Sorry for the delayed reply. I have had a busy weekend.
I was unable to run RootRepeal. It says it is initializing and to wait but I let it run a full 12 hours and it never moved forward from there. I tried to run it in safe mode but my computer will not run in safe mode. Each time I try to start in safe mode my computer crashes and I get a blue screen error that says windows was unable to start.
I saved the runme.bat file to my desktop but when I double click it it only opens that same text file with Notepad and nothing else happens.
Following are the two logs I was able to get from DDS and Gmer. I have also attached the second log from DDS just in case you may need it.
Thanks.
DDS (Ver_09-07-30.01) - NTFSx86
Run by [removed] at 15:17:24.50 on Sun 08/23/2009
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.282 [GMT -6:00]
AV: AVG Anti-Virus *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: *disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe
svchost.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\PROGRA~1\AVG\AVG8\avgam.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\WINDOWS\ehome\RMSvc.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
svchost.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
c:\WINDOWS\system32\ZuneBusEnum.exe
C:\Program Files\Pure Networks\Network Magic\nmsrvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Pure Networks\Network Magic\nmapp.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Logitech\QuickCam10\QuickCam10.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\Zune\ZuneLauncher.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\LVComSX.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\Program Files\BitComet\BitComet.exe
C:\WINDOWS\system32\HPZinw12.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Opera\opera.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Documents and Settings\TEMP\Desktop\dds.com
============== Pseudo HJT Report ===============
uSearch Page = hxxp://www.google.com/hws/sb/dell-usuk/en/side.html?channel=us
uSearch Bar = hxxp://www.google.com/hws/sb/dell-usuk/en/side.html?channel=us
uDefault_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=1060915
uInternet Settings,ProxyOverride = *.local
mSearchAssistant = hxxp://www.google.com/ie
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\progra~1\yahoo!\companion\installs\cpn\yt.dll
uURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg8\toolbar\IEToolbar.dll
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\progra~1\yahoo!\companion\installs\cpn\yt.dll
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: BitComet Helper: {39f7e362-828a-4b5a-bcaf-5b79bfdfea60} - c:\program files\bitcomet\tools\BitCometBHO_1.3.3.2.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\program files\spybot - search & destroy\SDHelper.dll
BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\tfswshx.dll
BHO: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg8\toolbar\IEToolbar.dll
BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\bae\BAE.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\progra~1\yahoo!\companion\installs\cpn\YTSingleInstance.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\progra~1\yahoo!\companion\installs\cpn\yt.dll
TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - c:\program files\avg\avg8\toolbar\IEToolbar.dll
EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll
uRun: [DellSupport] "c:\program files\dellsupport\DSAgnt.exe" /startup
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [H/PC Connection Agent] "c:\program files\microsoft activesync\wcescomm.exe"
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
mRun: [ehTray] c:\windows\ehome\ehtray.exe
mRun: [igfxtray] c:\windows\system32\igfxtray.exe
mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe
mRun: [igfxpers] c:\windows\system32\igfxpers.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [Broadcom Wireless Manager UI] c:\windows\system32\WLTRAY.exe
mRun: [SigmatelSysTrayApp] stsystra.exe
mRun: [DVDLauncher] "c:\program files\cyberlink\powerdvd\DVDLauncher.exe"
mRun: [ISUSPM Startup] "c:\program files\common files\installshield\updateservice\isuspm.exe" -startup
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: []
mRun: [dla] c:\windows\system32\dla\tfswctrl.exe
mRun: [MSKDetectorExe] c:\program files\mcafee\spamkiller\MSKDetct.exe /uninstall
mRun: [nmapp] "c:\program files\pure networks\network magic\nmapp.exe" -autorun -nosplash
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [LogitechQuickCamRibbon] "c:\program files\logitech\quickcam10\QuickCam10.exe" /hide
mRun: [LogitechCommunicationsManager] "c:\program files\common files\logishrd\lcommgr\Communications_Helper.exe"
mRun: [Zune Launcher] "c:\program files\zune\ZuneLauncher.exe"
mRun: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
mRun: [dscactivate] "c:\program files\dell support center\gs_agent\custom\dsca.exe"
mRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe
mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\extend~1.lnk - c:\windows\ehome\RMSysTry.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpphot~1.lnk - c:\program files\hp\digital imaging\bin\hpqthb08.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\logite~1.lnk - c:\program files\logitech\desktop messenger\8876480\program\LogitechDesktopMessenger.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\servic~1.lnk - c:\program files\microsoft sql server\80\tools\binn\sqlmangr.exe
uPolicies-system: EnableProfileQuota = 1 (0x1)
IE: &D&ownload &with BitComet - c:\program files\bitcomet\BitComet.exe/AddLink.htm
IE: &D&ownload all video with BitComet - c:\program files\bitcomet\BitComet.exe/AddVideo.htm
IE: &D&ownload all with BitComet - c:\program files\bitcomet\BitComet.exe/AddAllLink.htm
IE: E&xport to Microsoft Excel - c:\progra~1\mi1933~1\office11\EXCEL.EXE/3000
IE: {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://c:\program files\bitcomet\tools\BitCometBHO_1.3.3.2.dll/206
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\mi3aa1~1\INetRepl.dll
IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\mi3aa1~1\INetRepl.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\mi1933~1\office11\REFIEBAR.DLL
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll
Trusted Zone: musicmatch.com\online
DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - hxxp://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {ED28050F-D713-43BA-A376-DCC5C35407D5} - hxxp://entimg.msn.com/client/msnmusax4929.cab
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\logitech\desktop messenger\8876480\program\GAPlugProtocol-8876480.dll
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
Handler: pure-go - {4746C79A-2042-4332-8650-48966E44ABA8} - c:\program files\common files\pure networks shared\puresp3.dll
Notify: avgrsstarter - avgrsstx.dll
Notify: igfxcui - igfxdev.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
============= SERVICES / DRIVERS ===============
R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [2009-8-2 12552]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-8-2 335240]
R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2009-8-2 27784]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-8-2 108552]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2009-8-2 297752]
R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\McrdSvc.exe [2005-10-20 96256]
R3 ndisrd;WinpkFilter Service;c:\windows\system32\drivers\ndisrd.sys [2009-6-23 20480]
S2 srenum;srenum;c:\windows\system32\drivers\srenum.sys –> c:\windows\system32\drivers\srenum.sys [?]
S3 adxapie;adxapie;c:\docume~1\eddie\locals~1\temp\adxapie.sys [2005-3-29 15872]
S3 JL2005C;Dual Mode Camera;c:\windows\system32\drivers\jl2005c.sys [2007-1-26 68954]
=============== Created Last 30 ================
2009-08-18 22:45 –d—– c:\program files\Trend Micro
2009-08-18 19:48 410,984 a——- c:\windows\system32\deploytk.dll
2009-08-15 14:03 1,089,593 ——– c:\windows\system32\dllcache\ntprint.cat
2009-08-15 03:34 –d—– c:\windows\system32\XPSViewer
2009-08-15 03:30 117,760 ——– c:\windows\system32\prntvpt.dll
2009-08-15 03:30 89,088 ——– c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-08-15 03:30 597,504 ——– c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-08-15 03:30 575,488 ——– c:\windows\system32\xpsshhdr.dll
2009-08-15 03:30 575,488 ——– c:\windows\system32\dllcache\xpsshhdr.dll
2009-08-15 03:29 1,676,288 ——– c:\windows\system32\xpssvcs.dll
2009-08-15 03:29 1,676,288 ——– c:\windows\system32\dllcache\xpssvcs.dll
2009-08-15 03:26 –d—– c:\windows\SxsCaPendDel
2009-08-12 00:26 128,512 ——– c:\windows\system32\dllcache\dhtmled.ocx
2009-08-12 00:25 1,315,328 ——– c:\windows\system32\dllcache\msoe.dll
2009-08-07 10:04 –d-h— c:\windows\PIF
2009-08-07 10:02 38,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-07 10:02 19,096 a——- c:\windows\system32\drivers\mbam.sys
2009-08-07 10:02 –d—– c:\program files\Malwarebytes' Anti-Malware
2009-08-05 03:01 204,800 ——– c:\windows\system32\dllcache\mswebdvd.dll
2009-08-02 22:23 221 a——- c:\windows\NCLogConfig.ini
2009-08-02 19:37 –d-h— C:\$AVG8.VAULT$
2009-08-02 18:49 11,952 a——- c:\windows\system32\avgrsstx.dll
2009-08-02 18:49 108,552 a——- c:\windows\system32\drivers\avgtdix.sys
2009-08-02 18:49 12,552 a——- c:\windows\system32\drivers\avgrkx86.sys
2009-08-02 18:49 335,240 a——- c:\windows\system32\drivers\avgldx86.sys
2009-08-02 18:49 –d—– c:\windows\system32\drivers\Avg
2009-08-02 18:49 –d—– c:\docume~1\alluse~1\applic~1\AVG Security Toolbar
2009-08-02 18:48 –d—– c:\program files\AVG
2009-08-02 18:48 –d—– c:\docume~1\alluse~1\applic~1\avg8
2009-08-02 18:22 –d—– c:\docume~1\temp\applic~1\AVG8
2009-08-02 17:42 –d—– c:\docume~1\temp\applic~1\Malwarebytes
2009-08-02 17:42 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-07-31 10:09 –d—– c:\program files\sFX
2009-07-30 13:19 568 a——- c:\windows\system32\msexcr.ini
2009-07-27 22:32 –d—– c:\program files\Microsoft WSE
2009-07-26 16:21 –d—– c:\program files\CDisplay
==================== Find3M ====================
2009-08-22 23:37 3,558 a–sh— c:\windows\system32\KGyGaAvL.sys
2009-08-05 03:01 204,800 a——- c:\windows\system32\mswebdvd.dll
2009-07-22 19:57 43,008 a——- C:\mavj.exe
2009-07-19 18:48 11,067,392 ——– c:\windows\system32\dllcache\ieframe.dll
2009-07-19 07:18 5,937,152 ——– c:\windows\system32\dllcache\mshtml.dll
2009-07-17 13:01 58,880 a——- c:\windows\system32\atl.dll
2009-07-17 13:01 58,880 ——– c:\windows\system32\dllcache\atl.dll
2009-07-13 23:43 286,208 a——- c:\windows\system32\wmpdxm.dll
2009-07-13 23:43 10,841,088 ——– c:\windows\system32\dllcache\wmp.dll
2009-07-13 23:43 286,208 ——– c:\windows\system32\dllcache\wmpdxm.dll
2009-07-03 11:09 915,456 a——- c:\windows\system32\wininet.dll
2009-07-03 11:09 915,456 ——– c:\windows\system32\dllcache\wininet.dll
2009-07-03 11:09 12,800 ——– c:\windows\system32\dllcache\xpshims.dll
2009-07-03 11:09 206,848 a——- c:\windows\system32\dllcache\occache.dll
2009-07-03 11:09 1,208,832 ——– c:\windows\system32\dllcache\urlmon.dll
2009-07-03 11:09 594,432 a——- c:\windows\system32\dllcache\msfeeds.dll
2009-07-03 11:09 55,296 a——- c:\windows\system32\dllcache\msfeedsbs.dll
2009-07-03 11:09 1,985,536 ——– c:\windows\system32\dllcache\iertutil.dll
2009-07-03 11:09 25,600 ——– c:\windows\system32\dllcache\jsproxy.dll
2009-07-03 11:09 184,320 a——- c:\windows\system32\dllcache\iepeers.dll
2009-07-03 11:09 246,272 ——– c:\windows\system32\dllcache\ieproxy.dll
2009-07-03 11:09 386,048 ——– c:\windows\system32\dllcache\iedkcs32.dll
2009-07-03 05:01 173,056 ——– c:\windows\system32\dllcache\ie4uinit.exe
2009-06-16 08:36 119,808 a——- c:\windows\system32\t2embed.dll
2009-06-16 08:36 81,920 a——- c:\windows\system32\fontsub.dll
2009-06-16 08:36 119,808 ——– c:\windows\system32\dllcache\t2embed.dll
2009-06-16 08:36 81,920 ——– c:\windows\system32\dllcache\fontsub.dll
2009-06-12 06:31 80,896 a——- c:\windows\system32\tlntsess.exe
2009-06-12 06:31 80,896 ——– c:\windows\system32\dllcache\tlntsess.exe
2009-06-12 06:31 76,288 a——- c:\windows\system32\telnet.exe
2009-06-12 06:31 76,288 ——– c:\windows\system32\dllcache\telnet.exe
2009-06-10 09:19 2,066,432 a——- c:\windows\system32\mstscax.dll
2009-06-10 09:19 2,066,432 ——– c:\windows\system32\dllcache\mstscax.dll
2009-06-10 08:13 84,992 a——- c:\windows\system32\avifil32.dll
2009-06-10 08:13 84,992 ——– c:\windows\system32\dllcache\avifil32.dll
2009-06-10 00:14 132,096 a——- c:\windows\system32\wkssvc.dll
2009-06-10 00:14 132,096 ——– c:\windows\system32\dllcache\wkssvc.dll
2009-06-05 11:42 2,060,288 a——- c:\windows\system32\usbaaplrc.dll
2009-06-03 13:09 1,291,264 a——- c:\windows\system32\quartz.dll
2009-06-03 13:09 1,291,264 ——– c:\windows\system32\dllcache\quartz.dll
2009-06-02 04:12 102,912 ——– c:\windows\system32\dllcache\iecompat.dll
2009-05-28 20:46 117,092 ac—— c:\windows\hpoins11.dat
2008-09-20 03:08 32,768 ac-sh— c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008092020080921\index.dat
============= FINISH: 15:18:26.41 ===============
GMER 1.0.15.15077 [gmer.exe] -
http://www.gmer.net
Rootkit scan 2009-08-23 22:15:52
Windows 5.1.2600 Service Pack 3
—- Devices - GMER 1.0.15 —-
AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
Device \FileSystem\Fastfat \Fat A7B34D20
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
Device \FileSystem\Cdfs \Cdfs tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
—- Processes - GMER 1.0.15 —-
Library \\?\globalroot\Device\__max++>\F8AA1E84.x86.dll (*** hidden *** ) @ C:\WINDOWS\system32\svchost.exe [224] 0x35670000
Library \\?\globalroot\Device\__max++>\F8AA1E84.x86.dll (*** hidden *** ) @ C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [308] 0x35670000
Library \\?\globalroot\Device\__max++>\F8AA1E84.x86.dll (*** hidden *** ) @ C:\Program Files\Bonjour\mDNSResponder.exe [492] 0x35670000
Library \\?\globalroot\Device\__max++>\F8AA1E84.x86.dll (*** hidden *** ) @ C:\WINDOWS\eHome\ehSched.exe [744] 0x35670000
Library \\?\globalroot\Device\__max++>\F8AA1E84.x86.dll (*** hidden *** ) @ C:\Program Files\Java\jre6\bin\jqs.exe [916] 0x35670000
Library \\?\globalroot\Device\__max++>\F8AA1E84.x86.dll (*** hidden *** ) @ C:\PROGRA~1\AVG\AVG8\avgnsx.exe [1228] 0x35670000
Library \\?\globalroot\Device\__max++>\F8AA1E84.x86.dll (*** hidden *** ) @ C:\WINDOWS\system32\svchost.exe [1264] 0x35670000
Library \\?\globalroot\Device\__max++>\F8AA1E84.x86.dll (*** hidden *** ) @ C:\Program Files\Microsoft ActiveSync\wcescomm.exe [1288] 0x35670000
Library \\?\globalroot\Device\__max++>\F8AA1E84.x86.dll (*** hidden *** ) @ C:\WINDOWS\System32\svchost.exe [1304] 0x35670000
Library \\?\globalroot\Device\__max++>\F8AA1E84.x86.dll (*** hidden *** ) @ C:\WINDOWS\system32\svchost.exe [1412] 0x35670000
Library \\?\globalroot\Device\__max++>\F8AA1E84.x86.dll (*** hidden *** ) @ C:\WINDOWS\system32\svchost.exe [1576] 0x35670000
Library \\?\globalroot\Device\__max++>\F8AA1E84.x86.dll (*** hidden *** ) @ C:\WINDOWS\system32\spoolsv.exe [1844] 0x35670000
Library \\?\globalroot\Device\__max++>\F8AA1E84.x86.dll (*** hidden *** ) @ C:\Program Files\iTunes\iTunesHelper.exe [2140] 0x35670000
Library \\?\globalroot\Device\__max++>\F8AA1E84.x86.dll (*** hidden *** ) @ C:\Program Files\Dell Support Center\bin\sprtcmd.exe [2256] 0x35670000
Library \\?\globalroot\Device\__max++>\F8AA1E84.x86.dll (*** hidden *** ) @ C:\Program Files\Dell Support Center\bin\sprtsvc.exe [2320] 0x35670000
Library \\?\globalroot\Device\__max++>\F8AA1E84.x86.dll (*** hidden *** ) @ C:\WINDOWS\system32\svchost.exe [2384] 0x35670000
Library \\?\globalroot\Device\__max++>\F8AA1E84.x86.dll (*** hidden *** ) @ c:\WINDOWS\system32\ZuneBusEnum.exe [2480] 0x35670000
Library \\?\globalroot\Device\__max++>\F8AA1E84.x86.dll (*** hidden *** ) @ C:\WINDOWS\ehome\McrdSvc.exe [2740] 0x35670000
Library \\?\globalroot\Device\__max++>\F8AA1E84.x86.dll (*** hidden *** ) @ C:\Program Files\Pure Networks\Network Magic\nmsrvc.exe [2768] 0x35670000
Library \\?\globalroot\Device\__max++>\F8AA1E84.x86.dll (*** hidden *** ) @ C:\WINDOWS\Explorer.EXE [2844] 0x35670000
Library \\?\globalroot\Device\__max++>\F8AA1E84.x86.dll (*** hidden *** ) @ C:\Program Files\DellSupport\DSAgnt.exe [2884] 0x35670000
Library \\?\globalroot\Device\__max++>\F8AA1E84.x86.dll (*** hidden *** ) @ c:\Program Files\Zune\ZuneNss.exe [3352] 0x35670000
Library \\?\globalroot\Device\__max++>\F8AA1E84.x86.dll (*** hidden *** ) @ C:\Program Files\Pure Networks\Network Magic\nmapp.exe [4084] 0x35670000
Library \\?\globalroot\Device\__max++>\F8AA1E84.x86.dll (*** hidden *** ) @ C:\WINDOWS\System32\alg.exe [4092] 0x35670000
Library \\?\globalroot\Device\__max++>\F8AA1E84.x86.dll (*** hidden *** ) @ C:\Program Files\Opera\opera.exe [5284] 0x35670000
Library \\?\globalroot\Device\__max++>\F8AA1E84.x86.dll (*** hidden *** ) @ C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [5848] 0x35670000
Library \\?\globalroot\Device\__max++>\F8AA1E84.x86.dll (*** hidden *** ) @ C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [5964] 0x35670000
Library \\?\globalroot\Device\__max++>\F8AA1E84.x86.dll (*** hidden *** ) @ C:\Program Files\Internet Explorer\iexplore.exe [9160] 0x35670000
Library \\?\globalroot\Device\__max++>\F8AA1E84.x86.dll (*** hidden *** ) @ C:\WINDOWS\system32\HPZinw12.exe [9764] 0x35670000
Library \\?\globalroot\Device\__max++>\F8AA1E84.x86.dll (*** hidden *** ) @ C:\Program Files\Internet Explorer\iexplore.exe [11856] 0x35670000
—- Files - GMER 1.0.15 —-
ADS C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP486\A0091580.sys:1 8192 bytes executable
ADS C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP486\A0091614.sys:1 8192 bytes executable
ADS C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP490\A0092620.sys:1 8192 bytes executable
ADS C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP493\A0092766.sys:1 8192 bytes executable
ADS C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP494\A0092773.sys:1 8192 bytes executable
ADS C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP496\A0093774.sys:1 8192 bytes executable
ADS C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP496\A0094773.sys:1 8192 bytes executable
ADS C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP498\A0094796.sys:1 8192 bytes executable
ADS C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP498\A0095796.sys:1 8192 bytes executable
ADS C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP498\A0096796.sys:1 8192 bytes executable
ADS C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP498\A0097796.sys:1 8192 bytes executable
ADS C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP498\A0098796.sys:1 8192 bytes executable
ADS C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP500\A0099801.sys:1 8192 bytes executable
ADS C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP504\A0099852.sys:1 8192 bytes executable
ADS C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP505\A0100852.sys:1 8192 bytes executable
ADS C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP505\A0101852.sys:1 8192 bytes executable
ADS C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP505\A0102852.sys:1 8192 bytes executable
ADS C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP507\A0103852.sys:1 8192 bytes executable
ADS C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP508\A0103884.sys:1 8192 bytes executable
ADS C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP510\A0103933.sys:1 8192 bytes executable
ADS C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP510\A0103960.sys:1 8192 bytes executable
ADS C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP512\A0104010.sys:1 8192 bytes executable
ADS C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP514\A0104044.sys:1 8192 bytes executable
—- EOF - GMER 1.0.15 —-