26C314C]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwEnumerateKey [0xB27595B0]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwEnumerateValueKey [0xB27595C0]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwLoadDriver [0xB2757B00]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwLoadKey [0xB275AD50]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwOpenFile [0xB2759990]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenKey [0xB26C364E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenProcess [0xB26C308C]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwOpenSection [0xB2755E00]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenThread [0xB26C30F0]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwProtectVirtualMemory [0xB2757E00]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwQueryKey [0xB2759590]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwQueryValueKey [0xB26C376E]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwReplaceKey [0xB2759210]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwRequestWaitReplyPort [0xB27577D0]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwRestoreKey [0xB26C372E]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwResumeThread [0xB27571C0]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwSaveKey [0xB2759580]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwSetContextThread [0xB2756CC0]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwSetInformationFile [0xB2759E90]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwSetValueKey [0xB26C38AE]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwShutdownSystem [0xB2757A40]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwSuspendProcess [0xB2757300]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwSuspendThread [0xB2757060]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwSystemDebugControl [0xB2756F40]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwTerminateProcess [0xB2756430]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwTerminateThread [0xB2756B50]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwWriteVirtualMemory [0xB2757F60]

—- Kernel code sections - GMER 1.0.15 —-

.text ntoskrnl.exe!ZwYieldExecution + 12E 804E4968 12 Bytes [40, 74, 75, B2, F0, 81, 75, …] {INC EAX; JZ 0x78; MOV DL, 0xf0; XOR DWORD [EBP-0x4e], 0xb2755fd0}
.text ntoskrnl.exe!ZwYieldExecution + 46A 804E4CA4 12 Bytes [00, 73, 75, B2, 60, 70, 75, …] {ADD [EBX+0x75], DH; MOV DL, 0x60; JO 0x7c; MOV DL, 0x40; OUTSD ; JNZ 0xffffffffffffffbe}
? C:\WINDOWS\system32\drivers\OAnet.sys Access is denied.
? C:\WINDOWS\system32\drivers\OAmon.sys Access is denied.
.text OADriver.sys B27544F0 5 Bytes JMP 8A29C750
.text OADriver.sys B2754840 5 Bytes JMP 8A29C7F0
.text OADriver.sys B2755090 5 Bytes JMP 8A29C430
.text OADriver.sys B27553D0 5 Bytes JMP 8A29C4D0
.text OADriver.sys B2755700 5 Bytes JMP 8A29C570
.text …
? C:\WINDOWS\system32\drivers\OADriver.sys Access is denied.
.text win32k.sys!EngUnmapFontFileFD + E078 BF84CC41 5 Bytes JMP 8A29C610
? C:\WINDOWS\TEMP\mc21.tmp The system cannot find the file specified. !

