Thanks oldman960 for your very speedy reply. Followed your instructions exactly. Here are my GMER & DDS logs (DDS Attach file is attached as instructed):
GMER 1.0.15.15011 [gmer.exe] -
http://www.gmer.net
Rootkit scan 2009-08-02 21:30:05
Windows 5.1.2600 Service Pack 2
—- User code sections - GMER 1.0.15 —-
.text C:\PROGRA~1\AVG\AVG8\avgemc.exe[168] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA48F4
.text C:\PROGRA~1\AVG\AVG8\avgemc.exe[168] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA4983
.text C:\PROGRA~1\AVG\AVG8\avgemc.exe[168] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA4990
.text C:\PROGRA~1\AVG\AVG8\avgemc.exe[168] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4C14
.text C:\PROGRA~1\AVG\AVG8\avgemc.exe[168] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA4979
.text C:\PROGRA~1\AVG\AVG8\avgemc.exe[168] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA49D1
.text C:\WINDOWS\SOUNDMAN.EXE[192] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA48F4
.text C:\WINDOWS\SOUNDMAN.EXE[192] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA4983
.text C:\WINDOWS\SOUNDMAN.EXE[192] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA4990
.text C:\WINDOWS\SOUNDMAN.EXE[192] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4C14
.text C:\WINDOWS\SOUNDMAN.EXE[192] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA4979
.text C:\WINDOWS\SOUNDMAN.EXE[192] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA49D1
.text C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[244] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA48F4
.text C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[244] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA4983
.text C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[244] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA4990
.text C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[244] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4C14
.text C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[244] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA4979
.text C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[244] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA49D1
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[428] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA48F4
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[428] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA4983
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[428] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA4990
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[428] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4C14
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[428] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA4979
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[428] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA49D1
.text C:\Program Files\Tenda\W541U\UI.exe[540] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA48F4
.text C:\Program Files\Tenda\W541U\UI.exe[540] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA4983
.text C:\Program Files\Tenda\W541U\UI.exe[540] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA4990
.text C:\Program Files\Tenda\W541U\UI.exe[540] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4C14
.text C:\Program Files\Tenda\W541U\UI.exe[540] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA4979
.text C:\Program Files\Tenda\W541U\UI.exe[540] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA49D1
.text C:\Program Files\VIA\RAID\raid_tool.exe[560] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA48F4
.text C:\Program Files\VIA\RAID\raid_tool.exe[560] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA4983
.text C:\Program Files\VIA\RAID\raid_tool.exe[560] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA4990
.text C:\Program Files\VIA\RAID\raid_tool.exe[560] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4C14
.text C:\Program Files\VIA\RAID\raid_tool.exe[560] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA4979
.text C:\Program Files\VIA\RAID\raid_tool.exe[560] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA49D1
.text C:\Program Files\AVG\AVG8\avgcsrvx.exe[680] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA48F4
.text C:\Program Files\AVG\AVG8\avgcsrvx.exe[680] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA4983
.text C:\Program Files\AVG\AVG8\avgcsrvx.exe[680] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA4990
.text C:\Program Files\AVG\AVG8\avgcsrvx.exe[680] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4C14
.text C:\Program Files\AVG\AVG8\avgcsrvx.exe[680] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA4979
.text C:\Program Files\AVG\AVG8\avgcsrvx.exe[680] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA49D1
.text C:\WINDOWS\system32\spoolsv.exe[740] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA48F4
.text C:\WINDOWS\system32\spoolsv.exe[740] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA4983
.text C:\WINDOWS\system32\spoolsv.exe[740] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA4990
.text C:\WINDOWS\system32\spoolsv.exe[740] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4C14
.text C:\WINDOWS\system32\spoolsv.exe[740] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA4979
.text C:\WINDOWS\system32\spoolsv.exe[740] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA49D1
.text C:\WINDOWS\system32\winlogon.exe[980] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FF948F4
.text C:\WINDOWS\system32\winlogon.exe[980] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FF94983
.text C:\WINDOWS\system32\winlogon.exe[980] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FF94990
.text C:\WINDOWS\system32\winlogon.exe[980] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FF94C14
.text C:\WINDOWS\system32\winlogon.exe[980] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FF94979
.text C:\WINDOWS\system32\winlogon.exe[980] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FF949D1
.text C:\WINDOWS\system32\services.exe[1024] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FF948F4
.text C:\WINDOWS\system32\services.exe[1024] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FF94983
.text C:\WINDOWS\system32\services.exe[1024] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FF94990
.text C:\WINDOWS\system32\services.exe[1024] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FF94C14
.text C:\WINDOWS\system32\services.exe[1024] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FF94979
.text C:\WINDOWS\system32\services.exe[1024] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FF949D1
.text C:\WINDOWS\system32\lsass.exe[1036] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FF948F4
.text C:\WINDOWS\system32\lsass.exe[1036] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FF94983
.text C:\WINDOWS\system32\lsass.exe[1036] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FF94990
.text C:\WINDOWS\system32\lsass.exe[1036] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FF94C14
.text C:\WINDOWS\system32\lsass.exe[1036] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FF94979
.text C:\WINDOWS\system32\lsass.exe[1036] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FF949D1
.text C:\WINDOWS\system32\svchost.exe[1180] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA48F4
.text C:\WINDOWS\system32\svchost.exe[1180] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA4983
.text C:\WINDOWS\system32\svchost.exe[1180] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA4990
.text C:\WINDOWS\system32\svchost.exe[1180] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4C14
.text C:\WINDOWS\system32\svchost.exe[1180] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA4979
.text C:\WINDOWS\system32\svchost.exe[1180] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA49D1
.text C:\DOCUME~1\user\LOCALS~1\Temp\b.exe[1232] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA48F4
.text C:\DOCUME~1\user\LOCALS~1\Temp\b.exe[1232] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA4983
.text C:\DOCUME~1\user\LOCALS~1\Temp\b.exe[1232] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA4990
.text C:\DOCUME~1\user\LOCALS~1\Temp\b.exe[1232] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4C14
.text C:\DOCUME~1\user\LOCALS~1\Temp\b.exe[1232] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA4979
.text C:\DOCUME~1\user\LOCALS~1\Temp\b.exe[1232] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA49D1
.text C:\WINDOWS\system32\svchost.exe[1240] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA48F4
.text C:\WINDOWS\system32\svchost.exe[1240] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA4983
.text C:\WINDOWS\system32\svchost.exe[1240] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA4990
.text C:\WINDOWS\system32\svchost.exe[1240] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4C14
.text C:\WINDOWS\system32\svchost.exe[1240] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA4979
.text C:\WINDOWS\system32\svchost.exe[1240] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA49D1
.text C:\WINDOWS\System32\svchost.exe[1280] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FF848F4
.text C:\WINDOWS\System32\svchost.exe[1280] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FF84983
.text C:\WINDOWS\System32\svchost.exe[1280] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FF84990
.text C:\WINDOWS\System32\svchost.exe[1280] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FF84C14
.text C:\WINDOWS\System32\svchost.exe[1280] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FF84979
.text C:\WINDOWS\System32\svchost.exe[1280] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FF849D1
.text C:\WINDOWS\system32\svchost.exe[1372] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA48F4
.text C:\WINDOWS\system32\svchost.exe[1372] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA4983
.text C:\WINDOWS\system32\svchost.exe[1372] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA4990
.text C:\WINDOWS\system32\svchost.exe[1372] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4C14
.text C:\WINDOWS\system32\svchost.exe[1372] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA4979
.text C:\WINDOWS\system32\svchost.exe[1372] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA49D1
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[1428] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA48F4
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[1428] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA4983
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[1428] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA4990
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[1428] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4C14
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[1428] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA4979
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[1428] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA49D1
.text C:\Program Files\iPod Access for Windows\iPAHelper.exe[1460] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA48F4
.text C:\Program Files\iPod Access for Windows\iPAHelper.exe[1460] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA4983
.text C:\Program Files\iPod Access for Windows\iPAHelper.exe[1460] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA4990
.text C:\Program Files\iPod Access for Windows\iPAHelper.exe[1460] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4C14
.text C:\Program Files\iPod Access for Windows\iPAHelper.exe[1460] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA4979
.text C:\Program Files\iPod Access for Windows\iPAHelper.exe[1460] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA49D1
.text C:\WINDOWS\system32\HPZipm12.exe[1484] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA48F4
.text C:\WINDOWS\system32\HPZipm12.exe[1484] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA4983
.text C:\WINDOWS\system32\HPZipm12.exe[1484] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA4990
.text C:\WINDOWS\system32\HPZipm12.exe[1484] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4C14
.text C:\WINDOWS\system32\HPZipm12.exe[1484] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA4979
.text C:\WINDOWS\system32\HPZipm12.exe[1484] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA49D1
.text C:\WINDOWS\system32\svchost.exe[1512] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA48F4
.text C:\WINDOWS\system32\svchost.exe[1512] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA4983
.text C:\WINDOWS\system32\svchost.exe[1512] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA4990
.text C:\WINDOWS\system32\svchost.exe[1512] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4C14
.text C:\WINDOWS\system32\svchost.exe[1512] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA4979
.text C:\WINDOWS\system32\svchost.exe[1512] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA49D1
.reloc C:\WINDOWS\explorer.exe[1628] C:\WINDOWS\explorer.exe section is executable [0x010FB000, 0x8800, 0xE0000040]
.reloc C:\WINDOWS\explorer.exe[1628] C:\WINDOWS\explorer.exe entry point in ".reloc" section [0x0110363C]
.text C:\WINDOWS\explorer.exe[1628] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA48F4
.text C:\WINDOWS\explorer.exe[1628] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA4983
.text C:\WINDOWS\explorer.exe[1628] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA4990
.text C:\WINDOWS\explorer.exe[1628] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4C14
.text C:\WINDOWS\explorer.exe[1628] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA4979
.text C:\WINDOWS\explorer.exe[1628] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA49D1
.text C:\PROGRA~1\AVG\AVG8\avgrsx.exe[1852] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA48F4
.text C:\PROGRA~1\AVG\AVG8\avgrsx.exe[1852] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA4983
.text C:\PROGRA~1\AVG\AVG8\avgrsx.exe[1852] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA4990
.text C:\PROGRA~1\AVG\AVG8\avgrsx.exe[1852] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4C14
.text C:\PROGRA~1\AVG\AVG8\avgrsx.exe[1852] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA4979
.text C:\PROGRA~1\AVG\AVG8\avgrsx.exe[1852] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA49D1
.text C:\Program Files\Java\jre1.5.0\bin\jusched.exe[1884] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA48F4
.text C:\Program Files\Java\jre1.5.0\bin\jusched.exe[1884] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA4983
.text C:\Program Files\Java\jre1.5.0\bin\jusched.exe[1884] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA4990
.text C:\Program Files\Java\jre1.5.0\bin\jusched.exe[1884] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4C14
.text C:\Program Files\Java\jre1.5.0\bin\jusched.exe[1884] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA4979
.text C:\Program Files\Java\jre1.5.0\bin\jusched.exe[1884] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA49D1
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[1920] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA48F4
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[1920] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA4983
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[1920] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA4990
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[1920] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4C14
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[1920] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA4979
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[1920] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA49D1
.text C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe[1948] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA48F4
.text C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe[1948] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA4983
.text C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe[1948] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA4990
.text C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe[1948] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4C14
.text C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe[1948] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA4979
.text C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe[1948] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA49D1
.text C:\WINDOWS\system32\svchost.exe[1980] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA48F4
.text C:\WINDOWS\system32\svchost.exe[1980] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA4983
.text C:\WINDOWS\system32\svchost.exe[1980] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA4990
.text C:\WINDOWS\system32\svchost.exe[1980] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4C14
.text C:\WINDOWS\system32\svchost.exe[1980] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA4979
.text C:\WINDOWS\system32\svchost.exe[1980] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA49D1
.text C:\PROGRA~1\AVG\AVG8\avgtray.exe[2012] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA48F4
.text C:\PROGRA~1\AVG\AVG8\avgtray.exe[2012] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA4983
.text C:\PROGRA~1\AVG\AVG8\avgtray.exe[2012] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA4990
.text C:\PROGRA~1\AVG\AVG8\avgtray.exe[2012] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4C14
.text C:\PROGRA~1\AVG\AVG8\avgtray.exe[2012] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA4979
.text C:\PROGRA~1\AVG\AVG8\avgtray.exe[2012] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA49D1
.text C:\WINDOWS\System32\alg.exe[2108] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA48F4
.text C:\WINDOWS\System32\alg.exe[2108] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA4983
.text C:\WINDOWS\System32\alg.exe[2108] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA4990
.text C:\WINDOWS\System32\alg.exe[2108] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4C14
.text C:\WINDOWS\System32\alg.exe[2108] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA4979
.text C:\WINDOWS\System32\alg.exe[2108] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA49D1
.text C:\WINDOWS\system32\wscntfy.exe[2228] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA48F4
.text C:\WINDOWS\system32\wscntfy.exe[2228] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA4983
.text C:\WINDOWS\system32\wscntfy.exe[2228] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA4990
.text C:\WINDOWS\system32\wscntfy.exe[2228] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4C14
.text C:\WINDOWS\system32\wscntfy.exe[2228] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA4979
.text C:\WINDOWS\system32\wscntfy.exe[2228] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA49D1
.text C:\Program Files\Mozilla Firefox\firefox.exe[2376] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA48F4
.text C:\Program Files\Mozilla Firefox\firefox.exe[2376] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA4983
.text C:\Program Files\Mozilla Firefox\firefox.exe[2376] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA4990
.text C:\Program Files\Mozilla Firefox\firefox.exe[2376] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4C14
.text C:\Program Files\Mozilla Firefox\firefox.exe[2376] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA4979
.text C:\Program Files\Mozilla Firefox\firefox.exe[2376] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA49D1
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[2492] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA48F4
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[2492] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA4983
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[2492] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA4990
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[2492] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4C14
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[2492] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA4979
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[2492] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA49D1
.text C:\Documents and Settings\user\Desktop\gmer.exe[3028] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA48F4
.text C:\Documents and Settings\user\Desktop\gmer.exe[3028] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA4983
.text C:\Documents and Settings\user\Desktop\gmer.exe[3028] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA4990
.text C:\Documents and Settings\user\Desktop\gmer.exe[3028] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4C14
.text C:\Documents and Settings\user\Desktop\gmer.exe[3028] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA4979
.text C:\Documents and Settings\user\Desktop\gmer.exe[3028] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA49D1
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[3272] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA48F4
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[3272] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA4983
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[3272] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA4990
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[3272] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4C14
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[3272] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA4979
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[3272] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA49D1
.text C:\WINDOWS\system32\wuauclt.exe[3452] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA48F4
.text C:\WINDOWS\system32\wuauclt.exe[3452] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA4983
.text C:\WINDOWS\system32\wuauclt.exe[3452] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA4990
.text C:\WINDOWS\system32\wuauclt.exe[3452] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4C14
.text C:\WINDOWS\system32\wuauclt.exe[3452] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA4979
.text C:\WINDOWS\system32\wuauclt.exe[3452] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA49D1
—- User IAT/EAT - GMER 1.0.15 —-
IAT C:\DOCUME~1\user\LOCALS~1\Temp\b.exe[1232] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!CreateWindowExA] [0041657D] C:\DOCUME~1\user\LOCALS~1\Temp\b.exe
IAT C:\DOCUME~1\user\LOCALS~1\Temp\b.exe[1232] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!CreateWindowExW] [004165F7] C:\DOCUME~1\user\LOCALS~1\Temp\b.exe
IAT C:\DOCUME~1\user\LOCALS~1\Temp\b.exe[1232] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!ShowWindow] [00416671] C:\DOCUME~1\user\LOCALS~1\Temp\b.exe
IAT C:\DOCUME~1\user\LOCALS~1\Temp\b.exe[1232] @ C:\WINDOWS\system32\WININET.dll [USER32.dll!SetWindowPos] [00416723] C:\DOCUME~1\user\LOCALS~1\Temp\b.exe
IAT C:\DOCUME~1\user\LOCALS~1\Temp\b.exe[1232] @ C:\WINDOWS\system32\WININET.dll [USER32.dll!ShowWindow] [00416671] C:\DOCUME~1\user\LOCALS~1\Temp\b.exe
IAT C:\DOCUME~1\user\LOCALS~1\Temp\b.exe[1232] @ C:\WINDOWS\system32\WININET.dll [USER32.dll!CreateWindowExA] [0041657D] C:\DOCUME~1\user\LOCALS~1\Temp\b.exe
IAT C:\DOCUME~1\user\LOCALS~1\Temp\b.exe[1232] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!CreateWindowExA] [0041657D] C:\DOCUME~1\user\LOCALS~1\Temp\b.exe
IAT C:\DOCUME~1\user\LOCALS~1\Temp\b.exe[1232] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!CreateWindowExW] [004165F7] C:\DOCUME~1\user\LOCALS~1\Temp\b.exe
IAT C:\DOCUME~1\user\LOCALS~1\Temp\b.exe[1232] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!SetWindowPos] [00416723] C:\DOCUME~1\user\LOCALS~1\Temp\b.exe
IAT C:\DOCUME~1\user\LOCALS~1\Temp\b.exe[1232] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!ShowWindow] [00416671] C:\DOCUME~1\user\LOCALS~1\Temp\b.exe
IAT C:\DOCUME~1\user\LOCALS~1\Temp\b.exe[1232] @ C:\WINDOWS\system32\shell32.dll [USER32.dll!CreateWindowExW] [004165F7] C:\DOCUME~1\user\LOCALS~1\Temp\b.exe
IAT C:\DOCUME~1\user\LOCALS~1\Temp\b.exe[1232] @ C:\WINDOWS\system32\shell32.dll [USER32.dll!ShowWindow] [00416671] C:\DOCUME~1\user\LOCALS~1\Temp\b.exe
IAT C:\DOCUME~1\user\LOCALS~1\Temp\b.exe[1232] @ C:\WINDOWS\system32\shell32.dll [USER32.dll!SetWindowPos] [00416723] C:\DOCUME~1\user\LOCALS~1\Temp\b.exe
—- Devices - GMER 1.0.15 —-
AttachedDevice \FileSystem\Ntfs \Ntfs sisidex.sys (FileSpy Filter Driver/Windows ® 2000 DDK provider)
AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \FileSystem\Fastfat \Fat sisidex.sys (FileSpy Filter Driver/Windows ® 2000 DDK provider)
AttachedDevice \FileSystem\Fastfat \Fat fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
—- Services - GMER 1.0.15 —-
Service C:\WINDOWS\system32\svchost.exe (*** hidden *** ) [AUTO] AppSvc <– ROOTKIT !!!
—- Registry - GMER 1.0.15 —-
Reg HKLM\SYSTEM\ControlSet001\Services\enqwwivy@DisplayName Security Monitor
Reg HKLM\SYSTEM\ControlSet001\Services\enqwwivy@Type 32
Reg HKLM\SYSTEM\ControlSet001\Services\enqwwivy@Start 2
Reg HKLM\SYSTEM\ControlSet001\Services\enqwwivy@ErrorControl 0
Reg HKLM\SYSTEM\ControlSet001\Services\enqwwivy@ImagePath %SystemRoot%\system32\svchost.exe -k netsvcs
Reg HKLM\SYSTEM\ControlSet001\Services\enqwwivy@ObjectName LocalSystem
Reg HKLM\SYSTEM\ControlSet001\Services\enqwwivy@Description Provides notifications for AutoPlay hardware events.
Reg HKLM\SYSTEM\ControlSet001\Services\enqwwivy\Parameters (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\enqwwivy\Parameters@ServiceDll C:\WINDOWS\system32\oengp.dll
Reg HKLM\SYSTEM\ControlSet002\Services\AppSvc@DisplayName Shell Time
Reg HKLM\SYSTEM\ControlSet002\Services\AppSvc@Type 32
Reg HKLM\SYSTEM\ControlSet002\Services\AppSvc@Start 2
Reg HKLM\SYSTEM\ControlSet002\Services\AppSvc@ErrorControl 0
Reg HKLM\SYSTEM\ControlSet002\Services\AppSvc@ImagePath %SystemRoot%\system32\svchost.exe -k netsvcs
Reg HKLM\SYSTEM\ControlSet002\Services\AppSvc@ObjectName LocalSystem
Reg HKLM\SYSTEM\ControlSet002\Services\AppSvc@Description Resolves and caches Domain Name System (DNS) names for this computer. If this service is stopped, this computer will not be able to resolve DNS names and locate Active Directory domain controllers. If this service is disabled, any services that explicitly depend on it will fail to start.
Reg HKLM\SYSTEM\ControlSet002\Services\AppSvc\Parameters (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\AppSvc\Parameters@ServiceDll C:\WINDOWS\system32\hslel.dll
Reg HKLM\SYSTEM\ControlSet003\Services\AppSvc@DisplayName Shell Time
Reg HKLM\SYSTEM\ControlSet003\Services\AppSvc@Type 32
Reg HKLM\SYSTEM\ControlSet003\Services\AppSvc@Start 2
Reg HKLM\SYSTEM\ControlSet003\Services\AppSvc@ErrorControl 0
Reg HKLM\SYSTEM\ControlSet003\Services\AppSvc@ImagePath %SystemRoot%\system32\svchost.exe -k netsvcs
Reg HKLM\SYSTEM\ControlSet003\Services\AppSvc@ObjectName LocalSystem
Reg HKLM\SYSTEM\ControlSet003\Services\AppSvc@Description Resolves and caches Domain Name System (DNS) names for this computer. If this service is stopped, this computer will not be able to resolve DNS names and locate Active Directory domain controllers. If this service is disabled, any services that explicitly depend on it will fail to start.
Reg HKLM\SYSTEM\ControlSet003\Services\AppSvc\Parameters (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\AppSvc\Parameters@ServiceDll C:\WINDOWS\system32\hslel.dll
Reg HKLM\SYSTEM\ControlSet004\Services\AppSvc@DisplayName Shell Time
Reg HKLM\SYSTEM\ControlSet004\Services\AppSvc@Type 32
Reg HKLM\SYSTEM\ControlSet004\Services\AppSvc@Start 2
Reg HKLM\SYSTEM\ControlSet004\Services\AppSvc@ErrorControl 0
Reg HKLM\SYSTEM\ControlSet004\Services\AppSvc@ImagePath %SystemRoot%\system32\svchost.exe -k netsvcs
Reg HKLM\SYSTEM\ControlSet004\Services\AppSvc@ObjectName LocalSystem
Reg HKLM\SYSTEM\ControlSet004\Services\AppSvc@Description Resolves and caches Domain Name System (DNS) names for this computer. If this service is stopped, this computer will not be able to resolve DNS names and locate Active Directory domain controllers. If this service is disabled, any services that explicitly depend on it will fail to start.
Reg HKLM\SYSTEM\ControlSet004\Services\AppSvc\Parameters (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\AppSvc\Parameters@ServiceDll C:\WINDOWS\system32\hslel.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\AppSvc@DisplayName Shell Time
Reg HKLM\SYSTEM\CurrentControlSet\Services\AppSvc@Type 32
Reg HKLM\SYSTEM\CurrentControlSet\Services\AppSvc@Start 2
Reg HKLM\SYSTEM\CurrentControlSet\Services\AppSvc@ErrorControl 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\AppSvc@ImagePath %SystemRoot%\system32\svchost.exe -k netsvcs
Reg HKLM\SYSTEM\CurrentControlSet\Services\AppSvc@ObjectName LocalSystem
Reg HKLM\SYSTEM\CurrentControlSet\Services\AppSvc@Description Resolves and caches Domain Name System (DNS) names for this computer. If this service is stopped, this computer will not be able to resolve DNS names and locate Active Directory domain controllers. If this service is disabled, any services that explicitly depend on it will fail to start.
Reg HKLM\SYSTEM\CurrentControlSet\Services\AppSvc\Parameters
Reg HKLM\SYSTEM\CurrentControlSet\Services\AppSvc\Parameters@ServiceDll C:\WINDOWS\system32\hslel.dll
Reg HKLM\SYSTEM\ControlSet006\Services\AppSvc@DisplayName Shell Time
Reg HKLM\SYSTEM\ControlSet006\Services\AppSvc@Type 32
Reg HKLM\SYSTEM\ControlSet006\Services\AppSvc@Start 2
Reg HKLM\SYSTEM\ControlSet006\Services\AppSvc@ErrorControl 0
Reg HKLM\SYSTEM\ControlSet006\Services\AppSvc@ImagePath %SystemRoot%\system32\svchost.exe -k netsvcs
Reg HKLM\SYSTEM\ControlSet006\Services\AppSvc@ObjectName LocalSystem
Reg HKLM\SYSTEM\ControlSet006\Services\AppSvc@Description Resolves and caches Domain Name System (DNS) names for this computer. If this service is stopped, this computer will not be able to resolve DNS names and locate Active Directory domain controllers. If this service is disabled, any services that explicitly depend on it will fail to start.
Reg HKLM\SYSTEM\ControlSet006\Services\AppSvc\Parameters (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet006\Services\AppSvc\Parameters@ServiceDll C:\WINDOWS\system32\hslel.dll
—- EOF - GMER 1.0.15 —-
DDS (Ver_09-07-30.01) - NTFSx86
Run by [removed] at 21:31:28.57 on 02/08/2009
Internet Explorer: 6.0.2900.2180
Microsoft Windows XP Home Edition 5.1.2600.2.1252.44.1033.18.1023.551 [GMT 1:00]
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\iPod Access for Windows\iPAHelper.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\explorer.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\Java\jre1.5.0\bin\jusched.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Tenda\W541U\UI.exe
C:\Program Files\VIA\RAID\raid_tool.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\DOCUME~1\user\LOCALS~1\Temp\b.exe
C:\Documents and Settings\user\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.co.uk/
uInternet Settings,ProxyOverride =
uRun: [AdobeBridge]
uRun: [Monopod] c:\docume~1\user\locals~1\temp\b.exe
mRun: [SunJavaUpdateSched] c:\program files\java\jre1.5.0\bin\jusched.exe
mRun: [SpeedTouch USB Diagnostics] "c:\program files\thomson\speedtouch usb\Dragdiag.exe" /icon
mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe
mRun: [AdobeCS4ServiceManager] "c:\program files\common files\adobe\cs4servicemanager\CS4ServiceManager.exe" -launchedbylogin
mRun: [SoundMan] SOUNDMAN.EXE
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRunOnce: [X0@] 58304000
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office\OSA9.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\tendaw~1.lnk - c:\program files\tenda\w541u\UI.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\viarai~1.lnk - c:\program files\via\raid\raid_tool.exe
uPolicies-system: EnableProfileQuota = 1 (0x1)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBC} - c:\program files\java\jre1.5.0\bin\npjpi150.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0-windows-i586.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
Notify: avgrsstarter - avgrsstx.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\user\applic~1\mozilla\firefox\profiles\xaic2nf4.default\
FF - prefs.js: browser.startup.homepage - www.google.com
FF - component: c:\program files\avg\avg8\firefox\components\avgssff.dll
============= SERVICES / DRIVERS ===============
R0 viasraid;viasraid;c:\windows\system32\drivers\viasraid.sys [2009-4-15 77312]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-1-11 335752]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2009-1-11 27784]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-1-11 108552]
R2 aawservice;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\aawservice.exe [2008-9-10 611664]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\avg\avg8\avgemc.exe [2009-1-11 907032]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2009-1-11 298776]
S1 sFxdrv;sFxdrv;\??\c:\program files\sfx\sfx.sys –> c:\program files\sfx\sfX.sYs [?]
S2 AppSvc;Shell Time;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336]
S2 sfx;sfx;c:\windows\system32\SvchoSt.ExE -k sfx [2004-8-4 14336]
S3 scsiscan;SCSI Scanner Driver;c:\windows\system32\drivers\scsiscan.sys [2009-4-10 10880]
=============== Created Last 30 ================
2009-08-02 16:32 –d—– C:\VundoFix Backups
2009-08-02 13:50 –d—– c:\docume~1\user\applic~1\GetPrimo
2009-08-02 13:50 –d—– c:\program files\iPrimo
2009-08-02 13:50 –d—– c:\program files\GetPrimo
2009-08-02 13:49 –d—– c:\docume~1\user\applic~1\pridl
2009-08-01 22:59 –d—– c:\docume~1\user\applic~1\cft
2009-08-01 22:54 –d—– c:\docume~1\alluse~1\applic~1\12299214
2009-08-01 22:54 0 a——- c:\windows\SC.INS
2009-08-01 22:54 0 a——- c:\windows\sc.exe
2009-08-01 22:54 –d—– c:\program files\Protection System
2009-08-01 22:54 359,040 a——- c:\windows\system32\drivers\TCPIP.SYS.ORIGINAL
2009-07-12 12:29 12,632 a——- c:\windows\system32\lsdelete.exe
2009-07-12 11:47 252 a——- c:\windows\system32\wisdstr.exe
2009-07-12 11:07 –d—– c:\program files\sFX
2009-07-12 11:07 2 a——- c:\windows\0101120101464849.dat
2009-07-12 11:07 2 a——- c:\windows\010112010146118114.dat
2009-07-12 11:07 1 a——- c:\windows\934fdfg34fgjf23
==================== Find3M ====================
2009-08-02 13:49 359,040 a——- c:\windows\system32\drivers\TCPIP.SYS
2009-07-19 10:16 335,752 a——- c:\windows\system32\drivers\avgldx86.sys
2009-06-26 09:11 11,952 a——- c:\windows\system32\avgrsstx.dll
============= FINISH: 21:31:35.60 ===============