boeman1995
Topic Starter
Hey! I got a message that I have Renos.IO on my Vista a few days ago, and it seemed smart to look at what it is… Now, I've become quite worried, and want to fix it, as it is still in an early stage and my I-net is still working fine…I think. I really anna fix it, because I have So much schoolstuff and other things on my Comp, that it would be an absolute disaster if I lost it… And I'm 13 years old, so it doesn't get better… Please help me! I heard something about logs, and I saw in another topic here, that you had to dl dds.pif, so I did, and then I copied the log… Here it is!
DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 19:56:26,69 on vr 10-07-2009
Internet Explorer: 8.0.6001.18783
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.31.1043.18.2047.902 [GMT 2:00]
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\Ati2evxx.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\taskeng.exe
C:\Windows\msa.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
c:\hp\HPEZBTN\HPBtnSrv.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\hp\support\hpsysdrv.exe
C:\PROGRA~1\AVG\AVG8\avgam.exe
C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Windows\system32\svchost.exe -k hpdevmgmt
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\Windows\system32\schtasks.exe
c:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\Creative\Creative ZEN\ZEN Media Explorer\CTCheck.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Search Settings\SearchSettings.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Program Files\SweetIM\Messenger\SweetIM.exe
C:\Program Files\AVG\AVG8\avgtray.exe
C:\Windows\system32\SearchIndexer.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\WUDFHost.exe
C:\Program Files\Logitech\QuickCam\Quickcam.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe
C:\Windows\system32\jusched.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Users\Rick\Program Files\DNA\btdna.exe
C:\Program Files\BitTorrent\bittorrent.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Windows\system32\svchost.exe -k HPService
C:\Program Files\Mozilla Firefox\firefox.exe
C:\hp\kbd\kbd.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\system32\DllHost.exe
C:\Users\Rick\Downloads\dds.pif
C:\Windows\system32\conime.exe
C:\Windows\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.ask.com/?o=101764&l;=dis
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
mStart Page = hxxp://www.yahoo.com
mDefault_Page_URL = hxxp://www.yahoo.com
uInternet Settings,ProxyOverride = plimus.com,www.plimus.com,regnow.com,www.regnow.com,;*.local
uInternet Settings,ProxyServer = socks=
uURLSearchHooks: H - No File
uURLSearchHooks: H - No File
uURLSearchHooks: H - No File
uURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg8\toolbar\IEToolbar.dll
mURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg8\toolbar\IEToolbar.dll
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: Adobe PDF Reader Help bij koppelingen: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Skype add-on (mastermind): {22bf413b-c6d2-4d91-82a9-a0f997ba588c} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
BHO: XML Class: {500bca15-57a7-4eaf-8143-8c619470b13d} - c:\windows\system32\msxml71.dll
BHO: Click-to-Call BHO: {5c255c8a-e604-49b4-9d64-90988571cecb} - c:\program files\windows live\messenger\wlchtc.dll
BHO: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - No File
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_01\bin\ssv.dll
BHO: Windows Live Aanmelden - Help: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg8\toolbar\IEToolbar.dll
BHO: SearchSettings Class: {e312764e-7706-43f1-8dab-fcdd2b1e416d} - c:\program files\search settings\kb127\SearchSettings.dll
BHO: SweetIM Toolbar Helper: {eee6c35c-6118-11dc-9c72-001320c79847} - c:\program files\sweetim\toolbars\internet explorer\mgToolbarIE.dll
BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
TB: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
TB: SweetIM Toolbar for Internet Explorer: {eee6c35b-6118-11dc-9c72-001320c79847} - c:\program files\sweetim\toolbars\internet explorer\mgToolbarIE.dll
TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - c:\program files\avg\avg8\toolbar\IEToolbar.dll
TB: {E67C74F4-A00A-4F2C-9FEC-FD9DC004A67F} - No File
TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
uRun: [MsnMsgr] ~"c:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: [Netlog Music Tool] "c:\program files\netlog music tool\NetlogMusicTool.exe"
uRun: [CTSyncU.exe] "c:\program files\creative\sync manager unicode\CTSyncU.exe"
uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized
uRun: [DAEMON Tools Lite] "c:\program files\daemon tools lite\daemon.exe" -autorun
uRun: [BitTorrent DNA] "c:\users\rick\program files\dna\btdna.exe"
uRun: [BitTorrent] "c:\program files\bittorrent\bittorrent.exe"
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRunOnce: [Shockwave Updater] c:\windows\system32\adobe\shockw~1\SWHELP~2.EXE -Update -1103472 -"Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0; SIMBAR={5A7D5C6F-2232-496B-87D8-7E7ABA46DD85}; SLCC1; .NET CLR 2.0.50727; Media Center PC 5.0; Dealio Toolbar 3.4; .NET CLR 1.1.4322; .NET CLR 3.0.30618; .NET CLR 3.5.30729)" -"http://www.switchin.net/switchlaunch.php?partner=bbgames"
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [hpsysdrv] c:\hp\support\hpsysdrv.exe
mRun: [KBD] c:\hp\kbd\KbdStub.EXE
mRun: [OsdMaestro] "c:\program files\hewlett-packard\on-screen osd indicator\OSD.exe"
mRun: [RtHDVCpl] RtHDVCpl.exe
mRun: [HP Health Check Scheduler] [ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
mRun: [SunJavaUpdateReg] "c:\windows\system32\jureg.exe"
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: []
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe"
mRun: [hpqSRMon] c:\program files\hp\digital imaging\bin\hpqSRMon.exe
mRun: [IAAnotif] "c:\program files\intel\intel matrix storage manager\Iaanotif.exe"
mRun: [CTCheck] c:\program files\creative\creative zen\zen media explorer\CTCheck.exe
mRun: [SearchSettings] c:\program files\search settings\SearchSettings.exe
mRun: [SweetIM] c:\program files\sweetim\messenger\SweetIM.exe
mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [LogitechQuickCamRibbon] "c:\program files\logitech\quickcam\Quickcam.exe" /hide
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport; to Microsoft Excel - c:\progra~1\micros~3\office11\EXCEL.EXE/3000
IE: E&xporteren; naar Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_01\bin\ssv.dll
IE: {77BF5300-1474-4EC7-9980-D32B190E9B07} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/C/0/C/C0CBBA88-A6F2-48D9-9B0E-1719D1177202/LegitCheckControl.cab
DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884} - hxxp://www.creative.com/softwareupdate/su/ocx/15101/CTSUEng.cab
DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} - hxxp://cid-4600194146f8042a.spaces.live.com/PhotoUpload/VistaMsnPUpldnl-nl.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} - hxxp://game05.zylom.com/activex/zylomgamesplayer.cab
DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab
DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - hxxp://www.creative.com/softwareupdate/su/ocx/15106/CTPID.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
AppInit_DLLs: avgrsstx.dll
================= FIREFOX ===================
FF - ProfilePath - c:\users\rick\appdata\roaming\mozilla\firefox\profiles\mjed6qtw.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo! Search
FF - prefs.js: browser.startup.homepage - hxxp://www.ask.com/?o=101764&l;=dis
FF - prefs.js: keyword.URL - hxxp://toolbar.ask.com/toolbarv/askRedirect?o=101761&gct;=&gc;=1&q;=
FF - component: c:\program files\avg\avg8\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\avg\avg8\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\avg\avg8\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\avg\avg8\toolbar\firefox\avg@igeared\components\xpavgtbapi.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npbittorrent.dll
FF - plugin: c:\users\rick\program files\dna\plugins\npbtdna.dll
FF - plugin: c:\windows\system32\c2mp\npdivx32.dll
============= SERVICES / DRIVERS ===============
R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [2009-3-29 12552]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-3-29 335752]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-3-29 108552]
R2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\avg\avg8\avgemc.exe [2009-5-6 907032]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2009-5-6 298776]
R2 HPBtnSrv;HP Chasis Button Service;c:\hp\hpezbtn\HPBtnSrv.exe [2007-12-22 198240]
R3 netr73;USB Wireless 802.11 b/g Adaptor Driver for Vista;c:\windows\system32\drivers\netr73.sys [2008-2-26 493568]
=============== Created Last 30 ================
2009-07-08 22:43 136,704 a——- c:\windows\msa.exe
2009-07-08 22:43 211,460 a——- c:\windows\system32\msxml71.dll
2009-07-04 21:35 –d—– c:\programdata\Test Drive Unlimited
2009-07-04 21:35 –d—– c:\progra~2\Test Drive Unlimited
2009-07-01 20:08 90,112 a——- c:\windows\unvise32.exe
2009-07-01 20:08 –d—– c:\program files\Magic Bullet Editors 2.0 Vegas
2009-07-01 20:01 –d—– c:\programdata\eSellerate
2009-07-01 20:01 –d—– c:\program files\common files\eSellerate
2009-07-01 20:01 –d—– c:\progra~2\eSellerate
2009-07-01 20:01 –d—– c:\program files\NewBlue
2009-07-01 19:52 –d—– c:\program files\Vstplugins
2009-07-01 19:51 –d—– c:\programdata\Sony
2009-07-01 19:51 –d—– c:\program files\Sony
2009-07-01 19:49 –d—– c:\program files\Sony Setup
2009-06-30 21:29 –d—– c:\program files\Bus Simulator
2009-06-18 16:56 11 a—-r– c:\windows\amunres.lsl
2009-06-15 17:54 –d—– c:\program files\Bonjour
2009-06-15 17:44 –d—– c:\program files\common files\Macrovision Shared
2009-06-14 19:31 428,544 a——- c:\windows\system32\EncDec.dll
2009-06-14 19:31 293,376 a——- c:\windows\system32\psisdecd.dll
2009-06-14 19:31 217,088 a——- c:\windows\system32\psisrndr.ax
2009-06-14 19:31 177,664 a——- c:\windows\system32\mpg2splt.ax
2009-06-14 19:31 80,896 a——- c:\windows\system32\MSNP.ax
2009-06-11 20:50 –d—– c:\windows\system32\xlive
2009-06-11 20:50 –d—– c:\program files\Microsoft Games for Windows - LIVE
2009-06-11 20:22 –d—– c:\program files\Rockstar Games
2009-06-11 18:36 –d—– c:\programdata\AVG Security Toolbar
2009-06-11 18:36 –d—– c:\progra~2\AVG Security Toolbar
==================== Find3M ====================
2009-07-08 19:55 335,752 a——- c:\windows\system32\drivers\avgldx86.sys
2009-07-01 21:15 711,660 a——- c:\windows\system32\perfh013.dat
2009-07-01 21:15 147,296 a——- c:\windows\system32\perfc013.dat
2009-05-26 18:42 119,037 a——- c:\windows\hpqins00.dat
2009-05-17 19:36 143,360 a——- c:\windows\inf\infstrng.dat
2009-05-17 19:36 86,016 a——- c:\windows\inf\infstor.dat
2009-05-17 19:36 51,200 a——- c:\windows\inf\infpub.dat
2009-05-09 07:50 915,456 a——- c:\windows\system32\wininet.dll
2009-05-09 07:34 71,680 a——- c:\windows\system32\iesetup.dll
2009-05-06 08:49 11,952 a——- c:\windows\system32\avgrsstx.dll
2009-04-23 14:43 784,896 a——- c:\windows\system32\rpcrt4.dll
2009-04-23 14:42 636,928 a——- c:\windows\system32\localspl.dll
2009-04-22 00:20 14,311,680 a——- c:\windows\system32\xlive.dll
2009-04-22 00:20 13,642,496 a——- c:\windows\system32\xlivefnt.dll
2009-04-21 13:55 2,033,152 a——- c:\windows\system32\win32k.sys
2009-04-19 20:43 796,672 a——- c:\windows\GPInstall.exe
2009-04-06 16:38 70,172 a——- c:\users\rick\Uninstal Ariane 800 X2 Airline Expansion Pack.exe
2009-04-06 16:29 48,909 a——- c:\users\rick\Uninstal Ariane Boeing 737-800 X2 P1.exe
2009-03-26 17:47 56 a—h— c:\programdata\ezsidmv.dat
2009-03-26 17:47 56 a—h— c:\progra~2\ezsidmv.dat
2009-02-04 19:30 32 a——- c:\programdata\ezsid.dat
2009-02-04 19:30 32 a——- c:\progra~2\ezsid.dat
2008-12-31 16:27 94,208 a——- c:\users\rick\appdata\roaming\ezplay.sys
2008-12-31 16:27 87,608 a——- c:\users\rick\appdata\roaming\inst.exe
2008-12-31 16:27 47,360 a——- c:\users\rick\appdata\roaming\pcouffin.sys
2008-07-19 13:24 10,954 a——- c:\program files\PaintInfo.txt
2008-07-16 01:00 174 a–sh— c:\program files\desktop.ini
2008-07-16 00:47 665,600 a——- c:\windows\inf\drvindex.dat
2008-05-20 17:29 1,360 a——- c:\users\rick\appdata\roaming\wklnhst.dat
2007-12-22 09:55 336,440 a——- c:\windows\inf\perflib\0413\perfi.dat
2007-12-22 09:55 336,440 a——- c:\windows\inf\perflib\0413\perfh.dat
2007-12-22 09:55 41,976 a——- c:\windows\inf\perflib\0413\perfd.dat
2007-12-22 09:55 41,976 a——- c:\windows\inf\perflib\0413\perfc.dat
2006-11-02 11:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 11:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 11:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 11:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat
2008-08-15 19:59 952 a–sh— c:\windows\system32\KGyGaAvL.sys
2007-12-22 10:11 8,192 a–sh— c:\windows\users\default\NTUSER.DAT
============= FINISH: 20:00:59,62 ===============
Here it is, and I hope you can help me…