—- User code sections - GMER 1.0.15 —-

.text C:\Program Files\Java\jre6\bin\jusched.exe[148] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\Java\jre6\bin\jusched.exe[148] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Java\jre6\bin\jusched.exe[148] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\Program Files\Java\jre6\bin\jusched.exe[148] kernel32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes CALL 5F00003D
.text C:\Program Files\Java\jre6\bin\jusched.exe[148] USER32.dll!ExitWindowsEx 7E45A045 6 Bytes JMP 5F0D0F5A
.text C:\Program Files\Tall Emu\Online Armor\oaui.exe[204] kernel32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes CALL 5F00003D
.text C:\Program Files\Sandboxie\SbieCtrl.exe[388] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\Sandboxie\SbieCtrl.exe[388] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Sandboxie\SbieCtrl.exe[388] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\Program Files\Sandboxie\SbieCtrl.exe[388] kernel32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes CALL 5F00003D
.text C:\Program Files\Sandboxie\SbieCtrl.exe[388] USER32.dll!ExitWindowsEx 7E45A045 6 Bytes JMP 5F0D0F5A
.text C:\Program Files\Calibrize\CalibrizeResume.exe[416] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\Calibrize\CalibrizeResume.exe[416] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Calibrize\CalibrizeResume.exe[416] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\Program Files\Calibrize\CalibrizeResume.exe[416] kernel32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes CALL 5F00003D
.text C:\Program Files\Calibrize\CalibrizeResume.exe[416] USER32.dll!ExitWindowsEx 7E45A045 6 Bytes JMP 5F0D0F5A
.text C:\WINDOWS\system32\ctfmon.exe[604] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\ctfmon.exe[604] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\ctfmon.exe[604] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\ctfmon.exe[604] kernel32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes CALL 5F00003D
.text C:\WINDOWS\system32\ctfmon.exe[604] USER32.dll!ExitWindowsEx 7E45A045 6 Bytes JMP 5F0D0F5A
.text C:\WINDOWS\system32\wscntfy.exe[756] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\wscntfy.exe[756] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\wscntfy.exe[756] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\wscntfy.exe[756] kernel32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes CALL 5F00003D
.text C:\WINDOWS\system32\wscntfy.exe[756] USER32.dll!ExitWindowsEx 7E45A045 6 Bytes JMP 5F0D0F5A
.text C:\WINDOWS\Explorer.EXE[836] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\Explorer.EXE[836] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\Explorer.EXE[836] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\Explorer.EXE[836] kernel32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes CALL 5F00003D
.text C:\WINDOWS\Explorer.EXE[836] USER32.dll!ExitWindowsEx 7E45A045 6 Bytes JMP 5F0D0F5A
.text C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe[1128] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe[1128] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe[1128] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe[1128] kernel32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes CALL 5F00003D
.text C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe[1128] USER32.dll!ExitWindowsEx 7E45A045 6 Bytes JMP 5F0D0F5A
.text C:\Program Files\Intel\PROSetWired\NCS\PROSet\PRONoMgr.exe[1512] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\Intel\PROSetWired\NCS\PROSet\PRONoMgr.exe[1512] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Intel\PROSetWired\NCS\PROSet\PRONoMgr.exe[1512] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\Program Files\Intel\PROSetWired\NCS\PROSet\PRONoMgr.exe[1512] kernel32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes CALL 5F00003D
.text C:\Program Files\Intel\PROSetWired\NCS\PROSet\PRONoMgr.exe[1512] USER32.dll!ExitWindowsEx 7E45A045 6 Bytes JMP 5F0D0F5A
.text C:\PROGRA~1\TITANB~1\TITANB~2.EXE[1524] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\PROGRA~1\TITANB~1\TITANB~2.EXE[1524] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\PROGRA~1\TITANB~1\TITANB~2.EXE[1524] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\PROGRA~1\TITANB~1\TITANB~2.EXE[1524] kernel32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes CALL 5F00003D
.text C:\PROGRA~1\TITANB~1\TITANB~2.EXE[1524] USER32.dll!ExitWindowsEx 7E45A045 6 Bytes JMP 5F0D0F5A
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[1580] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[1580] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[1580] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[1580] kernel32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes CALL 5F00003D
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[1580] USER32.dll!ExitWindowsEx 7E45A045 6 Bytes JMP 5F0D0F5A
.text C:\DOCUME~1\BRYAN~1.JET\LOCALS~1\Temp\Temporary Directory 3 for gmer.zip\gmer.exe[1768] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\DOCUME~1\BRYAN~1.JET\LOCALS~1\Temp\Temporary Directory 3 for gmer.zip\gmer.exe[1768] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\DOCUME~1\BRYAN~1.JET\LOCALS~1\Temp\Temporary Directory 3 for gmer.zip\gmer.exe[1768] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\DOCUME~1\BRYAN~1.JET\LOCALS~1\Temp\Temporary Directory 3 for gmer.zip\gmer.exe[1768] kernel32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes CALL 5F00003D
.text C:\DOCUME~1\BRYAN~1.JET\LOCALS~1\Temp\Temporary Directory 3 for gmer.zip\gmer.exe[1768] user32.dll!ExitWindowsEx 7E45A045 6 Bytes JMP 5F0D0F5A
.text C:\PROGRA~1\Returnil\Returnil.exe[1776] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\PROGRA~1\Returnil\Returnil.exe[1776] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\PROGRA~1\Returnil\Returnil.exe[1776] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\PROGRA~1\Returnil\Returnil.exe[1776] kernel32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes CALL 5F00003D
.text C:\PROGRA~1\Returnil\Returnil.exe[1776] user32.dll!ExitWindowsEx 7E45A045 6 Bytes JMP 5F0D0F5A
.text C:\Program Files\filehippo.com\UpdateChecker.exe[1780] KERNEL32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\filehippo.com\UpdateChecker.exe[1780] KERNEL32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\filehippo.com\UpdateChecker.exe[1780] KERNEL32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\Program Files\filehippo.com\UpdateChecker.exe[1780] KERNEL32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes CALL 5F00003D
.text C:\Program Files\filehippo.com\UpdateChecker.exe[1780] user32.dll!ExitWindowsEx 7E45A045 6 Bytes JMP 5F0D0F5A
.text C:\Program Files\Trend Micro\RUBotted\TMRUBottedTray.exe[1856] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\Trend Micro\RUBotted\TMRUBottedTray.exe[1856] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Trend Micro\RUBotted\TMRUBottedTray.exe[1856] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\Program Files\Trend Micro\RUBotted\TMRUBottedTray.exe[1856] kernel32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes CALL 5F00003D
.text C:\Program Files\Trend Micro\RUBotted\TMRUBottedTray.exe[1856] USER32.dll!ExitWindowsEx 7E45A045 6 Bytes JMP 5F0D0F5A
.text C:\WINDOWS\System32\alg.exe[2040] kernel32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes CALL 5F00003D
.text C:\WINDOWS\system32\spoolsv.exe[2164] kernel32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes CALL 5F00003D
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[2340] kernel32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes CALL 5F00003D
.text C:\Program Files\PrevxCSI\prevxcsi.exe[2400] kernel32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes CALL 5F00003D
.text C:\Program Files\Java\jre6\bin\jqs.exe[2540] kernel32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes CALL 5F00003D
.text …
.text C:\WINDOWS\system32\SearchIndexer.exe[3276] kernel32.dll!WriteFile 7C810D87 7 Bytes JMP 00585C0C C:\WINDOWS\system32\MSSRCH.DLL (mssrch.dll/Microsoft Corporation)
.text C:\Program Files\PrevxCSI\prevxcsi.exe[3376] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\PrevxCSI\prevxcsi.exe[3376] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\PrevxCSI\prevxcsi.exe[3376] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\Program Files\PrevxCSI\prevxcsi.exe[3376] kernel32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes CALL 5F00003D
.text C:\Program Files\PrevxCSI\prevxcsi.exe[3376] USER32.dll!ExitWindowsEx 7E45A045 6 Bytes JMP 5F0D0F5A
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[4888] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[4888] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[4888] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[4888] kernel32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes CALL 5F00003D
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[4888] USER32.dll!DialogBoxParamW 7E42555F 5 Bytes JMP 42F0F341 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[4888] USER32.dll!DialogBoxIndirectParamW 7E432032 5 Bytes JMP 430A187F C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[4888] USER32.dll!MessageBoxIndirectA 7E43A04A 5 Bytes JMP 430A1800 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[4888] USER32.dll!DialogBoxParamA 7E43B10C 5 Bytes JMP 430A1844 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[4888] USER32.dll!MessageBoxExW 7E4505D8 5 Bytes JMP 430A178C C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[4888] USER32.dll!MessageBoxExA 7E4505FC 5 Bytes JMP 430A17C6 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[4888] USER32.dll!DialogBoxIndirectParamA 7E456B50 5 Bytes JMP 430A18BA C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[4888] USER32.dll!ExitWindowsEx 7E45A045 6 Bytes JMP 5F0D0F5A
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[4888] USER32.dll!MessageBoxIndirectW 7E4662AB 5 Bytes JMP 42F316F6 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)

—- Kernel IAT/EAT - GMER 1.0.15 —-

IAT \SystemRoot\system32\DRIVERS\tcpip.sys[NDIS.SYS!NdisCloseAdapter] [BAF93410] \??\C:\WINDOWS\system32\drivers\OAnet.sys
IAT \SystemRoot\system32\DRIVERS\tcpip.sys[NDIS.SYS!NdisOpenAdapter] [BAF93470] \??\C:\WINDOWS\system32\drivers\OAnet.sys
IAT \SystemRoot\system32\DRIVERS\tcpip.sys[NDIS.SYS!NdisRegisterProtocol] [BAF93720] \??\C:\WINDOWS\system32\drivers\OAnet.sys
IAT \SystemRoot\system32\DRIVERS\wanarp.sys[NDIS.SYS!NdisDeregisterProtocol] [BAF93760] \??\C:\WINDOWS\system32\drivers\OAnet.sys
IAT \SystemRoot\system32\DRIVERS\wanarp.sys[NDIS.SYS!NdisRegisterProtocol] [BAF93720] \??\C:\WINDOWS\system32\drivers\OAnet.sys
IAT \SystemRoot\system32\DRIVERS\wanarp.sys[NDIS.SYS!NdisOpenAdapter] [BAF93470] \??\C:\WINDOWS\system32\drivers\OAnet.sys
IAT \SystemRoot\system32\DRIVERS\wanarp.sys[NDIS.SYS!NdisCloseAdapter] [BAF93410] \??\C:\WINDOWS\system32\drivers\OAnet.sys
IAT \SystemRoot\system32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisRegisterProtocol] [BAF93720] \??\C:\WINDOWS\system32\drivers\OAnet.sys
IAT \SystemRoot\system32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisDeregisterProtocol] [BAF93760] \??\C:\WINDOWS\system32\drivers\OAnet.sys
IAT \SystemRoot\system32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisCloseAdapter] [BAF93410] \??\C:\WINDOWS\system32\drivers\OAnet.sys
IAT \SystemRoot\system32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisOpenAdapter] [BAF93470] \??\C:\WINDOWS\system32\drivers\OAnet.sys

—- User IAT/EAT - GMER 1.0.15 —-

IAT C:\WINDOWS\system32\services.exe[932] @ C:\WINDOWS\system32\services.exe [ADVAPI32.dll!CreateProcessAsUserW] 00380002
IAT C:\WINDOWS\system32\services.exe[932] @ C:\WINDOWS\system32\services.exe [KERNEL32.dll!CreateProcessW] 00380000

—- Devices - GMER 1.0.15 —-

AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)

Device \Driver\Tcpip \Device\Ip OAmon.sys
Device \Driver\Tcpip \Device\Tcp OAmon.sys

AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume1 RVSYSTEM.sys (Returnil Virtual System 2008/Returnil SIA)

Device \Driver\Tcpip \Device\Udp OAmon.sys
Device \Driver\Tcpip \Device\RawIp OAmon.sys
Device \Driver\Tcpip \Device\IPMULTICAST OAmon.sys

—- Registry - GMER 1.0.15 —-

Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager@PendingFileRenameOperations ????p???Pacific Daylight Time???ShellSvcGroup???? ???%???????????$???????&??????????????Windows Socket 2.0 Non-IFS Service Provider Support Environment????? ?`?????????????????p??????&?????&??????? ????????????r?????????? ???r?????????)nt???&?????@???@????%SystemRoot%\system32\config\Antivirus.Evt?s.??????&?&??? ?????????????&??????????????&?V?????????s?????Provides automatic configuration for the 802.11 adapters?? ?????????????????LegacyDriver?l?????&??????????????????ity Suit??? ???????&??????????? ????????&?d?????????????d??&??????????????????C:\Program Files\Alwil Software\Avast4\aswRes.dll?????d??&???o??????????C:\Program Files\Alwil Software\Avast4\aswRes.dll??????????????????????"l???Monitors system security settings and configurations.???????????????????????????????????avast! Mail Scanner?y ??? ???????????????????&???????? ????????????2Av??? ?????????????&?????&8:??????????????????????????RC:\???????????e??????a\??? ???????&???????????%8:????????N???????tm?????&?&??avast! Web Scanner?\Av??????????? ?

—- EOF - GMER 1.0.15 —-

I don't know where all the question marks came from, the original file only had a line of question marks in the last couple of line s after the REG entry heading.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI