This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Trojan Virtumonde

16 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,
I keep getting pop-ups advertising many things including recommended anti-malware software. My Spyware Doctor and AVG have found Trojan Virtumonde. Following a previous thread on Whatthetech I ran VundoFix which said that it didn't find anything, and ComboFix and HiJackThis. The log files are given below and any help is greatly appreciated!

VundoFix.txt


VundoFix V7.0.6

Scan started at 23:16:52 09/04/2009

Listing files found while scanning….

No infected files were found.


VundoFix V7.0.6

Scan started at 15:18:46 10/04/2009

Listing files found while scanning….

No infected files were found.


Beginning removal…

——————————-

ComboFix.txt

ComboFix 09-04-04.01 - Glenn 2009-04-10 15:56:22.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.477 [GMT 1:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated)
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\arawigav.ini
c:\windows\system32\drivers\seneka.sys
c:\windows\system32\drivers\senekaasmeixhx.sys
c:\windows\system32\drivers\senekairwjsyly.sys
c:\windows\system32\drivers\senekaohqxmqfy.sys
c:\windows\system32\drivers\senekapbneolew.sys
c:\windows\system32\drivers\senekaqhuwslik.sys
c:\windows\system32\drivers\senekassfoepav.sys
c:\windows\system32\drivers\senekatfuwnkvv.sys
c:\windows\system32\drivers\senekattpiqqoe.sys
c:\windows\system32\drivers\senekayegapqdl.sys
c:\windows\system32\hopawiki.dll
c:\windows\system32\pthreadVC.dll
c:\windows\system32\senekaappqxvea.dll
c:\windows\system32\senekacfawbwwb.dll
c:\windows\system32\senekacfmlyeey.dll
c:\windows\system32\senekacjpeqqwx.dll
c:\windows\system32\senekacvnfyats.dll
c:\windows\system32\senekaecbqylby.dll
c:\windows\system32\senekaetjeycfm.dat
c:\windows\system32\senekahostyjai.dll
c:\windows\system32\senekahxrwcnlr.dll
c:\windows\system32\senekaiksmcego.dat
c:\windows\system32\senekaiqppptxd.dll
c:\windows\system32\senekaivrxbdmu.dll
c:\windows\system32\senekakigyupbm.dll
c:\windows\system32\senekamxbejwcd.dat
c:\windows\system32\senekamyxwerdt.dat
c:\windows\system32\senekanidrtfpc.dat
c:\windows\system32\senekannxwbjri.dll
c:\windows\system32\senekanokhlral.dat
c:\windows\system32\senekanrilfpaf.dat
c:\windows\system32\senekaofhkymcx.dat
c:\windows\system32\senekapfpmpeqr.dll
c:\windows\system32\senekaqkiltpuq.dll
c:\windows\system32\senekasxmulrqj.dll
c:\windows\system32\senekatwuffdxi.dat
c:\windows\system32\senekauthqfgoi.dll
c:\windows\system32\senekaxmwrejcx.dat

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_SENEKA
——-\Legacy_NPF


((((((((((((((((((((((((( Files Created from 2009-03-10 to 2009-04-10 )))))))))))))))))))))))))))))))
.

2009-04-10 15:40 . 2009-04-10 15:47 d——– C:\32788R22FWJFW
2009-04-10 15:40 . 2006-03-03 00:42 73,728 –a—— C:\pv.exe
2009-04-10 10:27 . 2009-04-10 10:27 46,592 –a—— c:\windows\system32\wininstall.exe
2009-04-10 01:19 . 2009-04-10 01:21 d——– c:\program files\Spybot - Search & Destroy
2009-04-10 01:19 . 2009-04-10 02:00 d——– c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-04-09 23:16 . 2009-04-09 23:16 d——– C:\VundoFix Backups
2009-04-09 01:00 . 2009-04-09 01:00 d——– c:\windows\system32\KB905474
2009-04-09 01:00 . 2009-03-10 22:26 1,403,264 –a—— c:\windows\system32\KB905474\wganotifypackageinner.exe
2009-04-09 01:00 . 2009-03-10 22:18 453,512 –a—— c:\windows\system32\KB905474\wgasetup.exe
2009-04-09 01:00 . 2009-02-09 18:51 12,490 –a—— c:\windows\system32\KB905474\wga_eula.txt
2009-04-03 00:38 . 2009-04-03 00:38 54,156 –ah—– c:\windows\QTFont.qfn
2009-04-03 00:38 . 2009-04-03 00:38 1,409 –a—— c:\windows\QTFont.for

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-10 15:03 ——— d—a-w c:\documents and settings\All Users\Application Data\TEMP
2009-04-10 15:02 ——— d—–w c:\program files\DNA
2009-04-10 15:02 ——— d—–w c:\documents and settings\Glenn\Application Data\DNA
2009-04-10 11:57 ——— d—–w c:\program files\Spyware Doctor
2009-04-10 11:22 ——— d—–w c:\documents and settings\Glenn\Application Data\Pro Cycling Manager 2007
2009-04-09 20:47 ——— d—–w c:\documents and settings\All Users\Application Data\avg8
2009-04-09 20:29 ——— d—–w c:\documents and settings\All Users\Application Data\Google Updater
2009-04-09 18:58 ——— d—–w c:\program files\Java
2009-04-07 23:26 ——— d—–w c:\documents and settings\Glenn\Application Data\BitTorrent
2009-04-06 23:10 ——— d—–w c:\program files\Football Manager 2006
2009-03-06 19:08 ——— d—–w c:\documents and settings\Glenn\Application Data\dvdcss
2009-03-05 21:11 ——— d—–w c:\program files\Common Files\Adobe
2009-03-05 00:14 ——— d—–w c:\documents and settings\All Users\Application Data\Adobe Systems
2009-03-05 00:13 ——— d—–w c:\program files\Common Files\Adobe Systems Shared
2009-02-28 17:30 ——— d—–w c:\program files\Soulseek
2009-02-22 16:15 ——— d—a-w c:\documents and settings\All Users\Application Data\Sports Interactive
2009-02-22 16:00 ——— d—–w c:\documents and settings\Glenn\Application Data\Sports Interactive
2009-02-22 15:54 ——— d–h–w c:\program files\Zero G Registry
2009-02-22 15:47 ——— d—–w c:\program files\Sports Interactive
2009-02-22 15:17 ——— d—–w c:\program files\Football Manager 2009
2009-02-22 01:00 ——— d—–w c:\program files\FinePixViewer
2009-02-12 17:56 ——— d—–w c:\program files\Google
2008-06-14 21:43 33,904 —-a-w c:\documents and settings\Glenn\Application Data\GDIPFONTCACHEV1.DAT
2008-03-30 18:15 32 —-a-w c:\documents and settings\All Users\Application Data\ezsid.dat
2006-02-03 19:19 56 –sh–r c:\windows\system32\BA025EC27E.sys
2006-04-05 17:13 56 –sh–r c:\windows\system32\F1AB804D5A.sys
2006-08-05 21:28 2,828 –sha-w c:\windows\system32\KGyGaAvL.sys
2008-11-28 13:34 32,768 –sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008112820081129\index.dat
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2008-12-16 342848]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-12-29 687560]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-07-20 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-07-20 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-07-20 114688]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 53248]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-01-11 98304]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-12-06 127035]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"MSKDetectorExe"="c:\program files\McAfee\SpamKiller\MSKDetct.exe" [2006-11-07 1121280]
"PWRISOVM.EXE"="c:\program files\PowerISO\PWRISOVM.EXE" [2007-04-09 200704]
"tsnpstd3"="c:\windows\tsnpstd3.exe" [2005-12-20 94208]
"snpstd3"="c:\windows\vsnpstd3.exe" [2006-09-19 827392]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384]
"REGSHAVE"="c:\program files\REGSHAVE\REGSHAVE.EXE" [2002-02-04 53248]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-01-29 1601304]
"ISTray"="c:\program files\Spyware Doctor\pctsTray.exe" [2008-11-03 1168264]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-06-29 185896]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\Glenn\Start Menu\Programs\Startup\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2006-01-19 108544]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
ExifLauncher2.lnk - c:\program files\FinePixViewer\QuickDCF2.exe [2008-02-07 303104]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]
NkvMon.exe.lnk - c:\program files\Nikon\NkView6\NkvMon.exe [2006-01-17 233472]
QuickTV.lnk - c:\program files\AVerTV USB 2.0 Plus\QuickTV.exe [2005-06-24 401408]
WlanUtility.lnk - c:\program files\MicroStar\WLANUtility\WlanUtility.exe [2005-10-14 173056]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-01-29 21:05 10520 c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\SmartFTP Client 2.0\\SmartFTP.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\WebEye\\WebEye.exe"=
"c:\\Program Files\\GameCenter\\GameCenter.exe"=
"c:\\Program Files\\Pro Cycling Manager 2007\\PCM.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\Zattoo\\zattood.exe"=
"c:\\Program Files\\Zattoo\\Zattoo2.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Zattoo\\Zattoo.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\MicroStar\\WLANUtility\\APUtility.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Sports Interactive\\Football Manager 2009\\fm.exe"=

R0 pe3akt6c;Cycling Manager 2007 Environment Driver (pe3akt6c);c:\windows\system32\drivers\pe3akt6c.sys [2007-06-08 64912]
R0 pf2akt6c;Cycling Manager 2007 File System Driver (pf2akt6c);c:\windows\system32\drivers\pf2akt6c.sys [2007-06-08 83856]
R0 ps6akt6c;Cycling Manager 2007 Synchronization Driver (ps6akt6c);c:\windows\system32\drivers\ps6akt6c.sys [2007-06-08 55704]
R0 ps7akt6c;Cycling Manager 2007 Synchronization Driver (ps7akt6c);c:\windows\system32\drivers\ps7akt6c.sys [2007-09-28 68752]
R1 Asapi;Asapi;c:\windows\system32\drivers\asapi.sys [2006-02-05 10240]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-05-10 325128]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2008-05-10 107272]
R2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2008-07-04 903960]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2008-07-04 298264]
R2 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [2008-06-08 356920]
R3 StkMini;AVerTV USB 2.0 Plus Video Capture;c:\windows\system32\drivers\StkMini.sys [2005-02-15 185792]
S2 gupdate1c98b04c8dcc954;Google Update Service (gupdate1c98b04c8dcc954);c:\program files\Google\Update\GoogleUpdate.exe [2009-02-09 133104]
S2 pr2akt6c;Cycling Manager 2007 Drivers Auto Removal (pr2akt6c);c:\windows\system32\pr2akt6c.exe svc –> c:\windows\system32\pr2akt6c.exe svc [?]

— Other Services/Drivers In Memory —

*Deregistered* - mchInjDrv

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d9ee93ab-867a-11dd-a58e-0011092a4082}]
\Shell\AutoRun\command - G:\setupSNK.exe
.
Contents of the 'Scheduled Tasks' folder

2009-04-10 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-03-25 20:10]

2009-04-10 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-09 23:21]

2009-04-10 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2009-03-10 22:18]
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-mepoliluba - c:\windows\system32\tegawula.dll
HKLM-Run-pdfSaver3 - (no file)
SharedTaskScheduler-{EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\hopawiki.dll


.
——- Supplementary Scan ——-
.
uInternet Connection Wizard,ShellNext = hxxp://www.dell.co.uk/myway
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office10\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Glenn\Application Data\Mozilla\Firefox\Profiles\7xvfgbuy.Default User\
FF - prefs.js: browser.startup.homepage - hxxp://login.live.com/login.srf?id=2
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.141.5\npGoogleOneClick7.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
.

**************************************************************************

catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-04-10 16:03:28
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-38622347-797492410-3121079378-1005\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{F9D82965-1D6E-A4D7-1258-C3C5977145A7}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"iaijeaodligifknoag"=hex:6b,61,6a,63,67,67,70,6d,6d,6a,6a,6b,6a,70,66,6e,63,68,
6e,69,70,62,00,00
"haoicpfecgfoohhf"=hex:6b,61,6d,63,61,6b,64,69,62,69,66,63,66,70,70,6b,68,62,
65,68,6c,67,00,00
.
———————— Other Running Processes ————————
.
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\program files\Spyware Doctor\pctsSvc.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\program files\Spyware Doctor\sdhelp.exe
c:\program files\AVG\AVG8\avgcsrvx.exe
c:\windows\system32\wscntfy.exe
c:\program files\MicroStar\WLANUtility\WLAN_Service.exe
.
**************************************************************************
.
Completion time: 2009-04-10 16:08:41 - machine was rebooted
ComboFix-quarantined-files.txt 2009-04-10 15:08:37

Pre-Run: 66,421,383,168 bytes free
Post-Run: 66,350,477,312 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

247 — E O F — 2009-04-09 00:00:53


———————————————

Hijackthis.txt

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:42:49, on 10/04/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\WINDOWS\tsnpstd3.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DNA\btdna.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\FinePixViewer\QuickDCF2.exe
C:\Program Files\Nikon\NkView6\NkvMon.exe
C:\Program Files\AVerTV USB 2.0 Plus\QuickTV.exe
C:\Program Files\MicroStar\WLANUtility\WlanUtility.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\MicroStar\WLANUtility\WLAN_Service.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell.co.uk/myway
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll (file missing)
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll (file missing)
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [tsnpstd3] C:\WINDOWS\tsnpstd3.exe
O4 - HKLM\..\Run: [snpstd3] C:\WINDOWS\vsnpstd3.exe
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: ExifLauncher2.lnk = C:\Program Files\FinePixViewer\QuickDCF2.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: NkvMon.exe.lnk = C:\Program Files\Nikon\NkView6\NkvMon.exe
O4 - Global Startup: QuickTV.lnk = C:\Program Files\AVerTV USB 2.0 Plus\QuickTV.exe
O4 - Global Startup: WlanUtility.lnk = C:\Program Files\MicroStar\WLANUtility\WlanUtility.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1138911712031
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Google Update Service (gupdate1c98b04c8dcc954) (gupdate1c98b04c8dcc954) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Imapi Helper - Alex Feinman - C:\Program Files\ISO Recorder\ImapiHelper.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Cycling Manager 2007 Drivers Auto Removal (pr2akt6c) (pr2akt6c) - Cyanide - C:\WINDOWS\system32\pr2akt6c.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe

–
End of file - 9856 bytes
Hello.

You had a nasty infection.

[external image: Posted Image]Rootkit Threat

Unfortunatly One or more of the identified infections is a Rootkit/backdoor trojan.

IMPORTANT NOTE: Rootkits and backdoor Trojans are very dangerous because they use advanced techniques (backdoors) as a means of accessing a computer system that bypasses security mechanisms and steal sensitive information which they send back to the hacker. Many rootkits can hook into the Windows 32-bit kernel, and patch several APIs to hide new registry keys and files they install. Remote attackers use backdoor Trojans and rootkits as part of an exploit to gain unauthorized access to a computer and take control of it without your knowledge.

If your computer was used for online banking, has credit card information or other sensitive data on it, you should immediately disconnect from the Internet until your system is cleaned. All passwords should be changed immediately to include those used for banking, email, eBay, paypal and online forums. You should consider them to be compromised. You should change each password by using a different computer and not the infected one. If not, an attacker may get the new passwords and transaction information. If using a router, you need to reset it with a strong logon/password so the malware cannot gain control before connect again. Banking and credit card institutions should be notified of the possible security breach. Because your computer was compromised please read How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud?

Although the rootkit has been identified and may be removed, your PC has likely been compromised and there is no way to be sure the computer can ever be trusted again. It is dangerous and incorrect to assume that because this malware has been removed the computer is now secure. In some instances an infection may have caused so much damage to your system that it cannot be completely cleaned or repaired. The malware may leave so many remnants behind that security tools cannot find them. Many experts in the security community believe that once infected with this type of malware, the best course of action is to wipe the drive clean, reformat and reinstall the OS. Please read: Should you decide not to follow that advice, we will do our best to help clean the computer of any infections but we cannot guarantee it to be trustworthy or that the removal will be successful. Tell me what you want to do.

With Regards,
Extremeboy
Thanks Extremeboy Sounds bad. I've just done a little more research and I would like some more help to at least try to get rid of it, if possible. I can use other machines for internet use and only use my infected one offline to try to zap the trojan. I noticed in my registry that there is something called BOWebAgent. Is this the Back Orifice trojan, and should I remove it from the system? I'm certainly no expert on this BTW! Cheers! Sooth
Hello.

I apologize for the delay. Seems like I forgot about this topic. As stated in my signature, if I ever don't reply within 48 hours unless stated otherwise, feel free to PM me ;)

Let's see what there's left on your computer.

Please delete Combofix.exe you have right now on your desktop.

Re-download it from one of the following locations and save it onto your desktop.

Link 1
Link 2
Link 3

Double click on Combofix and follow the prompts to run it. Once it's finished post back with the log.

Please alos run GMER for me.

Download and Run Scan with GMER

We will use GMER to scan for rootkits.
  • Double-click on Gmer.exe to start the program.
  • Allow the gmer.sys driver to load if asked.
    If it detects rootkit activity, you will receive a prompt to run a full scan. Click Yes..
  • When it's done scanning, you may receive another notice. Click OK if prompted.
  • Click on Save … to save the log on your desktop.
    Save the log as GMER.txt when you save it on your desktop.
  • Close Gmer and copy and paste the contents of GMER.txt in your next reply.
  • If you receive no notice, click on the Scan button near the bottom.
  • It will start scanning again like before.
  • When it is done, Click on Save … to save the log on your desktop.
    Save the log as GMER.txt when you save it on your desktop.
  • Close Gmer and copy and paste the contents of GMER.txt in your next reply.If GMER doesn't work in Normal Mode try running it in Safe Mode

Note: Do Not run any program while GMER is running

Important!:Please do not select the Show all checkbox during the scan.

post back with:
-Combofix log
-GMER log

Thanks.

With Regards,
Extremeoby
No worries for the delay Extremeboy,

Here is the Combofix Log:

ComboFix 09-04-17.01 - Glenn 16/04/2009 18:29.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.529 [GMT 1:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated)
* Created a new restore point
.

((((((((((((((((((((((((( Files Created from 2009-03-17 to 2009-04-17 )))))))))))))))))))))))))))))))
.

2009-04-16 17:13 . 2009-04-16 17:13 ——– d—–w c:\windows\LastGood
2009-04-14 23:17 . 2009-04-14 23:17 758 —ha-w C:\aaw7boot.cmd
2009-04-14 21:53 . 2009-04-14 23:20 ——– dc—-w c:\windows\system32\DRVSTORE
2009-04-14 21:52 . 2009-04-14 23:21 ——– d—–w c:\documents and settings\All Users\Application Data\Lavasoft
2009-04-14 19:58 . 2009-04-14 21:49 ——– d—–w c:\documents and settings\Glenn\.housecall6.6
2009-04-14 19:42 . 2009-04-14 19:42 ——– d—–w c:\program files\CCleaner
2009-04-10 15:42 . 2009-04-10 15:42 ——– d—–w c:\program files\Trend Micro
2009-04-10 00:19 . 2009-04-14 23:24 ——– d—–w c:\program files\Spybot - Search & Destroy
2009-04-10 00:19 . 2009-04-14 23:24 ——– d—–w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-04-09 22:16 . 2009-04-09 22:16 ——– d—–w C:\VundoFix Backups

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-16 17:28 . 2008-10-18 09:14 ——– d—–w c:\documents and settings\Glenn\Application Data\DNA
2009-04-16 17:09 . 2008-06-08 22:22 ——– d—a-w c:\documents and settings\All Users\Application Data\TEMP
2009-04-16 17:08 . 2008-10-18 09:14 ——– d—–w c:\program files\DNA
2009-04-15 23:33 . 2007-07-11 18:33 ——– d—–w c:\documents and settings\Glenn\Application Data\Pro Cycling Manager 2007
2009-04-15 18:47 . 2006-06-11 11:21 ——– d—–w c:\program files\Spyware Doctor
2009-04-15 18:15 . 2008-05-10 10:24 108552 —-a-w c:\windows\system32\drivers\avgtdix.sys
2009-04-15 18:15 . 2008-05-10 10:24 325640 —-a-w c:\windows\system32\drivers\avgldx86.sys
2009-04-15 18:15 . 2008-05-10 10:24 10520 —-a-w c:\windows\system32\avgrsstx.dll
2009-04-15 18:14 . 2008-05-10 10:23 ——– d—–w c:\documents and settings\All Users\Application Data\avg8
2009-04-14 23:21 . 2006-06-11 14:51 ——– d—–w c:\program files\Lavasoft
2009-04-11 22:47 . 2008-06-08 22:20 ——– d—–w c:\documents and settings\All Users\Application Data\Google Updater
2009-04-10 14:38 . 2009-04-09 22:16 294 —-a-w C:\VundoFix.txt
2009-04-09 20:29 . 2009-01-09 20:29 51200 –sha-w c:\windows\system32\fuhubuga.exe
2009-04-09 18:58 . 2006-01-11 11:24 ——– d—–w c:\program files\Java
2009-04-07 23:26 . 2006-02-05 15:42 ——– d—–w c:\documents and settings\Glenn\Application Data\BitTorrent
2009-04-06 23:10 . 2006-02-01 21:02 ——– d—–w c:\program files\Football Manager 2006
2009-04-04 18:13 . 2006-01-16 23:49 34680 —-a-w c:\documents and settings\Glenn\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-03-29 14:06 . 2006-01-19 21:26 75 —-a-w C:\audiodec.txt
2009-03-09 04:19 . 2008-12-08 18:51 410984 —-a-w c:\windows\system32\deploytk.dll
2009-03-06 19:08 . 2009-03-06 19:08 ——– d—–w c:\documents and settings\Glenn\Application Data\dvdcss
2009-03-05 21:11 . 2006-01-17 20:40 ——– d—–w c:\program files\Common Files\Adobe
2009-03-05 00:14 . 2009-03-05 00:14 ——– d—–w c:\documents and settings\All Users\Application Data\Adobe Systems
2009-03-05 00:13 . 2009-03-05 00:13 ——– d—–w c:\program files\Common Files\Adobe Systems Shared
2009-02-28 17:30 . 2006-05-14 13:34 ——– d—–w c:\program files\Soulseek
2009-02-22 16:15 . 2009-02-22 16:00 ——– d—a-w c:\documents and settings\All Users\Application Data\Sports Interactive
2009-02-22 16:00 . 2009-02-22 16:00 ——– d—–w c:\documents and settings\Glenn\Application Data\Sports Interactive
2009-02-22 15:54 . 2009-02-22 15:47 ——– d–h–w c:\program files\Zero G Registry
2009-02-22 15:47 . 2009-02-22 15:47 ——– d—–w c:\program files\Sports Interactive
2009-02-22 15:17 . 2009-02-22 15:17 ——– d—–w c:\program files\Football Manager 2009
2009-02-22 01:00 . 2008-02-07 22:48 ——– d—–w c:\program files\FinePixViewer
2009-02-09 11:13 . 2008-10-15 22:41 1846784 ——w c:\windows\system32\dllcache\win32k.sys
2009-02-09 11:13 . 2004-08-11 17:00 1846784 —-a-w c:\windows\system32\win32k.sys
2009-01-16 21:35 . 2006-05-19 15:06 3594752 —-a-w c:\windows\system32\dllcache\mshtml.dll
2008-06-14 21:43 . 2008-06-14 21:43 33904 —-a-w c:\documents and settings\Glenn\Application Data\GDIPFONTCACHEV1.DAT
2008-03-30 18:15 . 2008-03-30 18:15 32 —-a-w c:\documents and settings\All Users\Application Data\ezsid.dat
2006-01-17 00:36 . 2006-01-17 00:36 128 —-a-w c:\documents and settings\Glenn\Local Settings\Application Data\fusioncache.dat
2006-02-03 19:19 . 2006-02-03 19:19 56 –sh–r c:\windows\system32\BA025EC27E.sys
2006-04-05 17:13 . 2006-01-19 21:23 56 –sh–r c:\windows\system32\F1AB804D5A.sys
2006-08-05 21:28 . 2006-08-05 21:28 2828 –sha-w c:\windows\system32\KGyGaAvL.sys
2008-11-28 13:34 . 2008-11-28 13:35 32768 –sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008112820081129\index.dat
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2008-12-16 342848]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-12-29 687560]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-07-19 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-07-19 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-07-19 114688]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 53248]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-01-11 98304]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-12-06 127035]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"MSKDetectorExe"="c:\program files\McAfee\SpamKiller\MSKDetct.exe" [2006-11-07 1121280]
"PWRISOVM.EXE"="c:\program files\PowerISO\PWRISOVM.EXE" [2007-04-09 200704]
"tsnpstd3"="c:\windows\tsnpstd3.exe" [2005-12-20 94208]
"snpstd3"="c:\windows\vsnpstd3.exe" [2006-09-19 827392]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384]
"REGSHAVE"="c:\program files\REGSHAVE\REGSHAVE.EXE" [2002-02-04 53248]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-04-15 1932568]
"ISTray"="c:\program files\Spyware Doctor\pctsTray.exe" [2008-11-02 1168264]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-06-29 185896]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\Glenn\Start Menu\Programs\Startup\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2006-1-19 108544]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
ExifLauncher2.lnk - c:\program files\FinePixViewer\QuickDCF2.exe [2008-2-7 303104]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
NkvMon.exe.lnk - c:\program files\Nikon\NkView6\NkvMon.exe [2006-1-17 233472]
QuickTV.lnk - c:\program files\AVerTV USB 2.0 Plus\QuickTV.exe [2005-6-24 401408]
WlanUtility.lnk - c:\program files\MicroStar\WLANUtility\WlanUtility.exe [2005-10-14 173056]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-04-15 18:15 10520 —-a-w c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\SmartFTP Client 2.0\\SmartFTP.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\WebEye\\WebEye.exe"=
"c:\\Program Files\\GameCenter\\GameCenter.exe"=
"c:\\Program Files\\Pro Cycling Manager 2007\\PCM.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\Zattoo\\zattood.exe"=
"c:\\Program Files\\Zattoo\\Zattoo2.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Zattoo\\Zattoo.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\MicroStar\\WLANUtility\\APUtility.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Sports Interactive\\Football Manager 2009\\fm.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=

R2 gupdate1c98b04c8dcc954;Google Update Service (gupdate1c98b04c8dcc954);c:\program files\Google\Update\GoogleUpdate.exe [2009-02-09 133104]
R2 pr2akt6c;Cycling Manager 2007 Drivers Auto Removal (pr2akt6c); [x]
S0 pe3akt6c;Cycling Manager 2007 Environment Driver (pe3akt6c);c:\windows\system32\drivers\pe3akt6c.sys [2007-06-08 64912]
S0 pf2akt6c;Cycling Manager 2007 File System Driver (pf2akt6c);c:\windows\system32\drivers\pf2akt6c.sys [2007-06-08 83856]
S0 ps6akt6c;Cycling Manager 2007 Synchronization Driver (ps6akt6c);c:\windows\system32\drivers\ps6akt6c.sys [2007-06-08 55704]
S0 ps7akt6c;Cycling Manager 2007 Synchronization Driver (ps7akt6c);c:\windows\system32\drivers\ps7akt6c.sys [2007-09-28 68752]
S1 Asapi;Asapi; [x]
S1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\System32\Drivers\avgldx86.sys [2009-04-15 325640]
S1 AvgTdiX;AVG8 Network Redirector;c:\windows\System32\Drivers\avgtdix.sys [2009-04-15 108552]
S2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2009-04-15 908056]
S2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-04-15 298264]
S2 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [2008-06-13 356920]
S3 StkMini;AVerTV USB 2.0 Plus Video Capture;c:\windows\system32\Drivers\StkMini.sys [2005-02-15 185792]


— Other Services/Drivers In Memory —

*Deregistered* - mchInjDrv

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d9ee93ab-867a-11dd-a58e-0011092a4082}]
\Shell\AutoRun\command - G:\setupSNK.exe
.
Contents of the 'Scheduled Tasks' folder

2009-04-16 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-06-08 19:10]

2009-04-16 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-09 22:21]
.
.
——- Supplementary Scan ——-
.
uInternet Connection Wizard,ShellNext = hxxp://www.dell.co.uk/myway
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office10\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Glenn\Application Data\Mozilla\Firefox\Profiles\7xvfgbuy.Default User\
FF - prefs.js: browser.startup.homepage - hxxp://login.live.com/login.srf?id=2
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.141.5\npGoogleOneClick7.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
.

**************************************************************************

catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-04-16 18:34
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-38622347-797492410-3121079378-1005\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{F9D82965-1D6E-A4D7-1258-C3C5977145A7}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"iaijeaodligifknoag"=hex:6b,61,6a,63,67,67,70,6d,6d,6a,6a,6b,6a,70,66,6e,63,68,
6e,69,70,62,00,00
"haoicpfecgfoohhf"=hex:6b,61,6d,63,61,6b,64,69,62,69,66,63,66,70,70,6b,68,62,
65,68,6c,67,00,00
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(1364)
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2009-04-16 18:36
ComboFix-quarantined-files.txt 2009-04-16 17:36
ComboFix2.txt 2009-04-10 15:08

Pre-Run: 69,704,527,872 bytes free
Post-Run: 69,975,441,408 bytes free

194 — E O F — 2009-04-09 00:00



And the GMER log:

GMER 1.0.15.14966 - http://www.gmer.net
Rootkit scan 2009-04-16 20:02:35
Windows 5.1.2600 Service Pack 3


—- System - GMER 1.0.15 —-

SSDT sphv.sys ZwCreateKey [0xF733E0E0]
SSDT \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.) ZwCreateProcess [0xAA672794]
SSDT \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.) ZwCreateProcessEx [0xAA672F1E]
SSDT sphv.sys ZwEnumerateKey [0xF735CCA2]
SSDT sphv.sys ZwEnumerateValueKey [0xF735D030]
SSDT sphv.sys ZwOpenKey [0xF733E0C0]
SSDT sphv.sys ZwQueryKey [0xF735D108]
SSDT sphv.sys ZwQueryValueKey [0xF735CF88]
SSDT sphv.sys ZwSetValueKey [0xF735D19A]
SSDT \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.) ZwTerminateProcess [0xAA671D0A]
SSDT \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.) ZwWriteVirtualMemory [0xAA671384]

INT 0x62 ? 86FD6BF8
INT 0x63 ? 86FD6BF8
INT 0x63 ? 86FD6BF8
INT 0x63 ? 86FD6BF8
INT 0x84 ? 86E18BF8
INT 0x94 ? 86E18BF8
INT 0xA4 ? 86E18BF8
INT 0xB4 ? 86E18BF8

Code \??\C:\DOCUME~1\Glenn\LOCALS~1\Temp\catchme.sys pIofCallDriver

—- Kernel code sections - GMER 1.0.15 —-

? sphv.sys The system cannot find the file specified. !
.text USBPORT.SYS!DllUnload F652F8AC 5 Bytes JMP 86E181D8
? System32\Drivers\auicgk2m.SYS The system cannot find the path specified. !
? C:\WINDOWS\system32\Drivers\mchInjDrv.sys The system cannot find the file specified. !
? C:\DOCUME~1\Glenn\LOCALS~1\Temp\catchme.sys The system cannot find the file specified. !
? C:\WINDOWS\system32\Drivers\PROCEXP90.SYS The system cannot find the file specified. !

—- User code sections - GMER 1.0.15 —-

.text C:\WINDOWS\system32\igfxpers.exe[176] ntdll.dll!NtCreateSection 7C90D160 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\igfxpers.exe[176] ntdll.dll!NtCreateSection + 4 7C90D164 2 Bytes [05, 5F]
.text C:\WINDOWS\system32\igfxpers.exe[176] ntdll.dll!NtTerminateProcess 7C90DE50 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\igfxpers.exe[176] ntdll.dll!NtTerminateProcess + 4 7C90DE54 2 Bytes [0B, 5F]
.text C:\WINDOWS\system32\igfxpers.exe[176] ntdll.dll!NtWriteVirtualMemory 7C90DF90 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\igfxpers.exe[176] ntdll.dll!NtWriteVirtualMemory + 4 7C90DF94 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\WINDOWS\system32\igfxpers.exe[176] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 012F0001
.text C:\WINDOWS\system32\hkcmd.exe[184] ntdll.dll!NtCreateSection 7C90D160 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\hkcmd.exe[184] ntdll.dll!NtCreateSection + 4 7C90D164 2 Bytes [05, 5F]
.text C:\WINDOWS\system32\hkcmd.exe[184] ntdll.dll!NtTerminateProcess 7C90DE50 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\hkcmd.exe[184] ntdll.dll!NtTerminateProcess + 4 7C90DE54 2 Bytes [0B, 5F]
.text C:\WINDOWS\system32\hkcmd.exe[184] ntdll.dll!NtWriteVirtualMemory 7C90DF90 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\hkcmd.exe[184] ntdll.dll!NtWriteVirtualMemory + 4 7C90DF94 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\WINDOWS\system32\hkcmd.exe[184] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 01280001
.text C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe[208] ntdll.dll!NtCreateSection 7C90D160 3 Bytes [FF, 25, 1E]
.text C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe[208] ntdll.dll!NtCreateSection + 4 7C90D164 2 Bytes [05, 5F]
.text C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe[208] ntdll.dll!NtTerminateProcess 7C90DE50 3 Bytes [FF, 25, 1E]
.text C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe[208] ntdll.dll!NtTerminateProcess + 4 7C90DE54 2 Bytes [0B, 5F]
.text C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe[208] ntdll.dll!NtWriteVirtualMemory 7C90DF90 3 Bytes [FF, 25, 1E]
.text C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe[208] ntdll.dll!NtWriteVirtualMemory + 4 7C90DF94 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe[208] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 01180001
.text C:\WINDOWS\system32\dla\tfswctrl.exe[276] ntdll.dll!NtCreateSection 7C90D160 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\dla\tfswctrl.exe[276] ntdll.dll!NtCreateSection + 4 7C90D164 2 Bytes [05, 5F]
.text C:\WINDOWS\system32\dla\tfswctrl.exe[276] ntdll.dll!NtTerminateProcess 7C90DE50 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\dla\tfswctrl.exe[276] ntdll.dll!NtTerminateProcess + 4 7C90DE54 2 Bytes [0B, 5F]
.text C:\WINDOWS\system32\dla\tfswctrl.exe[276] ntdll.dll!NtWriteVirtualMemory 7C90DF90 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\dla\tfswctrl.exe[276] ntdll.dll!NtWriteVirtualMemory + 4 7C90DF94 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\WINDOWS\system32\dla\tfswctrl.exe[276] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 012C0001
.text C:\WINDOWS\system32\wscntfy.exe[280] ntdll.dll!NtCreateSection 7C90D160 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\wscntfy.exe[280] ntdll.dll!NtCreateSection + 4 7C90D164 2 Bytes [05, 5F]
.text C:\WINDOWS\system32\wscntfy.exe[280] ntdll.dll!NtTerminateProcess 7C90DE50 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\wscntfy.exe[280] ntdll.dll!NtTerminateProcess + 4 7C90DE54 2 Bytes [0B, 5F]
.text C:\WINDOWS\system32\wscntfy.exe[280] ntdll.dll!NtWriteVirtualMemory 7C90DF90 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\wscntfy.exe[280] ntdll.dll!NtWriteVirtualMemory + 4 7C90DF94 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\WINDOWS\system32\wscntfy.exe[280] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 009F0001
.text C:\WINDOWS\system32\wscntfy.exe[280] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes CALL 7170003D
.text C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe[308] ntdll.dll!NtCreateSection 7C90D160 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe[308] ntdll.dll!NtCreateSection + 4 7C90D164 2 Bytes [05, 5F]
.text C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe[308] ntdll.dll!NtTerminateProcess 7C90DE50 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe[308] ntdll.dll!NtTerminateProcess + 4 7C90DE54 2 Bytes [0B, 5F]
.text C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe[308] ntdll.dll!NtWriteVirtualMemory 7C90DF90 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe[308] ntdll.dll!NtWriteVirtualMemory + 4 7C90DF94 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe[308] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00B90001
.text C:\Program Files\PowerISO\PWRISOVM.EXE[352] ntdll.dll!NtCreateSection 7C90D160 3 Bytes [FF, 25, 1E]
.text C:\Program Files\PowerISO\PWRISOVM.EXE[352] ntdll.dll!NtCreateSection + 4 7C90D164 2 Bytes [05, 5F]
.text C:\Program Files\PowerISO\PWRISOVM.EXE[352] ntdll.dll!NtTerminateProcess 7C90DE50 3 Bytes [FF, 25, 1E]
.text C:\Program Files\PowerISO\PWRISOVM.EXE[352] ntdll.dll!NtTerminateProcess + 4 7C90DE54 2 Bytes [0B, 5F]
.text C:\Program Files\PowerISO\PWRISOVM.EXE[352] ntdll.dll!NtWriteVirtualMemory 7C90DF90 3 Bytes [FF, 25, 1E]
.text C:\Program Files\PowerISO\PWRISOVM.EXE[352] ntdll.dll!NtWriteVirtualMemory + 4 7C90DF94 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\PowerISO\PWRISOVM.EXE[352] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00920001
.text C:\Program Files\DAEMON Tools Lite\daemon.exe[400] ntdll.dll!NtCreateSection 7C90D160 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DAEMON Tools Lite\daemon.exe[400] ntdll.dll!NtCreateSection + 4 7C90D164 2 Bytes [05, 5F]
.text C:\Program Files\DAEMON Tools Lite\daemon.exe[400] ntdll.dll!NtTerminateProcess 7C90DE50 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DAEMON Tools Lite\daemon.exe[400] ntdll.dll!NtTerminateProcess + 4 7C90DE54 2 Bytes [0B, 5F]
.text C:\Program Files\DAEMON Tools Lite\daemon.exe[400] ntdll.dll!NtWriteVirtualMemory 7C90DF90 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DAEMON Tools Lite\daemon.exe[400] ntdll.dll!NtWriteVirtualMemory + 4 7C90DF94 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\DAEMON Tools Lite\daemon.exe[400] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 021F0001
.text C:\WINDOWS\tsnpstd3.exe[408] ntdll.dll!NtCreateSection 7C90D160 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\tsnpstd3.exe[408] ntdll.dll!NtCreateSection + 4 7C90D164 2 Bytes [05, 5F]
.text C:\WINDOWS\tsnpstd3.exe[408] ntdll.dll!NtTerminateProcess 7C90DE50 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\tsnpstd3.exe[408] ntdll.dll!NtTerminateProcess + 4 7C90DE54 2 Bytes [0B, 5F]
.text C:\WINDOWS\tsnpstd3.exe[408] ntdll.dll!NtWriteVirtualMemory 7C90DF90 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\tsnpstd3.exe[408] ntdll.dll!NtWriteVirtualMemory + 4 7C90DF94 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\WINDOWS\tsnpstd3.exe[408] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00CA0001
.text C:\PROGRA~1\AVG\AVG8\avgtray.exe[472] ntdll.dll!NtCreateSection 7C90D160 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\AVG\AVG8\avgtray.exe[472] ntdll.dll!NtCreateSection + 4 7C90D164 2 Bytes [05, 5F]
.text C:\PROGRA~1\AVG\AVG8\avgtray.exe[472] ntdll.dll!NtTerminateProcess 7C90DE50 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\AVG\AVG8\avgtray.exe[472] ntdll.dll!NtTerminateProcess + 4 7C90DE54 2 Bytes [0B, 5F]
.text C:\PROGRA~1\AVG\AVG8\avgtray.exe[472] ntdll.dll!NtWriteVirtualMemory 7C90DF90 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\AVG\AVG8\avgtray.exe[472] ntdll.dll!NtWriteVirtualMemory + 4 7C90DF94 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\PROGRA~1\AVG\AVG8\avgtray.exe[472] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 01B40001
.text C:\Program Files\Spyware Doctor\pctsTray.exe[496] kernel32.dll!CreateThread + 1A 7C8106E1 4 Bytes CALL 0044A81D C:\Program Files\Spyware Doctor\pctsTray.exe (PC Tools Tray Application/PC Tools)
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[520] ntdll.dll!NtCreateSection 7C90D160 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[520] ntdll.dll!NtCreateSection + 4 7C90D164 2 Bytes [05, 5F]
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[520] ntdll.dll!NtTerminateProcess 7C90DE50 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[520] ntdll.dll!NtTerminateProcess + 4 7C90DE54 2 Bytes [0B, 5F]
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[520] ntdll.dll!NtWriteVirtualMemory 7C90DF90 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[520] ntdll.dll!NtWriteVirtualMemory + 4 7C90DF94 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[520] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 013A0001
.text C:\Program Files\Java\jre6\bin\jusched.exe[528] ntdll.dll!NtCreateSection 7C90D160 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Java\jre6\bin\jusched.exe[528] ntdll.dll!NtCreateSection + 4 7C90D164 2 Bytes [05, 5F]
.text C:\Program Files\Java\jre6\bin\jusched.exe[528] ntdll.dll!NtTerminateProcess 7C90DE50 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Java\jre6\bin\jusched.exe[528] ntdll.dll!NtTerminateProcess + 4 7C90DE54 2 Bytes [0B, 5F]
.text C:\Program Files\Java\jre6\bin\jusched.exe[528] ntdll.dll!NtWriteVirtualMemory 7C90DF90 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Java\jre6\bin\jusched.exe[528] ntdll.dll!NtWriteVirtualMemory + 4 7C90DF94 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Java\jre6\bin\jusched.exe[528] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00E70001
.text C:\WINDOWS\system32\ctfmon.exe[552] ntdll.dll!NtCreateSection 7C90D160 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\ctfmon.exe[552] ntdll.dll!NtCreateSection + 4 7C90D164 2 Bytes [05, 5F]
.text C:\WINDOWS\system32\ctfmon.exe[552] ntdll.dll!NtTerminateProcess 7C90DE50 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\ctfmon.exe[552] ntdll.dll!NtTerminateProcess + 4 7C90DE54 2 Bytes [0B, 5F]
.text C:\WINDOWS\system32\ctfmon.exe[552] ntdll.dll!NtWriteVirtualMemory 7C90DF90 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\ctfmon.exe[552] ntdll.dll!NtWriteVirtualMemory + 4 7C90DF94 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\WINDOWS\system32\ctfmon.exe[552] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00D20001
.text C:\Program Files\DNA\btdna.exe[568] ntdll.dll!NtCreateSection 7C90D160 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DNA\btdna.exe[568] ntdll.dll!NtCreateSection + 4 7C90D164 2 Bytes [05, 5F]
.text C:\Program Files\DNA\btdna.exe[568] ntdll.dll!NtTerminateProcess 7C90DE50 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DNA\btdna.exe[568] ntdll.dll!NtTerminateProcess + 4 7C90DE54 2 Bytes [0B, 5F]
.text C:\Program Files\DNA\btdna.exe[568] ntdll.dll!NtWriteVirtualMemory 7C90DF90 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DNA\btdna.exe[568] ntdll.dll!NtWriteVirtualMemory + 4 7C90DF94 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\DNA\btdna.exe[568] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 01BA0001
.text C:\Program Files\FinePixViewer\QuickDCF2.exe[676] ntdll.dll!NtCreateSection 7C90D160 3 Bytes [FF, 25, 1E]
.text C:\Program Files\FinePixViewer\QuickDCF2.exe[676] ntdll.dll!NtCreateSection + 4 7C90D164 2 Bytes [05, 5F]
.text C:\Program Files\FinePixViewer\QuickDCF2.exe[676] ntdll.dll!NtTerminateProcess 7C90DE50 3 Bytes [FF, 25, 1E]
.text C:\Program Files\FinePixViewer\QuickDCF2.exe[676] ntdll.dll!NtTerminateProcess + 4 7C90DE54 2 Bytes [0B, 5F]
.text C:\Program Files\FinePixViewer\QuickDCF2.exe[676] ntdll.dll!NtWriteVirtualMemory 7C90DF90 3 Bytes [FF, 25, 1E]
.text C:\Program Files\FinePixViewer\QuickDCF2.exe[676] ntdll.dll!NtWriteVirtualMemory + 4 7C90DF94 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\FinePixViewer\QuickDCF2.exe[676] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 01260001
.text C:\WINDOWS\system32\csrss.exe[700] ntdll.dll!NtCreateSection 7C90D160 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\csrss.exe[700] ntdll.dll!NtCreateSection + 4 7C90D164 2 Bytes [05, 5F]
.text C:\WINDOWS\system32\csrss.exe[700] ntdll.dll!NtTerminateProcess 7C90DE50 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\csrss.exe[700] ntdll.dll!NtTerminateProcess + 4 7C90DE54 2 Bytes [0B, 5F]
.text C:\WINDOWS\system32\csrss.exe[700] ntdll.dll!NtWriteVirtualMemory 7C90DF90 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\csrss.exe[700] ntdll.dll!NtWriteVirtualMemory + 4 7C90DF94 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\WINDOWS\system32\csrss.exe[700] KERNEL32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 016C0001
.text C:\WINDOWS\system32\winlogon.exe[724] ntdll.dll!NtCreateSection 7C90D160 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\winlogon.exe[724] ntdll.dll!NtCreateSection + 4 7C90D164 2 Bytes [05, 5F]
.text C:\WINDOWS\system32\winlogon.exe[724] ntdll.dll!NtTerminateProcess 7C90DE50 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\winlogon.exe[724] ntdll.dll!NtTerminateProcess + 4 7C90DE54 2 Bytes [0B, 5F]
.text C:\WINDOWS\system32\winlogon.exe[724] ntdll.dll!NtWriteVirtualMemory 7C90DF90 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\winlogon.exe[724] ntdll.dll!NtWriteVirtualMemory + 4 7C90DF94 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\WINDOWS\system32\winlogon.exe[724] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 011C0001
.text C:\WINDOWS\system32\services.exe[768] ntdll.dll!NtCreateSection 7C90D160 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\services.exe[768] ntdll.dll!NtCreateSection + 4 7C90D164 2 Bytes [05, 5F]
.text C:\WINDOWS\system32\services.exe[768] ntdll.dll!NtTerminateProcess 7C90DE50 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\services.exe[768] ntdll.dll!NtTerminateProcess + 4 7C90DE54 2 Bytes [0B, 5F]
.text C:\WINDOWS\system32\services.exe[768] ntdll.dll!NtWriteVirtualMemory 7C90DF90 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\services.exe[768] ntdll.dll!NtWriteVirtualMemory + 4 7C90DF94 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\WINDOWS\system32\services.exe[768] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00CD0001
.text C:\WINDOWS\system32\lsass.exe[780] ntdll.dll!NtCreateSection 7C90D160 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\lsass.exe[780] ntdll.dll!NtCreateSection + 4 7C90D164 2 Bytes [05, 5F]
.text C:\WINDOWS\system32\lsass.exe[780] ntdll.dll!NtTerminateProcess 7C90DE50 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\lsass.exe[780] ntdll.dll!NtTerminateProcess + 4 7C90DE54 2 Bytes [0B, 5F]
.text C:\WINDOWS\system32\lsass.exe[780] ntdll.dll!NtWriteVirtualMemory 7C90DF90 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\lsass.exe[780] ntdll.dll!NtWriteVirtualMemory + 4 7C90DF94 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\WINDOWS\system32\lsass.exe[780] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00F20001
.text C:\WINDOWS\system32\svchost.exe[980] ntdll.dll!NtCreateSection 7C90D160 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\svchost.exe[980] ntdll.dll!NtCreateSection + 4 7C90D164 2 Bytes [05, 5F]
.text C:\WINDOWS\system32\svchost.exe[980] ntdll.dll!NtTerminateProcess 7C90DE50 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\svchost.exe[980] ntdll.dll!NtTerminateProcess + 4 7C90DE54 2 Bytes [0B, 5F]
.text C:\WINDOWS\system32\svchost.exe[980] ntdll.dll!NtWriteVirtualMemory 7C90DF90 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\svchost.exe[980] ntdll.dll!NtWriteVirtualMemory + 4 7C90DF94 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\WINDOWS\system32\svchost.exe[980] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00F20001
.text C:\Program Files\Nikon\NkView6\NkvMon.exe[1032] ntdll.dll!NtCreateSection 7C90D160 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Nikon\NkView6\NkvMon.exe[1032] ntdll.dll!NtCreateSection + 4 7C90D164 2 Bytes [05, 5F]
.text C:\Program Files\Nikon\NkView6\NkvMon.exe[1032] ntdll.dll!NtTerminateProcess 7C90DE50 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Nikon\NkView6\NkvMon.exe[1032] ntdll.dll!NtTerminateProcess + 4 7C90DE54 2 Bytes [0B, 5F]
.text C:\Program Files\Nikon\NkView6\NkvMon.exe[1032] ntdll.dll!NtWriteVirtualMemory 7C90DF90 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Nikon\NkView6\NkvMon.exe[1032] ntdll.dll!NtWriteVirtualMemory + 4 7C90DF94 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Nikon\NkView6\NkvMon.exe[1032] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 01130001
.text C:\WINDOWS\system32\svchost.exe[1048] ntdll.dll!NtCreateSection 7C90D160 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\svchost.exe[1048] ntdll.dll!NtCreateSection + 4 7C90D164 2 Bytes [05, 5F]
.text C:\WINDOWS\system32\svchost.exe[1048] ntdll.dll!NtTerminateProcess 7C90DE50 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\svchost.exe[1048] ntdll.dll!NtTerminateProcess + 4 7C90DE54 2 Bytes [0B, 5F]
.text C:\WINDOWS\system32\svchost.exe[1048] ntdll.dll!NtWriteVirtualMemory 7C90DF90 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\svchost.exe[1048] ntdll.dll!NtWriteVirtualMemory + 4 7C90DF94 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\WINDOWS\system32\svchost.exe[1048] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00FD0001
.text C:\Program Files\AVerTV USB 2.0 Plus\QuickTV.exe[1104] ntdll.dll!NtCreateSection 7C90D160 3 Bytes [FF, 25, 1E]
.text C:\Program Files\AVerTV USB 2.0 Plus\QuickTV.exe[1104] ntdll.dll!NtCreateSection + 4 7C90D164 2 Bytes [05, 5F]
.text C:\Program Files\AVerTV USB 2.0 Plus\QuickTV.exe[1104] ntdll.dll!NtTerminateProcess 7C90DE50 3 Bytes [FF, 25, 1E]
.text C:\Program Files\AVerTV USB 2.0 Plus\QuickTV.exe[1104] ntdll.dll!NtTerminateProcess + 4 7C90DE54 2 Bytes [0B, 5F]
.text C:\Program Files\AVerTV USB 2.0 Plus\QuickTV.exe[1104] ntdll.dll!NtWriteVirtualMemory 7C90DF90 3 Bytes [FF, 25, 1E]
.text C:\Program Files\AVerTV USB 2.0 Plus\QuickTV.exe[1104] ntdll.dll!NtWriteVirtualMemory + 4 7C90DF94 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\AVerTV USB 2.0 Plus\QuickTV.exe[1104] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 013D0001
.text C:\WINDOWS\System32\svchost.exe[1144] ntdll.dll!NtCreateSection 7C90D160 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\System32\svchost.exe[1144] ntdll.dll!NtCreateSection + 4 7C90D164 2 Bytes [05, 5F]
.text C:\WINDOWS\System32\svchost.exe[1144] ntdll.dll!NtTerminateProcess 7C90DE50 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\System32\svchost.exe[1144] ntdll.dll!NtTerminateProcess + 4 7C90DE54 2 Bytes [0B, 5F]
.text C:\WINDOWS\System32\svchost.exe[1144] ntdll.dll!NtWriteVirtualMemory 7C90DF90 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\System32\svchost.exe[1144] ntdll.dll!NtWriteVirtualMemory + 4 7C90DF94 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\WINDOWS\System32\svchost.exe[1144] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 02CC0001
.text C:\Program Files\MicroStar\WLANUtility\WlanUtility.exe[1168] ntdll.dll!NtCreateSection 7C90D160 3 Bytes [FF, 25, 1E]
.text C:\Program Files\MicroStar\WLANUtility\WlanUtility.exe[1168] ntdll.dll!NtCreateSection + 4 7C90D164 2 Bytes [05, 5F]
.text C:\Program Files\MicroStar\WLANUtility\WlanUtility.exe[1168] ntdll.dll!NtTerminateProcess 7C90DE50 3 Bytes [FF, 25, 1E]
.text C:\Program Files\MicroStar\WLANUtility\WlanUtility.exe[1168] ntdll.dll!NtTerminateProcess + 4 7C90DE54 2 Bytes [0B, 5F]
.text C:\Program Files\MicroStar\WLANUtility\WlanUtility.exe[1168] ntdll.dll!NtWriteVirtualMemory 7C90DF90 3 Bytes [FF, 25, 1E]
.text C:\Program Files\MicroStar\WLANUtility\WlanUtility.exe[1168] ntdll.dll!NtWriteVirtualMemory + 4 7C90DF94 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\MicroStar\WLANUtility\WlanUtility.exe[1168] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00EE0001
.text C:\WINDOWS\system32\svchost.exe[1188] ntdll.dll!NtCreateSection 7C90D160 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\svchost.exe[1188] ntdll.dll!NtCreateSection + 4 7C90D164 2 Bytes [05, 5F]
.text C:\WINDOWS\system32\svchost.exe[1188] ntdll.dll!NtTerminateProcess 7C90DE50 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\svchost.exe[1188] ntdll.dll!NtTerminateProcess + 4 7C90DE54 2 Bytes [0B, 5F]
.text C:\WINDOWS\system32\svchost.exe[1188] ntdll.dll!NtWriteVirtualMemory 7C90DF90 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\svchost.exe[1188] ntdll.dll!NtWriteVirtualMemory + 4 7C90DF94 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\WINDOWS\system32\svchost.exe[1188] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00650001
.text C:\WINDOWS\system32\svchost.exe[1300] ntdll.dll!NtCreateSection 7C90D160 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\svchost.exe[1300] ntdll.dll!NtCreateSection + 4 7C90D164 2 Bytes [05, 5F]
.text C:\WINDOWS\system32\svchost.exe[1300] ntdll.dll!NtTerminateProcess 7C90DE50 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\svchost.exe[1300] ntdll.dll!NtTerminateProcess + 4 7C90DE54 2 Bytes [0B, 5F]
.text C:\WINDOWS\system32\svchost.exe[1300] ntdll.dll!NtWriteVirtualMemory 7C90DF90 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\svchost.exe[1300] ntdll.dll!NtWriteVirtualMemory + 4 7C90DF94 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\WINDOWS\system32\svchost.exe[1300] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00AE0001
.text C:\WINDOWS\explorer.exe[1364] ntdll.dll!NtCreateSection 7C90D160 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\explorer.exe[1364] ntdll.dll!NtCreateSection + 4 7C90D164 2 Bytes [05, 5F]
.text C:\WINDOWS\explorer.exe[1364] ntdll.dll!NtTerminateProcess 7C90DE50 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\explorer.exe[1364] ntdll.dll!NtTerminateProcess + 4 7C90DE54 2 Bytes [0B, 5F]
.text C:\WINDOWS\explorer.exe[1364] ntdll.dll!NtWriteVirtualMemory 7C90DF90 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\explorer.exe[1364] ntdll.dll!NtWriteVirtualMemory + 4 7C90DF94 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\WINDOWS\explorer.exe[1364] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00D80001
.text C:\WINDOWS\explorer.exe[1364] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes CALL 7170003D
.text C:\WINDOWS\system32\svchost.exe[1380] ntdll.dll!NtCreateSection 7C90D160 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\svchost.exe[1380] ntdll.dll!NtCreateSection + 4 7C90D164 2 Bytes [05, 5F]
.text C:\WINDOWS\system32\svchost.exe[1380] ntdll.dll!NtTerminateProcess 7C90DE50 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\svchost.exe[1380] ntdll.dll!NtTerminateProcess + 4 7C90DE54 2 Bytes [0B, 5F]
.text C:\WINDOWS\system32\svchost.exe[1380] ntdll.dll!NtWriteVirtualMemory 7C90DF90 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\svchost.exe[1380] ntdll.dll!NtWriteVirtualMemory + 4 7C90DF94 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\WINDOWS\system32\svchost.exe[1380] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 009F0001
.text C:\Program Files\Java\jre6\bin\jqs.exe[1456] ntdll.dll!NtCreateSection 7C90D160 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Java\jre6\bin\jqs.exe[1456] ntdll.dll!NtCreateSection + 4 7C90D164 2 Bytes [05, 5F]
.text C:\Program Files\Java\jre6\bin\jqs.exe[1456] ntdll.dll!NtTerminateProcess 7C90DE50 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Java\jre6\bin\jqs.exe[1456] ntdll.dll!NtTerminateProcess + 4 7C90DE54 2 Bytes [0B, 5F]
.text C:\Program Files\Java\jre6\bin\jqs.exe[1456] ntdll.dll!NtWriteVirtualMemory 7C90DF90 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Java\jre6\bin\jqs.exe[1456] ntdll.dll!NtWriteVirtualMemory + 4 7C90DF94 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Java\jre6\bin\jqs.exe[1456] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 013C0001
.text C:\WINDOWS\system32\spoolsv.exe[1532] ntdll.dll!NtCreateSection 7C90D160 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\spoolsv.exe[1532] ntdll.dll!NtCreateSection + 4 7C90D164 2 Bytes [05, 5F]
.text C:\WINDOWS\system32\spoolsv.exe[1532] ntdll.dll!NtTerminateProcess 7C90DE50 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\spoolsv.exe[1532] ntdll.dll!NtTerminateProcess + 4 7C90DE54 2 Bytes [0B, 5F]
.text C:\WINDOWS\system32\spoolsv.exe[1532] ntdll.dll!NtWriteVirtualMemory 7C90DF90 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\spoolsv.exe[1532] ntdll.dll!NtWriteVirtualMemory + 4 7C90DF94 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\WINDOWS\system32\spoolsv.exe[1532] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00FD0001
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[1592] ntdll.dll!NtCreateSection 7C90D160 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[1592] ntdll.dll!NtCreateSection + 4 7C90D164 2 Bytes [05, 5F]
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[1592] ntdll.dll!NtTerminateProcess 7C90DE50 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[1592] ntdll.dll!NtTerminateProcess + 4 7C90DE54 2 Bytes [0B, 5F]
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[1592] ntdll.dll!NtWriteVirtualMemory 7C90DF90 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[1592] ntdll.dll!NtWriteVirtualMemory + 4 7C90DF94 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[1592] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00900001
.text C:\Program Files\Google\Update\GoogleUpdate.exe[1872] ntdll.dll!NtCreateSection 7C90D160 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\Update\GoogleUpdate.exe[1872] ntdll.dll!NtCreateSection + 4 7C90D164 2 Bytes [05, 5F]
.text C:\Program Files\Google\Update\GoogleUpdate.exe[1872] ntdll.dll!NtTerminateProcess 7C90DE50 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\Update\GoogleUpdate.exe[1872] ntdll.dll!NtTerminateProcess + 4 7C90DE54 2 Bytes [0B, 5F]
.text C:\Program Files\Google\Update\GoogleUpdate.exe[1872] ntdll.dll!NtWriteVirtualMemory 7C90DF90 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\Update\GoogleUpdate.exe[1872] ntdll.dll!NtWriteVirtualMemory + 4 7C90DF94 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Google\Update\GoogleUpdate.exe[1872] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00E30001
.text C:\Program Files\MicroStar\WLANUtility\WLAN_Service.exe[2020] ntdll.dll!NtCreateSection 7C90D160 3 Bytes [FF, 25, 1E]
.text C:\Program Files\MicroStar\WLANUtility\WLAN_Service.exe[2020] ntdll.dll!NtCreateSection + 4 7C90D164 2 Bytes [05, 5F]
.text C:\Program Files\MicroStar\WLANUtility\WLAN_Service.exe[2020] ntdll.dll!NtTerminateProcess 7C90DE50 3 Bytes [FF, 25, 1E]
.text C:\Program Files\MicroStar\WLANUtility\WLAN_Service.exe[2020] ntdll.dll!NtTerminateProcess + 4 7C90DE54 2 Bytes [0B, 5F]
.text C:\Program Files\MicroStar\WLANUtility\WLAN_Service.exe[2020] ntdll.dll!NtWriteVirtualMemory 7C90DF90 3 Bytes [FF, 25, 1E]
.text C:\Program Files\MicroStar\WLANUtility\WLAN_Service.exe[2020] ntdll.dll!NtWriteVirtualMemory + 4 7C90DF94 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\MicroStar\WLANUtility\WLAN_Service.exe[2020] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00B90001
.text C:\Program Files\MicroStar\WLANUtility\WLAN_Service.exe[2020] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes CALL 7170003D
.text C:\WINDOWS\System32\alg.exe[2160] ntdll.dll!NtCreateSection 7C90D160 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\System32\alg.exe[2160] ntdll.dll!NtCreateSection + 4 7C90D164 2 Bytes [05, 5F]
.text C:\WINDOWS\System32\alg.exe[2160] ntdll.dll!NtTerminateProcess 7C90DE50 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\System32\alg.exe[2160] ntdll.dll!NtTerminateProcess + 4 7C90DE54 2 Bytes [0B, 5F]
.text C:\WINDOWS\System32\alg.exe[2160] ntdll.dll!NtWriteVirtualMemory 7C90DF90 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\System32\alg.exe[2160] ntdll.dll!NtWriteVirtualMemory + 4 7C90DF94 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\WINDOWS\System32\alg.exe[2160] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 006E0001
.text C:\WINDOWS\System32\alg.exe[2160] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes CALL 7170003D
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2176] ntdll.dll!NtCreateSection 7C90D160 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2176] ntdll.dll!NtCreateSection + 4 7C90D164 2 Bytes [05, 5F]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2176] ntdll.dll!NtTerminateProcess 7C90DE50 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2176] ntdll.dll!NtTerminateProcess + 4 7C90DE54 2 Bytes [0B, 5F]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2176] ntdll.dll!NtWriteVirtualMemory 7C90DF90 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2176] ntdll.dll!NtWriteVirtualMemory + 4 7C90DF94 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2176] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00730001
.text C:\Program Files\Spyware Doctor\pctsSvc.exe[2348] kernel32.dll!CreateThread + 1A 7C8106E1 4 Bytes CALL 0044A809 C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools Security Service/PC Tools)
.text C:\PROGRA~1\AVG\AVG8\avgrsx.exe[2372] ntdll.dll!NtCreateSection 7C90D160 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\AVG\AVG8\avgrsx.exe[2372] ntdll.dll!NtCreateSection + 4 7C90D164 2 Bytes [05, 5F]
.text C:\PROGRA~1\AVG\AVG8\avgrsx.exe[2372] ntdll.dll!NtTerminateProcess 7C90DE50 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\AVG\AVG8\avgrsx.exe[2372] ntdll.dll!NtTerminateProcess + 4 7C90DE54 2 Bytes [0B, 5F]
.text C:\PROGRA~1\AVG\AVG8\avgrsx.exe[2372] ntdll.dll!NtWriteVirtualMemory 7C90DF90 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\AVG\AVG8\avgrsx.exe[2372] ntdll.dll!NtWriteVirtualMemory + 4 7C90DF94 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\PROGRA~1\AVG\AVG8\avgrsx.exe[2372] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 04EB0001
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[2388] ntdll.dll!NtCreateSection 7C90D160 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[2388] ntdll.dll!NtCreateSection + 4 7C90D164 2 Bytes [05, 5F]
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[2388] ntdll.dll!NtTerminateProcess 7C90DE50 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[2388] ntdll.dll!NtTerminateProcess + 4 7C90DE54 2 Bytes [0B, 5F]
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[2388] ntdll.dll!NtWriteVirtualMemory 7C90DF90 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[2388] ntdll.dll!NtWriteVirtualMemory + 4 7C90DF94 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[2388] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00C80001
.text C:\Documents and Settings\Glenn\Desktop\gmer\gmer.exe[2696] ntdll.dll!NtCreateSection 7C90D160 3 Bytes [FF, 25, 1E]
.text C:\Documents and Settings\Glenn\Desktop\gmer\gmer.exe[2696] ntdll.dll!NtCreateSection + 4 7C90D164 2 Bytes [05, 5F]
.text C:\Documents and Settings\Glenn\Desktop\gmer\gmer.exe[2696] ntdll.dll!NtTerminateProcess 7C90DE50 3 Bytes [FF, 25, 1E]
.text C:\Documents and Settings\Glenn\Desktop\gmer\gmer.exe[2696] ntdll.dll!NtTerminateProcess + 4 7C90DE54 2 Bytes [0B, 5F]
.text C:\Documents and Settings\Glenn\Desktop\gmer\gmer.exe[2696] ntdll.dll!NtWriteVirtualMemory 7C90DF90 3 Bytes [FF, 25, 1E]
.text C:\Documents and Settings\Glenn\Desktop\gmer\gmer.exe[2696] ntdll.dll!NtWriteVirtualMemory + 4 7C90DF94 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Documents and Settings\Glenn\Desktop\gmer\gmer.exe[2696] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 003D0001
.text C:\Documents and Settings\Glenn\Desktop\gmer\gmer.exe[2696] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes CALL 7170003D
.text C:\Program Files\Spyware Doctor\sdhelp.exe[2744] ntdll.dll!NtCreateSection 7C90D160 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spyware Doctor\sdhelp.exe[2744] ntdll.dll!NtCreateSection + 4 7C90D164 2 Bytes [05, 5F]
.text C:\Program Files\Spyware Doctor\sdhelp.exe[2744] ntdll.dll!NtTerminateProcess 7C90DE50 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spyware Doctor\sdhelp.exe[2744] ntdll.dll!NtTerminateProcess + 4 7C90DE54 2 Bytes [0B, 5F]
.text C:\Program Files\Spyware Doctor\sdhelp.exe[2744] ntdll.dll!NtWriteVirtualMemory 7C90DF90 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spyware Doctor\sdhelp.exe[2744] ntdll.dll!NtWriteVirtualMemory + 4 7C90DF94 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Spyware Doctor\sdhelp.exe[2744] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 01080001
.text C:\WINDOWS\system32\svchost.exe[2836] ntdll.dll!NtCreateSection 7C90D160 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\svchost.exe[2836] ntdll.dll!NtCreateSection + 4 7C90D164 2 Bytes [05, 5F]
.text C:\WINDOWS\system32\svchost.exe[2836] ntdll.dll!NtTerminateProcess 7C90DE50 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\svchost.exe[2836] ntdll.dll!NtTerminateProcess + 4 7C90DE54 2 Bytes [0B, 5F]
.text C:\WINDOWS\system32\svchost.exe[2836] ntdll.dll!NtWriteVirtualMemory 7C90DF90 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\svchost.exe[2836] ntdll.dll!NtWriteVirtualMemory + 4 7C90DF94 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\WINDOWS\system32\svchost.exe[2836] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 00E70001
.text C:\PROGRA~1\AVG\AVG8\avgemc.exe[2908] ntdll.dll!NtCreateSection 7C90D160 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\AVG\AVG8\avgemc.exe[2908] ntdll.dll!NtCreateSection + 4 7C90D164 2 Bytes [05, 5F]
.text C:\PROGRA~1\AVG\AVG8\avgemc.exe[2908] ntdll.dll!NtTerminateProcess 7C90DE50 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\AVG\AVG8\avgemc.exe[2908] ntdll.dll!NtTerminateProcess + 4 7C90DE54 2 Bytes [0B, 5F]
.text C:\PROGRA~1\AVG\AVG8\avgemc.exe[2908] ntdll.dll!NtWriteVirtualMemory 7C90DF90 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\AVG\AVG8\avgemc.exe[2908] ntdll.dll!NtWriteVirtualMemory + 4 7C90DF94 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\PROGRA~1\AVG\AVG8\avgemc.exe[2908] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 02160001
.text C:\Program Files\AVG\AVG8\avgcsrvx.exe[3060] ntdll.dll!NtCreateSection 7C90D160 3 Bytes [FF, 25, 1E]
.text C:\Program Files\AVG\AVG8\avgcsrvx.exe[3060] ntdll.dll!NtCreateSection + 4 7C90D164 2 Bytes [05, 5F]
.text C:\Program Files\AVG\AVG8\avgcsrvx.exe[3060] ntdll.dll!NtTerminateProcess 7C90DE50 3 Bytes [FF, 25, 1E]
.text C:\Program Files\AVG\AVG8\avgcsrvx.exe[3060] ntdll.dll!NtTerminateProcess + 4 7C90DE54 2 Bytes [0B, 5F]
.text C:\Program Files\AVG\AVG8\avgcsrvx.exe[3060] ntdll.dll!NtWriteVirtualMemory 7C90DF90 3 Bytes [FF, 25, 1E]
.text C:\Program Files\AVG\AVG8\avgcsrvx.exe[3060] ntdll.dll!NtWriteVirtualMemory + 4 7C90DF94 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\AVG\AVG8\avgcsrvx.exe[3060] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 04CA0001

—- Kernel IAT/EAT - GMER 1.0.15 —-

IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [F733F040] sphv.sys
IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [F733F13C] sphv.sys
IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [F733F0BE] sphv.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [F733F7FC] sphv.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [F733F6D2] sphv.sys

—- User IAT/EAT - GMER 1.0.15 —-

IAT C:\Program Files\Spyware Doctor\sdhelp.exe[2744] @ C:\WINDOWS\system32\user32.dll [KERNEL32.dll!CreateThread] [0042B098] C:\Program Files\Spyware Doctor\sdhelp.exe (PC Tools Research Pty Ltd)
IAT C:\Program Files\Spyware Doctor\sdhelp.exe[2744] @ C:\WINDOWS\system32\advapi32.dll [KERNEL32.dll!CreateThread] [0042B098] C:\Program Files\Spyware Doctor\sdhelp.exe (PC Tools Research Pty Ltd)
IAT C:\Program Files\Spyware Doctor\sdhelp.exe[2744] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!CreateThread] [0042B098] C:\Program Files\Spyware Doctor\sdhelp.exe (PC Tools Research Pty Ltd)
IAT C:\Program Files\Spyware Doctor\sdhelp.exe[2744] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateThread] [0042B098] C:\Program Files\Spyware Doctor\sdhelp.exe (PC Tools Research Pty Ltd)
IAT C:\Program Files\Spyware Doctor\sdhelp.exe[2744] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CreateThread] [0042B098] C:\Program Files\Spyware Doctor\sdhelp.exe (PC Tools Research Pty Ltd)
IAT C:\Program Files\Spyware Doctor\sdhelp.exe[2744] @ C:\WINDOWS\system32\shell32.dll [KERNEL32.dll!CreateThread] [0042B098] C:\Program Files\Spyware Doctor\sdhelp.exe (PC Tools Research Pty Ltd)
IAT C:\Program Files\Spyware Doctor\sdhelp.exe[2744] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateThread] [0042B098] C:\Program Files\Spyware Doctor\sdhelp.exe (PC Tools Research Pty Ltd)
IAT C:\Program Files\Spyware Doctor\sdhelp.exe[2744] @ C:\WINDOWS\system32\WS2_32.dll [KERNEL32.dll!CreateThread] [0042B098] C:\Program Files\Spyware Doctor\sdhelp.exe (PC Tools Research Pty Ltd)
IAT C:\Program Files\Spyware Doctor\sdhelp.exe[2744] @ C:\WINDOWS\system32\WS2HELP.dll [KERNEL32.dll!CreateThread] [0042B098] C:\Program Files\Spyware Doctor\sdhelp.exe (PC Tools Research Pty Ltd)

—- Devices - GMER 1.0.15 —-

Device \FileSystem\Ntfs \Ntfs 86FD51F8
Device \Driver\NetBT \Device\NetBT_Tcpip_{E5DA4B59-FF9F-4B8C-9FD6-5BA84E5F19CF} 868B51F8

AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

Device \Driver\sptd \Device\3897215942 sphv.sys
Device \Driver\usbehci \Device\USBPDO-0 86E141F8
Device \Driver\PCI_PNP2192 \Device\00000051 sphv.sys
Device \Driver\dmio \Device\DmControl\DmIoDaemon 86F661F8
Device \Driver\dmio \Device\DmControl\DmConfig 86F661F8
Device \Driver\dmio \Device\DmControl\DmPnP 86F661F8
Device \Driver\dmio \Device\DmControl\DmInfo 86F661F8
Device \Driver\usbuhci \Device\USBPDO-1 86DC51F8
Device \Driver\usbuhci \Device\USBPDO-2 86DC51F8
Device \Driver\usbuhci \Device\USBPDO-3 86DC51F8
Device \Driver\usbuhci \Device\USBPDO-4 86DC51F8

AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

Device \Driver\Ftdisk \Device\HarddiskVolume1 86FD71F8
Device \Driver\Ftdisk \Device\HarddiskVolume2 86FD71F8
Device \Driver\Cdrom \Device\CdRom0 86D981F8
Device \Driver\Cdrom \Device\CdRom1 86D981F8
Device \Driver\Ftdisk \Device\HarddiskVolume3 86FD71F8
Device \Driver\NetBT \Device\NetBt_Wins_Export 868B51F8
Device \Driver\NetBT \Device\NetbiosSmb 868B51F8

AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

Device \Driver\usbuhci \Device\USBFDO-0 86DC51F8
Device \Driver\usbuhci \Device\USBFDO-1 86DC51F8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 868AA1F8
Device \Driver\usbuhci \Device\USBFDO-2 86DC51F8
Device \FileSystem\MRxSmb \Device\LanmanRedirector 868AA1F8
Device \Driver\usbuhci \Device\USBFDO-3 86DC51F8
Device \Driver\usbehci \Device\USBFDO-4 86E141F8
Device \Driver\Ftdisk \Device\FtControl 86FD71F8
Device \Driver\auicgk2m \Device\Scsi\auicgk2m1Port3Path0Target0Lun0 86D8C500
Device \Driver\auicgk2m \Device\Scsi\auicgk2m1 86D8C500
Device \FileSystem\Fastfat \Fat 859D01F8
Device \FileSystem\Fastfat \Fat A844B297

AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

Device \FileSystem\Fs_Rec \FileSystem\UdfsCdRomRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\FatCdRomRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\CdfsRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\FatDiskRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\UdfsDiskRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Cdfs \Cdfs 86BBA338
Device \FileSystem\Cdfs \Cdfs tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)

—- Registry - GMER 1.0.15 —-

Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xA0 0x46 0xA1 0x1C …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x0F 0x2A 0x51 0x97 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x5F 0xF8 0x08 0x30 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xA0 0x46 0xA1 0x1C …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x0F 0x2A 0x51 0x97 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x5F 0xF8 0x08 0x30 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x64 0xF2 0x1B 0x79 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0xC0 0x5A 0xEA 0xB8 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x5F 0xF8 0x08 0x30 …
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{F9D82965-1D6E-A4D7-1258-C3C5977145A7}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{F9D82965-1D6E-A4D7-1258-C3C5977145A7}@iaijeaodligifknoag 0x6B 0x61 0x6A 0x63 …
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{F9D82965-1D6E-A4D7-1258-C3C5977145A7}@haoicpfecgfoohhf 0x6B 0x61 0x6D 0x63 …

—- Files - GMER 1.0.15 —-

File C:\WINDOWS\system32\LogFiles\WUDF\WUDFTrace.etl (size mismatch) 8192/4096 bytes

—- EOF - GMER 1.0.15 —-


Cheers!
Sooth
Hello.

Let's continue

Peer-to-Peer Programs Warning

Your log shows that you are using so called peer-to-peer or file-sharing programs (in your case BitTorrent DNA). These programs allow to share files between users as the name(s) suggest. In today's world cyber crime has come to an enormous dimension and any means is used to infect personal computers to make use of their stored data or machine power for further propagation of the malware files. A popular means is the use of file-sharing tools as a tremendous amount of prospective victims can be reached through it.

It is therefore possible to be infected by downloading manipulated files via peer-to-peer tools and thus suggested to be used with intense care. Some further readings on this subject, along the included links, are as follows: File-Sharing, otherwise known as Peer To Peer and Risks of File-Sharing Technology.

It is also important to note that sharing entertainment files and proprietary software infringes the copyright laws in many countries over the world and you are putting yourself at risk of being indicted through organizations watching over the rights of the authors of such files (i.e. the RIAA for music files, or the MPAA for movie files in the USA) or the authors of the files themselves.

Naturally there are also legal ways to use these services, such as downloading Linux distributions or office suites such as "Open Office."

It is your decision whether or not you wish to keep your program(s) but I suggest you remove it via add/remove. However, please refrain from using them until your computer has been declared clean..

Run ComboFix with CFScript

We will run ComboFix again. This time, the instructions are slightly different.
  • Close any open browsers.
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix. Refer to this page if you are unsure how.
  • Open notepad (Start>Run>"notepad") and copy/paste the text in the quotebox below into it:
    File::
    c:\windows\system32\fuhubuga.exe
    C:\VundoFix.txt 
    Folder::
    C:\VundoFix Backups
    RegNull::
    [HKEY_USERS\S-1-5-21-38622347-797492410-3121079378-1005\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{F9D82965-1D6E-A4D7-1258-C3C5977145A7}*]
    Registry::
    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
    "UpdatesDisableNotify"=dword:00000000
    Driver::
    Asapi
    pr2akt6c
    Save this as CFScript.txt, in the same location as ComboFix.exe. (This should be your desktop.)
    [external image: Posted Image]
    Refering to the picture above, drag CFScript into ComboFix.exe.
When finished, it shall produce a log for you at "C:\ComboFix.txt". Post back with that log.

Do not mouseclick ComboFix's window while it's running. That may cause it to stall

Download and run MalwareBytes Anti-Malware

Please download Malwarebytes Anti-Malware and save it to your desktop.
alternate download link 1
alternate download link 2
  • Make sure you are connected to the Internet.
  • Double-click on Download_mbam-setup.exe to install the application.
  • When the installation begins, follow the prompts and do not make any changes to default settings.
  • When installation has finished, make sure you leave both of these checked:
    • Update Malwarebytes' Anti-Malware
    • Launch Malwarebytes' Anti-Malware
  • Then click Finish.
  • MBAM will automatically start and you will be asked to update the program before performing a scan. If an update is found, the program will automatically update itself. Press the OK button to close that box and continue. If you encounter any problems while downloading the updates, manually download them from here and just double-click on mbam-rules.exe to install.
  • On the Scanner tab:
    • Make sure the "Perform Quick Scan" option is selected.
    • Then click on the Scan button.
  • If asked to select the drives to scan, leave all the drives selected and click on the Start Scan button.
  • The scan will begin and "Scan in progress" will show at the top. It may take some time to complete so please be patient.
  • When the scan is finished, a message box will say "The scan completed successfully. Click 'Show Results' to display all objects found".
  • Click OK to close the message box and continue with the removal process.
  • Back at the main Scanner screen, click on the Show Results button to see a list of any malware that was found.
  • Make sure that everything is checked, and click Remove Selected.
  • When removal is completed, a log report will open in Notepad and you may be prompted to restart your computer. (see Note below)
  • The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the contents of that report in your next reply and exit MBAM.
Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.

For complete or visual instructions on installing and running Malwarebytes Anti-Malware please read this link

Post back with:
-Combofix log
-MBAM log


With Regards,
Extremeboy
ComboFix.txt:

ComboFix 09-04-17.01 - Glenn 18/04/2009 0:32.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.515 [GMT 1:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Glenn\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated)
* Created a new restore point

FILE ::
C:\VundoFix.txt
c:\windows\system32\fuhubuga.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\VundoFix Backups
C:\VundoFix.txt
c:\windows\system32\fuhubuga.exe

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_PR2AKT6C
——-\Service_Asapi
——-\Service_pr2akt6c


((((((((((((((((((((((((( Files Created from 2009-03-17 to 2009-04-17 )))))))))))))))))))))))))))))))
.

2009-04-17 00:18 . 2009-04-17 00:23 1374 —-a-w c:\windows\imsins.BAK
2009-04-16 17:13 . 2009-03-06 14:22 284160 ——w c:\windows\system32\dllcache\pdh.dll
2009-04-16 17:13 . 2009-02-09 12:10 473600 ——w c:\windows\system32\dllcache\fastprox.dll
2009-04-16 17:13 . 2009-02-09 12:10 453120 ——w c:\windows\system32\dllcache\wmiprvsd.dll
2009-04-16 17:13 . 2009-02-09 12:10 401408 ——w c:\windows\system32\dllcache\rpcss.dll
2009-04-16 17:13 . 2009-02-06 11:11 110592 ——w c:\windows\system32\dllcache\services.exe
2009-04-16 17:13 . 2009-02-06 10:39 35328 ——w c:\windows\system32\dllcache\sc.exe
2009-04-16 17:13 . 2009-02-06 10:10 227840 ——w c:\windows\system32\dllcache\wmiprvse.exe
2009-04-16 17:13 . 2009-02-09 12:10 729088 ——w c:\windows\system32\dllcache\lsasrv.dll
2009-04-16 17:13 . 2009-02-09 12:10 714752 ——w c:\windows\system32\dllcache\ntdll.dll
2009-04-16 17:13 . 2009-02-09 12:10 617472 ——w c:\windows\system32\dllcache\advapi32.dll
2009-04-16 17:12 . 2008-05-03 11:55 2560 ——w c:\windows\system32\xpsp4res.dll
2009-04-16 17:12 . 2009-03-27 06:58 1203922 ——w c:\windows\system32\dllcache\sysmain.sdb
2009-04-16 17:12 . 2008-04-21 12:08 215552 ——w c:\windows\system32\dllcache\wordpad.exe
2009-04-14 23:17 . 2009-04-14 23:17 758 —ha-w C:\aaw7boot.cmd
2009-04-14 21:53 . 2009-04-14 23:20 ——– dc—-w c:\windows\system32\DRVSTORE
2009-04-14 21:52 . 2009-04-14 23:21 ——– d—–w c:\documents and settings\All Users\Application Data\Lavasoft
2009-04-14 19:58 . 2009-04-14 21:49 ——– d—–w c:\documents and settings\Glenn\.housecall6.6
2009-04-14 19:42 . 2009-04-14 19:42 ——– d—–w c:\program files\CCleaner
2009-04-10 15:42 . 2009-04-10 15:42 ——– d—–w c:\program files\Trend Micro
2009-04-10 00:19 . 2009-04-14 23:24 ——– d—–w c:\program files\Spybot - Search & Destroy
2009-04-10 00:19 . 2009-04-14 23:24 ——– d—–w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-03-21 14:06 . 2009-03-21 14:06 989696 ——w c:\windows\system32\dllcache\kernel32.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-17 23:40 . 2008-06-08 22:22 ——– d—a-w c:\documents and settings\All Users\Application Data\TEMP
2009-04-17 23:39 . 2008-10-18 09:14 ——– d—–w c:\program files\DNA
2009-04-17 23:39 . 2008-10-18 09:14 ——– d—–w c:\documents and settings\Glenn\Application Data\DNA
2009-04-17 23:24 . 2008-06-08 22:20 ——– d—–w c:\documents and settings\All Users\Application Data\Google Updater
2009-04-16 22:10 . 2007-07-11 18:33 ——– d—–w c:\documents and settings\Glenn\Application Data\Pro Cycling Manager 2007
2009-04-16 17:38 . 2006-06-11 11:21 ——– d—–w c:\program files\Spyware Doctor
2009-04-15 18:15 . 2008-05-10 10:24 108552 —-a-w c:\windows\system32\drivers\avgtdix.sys
2009-04-15 18:15 . 2008-05-10 10:24 325640 —-a-w c:\windows\system32\drivers\avgldx86.sys
2009-04-15 18:15 . 2008-05-10 10:24 10520 —-a-w c:\windows\system32\avgrsstx.dll
2009-04-15 18:14 . 2008-05-10 10:23 ——– d—–w c:\documents and settings\All Users\Application Data\avg8
2009-04-14 23:21 . 2006-06-11 14:51 ——– d—–w c:\program files\Lavasoft
2009-04-09 18:58 . 2006-01-11 11:24 ——– d—–w c:\program files\Java
2009-04-07 23:26 . 2006-02-05 15:42 ——– d—–w c:\documents and settings\Glenn\Application Data\BitTorrent
2009-04-06 23:10 . 2006-02-01 21:02 ——– d—–w c:\program files\Football Manager 2006
2009-04-04 18:13 . 2006-01-16 23:49 34680 —-a-w c:\documents and settings\Glenn\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-03-29 14:06 . 2006-01-19 21:26 75 —-a-w C:\audiodec.txt
2009-03-09 04:19 . 2008-12-08 18:51 410984 —-a-w c:\windows\system32\deploytk.dll
2009-03-06 19:08 . 2009-03-06 19:08 ——– d—–w c:\documents and settings\Glenn\Application Data\dvdcss
2009-03-06 14:22 . 2004-08-11 17:00 284160 —-a-w c:\windows\system32\pdh.dll
2009-03-05 21:11 . 2006-01-17 20:40 ——– d—–w c:\program files\Common Files\Adobe
2009-03-05 00:14 . 2009-03-05 00:14 ——– d—–w c:\documents and settings\All Users\Application Data\Adobe Systems
2009-03-05 00:13 . 2009-03-05 00:13 ——– d—–w c:\program files\Common Files\Adobe Systems Shared
2009-03-03 00:18 . 2006-05-10 05:25 826368 —-a-w c:\windows\system32\dllcache\wininet.dll
2009-03-03 00:18 . 2004-08-11 17:00 826368 —-a-w c:\windows\system32\wininet.dll
2009-02-28 17:30 . 2006-05-14 13:34 ——– d—–w c:\program files\Soulseek
2009-02-28 04:54 . 2006-10-17 12:04 636072 ——w c:\windows\system32\dllcache\iexplore.exe
2009-02-22 16:15 . 2009-02-22 16:00 ——– d—a-w c:\documents and settings\All Users\Application Data\Sports Interactive
2009-02-22 16:00 . 2009-02-22 16:00 ——– d—–w c:\documents and settings\Glenn\Application Data\Sports Interactive
2009-02-22 15:54 . 2009-02-22 15:47 ——– d–h–w c:\program files\Zero G Registry
2009-02-22 15:47 . 2009-02-22 15:47 ——– d—–w c:\program files\Sports Interactive
2009-02-22 15:17 . 2009-02-22 15:17 ——– d—–w c:\program files\Football Manager 2009
2009-02-22 01:00 . 2008-02-07 22:48 ——– d—–w c:\program files\FinePixViewer
2009-02-20 10:20 . 2007-05-08 19:41 13824 ——w c:\windows\system32\dllcache\ieudinit.exe
2009-02-20 10:20 . 2006-11-07 03:26 70656 ——w c:\windows\system32\dllcache\ie4uinit.exe
2009-02-20 05:14 . 2006-11-07 03:25 161792 ——w c:\windows\system32\dllcache\ieakui.dll
2009-02-09 12:10 . 2004-08-11 17:00 729088 —-a-w c:\windows\system32\lsasrv.dll
2009-02-09 12:10 . 2004-08-11 17:00 401408 —-a-w c:\windows\system32\rpcss.dll
2009-02-09 12:10 . 2004-08-11 17:00 714752 —-a-w c:\windows\system32\ntdll.dll
2009-02-09 12:10 . 2004-08-11 17:00 617472 —-a-w c:\windows\system32\advapi32.dll
2009-02-09 11:13 . 2008-10-15 22:41 1846784 ——w c:\windows\system32\dllcache\win32k.sys
2009-02-09 11:13 . 2004-08-11 17:00 1846784 —-a-w c:\windows\system32\win32k.sys
2009-02-07 18:02 . 2008-10-15 23:24 2066048 ——w c:\windows\system32\dllcache\ntkrnlpa.exe
2009-02-06 11:11 . 2004-08-11 17:00 110592 —-a-w c:\windows\system32\services.exe
2009-02-06 11:08 . 2008-10-15 23:24 2189056 ——w c:\windows\system32\dllcache\ntoskrnl.exe
2009-02-06 11:06 . 2008-10-15 23:24 2145280 ——w c:\windows\system32\dllcache\ntkrnlmp.exe
2009-02-06 11:06 . 2004-08-11 17:00 2145280 —-a-w c:\windows\system32\ntoskrnl.exe
2009-02-06 10:39 . 2004-08-11 17:00 35328 —-a-w c:\windows\system32\sc.exe
2009-02-06 10:32 . 2008-10-15 23:24 2023936 ——w c:\windows\system32\dllcache\ntkrpamp.exe
2009-02-06 10:32 . 2004-08-03 22:59 2023936 —-a-w c:\windows\system32\ntkrnlpa.exe
2009-02-03 19:59 . 2009-02-03 19:59 56832 ——w c:\windows\system32\dllcache\secur32.dll
2009-02-03 19:59 . 2004-08-11 17:00 56832 —-a-w c:\windows\system32\secur32.dll
2008-06-14 21:43 . 2008-06-14 21:43 33904 —-a-w c:\documents and settings\Glenn\Application Data\GDIPFONTCACHEV1.DAT
2008-03-30 18:15 . 2008-03-30 18:15 32 —-a-w c:\documents and settings\All Users\Application Data\ezsid.dat
2006-01-17 00:36 . 2006-01-17 00:36 128 —-a-w c:\documents and settings\Glenn\Local Settings\Application Data\fusioncache.dat
2006-02-03 19:19 . 2006-02-03 19:19 56 –sh–r c:\windows\system32\BA025EC27E.sys
2006-04-05 17:13 . 2006-01-19 21:23 56 –sh–r c:\windows\system32\F1AB804D5A.sys
2006-08-05 21:28 . 2006-08-05 21:28 2828 –sha-w c:\windows\system32\KGyGaAvL.sys
2008-11-28 13:34 . 2008-11-28 13:35 32768 –sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008112820081129\index.dat
.

((((((((((((((((((((((((((((( SnapShot@2009-04-16_17.34.43 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-04-17 23:39 . 2009-04-17 23:39 16384 c:\windows\temp\Perflib_Perfdata_420.dat
+ 2006-03-06 01:46 . 2008-07-09 07:38 26488 c:\windows\system32\spupdsvc.exe
- 2006-03-06 01:46 . 2007-08-10 19:46 26488 c:\windows\system32\spupdsvc.exe
+ 2007-09-19 17:33 . 2007-11-30 12:39 17272 c:\windows\system32\spmsg.dll
- 2007-09-19 17:33 . 2007-11-30 11:18 17272 c:\windows\system32\spmsg.dll
+ 2004-08-11 17:00 . 2009-02-20 18:09 44544 c:\windows\system32\pngfilt.dll
- 2004-08-11 17:00 . 2008-12-20 23:15 44544 c:\windows\system32\pngfilt.dll
- 2004-08-11 17:00 . 2009-03-29 10:49 64200 c:\windows\system32\perfc009.dat
+ 2004-08-11 17:00 . 2009-04-17 23:28 64200 c:\windows\system32\perfc009.dat
- 2004-08-11 17:11 . 2008-04-14 00:12 91648 c:\windows\system32\mtxoci.dll
+ 2004-08-11 17:11 . 2008-06-12 14:23 91648 c:\windows\system32\mtxoci.dll
- 2004-08-11 17:00 . 2008-04-14 00:12 66560 c:\windows\system32\mtxclu.dll
+ 2004-08-11 17:00 . 2008-06-12 14:23 66560 c:\windows\system32\mtxclu.dll
- 2006-11-07 21:03 . 2008-12-20 23:15 52224 c:\windows\system32\msfeedsbs.dll
+ 2006-11-07 21:03 . 2009-02-20 18:09 52224 c:\windows\system32\msfeedsbs.dll
+ 2004-08-11 17:11 . 2008-06-12 14:23 58880 c:\windows\system32\msdtclog.dll
- 2004-08-11 17:11 . 2008-04-14 00:11 58880 c:\windows\system32\msdtclog.dll
- 2004-08-11 17:00 . 2008-12-20 23:15 27648 c:\windows\system32\jsproxy.dll
+ 2004-08-11 17:00 . 2009-02-20 18:09 27648 c:\windows\system32\jsproxy.dll
- 2006-11-07 03:26 . 2008-12-19 09:10 13824 c:\windows\system32\ieudinit.exe
+ 2006-11-07 03:26 . 2009-02-20 10:20 13824 c:\windows\system32\ieudinit.exe
+ 2004-08-11 17:00 . 2009-02-20 18:09 44544 c:\windows\system32\iernonce.dll
- 2004-08-11 17:00 . 2008-12-20 23:15 44544 c:\windows\system32\iernonce.dll
+ 2004-08-11 17:00 . 2009-02-20 18:09 78336 c:\windows\system32\ieencode.dll
- 2004-08-11 17:00 . 2008-12-19 09:10 70656 c:\windows\system32\ie4uinit.exe
+ 2004-08-11 17:00 . 2009-02-20 10:20 70656 c:\windows\system32\ie4uinit.exe
- 2006-10-17 11:58 . 2008-12-20 23:15 63488 c:\windows\system32\icardie.dll
+ 2006-10-17 11:58 . 2009-02-20 18:09 63488 c:\windows\system32\icardie.dll
- 2006-05-10 05:25 . 2008-12-20 23:15 44544 c:\windows\system32\dllcache\pngfilt.dll
+ 2006-05-10 05:25 . 2009-02-20 18:09 44544 c:\windows\system32\dllcache\pngfilt.dll
+ 2008-06-12 14:23 . 2008-06-12 14:23 91648 c:\windows\system32\dllcache\mtxoci.dll
+ 2008-06-12 14:23 . 2008-06-12 14:23 66560 c:\windows\system32\dllcache\mtxclu.dll
+ 2007-05-08 19:41 . 2009-02-20 18:09 52224 c:\windows\system32\dllcache\msfeedsbs.dll
- 2007-05-08 19:41 . 2008-12-20 23:15 52224 c:\windows\system32\dllcache\msfeedsbs.dll
+ 2008-06-12 14:23 . 2008-06-12 14:23 58880 c:\windows\system32\dllcache\msdtclog.dll
- 2006-05-10 05:25 . 2008-12-20 23:15 27648 c:\windows\system32\dllcache\jsproxy.dll
+ 2006-05-10 05:25 . 2009-02-20 18:09 27648 c:\windows\system32\dllcache\jsproxy.dll
+ 2006-11-07 03:26 . 2009-02-20 18:09 44544 c:\windows\system32\dllcache\iernonce.dll
- 2006-11-07 03:26 . 2008-12-20 23:15 44544 c:\windows\system32\dllcache\iernonce.dll
+ 2009-02-20 18:09 . 2009-02-20 18:09 78336 c:\windows\system32\dllcache\ieencode.dll
- 2007-08-20 10:04 . 2008-12-20 23:15 63488 c:\windows\system32\dllcache\icardie.dll
+ 2007-08-20 10:04 . 2009-02-20 18:09 63488 c:\windows\system32\dllcache\icardie.dll
+ 2009-04-17 00:23 . 2008-12-20 23:15 44544 c:\windows\ie7updates\KB963027-IE7\pngfilt.dll
+ 2009-04-17 00:23 . 2008-12-20 23:15 52224 c:\windows\ie7updates\KB963027-IE7\msfeedsbs.dll
+ 2009-04-17 00:23 . 2008-12-20 23:15 27648 c:\windows\ie7updates\KB963027-IE7\jsproxy.dll
+ 2009-04-17 00:23 . 2008-12-19 09:10 13824 c:\windows\ie7updates\KB963027-IE7\ieudinit.exe
+ 2009-04-17 00:23 . 2008-12-20 23:15 44544 c:\windows\ie7updates\KB963027-IE7\iernonce.dll
+ 2009-04-17 00:23 . 2008-04-14 00:11 81920 c:\windows\ie7updates\KB963027-IE7\ieencode.dll
+ 2009-04-17 00:23 . 2008-12-19 09:10 70656 c:\windows\ie7updates\KB963027-IE7\ie4uinit.exe
+ 2009-04-17 00:23 . 2008-12-20 23:15 63488 c:\windows\ie7updates\KB963027-IE7\icardie.dll
+ 2004-08-11 17:00 . 2008-12-16 12:30 354304 c:\windows\system32\winhttp.dll
- 2004-08-11 17:00 . 2008-04-14 00:12 354304 c:\windows\system32\winhttp.dll
- 2004-08-11 17:00 . 2008-12-20 23:15 233472 c:\windows\system32\webcheck.dll
+ 2004-08-11 17:00 . 2009-02-20 18:09 233472 c:\windows\system32\webcheck.dll
+ 2004-08-11 17:11 . 2009-02-06 10:10 227840 c:\windows\system32\wbem\wmiprvse.exe
+ 2004-08-11 17:11 . 2009-02-09 12:10 453120 c:\windows\system32\wbem\wmiprvsd.dll
+ 2004-08-11 17:11 . 2009-02-09 12:10 473600 c:\windows\system32\wbem\fastprox.dll
- 2004-08-11 17:00 . 2008-12-20 23:15 105984 c:\windows\system32\url.dll
+ 2004-08-11 17:00 . 2009-02-20 18:09 105984 c:\windows\system32\url.dll
+ 2004-08-11 17:00 . 2009-04-17 23:28 407670 c:\windows\system32\perfh009.dat
- 2004-08-11 17:00 . 2009-03-29 10:49 407670 c:\windows\system32\perfh009.dat
+ 2004-08-11 17:00 . 2009-02-20 18:09 102912 c:\windows\system32\occache.dll
- 2004-08-11 17:00 . 2008-12-20 23:15 102912 c:\windows\system32\occache.dll
- 2004-08-11 17:00 . 2008-12-20 23:15 671232 c:\windows\system32\mstime.dll
+ 2004-08-11 17:00 . 2009-02-20 18:09 671232 c:\windows\system32\mstime.dll
+ 2004-08-11 17:00 . 2009-02-20 18:09 193024 c:\windows\system32\msrating.dll
- 2004-08-11 17:00 . 2008-12-20 23:15 193024 c:\windows\system32\msrating.dll
- 2004-08-11 17:00 . 2008-12-20 23:15 477696 c:\windows\system32\mshtmled.dll
+ 2004-08-11 17:00 . 2009-02-20 18:09 477696 c:\windows\system32\mshtmled.dll
+ 2006-11-07 21:03 . 2009-02-20 18:09 459264 c:\windows\system32\msfeeds.dll
- 2006-11-07 21:03 . 2008-12-20 23:15 459264 c:\windows\system32\msfeeds.dll
+ 2004-08-11 17:11 . 2008-06-12 14:23 161792 c:\windows\system32\msdtcuiu.dll
- 2004-08-11 17:11 . 2008-04-14 00:11 161792 c:\windows\system32\msdtcuiu.dll
- 2004-08-11 17:11 . 2008-04-14 00:11 956928 c:\windows\system32\msdtctm.dll
+ 2004-08-11 17:11 . 2008-06-12 14:23 956928 c:\windows\system32\msdtctm.dll
+ 2004-08-11 17:11 . 2008-06-12 14:23 428032 c:\windows\system32\msdtcprx.dll
+ 2004-08-11 17:00 . 2009-03-21 14:06 989696 c:\windows\system32\kernel32.dll
- 2004-08-11 17:00 . 2008-04-14 00:11 989696 c:\windows\system32\kernel32.dll
+ 2006-10-17 11:57 . 2009-02-20 18:09 268288 c:\windows\system32\iertutil.dll
+ 2004-08-11 17:00 . 2009-02-20 18:09 385024 c:\windows\system32\iedkcs32.dll
+ 2006-10-17 11:27 . 2009-02-20 18:09 383488 c:\windows\system32\ieapfltr.dll
- 2006-10-17 11:27 . 2008-12-20 23:15 383488 c:\windows\system32\ieapfltr.dll
+ 2004-08-11 17:00 . 2009-02-20 05:14 161792 c:\windows\system32\ieakui.dll
- 2004-08-11 17:00 . 2008-12-19 05:23 161792 c:\windows\system32\ieakui.dll
+ 2004-08-11 17:00 . 2009-02-20 18:09 230400 c:\windows\system32\ieaksie.dll
- 2004-08-11 17:00 . 2008-12-20 23:15 230400 c:\windows\system32\ieaksie.dll
- 2004-08-11 17:00 . 2008-12-20 23:15 153088 c:\windows\system32\ieakeng.dll
+ 2004-08-11 17:00 . 2009-02-20 18:09 153088 c:\windows\system32\ieakeng.dll
- 2004-08-11 17:00 . 2008-12-20 23:15 133120 c:\windows\system32\extmgr.dll
+ 2004-08-11 17:00 . 2009-02-20 18:09 133120 c:\windows\system32\extmgr.dll
- 2004-08-11 17:00 . 2008-12-20 23:15 214528 c:\windows\system32\dxtrans.dll
+ 2004-08-11 17:00 . 2009-02-20 18:09 214528 c:\windows\system32\dxtrans.dll
+ 2004-08-11 17:00 . 2009-02-20 18:09 347136 c:\windows\system32\dxtmsft.dll
- 2004-08-11 17:00 . 2008-12-20 23:15 347136 c:\windows\system32\dxtmsft.dll
+ 2008-12-16 12:30 . 2008-12-16 12:30 354304 c:\windows\system32\dllcache\winhttp.dll
- 2006-11-07 21:03 . 2008-12-20 23:15 233472 c:\windows\system32\dllcache\webcheck.dll
+ 2006-11-07 21:03 . 2009-02-20 18:09 233472 c:\windows\system32\dllcache\webcheck.dll
+ 2006-10-17 12:05 . 2009-02-20 18:09 105984 c:\windows\system32\dllcache\url.dll
- 2006-10-17 12:05 . 2008-12-20 23:15 105984 c:\windows\system32\dllcache\url.dll
- 2006-10-17 12:04 . 2008-12-20 23:15 102912 c:\windows\system32\dllcache\occache.dll
+ 2006-10-17 12:04 . 2009-02-20 18:09 102912 c:\windows\system32\dllcache\occache.dll
+ 2006-05-10 05:25 . 2009-02-20 18:09 671232 c:\windows\system32\dllcache\mstime.dll
- 2006-05-10 05:25 . 2008-12-20 23:15 671232 c:\windows\system32\dllcache\mstime.dll
+ 2006-05-10 05:25 . 2009-02-20 18:09 193024 c:\windows\system32\dllcache\msrating.dll
- 2006-05-10 05:25 . 2008-12-20 23:15 193024 c:\windows\system32\dllcache\msrating.dll
+ 2006-05-10 05:25 . 2009-02-20 18:09 477696 c:\windows\system32\dllcache\mshtmled.dll
- 2006-05-10 05:25 . 2008-12-20 23:15 477696 c:\windows\system32\dllcache\mshtmled.dll
+ 2007-05-08 19:41 . 2009-02-20 18:09 459264 c:\windows\system32\dllcache\msfeeds.dll
- 2007-05-08 19:41 . 2008-12-20 23:15 459264 c:\windows\system32\dllcache\msfeeds.dll
+ 2008-06-12 14:23 . 2008-06-12 14:23 161792 c:\windows\system32\dllcache\msdtcuiu.dll
+ 2008-06-12 14:23 . 2008-06-12 14:23 956928 c:\windows\system32\dllcache\msdtctm.dll
+ 2008-06-12 14:23 . 2008-06-12 14:23 428032 c:\windows\system32\dllcache\msdtcprx.dll
+ 2007-05-08 19:41 . 2009-02-20 18:09 268288 c:\windows\system32\dllcache\iertutil.dll
+ 2006-11-07 03:27 . 2009-02-20 18:09 385024 c:\windows\system32\dllcache\iedkcs32.dll
+ 2007-05-08 19:41 . 2009-02-20 18:09 383488 c:\windows\system32\dllcache\ieapfltr.dll
- 2007-05-08 19:41 . 2008-12-20 23:15 383488 c:\windows\system32\dllcache\ieapfltr.dll
- 2006-11-07 03:27 . 2008-12-20 23:15 230400 c:\windows\system32\dllcache\ieaksie.dll
+ 2006-11-07 03:27 . 2009-02-20 18:09 230400 c:\windows\system32\dllcache\ieaksie.dll
+ 2006-11-07 03:26 . 2009-02-20 18:09 153088 c:\windows\system32\dllcache\ieakeng.dll
- 2006-11-07 03:26 . 2008-12-20 23:15 153088 c:\windows\system32\dllcache\ieakeng.dll
+ 2006-05-10 05:25 . 2009-02-20 18:09 133120 c:\windows\system32\dllcache\extmgr.dll
- 2006-05-10 05:25 . 2008-12-20 23:15 133120 c:\windows\system32\dllcache\extmgr.dll
+ 2006-05-10 05:25 . 2009-02-20 18:09 214528 c:\windows\system32\dllcache\dxtrans.dll
- 2006-05-10 05:25 . 2008-12-20 23:15 214528 c:\windows\system32\dllcache\dxtrans.dll
- 2006-05-10 05:25 . 2008-12-20 23:15 347136 c:\windows\system32\dllcache\dxtmsft.dll
+ 2006-05-10 05:25 . 2009-02-20 18:09 347136 c:\windows\system32\dllcache\dxtmsft.dll
- 2006-11-07 03:26 . 2008-12-20 23:15 124928 c:\windows\system32\dllcache\advpack.dll
+ 2006-11-07 03:26 . 2009-02-20 18:09 124928 c:\windows\system32\dllcache\advpack.dll
- 2004-08-11 17:00 . 2008-12-20 23:15 124928 c:\windows\system32\advpack.dll
+ 2004-08-11 17:00 . 2009-02-20 18:09 124928 c:\windows\system32\advpack.dll
+ 2009-04-17 00:23 . 2008-12-20 23:15 826368 c:\windows\ie7updates\KB963027-IE7\wininet.dll
+ 2009-04-17 00:23 . 2008-12-20 23:15 233472 c:\windows\ie7updates\KB963027-IE7\webcheck.dll
+ 2009-04-17 00:23 . 2008-12-20 23:15 105984 c:\windows\ie7updates\KB963027-IE7\url.dll
+ 2009-04-17 00:23 . 2008-07-09 07:38 382840 c:\windows\ie7updates\KB963027-IE7\spuninst\updspapi.dll
+ 2009-04-17 00:23 . 2008-07-08 13:02 231288 c:\windows\ie7updates\KB963027-IE7\spuninst\spuninst.exe
+ 2009-04-17 00:23 . 2008-12-20 23:15 102912 c:\windows\ie7updates\KB963027-IE7\occache.dll
+ 2009-04-17 00:23 . 2008-12-20 23:15 671232 c:\windows\ie7updates\KB963027-IE7\mstime.dll
+ 2009-04-17 00:23 . 2008-12-20 23:15 193024 c:\windows\ie7updates\KB963027-IE7\msrating.dll
+ 2009-04-17 00:23 . 2008-12-20 23:15 477696 c:\windows\ie7updates\KB963027-IE7\mshtmled.dll
+ 2009-04-17 00:23 . 2008-12-20 23:15 459264 c:\windows\ie7updates\KB963027-IE7\msfeeds.dll
+ 2009-04-17 00:23 . 2008-12-19 05:25 634024 c:\windows\ie7updates\KB963027-IE7\iexplore.exe
+ 2009-04-17 00:23 . 2008-12-20 23:15 267776 c:\windows\ie7updates\KB963027-IE7\iertutil.dll
+ 2009-04-17 00:23 . 2008-12-20 23:15 384512 c:\windows\ie7updates\KB963027-IE7\iedkcs32.dll
+ 2009-04-17 00:23 . 2008-12-20 23:15 383488 c:\windows\ie7updates\KB963027-IE7\ieapfltr.dll
+ 2009-04-17 00:23 . 2008-12-19 05:23 161792 c:\windows\ie7updates\KB963027-IE7\ieakui.dll
+ 2009-04-17 00:23 . 2008-12-20 23:15 230400 c:\windows\ie7updates\KB963027-IE7\ieaksie.dll
+ 2009-04-17 00:23 . 2008-12-20 23:15 153088 c:\windows\ie7updates\KB963027-IE7\ieakeng.dll
+ 2009-04-17 00:23 . 2008-12-20 23:15 133120 c:\windows\ie7updates\KB963027-IE7\extmgr.dll
+ 2009-04-17 00:23 . 2008-12-20 23:15 214528 c:\windows\ie7updates\KB963027-IE7\dxtrans.dll
+ 2009-04-17 00:23 . 2008-12-20 23:15 347136 c:\windows\ie7updates\KB963027-IE7\dxtmsft.dll
+ 2009-04-17 00:23 . 2008-12-20 23:15 124928 c:\windows\ie7updates\KB963027-IE7\advpack.dll
+ 2004-08-11 17:00 . 2009-02-20 18:09 1160192 c:\windows\system32\urlmon.dll
- 2004-08-11 17:00 . 2008-12-20 23:15 1160192 c:\windows\system32\urlmon.dll
+ 2004-08-11 17:00 . 2008-12-20 22:14 1288192 c:\windows\system32\quartz.dll
- 2004-08-11 17:00 . 2008-05-07 05:12 1288192 c:\windows\system32\quartz.dll
+ 2004-08-11 17:00 . 2009-02-20 18:09 3595264 c:\windows\system32\mshtml.dll
+ 2006-11-07 21:03 . 2009-02-20 18:09 6066176 c:\windows\system32\ieframe.dll
+ 2006-09-05 23:01 . 2008-07-09 14:25 2455488 c:\windows\system32\ieapfltr.dat
- 2006-09-05 23:01 . 2007-04-17 09:28 2455488 c:\windows\system32\ieapfltr.dat
+ 2006-05-10 05:25 . 2009-02-20 18:09 1160192 c:\windows\system32\dllcache\urlmon.dll
- 2006-05-10 05:25 . 2008-12-20 23:15 1160192 c:\windows\system32\dllcache\urlmon.dll
- 2008-05-07 05:12 . 2008-05-07 05:12 1288192 c:\windows\system32\dllcache\quartz.dll
+ 2008-05-07 05:12 . 2008-12-20 22:14 1288192 c:\windows\system32\dllcache\quartz.dll
+ 2006-05-19 15:06 . 2009-02-20 18:09 3595264 c:\windows\system32\dllcache\mshtml.dll
+ 2007-05-08 19:41 . 2009-02-20 18:09 6066176 c:\windows\system32\dllcache\ieframe.dll
+ 2007-05-08 19:41 . 2008-07-09 14:25 2455488 c:\windows\system32\dllcache\ieapfltr.dat
- 2007-05-08 19:41 . 2007-04-17 09:28 2455488 c:\windows\system32\dllcache\ieapfltr.dat
+ 2009-04-17 00:23 . 2008-12-20 23:15 1160192 c:\windows\ie7updates\KB963027-IE7\urlmon.dll
+ 2009-04-17 00:23 . 2009-01-16 21:35 3594752 c:\windows\ie7updates\KB963027-IE7\mshtml.dll
+ 2009-04-17 00:23 . 2008-12-20 23:15 6066688 c:\windows\ie7updates\KB963027-IE7\ieframe.dll
+ 2009-04-17 00:23 . 2007-04-17 09:28 2455488 c:\windows\ie7updates\KB963027-IE7\ieapfltr.dat
+ 2008-10-15 23:24 . 2009-02-06 11:08 2189056 c:\windows\Driver Cache\i386\ntoskrnl.exe
- 2008-10-15 23:24 . 2008-08-14 09:33 2023936 c:\windows\Driver Cache\i386\ntkrpamp.exe
+ 2008-10-15 23:24 . 2009-02-06 10:32 2023936 c:\windows\Driver Cache\i386\ntkrpamp.exe
- 2008-10-15 23:24 . 2008-08-14 09:33 2066048 c:\windows\Driver Cache\i386\ntkrnlpa.exe
+ 2008-10-15 23:24 . 2009-02-07 18:02 2066048 c:\windows\Driver Cache\i386\ntkrnlpa.exe
+ 2008-10-15 23:24 . 2009-02-06 11:06 2145280 c:\windows\Driver Cache\i386\ntkrnlmp.exe
- 2008-10-15 23:24 . 2008-08-14 10:09 2145280 c:\windows\Driver Cache\i386\ntkrnlmp.exe
+ 2009-04-17 00:19 . 2009-04-06 06:57 24921544 c:\windows\system32\MRT.exe
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2008-12-16 342848]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-12-29 687560]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-07-19 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-07-19 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-07-19 114688]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 53248]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-01-11 98304]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-12-06 127035]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"MSKDetectorExe"="c:\program files\McAfee\SpamKiller\MSKDetct.exe" [2006-11-07 1121280]
"PWRISOVM.EXE"="c:\program files\PowerISO\PWRISOVM.EXE" [2007-04-09 200704]
"tsnpstd3"="c:\windows\tsnpstd3.exe" [2005-12-20 94208]
"snpstd3"="c:\windows\vsnpstd3.exe" [2006-09-19 827392]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384]
"REGSHAVE"="c:\program files\REGSHAVE\REGSHAVE.EXE" [2002-02-04 53248]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-04-15 1932568]
"ISTray"="c:\program files\Spyware Doctor\pctsTray.exe" [2008-11-02 1168264]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-06-29 185896]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\Glenn\Start Menu\Programs\Startup\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2006-1-19 108544]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
ExifLauncher2.lnk - c:\program files\FinePixViewer\QuickDCF2.exe [2008-2-7 303104]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
NkvMon.exe.lnk - c:\program files\Nikon\NkView6\NkvMon.exe [2006-1-17 233472]
QuickTV.lnk - c:\program files\AVerTV USB 2.0 Plus\QuickTV.exe [2005-6-24 401408]
WlanUtility.lnk - c:\program files\MicroStar\WLANUtility\WlanUtility.exe [2005-10-14 173056]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-04-15 18:15 10520 —-a-w c:\windows\system32\avgrsstx.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\SmartFTP Client 2.0\\SmartFTP.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\WebEye\\WebEye.exe"=
"c:\\Program Files\\GameCenter\\GameCenter.exe"=
"c:\\Program Files\\Pro Cycling Manager 2007\\PCM.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\Zattoo\\zattood.exe"=
"c:\\Program Files\\Zattoo\\Zattoo2.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Zattoo\\Zattoo.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\MicroStar\\WLANUtility\\APUtility.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Sports Interactive\\Football Manager 2009\\fm.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=

R2 gupdate1c98b04c8dcc954;Google Update Service (gupdate1c98b04c8dcc954);c:\program files\Google\Update\GoogleUpdate.exe [2009-02-09 133104]
S0 pe3akt6c;Cycling Manager 2007 Environment Driver (pe3akt6c);c:\windows\system32\drivers\pe3akt6c.sys [2007-06-08 64912]
S0 pf2akt6c;Cycling Manager 2007 File System Driver (pf2akt6c);c:\windows\system32\drivers\pf2akt6c.sys [2007-06-08 83856]
S0 ps6akt6c;Cycling Manager 2007 Synchronization Driver (ps6akt6c);c:\windows\system32\drivers\ps6akt6c.sys [2007-06-08 55704]
S0 ps7akt6c;Cycling Manager 2007 Synchronization Driver (ps7akt6c);c:\windows\system32\drivers\ps7akt6c.sys [2007-09-28 68752]
S1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\System32\Drivers\avgldx86.sys [2009-04-15 325640]
S1 AvgTdiX;AVG8 Network Redirector;c:\windows\System32\Drivers\avgtdix.sys [2009-04-15 108552]
S2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2009-04-15 908056]
S2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-04-15 298264]
S2 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [2008-06-13 356920]
S3 StkMini;AVerTV USB 2.0 Plus Video Capture;c:\windows\system32\Drivers\StkMini.sys [2005-02-15 185792]


— Other Services/Drivers In Memory —

*Deregistered* - mchInjDrv

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d9ee93ab-867a-11dd-a58e-0011092a4082}]
\Shell\AutoRun\command - G:\setupSNK.exe
.
Contents of the 'Scheduled Tasks' folder

2009-04-17 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-06-08 19:10]

2009-04-17 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-09 22:21]
.
.
——- Supplementary Scan ——-
.
uInternet Connection Wizard,ShellNext = hxxp://www.dell.co.uk/myway
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office10\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Glenn\Application Data\Mozilla\Firefox\Profiles\7xvfgbuy.Default User\
FF - prefs.js: browser.startup.homepage - hxxp://login.live.com/login.srf?id=2
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.141.5\npGoogleOneClick7.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
.

**************************************************************************

catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-04-18 00:40
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(3600)
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\SmartFTP Client 2.0\smarthook.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Spyware Doctor\pctsSvc.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\program files\Spyware Doctor\sdhelp.exe
c:\program files\AVG\AVG8\avgcsrvx.exe
c:\program files\MicroStar\WLANUtility\WLAN_Service.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-04-17 0:45 - machine was rebooted
ComboFix-quarantined-files.txt 2009-04-17 23:44
ComboFix2.txt 2009-04-16 17:36
ComboFix3.txt 2009-04-10 15:08

Pre-Run: 69,740,621,824 bytes free
Post-Run: 69,729,427,456 bytes free

426 — E O F — 2009-04-17 00:23


MBAM log:

Malwarebytes' Anti-Malware 1.36
Database version: 1996
Windows 5.1.2600 Service Pack 3

18/04/2009 00:54:49
mbam-log-2009-04-18 (00-54-49).txt

Scan type: Quick Scan
Objects scanned: 75122
Time elapsed: 3 minute(s), 2 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 2
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\Program Files\MyWaySA (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWaySA\SrchAsDe (Adware.MyWebSearch) -> Quarantined and deleted successfully.

Files Infected:
(No malicious items detected)


Cheers buddy!
Hello.

How's your computer running now?

Do you have the latest Java (Ver.Java 6 update 13) ?

If not, please install it in the link below, under Kaspersky heading with the link Java Runtime Environment (JRE)

Run Scan with Kaspersky

Please do a scan with Kaspersky Online Scanner. Please note: Kaspersky requires Java Runtime Environment (JRE) be installed before scanning for malware, as ActiveX is no longer being used.)

If you are using Windows Vista, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.


  • Open the Kaspersky WebScanner
    page.
  • Click on the 🖼Click to load external image (Posted Image) button on the main page.
  • The program will launch and fill in the Information section on the left.
  • Read the "Requirements and Limitations" then press the 🖼Click to load external image (Posted Image) button.
  • The program will begin downloading the latest program and definition files. It may take a while so please be patient and let it finish.
  • Once the files have been downloaded, click on the 🖼Click to load external image (Posted Image) …button.
    In the scan settings make sure the following are selected:
    • Detect malicious programs of the following categories:
      Viruses, Worms, Trojan Horses, Rootkits
      Spyware, Adware, Dialers and other potentially dangerous programs
    • Scan compound files (doesn't apply to the File scan area):
      Archives
      Mail databases
      By default the above items should already be checked.
    • Click the 🖼Click to load external image (Posted Image) button, if you made any changes.
  • Now under the Scan section on the left:

    Select My Computer
  • The program will now start and scan your system. This will run for a while, be patient and let it finish.
  • Once the scan is complete, click on View scan report
  • Now, click on the Save Report as button.
  • Save the file to your desktop.
  • Copy and paste that information in your next post.
You can refer to this animation by sundavis.

Post back with:
-Kaspersky log
-New Hijackthis log

With Regards,
Extremeboy
Hi,
My computer is running fine, if a little slow. I do keep getting unwanted pop-ups when on the internet though, which I never got before.

Here are the latest logs:

Kaspersky Log:

——————————————————————————–
KASPERSKY ONLINE SCANNER 7.0 REPORT
Sunday, April 19, 2009
Operating System: Microsoft Windows XP Professional Service Pack 3 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Program database last update: Sunday, April 19, 2009 15:14:47
Records in database: 2060684
——————————————————————————–

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
C:\
D:\

Scan statistics:
Files scanned: 99840
Threat name: 3
Infected objects: 11
Suspicious objects: 0
Duration of the scan: 04:23:24


File name / Threat name / Threats count
C:\Program Files\MicroStar\WLANUtility\WLAN_Service.exe/C:\Program Files\MicroStar\WLANUtility\WLAN_Service.exe Infected: not-a-virus:AdWare.Win32.Agent.emg 1
C:\Program Files\MicroStar\WLANUtility\WLAN_Service.exe Infected: not-a-virus:AdWare.Win32.Agent.emg 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\senekaecbqylby.dll.vir Infected: Trojan.Win32.Tdss.sbq 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\senekahostyjai.dll.vir Infected: Trojan.Win32.Tdss.vcg 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\senekahxrwcnlr.dll.vir Infected: Trojan.Win32.Tdss.vcg 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\senekaiqppptxd.dll.vir Infected: Trojan.Win32.Tdss.sbq 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\senekaivrxbdmu.dll.vir Infected: Trojan.Win32.Tdss.sbq 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\senekakigyupbm.dll.vir Infected: Trojan.Win32.Tdss.vcg 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\senekapfpmpeqr.dll.vir Infected: Trojan.Win32.Tdss.sbq 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\senekasxmulrqj.dll.vir Infected: Trojan.Win32.Tdss.vcg 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\senekauthqfgoi.dll.vir Infected: Trojan.Win32.Tdss.sbq 1

The selected area was scanned.


HiJackThis.txt:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:46:29, on 19/04/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\WINDOWS\tsnpstd3.exe
C:\WINDOWS\vsnpstd3.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DNA\btdna.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\FinePixViewer\QuickDCF2.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Nikon\NkView6\NkvMon.exe
C:\Program Files\AVerTV USB 2.0 Plus\QuickTV.exe
C:\Program Files\MicroStar\WLANUtility\WlanUtility.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\MicroStar\WLANUtility\WLAN_Service.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Java\jre6\bin\java.exe
C:\Documents and Settings\Glenn\Local Settings\temp\jkos-Glenn\binaries\ScanningProcess.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Documents and Settings\Glenn\Local Settings\temp\jkos-Glenn\binaries\ScanningProcess.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell.co.uk/myway
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll (file missing)
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll (file missing)
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [tsnpstd3] C:\WINDOWS\tsnpstd3.exe
O4 - HKLM\..\Run: [snpstd3] C:\WINDOWS\vsnpstd3.exe
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: ExifLauncher2.lnk = C:\Program Files\FinePixViewer\QuickDCF2.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: NkvMon.exe.lnk = C:\Program Files\Nikon\NkView6\NkvMon.exe
O4 - Global Startup: QuickTV.lnk = C:\Program Files\AVerTV USB 2.0 Plus\QuickTV.exe
O4 - Global Startup: WlanUtility.lnk = C:\Program Files\MicroStar\WLANUtility\WlanUtility.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1138911712031
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Google Update Service (gupdate1c98b04c8dcc954) (gupdate1c98b04c8dcc954) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Imapi Helper - Alex Feinman - C:\Program Files\ISO Recorder\ImapiHelper.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe

–
End of file - 9123 bytes

Sooth
Hello.

I do keep getting unwanted pop-ups when on the internet though, which I never got before.

Any specfic sites, and what kind of pop-ups? Is this in IE or FF? Please be a bit more specfic and elaborate a bit please.

Thanks.

With Regards,
Extremeboy
In FF. Mainly advertising pop-ups, selling various things, including anti-virus software! Also when I use Google, sometimes the links take me to other websites.

examples are:
hxxp://www.google.co.uk/undefined
hxxp://www.britanniasearch.co.uk/search.asp?q=anything"
hxxp://www.approvedchoices.com/search44.php?clickid=B582C28E-3524-4FE9-9851-793997076AF5&keyword=anything

Did the latest log files tell you anything useful?

Sooth

/edit: To kill links (not necessarily bad however.)
Hello.

Thank you. That helps. Please run the following tool.

Run GooredFix using Option2 (Removal)

Please download GooredFix and save it to your Desktop.
Alternative Download Mirror #2

Please make sure all instances of Firefox are closed at this point before proceeding.

  • Please double-click Goored.exe on your Desktop to run it.
  • A window will appear, please Select 2. (Fix Goored) by typing 2 and pressing Enter.
  • Type Y at the prompt and press Enter. The removal process will begin
  • A log will open with the file after completion, please post the contents of that log in your next reply
*Note: The log can also be found on your desktop (Goored.txt)

Reboot your computer and let me know if you still have the redirects.

Now, please run the following tool.

Download and Run DDS

We need to see some information about what is happening in your machine. Please perform the following scan:
  • Download DDS by sUBs from one of the following links. Save it to your desktop.
  • Double click on the DDS icon, allow it to run.
  • A small box will open, with an explanation about the tool. No input is needed, the scan is running.
  • Notepad will open with the results, click no to the Optional_Scan
  • Follow the instructions that pop up for posting the results.
  • Close the program window, and delete the program from your desktop.
Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet. Information on A/V control HERE

– Note: The screen instructions indicate the attach.txt must be zipped before attaching (not posted) to your forum post. Instead, we want you to include attach.txt as an attachment to upload using the "Browse" button in the text editor when making your reply.

For your next reply I would like to see:
-GooredFix log
-DDS log
-Attach log
-Do you still have redirects?

With Regards,
Extremeboy
OK, first of all, the redirects seem to have stopped, I think. :)

Here are the logs.

Goored Log:

GooredFix v1.92 by jpshortstuff
Log created at 20:04 on 22/04/2009 running Option #2 (Glenn)
Firefox version 3.0.8 (en-US)

=====Goored Deletions=====
C:\Program Files\Mozilla Firefox\extensions\{EC9A0484-C574-4D77-A6DC-6C8347379A2A}
->Backing up folder… Done.
->Emptying folder… Done.
->Deleting folder… Done.
C:\Program Files\Mozilla Firefox\extensions\{CC1EBE8F-D7AB-42B9-AAA6-B587C54E64FF}
->Backing up folder… Done.
->Emptying folder… Done.
->Deleting folder… Done.
C:\Program Files\Mozilla Firefox\extensions\{9CD5AEA9-BD79-40EB-A5FA-18BCA64DB103}
->Backing up folder… Done.
->Emptying folder… Done.
->Deleting folder… Done.
C:\Program Files\Mozilla Firefox\extensions\{930FD9A8-43D4-4F6D-869D-F5DA210D787E}
->Backing up folder… Done.
->Emptying folder… Done.
->Deleting folder… Done.

=====Dumping Registry Values=====

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox 3.0.8\extensions]
"Plugins"="C:\Program Files\Mozilla Firefox\plugins"

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox 3.0.8\extensions]
"Components"="C:\Program Files\Mozilla Firefox\components"

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions]
"[removed]"="C:\Program Files\Java\jre6\lib\deploy\jqs\ff"

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions]
"{3f963a5b-e555-4543-90e2-c3908898db71}"="C:\Program Files\AVG\AVG8\Firefox"


DDS log:

DDS (Ver_09-03-16.01) - NTFSx86
Run by [removed] at 20:16:42.64 on 22/04/2009
Internet Explorer: 7.0.5730.11 BrowserJavaVersion: 1.6.0_13
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.608 [GMT 1:00]

AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated)

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\WINDOWS\tsnpstd3.exe
C:\WINDOWS\vsnpstd3.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DNA\btdna.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\Program Files\FinePixViewer\QuickDCF2.exe
C:\Program Files\Nikon\NkView6\NkvMon.exe
C:\Program Files\AVerTV USB 2.0 Plus\QuickTV.exe
C:\Program Files\MicroStar\WLANUtility\WlanUtility.exe
svchost.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Program Files\MicroStar\WLANUtility\WLAN_Service.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Documents and Settings\Glenn\Desktop\dds.com

============== Pseudo HJT Report ===============

uInternet Connection Wizard,ShellNext = hxxp://www.dell.co.uk/myway
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 6.0\reader\activex\AcroIEHelper.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
BHO: PCTools Site Guard: {5c8b2a36-3db1-42a4-a3cb-d426709bbfeb} - c:\progra~1\spywar~1\tools\iesdsg.dll
BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\tfswshx.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.3572\swg.dll
BHO: PCTools Browser Monitor: {b56a7d7d-6927-48c8-a975-17df180c71ac} - c:\progra~1\spywar~1\tools\iesdpb.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [BitTorrent DNA] "c:\program files\dna\btdna.exe"
uRun: [DAEMON Tools Lite] "c:\program files\daemon tools lite\daemon.exe" -autorun
mRun: [igfxtray] c:\windows\system32\igfxtray.exe
mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe
mRun: [igfxpers] c:\windows\system32\igfxpers.exe
mRun: [DVDLauncher] "c:\program files\cyberlink\powerdvd\DVDLauncher.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [dla] c:\windows\system32\dla\tfswctrl.exe
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [MSKDetectorExe] c:\program files\mcafee\spamkiller\MSKDetct.exe /uninstall
mRun: [PWRISOVM.EXE] c:\program files\poweriso\PWRISOVM.EXE
mRun: [tsnpstd3] c:\windows\tsnpstd3.exe
mRun: [snpstd3] c:\windows\vsnpstd3.exe
mRun: [dscactivate] "c:\program files\dell support center\gs_agent\custom\dsca.exe"
mRun: [REGSHAVE] c:\program files\regshave\REGSHAVE.EXE /AUTORUN
mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
StartupFolder: c:\docume~1\glenn\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\exifla~1.lnk - c:\program files\finepixviewer\QuickDCF2.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\nkvmon~1.lnk - c:\program files\nikon\nkview6\NkvMon.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\quicktv.lnk - c:\program files\avertv usb 2.0 plus\QuickTV.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\wlanut~1.lnk - c:\program files\microstar\wlanutility\WlanUtility.exe
IE: E&xport; to Microsoft Excel - c:\progra~1\micros~4\office10\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - {A1EDC4A1-940F-48E0-8DFD-E38F1D501021} - c:\progra~1\spywar~1\tools\iesdpb.dll
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1138911712031
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {CAFEEFAC-0015-0000-0008-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_08-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_10-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: avgrsstarter - avgrsstx.dll
Notify: igfxcui - igfxdev.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\glenn\applic~1\mozilla\firefox\profiles\7xvfgbuy.default user\
FF - prefs.js: browser.startup.homepage - hxxp://login.live.com/login.srf?id=2
FF - component: c:\program files\avg\avg8\firefox\components\avgssff.dll
FF - plugin: c:\program files\google\google updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\google\update\1.2.141.5\npGoogleOneClick7.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npbittorrent.dll
FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll

============= SERVICES / DRIVERS ===============

R0 pe3akt6c;Cycling Manager 2007 Environment Driver (pe3akt6c);c:\windows\system32\drivers\pe3akt6c.sys [2007-6-8 64912]
R0 pf2akt6c;Cycling Manager 2007 File System Driver (pf2akt6c);c:\windows\system32\drivers\pf2akt6c.sys [2007-6-8 83856]
R0 ps6akt6c;Cycling Manager 2007 Synchronization Driver (ps6akt6c);c:\windows\system32\drivers\ps6akt6c.sys [2007-6-8 55704]
R0 ps7akt6c;Cycling Manager 2007 Synchronization Driver (ps7akt6c);c:\windows\system32\drivers\ps7akt6c.sys [2007-9-28 68752]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-5-10 325640]
R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2007-5-22 27656]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2008-5-10 108552]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\avg\avg8\avgemc.exe [2008-7-4 908056]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2008-7-4 298264]
R3 StkMini;AVerTV USB 2.0 Plus Video Capture;c:\windows\system32\drivers\StkMini.sys [2005-2-15 185792]
S2 gupdate1c98b04c8dcc954;Google Update Service (gupdate1c98b04c8dcc954);c:\program files\google\update\GoogleUpdate.exe [2009-2-9 133104]
S2 pr2akt6c;Cycling Manager 2007 Drivers Auto Removal (pr2akt6c);c:\windows\system32\pr2akt6c.exe svc –> c:\windows\system32\pr2akt6c.exe svc [?]
S3 IKFileSec;File Security Driver;c:\windows\system32\drivers\ikfilesec.sys [2008-6-8 40840]
S3 IKSysFlt;System Filter Driver;c:\windows\system32\drivers\iksysflt.sys [2008-6-8 66952]
S3 IKSysSec;System Security Driver;c:\windows\system32\drivers\iksyssec.sys [2008-6-8 81288]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\spyware doctor\pctsAuxs.exe [2008-6-8 356920]
S3 sdCoreService;PC Tools Security Service;c:\program files\spyware doctor\pctsSvc.exe [2008-6-8 1079176]

=============== Created Last 30 ================

2009-04-18 00:49 –d—– c:\docume~1\glenn\applic~1\Malwarebytes
2009-04-18 00:49 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-04-16 18:12 2,560 ——– c:\windows\system32\xpsp4res.dll
2009-04-16 18:12 1,203,922 ——– c:\windows\system32\dllcache\sysmain.sdb
2009-04-16 18:12 215,552 ——– c:\windows\system32\dllcache\wordpad.exe
2009-04-15 00:17 758 a—h— C:\aaw7boot.cmd
2009-04-14 20:58 –d—– c:\documents and settings\glenn\.housecall6.6
2009-04-14 20:42 –d—– c:\program files\CCleaner
2009-04-10 16:42 –d—– c:\program files\Trend Micro
2009-04-10 15:49 a-dshr– C:\cmdcons
2009-04-10 15:48 161,792 a——- c:\windows\SWREG.exe
2009-04-10 15:48 98,816 a——- c:\windows\sed.exe
2009-04-10 01:19 –d—– c:\program files\Spybot - Search & Destroy
2009-04-10 01:19 –d—– c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy

==================== Find3M ====================

2009-04-15 19:15 325,640 a——- c:\windows\system32\drivers\avgldx86.sys
2009-04-15 19:15 108,552 a——- c:\windows\system32\drivers\avgtdix.sys
2009-04-15 19:15 10,520 a——- c:\windows\system32\avgrsstx.dll
2009-03-21 15:06 989,696 ——– c:\windows\system32\dllcache\kernel32.dll
2009-03-09 05:19 410,984 a——- c:\windows\system32\deploytk.dll
2009-03-06 15:22 284,160 a——- c:\windows\system32\pdh.dll
2009-03-06 15:22 284,160 ——– c:\windows\system32\dllcache\pdh.dll
2009-03-03 01:18 826,368 a——- c:\windows\system32\wininet.dll
2009-03-03 01:18 826,368 a——- c:\windows\system32\dllcache\wininet.dll
2009-02-28 05:54 636,072 ——– c:\windows\system32\dllcache\iexplore.exe
2009-02-20 11:20 70,656 ——– c:\windows\system32\dllcache\ie4uinit.exe
2009-02-20 11:20 13,824 ——– c:\windows\system32\dllcache\ieudinit.exe
2009-02-20 06:14 161,792 ——– c:\windows\system32\dllcache\ieakui.dll
2009-02-09 13:10 729,088 a——- c:\windows\system32\lsasrv.dll
2009-02-09 13:10 729,088 ——– c:\windows\system32\dllcache\lsasrv.dll
2009-02-09 13:10 714,752 a——- c:\windows\system32\ntdll.dll
2009-02-09 13:10 617,472 a——- c:\windows\system32\advapi32.dll
2009-02-09 13:10 401,408 a——- c:\windows\system32\rpcss.dll
2009-02-09 13:10 714,752 ——– c:\windows\system32\dllcache\ntdll.dll
2009-02-09 13:10 617,472 ——– c:\windows\system32\dllcache\advapi32.dll
2009-02-09 13:10 473,600 ——– c:\windows\system32\dllcache\fastprox.dll
2009-02-09 13:10 453,120 ——– c:\windows\system32\dllcache\wmiprvsd.dll
2009-02-09 13:10 401,408 ——– c:\windows\system32\dllcache\rpcss.dll
2009-02-09 12:13 1,846,784 a——- c:\windows\system32\win32k.sys
2009-02-09 12:13 1,846,784 ——– c:\windows\system32\dllcache\win32k.sys
2009-02-07 19:02 2,066,048 ——– c:\windows\system32\dllcache\ntkrnlpa.exe
2009-02-06 12:11 110,592 a——- c:\windows\system32\services.exe
2009-02-06 12:11 110,592 ——– c:\windows\system32\dllcache\services.exe
2009-02-06 12:08 2,189,056 ——– c:\windows\system32\dllcache\ntoskrnl.exe
2009-02-06 12:06 2,145,280 a——- c:\windows\system32\ntoskrnl.exe
2009-02-06 12:06 2,145,280 ——– c:\windows\system32\dllcache\ntkrnlmp.exe
2009-02-06 11:39 35,328 a——- c:\windows\system32\sc.exe
2009-02-06 11:39 35,328 ——– c:\windows\system32\dllcache\sc.exe
2009-02-06 11:32 2,023,936 a——- c:\windows\system32\ntkrnlpa.exe
2009-02-06 11:32 2,023,936 ——– c:\windows\system32\dllcache\ntkrpamp.exe
2009-02-06 11:10 227,840 ——– c:\windows\system32\dllcache\wmiprvse.exe
2009-02-03 20:59 56,832 a——- c:\windows\system32\secur32.dll
2009-02-03 20:59 56,832 ——– c:\windows\system32\dllcache\secur32.dll
2008-06-14 22:43 33,904 a——- c:\docume~1\glenn\applic~1\GDIPFONTCACHEV1.DAT
2008-03-30 19:15 32 a——- c:\docume~1\alluse~1\applic~1\ezsid.dat
2006-02-03 20:19 56 —shr– c:\windows\system32\BA025EC27E.sys
2006-04-05 18:13 56 —shr– c:\windows\system32\F1AB804D5A.sys
2006-08-05 22:28 2,828 a–sh— c:\windows\system32\KGyGaAvL.sys
2008-11-28 14:34 32,768 a–sh— c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008112820081129\index.dat

============= FINISH: 20:17:16.68 ===============


Attach.txt is attached!

Regards,
Sooth

Attachments:

Hello.

A few things you need to be warned about and removed.

Peer-to-Peer Programs Warning

Your log shows that you are using so called peer-to-peer or file-sharing programs (in your case BitTorrent and LimeWire PRO 4.12.3). These programs allow to share files between users as the name(s) suggest. In today's world cyber crime has come to an enormous dimension and any means is used to infect personal computers to make use of their stored data or machine power for further propagation of the malware files. A popular means is the use of file-sharing tools as a tremendous amount of prospective victims can be reached through it.

It is therefore possible to be infected by downloading manipulated files via peer-to-peer tools and thus suggested to be used with intense care. Some further readings on this subject, along the included links, are as follows: File-Sharing, otherwise known as Peer To Peer and Risks of File-Sharing Technology.

It is also important to note that sharing entertainment files and proprietary software infringes the copyright laws in many countries over the world and you are putting yourself at risk of being indicted through organizations watching over the rights of the authors of such files (i.e. the RIAA for music files, or the MPAA for movie files in the USA) or the authors of the files themselves.

Naturally there are also legal ways to use these services, such as downloading Linux distributions or office suites such as "Open Office."

It is your decision whether or not you wish to keep your program(s) but I suggest you remove it via add/remove. However, please refrain from using them until your computer has been declared clean.

Also please remove the following older versions of Java since they are a security risk.

J2SE Runtime Environment 5.0 Update 10
J2SE Runtime Environment 5.0 Update 11
J2SE Runtime Environment 5.0 Update 8
Java 2 Runtime Environment, SE v1.4.2_03
Java™ 6 Update 2
Java™ 6 Update 3
Java™ 6 Update 5
Java™ SE Runtime Environment 6 Update 1


Then, let me know how your computer is running and post a new DDS log (attach as well).

With Regards,
Extremeboy
Computer seems fine.

DDS Log:


DDS (Ver_09-03-16.01) - NTFSx86
Run by [removed] at 22:33:56.93 on 22/04/2009
Internet Explorer: 7.0.5730.11
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.556 [GMT 1:00]

AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated)

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\WINDOWS\tsnpstd3.exe
C:\WINDOWS\vsnpstd3.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DNA\btdna.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\Program Files\FinePixViewer\QuickDCF2.exe
C:\Program Files\Nikon\NkView6\NkvMon.exe
C:\Program Files\AVerTV USB 2.0 Plus\QuickTV.exe
C:\Program Files\MicroStar\WLANUtility\WlanUtility.exe
svchost.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Program Files\MicroStar\WLANUtility\WLAN_Service.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\WINDOWS\system32\wscntfy.exe
C:\Documents and Settings\Glenn\Desktop\dds.com

============== Pseudo HJT Report ===============

uInternet Connection Wizard,ShellNext = hxxp://www.dell.co.uk/myway
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 6.0\reader\activex\AcroIEHelper.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
BHO: PCTools Site Guard: {5c8b2a36-3db1-42a4-a3cb-d426709bbfeb} - c:\progra~1\spywar~1\tools\iesdsg.dll
BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\tfswshx.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.3572\swg.dll
BHO: PCTools Browser Monitor: {b56a7d7d-6927-48c8-a975-17df180c71ac} - c:\progra~1\spywar~1\tools\iesdpb.dll
EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [BitTorrent DNA] "c:\program files\dna\btdna.exe"
uRun: [DAEMON Tools Lite] "c:\program files\daemon tools lite\daemon.exe" -autorun
mRun: [igfxtray] c:\windows\system32\igfxtray.exe
mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe
mRun: [igfxpers] c:\windows\system32\igfxpers.exe
mRun: [DVDLauncher] "c:\program files\cyberlink\powerdvd\DVDLauncher.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [dla] c:\windows\system32\dla\tfswctrl.exe
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [MSKDetectorExe] c:\program files\mcafee\spamkiller\MSKDetct.exe /uninstall
mRun: [PWRISOVM.EXE] c:\program files\poweriso\PWRISOVM.EXE
mRun: [tsnpstd3] c:\windows\tsnpstd3.exe
mRun: [snpstd3] c:\windows\vsnpstd3.exe
mRun: [dscactivate] "c:\program files\dell support center\gs_agent\custom\dsca.exe"
mRun: [REGSHAVE] c:\program files\regshave\REGSHAVE.EXE /AUTORUN
mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
StartupFolder: c:\docume~1\glenn\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\exifla~1.lnk - c:\program files\finepixviewer\QuickDCF2.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\nkvmon~1.lnk - c:\program files\nikon\nkview6\NkvMon.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\quicktv.lnk - c:\program files\avertv usb 2.0 plus\QuickTV.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\wlanut~1.lnk - c:\program files\microstar\wlanutility\WlanUtility.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office10\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - {A1EDC4A1-940F-48E0-8DFD-E38F1D501021} - c:\progra~1\spywar~1\tools\iesdpb.dll
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1138911712031
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: avgrsstarter - avgrsstx.dll
Notify: igfxcui - igfxdev.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\glenn\applic~1\mozilla\firefox\profiles\7xvfgbuy.default user\
FF - prefs.js: browser.startup.homepage - hxxp://login.live.com/login.srf?id=2
FF - component: c:\program files\avg\avg8\firefox\components\avgssff.dll
FF - plugin: c:\program files\google\google updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\google\update\1.2.141.5\npGoogleOneClick7.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npbittorrent.dll
FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll

============= SERVICES / DRIVERS ===============

R0 pe3akt6c;Cycling Manager 2007 Environment Driver (pe3akt6c);c:\windows\system32\drivers\pe3akt6c.sys [2007-6-8 64912]
R0 pf2akt6c;Cycling Manager 2007 File System Driver (pf2akt6c);c:\windows\system32\drivers\pf2akt6c.sys [2007-6-8 83856]
R0 ps6akt6c;Cycling Manager 2007 Synchronization Driver (ps6akt6c);c:\windows\system32\drivers\ps6akt6c.sys [2007-6-8 55704]
R0 ps7akt6c;Cycling Manager 2007 Synchronization Driver (ps7akt6c);c:\windows\system32\drivers\ps7akt6c.sys [2007-9-28 68752]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-5-10 325640]
R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2007-5-22 27656]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2008-5-10 108552]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\avg\avg8\avgemc.exe [2008-7-4 908056]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2008-7-4 298264]
R3 StkMini;AVerTV USB 2.0 Plus Video Capture;c:\windows\system32\drivers\StkMini.sys [2005-2-15 185792]
S2 gupdate1c98b04c8dcc954;Google Update Service (gupdate1c98b04c8dcc954);c:\program files\google\update\GoogleUpdate.exe [2009-2-9 133104]
S2 pr2akt6c;Cycling Manager 2007 Drivers Auto Removal (pr2akt6c);c:\windows\system32\pr2akt6c.exe svc –> c:\windows\system32\pr2akt6c.exe svc [?]
S3 IKFileSec;File Security Driver;c:\windows\system32\drivers\ikfilesec.sys [2008-6-8 40840]
S3 IKSysFlt;System Filter Driver;c:\windows\system32\drivers\iksysflt.sys [2008-6-8 66952]
S3 IKSysSec;System Security Driver;c:\windows\system32\drivers\iksyssec.sys [2008-6-8 81288]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\spyware doctor\pctsAuxs.exe [2008-6-8 356920]
S3 sdCoreService;PC Tools Security Service;c:\program files\spyware doctor\pctsSvc.exe [2008-6-8 1079176]

=============== Created Last 30 ================

2009-04-18 00:49 –d—– c:\docume~1\glenn\applic~1\Malwarebytes
2009-04-18 00:49 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-04-16 18:12 2,560 ——– c:\windows\system32\xpsp4res.dll
2009-04-16 18:12 1,203,922 ——– c:\windows\system32\dllcache\sysmain.sdb
2009-04-16 18:12 215,552 ——– c:\windows\system32\dllcache\wordpad.exe
2009-04-15 00:17 758 a—h— C:\aaw7boot.cmd
2009-04-14 20:58 –d—– c:\documents and settings\glenn\.housecall6.6
2009-04-14 20:42 –d—– c:\program files\CCleaner
2009-04-10 16:42 –d—– c:\program files\Trend Micro
2009-04-10 15:49 a-dshr– C:\cmdcons
2009-04-10 15:48 161,792 a——- c:\windows\SWREG.exe
2009-04-10 15:48 98,816 a——- c:\windows\sed.exe
2009-04-10 01:19 –d—– c:\program files\Spybot - Search & Destroy
2009-04-10 01:19 –d—– c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy

==================== Find3M ====================

2009-04-15 19:15 325,640 a——- c:\windows\system32\drivers\avgldx86.sys
2009-04-15 19:15 108,552 a——- c:\windows\system32\drivers\avgtdix.sys
2009-04-15 19:15 10,520 a——- c:\windows\system32\avgrsstx.dll
2009-03-21 15:06 989,696 ——– c:\windows\system32\dllcache\kernel32.dll
2009-03-09 05:19 410,984 a——- c:\windows\system32\deploytk.dll
2009-03-06 15:22 284,160 a——- c:\windows\system32\pdh.dll
2009-03-06 15:22 284,160 ——– c:\windows\system32\dllcache\pdh.dll
2009-03-03 01:18 826,368 a——- c:\windows\system32\wininet.dll
2009-03-03 01:18 826,368 a——- c:\windows\system32\dllcache\wininet.dll
2009-02-28 05:54 636,072 ——– c:\windows\system32\dllcache\iexplore.exe
2009-02-20 11:20 70,656 ——– c:\windows\system32\dllcache\ie4uinit.exe
2009-02-20 11:20 13,824 ——– c:\windows\system32\dllcache\ieudinit.exe
2009-02-20 06:14 161,792 ——– c:\windows\system32\dllcache\ieakui.dll
2009-02-09 13:10 729,088 a——- c:\windows\system32\lsasrv.dll
2009-02-09 13:10 729,088 ——– c:\windows\system32\dllcache\lsasrv.dll
2009-02-09 13:10 714,752 a——- c:\windows\system32\ntdll.dll
2009-02-09 13:10 617,472 a——- c:\windows\system32\advapi32.dll
2009-02-09 13:10 401,408 a——- c:\windows\system32\rpcss.dll
2009-02-09 13:10 714,752 ——– c:\windows\system32\dllcache\ntdll.dll
2009-02-09 13:10 617,472 ——– c:\windows\system32\dllcache\advapi32.dll
2009-02-09 13:10 473,600 ——– c:\windows\system32\dllcache\fastprox.dll
2009-02-09 13:10 453,120 ——– c:\windows\system32\dllcache\wmiprvsd.dll
2009-02-09 13:10 401,408 ——– c:\windows\system32\dllcache\rpcss.dll
2009-02-09 12:13 1,846,784 a——- c:\windows\system32\win32k.sys
2009-02-09 12:13 1,846,784 ——– c:\windows\system32\dllcache\win32k.sys
2009-02-07 19:02 2,066,048 ——– c:\windows\system32\dllcache\ntkrnlpa.exe
2009-02-06 12:11 110,592 a——- c:\windows\system32\services.exe
2009-02-06 12:11 110,592 ——– c:\windows\system32\dllcache\services.exe
2009-02-06 12:08 2,189,056 ——– c:\windows\system32\dllcache\ntoskrnl.exe
2009-02-06 12:06 2,145,280 a——- c:\windows\system32\ntoskrnl.exe
2009-02-06 12:06 2,145,280 ——– c:\windows\system32\dllcache\ntkrnlmp.exe
2009-02-06 11:39 35,328 a——- c:\windows\system32\sc.exe
2009-02-06 11:39 35,328 ——– c:\windows\system32\dllcache\sc.exe
2009-02-06 11:32 2,023,936 a——- c:\windows\system32\ntkrnlpa.exe
2009-02-06 11:32 2,023,936 ——– c:\windows\system32\dllcache\ntkrpamp.exe
2009-02-06 11:10 227,840 ——– c:\windows\system32\dllcache\wmiprvse.exe
2009-02-03 20:59 56,832 a——- c:\windows\system32\secur32.dll
2009-02-03 20:59 56,832 ——– c:\windows\system32\dllcache\secur32.dll
2008-06-14 22:43 33,904 a——- c:\docume~1\glenn\applic~1\GDIPFONTCACHEV1.DAT
2008-03-30 19:15 32 a——- c:\docume~1\alluse~1\applic~1\ezsid.dat
2006-02-03 20:19 56 —shr– c:\windows\system32\BA025EC27E.sys
2006-04-05 18:13 56 —shr– c:\windows\system32\F1AB804D5A.sys
2006-08-05 22:28 2,828 a–sh— c:\windows\system32\KGyGaAvL.sys
2008-11-28 14:34 32,768 a–sh— c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008112820081129\index.dat

============= FINISH: 22:34:06.54 ===============

Sooth

Attachments:

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI