This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Cannot open hijack this or malwarebytes

32 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My computer is very slow. I have hijack this and malwarebytes both on my computer but when i click to open them neither will open. I also get redirected when i try to navigate to any page on the internet. Plaease help
Hi and Welcome,

NOTE:
  • Malware removal is NOT instantaneous, most infections require several courses of action to completely eradicate.
  • Absence of symptoms does not always mean the computer is clean
  • Kindly follow my instructions in the order posted.
  • Please DO NOT run any scans or fix items without my direction.



Please do the following:

STEP #1

Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.pif to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.


STEP #2


[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your next reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 22:03:57.06 on Sun 07/26/2009
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.495.54 [GMT -5:00]

AV: AVG Anti-Virus *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifSvc.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\PROGRA~1\AVG\AVG8\avgam.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\WINDOWS\System32\dmadmin.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifSvc.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\sistray.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Susan White\Local Settings\Temporary Internet Files\Content.IE5\J4JL0SQR\dds[1].pif
C:\Documents and Settings\Susan White\Local Settings\Temporary Internet Files\Content.IE5\J4JL0SQR\dds[1].pif

============== Pseudo HJT Report ===============

uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uStart Page = hxxp://www.google.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
uURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg8\toolbar\IEToolbar.dll
mURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg8\toolbar\IEToolbar.dll
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: AskBar BHO: {201f27d4-3704-41d6-89c1-aa35e39143ed} - c:\program files\askbardis\bar\bin\askBar.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
BHO: Yahoo! IE Services Button: {5bab4b5b-68bc-4b02-94d6-2fc0de4a7897} - c:\program files\yahoo!\common\yiesrvc.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_07\bin\ssv.dll
BHO: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg8\toolbar\IEToolbar.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.15642\swg.dll
BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll
BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\program files\yahoo!\companion\installs\cpn\YTSingleInstance.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - c:\program files\avg\avg8\toolbar\IEToolbar.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll
TB: Ask Toolbar: {3041d03e-fd4b-44e0-b742-2d9b88305f98} - c:\program files\askbardis\bar\bin\askBar.dll
TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe
uRun: [AdobeUpdater] c:\program files\common files\adobe\updater5\AdobeUpdater.exe
mRun: [SiSPower] "Rundll32.exe" SiSPower.dll,ModeAgent
mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide
mRun: [Symantec PIF AlertEng] "c:\program files\common files\symantec shared\pif\{b8e1dd85-8582-4c61-b58f-2f227fca9a08}\pifsvc.exe" /a /m "c:\program files\common

files\symantec shared\pif\{b8e1dd85-8582-4c61-b58f-2f227fca9a08}\AlertEng.dll"
mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: []
mRun: [RoxWatchTray] "c:\program files\common files\roxio shared\9.0\sharedcom\RoxWatchTray9.exe"
mRun: [sysmstray] c:\windows\mstre19.exe
mRunOnce: [Malwarebytes' Anti-Malware] c:\program files\malwarebytes' anti-malware\mbamgui.exe /install /silent
mRunOnce: [InnoSetupRegFile.0000000001] "c:\windows\is-AN067.exe" /REG
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
StartupFolder: c:\docume~1\alluse~1.win\startm~1\programs\startup\utilit~1.lnk - c:\windows\system32\sistray.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_07\bin\ssv.dll
IE: {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - c:\program files\yahoo!\common\yiesrvc.dll
IE: {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - {552781AF-37E4-4FEE-920A-CED9E648EADD} - c:\program files\common files\microsoft shared\encarta search bar\ENCSBAR.DLL
DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} - hxxp://zone.msn.com/binFrameWork/v10/StagingUI.cab55579.cab
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} - hxxp://pcpitstop.com/betapit/PCPitStop.CAB
DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} - hxxp://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper.dll
DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} - hxxp://zone.msn.com/BinFrameWork/v10/ZBuddy.cab55579.cab
DPF: {3F0EECCE-E138-11D1-8712-0060083D83F5} - hxxp://www.mgisoft.com/ActiveX/LPControl.cab
DPF: {48DD0448-9209-4F81-9F6D-D83562940134} - hxxp://lads.myspace.com/upload/MySpaceUploader1006.cab
DPF: {55027008-315F-4F45-BBC3-8BE119764741} - hxxp://static.slide.com/uploader/SlideImageUploader.cab
DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} - hxxp://zone.msn.com/binframework/v10/ZPAChat.cab55579.cab
DPF: {83AFB5CA-ED35-11D4-A452-0080C8D85045} - hxxp://67.15.101.33/g_bin/eng/poker_2_0_0_49.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {9BDF4724-10AA-43D5-BD15-AEA0D2287303} - hxxp://zone.msn.com/bingame/zpagames/zpa_txhe.cab60231.cab
DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} - hxxp://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
DPF: {BD8667B7-38D8-4C77-B580-18C3E146372C} - hxxp://www.imgag.com/cp/install/Crusher.cab
DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_06-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {D71F9A27-723E-4B8B-B428-B725E47CBA3E} - hxxp://imikimi.com/download/imikimi_plugin_0.5.1.cab
DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} - hxxp://zone.msn.com/binframework/v10/StProxy.cab55579.cab
DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} - hxxp://driveragent.com/files/driveragent.cab
TCP: NameServer = 85.255.112.177,85.255.112.117
TCP: {57B30B3A-39FA-4328-88D3-33C8D6176E7B} = 85.255.112.177,85.255.112.117
Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
Notify: avgrsstarter - avgrsstx.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\wifd1f~1\MpShHook.dll

============= SERVICES / DRIVERS ===============

R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [2009-5-13 12552]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-5-13 335752]
R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2009-5-13 27784]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-5-13 108552]
R2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\avg\avg8\avgemc.exe [2009-5-14 907032]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2009-5-14 298776]
R2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592]
S3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\drivers\motccgp.sys [2007-9-19 18176]
S3 motccgpfl;MotCcgpFlService;c:\windows\system32\drivers\motccgpfl.sys [2007-9-19 7680]

=============== Created Last 30 ================

2009-07-26 21:32 687,104 a——- c:\windows\is-AN067.exe
2009-07-26 21:32 10,498 a——- c:\windows\is-AN067.msg
2009-07-26 21:32 469 a——- c:\windows\is-AN067.lst
2009-07-14 19:52 10 a——- c:\windows\popcinfo.dat
2009-07-13 20:38 –d—– c:\docume~1\susanw~1\applic~1\BitTorrent
2009-07-13 20:38 –d—– c:\program files\BitTorrent
2009-07-13 20:37 –d—– c:\program files\AskBarDis
2009-07-13 20:36 –d—– c:\docume~1\susanw~1\applic~1\Convivea
2009-07-13 20:12 –d—– c:\docume~1\susanw~1\applic~1\AVS4YOU
2009-07-13 20:12 –d—– c:\docume~1\alluse~1.win\applic~1\AVS4YOU
2009-07-13 20:10 –d—– c:\program files\common files\AVSMedia
2009-07-13 20:10 1,700,352 a——- c:\windows\system32\GdiPlus.dll
2009-07-13 20:10 974,848 a——- c:\windows\system32\mfc70.dll
2009-07-13 20:10 487,424 a——- c:\windows\system32\msvcp70.dll
2009-07-13 20:10 344,064 a——- c:\windows\system32\msvcr70.dll
2009-07-13 20:10 24,576 a——- c:\windows\system32\msxml3a.dll
2009-07-13 20:10 –d—– c:\program files\AVS4YOU
2009-07-12 21:20 –d—– c:\docume~1\susanw~1\applic~1\MSNInstaller
2009-07-07 17:05 –d—– c:\program files\Elaborate Bytes
2009-07-06 17:00 1 —-h— c:\windows\bf23567.dat
2009-07-06 17:00 2 a——- c:\windows\0101120101465752.dat
2009-07-06 12:43 1 —-h— c:\windows\jmmark2.dat
2009-07-06 12:43 2 a——- c:\windows\0101120101465749.dat
2009-07-06 10:31 2 a——- c:\windows\0101120101464849.dat
2009-07-06 10:30 2 a——- c:\windows\010112010146118114.dat
2009-07-06 10:07 –d—– c:\docume~1\susanw~1\applic~1\DriverCure
2009-07-06 10:06 –d—– c:\docume~1\alluse~1.win\applic~1\ParetoLogic
2009-07-06 10:06 –d—– c:\docume~1\alluse~1.win\applic~1\DriverCure

==================== Find3M ====================

2009-07-13 13:36 38,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-13 13:36 19,096 a——- c:\windows\system32\drivers\mbam.sys
2009-07-04 09:03 335,752 a——- c:\windows\system32\drivers\avgldx86.sys
2009-06-07 22:38 4,810 a——- c:\docume~1\susanw~1\applic~1\wklnhst.dat
2009-05-22 09:13 256 a——- c:\documents and settings\susan white\pool.bin
2009-05-20 08:46 376,424 a——- c:\docume~1\susanw~1\applic~1\GDIPFONTCACHEV1.DAT
2009-05-14 18:41 11,952 a——- c:\windows\system32\avgrsstx.dll
2009-05-13 00:15 915,456 a——- c:\windows\system32\wininet.dll
2009-05-07 10:32 345,600 a——- c:\windows\system32\localspl.dll
2008-05-29 10:53 0 a–sh— c:\docume~1\susanw~1\applic~1\0000000000CHEV1.dat
2008-05-27 11:17 0 a–sh— c:\docume~1\susanw~1\applic~1\0000000000t.dat
2007-09-19 11:46 92,064 ac—— c:\documents and settings\susan white\mqdmmdm.sys
2007-09-19 11:46 79,328 ac—— c:\documents and settings\susan white\mqdmserd.sys
2007-09-19 11:46 66,656 ac—— c:\documents and settings\susan white\mqdmbus.sys
2007-09-19 11:46 25,600 ac—— c:\documents and settings\susan white\usbsermptxp.sys
2007-09-19 11:46 22,768 ac—— c:\documents and settings\susan white\usbsermpt.sys
2007-09-19 11:46 9,232 ac—— c:\documents and settings\susan white\mqdmmdfl.sys
2007-09-19 11:46 6,208 ac—— c:\documents and settings\susan white\mqdmcmnt.sys
2007-09-19 11:46 5,936 ac—— c:\documents and settings\susan white\mqdmwhnt.sys
2007-09-19 11:46 4,048 ac—— c:\documents and settings\susan white\mqdmcr.sys
2007-05-10 03:00 288,104 ac—— c:\program files\dxwebsetup.exe
2004-10-01 16:00 40,960 ac—— c:\program files\Uninstall_CDS.exe
2004-10-01 16:00 40,960 ac—— c:\program files\Uninstall_CDS(2).exe

============= FINISH: 22:05:18.09 ===============






UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_09-06-26.01)

Microsoft Windows XP Home Edition
Boot Device: \Device\HarddiskVolume1
Install Date: 5/10/2007 12:22:22 AM
System Uptime: 7/26/2009 9:25:31 PM (1 hours ago)

Motherboard: ASUSTeK Computer INC. | | P5S800-VM
Processor: Intel® Pentium® 4 CPU 3.00GHz | CPU 1 | 2992/200mhz

==== Disk Partitions =========================

A: is Removable
C: is FIXED (NTFS) - 149 GiB total, 112.201 GiB free.
D: is CDROM ()

==== Disabled Device Manager Items =============

Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description: PCI Simple Communications Controller
Device ID: PCI\VEN_14F1&DEV_2F30&SUBSYS_205114F1&REV_01\3&267A616A&0&50
Manufacturer:
Name: PCI Simple Communications Controller
PNP Device ID: PCI\VEN_14F1&DEV_2F30&SUBSYS_205114F1&REV_01\3&267A616A&0&50
Service:

==== System Restore Points ===================

RP244: 4/13/2009 1:14:46 PM - Software Distribution Service 3.0
RP245: 4/14/2009 11:04:18 AM - Software Distribution Service 3.0
RP246: 4/24/2009 12:08:57 PM - Software Distribution Service 3.0
RP247: 4/24/2009 8:58:17 PM - Software Distribution Service 3.0
RP248: 4/24/2009 9:54:11 PM - Removed BlackBerry Desktop Software 4.2
RP249: 4/24/2009 9:55:22 PM - Removed BlackBerry Device Software Updater.
RP250: 4/25/2009 9:25:38 AM - Installed BlackBerry Desktop Software 4.6.
RP251: 4/25/2009 9:36:02 AM - Installed Roxio Media Manager
RP252: 4/26/2009 10:07:35 AM - System Checkpoint
RP253: 4/27/2009 10:51:49 AM - System Checkpoint
RP254: 4/28/2009 11:19:37 AM - System Checkpoint
RP255: 4/29/2009 11:42:35 AM - System Checkpoint
RP256: 4/30/2009 2:14:57 PM - System Checkpoint
RP257: 5/1/2009 2:42:30 PM - System Checkpoint
RP258: 5/3/2009 8:10:22 AM - System Checkpoint
RP259: 5/4/2009 8:51:55 AM - Software Distribution Service 3.0
RP260: 5/5/2009 10:18:02 AM - System Checkpoint
RP261: 5/7/2009 9:23:31 AM - System Checkpoint
RP262: 5/11/2009 3:03:01 PM - System Checkpoint
RP263: 5/12/2009 9:20:05 PM - System Checkpoint
RP264: 5/13/2009 5:08:23 PM - Software Distribution Service 3.0
RP265: 5/13/2009 8:14:06 PM - Removed Norton Security Scan
RP266: 5/13/2009 8:32:25 PM - Installed AVG 8.0
RP267: 5/13/2009 8:56:43 PM - Software Distribution Service 3.0
RP268: 5/14/2009 6:39:10 PM - Avg8 Update
RP269: 5/14/2009 6:42:03 PM - Avg8 Update
RP270: 5/14/2009 6:48:19 PM - Software Distribution Service 3.0
RP271: 5/15/2009 9:03:33 AM - Removed BlackBerry Desktop Software 4.6.
RP272: 5/15/2009 9:12:21 AM - Removed Roxio Media Manager
RP273: 5/15/2009 9:18:09 AM - Removed Windows Live Messenger
RP274: 5/15/2009 9:19:21 AM - Removed Windows Live Mail
RP275: 5/15/2009 9:21:06 AM - Removed Windows Live Photo Gallery
RP276: 5/15/2009 9:23:09 AM - Removed Windows Live Sign-in Assistant
RP277: 5/15/2009 9:24:16 AM - Removed Windows Live installer
RP278: 5/16/2009 12:06:58 PM - System Checkpoint
RP279: 5/17/2009 2:05:15 PM - System Checkpoint
RP280: 5/18/2009 10:18:34 AM - Software Distribution Service 3.0
RP281: 5/18/2009 11:21:32 PM - Software Distribution Service 3.0
RP282: 5/19/2009 8:33:21 AM - Avg8 Update
RP283: 5/19/2009 8:34:07 AM - Avg8 Update
RP284: 5/19/2009 12:25:25 PM - Installed BlackBerry Desktop Software 4.6.
RP285: 5/19/2009 12:34:58 PM - Installed Roxio Media Manager
RP286: 5/20/2009 12:50:26 PM - System Checkpoint
RP287: 5/21/2009 3:24:46 PM - System Checkpoint
RP288: 5/22/2009 1:51:54 AM - Software Distribution Service 3.0
RP289: 5/23/2009 8:33:31 AM - System Checkpoint
RP290: 5/24/2009 9:22:49 AM - System Checkpoint
RP291: 5/24/2009 8:00:01 PM - Software Distribution Service 3.0
RP292: 5/25/2009 5:06:46 PM - Software Distribution Service 3.0
RP293: 5/27/2009 9:40:15 AM - System Checkpoint
RP294: 5/28/2009 1:49:29 PM - System Checkpoint
RP295: 5/28/2009 3:33:31 PM - Software Distribution Service 3.0
RP296: 5/29/2009 4:17:02 PM - System Checkpoint
RP297: 5/31/2009 11:47:26 AM - System Checkpoint
RP298: 6/1/2009 11:23:23 AM - Software Distribution Service 3.0
RP299: 6/2/2009 1:10:31 PM - System Checkpoint
RP300: 6/3/2009 2:10:19 PM - System Checkpoint
RP301: 6/4/2009 3:10:23 PM - System Checkpoint
RP302: 6/5/2009 10:46:02 AM - Software Distribution Service 3.0
RP303: 6/6/2009 11:28:34 AM - System Checkpoint
RP304: 6/7/2009 12:10:15 PM - System Checkpoint
RP305: 6/8/2009 12:48:34 PM - System Checkpoint
RP306: 6/8/2009 3:20:30 PM - Software Distribution Service 3.0
RP307: 6/9/2009 5:51:06 PM - System Checkpoint
RP308: 6/10/2009 6:18:04 PM - System Checkpoint
RP309: 6/10/2009 7:27:10 PM - Software Distribution Service 3.0
RP310: 6/10/2009 10:25:31 PM - Software Distribution Service 3.0
RP311: 6/11/2009 10:33:08 PM - System Checkpoint
RP312: 6/12/2009 1:32:30 AM - Software Distribution Service 3.0
RP313: 6/12/2009 8:31:48 AM - Avg8 Update
RP314: 6/12/2009 8:32:38 AM - Avg8 Update
RP315: 6/13/2009 8:59:49 AM - System Checkpoint
RP316: 6/14/2009 11:55:40 AM - System Checkpoint
RP317: 6/15/2009 9:26:36 AM - Software Distribution Service 3.0
RP318: 6/15/2009 3:49:47 PM - Software Distribution Service 3.0
RP319: 6/16/2009 8:39:31 AM - Avg8 Update
RP320: 6/16/2009 8:40:10 AM - Avg8 Update
RP321: 6/17/2009 9:10:22 AM - System Checkpoint
RP322: 6/17/2009 1:13:59 PM - Software Distribution Service 3.0
RP323: 6/18/2009 1:19:40 PM - System Checkpoint
RP324: 6/18/2009 2:34:39 PM - Software Distribution Service 3.0
RP325: 6/19/2009 3:43:43 PM - System Checkpoint
RP326: 6/19/2009 9:34:06 PM - Software Distribution Service 3.0
RP327: 6/20/2009 8:18:30 AM - Avg8 Update
RP328: 6/21/2009 9:35:54 AM - System Checkpoint
RP329: 6/22/2009 10:22:49 AM - System Checkpoint
RP330: 6/22/2009 3:57:04 PM - Software Distribution Service 3.0
RP331: 6/28/2009 4:48:55 PM - System Checkpoint
RP332: 6/29/2009 5:08:35 PM - System Checkpoint
RP333: 6/29/2009 10:52:22 PM - Software Distribution Service 3.0
RP334: 7/1/2009 12:26:40 AM - System Checkpoint
RP335: 7/2/2009 10:41:24 AM - System Checkpoint
RP336: 7/2/2009 4:29:53 PM - Software Distribution Service 3.0
RP337: 7/3/2009 5:50:43 PM - System Checkpoint
RP338: 7/4/2009 9:02:25 AM - Avg8 Update
RP339: 7/4/2009 9:03:12 AM - Avg8 Update
RP340: 7/5/2009 1:43:06 PM - System Checkpoint
RP341: 7/6/2009 9:53:22 AM - Software Distribution Service 3.0
RP342: 7/6/2009 10:49:13 AM - Windows Defender Checkpoint

==== Installed Programs ======================

4300
4300_Help
4300Trb
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 8.1.1
Adobe Shockwave Player
AiO_Scan_CDA
AiOSoftwareNPI
Apple Mobile Device Support
Apple Software Update
ArcSoft PhotoStudio 5.5
ArcSoft VideoImpression 2
Ask Toolbar
AutoUpdate
AVG 8.5
AVS Update Manager 1.0
AVS Video Converter 6
AVS4YOU Software Navigator 1.3
Bit Che
BitTorrent
BlackBerry Desktop Software 4.6
Bonjour
BufferChm
CCleaner (remove only)
CP_Package_Variety1
CP_Package_Variety2
CP_Package_Variety3
Critical Update for Windows Media Player 11 (KB959772)
Destinations
DeviceManagementQFolder
DivX
DocProc
eSupportQFolder
Fax_CDA
Google Earth
Google Toolbar for Internet Explorer
Google Updater
HijackThis 2.0.2
Hotfix for Windows Internet Explorer 7 (KB947864)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB952287)
HP Imaging Device Functions 6.1
HP Photosmart Essential
HP PSC & OfficeJet 6.1.A
HP Software Update
HP Solution Center and Imaging Support Tools 6.1
HPProductAssistant
iTunes
Java™ 6 Update 6
Java™ 6 Update 7
Kaspersky Online Scanner
LiveUpdate (Symantec Corporation)
LiveUpdate Notice (Symantec Corporation)
Malwarebytes' Anti-Malware
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft .NET Framework 2.0 Service Pack 1
Microsoft Application Error Reporting
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Digital Image Library 9 - Blocker
Microsoft Digital Image Standard 2006
Microsoft Digital Image Standard 2006 Editor
Microsoft Digital Image Standard 2006 Library
Microsoft Encarta Encyclopedia Standard 2006
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
Microsoft Money 2006
Microsoft National Language Support Downlevel APIs
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
Microsoft Web Publishing Wizard 1.52
Microsoft Word 2002
Microsoft Works
Microsoft Works Suite 2006 Setup Launcher
Microsoft Works Suite Add-in for Microsoft Word
MSXML 4.0 SP2 (KB954430)
NewCopy_CDA
ProductContextNPI
QuickTime
Readme
RealPlayer
Realtek AC'97 Audio
Roxio Media Manager
Scan
ScannerCopy
Security Update for Windows Internet Explorer 7 (KB937143)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB939653)
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Internet Explorer 7 (KB944533)
Security Update for Windows Internet Explorer 7 (KB950759)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Internet Explorer 7 (KB963027)
Security Update for Windows Internet Explorer 7 (KB969897)
Security Update for Windows Internet Explorer 8 (KB969897)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows Media Player 9 (KB917734)
Security Update for Windows Media Player 9 (KB936782)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951376)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB970238)
SiS VGA Utilities
SiSAGP driver
SolutionCenter
SpywareBlaster 4.2
Status
The Print Shop 22
Toolbox
TrayApp
Unload
Update for Windows Internet Explorer 8 (KB971180)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
Wal-Mart Digital Photo Manager
WeatherBug
WebFldrs XP
WebReg
Windows Defender
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Internet Explorer 7
Windows Internet Explorer 8
Windows Live Mail
Windows Media Format 11 runtime
Windows Media Player 11
Windows XP Service Pack 3
Works Upgrade
Yahoo! Browser Services
Yahoo! Internet Mail
Yahoo! Messenger
Yahoo! Toolbar
Zuma Deluxe 1.0

==== Event Viewer Messages From Past Week ========

7/23/2009 10:47:42 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds)

waiting for the Roxio Hard Drive Watcher 9 service to connect.
7/23/2009 10:47:42 AM, error: Service Control Manager [7000] - The Zune Bus Enumerator Driver

service failed to start due to the following error: The system cannot find the file specified.

==== End Of File ===========================





GMER 1.0.15.14972 - http://www.gmer.net
Rootkit scan 2009-07-26 22:13:41
Windows 5.1.2600 Service Pack 3


—- System - GMER 1.0.15 —-

Code 86084F20 ZwEnumerateKey
Code 86084EE8 ZwFlushInstructionCache
Code 86084F56 IofCallDriver
Code 860863DE IofCompleteRequest

—- Devices - GMER 1.0.15 —-

AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

—- Services - GMER 1.0.15 —-

Service C:\WINDOWS\system32\drivers\MSIVXgwsyejrjtqunckjenacytlpptqohmxtg.sys (*** hidden *** ) [SYSTEM] MSIVXserv.sys <– ROOTKIT !!!

—- Registry - GMER 1.0.15 —-

Reg HKLM\SYSTEM\CurrentControlSet\Services\MSIVXserv.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\MSIVXserv.sys@start 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\MSIVXserv.sys@type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\MSIVXserv.sys@imagepath \systemroot\system32\drivers\MSIVXgwsyejrjtqunckjenacytlpptqohmxtg.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\MSIVXserv.sys@group file system
Reg HKLM\SYSTEM\CurrentControlSet\Services\MSIVXserv.sys\modules
Reg HKLM\SYSTEM\CurrentControlSet\Services\MSIVXserv.sys\modules@MSIVXserv \\?\globalroot\systemroot\system32\drivers\MSIVXgwsyejrjtqunckjenacytlpptqohmxtg.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\MSIVXserv.sys\modules@MSIVXl \\?\globalroot\systemroot\system32\MSIVXmuhoabyrdlpkycoxfdxgnarctusdodgh.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\MSIVXserv.sys\modules@MSIVXclk \\?\globalroot\systemroot\system32\MSIVXyowoklwtugrmmeylqjgjjpklcioqflhd.dll
Reg HKLM\SYSTEM\ControlSet003\Services\MSIVXserv.sys
Reg HKLM\SYSTEM\ControlSet003\Services\MSIVXserv.sys@start 1
Reg HKLM\SYSTEM\ControlSet003\Services\MSIVXserv.sys@type 1
Reg HKLM\SYSTEM\ControlSet003\Services\MSIVXserv.sys@imagepath \systemroot\system32\drivers\MSIVXgwsyejrjtqunckjenacytlpptqohmxtg.sys
Reg HKLM\SYSTEM\ControlSet003\Services\MSIVXserv.sys@group file system
Reg HKLM\SYSTEM\ControlSet003\Services\MSIVXserv.sys\modules
Reg HKLM\SYSTEM\ControlSet003\Services\MSIVXserv.sys\modules@MSIVXserv \\?\globalroot\systemroot\system32\drivers\MSIVXgwsyejrjtqunckjenacytlpptqohmxtg.sys
Reg HKLM\SYSTEM\ControlSet003\Services\MSIVXserv.sys\modules@MSIVXl \\?\globalroot\systemroot\system32\MSIVXmuhoabyrdlpkycoxfdxgnarctusdodgh.dll
Reg HKLM\SYSTEM\ControlSet003\Services\MSIVXserv.sys\modules@MSIVXclk \\?\globalroot\systemroot\system32\MSIVXyowoklwtugrmmeylqjgjjpklcioqflhd.dll

—- EOF - GMER 1.0.15 —-
Hi,

Please do the following:

Download Combofix from either of the links below. You must rename it before saving it.
Save it to your desktop.

**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved and renamed following this process directly to your desktop**

  • If you are using Firefox, make sure that your download settings are as follows:
  • Tools->Options->Main tab
  • Set to "Always ask me where to Save the files".


Link 1
Link 2



During the download, rename Combofix to Combo-Fix as follows:

[external image: Posted Image]


[external image: Posted Image]
——————————————————————–
  • It is important you rename Combofix during the download, but not after.
  • Please do not rename Combofix to other names, but only to the one indicated.


———————————————————–

  • Double click on Combo-Fix.exe & follow the prompts.
    • When finished, it will produce a report for you.
    • Please post the "C:\Combo-Fix.txt" for further review.
    **Note: Do not mouseclick combo-fix's window while it's running. That may cause it to stall**


    ———————————————————–

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

    ———————————————————–

Hey CatByte, Sorry it took so long to get back to you. I am experiencing problems with the combo fix link. It says its broken. I have tried to download it from other locations but still cannot find a good link that works. Let me know what you need me to do. Thanks
Hi, I suspect the malware is preventing you from getting to the download site:

Do you have access to another computer?

If you do, download the program to the other computer, renaming it before you save it, then transfer it over to the infected PC via a USB stick.

If you dont have access let me know and I'll see what other options we have,


could you please run this program as well.

Please download Sysprot Antirootkit from here

http://sites.google.com/site/sysprotantirootkit/

Unzip it into a folder on your desktop.

  • Double click Sysprot.exe to start the program.
  • Click on the Log tab.
  • In the Write to log box select all items.
  • Click on the Create Log button on the bottom right.
  • After a few seconds a new window should appear.
  • Select Scan Root Drive. Click on the Start button.
  • When it is complete a new window will appear to indicate that the scan is finished.
  • The log will be saved automatically in the same folder Sysprot.exe was extracted to.
  • Open the text file and copy/paste the log here.
SysProt AntiRootkit v1.0.1.0 by swatkat ******************************************************************************** ********** ******************************************************************************** ********** Process: Name: [System Idle Process] PID: 0 Hidden: No Window Visible: No Name: System PID: 4 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\smss.exe PID: 432 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\csrss.exe PID: 480 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\winlogon.exe PID: 504 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\services.exe PID: 548 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\lsass.exe PID: 560 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\svchost.exe PID: 724 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\svchost.exe PID: 828 Hidden: No Window Visible: No Name: C:\Program Files\Windows Defender\MsMpEng.exe PID: 916 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\svchost.exe PID: 956 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\svchost.exe PID: 996 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\svchost.exe PID: 1152 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\svchost.exe PID: 1240 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\spoolsv.exe PID: 1456 Hidden: No Window Visible: No Name: C:\WINDOWS\explorer.exe PID: 1692 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\svchost.exe PID: 304 Hidden: No Window Visible: No Name: C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe PID: 352 Hidden: No Window Visible: No Name: C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe PID: 372 Hidden: No Window Visible: No Name: C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe PID: 280 Hidden: No Window Visible: No Name: C:\Program Files\Bonjour\mDNSResponder.exe PID: 424 Hidden: No Window Visible: No Name: C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe PID: 988 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\HPZipm12.exe PID: 1088 Hidden: No Window Visible: No Name: C:\PROGRA~1\AVG\AVG8\avgam.exe PID: 1612 Hidden: No Window Visible: No Name: C:\Program Files\AVG\AVG8\avgrsx.exe PID: 1444 Hidden: No Window Visible: No Name: C:\PROGRA~1\AVG\AVG8\avgnsx.exe PID: 1652 Hidden: No Window Visible: No Name: C:\Program Files\Windows Defender\MSASCui.exe PID: 524 Hidden: No Window Visible: No Name: C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe PID: 688 Hidden: No Window Visible: No Name: C:\PROGRA~1\AVG\AVG8\avgtray.exe PID: 608 Hidden: No Window Visible: No Name: C:\Program Files\QuickTime\QTTask.exe PID: 768 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\ctfmon.exe PID: 448 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\sistray.exe PID: 860 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\svchost.exe PID: 2064 Hidden: No Window Visible: No Name: C:\PROGRA~1\AVG\AVG8\avgemc.exe PID: 2108 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\dmadmin.exe PID: 2184 Hidden: No Window Visible: No Name: C:\Program Files\AVG\AVG8\avgcsrvx.exe PID: 2332 Hidden: No Window Visible: No Name: C:\WINDOWS\system32\alg.exe PID: 3548 Hidden: No Window Visible: No Name: C:\Program Files\Internet Explorer\iexplore.exe PID: 3008 Hidden: No Window Visible: No Name: C:\Program Files\Internet Explorer\iexplore.exe PID: 676 Hidden: No Window Visible: No Name: C:\Documents and Settings\Susan White\Desktop\SysProt\SysProt\SysProt.exe PID: 3436 Hidden: No Window Visible: Yes ******************************************************************************** ********** ******************************************************************************** ********** Kernel Modules: Module Name: \systemroot\system32\drivers\MSIVXgwsyejrjtqunckjenacytlpptqohmxtg.sys Service Name: MSIVXserv.sys Module Base: — Module End: — Hidden: Yes Module Name: \??\C:\Documents and Settings\Susan White\Desktop\SysProt\SysProt\SysProtDrv.sys Service Name: SysProtDrv.sys Module Base: F45AB000 Module End: F45B6000 Hidden: No Module Name: \WINDOWS\system32\ntoskrnl.exe Service Name: — Module Base: 804D7000 Module End: 806FF000 Hidden: No Module Name: \WINDOWS\system32\hal.dll Service Name: — Module Base: 806FF000 Module End: 8071FD00 Hidden: No Module Name: \WINDOWS\system32\KDCOM.DLL Service Name: — Module Base: F7B25000 Module End: F7B27000 Hidden: No Module Name: \WINDOWS\system32\BOOTVID.dll Service Name: — Module Base: F7A35000 Module End: F7A38000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\ACPI.sys Service Name: ACPI Module Base: F75D6000 Module End: F7604000 Hidden: No Module Name: \WINDOWS\system32\DRIVERS\WMILIB.SYS Service Name: — Module Base: F7B27000 Module End: F7B29000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\pci.sys Service Name: PCI Module Base: F75C5000 Module End: F75D6000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\isapnp.sys Service Name: isapnp Module Base: F7625000 Module End: F762F000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\pciide.sys Service Name: PCIIde Module Base: F7BED000 Module End: F7BEE000 Hidden: No Module Name: \WINDOWS\system32\DRIVERS\PCIIDEX.SYS Service Name: — Module Base: F78A5000 Module End: F78AC000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\MountMgr.sys Service Name: MountMgr Module Base: F7635000 Module End: F7640000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\ftdisk.sys Service Name: Disk Module Base: F75A6000 Module End: F75C5000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\PartMgr.sys Service Name: PartMgr Module Base: F78AD000 Module End: F78B2000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\VolSnap.sys Service Name: VolSnap Module Base: F7645000 Module End: F7652000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\atapi.sys Service Name: atapi Module Base: F758E000 Module End: F75A6000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\disk.sys Service Name: — Module Base: F7655000 Module End: F765E000 Hidden: No Module Name: \WINDOWS\system32\DRIVERS\CLASSPNP.SYS Service Name: — Module Base: F7665000 Module End: F7672000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\fltmgr.sys Service Name: FltMgr Module Base: F756E000 Module End: F758E000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\sr.sys Service Name: sr Module Base: F755C000 Module End: F756E000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\PxHelp20.sys Service Name: PxHelp20 Module Base: F7675000 Module End: F767E000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\KSecDD.sys Service Name: KSecDD Module Base: F7545000 Module End: F755C000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\WudfPf.sys Service Name: WudfPf Module Base: F7532000 Module End: F7545000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\Ntfs.sys Service Name: Ntfs Module Base: F74A5000 Module End: F7532000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\NDIS.sys Service Name: NDIS Module Base: F7478000 Module End: F74A5000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\uagp35.sys Service Name: uagp35 Module Base: F7685000 Module End: F7690000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\SISAGPX.sys Service Name: SISAGP Module Base: F7695000 Module End: F769F000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\Mup.sys Service Name: Mup Module Base: F745E000 Module End: F7478000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\avgrkx86.sys Service Name: AvgRkx86 Module Base: F7B29000 Module End: F7B2B000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\intelppm.sys Service Name: intelppm Module Base: F76E5000 Module End: F76EE000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\sisgrp.sys Service Name: SiS315 Module Base: F73D6000 Module End: F7416000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\VIDEOPRT.SYS Service Name: — Module Base: F73C2000 Module End: F73D6000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\i8042prt.sys Service Name: i8042prt Module Base: F76F5000 Module End: F7702000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\kbdclass.sys Service Name: Kbdclass Module Base: F78ED000 Module End: F78F3000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\mouclass.sys Service Name: Mouclass Module Base: F78F5000 Module End: F78FB000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\parport.sys Service Name: Parport Module Base: F73AE000 Module End: F73C2000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\serial.sys Service Name: Serial Module Base: F7705000 Module End: F7715000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\serenum.sys Service Name: serenum Module Base: F7AC1000 Module End: F7AC5000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\imapi.sys Service Name: Imapi Module Base: F7715000 Module End: F7720000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\Afc.sys Service Name: Afc Module Base: F790D000 Module End: F7915000 Hidden: No Module Name: C:\WINDOWS\System32\Drivers\AFS2K.SYS Service Name: AFS2K Module Base: F7725000 Module End: F772E000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\cdrom.sys Service Name: Cdrom Module Base: F7735000 Module End: F7745000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\redbook.sys Service Name: redbook Module Base: F7745000 Module End: F7754000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\ks.sys Service Name: — Module Base: F738B000 Module End: F73AE000 Hidden: No Module Name: C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys Service Name: GEARAspiWDM Module Base: F7AD1000 Module End: F7AD4000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\ALCXWDM.SYS Service Name: ALCXWDM Module Base: F715A000 Module End: F738B000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\portcls.sys Service Name: — Module Base: F7136000 Module End: F715A000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\drmk.sys Service Name: — Module Base: F7755000 Module End: F7764000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\usbohci.sys Service Name: usbohci Module Base: F792D000 Module End: F7932000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\USBPORT.SYS Service Name: — Module Base: F7112000 Module End: F7136000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\usbehci.sys Service Name: usbehci Module Base: F7935000 Module End: F793D000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\RTL8139.SYS Service Name: rtl8139 Module Base: F793D000 Module End: F7943000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\audstub.sys Service Name: audstub Module Base: F7CDE000 Module End: F7CDF000 Hidden: No Module Name: C:\WINDOWS\System32\Drivers\RootMdm.sys Service Name: ROOTMODEM Module Base: F7B2D000 Module End: F7B2F000 Hidden: No Module Name: C:\WINDOWS\System32\Drivers\Modem.SYS Service Name: Modem Module Base: F794D000 Module End: F7955000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\rasl2tp.sys Service Name: Rasl2tp Module Base: F7765000 Module End: F7772000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\ndistapi.sys Service Name: NdisTapi Module Base: F7ADD000 Module End: F7AE0000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\ndiswan.sys Service Name: NdisWan Module Base: F705B000 Module End: F7072000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\raspppoe.sys Service Name: RasPppoe Module Base: F7775000 Module End: F7780000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\raspptp.sys Service Name: PptpMiniport Module Base: F7785000 Module End: F7791000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\TDI.SYS Service Name: — Module Base: F796D000 Module End: F7972000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\psched.sys Service Name: PSched Module Base: F704A000 Module End: F705B000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\msgpc.sys Service Name: Gpc Module Base: F7795000 Module End: F779E000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\ptilink.sys Service Name: Ptilink Module Base: F797D000 Module End: F7982000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\raspti.sys Service Name: Raspti Module Base: F798D000 Module End: F7992000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\RimSerial.sys Service Name: RimVSerPort Module Base: F799D000 Module End: F79A4000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\termdd.sys Service Name: TermDD Module Base: F77A5000 Module End: F77AF000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\swenum.sys Service Name: swenum Module Base: F7B33000 Module End: F7B35000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\update.sys Service Name: Update Module Base: F6FEC000 Module End: F704A000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\mssmbios.sys Service Name: mssmbios Module Base: F7AF1000 Module End: F7AF5000 Hidden: No Module Name: C:\WINDOWS\System32\Drivers\NDProxy.SYS Service Name: NDProxy Module Base: F77C5000 Module End: F77CF000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\usbhub.sys Service Name: usbhub Module Base: F77E5000 Module End: F77F4000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\USBD.SYS Service Name: — Module Base: F7B3B000 Module End: F7B3D000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\flpydisk.sys Service Name: Flpydisk Module Base: F79B5000 Module End: F79BA000 Hidden: No Module Name: C:\WINDOWS\System32\Drivers\Beep.SYS Service Name: Beep Module Base: F7B43000 Module End: F7B45000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\HIDPARSE.SYS Service Name: — Module Base: F79D5000 Module End: F79DC000 Hidden: No Module Name: C:\WINDOWS\System32\drivers\vga.sys Service Name: VgaSave Module Base: F79DD000 Module End: F79E3000 Hidden: No Module Name: C:\WINDOWS\System32\Drivers\mnmdd.SYS Service Name: mnmdd Module Base: F7B47000 Module End: F7B49000 Hidden: No Module Name: C:\WINDOWS\System32\DRIVERS\RDPCDD.sys Service Name: RDPCDD Module Base: F7B4B000 Module End: F7B4D000 Hidden: No Module Name: C:\WINDOWS\System32\Drivers\Npfs.SYS Service Name: Npfs Module Base: F79FD000 Module End: F7A05000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\rasacd.sys Service Name: RasAcd Module Base: F7422000 Module End: F7425000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\ipsec.sys Service Name: IPSec Module Base: F571D000 Module End: F5730000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\tcpip.sys Service Name: Tcpip Module Base: F56C4000 Module End: F571D000 Hidden: No Module Name: C:\WINDOWS\System32\Drivers\avgtdix.sys Service Name: AvgTdiX Module Base: F56AB000 Module End: F56C4000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\ipnat.sys Service Name: IpNat Module Base: F5685000 Module End: F56AB000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\wanarp.sys Service Name: Wanarp Module Base: F7805000 Module End: F780E000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\netbt.sys Service Name: NetBT Module Base: F565D000 Module End: F5685000 Hidden: No Module Name: C:\WINDOWS\System32\drivers\afd.sys Service Name: AFD Module Base: F563B000 Module End: F565D000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\netbios.sys Service Name: NetBIOS Module Base: F7815000 Module End: F781E000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\srvkp.sys Service Name: SiSkp Module Base: F7AC9000 Module End: F7ACC000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\rdbss.sys Service Name: Rdbss Module Base: F5570000 Module End: F559B000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\usbccgp.sys Service Name: usbccgp Module Base: F7A15000 Module End: F7A1D000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\mrxsmb.sys Service Name: MRxSmb Module Base: F5500000 Module End: F5570000 Hidden: No Module Name: C:\WINDOWS\System32\Drivers\Fips.SYS Service Name: Fips Module Base: F7825000 Module End: F7830000 Hidden: No Module Name: C:\WINDOWS\System32\Drivers\avgmfx86.sys Service Name: AvgMfx86 Module Base: F7A2D000 Module End: F7A33000 Hidden: No Module Name: C:\WINDOWS\System32\Drivers\avgldx86.sys Service Name: AvgLdx86 Module Base: F54AF000 Module End: F5500000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\usbscan.sys Service Name: usbscan Module Base: F7AD9000 Module End: F7ADD000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\usbprint.sys Service Name: usbprint Module Base: F78FD000 Module End: F7904000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\HPZius12.sys Service Name: HPZius12 Module Base: F791D000 Module End: F7923000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\HPZid412.sys Service Name: HPZid412 Module Base: F7835000 Module End: F7842000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\HPZipr12.sys Service Name: HPZipr12 Module Base: F7AE5000 Module End: F7AE9000 Hidden: No Module Name: C:\WINDOWS\System32\Drivers\Cdfs.SYS Service Name: Cdfs Module Base: F7865000 Module End: F7875000 Hidden: No Module Name: \SystemRoot\System32\Drivers\dump_atapi.sys Service Name: — Module Base: F546F000 Module End: F5487000 Hidden: Yes Module Name: \SystemRoot\System32\Drivers\dump_WMILIB.SYS Service Name: — Module Base: F7B5D000 Module End: F7B5F000 Hidden: Yes Module Name: C:\WINDOWS\System32\drivers\Dxapi.sys Service Name: — Module Base: F6FCC000 Module End: F6FCF000 Hidden: No Module Name: C:\WINDOWS\System32\watchdog.sys Service Name: — Module Base: F79AD000 Module End: F79B2000 Hidden: No Module Name: C:\WINDOWS\System32\drivers\dxgthk.sys Service Name: — Module Base: F7CCA000 Module End: F7CCB000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\ndisuio.sys Service Name: Ndisuio Module Base: F51CF000 Module End: F51D3000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\wdmaud.sys Service Name: wdmaud Module Base: F4F62000 Module End: F4F77000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\sysaudio.sys Service Name: sysaudio Module Base: F50AF000 Module End: F50BE000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\mrxdav.sys Service Name: MRxDAV Module Base: F4D2D000 Module End: F4D5A000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\srv.sys Service Name: Srv Module Base: F4B9B000 Module End: F4BED000 Hidden: No Module Name: C:\WINDOWS\System32\Drivers\HTTP.sys Service Name: HTTP Module Base: F44CA000 Module End: F450B000 Hidden: No Module Name: C:\WINDOWS\system32\drivers\kmixer.sys Service Name: kmixer Module Base: F417C000 Module End: F41A7000 Hidden: No Module Name: C:\WINDOWS\system32\DRIVERS\fdc.sys Service Name: Fdc Module Base: F7905000 Module End: F790C000 Hidden: No Module Name: C:\WINDOWS\System32\Drivers\ParVdm.SYS Service Name: ParVdm Module Base: F7B71000 Module End: F7B73000 Hidden: No Module Name: C:\WINDOWS\System32\Drivers\Null.SYS Service Name: Null Module Base: F7D33000 Module End: F7D34000 Hidden: No Module Name: C:\WINDOWS\System32\Drivers\Msfs.SYS Service Name: Msfs Module Base: F79ED000 Module End: F79F2000 Hidden: No ******************************************************************************** ********** ******************************************************************************** ********** No SSDT Hooks found ******************************************************************************** ********** ******************************************************************************** ********** Kernel Hooks: Hooked Function: ZwFlushInstructionCache At Address: 80587BFB Jump To: 8608413C Module Name: _unknown_ Hooked Function: ZwEnumerateKey At Address: 80578E14 Jump To: 86084174 Module Name: _unknown_ Hooked Function: PsGetProcessWin32WindowStation At Address: 804F41EC Jump To: FD806070 Module Name: _unknown_ Hooked Function: PsGetProcessJob At Address: 804F41EC Jump To: FD806070 Module Name: _unknown_ Hooked Function: IofCompleteRequest At Address: 804E17BD Jump To: 8608525B Module Name: _unknown_ Hooked Function: IofCallDriver At Address: 804E13A7 Jump To: 860841AB Module Name: _unknown_ ******************************************************************************** ********** ******************************************************************************** ********** No IRP Hooks found ******************************************************************************** ********** ******************************************************************************** ********** Ports: Local Address: SUSAN.MYHOME.WESTELL.COM:2749 Remote Address: SPYNETTEST.MICROSOFT.COM:HTTPS Type: TCP Process: C:\Program Files\Windows Defender\MSASCui.exe State: ESTABLISHED Local Address: SUSAN.MYHOME.WESTELL.COM:2748 Remote Address: CHANNEL21.01.05.SF2P.FACEBOOK.COM:HTTP Type: TCP Process: C:\PROGRA~1\AVG\AVG8\avgnsx.exe State: ESTABLISHED Local Address: SUSAN.MYHOME.WESTELL.COM:2742 Remote Address: QY-IN-F137.GOOGLE.COM:HTTP Type: TCP Process: [System Idle Process] State: TIME_WAIT Local Address: SUSAN.MYHOME.WESTELL.COM:2740 Remote Address: VW-IN-F101.GOOGLE.COM:HTTP Type: TCP Process: [System Idle Process] State: TIME_WAIT Local Address: SUSAN.MYHOME.WESTELL.COM:NETBIOS-SSN Remote Address: 0.0.0.0:0 Type: TCP Process: System State: LISTENING Local Address: SUSAN:27015 Remote Address: 0.0.0.0:0 Type: TCP Process: C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe State: LISTENING Local Address: SUSAN:18080 Remote Address: 0.0.0.0:0 Type: TCP Process: C:\PROGRA~1\AVG\AVG8\avgnsx.exe State: LISTENING Local Address: SUSAN:13128 Remote Address: 0.0.0.0:0 Type: TCP Process: C:\PROGRA~1\AVG\AVG8\avgnsx.exe State: LISTENING Local Address: SUSAN:10110 Remote Address: 0.0.0.0:0 Type: TCP Process: C:\PROGRA~1\AVG\AVG8\avgemc.exe State: LISTENING Local Address: SUSAN:10080 Remote Address: LOCALHOST:2747 Type: TCP Process: C:\PROGRA~1\AVG\AVG8\avgnsx.exe State: ESTABLISHED Local Address: SUSAN:10080 Remote Address: 0.0.0.0:0 Type: TCP Process: C:\PROGRA~1\AVG\AVG8\avgnsx.exe State: LISTENING Local Address: SUSAN:10025 Remote Address: 0.0.0.0:0 Type: TCP Process: C:\PROGRA~1\AVG\AVG8\avgemc.exe State: LISTENING Local Address: SUSAN:5354 Remote Address: 0.0.0.0:0 Type: TCP Process: C:\Program Files\Bonjour\mDNSResponder.exe State: LISTENING Local Address: SUSAN:2747 Remote Address: LOCALHOST:10080 Type: TCP Process: C:\Program Files\Internet Explorer\iexplore.exe State: ESTABLISHED Local Address: SUSAN:1033 Remote Address: 0.0.0.0:0 Type: TCP Process: C:\WINDOWS\system32\alg.exe State: LISTENING Local Address: SUSAN:MICROSOFT-DS Remote Address: 0.0.0.0:0 Type: TCP Process: System State: LISTENING Local Address: SUSAN:EPMAP Remote Address: 0.0.0.0:0 Type: TCP Process: C:\WINDOWS\system32\svchost.exe State: LISTENING Local Address: SUSAN.MYHOME.WESTELL.COM:5353 Remote Address: NA Type: UDP Process: C:\Program Files\Bonjour\mDNSResponder.exe State: NA Local Address: SUSAN.MYHOME.WESTELL.COM:1900 Remote Address: NA Type: UDP Process: C:\WINDOWS\system32\svchost.exe State: NA Local Address: SUSAN.MYHOME.WESTELL.COM:138 Remote Address: NA Type: UDP Process: System State: NA Local Address: SUSAN.MYHOME.WESTELL.COM:NETBIOS-NS Remote Address: NA Type: UDP Process: System State: NA Local Address: SUSAN.MYHOME.WESTELL.COM:123 Remote Address: NA Type: UDP Process: C:\WINDOWS\system32\svchost.exe State: NA Local Address: SUSAN:2322 Remote Address: NA Type: UDP Process: C:\Program Files\Internet Explorer\iexplore.exe State: NA Local Address: SUSAN:1900 Remote Address: NA Type: UDP Process: C:\WINDOWS\system32\svchost.exe State: NA Local Address: SUSAN:1106 Remote Address: NA Type: UDP Process: C:\Program Files\Internet Explorer\iexplore.exe State: NA Local Address: SUSAN:123 Remote Address: NA Type: UDP Process: C:\WINDOWS\system32\svchost.exe State: NA Local Address: SUSAN:61049 Remote Address: NA Type: UDP Process: C:\Program Files\Bonjour\mDNSResponder.exe State: NA Local Address: SUSAN:4500 Remote Address: NA Type: UDP Process: C:\WINDOWS\system32\lsass.exe State: NA Local Address: SUSAN:1025 Remote Address: NA Type: UDP Process: C:\Program Files\Bonjour\mDNSResponder.exe State: NA Local Address: SUSAN:500 Remote Address: NA Type: UDP Process: C:\WINDOWS\system32\lsass.exe State: NA Local Address: SUSAN:MICROSOFT-DS Remote Address: NA Type: UDP Process: System State: NA ******************************************************************************** ********** ******************************************************************************** ********** Hidden files/folders: Object: C:\Documents and Settings\All Users\Application Data\Broderbund Software\Print\The Print Shop\22.0\Books\Sender\Sender.abk Status: Access denied Object: C:\Documents and Settings\All Users\Application Data\Broderbund Software\Print\The Print Shop\22.0\Books\Sender Status: Access denied Object: C:\Documents and Settings\Susan White\My Documents\LimeWire\Incomplete\XZAHG3XGVEWQXO6B7PHJEEV6E4O7KAOT Status: Hidden Object: C:\System Volume Information\MountPointManagerRemoteDatabase Status: Access denied Object: C:\System Volume Information\tracking.log Status: Access denied Object: C:\System Volume Information\_restore{92326D68-0999-4147-A5A9-63DE7970BEF0} Status: Access denied Object: C:\System Volume Information\_restore{B66C3366-4CAA-4FDF-BD35-F3ED75B6D4CB} Status: Access denied Object: C:\WINDOWS\system32\drivers\MSIVXgwsyejrjtqunckjenacytlpptqohmxtg.sys Status: Hidden Object: C:\WINDOWS\system32\MSIVXcount Status: Hidden Object: C:\WINDOWS\system32\MSIVXmuhoabyrdlpkycoxfdxgnarctusdodgh.dll Status: Hidden Object: C:\WINDOWS\system32\MSIVXyowoklwtugrmmeylqjgjjpklcioqflhd.dll Status: Hidden
Hi,

Please do the following:

1. Please download The Avenger2 by Swandog46 to your Desktop.
  • Right click on the Avenger.zip folder and select "Extract All…"
  • Follow the prompts and extract the avenger folder to your desktop
2. Copy all the text contained in the code box below to your Clipboard by highlighting it and pressing (Ctrl+C):
Begin copying here:

Files to delete:
C:\WINDOWS\system32\drivers\MSIVXgwsyejrjtqunckjenacytlpptqohmxtg.sys
C:\WINDOWS\system32\MSIVXmuhoabyrdlpkycoxfdxgnarctusdodgh.dll
C:\WINDOWS\system32\MSIVXyowoklwtugrmmeylqjgjjpklcioqflhd.dll

Folders to delete:
C:\WINDOWS\system32\MSIVXcount

Drivers to delete:
MSIVXserv.sys

Note: the above code was created specifically for this user.  If you are not this user, do NOT follow these directions as they could damage the workings of your system.

3. Now, open the Avenger folder and start The Avenger program by clicking on its icon.
  • Right click on the window under Input script here:, and select Paste.
  • You can also Paste the text copied to the clipboard into this window by pressing (Ctrl+V), or click on the third button under the menu to paste it from the clipboard.
  • Click on Execute
  • Answer "Yes" twice when prompted.
4. The Avenger will automatically do the following:
  • It will Restart your computer. ( In cases where the code to execute contains "Drivers to Delete" or "Drivers to Disable", The Avenger will actually restart your system twice.)
  • On reboot, it will briefly open a black command window on your desktop, this is normal.
  • After the restart, it creates a log file that should open with the results of Avenger’s actions.  This log file will be located at  C:\avenger.txt
  • The Avenger will also have backed up all the files, etc., that you asked it to delete, and will have zipped them and moved the zip archives to C:\avenger\backup.zip.
5. Please copy/paste the content of c:\avenger.txt into your reply
Hey CatByte, It wont allow me to goto got avenger2. It tells me the link is broken. Same error message as combofix. So is there another link perhaps?
Sorry it took so long to get back to you. It wouldn't let me navigate back to you. I had to restart the computer and it was sloooooooooooooooooooooooooooooooooooooooooow going.








//////////////////////////////////////////
Avenger Pre-Processor log
//////////////////////////////////////////

Platform: Windows XP (build 2600, Service Pack 3)
Tue Jul 28 13:06:42 2009

13:06:42: Error: Invalid script. A valid script must begin with a command directive.
Aborting execution!


//////////////////////////////////////////


//////////////////////////////////////////
Avenger Pre-Processor log
//////////////////////////////////////////

Platform: Windows XP (build 2600, Service Pack 3)
Tue Jul 28 13:06:59 2009

13:06:59: Error: Invalid script. A valid script must begin with a command directive.
Aborting execution!


//////////////////////////////////////////


Logfile of The Avenger Version 2.0, © by Swandog46
http://swandog46.geekstogo.com

Platform: Windows XP

*******************

Script file opened successfully.
Script file read successfully.

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

Rootkit scan active.

Hidden driver "MSIVXserv.sys" found!
ImagePath: \systemroot\system32\drivers\MSIVXgwsyejrjtqunckjenacytlpptqohmxtg.sys
Start Type: 4 (Disabled)

Rootkit scan completed.

File "C:\WINDOWS\system32\drivers\MSIVXgwsyejrjtqunckjenacytlpptqohmxtg.sys" deleted successfully.
File "C:\WINDOWS\system32\MSIVXmuhoabyrdlpkycoxfdxgnarctusdodgh.dll" deleted successfully.
File "C:\WINDOWS\system32\MSIVXyowoklwtugrmmeylqjgjjpklcioqflhd.dll" deleted successfully.

Error: "C:\WINDOWS\system32\MSIVXcount" is not a folder! It may instead be a file.
Deletion of folder "C:\WINDOWS\system32\MSIVXcount" failed!
Status: 0xc0000103 (STATUS_NOT_A_DIRECTORY)
–> use "Files to delete:" instead of "Folders to delete:" to delete an ordinary file

Driver "MSIVXserv.sys" deleted successfully.

Completed script processing.

*******************

Finished! Terminate.
Hi,

can we do that again with the last one, Avenger tells me it's a file even though there.s no extention, it didn't delete it with the Folders to delete: command.


Begin copying here:

Files to delete:
C:\WINDOWS\system32\MSIVXcount

If you could run that program again using this script, thanks

Apologize for that

~CB
Logfile of The Avenger Version 2.0, © by Swandog46
http://swandog46.geekstogo.com

Platform: Windows XP

*******************

Script file opened successfully.
Script file read successfully.

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

Rootkit scan active.
No rootkits found!

File "C:\WINDOWS\system32\MSIVXcount" deleted successfully.

Completed script processing.

*******************

Finished! Terminate.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI