This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Firefox redirects to different websites

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hey everyone. Yesterday I was downloading what I thought was an Ebook but it appeared that it had some sort of malware or virus attached to it because since then everytime I google something it seems that firefox is trying to open the page then as its trying to load it it says "Done" but nothing is loaded and then loads a different website. Also sometimes it will load the page but you cant go back to the search engine.
I ran avast and although some spyware was detected the problem persists.
Here is my hijackthis log, Any help would be really appreciated it, thank you :)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:06:05 AM, on 3/12/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Windows\System32\smss.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\winlogon.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\rundll32.exe
C:\Program Files\Dell\DellDock\DockLogin.exe
C:\Program Files\Fingerprint Reader Suite\upeksvr.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\WLTRYSVC.EXE
C:\Windows\System32\bcmwltry.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Windows\system32\WLANExt.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\aestsrv.exe
C:\ProgramData\SingleClick Systems\apache\bin\httpd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
C:\Windows\system32\CTsvcCDA.exe
C:\ProgramData\SingleClick Systems\MySQL\bin\mysqld.exe
C:\ProgramData\SingleClick Systems\Remote Access File Sync Service\dsl_fs_sync.exe
c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe
C:\ProgramData\SingleClick Systems\apache\bin\httpd.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Windows\system32\STacSV.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Dell\DellDock\DellDock.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\DellTPad\Apoint.exe
C:\Windows\OEM02Mon.exe
C:\Windows\System32\rundll32.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Windows\System32\WLTRAY.EXE
C:\Program Files\Fingerprint Reader Suite\psqltray.exe
C:\Program Files\Dell\MediaDirect\PCMService.exe
C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Dell Remote Access\ezi_ra.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\Windows\System32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Program Files\AVG\AVG8\avgtray.exe
C:\Program Files\AVG\AVG8\avgui.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\wbem\wmiprvse.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer provided by Dell
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe
O4 - HKLM\..\Run: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NVHotkey] rundll32.exe C:\Windows\system32\nvHotkey.dll,Start
O4 - HKLM\..\Run: [UpdReg] C:\Windows\UpdReg.EXE
O4 - HKLM\..\Run: [PSQLLauncher] "C:\Program Files\Fingerprint Reader Suite\launcher.exe" /startup
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\Windows\system32\WLTRAY.exe
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe"
O4 - HKLM\..\Run: [Dell DataSafe Online] "C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe" /m
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "c:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [dellsupportcenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P dellsupportcenter
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-1473925604-2817497633-4204280994-1001\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'RA Media Server')
O4 - Startup: Dell Dock.lnk = C:\Program Files\Dell\DellDock\DellDock.exe
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: Dell Remote Access.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: QuickSet.lnk = C:\Program Files\Dell\QuickSet\quickset.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send image to &Bluetooth Device… - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device… - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O13 - Gopher Prefix:
O17 - HKLM\System\CCS\Services\Tcpip\..\{15195D6D-8F62-40F2-AB98-171FA4A21CEE}: NameServer = 85.255.112.60,85.255.112.82
O17 - HKLM\System\CCS\Services\Tcpip\..\{8D0F50EC-F343-47F0-AB10-E32D7C4E4F96}: NameServer = 85.255.112.60,85.255.112.82
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.112.60,85.255.112.82
O17 - HKLM\System\CS1\Services\Tcpip\..\{15195D6D-8F62-40F2-AB98-171FA4A21CEE}: NameServer = 85.255.112.60,85.255.112.82
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.112.60,85.255.112.82
O17 - HKLM\System\CS2\Services\Tcpip\..\{15195D6D-8F62-40F2-AB98-171FA4A21CEE}: NameServer = 85.255.112.60,85.255.112.82
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.112.60,85.255.112.82
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL,avgrsstx.dll
O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\system32\aestsrv.exe
O23 - Service: Remote Access Media Server (Apache2.2) - Apache Software Foundation - C:\ProgramData\SingleClick Systems\apache\bin\httpd.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Creative Labs Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\Windows\system32\CTsvcCDA.exe
O23 - Service: Dock Login Service (DockLoginService) - Stardock Corporation - C:\Program Files\Dell\DellDock\DockLogin.exe
O23 - Service: Remote Access DB (dsl-db) - Unknown owner - C:\ProgramData\SingleClick Systems\MySQL\bin\mysqld.exe
O23 - Service: Remote Access File Sync Service (dsl-fs-sync) - SingleClick Systems - C:\ProgramData\SingleClick Systems\Remote Access File Sync Service\dsl_fs_sync.exe
O23 - Service: Google Desktop Manager 5.8.809.23506 (GoogleDesktopManager-092308-165331) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Advanced Networking Service (hnmsvc) - Dell Inc. - c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: SupportSoft Sprocket Service (DellSupportCenter) (sprtsvc_DellSupportCenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: SigmaTel Audio Service (STacSV) - IDT, Inc. - C:\Windows\system32\STacSV.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\Windows\System32\WLTRYSVC.EXE

–
End of file - 15457 bytes
hello

Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt log in your next reply.
Thanks, I ran combofix and after it produced the log eventhough avast was disabled I got a notification saying that avast! had detected a virus in the operating memory and that I should schedule a boot-time scan. Here's the log for combofix

ComboFix 09-03-10.03 - Liza 2009-03-12 10:54:27.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.3581.2616 [GMT -5:00]
Running from: c:\users\[removed]\Downloads\ComboFix.exe
AV: avast! antivirus 4.8.1229 [VPS 090128-0] *On-access scanning disabled* (Outdated)
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\autorun.inf
c:\programdata\Microsoft\Windows\Start Menu\Programs\WatchFree
c:\recycler\S-8-8-86-100005551-100001553-100000685-6023.com
c:\users\Liza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WatchFree
c:\windows\System32\BCMLogon.dll
c:\windows\system32\drivers\gaopdxwtiomrhinfvvfwtuwmbtpwixpgtfidoi.sys
c:\windows\system32\gaopdxuepndspimnygcklesxbfervnteqcyvas.dll
D:\Autorun.inf
d:\recycler\S-8-8-86-100005551-100001553-100000685-6023.com

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_gaopdxserv.sys
——-\Legacy_PACKET
——-\Service_Packet


((((((((((((((((((((((((( Files Created from 2009-02-12 to 2009-03-12 )))))))))))))))))))))))))))))))
.

2009-03-12 11:00 . 2009-03-12 11:01 294,137,265 –a—— c:\windows\MEMORY.DMP
2009-03-12 09:49 . 2009-03-12 09:49 d——– c:\program files\Trend Micro
2009-03-12 09:32 . 2009-03-12 09:32 d——– c:\windows\System32\drivers\Avg
2009-03-12 09:32 . 2009-03-12 09:32 d——– c:\users\All Users\avg8
2009-03-12 09:32 . 2009-03-12 09:32 d——– c:\programdata\avg8
2009-03-12 09:32 . 2009-03-12 09:32 d——– c:\program files\AVG
2009-03-12 09:32 . 2009-03-12 09:32 325,640 –a—— c:\windows\System32\drivers\avgldx86.sys
2009-03-12 09:32 . 2009-03-12 09:32 107,912 –a—— c:\windows\System32\drivers\avgtdix.sys
2009-03-12 09:32 . 2009-03-12 09:32 10,520 –a—— c:\windows\System32\avgrsstx.dll
2009-03-11 17:08 . 2008-06-19 16:24 28,544 –a—— c:\windows\System32\drivers\pavboot.sys
2009-03-11 17:06 . 2009-03-11 17:06 d——– c:\program files\Panda Security
2009-03-11 12:30 . 2009-03-12 10:50 4 –a—— c:\windows\System32\gaopdxcounter
2009-03-10 19:42 . 2008-12-15 22:29 8,147,456 –a—— c:\windows\System32\wmploc.DLL
2009-03-10 19:42 . 2009-02-08 22:10 2,033,152 –a—— c:\windows\System32\win32k.sys
2009-03-10 19:42 . 2008-11-26 23:43 268,288 –a—— c:\windows\System32\schannel.dll
2009-03-10 19:42 . 2008-12-16 00:31 7,680 –a—— c:\windows\System32\spwmp.dll
2009-03-10 19:42 . 2008-12-16 00:31 4,096 –a—— c:\windows\System32\msdxm.ocx
2009-03-10 19:42 . 2008-12-16 00:31 4,096 –a—— c:\windows\System32\dxmasf.dll
2009-02-28 20:49 . 2009-02-28 20:49 d——– c:\users\Liza\AppData\Roaming\Yahoo!
2009-02-28 20:48 . 2009-02-28 20:57 d——– c:\users\All Users\Yahoo!
2009-02-28 20:48 . 2009-02-28 20:57 d——– c:\programdata\Yahoo!
2009-02-28 20:48 . 2009-02-28 20:59 d——– c:\program files\Yahoo!
2009-02-21 10:57 . 2009-02-21 10:57 d——– c:\program files\Audacity
2009-02-19 11:59 . 2009-03-07 09:37 d——– c:\program files\Microsoft Silverlight
2009-02-19 11:59 . 2009-02-19 11:59 d——– c:\program files\Microsoft Office Outlook Connector
2009-02-19 11:59 . 2009-02-06 19:08 55,280 –a—— c:\windows\System32\drivers\fssfltr.sys
2009-02-19 11:58 . 2009-02-19 11:58 d——– c:\program files\Microsoft Sync Framework
2009-02-12 00:00 . 2009-01-14 22:36 1,383,424 –a—— c:\windows\System32\mshtml.tlb
2009-02-12 00:00 . 2009-01-15 01:11 827,392 –a—— c:\windows\System32\wininet.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-12 16:04 ——— d—a-w c:\programdata\TEMP
2009-03-12 01:16 ——— d—–w c:\users\Liza\AppData\Roaming\U3
2009-03-11 20:42 ——— d—–w c:\users\Liza\AppData\Roaming\Skype
2009-03-11 20:39 ——— d—–w c:\users\Liza\AppData\Roaming\skypePM
2009-03-10 15:13 2,828 –sha-w c:\windows\System32\KGyGaAvL.sys
2009-03-07 00:01 ——— d—–w c:\program files\Steam
2009-03-07 00:01 ——— d—–w c:\program files\Common Files\Steam
2009-02-27 12:44 27,744 —-a-w c:\users\All Users\nvModes.dat
2009-02-27 12:44 27,744 —-a-w c:\programdata\nvModes.dat
2009-02-21 16:49 ——— d—–w c:\users\Liza\AppData\Roaming\LimeWire
2009-02-21 15:52 ——— d—–w c:\users\Liza\AppData\Roaming\Audacity
2009-02-19 16:59 ——— d—–w c:\program files\Windows Live
2009-02-19 16:59 ——— d—–w c:\program files\Microsoft
2009-02-14 23:06 4,350 —-a-w c:\users\Liza\AppData\Roaming\wklnhst.dat
2009-02-09 16:19 0 —ha-w c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
2009-02-07 01:03 307,576 —-a-w c:\windows\WLXPGSS.SCR
2009-02-07 00:52 49,504 —-a-w c:\windows\System32\sirenacm.dll
2009-02-06 18:14 ——— d—–w c:\program files\Microsoft ActiveSync
2009-02-06 18:13 ——— d—–w c:\program files\Microsoft.NET
2009-02-06 03:35 ——— d—–w c:\program files\Netflix
2009-02-03 02:03 ——— d—–w c:\users\Liza\AppData\Roaming\HP
2009-02-03 02:00 ——— d—–w c:\programdata\HP Product Assistant
2009-02-03 02:00 ——— d—–w c:\programdata\HP
2009-02-03 02:00 ——— d—–w c:\program files\HP
2009-02-03 01:49 ——— d—–w c:\programdata\WEBREG
2009-01-31 00:01 410,984 —-a-w c:\windows\System32\deploytk.dll
2009-01-31 00:01 ——— d—–w c:\program files\Java
2009-01-29 18:32 ——— d—–w c:\program files\BitLord
2009-01-29 18:00 ——— d—–w c:\program files\Pcsx2_0.9.4
2009-01-25 21:52 ——— d—–w c:\program files\Hewlett-Packard
2009-01-25 21:52 ——— d—–w c:\program files\Common Files\Hewlett-Packard
2009-01-25 21:51 ——— d—–w c:\program files\Common Files\HP
2009-01-25 21:50 ——— d—–w c:\programdata\Hewlett-Packard
2009-01-25 21:10 ——— d—–w c:\users\Liza\AppData\Roaming\Template
2009-01-24 17:47 ——— d—–w c:\program files\MSXML 4.0
2009-01-24 00:00 48 —ha-w c:\users\All Users\ezsidmv.dat
2009-01-24 00:00 48 —ha-w c:\programdata\ezsidmv.dat
2009-01-23 23:59 ——— d—–w c:\programdata\Skype
2009-01-23 23:59 ——— d—–w c:\program files\Skype
2009-01-23 23:59 ——— d—–w c:\program files\Common Files\Skype
2009-01-23 20:46 ——— d—–w c:\users\Liza\AppData\Roaming\Corel
2009-01-23 20:46 ——— d—–w c:\program files\Common Files\Corel
2009-01-23 20:45 ——— d—–w c:\program files\Corel
2009-01-23 19:44 ——— d—–w c:\users\Liza\AppData\Roaming\Download Manager
2009-01-22 22:03 ——— d—–w c:\program files\LimeWire
2009-01-22 18:23 ——— d—–w c:\users\Liza\AppData\Roaming\tmp
2009-01-22 18:23 ——— d—–w c:\users\Liza\AppData\Roaming\Reallusion
2009-01-22 03:25 ——— d–h–r c:\users\Liza\AppData\Roaming\SecuROM
2009-01-22 03:21 ——— d—–w c:\users\Liza\AppData\Roaming\Apple Computer
2009-01-22 03:21 ——— d—–w c:\programdata\Apple Computer
2009-01-22 03:21 ——— d—–w c:\programdata\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2009-01-22 03:21 ——— d—–w c:\program files\iTunes
2009-01-22 03:21 ——— d—–w c:\program files\iPod
2009-01-22 03:21 ——— d—–w c:\program files\Common Files\Apple
2009-01-22 03:20 ——— d—–w c:\program files\QuickTime
2009-01-22 03:20 ——— d—–w c:\program files\Bonjour
2009-01-22 03:19 ——— d—–w c:\program files\Apple Software Update
2009-01-22 03:18 ——— d—–w c:\programdata\Apple
2009-01-22 02:55 ——— d—–w c:\program files\EA Games
2009-01-22 02:36 0 —ha-w c:\windows\system32\drivers\Msft_User_WpdFs_01_00_00.Wdf
2009-01-20 15:29 ——— d—–w c:\programdata\Dell
2009-01-19 22:17 ——— d—–w c:\users\Liza\AppData\Roaming\Creative
2009-01-19 22:07 ——— d—–w c:\program files\Common Files\Windows Live
2009-01-19 16:11 ——— d—–w c:\program files\Windows Mail
2009-01-19 15:23 ——— d—–w c:\program files\Alwil Software
2009-01-19 15:16 ——— d—–w c:\programdata\McAfee
2009-01-19 14:54 ——— d—–w c:\users\Liza\AppData\Roaming\Dell
2009-01-19 14:52 ——— d-sh–w c:\programdata\Templates
2009-01-19 14:52 ——— d-sh–w c:\programdata\Start Menu
2009-01-19 14:52 ——— d-sh–w c:\programdata\Favorites
2009-01-19 14:52 ——— d-sh–w c:\programdata\Documents
2009-01-19 14:52 ——— d-sh–w c:\programdata\Desktop
2009-01-19 14:52 ——— d-sh–w c:\programdata\Application Data
2009-01-05 16:39 8,704 —-a-w c:\windows\System32\hccoin.dll
2009-01-05 16:39 15,872 —-a-w c:\windows\System32\hcrstco.dll
2009-01-05 16:38 74,752 —-a-w c:\windows\System32\newdev.exe
2009-01-05 16:38 468,992 —-a-w c:\windows\System32\newdev.dll
2009-01-05 16:38 26,112 —-a-w c:\windows\System32\hidserv.dll
2009-01-05 16:38 22,016 —-a-w c:\windows\System32\hid.dll
2009-01-05 16:36 738,304 —-a-w c:\windows\System32\inetcomm.dll
2009-01-05 16:35 269,312 —-a-w c:\windows\System32\es.dll
2009-01-05 16:32 361,984 —-a-w c:\windows\System32\IPSECSVC.DLL
2009-01-05 16:31 303,616 —-a-w c:\windows\System32\wmpeffects.dll
2009-01-05 16:30 885,248 —-a-w c:\windows\System32\RacEngn.dll
2009-01-05 16:29 1,695,744 —-a-w c:\windows\System32\gameux.dll
2009-01-05 16:29 1,314,816 —-a-w c:\windows\System32\quartz.dll
2009-01-05 16:28 801,280 —-a-w c:\windows\System32\NaturalLanguage6.dll
2009-01-05 16:28 2,644,480 —-a-w c:\windows\System32\NlsLexicons0009.dll
2009-01-05 16:28 12,240,896 —-a-w c:\windows\System32\NlsLexicons0007.dll
2009-01-05 16:27 181,760 —-a-w c:\windows\System32\fsquirt.exe
2009-01-05 16:26 3,601,464 —-a-w c:\windows\System32\ntkrnlpa.exe
2009-01-05 16:26 3,549,240 —-a-w c:\windows\System32\ntoskrnl.exe
2009-01-05 16:24 408,064 —-a-w c:\windows\System32\msinfo32.exe
2009-01-05 16:24 246,840 —-a-w c:\windows\System32\clfs.sys
2009-01-05 16:24 2,560 —-a-w c:\windows\AppPatch\AcRes.dll
2009-01-05 15:06 409,600 —-a-w c:\windows\System32\wrap_oal.dll
2009-01-05 15:06 114,688 —-a-w c:\windows\System32\OpenAL32.dll
2008-01-21 02:43 174 –sha-w c:\program files\desktop.ini
2009-01-05 15:28 122,880 —-a-w c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\UEAFOverlay]
@="{F2F31467-B1AC-4df0-AE79-FD5FA085E22B}"
[HKEY_CLASSES_ROOT\CLSID\{F2F31467-B1AC-4df0-AE79-FD5FA085E22B}]
2007-04-17 00:13 721408 –a—— c:\program files\Fingerprint Reader Suite\farchns.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\UEAFOverlayOpen]
@="{A3E208F7-0E3A-4182-A7A6-B169D5D691AA}"
[HKEY_CLASSES_ROOT\CLSID\{A3E208F7-0E3A-4182-A7A6-B169D5D691AA}]
2007-04-17 00:13 721408 –a—— c:\program files\Fingerprint Reader Suite\farchns.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-01-05 39408]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2008-01-25 167936]
"OEM02Mon.exe"="c:\windows\OEM02Mon.exe" [2008-03-04 36864]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-09-25 13552160]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-09-25 92704]
"NVHotkey"="c:\windows\system32\nvHotkey.dll" [2008-09-25 96800]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"PSQLLauncher"="c:\program files\Fingerprint Reader Suite\launcher.exe" [2007-04-16 49168]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-03-21 174872]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2008-10-27 3563520]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2009-01-05 30192]
"PCMService"="c:\program files\Dell\MediaDirect\PCMService.exe" [2007-12-21 184320]
"Dell DataSafe Online"="c:\program files\Dell DataSafe Online\DataSafeOnline.exe" [2008-11-03 1745648]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"dellsupportcenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-10-04 206064]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-07-19 78008]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-01-06 290088]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-01-30 136600]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-10-14 49152]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-03-12 1932568]

c:\users\Liza\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dell Dock.lnk - c:\program files\Dell\DellDock\DellDock.exe [2008-09-23 1295656]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-11-03 703280]
Dell Remote Access.lnk - c:\windows\Installer\{F66A31D9-7831-4FBA-BA02-C411C0047CC5}\NewShortcut10_F66A31D978314FBABA02C411C0047CC5.exe [2009-01-05 53248]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-10-14 214360]
QuickSet.lnk - c:\program files\Dell\QuickSet\quickset.exe [2008-02-22 1193240]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
"DisableCAD"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2009-01-05 10:39 10536 c:\program files\Citrix\GoToAssist\514\g2awinlogon.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\psfus]
2007-04-17 00:04 86528 c:\windows\System32\psqlpwd.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~3\GOEC62~1.DLL avgrsstx.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli psqlpwd

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{9DAFCEC2-9C83-49A3-9573-44B11ACC1B5E}"= c:\program files\Dell\MediaDirect\MediaDirect.exe:Dell MediaDirect
"{4EC7E21A-77DA-47B6-A26C-BCFA57BE9E9C}"= c:\program files\Dell\MediaDirect\PCMService.exe:CyberLink PowerCinema Resident Program
"{AF82ED98-F7D2-4446-AD0B-BCD00F271F9C}"= c:\program files\Dell\MediaDirect\Kernel\DMP\CLBrowserEngine.exe:Cyberlink Media Server Browser Engine
"{C933DEC0-F19F-4E7A-8612-E29BDC49C61D}"= c:\program files\Dell\MediaDirect\Kernel\DMS\CLMSService.exe:CyberLink Media Server
"{925E3B2F-D30B-4B3C-9DD1-04F0BA97EE34}"= UDP:c:\program files\Dell Remote Access\ezi_ra.exe:Dell Remote Access
"{1F4E5DEE-AE26-4373-AB57-2861B076BB9E}"= TCP:c:\program files\Dell Remote Access\ezi_ra.exe:Dell Remote Access
"{C4A44CA8-B568-41BB-A156-689E926E8D0F}"= UDP:c:\programdata\SingleClick Systems\Advanced Networking Service\hnm_svc.exe:Advanced Networking Service
"{E944A75A-FF3B-43DF-BC3D-A0C214B16800}"= TCP:c:\programdata\SingleClick Systems\Advanced Networking Service\hnm_svc.exe:Advanced Networking Service
"{78A22E1B-2EBC-41D6-9359-12D3C8167B10}"= UDP:c:\programdata\SingleClick Systems\VLC\vlc.exe:Remote Access VLC
"{7D82C06F-78FC-4CFA-91E3-70413A889F8E}"= TCP:c:\programdata\SingleClick Systems\VLC\vlc.exe:Remote Access VLC
"{866FCF58-D67F-4DD8-9378-7AB2B78F7D46}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{A2FE929F-BAF9-47FD-A25E-6483124EC6A8}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{5B52A12D-BEE8-4497-89FB-A563297EB106}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{FFFFB27E-C502-4131-8538-209A1DC3674F}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"TCP Query User{30C60196-44C0-440E-9728-15C1787DA8B7}c:\\program files\\limewire\\limewire.exe"= UDP:c:\program files\limewire\limewire.exe:LimeWire
"UDP Query User{66B2E263-907A-4EF1-8545-3036A19BB758}c:\\program files\\limewire\\limewire.exe"= TCP:c:\program files\limewire\limewire.exe:LimeWire
"{0A0659EC-747D-4AB5-A312-3D2F267089E5}"= c:\program files\Skype\Phone\Skype.exe:Skype
"{36880B6D-478A-42C8-9DD8-08A5C03D7267}"= UDP:c:\programdata\SingleClick Systems\apache\bin\httpd.exe:Remote Access Media Server
"{1D831369-75C5-4F8C-9AA8-C0BD78EB4DA3}"= TCP:c:\programdata\SingleClick Systems\apache\bin\httpd.exe:Remote Access Media Server
"{2BDFEC2B-FD60-4A87-9124-A5C9B4576AE0}"= UDP:c:\programdata\SingleClick Systems\MySQL\bin\mysqld.exe:Remote Access DB
"{9D922180-285A-40A2-9890-F0AAB8ACF16C}"= TCP:c:\programdata\SingleClick Systems\MySQL\bin\mysqld.exe:Remote Access DB
"{7BA47EF9-3E30-4329-874C-B68ACDBCDA65}"= UDP:c:\programdata\SingleClick Systems\MySQL\bin\mysql.exe:Remote Access CLI
"{5ACF7ABD-F1C5-4225-8AB6-4C43D347BB84}"= TCP:c:\programdata\SingleClick Systems\MySQL\bin\mysql.exe:Remote Access CLI
"{C82363E7-64DF-4463-9F51-D41CED3A1856}"= UDP:c:\programdata\SingleClick Systems\apache\php.exe:Remote Access PHP
"{573D0E5A-5097-4ADB-833A-16B4D8345B5A}"= TCP:c:\programdata\SingleClick Systems\apache\php.exe:Remote Access PHP
"{B3342A04-6456-420F-929F-85B7DB0DDC3B}"= UDP:c:\programdata\SingleClick Systems\Remote Access File Sync Service\dsl_fs_sync.exe:Remote Access File Sync Service
"{331ACFA8-C4C3-4577-96EB-9E985FE7D6D4}"= TCP:c:\programdata\SingleClick Systems\Remote Access File Sync Service\dsl_fs_sync.exe:Remote Access File Sync Service
"{FEEB36B8-C4C1-41B6-9AF7-2A547373DF9E}"= UDP:40080:Remote Access Media Server
"{E98D664C-78F0-4407-B0C3-112EA4E92439}"= UDP:40090:Streaming Web Cam
"{57C393B7-3B87-4306-B96A-9FF238F45A48}"= UDP:40091:Streaming Web Cam
"{97F8C86D-3C49-46F9-ADF2-7C939B3842EB}"= UDP:40092:Streaming Web Cam
"{2F0133B5-42DF-4494-9018-8224E67C51EE}"= UDP:40093:Streaming Web Cam
"{5268A796-722B-445B-BF73-6532BF4D7CC4}"= UDP:40094:Streaming Web Cam
"{DA1894F1-74D9-4D6C-9173-AA48B173523E}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hposid01.exe:hposid01.exe
"{3507A5DB-F4F6-44F8-9D28-C5283E4CF968}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hposid01.exe:hposid01.exe
"{4ADEBFBA-CA94-49E9-A8B7-0C79AA5568C3}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hpiscnapp.exe:hpiscnapp.exe
"{91B751D3-19C2-4FDB-A54D-B2EE6A1148E1}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hpiscnapp.exe:hpiscnapp.exe
"{FC8A1A98-7AE3-4FEE-BBB2-21D60A887673}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hpqkygrp.exe:hpqkygrp.exe
"{3ACE6430-7827-497A-B8C2-FE16787CB798}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hpqkygrp.exe:hpqkygrp.exe
"TCP Query User{CFAE8F74-A2B8-49DF-9E51-A1D6AE490D16}c:\\program files\\limewire\\limewire.exe"= UDP:c:\program files\limewire\limewire.exe:LimeWire
"UDP Query User{B3EC66B8-6096-4714-A984-88DCEB01EBD3}c:\\program files\\limewire\\limewire.exe"= TCP:c:\program files\limewire\limewire.exe:LimeWire
"TCP Query User{8D276D23-2C10-4B19-B221-AA2BEF1E4E8F}c:\\program files\\bitlord\\bitlord.exe"= UDP:c:\program files\bitlord\bitlord.exe:BitLord
"UDP Query User{BE4CEAC8-79DF-49C1-8F5C-2B1839AE94D4}c:\\program files\\bitlord\\bitlord.exe"= TCP:c:\program files\bitlord\bitlord.exe:BitLord
"{F1DBCC14-E50A-40AB-BB49-1D07AD94E080}"= c:\program files\Windows Live\Sync\WindowsLiveSync.exe:Windows Live Sync
"TCP Query User{43A6FA3B-3A7B-4EAE-96EA-19C5138FDBF8}c:\\program files\\quicktime\\quicktimeplayer.exe"= UDP:c:\program files\quicktime\quicktimeplayer.exe:QuickTime Player
"UDP Query User{58626F50-57F8-4EC9-93EF-BE75BFED4960}c:\\program files\\quicktime\\quicktimeplayer.exe"= TCP:c:\program files\quicktime\quicktimeplayer.exe:QuickTime Player
"{B62B4EB6-BB84-4266-86C3-3DE334D9E78D}"= UDP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{84FC539B-D4A5-4175-B606-10B020FA0A77}"= TCP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{52B6756B-4718-42B1-B1E4-47422B0DB632}"= c:\program files\AVG\AVG8\avgupd.exe:avgupd.exe
"{7D9B3B45-AC1E-42D0-9C44-9DCDFE3080AF}"= c:\program files\AVG\AVG8\avgnsx.exe:avgnsx.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)

R0 pavboot;pavboot;c:\windows\System32\drivers\pavboot.sys [2009-03-11 28544]
R1 aswSP;avast! Self Protection;c:\windows\System32\drivers\aswSP.sys [2009-01-19 78416]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\drivers\avgldx86.sys [2009-03-12 325640]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\System32\drivers\avgtdix.sys [2009-03-12 107912]
R2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\AEstSrv.exe [2009-01-05 73728]
R2 Apache2.2;Remote Access Media Server;c:\programdata\SingleClick Systems\apache\bin\httpd.exe [2007-09-21 15872]
R2 aswFsBlk;aswFsBlk;c:\windows\System32\drivers\aswFsBlk.sys [2009-01-19 20560]
R2 aswMonFlt;aswMonFlt;c:\windows\System32\drivers\aswMonFlt.sys [2009-01-19 51280]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-03-12 298264]
R2 DockLoginService;Dock Login Service;c:\program files\Dell\DellDock\DockLogin.exe [2008-09-23 155648]
R2 dsl-db;Remote Access DB;c:\programdata\SingleClick Systems\MySQL\bin\mysqld.exe [2007-09-14 5730304]
R2 dsl-fs-sync;Remote Access File Sync Service;c:\programdata\SingleClick Systems\Remote Access File Sync Service\dsl_fs_sync.exe [2008-09-30 173296]
R2 SeaPort;SeaPort;c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2009-01-14 226656]
R3 OEM02Dev;Creative Camera OEM002 Driver;c:\windows\System32\drivers\OEM02Dev.sys [2009-01-05 235648]
R3 OEM02Vfx;Creative Camera OEM002 Video VFX Driver;c:\windows\System32\drivers\OEM02Vfx.sys [2009-01-05 7424]
S3 fssfltr;FssFltr;c:\windows\System32\drivers\fssfltr.sys [2009-02-19 55280]
S3 fsssvc;Windows Live Family Safety;c:\program files\Windows Live\Family Safety\fsssvc.exe [2009-02-06 533360]
S3 GoogleDesktopManager-092308-165331;Google Desktop Manager 5.8.809.23506;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2009-01-05 30192]
S4 iaNvStor;Intel® Turbo Memory Controller;c:\windows\System32\drivers\iaNvStor.sys [2009-01-05 209408]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{52892e88-ea2d-11dd-9867-0023ae002216}]
\shell\AutoRun\command - G:\LaunchU3.exe -a
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/ig/dell?hl=en&client;=dell-usuk&channel;=us&ibd;=1090105
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
IE: Send image to &Bluetooth; Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth; Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
FF - ProfilePath - c:\users\Liza\AppData\Roaming\Mozilla\Firefox\Profiles\bfaxedoq.default\
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - component: c:\program files\Mozilla Firefox\components\GoogleDesktopMozilla.dll
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-12 11:06:38
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'lsass.exe'(720)
c:\windows\system32\psqlpwd.dll
c:\program files\Fingerprint Reader Suite\homefus2.dll
c:\program files\Fingerprint Reader Suite\infra.dll

- - - - - - - > 'Explorer.exe'(4692)
c:\program files\Fingerprint Reader Suite\farchns.dll
c:\program files\Fingerprint Reader Suite\infra.dll
c:\windows\system32\btncopy.dll
.
———————— Other Running Processes ————————
.
c:\windows\System32\nvvsvc.exe
c:\windows\System32\audiodg.exe
c:\windows\System32\WLTRYSVC.EXE
c:\windows\System32\wlanext.exe
c:\windows\System32\BCMWLTRY.EXE
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\windows\System32\rundll32.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\Fingerprint Reader Suite\upeksvr.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
c:\windows\System32\CTSVCCDA.EXE
c:\progra~1\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\program files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
c:\windows\System32\stacsv.exe
c:\windows\System32\rundll32.exe
c:\windows\System32\rundll32.exe
c:\program files\Fingerprint Reader Suite\psqltray.exe
c:\program files\Alwil Software\Avast4\ashDisp.exe
c:\program files\DellTPad\ApMsgFwd.exe
c:\program files\DellTPad\hidfind.exe
c:\program files\Dell Remote Access\ezi_ra.exe
c:\program files\DellTPad\ApntEx.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\HP\Digital Imaging\bin\hpqste08.exe
c:\program files\HP\Digital Imaging\bin\hpqbam08.exe
c:\program files\HP\Digital Imaging\bin\hpqgpc01.exe
c:\program files\Dell Support Center\bin\sprtsvc.exe
.
**************************************************************************
.
Completion time: 2009-03-12 11:10:57 - machine was rebooted
ComboFix-quarantined-files.txt 2009-03-12 16:10:26

Pre-Run: 218,467,889,152 bytes free
Post-Run: 217,925,537,792 bytes free

372 — E O F — 2009-03-11 08:01:25
hello

Please download OTMoveIt3 by OldTimer
  • Save it to your desktop.
  • Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    :Processes
    explorer.exe
    
    :Services
    
    :Reg
    
    :Files
    c:\windows\System32\gaopdxcounter
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.




Download RootRepeal.zip and unzip it to your Desktop.
  • Double click RootRepeal.exe to start the program
  • Click on the Report tab at the bottom of the program window
  • Click the Scan button
  • In the Select Scan dialog, check:
    • Drivers
    • Files
    • Processes
    • SSDT
    • Stealth Objects
    • Hidden Services
  • Click the OK button
  • In the next dialog, select all drives showing
  • Click OK to start the scan

    Note: The scan can take some time. DO NOT run any other programs while the scan is running

  • When the scan is complete, the Save Report button will become available
  • Click this and save the report to your Desktop as RootRepeal.txt
If the report is not too long, post the contents of RootRepeal.txt in your next reply. If the report is very long, it will not be complete if you post it, so please attach it to your reply instead.

To attach a file, do the following:
  • Click Add Reply
  • Under the reply panel is the Attachments Panel
  • Browse for the attachment file you want to upload, then click the green Upload button
  • Once it has uploaded, click the Manage Current Attachments drop down box
  • Click on [external image: Posted Image] to insert the attachment into your post
Thanks for the response. Here is the first log ========== PROCESSES ========== Process explorer.exe killed successfully. ========== SERVICES/DRIVERS ========== ========== REGISTRY ========== ========== FILES ========== c:\windows\System32\gaopdxcounter moved successfully. ========== COMMANDS ========== File delete failed. C:\Users\Liza\AppData\Local\Temp\etilqs_Orsrxalri7EVlFQxYKul scheduled to be deleted on reboot. File delete failed. C:\Users\Liza\AppData\Local\Temp\~DF503B.tmp scheduled to be deleted on reboot. File delete failed. C:\Users\Liza\AppData\Local\Temp\~DF7FD4.tmp scheduled to be deleted on reboot. File delete failed. C:\Users\Liza\AppData\Local\Temp\~DFEED1.tmp scheduled to be deleted on reboot. User's Temp folder emptied. User's Temporary Internet Files folder emptied. User's Internet Explorer cache folder emptied. Local Service Temp folder emptied. Local Service Temporary Internet Files folder emptied. File delete failed. C:\Windows\temp\_avast4_\Webshlock.txt scheduled to be deleted on reboot. Windows Temp folder emptied. File delete failed. C:\Users\Liza\AppData\Local\Mozilla\Firefox\Profiles\bfaxedoq.default\Cache\_CACHE_001_ scheduled to be deleted on reboot. File delete failed. C:\Users\Liza\AppData\Local\Mozilla\Firefox\Profiles\bfaxedoq.default\Cache\_CACHE_002_ scheduled to be deleted on reboot. File delete failed. C:\Users\Liza\AppData\Local\Mozilla\Firefox\Profiles\bfaxedoq.default\Cache\_CACHE_003_ scheduled to be deleted on reboot. File delete failed. C:\Users\Liza\AppData\Local\Mozilla\Firefox\Profiles\bfaxedoq.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot. File delete failed. C:\Users\Liza\AppData\Local\Mozilla\Firefox\Profiles\bfaxedoq.default\urlclassifier3.sqlite scheduled to be deleted on reboot. File delete failed. C:\Users\Liza\AppData\Local\Mozilla\Firefox\Profiles\bfaxedoq.default\XUL.mfl scheduled to be deleted on reboot. FireFox cache emptied. Temp folders emptied. Explorer started successfully OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 03122009_172016 Files moved on Reboot… File C:\Users\Liza\AppData\Local\Temp\etilqs_Orsrxalri7EVlFQxYKul not found! File C:\Users\Liza\AppData\Local\Temp\~DF503B.tmp not found! File C:\Users\Liza\AppData\Local\Temp\~DF7FD4.tmp not found! C:\Users\Liza\AppData\Local\Temp\~DFEED1.tmp moved successfully. File move failed. C:\Windows\temp\_avast4_\Webshlock.txt scheduled to be moved on reboot. C:\Users\Liza\AppData\Local\Mozilla\Firefox\Profiles\bfaxedoq.default\Cache\_CACHE_001_ moved successfully. C:\Users\Liza\AppData\Local\Mozilla\Firefox\Profiles\bfaxedoq.default\Cache\_CACHE_002_ moved successfully. C:\Users\Liza\AppData\Local\Mozilla\Firefox\Profiles\bfaxedoq.default\Cache\_CACHE_003_ moved successfully. C:\Users\Liza\AppData\Local\Mozilla\Firefox\Profiles\bfaxedoq.default\Cache\_CACHE_MAP_ moved successfully. C:\Users\Liza\AppData\Local\Mozilla\Firefox\Profiles\bfaxedoq.default\urlclassifier3.sqlite moved successfully. C:\Users\Liza\AppData\Local\Mozilla\Firefox\Profiles\bfaxedoq.default\XUL.mfl moved successfully. And here is the log for rootrepeal ROOTREPEAL © AD, 2007-2008 ================================================== Scan Time: 2009/03/12 17:36 Program Version: Version 1.2.3.0 Windows Version: Windows Vista SP1 ================================================== Drivers ——————- Name: dump_iaStor.sys Image Path: C:\Windows\System32\Drivers\dump_iaStor.sys Address: 0x8EA00000 Size: 815104 File Visible: No Status: - Name: rootrepeal.sys Image Path: C:\Windows\system32\drivers\rootrepeal.sys Address: 0x9D3C7000 Size: 45056 File Visible: No Status: - Hidden/Locked Files ——————- Path: C:\System Volume Information\{b9e82d98-002b-11de-b766-0023ae002216}{3808876b-c176-4e48-b7ae-04046e6cc752} Status: Locked to the Windows API! Path: C:\System Volume Information\{3808876b-c176-4e48-b7ae-04046e6cc752} Status: Locked to the Windows API! Path: C:\System Volume Information\{5873f1c9-fdcc-11dd-a8d5-0023ae002216}{3808876b-c176-4e48-b7ae-04046e6cc752} Status: Locked to the Windows API! Path: C:\System Volume Information\{5873f1d3-fdcc-11dd-a8d5-0023ae002216}{3808876b-c176-4e48-b7ae-04046e6cc752} Status: Locked to the Windows API! Path: C:\System Volume Information\{5873f211-fdcc-11dd-a8d5-0023ae002216}{3808876b-c176-4e48-b7ae-04046e6cc752} Status: Locked to the Windows API! Path: C:\System Volume Information\{6bedbf3b-0b25-11de-a68b-0023ae002216}{3808876b-c176-4e48-b7ae-04046e6cc752} Status: Locked to the Windows API! Path: C:\System Volume Information\{6bedbf45-0b25-11de-a68b-0023ae002216}{3808876b-c176-4e48-b7ae-04046e6cc752} Status: Locked to the Windows API! Path: C:\System Volume Information\{6bedbf55-0b25-11de-a68b-0023ae002216}{3808876b-c176-4e48-b7ae-04046e6cc752} Status: Locked to the Windows API! Path: C:\System Volume Information\{6bedbf6c-0b25-11de-a68b-0023ae002216}{3808876b-c176-4e48-b7ae-04046e6cc752} Status: Locked to the Windows API! Path: C:\System Volume Information\{6bedbfc1-0b25-11de-a68b-0023ae002216}{3808876b-c176-4e48-b7ae-04046e6cc752} Status: Locked to the Windows API! Path: C:\System Volume Information\{6bedbfc8-0b25-11de-a68b-0023ae002216}{3808876b-c176-4e48-b7ae-04046e6cc752} Status: Locked to the Windows API! Path: C:\System Volume Information\{6de587fe-0f0d-11de-86fd-0023ae002216}{3808876b-c176-4e48-b7ae-04046e6cc752} Status: Locked to the Windows API! Path: C:\System Volume Information\{6de58817-0f0d-11de-86fd-0023ae002216}{3808876b-c176-4e48-b7ae-04046e6cc752} Status: Locked to the Windows API! Path: C:\System Volume Information\{b9e82d26-002b-11de-b766-0023ae002216}{3808876b-c176-4e48-b7ae-04046e6cc752} Status: Locked to the Windows API! Path: C:\System Volume Information\{b9e82d38-002b-11de-b766-0023ae002216}{3808876b-c176-4e48-b7ae-04046e6cc752} Status: Locked to the Windows API! Path: C:\System Volume Information\{b9e82d46-002b-11de-b766-0023ae002216}{3808876b-c176-4e48-b7ae-04046e6cc752} Status: Locked to the Windows API! Path: C:\System Volume Information\{b9e82d50-002b-11de-b766-0023ae002216}{3808876b-c176-4e48-b7ae-04046e6cc752} Status: Locked to the Windows API! Path: C:\System Volume Information\{b9e82d74-002b-11de-b766-0023ae002216}{3808876b-c176-4e48-b7ae-04046e6cc752} Status: Locked to the Windows API! Path: C:\System Volume Information\{b9e82d84-002b-11de-b766-0023ae002216}{3808876b-c176-4e48-b7ae-04046e6cc752} Status: Locked to the Windows API! Path: C:\System Volume Information\{b9e82d92-002b-11de-b766-0023ae002216}{3808876b-c176-4e48-b7ae-04046e6cc752} Status: Locked to the Windows API! Path: C:\System Volume Information\{b9e82dc8-002b-11de-b766-0023ae002216}{3808876b-c176-4e48-b7ae-04046e6cc752} Status: Locked to the Windows API! Path: C:\System Volume Information\{b9e82dce-002b-11de-b766-0023ae002216}{3808876b-c176-4e48-b7ae-04046e6cc752} Status: Locked to the Windows API! Path: C:\System Volume Information\{b9e82ddf-002b-11de-b766-0023ae002216}{3808876b-c176-4e48-b7ae-04046e6cc752} Status: Locked to the Windows API! Path: C:\System Volume Information\{b9e82df0-002b-11de-b766-0023ae002216}{3808876b-c176-4e48-b7ae-04046e6cc752} Status: Locked to the Windows API! Path: C:\System Volume Information\{b9e82df7-002b-11de-b766-0023ae002216}{3808876b-c176-4e48-b7ae-04046e6cc752} Status: Locked to the Windows API! Path: C:\System Volume Information\{b9e82e09-002b-11de-b766-0023ae002216}{3808876b-c176-4e48-b7ae-04046e6cc752} Status: Locked to the Windows API! Path: C:\System Volume Information\{b9e82e15-002b-11de-b766-0023ae002216}{3808876b-c176-4e48-b7ae-04046e6cc752} Status: Locked to the Windows API! Path: C:\System Volume Information\{b9e82e2f-002b-11de-b766-0023ae002216}{3808876b-c176-4e48-b7ae-04046e6cc752} Status: Locked to the Windows API! Path: C:\Windows\Prefetch\SEARCHPROTOCOLHOST.EXE-69C456C3.pf Status: Size mismatch (API: 37136, Raw: 37082) Path: C:\Windows\Prefetch\WLCOMM.EXE-E9DF8E24.pf Status: Size mismatch (API: 51390, Raw: 49398) Path: C:\Windows\Prefetch\MSNMSGR.EXE-55A628AE.pf Status: Size mismatch (API: 166134, Raw: 165946) Path: C:\Windows\Temp\_avast4_\unp261451857.tmp Status: Invisible to the Windows API! Path: C:\Windows\Temp\_avast4_\unp225536925.tmp Status: Visible to the Windows API, but not on disk. Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.91_none_58b1a5 ca663317c4.cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Catalogs\x86_policy.4.1.microsoft.msxml2r_6bd6b9abf345378f_4.1.1.0_none_8b7b15c031cd a6db.cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.42_none_0e9c2a8d74fd3c e6.cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.762_none_0c178a139ee2a7ed .cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.762_none_10b2f55f9bffb8f8 .cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.42_none_dc990e4797f81af1. cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.91_none_5c400d 5e63e93b68.cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.openmp_1fc8b3b9a1e18e3b_8.0.50727.762_none_7b33aa7d21850 4d2.cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Catalogs\x86_microsoft.msxml2_6bd6b9abf345378f_4.20.9818.0_none_b7e811947b297f6d.cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.762_none_8e053 e8c6967ba9d.cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Catalogs\x86_policy.4.20.microsoft.msxml2_6bd6b9abf345378f_4.20.9870.0_none_a6dea5dc 0ea08098.cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.1801_none_5169 53ad0f4d16c4.cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.91_none_54c127 9468b7b84b.cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.1801_none_d088a2ec442ef17 b.cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.762_none_11ecb0ab9b2caf3c .cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Catalogs\x86_microsoft.msxml2_6bd6b9abf345378f_4.20.9870.0_none_b7e00e6c7b30b69b.cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.91_none_0e9c342f74fd2e 58.cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.openmp_1fc8b3b9a1e18e3b_8.0.50727.42_none_765 8964504b9f3b6.cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.762_none_8d d7dea5d5a7a18a.cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.762_none_8a14c 0566bec5b24.cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.21022.8_none_bcb86ed6ac711f91.c at Status: Locked to the Windows API! Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.42_none_58b19c 2866332652.cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.42_none_588 43c41d2730d3f.cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.91_none_d6c3f1519bae0514. cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.42_none_d6c3e7af9bae13a2. cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.762_none_9193a 620671dde41.cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.42_none_5c4003 bc63e949f6.cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.762_none_43efccf17831d 131.cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.91_none_db5f5c9d98cb161f. cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.openmp_1fc8b3b9a1e18e3b_8.0.50727.762_none_ab ac38a907ee8801.cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Catalogs\x86_microsoft.msxml2r_6bd6b9abf345378f_4.1.0.0_none_3658456fda6654f6.cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.42_none_54c11d f268b7c6d9.cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.91_none_588 445e3d272feb1.cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.42_none_db5f52fb98cb24ad. cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.91_none_dc9917e997f80c63. cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Catalogs\x86_microsoft.msxml2_6bd6b9abf345378f_4.1.0.0_none_6c030d6fdc86522c.cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Catalogs\x86_microsoft.msxml2r_6bd6b9abf345378f_4.1.1.0_none_365945b9da656e4d.cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Catalogs\x86_policy.9.0.microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.21022.8_none_60a5df5 6e60dc5df.cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.openmp_1fc8b3b9a1e18e3b_8.0.50727.42_none_45e008191e5070 87.cat Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-security-schannel_31bf3856ad364e35_6.0.6001.18000_none_22164b0e5542d6c1\$$DeleteMe.schannel.dll.01c9a22049cd9200.0000 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_policy.1.2.microsof..op.security.azroles_31bf3856ad364e35_6.0.6000.1638 6_none_ea83414c2e75b887\Microsoft.Interop.Security.AzRoles.config Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-i..ersandsecurityzones_31bf3856ad364e35_6.0.6001.18157_none_b4b40c2bd6ec2590\$$DeleteMe.urlmon.dll.01c98cf15a42a5b0.0000 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6001.18157_none_01b9e7cda1f54c23\$$DeleteMe.wininet.dll.01c98cf15a49c9d0.0002 Status: Locked to the Windows API! Path: C:\Windows\winsxs\x86_microsoft-windows-ie-runtimeutilities_31bf3856ad364e35_6.0.6001.18157_none_47749ea98ca66a80\$$DeleteMe.iertutil.dll.01c98cf15a476870.0001 Status: Locked to the Windows API! Path: C:\Users\Liza\AppData\Local\Temp\etilqs_wNMGr7mTjjks2yEBcEFN Status: Size mismatch (API: 24600, Raw: 0) Path: C:\Windows\assembly\GAC_32\Policy.1.2.Microsoft.Interop.Security.AzRoles\6.0.6000.16386__31bf3856ad364e35\Microsoft.Interop.Security.AzRoles.config Status: Locked to the Windows API! Path: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTDiagLog.etl Status: Locked to the Windows API! Path: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventLog-Application.etl Status: Locked to the Windows API! Path: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventlog-Security.etl Status: Locked to the Windows API! Path: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventLog-System.etl Status: Locked to the Windows API! Path: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTMsMpPsSession.etl Status: Locked to the Windows API! Path: C:\Users\Liza\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch.5672.232051 Status: Locked to the Windows API! Path: C:\Users\Liza\AppData\Local\Mozilla\Firefox\Profiles\bfaxedoq.default\Cache\_CACHE_001_ Status: Allocation size mismatch (API: 589824, Raw: 524288) Path: C:\Users\Liza\AppData\Local\Mozilla\Firefox\Profiles\bfaxedoq.default\Cache\_CACHE_002_ Status: Allocation size mismatch (API: 720896, Raw: 655360) Path: C:\Users\Liza\AppData\Local\Mozilla\Firefox\Profiles\bfaxedoq.default\Cache\_CACHE_003_ Status: Allocation size mismatch (API: 1507328, Raw: 1376256) Processes ——————- Path: System PID: 4 Status: Locked to the Windows API! Path: C:\Windows\System32\audiodg.exe PID: 1172 Status: Locked to the Windows API! Stealth Objects ——————- Object: Hidden Module [Name: winlogon.exe] Process: svchost.exe (PID: 984) Address: 0x00850000 Size: 323584 Object: Hidden Module [Name: WinMgmtR.dll] Process: svchost.exe (PID: 984) Address: 0x008a0000 Size: 8192 Object: Hidden Module [Name: winlogon.exe] Process: svchost.exe (PID: 984) Address: 0x023a0000 Size: 323584 Object: Hidden Module [Name: tquery.dll] Process: svchost.exe (PID: 984) Address: 0x700d0000 Size: 1589248 Object: Hidden Module [Name: WinMgmtR.dll] Process: svchost.exe (PID: 984) Address: 0x70450000 Size: 8192 Object: Hidden Module [Name: profsvc.dll] Process: svchost.exe (PID: 984) Address: 0x737f0000 Size: 163840 Object: Hidden Module [Name: wevtapi.dll] Process: svchost.exe (PID: 984) Address: 0x75090000 Size: 258048 Object: Hidden Module [Name: bcmwlrmt.dll] Process: bcmwltry.exe (PID: 1904) Address: 0x03e20000 Size: 77824 Object: Hidden Module [Name: msvcm80.dll] Process: bcmwltry.exe (PID: 1904) Address: 0x03e70000 Size: 507904 Object: Hidden Module [Name: WLTRAY.EXE] Process: bcmwltry.exe (PID: 1904) Address: 0x058d0000 Size: 3952640 Object: Hidden Module [Name: MenuSkinning.DLL] Process: DellDock.exe (PID: 2492) Address: 0x051c0000 Size: 4632576 Object: Hidden Module [Name: MyDock.Util.DLL] Process: DellDock.exe (PID: 2492) Address: 0x003e0000 Size: 102400 Object: Hidden Module [Name: VistaBridgeLibrary.DLL] Process: DellDock.exe (PID: 2492) Address: 0x00400000 Size: 110592 Object: Hidden Module [Name: VDialog.dll] Process: DellDock.exe (PID: 2492) Address: 0x008a0000 Size: 159744 Object: Hidden Module [Name: imageres.dll] Process: Explorer.EXE (PID: 3188) Address: 0x68220000 Size: 15822848 Object: Hidden Module [Name: msvcm80.dll] Process: WLTRAY.EXE (PID: 4212) Address: 0x04590000 Size: 507904 Object: Hidden Module [Name: bcmwlrmt.dll] Process: WLTRAY.EXE (PID: 4212) Address: 0x04610000 Size: 77824 Object: Hidden Module [Name: BalloonWindow.dll] Process: DataSafeOnline.exe (PID: 3016) Address: 0x009c0000 Size: 61440 Object: Hidden Module [Name: SdbShared.dll] Process: DataSafeOnline.exe (PID: 3016) Address: 0x00e20000 Size: 282624 Object: Hidden Module [Name: SdbUI.dll] Process: DataSafeOnline.exe (PID: 3016) Address: 0x00fc0000 Size: 110592 Object: Hidden Module [Name: SdbShared.XmlSerializers.dll] Process: DataSafeOnline.exe (PID: 3016) Address: 0x04190000 Size: 135168 Object: Hidden Module [Name: sprtmessage.dll] Process: sprtcmd.exe (PID: 5012) Address: 0x007e0000 Size: 77824 Object: Hidden Module [Name: SupportSoft.Agent.Sprocket.SupportMessage.dll] Process: sprtcmd.exe (PID: 5012) Address: 0x00870000 Size: 45056 Object: Hidden Module [Name: SupportSoft.Agent.Sprocket.dll] Process: sprtcmd.exe (PID: 5012) Address: 0x01770000 Size: 28672 Object: Hidden Code [ETHREAD: 0x846e17e8] Process: System Address: 0x8bc651e8 Size: - Object: Hidden Code [ETHREAD: 0x84706828] Process: System Address: 0x99fddc58 Size: - Object: Hidden Code [ETHREAD: 0x84706580] Process: System Address: 0x80d1c1e8 Size: - Object: Hidden Code [ETHREAD: 0x847062d8] Process: System Address: 0x8bd22328 Size: - Object: Hidden Code [ETHREAD: 0x84707d78] Process: System Address: 0x84707f6c Size: - Object: Hidden Code [ETHREAD: 0x84707ad0] Process: System Address: 0x84707cc4 Size: - Object: Hidden Code [ETHREAD: 0x84707828] Process: System Address: 0xa0ff77f0 Size: - Hidden Services ——————- Service Name: gaopdxserv.sys Image Path: C:\Windows\system32\drivers\gaopdxftgvapxqiutqbdoivpkewopiysuumwes.sys
Open RootRepeal Click Drivers tab and then Scan Right click on gaopdxserv.sys and select Force Delete Click the Files Tab and then Scan your C:\ drive Right click on C:\Windows\system32\drivers\gaopdxftgvapxqiutqbdoivpkewopiysuumwes.sys and select Force Delete Then reboot and post me a new RootRepeal log
I did what you asked but I couldn't find any of those files. I restarted the computer and scanned each again and still nothing showed up, what should I do?
do this

Please download ATF Cleaner by Atribune.
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.




Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.






Go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button. Then post it here.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI