This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Data Execution Preventer during startup

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello to all - First post, from long time lurker - haven't needed to post until now! I think I have just been infected by vundo variant. Scanned with AdAware, MalwareBytes, AVG & Vundofix - deleted everything that was found. Now wnen I start up a login screen appears, asks for password (I don't have any passwords set on this machine). I ok this and a 'Data Execution Preventer' pops up, tells me that Windows has closed userinit logon application, followed by a 'send report' popup. The same happens for automatic updates, then just a blank blue screen. Only way I can get desktop and taskbar to appear is to start explorer.exe as a new process via task manager. Be very grateful if anyone at this excellent forum could offer any help. This is my HJ log: Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 19:27:03, on 02/08/2009 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe C:\WINDOWS\system32\spoolsv.exe C:\DOCUME~1\user\LOCALS~1\Temp\b.exe C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe C:\Program Files\iPod Access for Windows\iPAHelper.exe C:\WINDOWS\system32\HPZipm12.exe C:\WINDOWS\explorer.exe C:\PROGRA~1\AVG\AVG8\avgrsx.exe C:\Program Files\Java\jre1.5.0\bin\jusched.exe C:\PROGRA~1\AVG\AVG8\avgnsx.exe C:\WINDOWS\system32\svchost.exe C:\PROGRA~1\AVG\AVG8\avgtray.exe C:\WINDOWS\SOUNDMAN.EXE C:\PROGRA~1\AVG\AVG8\avgemc.exe C:\Program Files\HP\HP Software Update\HPWuSchd2.exe C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe C:\Program Files\Tenda\W541U\UI.exe C:\Program Files\VIA\RAID\raid_tool.exe C:\Program Files\AVG\AVG8\avgcsrvx.exe C:\WINDOWS\system32\wscntfy.exe C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0\bin\jusched.exe O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe O4 - HKLM\..\Run: [AdobeCS4ServiceManager] "C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe O4 - HKLM\..\RunOnce: [X0@] X0@ O4 - HKCU\..\Run: [Monopod] C:\DOCUME~1\user\LOCALS~1\Temp\b.exe O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE O4 - Global Startup: Tenda W541U.lnk = ? O4 - Global Startup: VIA RAID TOOL.lnk = C:\Program Files\VIA\RAID\raid_tool.exe O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: iPAHelper.exe - Unknown owner - C:\Program Files\iPod Access for Windows\iPAHelper.exe O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe – End of file - 4320 bytes
Hi tonyperrin, welcome to the forum.

To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
  • Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.

Download the GMER Rootkit Scanner. Unzip it to your Desktop.

Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.

Double-click gmer.exe. The program will begin to run.

**Caution**
These types of scans can produce false positives. Do NOT take any action on any
"<— ROOKIT" entries unless advised!

If possible rootkit activity is found, you will be asked if you would like to perform a full scan.
  • Click NO
  • In the right panel, you will see a bunch of boxes that have been checked … leave everything checked and ensure the Show all box is un-checked.
  • Now click the Scan button.
    Once the scan is complete, you may receive another notice about rootkit activity.
  • Click OK.
  • GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "GMER.txt"
  • Save it where you can easily find it, such as your desktop.
If you do not receive notice about possible rootkit activity remain on the Rootkit/Malware tab & make sure the 'Show All' button is unticked.
  • Click the Scan button and let the program do its work. GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop



Please download DDS and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.scr to run the tool.
  • When done, DDS.txt will open.
  • Click Yes at the next prompt for Optional Scan.
  • Save both reports to your desktop.
—————————————————

Please include the contents of the following in your next reply:

DDS.txt

Please attach the second file; Attach.txt. To attach a file, do the following:
  • Under the reply panel is the Attachments Panel
  • Browse for the attachment file you want to upload, then click the green Upload button
  • Once it has uploaded, click the Manage Current Attachments drop down box
  • Click on [external image: Posted Image] to insert the attachment into your post

Please post back with
  • Gmer log
  • Both DDS logs

Thanks
Thanks oldman960 for your very speedy reply. Followed your instructions exactly. Here are my GMER & DDS logs (DDS Attach file is attached as instructed):

GMER 1.0.15.15011 [gmer.exe] - http://www.gmer.net
Rootkit scan 2009-08-02 21:30:05
Windows 5.1.2600 Service Pack 2


—- User code sections - GMER 1.0.15 —-

.text C:\PROGRA~1\AVG\AVG8\avgemc.exe[168] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA48F4
.text C:\PROGRA~1\AVG\AVG8\avgemc.exe[168] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA4983
.text C:\PROGRA~1\AVG\AVG8\avgemc.exe[168] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA4990
.text C:\PROGRA~1\AVG\AVG8\avgemc.exe[168] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4C14
.text C:\PROGRA~1\AVG\AVG8\avgemc.exe[168] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA4979
.text C:\PROGRA~1\AVG\AVG8\avgemc.exe[168] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA49D1
.text C:\WINDOWS\SOUNDMAN.EXE[192] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA48F4
.text C:\WINDOWS\SOUNDMAN.EXE[192] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA4983
.text C:\WINDOWS\SOUNDMAN.EXE[192] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA4990
.text C:\WINDOWS\SOUNDMAN.EXE[192] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4C14
.text C:\WINDOWS\SOUNDMAN.EXE[192] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA4979
.text C:\WINDOWS\SOUNDMAN.EXE[192] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA49D1
.text C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[244] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA48F4
.text C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[244] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA4983
.text C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[244] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA4990
.text C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[244] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4C14
.text C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[244] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA4979
.text C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[244] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA49D1
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[428] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA48F4
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[428] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA4983
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[428] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA4990
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[428] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4C14
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[428] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA4979
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[428] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA49D1
.text C:\Program Files\Tenda\W541U\UI.exe[540] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA48F4
.text C:\Program Files\Tenda\W541U\UI.exe[540] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA4983
.text C:\Program Files\Tenda\W541U\UI.exe[540] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA4990
.text C:\Program Files\Tenda\W541U\UI.exe[540] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4C14
.text C:\Program Files\Tenda\W541U\UI.exe[540] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA4979
.text C:\Program Files\Tenda\W541U\UI.exe[540] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA49D1
.text C:\Program Files\VIA\RAID\raid_tool.exe[560] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA48F4
.text C:\Program Files\VIA\RAID\raid_tool.exe[560] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA4983
.text C:\Program Files\VIA\RAID\raid_tool.exe[560] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA4990
.text C:\Program Files\VIA\RAID\raid_tool.exe[560] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4C14
.text C:\Program Files\VIA\RAID\raid_tool.exe[560] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA4979
.text C:\Program Files\VIA\RAID\raid_tool.exe[560] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA49D1
.text C:\Program Files\AVG\AVG8\avgcsrvx.exe[680] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA48F4
.text C:\Program Files\AVG\AVG8\avgcsrvx.exe[680] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA4983
.text C:\Program Files\AVG\AVG8\avgcsrvx.exe[680] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA4990
.text C:\Program Files\AVG\AVG8\avgcsrvx.exe[680] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4C14
.text C:\Program Files\AVG\AVG8\avgcsrvx.exe[680] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA4979
.text C:\Program Files\AVG\AVG8\avgcsrvx.exe[680] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA49D1
.text C:\WINDOWS\system32\spoolsv.exe[740] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA48F4
.text C:\WINDOWS\system32\spoolsv.exe[740] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA4983
.text C:\WINDOWS\system32\spoolsv.exe[740] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA4990
.text C:\WINDOWS\system32\spoolsv.exe[740] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4C14
.text C:\WINDOWS\system32\spoolsv.exe[740] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA4979
.text C:\WINDOWS\system32\spoolsv.exe[740] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA49D1
.text C:\WINDOWS\system32\winlogon.exe[980] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FF948F4
.text C:\WINDOWS\system32\winlogon.exe[980] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FF94983
.text C:\WINDOWS\system32\winlogon.exe[980] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FF94990
.text C:\WINDOWS\system32\winlogon.exe[980] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FF94C14
.text C:\WINDOWS\system32\winlogon.exe[980] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FF94979
.text C:\WINDOWS\system32\winlogon.exe[980] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FF949D1
.text C:\WINDOWS\system32\services.exe[1024] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FF948F4
.text C:\WINDOWS\system32\services.exe[1024] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FF94983
.text C:\WINDOWS\system32\services.exe[1024] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FF94990
.text C:\WINDOWS\system32\services.exe[1024] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FF94C14
.text C:\WINDOWS\system32\services.exe[1024] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FF94979
.text C:\WINDOWS\system32\services.exe[1024] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FF949D1
.text C:\WINDOWS\system32\lsass.exe[1036] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FF948F4
.text C:\WINDOWS\system32\lsass.exe[1036] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FF94983
.text C:\WINDOWS\system32\lsass.exe[1036] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FF94990
.text C:\WINDOWS\system32\lsass.exe[1036] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FF94C14
.text C:\WINDOWS\system32\lsass.exe[1036] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FF94979
.text C:\WINDOWS\system32\lsass.exe[1036] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FF949D1
.text C:\WINDOWS\system32\svchost.exe[1180] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA48F4
.text C:\WINDOWS\system32\svchost.exe[1180] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA4983
.text C:\WINDOWS\system32\svchost.exe[1180] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA4990
.text C:\WINDOWS\system32\svchost.exe[1180] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4C14
.text C:\WINDOWS\system32\svchost.exe[1180] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA4979
.text C:\WINDOWS\system32\svchost.exe[1180] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA49D1
.text C:\DOCUME~1\user\LOCALS~1\Temp\b.exe[1232] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA48F4
.text C:\DOCUME~1\user\LOCALS~1\Temp\b.exe[1232] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA4983
.text C:\DOCUME~1\user\LOCALS~1\Temp\b.exe[1232] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA4990
.text C:\DOCUME~1\user\LOCALS~1\Temp\b.exe[1232] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4C14
.text C:\DOCUME~1\user\LOCALS~1\Temp\b.exe[1232] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA4979
.text C:\DOCUME~1\user\LOCALS~1\Temp\b.exe[1232] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA49D1
.text C:\WINDOWS\system32\svchost.exe[1240] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA48F4
.text C:\WINDOWS\system32\svchost.exe[1240] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA4983
.text C:\WINDOWS\system32\svchost.exe[1240] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA4990
.text C:\WINDOWS\system32\svchost.exe[1240] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4C14
.text C:\WINDOWS\system32\svchost.exe[1240] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA4979
.text C:\WINDOWS\system32\svchost.exe[1240] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA49D1
.text C:\WINDOWS\System32\svchost.exe[1280] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FF848F4
.text C:\WINDOWS\System32\svchost.exe[1280] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FF84983
.text C:\WINDOWS\System32\svchost.exe[1280] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FF84990
.text C:\WINDOWS\System32\svchost.exe[1280] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FF84C14
.text C:\WINDOWS\System32\svchost.exe[1280] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FF84979
.text C:\WINDOWS\System32\svchost.exe[1280] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FF849D1
.text C:\WINDOWS\system32\svchost.exe[1372] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA48F4
.text C:\WINDOWS\system32\svchost.exe[1372] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA4983
.text C:\WINDOWS\system32\svchost.exe[1372] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA4990
.text C:\WINDOWS\system32\svchost.exe[1372] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4C14
.text C:\WINDOWS\system32\svchost.exe[1372] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA4979
.text C:\WINDOWS\system32\svchost.exe[1372] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA49D1
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[1428] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA48F4
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[1428] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA4983
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[1428] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA4990
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[1428] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4C14
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[1428] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA4979
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[1428] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA49D1
.text C:\Program Files\iPod Access for Windows\iPAHelper.exe[1460] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA48F4
.text C:\Program Files\iPod Access for Windows\iPAHelper.exe[1460] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA4983
.text C:\Program Files\iPod Access for Windows\iPAHelper.exe[1460] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA4990
.text C:\Program Files\iPod Access for Windows\iPAHelper.exe[1460] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4C14
.text C:\Program Files\iPod Access for Windows\iPAHelper.exe[1460] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA4979
.text C:\Program Files\iPod Access for Windows\iPAHelper.exe[1460] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA49D1
.text C:\WINDOWS\system32\HPZipm12.exe[1484] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA48F4
.text C:\WINDOWS\system32\HPZipm12.exe[1484] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA4983
.text C:\WINDOWS\system32\HPZipm12.exe[1484] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA4990
.text C:\WINDOWS\system32\HPZipm12.exe[1484] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4C14
.text C:\WINDOWS\system32\HPZipm12.exe[1484] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA4979
.text C:\WINDOWS\system32\HPZipm12.exe[1484] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA49D1
.text C:\WINDOWS\system32\svchost.exe[1512] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA48F4
.text C:\WINDOWS\system32\svchost.exe[1512] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA4983
.text C:\WINDOWS\system32\svchost.exe[1512] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA4990
.text C:\WINDOWS\system32\svchost.exe[1512] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4C14
.text C:\WINDOWS\system32\svchost.exe[1512] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA4979
.text C:\WINDOWS\system32\svchost.exe[1512] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA49D1
.reloc C:\WINDOWS\explorer.exe[1628] C:\WINDOWS\explorer.exe section is executable [0x010FB000, 0x8800, 0xE0000040]
.reloc C:\WINDOWS\explorer.exe[1628] C:\WINDOWS\explorer.exe entry point in ".reloc" section [0x0110363C]
.text C:\WINDOWS\explorer.exe[1628] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA48F4
.text C:\WINDOWS\explorer.exe[1628] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA4983
.text C:\WINDOWS\explorer.exe[1628] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA4990
.text C:\WINDOWS\explorer.exe[1628] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4C14
.text C:\WINDOWS\explorer.exe[1628] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA4979
.text C:\WINDOWS\explorer.exe[1628] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA49D1
.text C:\PROGRA~1\AVG\AVG8\avgrsx.exe[1852] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA48F4
.text C:\PROGRA~1\AVG\AVG8\avgrsx.exe[1852] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA4983
.text C:\PROGRA~1\AVG\AVG8\avgrsx.exe[1852] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA4990
.text C:\PROGRA~1\AVG\AVG8\avgrsx.exe[1852] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4C14
.text C:\PROGRA~1\AVG\AVG8\avgrsx.exe[1852] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA4979
.text C:\PROGRA~1\AVG\AVG8\avgrsx.exe[1852] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA49D1
.text C:\Program Files\Java\jre1.5.0\bin\jusched.exe[1884] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA48F4
.text C:\Program Files\Java\jre1.5.0\bin\jusched.exe[1884] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA4983
.text C:\Program Files\Java\jre1.5.0\bin\jusched.exe[1884] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA4990
.text C:\Program Files\Java\jre1.5.0\bin\jusched.exe[1884] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4C14
.text C:\Program Files\Java\jre1.5.0\bin\jusched.exe[1884] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA4979
.text C:\Program Files\Java\jre1.5.0\bin\jusched.exe[1884] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA49D1
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[1920] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA48F4
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[1920] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA4983
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[1920] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA4990
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[1920] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4C14
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[1920] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA4979
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[1920] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA49D1
.text C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe[1948] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA48F4
.text C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe[1948] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA4983
.text C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe[1948] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA4990
.text C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe[1948] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4C14
.text C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe[1948] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA4979
.text C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe[1948] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA49D1
.text C:\WINDOWS\system32\svchost.exe[1980] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA48F4
.text C:\WINDOWS\system32\svchost.exe[1980] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA4983
.text C:\WINDOWS\system32\svchost.exe[1980] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA4990
.text C:\WINDOWS\system32\svchost.exe[1980] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4C14
.text C:\WINDOWS\system32\svchost.exe[1980] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA4979
.text C:\WINDOWS\system32\svchost.exe[1980] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA49D1
.text C:\PROGRA~1\AVG\AVG8\avgtray.exe[2012] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA48F4
.text C:\PROGRA~1\AVG\AVG8\avgtray.exe[2012] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA4983
.text C:\PROGRA~1\AVG\AVG8\avgtray.exe[2012] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA4990
.text C:\PROGRA~1\AVG\AVG8\avgtray.exe[2012] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4C14
.text C:\PROGRA~1\AVG\AVG8\avgtray.exe[2012] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA4979
.text C:\PROGRA~1\AVG\AVG8\avgtray.exe[2012] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA49D1
.text C:\WINDOWS\System32\alg.exe[2108] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA48F4
.text C:\WINDOWS\System32\alg.exe[2108] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA4983
.text C:\WINDOWS\System32\alg.exe[2108] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA4990
.text C:\WINDOWS\System32\alg.exe[2108] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4C14
.text C:\WINDOWS\System32\alg.exe[2108] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA4979
.text C:\WINDOWS\System32\alg.exe[2108] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA49D1
.text C:\WINDOWS\system32\wscntfy.exe[2228] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA48F4
.text C:\WINDOWS\system32\wscntfy.exe[2228] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA4983
.text C:\WINDOWS\system32\wscntfy.exe[2228] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA4990
.text C:\WINDOWS\system32\wscntfy.exe[2228] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4C14
.text C:\WINDOWS\system32\wscntfy.exe[2228] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA4979
.text C:\WINDOWS\system32\wscntfy.exe[2228] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA49D1
.text C:\Program Files\Mozilla Firefox\firefox.exe[2376] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA48F4
.text C:\Program Files\Mozilla Firefox\firefox.exe[2376] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA4983
.text C:\Program Files\Mozilla Firefox\firefox.exe[2376] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA4990
.text C:\Program Files\Mozilla Firefox\firefox.exe[2376] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4C14
.text C:\Program Files\Mozilla Firefox\firefox.exe[2376] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA4979
.text C:\Program Files\Mozilla Firefox\firefox.exe[2376] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA49D1
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[2492] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA48F4
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[2492] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA4983
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[2492] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA4990
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[2492] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4C14
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[2492] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA4979
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[2492] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA49D1
.text C:\Documents and Settings\user\Desktop\gmer.exe[3028] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA48F4
.text C:\Documents and Settings\user\Desktop\gmer.exe[3028] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA4983
.text C:\Documents and Settings\user\Desktop\gmer.exe[3028] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA4990
.text C:\Documents and Settings\user\Desktop\gmer.exe[3028] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4C14
.text C:\Documents and Settings\user\Desktop\gmer.exe[3028] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA4979
.text C:\Documents and Settings\user\Desktop\gmer.exe[3028] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA49D1
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[3272] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA48F4
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[3272] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA4983
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[3272] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA4990
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[3272] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4C14
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[3272] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA4979
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[3272] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA49D1
.text C:\WINDOWS\system32\wuauclt.exe[3452] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA48F4
.text C:\WINDOWS\system32\wuauclt.exe[3452] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA4983
.text C:\WINDOWS\system32\wuauclt.exe[3452] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA4990
.text C:\WINDOWS\system32\wuauclt.exe[3452] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4C14
.text C:\WINDOWS\system32\wuauclt.exe[3452] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA4979
.text C:\WINDOWS\system32\wuauclt.exe[3452] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA49D1

—- User IAT/EAT - GMER 1.0.15 —-

IAT C:\DOCUME~1\user\LOCALS~1\Temp\b.exe[1232] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!CreateWindowExA] [0041657D] C:\DOCUME~1\user\LOCALS~1\Temp\b.exe
IAT C:\DOCUME~1\user\LOCALS~1\Temp\b.exe[1232] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!CreateWindowExW] [004165F7] C:\DOCUME~1\user\LOCALS~1\Temp\b.exe
IAT C:\DOCUME~1\user\LOCALS~1\Temp\b.exe[1232] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!ShowWindow] [00416671] C:\DOCUME~1\user\LOCALS~1\Temp\b.exe
IAT C:\DOCUME~1\user\LOCALS~1\Temp\b.exe[1232] @ C:\WINDOWS\system32\WININET.dll [USER32.dll!SetWindowPos] [00416723] C:\DOCUME~1\user\LOCALS~1\Temp\b.exe
IAT C:\DOCUME~1\user\LOCALS~1\Temp\b.exe[1232] @ C:\WINDOWS\system32\WININET.dll [USER32.dll!ShowWindow] [00416671] C:\DOCUME~1\user\LOCALS~1\Temp\b.exe
IAT C:\DOCUME~1\user\LOCALS~1\Temp\b.exe[1232] @ C:\WINDOWS\system32\WININET.dll [USER32.dll!CreateWindowExA] [0041657D] C:\DOCUME~1\user\LOCALS~1\Temp\b.exe
IAT C:\DOCUME~1\user\LOCALS~1\Temp\b.exe[1232] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!CreateWindowExA] [0041657D] C:\DOCUME~1\user\LOCALS~1\Temp\b.exe
IAT C:\DOCUME~1\user\LOCALS~1\Temp\b.exe[1232] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!CreateWindowExW] [004165F7] C:\DOCUME~1\user\LOCALS~1\Temp\b.exe
IAT C:\DOCUME~1\user\LOCALS~1\Temp\b.exe[1232] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!SetWindowPos] [00416723] C:\DOCUME~1\user\LOCALS~1\Temp\b.exe
IAT C:\DOCUME~1\user\LOCALS~1\Temp\b.exe[1232] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!ShowWindow] [00416671] C:\DOCUME~1\user\LOCALS~1\Temp\b.exe
IAT C:\DOCUME~1\user\LOCALS~1\Temp\b.exe[1232] @ C:\WINDOWS\system32\shell32.dll [USER32.dll!CreateWindowExW] [004165F7] C:\DOCUME~1\user\LOCALS~1\Temp\b.exe
IAT C:\DOCUME~1\user\LOCALS~1\Temp\b.exe[1232] @ C:\WINDOWS\system32\shell32.dll [USER32.dll!ShowWindow] [00416671] C:\DOCUME~1\user\LOCALS~1\Temp\b.exe
IAT C:\DOCUME~1\user\LOCALS~1\Temp\b.exe[1232] @ C:\WINDOWS\system32\shell32.dll [USER32.dll!SetWindowPos] [00416723] C:\DOCUME~1\user\LOCALS~1\Temp\b.exe

—- Devices - GMER 1.0.15 —-

AttachedDevice \FileSystem\Ntfs \Ntfs sisidex.sys (FileSpy Filter Driver/Windows ® 2000 DDK provider)
AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \FileSystem\Fastfat \Fat sisidex.sys (FileSpy Filter Driver/Windows ® 2000 DDK provider)
AttachedDevice \FileSystem\Fastfat \Fat fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

—- Services - GMER 1.0.15 —-

Service C:\WINDOWS\system32\svchost.exe (*** hidden *** ) [AUTO] AppSvc <– ROOTKIT !!!

—- Registry - GMER 1.0.15 —-

Reg HKLM\SYSTEM\ControlSet001\Services\enqwwivy@DisplayName Security Monitor
Reg HKLM\SYSTEM\ControlSet001\Services\enqwwivy@Type 32
Reg HKLM\SYSTEM\ControlSet001\Services\enqwwivy@Start 2
Reg HKLM\SYSTEM\ControlSet001\Services\enqwwivy@ErrorControl 0
Reg HKLM\SYSTEM\ControlSet001\Services\enqwwivy@ImagePath %SystemRoot%\system32\svchost.exe -k netsvcs
Reg HKLM\SYSTEM\ControlSet001\Services\enqwwivy@ObjectName LocalSystem
Reg HKLM\SYSTEM\ControlSet001\Services\enqwwivy@Description Provides notifications for AutoPlay hardware events.
Reg HKLM\SYSTEM\ControlSet001\Services\enqwwivy\Parameters (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\enqwwivy\Parameters@ServiceDll C:\WINDOWS\system32\oengp.dll
Reg HKLM\SYSTEM\ControlSet002\Services\AppSvc@DisplayName Shell Time
Reg HKLM\SYSTEM\ControlSet002\Services\AppSvc@Type 32
Reg HKLM\SYSTEM\ControlSet002\Services\AppSvc@Start 2
Reg HKLM\SYSTEM\ControlSet002\Services\AppSvc@ErrorControl 0
Reg HKLM\SYSTEM\ControlSet002\Services\AppSvc@ImagePath %SystemRoot%\system32\svchost.exe -k netsvcs
Reg HKLM\SYSTEM\ControlSet002\Services\AppSvc@ObjectName LocalSystem
Reg HKLM\SYSTEM\ControlSet002\Services\AppSvc@Description Resolves and caches Domain Name System (DNS) names for this computer. If this service is stopped, this computer will not be able to resolve DNS names and locate Active Directory domain controllers. If this service is disabled, any services that explicitly depend on it will fail to start.
Reg HKLM\SYSTEM\ControlSet002\Services\AppSvc\Parameters (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\AppSvc\Parameters@ServiceDll C:\WINDOWS\system32\hslel.dll
Reg HKLM\SYSTEM\ControlSet003\Services\AppSvc@DisplayName Shell Time
Reg HKLM\SYSTEM\ControlSet003\Services\AppSvc@Type 32
Reg HKLM\SYSTEM\ControlSet003\Services\AppSvc@Start 2
Reg HKLM\SYSTEM\ControlSet003\Services\AppSvc@ErrorControl 0
Reg HKLM\SYSTEM\ControlSet003\Services\AppSvc@ImagePath %SystemRoot%\system32\svchost.exe -k netsvcs
Reg HKLM\SYSTEM\ControlSet003\Services\AppSvc@ObjectName LocalSystem
Reg HKLM\SYSTEM\ControlSet003\Services\AppSvc@Description Resolves and caches Domain Name System (DNS) names for this computer. If this service is stopped, this computer will not be able to resolve DNS names and locate Active Directory domain controllers. If this service is disabled, any services that explicitly depend on it will fail to start.
Reg HKLM\SYSTEM\ControlSet003\Services\AppSvc\Parameters (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\AppSvc\Parameters@ServiceDll C:\WINDOWS\system32\hslel.dll
Reg HKLM\SYSTEM\ControlSet004\Services\AppSvc@DisplayName Shell Time
Reg HKLM\SYSTEM\ControlSet004\Services\AppSvc@Type 32
Reg HKLM\SYSTEM\ControlSet004\Services\AppSvc@Start 2
Reg HKLM\SYSTEM\ControlSet004\Services\AppSvc@ErrorControl 0
Reg HKLM\SYSTEM\ControlSet004\Services\AppSvc@ImagePath %SystemRoot%\system32\svchost.exe -k netsvcs
Reg HKLM\SYSTEM\ControlSet004\Services\AppSvc@ObjectName LocalSystem
Reg HKLM\SYSTEM\ControlSet004\Services\AppSvc@Description Resolves and caches Domain Name System (DNS) names for this computer. If this service is stopped, this computer will not be able to resolve DNS names and locate Active Directory domain controllers. If this service is disabled, any services that explicitly depend on it will fail to start.
Reg HKLM\SYSTEM\ControlSet004\Services\AppSvc\Parameters (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\AppSvc\Parameters@ServiceDll C:\WINDOWS\system32\hslel.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\AppSvc@DisplayName Shell Time
Reg HKLM\SYSTEM\CurrentControlSet\Services\AppSvc@Type 32
Reg HKLM\SYSTEM\CurrentControlSet\Services\AppSvc@Start 2
Reg HKLM\SYSTEM\CurrentControlSet\Services\AppSvc@ErrorControl 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\AppSvc@ImagePath %SystemRoot%\system32\svchost.exe -k netsvcs
Reg HKLM\SYSTEM\CurrentControlSet\Services\AppSvc@ObjectName LocalSystem
Reg HKLM\SYSTEM\CurrentControlSet\Services\AppSvc@Description Resolves and caches Domain Name System (DNS) names for this computer. If this service is stopped, this computer will not be able to resolve DNS names and locate Active Directory domain controllers. If this service is disabled, any services that explicitly depend on it will fail to start.
Reg HKLM\SYSTEM\CurrentControlSet\Services\AppSvc\Parameters
Reg HKLM\SYSTEM\CurrentControlSet\Services\AppSvc\Parameters@ServiceDll C:\WINDOWS\system32\hslel.dll
Reg HKLM\SYSTEM\ControlSet006\Services\AppSvc@DisplayName Shell Time
Reg HKLM\SYSTEM\ControlSet006\Services\AppSvc@Type 32
Reg HKLM\SYSTEM\ControlSet006\Services\AppSvc@Start 2
Reg HKLM\SYSTEM\ControlSet006\Services\AppSvc@ErrorControl 0
Reg HKLM\SYSTEM\ControlSet006\Services\AppSvc@ImagePath %SystemRoot%\system32\svchost.exe -k netsvcs
Reg HKLM\SYSTEM\ControlSet006\Services\AppSvc@ObjectName LocalSystem
Reg HKLM\SYSTEM\ControlSet006\Services\AppSvc@Description Resolves and caches Domain Name System (DNS) names for this computer. If this service is stopped, this computer will not be able to resolve DNS names and locate Active Directory domain controllers. If this service is disabled, any services that explicitly depend on it will fail to start.
Reg HKLM\SYSTEM\ControlSet006\Services\AppSvc\Parameters (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet006\Services\AppSvc\Parameters@ServiceDll C:\WINDOWS\system32\hslel.dll

—- EOF - GMER 1.0.15 —-



DDS (Ver_09-07-30.01) - NTFSx86
Run by [removed] at 21:31:28.57 on 02/08/2009
Internet Explorer: 6.0.2900.2180
Microsoft Windows XP Home Edition 5.1.2600.2.1252.44.1033.18.1023.551 [GMT 1:00]

AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\iPod Access for Windows\iPAHelper.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\explorer.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\Java\jre1.5.0\bin\jusched.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Tenda\W541U\UI.exe
C:\Program Files\VIA\RAID\raid_tool.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\DOCUME~1\user\LOCALS~1\Temp\b.exe
C:\Documents and Settings\user\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.co.uk/
uInternet Settings,ProxyOverride =
uRun: [AdobeBridge]
uRun: [Monopod] c:\docume~1\user\locals~1\temp\b.exe
mRun: [SunJavaUpdateSched] c:\program files\java\jre1.5.0\bin\jusched.exe
mRun: [SpeedTouch USB Diagnostics] "c:\program files\thomson\speedtouch usb\Dragdiag.exe" /icon
mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe
mRun: [AdobeCS4ServiceManager] "c:\program files\common files\adobe\cs4servicemanager\CS4ServiceManager.exe" -launchedbylogin
mRun: [SoundMan] SOUNDMAN.EXE
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRunOnce: [X0@] 58304000
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office\OSA9.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\tendaw~1.lnk - c:\program files\tenda\w541u\UI.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\viarai~1.lnk - c:\program files\via\raid\raid_tool.exe
uPolicies-system: EnableProfileQuota = 1 (0x1)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBC} - c:\program files\java\jre1.5.0\bin\npjpi150.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0-windows-i586.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
Notify: avgrsstarter - avgrsstx.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\user\applic~1\mozilla\firefox\profiles\xaic2nf4.default\
FF - prefs.js: browser.startup.homepage - www.google.com
FF - component: c:\program files\avg\avg8\firefox\components\avgssff.dll

============= SERVICES / DRIVERS ===============

R0 viasraid;viasraid;c:\windows\system32\drivers\viasraid.sys [2009-4-15 77312]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-1-11 335752]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2009-1-11 27784]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-1-11 108552]
R2 aawservice;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\aawservice.exe [2008-9-10 611664]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\avg\avg8\avgemc.exe [2009-1-11 907032]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2009-1-11 298776]
S1 sFxdrv;sFxdrv;\??\c:\program files\sfx\sfx.sys –> c:\program files\sfx\sfX.sYs [?]
S2 AppSvc;Shell Time;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336]
S2 sfx;sfx;c:\windows\system32\SvchoSt.ExE -k sfx [2004-8-4 14336]
S3 scsiscan;SCSI Scanner Driver;c:\windows\system32\drivers\scsiscan.sys [2009-4-10 10880]

=============== Created Last 30 ================

2009-08-02 16:32 –d—– C:\VundoFix Backups
2009-08-02 13:50 –d—– c:\docume~1\user\applic~1\GetPrimo
2009-08-02 13:50 –d—– c:\program files\iPrimo
2009-08-02 13:50 –d—– c:\program files\GetPrimo
2009-08-02 13:49 –d—– c:\docume~1\user\applic~1\pridl
2009-08-01 22:59 –d—– c:\docume~1\user\applic~1\cft
2009-08-01 22:54 –d—– c:\docume~1\alluse~1\applic~1\12299214
2009-08-01 22:54 0 a——- c:\windows\SC.INS
2009-08-01 22:54 0 a——- c:\windows\sc.exe
2009-08-01 22:54 –d—– c:\program files\Protection System
2009-08-01 22:54 359,040 a——- c:\windows\system32\drivers\TCPIP.SYS.ORIGINAL
2009-07-12 12:29 12,632 a——- c:\windows\system32\lsdelete.exe
2009-07-12 11:47 252 a——- c:\windows\system32\wisdstr.exe
2009-07-12 11:07 –d—– c:\program files\sFX
2009-07-12 11:07 2 a——- c:\windows\0101120101464849.dat
2009-07-12 11:07 2 a——- c:\windows\010112010146118114.dat
2009-07-12 11:07 1 a——- c:\windows\934fdfg34fgjf23

==================== Find3M ====================

2009-08-02 13:49 359,040 a——- c:\windows\system32\drivers\TCPIP.SYS
2009-07-19 10:16 335,752 a——- c:\windows\system32\drivers\avgldx86.sys
2009-06-26 09:11 11,952 a——- c:\windows\system32\avgrsstx.dll

============= FINISH: 21:31:35.60 ===============

Attachments:

Hi Tonyperrin,

Please read through tese instructions to familarize yourself with what to expect when this tool runs


Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Please post back with the combofix log.

How's the computer now?

Thanks
Hi oldman960 - Disabled AVG, I've tried three times to run combofix.exe - each time I click a warning panel flashes up very briefly, tells me that combofix has been compromised and the icon disappears from desktop! Thanks for sticking with me - Tony
Hi Tonyperrin.

No problem. Let's see if we can find out why combofix won't run.


Download Dr.Web CureIt to the desktop:
  • Doubleclick the drweb-cureit icon to start the program.
  • press start
  • Allow the program to run the initial express scan
  • This will scan the files currently running in memory. If something is found, click the YES button when it asks you if you want to cure it. This is only a short scan 10-15 min.
    Note: A pop up may appear during this phase suggesting you purchase their program - click the X at the top right corner of this pop-up to close it.
  • Once the scan is complete, the results will be displayed
  • If infections are found you will be able to save a report
  • on the menu bar, click file and choose report list.
  • Save the report to your desktop. The report will be called DrWeb.csv
  • Note:this report will need to be renamed to Dr.Web.txt in order to post it on the forum.
  • Close Dr.Web Cureit.
  • Please post the Dr.Web.txt report in your next reply

Thanks
Hi Tonyperrin,

Well that's a good sign.

Your system has been infected by one or more Rootkits/Backdoor Trojans.

This allows hackers to remotely control your computer, steal critical system information and Download and Execute files

Its very possible that anything could have been installed on your computer by the remote attacker, including opening other backdoors and installing rootkits. While we can attempt to clean what we see in your logs, we cannot guarantee that your computer will be completely in the clear since we have no way of knowing that has been done to the computer. Your computer could be completely compromised at this moment. It may be prudent to backup your information, reformat, and reinstall.

More information on Remote Access Trojans can be found here.

I strongly suggest you do the following immediately:
  • Call all of your banks, credit card companies, financial institutions and inform them that you may be a victim of identity theft and to put a watch on your accounts or change all your account numbers.
  • From a clean computer, change *all* your online passwords – for email, for banks, financial accounts, PayPal, eBay, online companies, any online forums or groups you belong to.
  • DO NOT change passwords or do any transactions while using the infected computer because the attacker will get the new passwords and transaction information.

Should you wish to continue cleaning this computer, please proceed.

Let's see if we can get combofix to run this way.

Please read through the instructions to familarize youself with what to expect when the tool runs.

It is vitally important that combofix is renamed before it is even started to download


Please download ComboFix from Here or Here to your Desktop.

**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**

  • If you are using Firefox, make sure that your download settings are as follows:
    -Tools->Options->Main tab
    -Set to "Always ask me where to Save the files".
  • During the download, rename Combofix to Combo-Fix as follows:

[external image: Posted Image]

[external image: Posted Image]

  • It is important you rename Combofix during the download, but not after.
  • Please do not rename Combofix to other names, but only to the one indicated.
  • Close any open browsers.
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix

———————————————————–

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

    ———————————————————–

  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.


Please post back with
  • combofix log.

Thanks
Hi oldman960 - Tried to run Combofix, renamed it as instructed, got the same result as before - just before it disappears a fast warning panel tells me I may be infected by the 'Virut' package. Thanks for your continuing help.
Hi Tonyperrin,

Let's see if it is Virut.

  • Go to http://java.sun.com/javase/downloads/index.jsp
  • Scroll down to "Java Runtime Environment (JRE) 6 Update 14
  • Click the download button on the right.
If Information Bar pop-ups up, right-click on it and say it's OK to display the blocked content.
  • Select the platform (Windows, in your case), mutli language.
  • Accept the license agreement, click continue.
You do not have to install the Java Web Start ActiveX Control
  • Scroll down and click on Windows Offline Installation,
  • Save the file jre-6u14-windows-i586-p.exe to your desktop;
Do not select Run . Do not install it yet.

When the download is complete, close your browser.

Open Control Panel > Add/Remove Programs and uninstall

J2SE Runtime Environment 5.0

Do not uninstall Java TM 6 Update 14 if found! :yeah:

Reboot your computer.

  • Double-click on the saved file ( jre-6u14-windows-i586-p.exe) to install the update.
  • Delete the downloaded installation file after completing the above procedure and reboot if not prompted to do so.

Next, clear the java cache

To clear the Java Plug-in cache:
  • Click Start > Control Panel.
  • Double-click the Java icon in the control panel.
  • On the General tab, Click Settings under Temporary Internet Files.
  • On the Temporary Files Settings screen, Click Delete Files.
  • check all boxes
  • Click OK



*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



Please go to Kaspersky website and perform an online antivirus scan.
  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions.
  • You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button
    • Spyware, Adware, Dialers, and other potentially dangerous programs
    • Archives
    • Mail databases
  • Click on My Computerr under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Change the Files of type to Text file (.txt)
  • Set the Save In to Desktop
  • click the Save button.
  • Please post this log in your next reply

Thanks
Thanks oldman960 - I've followed all java instructions, but can't access Kaspersky website Tried in IE which returns 'page cannot be displayed' and Firefox says 'can't find server' - tried on another computer and connects with no problem - is something preventing me?
Hi Tonyperrin,

This is not shaping up very well. If it is Virut, that could be the cause of the blocking.

Let's try to scan a few core files and see what happens.

Make sure to use Internet Explorer for this
  • Please go to VirSCAN.org FREE on-line scan service
  • Copy and paste the following file path, one at a time, into the "Suspicious files to scan" box on the top of the page
  • make sure the scan is complete and the results saved before submitting the next one.

    c:\docume~1\user\locals~1\temp\b.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\explorer.exe
    C:\WINDOWS\system32\spoolsv.exe
    c:\windows\system32\ctfmon.exe
    c:\windows\system32\userinit.exe

  • Click on the Upload button
  • If a pop-up appears saying the file has been scanned already, please select the ReScan button.
  • Once the Scan is completed, click on the "Copy to Clipboard" button. This will copy the link of the report into the Clipboard.
  • Paste the contents of the Clipboard in your next reply.

Please post back with the VirScan results.

Thanks
Hello oldman960

Here are my clipboard logs - It looks like virut is present and I am dreading what I think you will say to me next!

VirSCAN.org Scanned Report :
Scanned time : 2009/08/03 19:02:06 (BST)
Scanner results: 30% Scanner(11/37) found malware!
File Name : b.exe
File Size : 159232 byte
File Type : PE32 executable for MS Windows (GUI) Intel 80386 32-bit
MD5 : 485da45645950cfb0d03f365b2c7a334
SHA1 : 47aa5282c60c07eb5955b96e70794741c76dd9c7
Online report : http://virscan.org/report/d8552921c6f1f89f…b99da4ecb1.html

Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 4.5.0.3 20090803230129 2009-08-03 0.33 -
AhnLab V3 2009.08.03.08 2009.08.03 2009-08-03 1.30 -
AntiVir 8.2.0.240 7.1.5.66 2009-08-03 0.53 TR/Fakealert.138752
Antiy 2.0.18 20090803.2669463 2009-08-03 0.12 -
Arcavir 2009 200908031302 2009-08-03 0.05 -
Authentium 5.1.1 200908031553 2009-08-03 1.34 W32/Virut.AI!Generic (Heuristic)
AVAST! 4.7.4 090802-0 2009-08-02 0.01 -
AVG 8.5.288 270.13.42/2279 2009-08-03 0.51 Crypt.GDD
BitDefender 7.81008.3833206 7.26974 2009-08-04 3.34 -
CA (VET) 9.0.0.143 31.6.6650 2009-08-03 7.46 -
ClamAV 0.95.2 9647 2009-08-03 0.04 -
Comodo 3.10 1853 2009-08-03 0.69 Heur.Packed.Unknown
CP Secure 1.1.0.715 2009.08.04 2009-08-04 11.54 -
Dr.Web 4.44.0.9170 2009.08.03 2009-08-03 5.21 -
F-Prot 4.4.4.56 20090802 2009-08-02 1.38 Possible W32/Virut.AI!Generic
F-Secure 7.02.73807 2009.07.29.10 2009-07-29 7.65 Virus.Win32.Virut.ce [AVP]
Fortinet 2.81-3.120 10.675 2009-08-03 0.26 -
GData 19.6852/19.424 20090803 2009-08-03 4.95 -
ViRobot 20090730 2009.07.30 2009-07-30 0.41 -
Ikarus T3.1.01.64 2009.08.03.73149 2009-08-03 3.12 -
JiangMin 11.0.800 2009.08.03 2009-08-03 3.43 -
Kaspersky 5.5.10 2009.08.03 2009-08-03 0.06 -
KingSoft 2009.2.5.15 2009.8.3.18 2009-08-03 0.48 -
McAfee 5.3.00 5697 2009-08-03 3.03 -
Microsoft 1.4903 2009.08.03 2009-08-03 4.96 Virus:Win32/Virut.BM
Norman 6.01.09 6.01.00 2009-07-31 4.01 -
Panda 9.05.01 2009.08.03 2009-08-03 2.42 -
Trend Micro 8.700-1004 6.338.06 2009-08-03 0.05 -
Quick Heal 10.00 2009.08.03 2009-08-03 1.10 W32.Virut.G
Rising 20.0 21.41.02.00 2009-08-03 1.12 Packer.Win32.Agent.aq [Suspicious]
Sophos 2.89.1 4.44 2009-08-04 2.75 W32/Scribble-B
Sunbelt 5308 5308 2009-08-02 1.05 Virus.Win32.Virut.ce (v)
Symantec 1.3.0.24 20090803.005 2009-08-03 0.06 -
nProtect 20090803.02 4997410 2009-08-03 6.02 -
The Hacker 6.3.4.3 v00375 2009-07-31 0.81 -
VBA32 3.12.10.9 20090802.1657 2009-08-02 1.89 -
VirusBuster 4.5.11.10 10.111.1/1826083 2009-08-03 2.78 -


VirSCAN.org Scanned Report :
Scanned time : 2009/08/03 19:05:36 (BST)
Scanner results: All Scanners reported not find malware!
File Name : svchost.exe
File Size : 14336 byte
File Type : PE32 executable for MS Windows (GUI) Intel 80386 32-bit
MD5 : 8f078ae4ed187aaabc0a305146de6716
SHA1 : da0ff4006859a7580aba81f486f692dead2014fe
Online report : http://virscan.org/report/eff20c952a4992d3…8534f4a2a5.html

Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 4.5.0.3 20090803230129 2009-08-03 0.32 -
AhnLab V3 2009.08.03.08 2009.08.03 2009-08-03 0.98 -
AntiVir 8.2.0.240 7.1.5.66 2009-08-03 0.05 -
Antiy 2.0.18 20090803.2669463 2009-08-03 0.12 -
Arcavir 2009 200908031615 2009-08-03 0.03 -
Authentium 5.1.1 200908031553 2009-08-03 1.16 -
AVAST! 4.7.4 090803-0 2009-08-03 0.00 -
AVG 8.5.288 270.13.42/2279 2009-08-03 0.33 -
BitDefender 7.81008.3833206 7.26974 2009-08-04 3.69 -
CA (VET) 9.0.0.143 31.6.6650 2009-08-03 9.17 -
ClamAV 0.95.2 9647 2009-08-03 0.01 -
Comodo 3.10 1853 2009-08-03 0.71 -
CP Secure 1.1.0.715 2009.08.04 2009-08-04 11.76 -
Dr.Web 4.44.0.9170 2009.08.03 2009-08-03 5.12 -
F-Prot 4.4.4.56 20090802 2009-08-02 1.21 -
F-Secure 7.02.73807 2009.07.29.10 2009-07-29 0.04 -
Fortinet 2.81-3.120 10.675 2009-08-03 0.23 -
GData 19.6852/19.424 20090803 2009-08-03 4.75 -
ViRobot 20090730 2009.07.30 2009-07-30 0.41 -
Ikarus T3.1.01.64 2009.08.03.73149 2009-08-03 2.94 -
JiangMin 11.0.800 2009.08.03 2009-08-03 3.81 -
Kaspersky 5.5.10 2009.08.03 2009-08-03 0.05 -
KingSoft 2009.2.5.15 2009.8.3.18 2009-08-03 0.47 -
McAfee 5.3.00 5697 2009-08-03 3.01 -
Microsoft 1.4903 2009.08.03 2009-08-03 5.09 -
Norman 6.01.09 6.01.00 2009-07-31 4.01 -
Panda 9.05.01 2009.08.03 2009-08-03 2.44 -
Trend Micro 8.700-1004 6.338.06 2009-08-03 0.03 -
Quick Heal 10.00 2009.08.03 2009-08-03 1.04 -
Rising 20.0 21.41.02.00 2009-08-03 0.80 -
Sophos 2.89.1 4.44 2009-08-04 2.75 -
Sunbelt 5308 5308 2009-08-02 1.06 -
Symantec 1.3.0.24 20090803.005 2009-08-03 0.05 -
nProtect 20090803.02 4997410 2009-08-03 6.96 -
The Hacker 6.3.4.3 v00375 2009-07-31 0.74 -
VBA32 3.12.10.9 20090802.1657 2009-08-02 1.82 -
VirusBuster 4.5.11.10 10.111.2/1826084 2009-08-04 2.21 -


VirSCAN.org Scanned Report :
Scanned time : 2009/08/03 19:10:05 (BST)
Scanner results: 30% Scanner(11/37) found malware!
File Name : explorer.exe
File Size : 1052672 byte
File Type : PE32 executable for MS Windows (GUI) Intel 80386 32-bit
MD5 : c490a3b9de00c31f4244925abcb7b8da
SHA1 : 797a92c683f637a4a2c0f80d21a28e77055d3bfc
Online report : http://virscan.org/report/b3ec1f20de99f9c8…6505815aba.html

Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 4.5.0.3 20090803230129 2009-08-03 0.37 Virus.Win32.Virut.q!IK
AhnLab V3 2009.08.03.08 2009.08.03 2009-08-03 0.88 -
AntiVir 8.2.0.240 7.1.5.66 2009-08-03 0.17 W32/Virut.Gen
Antiy 2.0.18 20090803.2669463 2009-08-03 0.12 -
Arcavir 2009 200908031615 2009-08-03 0.05 -
Authentium 5.1.1 200908031553 2009-08-03 1.17 W32/Virut.AI!Generic (Heuristic)
AVAST! 4.7.4 090803-0 2009-08-03 0.05 -
AVG 8.5.288 270.13.42/2279 2009-08-03 0.53 -
BitDefender 7.81008.3833206 7.26974 2009-08-04 3.35 -
CA (VET) 9.0.0.143 31.6.6650 2009-08-03 8.63 -
ClamAV 0.95.2 9647 2009-08-03 0.17 -
Comodo 3.10 1853 2009-08-03 0.86 -
CP Secure 1.1.0.715 2009.08.04 2009-08-04 11.63 -
Dr.Web 4.44.0.9170 2009.08.03 2009-08-03 7.84 -
F-Prot 4.4.4.56 20090802 2009-08-02 1.30 Possible W32/Virut.AI!Generic
F-Secure 7.02.73807 2009.07.29.10 2009-07-29 7.90 -
Fortinet 2.81-3.120 10.675 2009-08-03 0.22 -
GData 19.6852/19.424 20090803 2009-08-03 4.17 -
ViRobot 20090730 2009.07.30 2009-07-30 0.41 -
Ikarus T3.1.01.64 2009.08.03.73150 2009-08-03 2.98 Virus.Win32.Virut.q
JiangMin 11.0.800 2009.08.03 2009-08-03 4.11 -
Kaspersky 5.5.10 2009.08.03 2009-08-03 0.06 -
KingSoft 2009.2.5.15 2009.8.3.18 2009-08-03 0.53 -
McAfee 5.3.00 5697 2009-08-03 3.04 New Win32.g2
Microsoft 1.4903 2009.08.03 2009-08-03 5.01 Virus:Win32/Virut.BM
Norman 6.01.09 6.01.00 2009-07-31 4.01 -
Panda 9.05.01 2009.08.03 2009-08-03 1.88 Suspicious file
Trend Micro 8.700-1004 6.338.06 2009-08-03 0.05 -
Quick Heal 10.00 2009.08.03 2009-08-03 1.38 W32.Virut.G
Rising 20.0 21.41.02.00 2009-08-03 1.16 -
Sophos 2.89.1 4.44 2009-08-04 2.76 W32/Scribble-B
Sunbelt 5308 5308 2009-08-02 1.03 Virus.Win32.Virut.ce (v)
Symantec 1.3.0.24 20090803.005 2009-08-03 0.07 -
nProtect 20090803.02 4997410 2009-08-03 6.15 -
The Hacker 6.3.4.3 v00375 2009-07-31 0.74 -
VBA32 3.12.10.9 20090802.1657 2009-08-02 2.03 -
VirusBuster 4.5.11.10 10.111.2/1826084 2009-08-04 3.02 -



VirSCAN.org Scanned Report :
Scanned time : 2009/08/03 19:24:12 (BST)
Scanner results: 35% Scanner(13/37) found malware!
File Name : spoolsv.exe
File Size : 78336 byte
File Type : PE32 executable for MS Windows (GUI) Intel 80386 32-bit
MD5 : 09f42976010cbb77550b8c263d05cf66
SHA1 : 9637915b92bc5b18bd68d08c0b60f4d15af87f64
Online report : http://virscan.org/report/d6d009d75f03aceb…6860a876dd.html

Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 4.5.0.3 20090803230129 2009-08-03 0.36 Virus.Win32.Patched!IK
AhnLab V3 2009.08.03.08 2009.08.03 2009-08-03 0.87 -
AntiVir 8.2.0.240 7.1.5.66 2009-08-03 0.32 W32/Virut.Gen
Antiy 2.0.18 20090803.2669463 2009-08-03 0.12 -
Arcavir 2009 200908031615 2009-08-03 0.04 -
Authentium 5.1.1 200908031553 2009-08-03 1.19 W32/Virut.AI!Generic (Heuristic)
AVAST! 4.7.4 090803-0 2009-08-03 0.01 -
AVG 8.5.288 270.13.42/2279 2009-08-03 0.59 -
BitDefender 7.81008.3833206 7.26974 2009-08-04 3.32 -
CA (VET) 9.0.0.143 31.6.6650 2009-08-03 2.99 -
ClamAV 0.95.2 9647 2009-08-03 0.02 -
Comodo 3.10 1853 2009-08-03 0.77 -
CP Secure 1.1.0.715 2009.08.04 2009-08-04 11.58 -
Dr.Web 4.44.0.9170 2009.08.03 2009-08-03 5.27 -
F-Prot 4.4.4.56 20090802 2009-08-02 1.15 Possible W32/Virut.AI!Generic
F-Secure 7.02.73807 2009.07.29.10 2009-07-29 6.00 Type_Win32 [AVP]
Fortinet 2.81-3.120 10.675 2009-08-03 0.24 -
GData 19.6852/19.424 20090803 2009-08-03 4.54 -
ViRobot 20090730 2009.07.30 2009-07-30 0.43 -
Ikarus T3.1.01.64 2009.08.03.73150 2009-08-03 2.95 Virus.Win32.Patched
JiangMin 11.0.800 2009.08.03 2009-08-03 3.45 -
Kaspersky 5.5.10 2009.08.03 2009-08-03 0.06 -
KingSoft 2009.2.5.15 2009.8.3.18 2009-08-03 0.56 -
McAfee 5.3.00 5697 2009-08-03 3.05 New Win32
Microsoft 1.4903 2009.08.03 2009-08-03 4.96 Virus:Win32/Virut.BM
Norman 6.01.09 6.01.00 2009-07-31 4.01 -
Panda 9.05.01 2009.08.03 2009-08-03 2.19 Suspicious file
Trend Micro 8.700-1004 6.338.06 2009-08-03 0.05 Cryp_Xed-15
Quick Heal 10.00 2009.08.03 2009-08-03 1.08 W32.Virut.G
Rising 20.0 21.41.02.00 2009-08-03 1.08 -
Sophos 2.89.1 4.44 2009-08-04 2.78 W32/Scribble-B
Sunbelt 5308 5308 2009-08-02 1.06 Virus.Win32.Virut.ce (v)
Symantec 1.3.0.24 20090803.005 2009-08-03 0.05 -
nProtect 20090803.02 4997410 2009-08-03 6.18 -
The Hacker 6.3.4.3 v00375 2009-07-31 0.69 -
VBA32 3.12.10.9 20090802.1657 2009-08-02 1.91 -
VirusBuster 4.5.11.10 10.111.2/1826084 2009-08-04 2.74 -


VirSCAN.org Scanned Report :
Scanned time : 2009/08/03 19:27:13 (BST)
Scanner results: 32% Scanner(12/37) found malware!
File Name : ctfmon.exe
File Size : 35840 byte
File Type : PE32 executable for MS Windows (GUI) Intel 80386 32-bit
MD5 : 7ea0fc2d2810bd68e7ecd39b95d46f1e
SHA1 : bba779c66a2ad915ccbee5c6733f36ec310f7bcd
Online report : http://virscan.org/report/1c16783cd8d7e138…2c3bd38322.html

Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 4.5.0.3 20090803230129 2009-08-03 0.41 -
AhnLab V3 2009.08.03.08 2009.08.03 2009-08-03 0.78 -
AntiVir 8.2.0.240 7.1.5.66 2009-08-03 0.21 W32/Virut.Gen
Antiy 2.0.18 20090803.2669463 2009-08-03 0.13 -
Arcavir 2009 200908031615 2009-08-03 0.04 -
Authentium 5.1.1 200908031553 2009-08-03 1.16 W32/Virut.AI!Generic (Heuristic)
AVAST! 4.7.4 090803-0 2009-08-03 0.01 -
AVG 8.5.288 270.13.42/2279 2009-08-03 0.55 -
BitDefender 7.81008.3833206 7.26974 2009-08-04 3.35 -
CA (VET) 9.0.0.143 31.6.6650 2009-08-03 8.71 -
ClamAV 0.95.2 9647 2009-08-03 0.01 -
Comodo 3.10 1853 2009-08-03 0.78 -
CP Secure 1.1.0.715 2009.08.04 2009-08-04 11.50 -
Dr.Web 4.44.0.9170 2009.08.03 2009-08-03 5.29 -
F-Prot 4.4.4.56 20090802 2009-08-02 1.14 Possible W32/Virut.AI!Generic
F-Secure 7.02.73807 2009.07.29.10 2009-07-29 5.90 Type_Win32 [AVP]
Fortinet 2.81-3.120 10.675 2009-08-03 0.23 -
GData 19.6852/19.424 20090803 2009-08-03 4.50 -
ViRobot 20090730 2009.07.30 2009-07-30 0.42 -
Ikarus T3.1.01.64 2009.08.03.73150 2009-08-03 3.12 -
JiangMin 11.0.800 2009.08.03 2009-08-03 3.96 -
Kaspersky 5.5.10 2009.08.03 2009-08-03 0.06 -
KingSoft 2009.2.5.15 2009.8.3.18 2009-08-03 0.48 -
McAfee 5.3.00 5697 2009-08-03 3.07 New Win32
Microsoft 1.4903 2009.08.03 2009-08-03 5.00 Virus:Win32/Virut.BM
Norman 6.01.09 6.01.00 2009-07-31 2.01 -
Panda 9.05.01 2009.08.03 2009-08-03 1.88 Suspicious file
Trend Micro 8.700-1004 6.338.06 2009-08-03 0.05 Cryp_Xed-15
Quick Heal 10.00 2009.08.03 2009-08-03 1.15 W32.Virut.G
Rising 20.0 21.41.02.00 2009-08-03 0.93 -
Sophos 2.89.1 4.44 2009-08-04 2.78 W32/Scribble-B
Sunbelt 5308 5308 2009-08-02 1.09 Virus.Win32.Virut.ce (v)
Symantec 1.3.0.24 20090803.005 2009-08-03 0.06 -
nProtect 20090803.02 4997410 2009-08-03 6.12 -
The Hacker 6.3.4.3 v00375 2009-07-31 0.95 -
VBA32 3.12.10.9 20090802.1657 2009-08-02 1.78 Virus.Win32.Virut.X6
VirusBuster 4.5.11.10 10.111.2/1826084 2009-08-04 2.75 -


VirSCAN.org Scanned Report :
Scanned time : 2009/08/03 19:30:11 (BST)
Scanner results: 35% Scanner(13/37) found malware!
File Name : userinit.exe
File Size : 45056 byte
File Type : PE32 executable for MS Windows (GUI) Intel 80386 32-bit
MD5 : a388ce13589d194fe81a7e46992c2118
SHA1 : 159f4378f4ae037b10f25eb4e0917023f84dbf9a
Online report : http://virscan.org/report/18b1b3385ca65187…c7311b8df6.html

Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 4.5.0.3 20090803230129 2009-08-03 0.38 Gen.Malware!IK
AhnLab V3 2009.08.03.08 2009.08.03 2009-08-03 0.96 -
AntiVir 8.2.0.240 7.1.5.66 2009-08-03 0.17 W32/Virut.Gen
Antiy 2.0.18 20090803.2669463 2009-08-03 0.12 -
Arcavir 2009 200908031615 2009-08-03 0.04 -
Authentium 5.1.1 200908031553 2009-08-03 1.16 W32/Virut.AI!Generic (Heuristic)
AVAST! 4.7.4 090803-0 2009-08-03 0.01 -
AVG 8.5.288 270.13.42/2279 2009-08-03 0.64 -
BitDefender 7.81008.3833206 7.26974 2009-08-04 3.44 -
CA (VET) 9.0.0.143 31.6.6650 2009-08-03 6.00 -
ClamAV 0.95.2 9647 2009-08-03 0.02 -
Comodo 3.10 1853 2009-08-03 0.76 -
CP Secure 1.1.0.715 2009.08.04 2009-08-04 11.70 -
Dr.Web 4.44.0.9170 2009.08.03 2009-08-03 5.28 -
F-Prot 4.4.4.56 20090802 2009-08-02 1.15 Possible W32/Virut.AI!Generic
F-Secure 7.02.73807 2009.07.29.10 2009-07-29 0.10 Type_Win32 [AVP]
Fortinet 2.81-3.120 10.675 2009-08-03 0.26 -
GData 19.6852/19.424 20090803 2009-08-03 4.79 -
ViRobot 20090730 2009.07.30 2009-07-30 0.42 -
Ikarus T3.1.01.64 2009.08.03.73150 2009-08-03 2.95 Gen.Malware
JiangMin 11.0.800 2009.08.03 2009-08-03 3.65 -
Kaspersky 5.5.10 2009.08.03 2009-08-03 0.06 -
KingSoft 2009.2.5.15 2009.8.3.18 2009-08-03 0.60 -
McAfee 5.3.00 5697 2009-08-03 3.00 New Win32
Microsoft 1.4903 2009.08.03 2009-08-03 5.04 Virus:Win32/Virut.BM
Norman 6.01.09 6.01.00 2009-07-31 4.01 -
Panda 9.05.01 2009.08.03 2009-08-03 1.63 Suspicious file
Trend Micro 8.700-1004 6.338.06 2009-08-03 0.05 Cryp_Xed-15
Quick Heal 10.00 2009.08.03 2009-08-03 1.32 W32.Virut.G
Rising 20.0 21.41.02.00 2009-08-03 0.91 -
Sophos 2.89.1 4.44 2009-08-04 2.77 W32/Scribble-B
Sunbelt 5308 5308 2009-08-02 1.07 Virus.Win32.Virut.ce (v)
Symantec 1.3.0.24 20090803.005 2009-08-03 0.23 -
nProtect 20090803.02 4997410 2009-08-03 7.80 -
The Hacker 6.3.4.3 v00375 2009-07-31 0.72 -
VBA32 3.12.10.9 20090802.1657 2009-08-02 1.97 -
VirusBuster 4.5.11.10 10.111.2/1826084 2009-08-04 2.72 -
Hi Tonyperrin,

Well it looks like our fears have neen confirmed. There is enough evidence there to convince me that Virut is indeed present, plus the fact that Kaspersky is being blocked and the other problems we are having .

What this infection can do coupled with the previous rootkit warning, reformat is the only way to go.

Some info on Virut

This infection can and will infect all the machine's executable files .exe, .scr plus .html and .htm. Because there are a number of bugs in its code, it may create executable files that are corrupted beyond repair resulting in an inoperative machine.

More information can be found here and here.

A Complete Reformat and Reinstall is the only way to clean the infection. This includes All Drives that contain .exe, .scr, .hlm, .html files.
  • Backup all your documents and important items only.
    data/documents/pictures/movies/songs/etc..
  • DO NOT backup any executable files (,exe .scr .html or .htm)
  • Do Not back up compressed files (zip/cab/rar) files that may contain .exe or .scr files
  • Reformat and Reinstall as outlined HERE

A CD would be best, but a blank USB device will work. Make sure there aren't any executable on it.

If you are going to use a USB device, I suggest you use a freshly formated one. After formatting it, use FDD on it before attaching it to the infected computer.

Be further advised that these infections may have backdoor capabilities.

I suggest you do the following immediately:
  • Call all of your banks, credit card companies, financial institutions and inform them that you may be a victim of identity theft and to put a watch on your accounts or change all your account numbers.
  • From a clean computer, change *all* your online passwords – for email, for banks, financial accounts, PayPal, eBay, online companies, any online forums or groups you belong to.
  • DO NOT change passwords or do any transactions while using the infected computer because the attacker will get the new passwords and transaction information.
Feel free to ask any questions, but keep in mind a Reformat is the only way to clean this computer.

Sorry :(

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI