This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Unknown Virus Infection

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I am sorry for not posting a HijackThis log but I am unable to due to the nature of my viral infection. I explain below. My ISP has contacted me to inform me about suspicious traffic from my network. I have tried to clean up both my computers myself but have so far been unable to. I have installed AVG Antivirus and ran several scans but they come up clean. I tried to install and run Malwarebytes' Anti-Malware but after installation it runs for the first time and it only gets as far as preparing to scan and then it crashes. When I try to run it again by double clicking on the desktop icon it tells me that "Windows cannot access the specified device, path, or file. You may not have the appropriate permissions to access the item." I get the same error message when I go to the actual .exe file in the program files folder. I have also tried to install and run Spybot - Search & Destroy and got the same results plus the following error. When I tried to reinstall the program, I received the following error message during installation "The existing file is marked as read-only. Click Retry to remove the read-only attribute and try again, Ignore to skip this file, or Abort to cancel installation." Clicking Retry only gets me the same error message over and over, Ignore makes the installation go forward, and Abort just cancels the installation. After clicking Ignore and continuing with the installation I get the following error message when I try to run Spybot SD "Unable to execute file. CreateProcess Failed; Code 5. Access is denied." When I double click on the desktop icon I get the same error message as with Malwarebytes. I have so far not been able to find the actual .exe file that the desktop shortcut points to. Lastly, I tried to install and run HijackThis but after I click on "Do a system scan and save a log file" the program runs for a bit and then crashes. Double clicking the desktop icon gives me the now too familiar error message that I get with Marwarebytes and Spybot SD. I have no idea how to proceed so that I can run HijackThis and give you the logs I am sure you need. Please let me know what I should do. Thanks.
[external image: Posted Image]

Hi, welcome to the WTT Forums. My username is Raktor, and I would be glad to take a look at your log.
Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advice.
This may cause a delay, but I will do my best to keep it as short as possible.

I will be back to you shortly with instructions. :)
[external image: Posted Image]

Hi, welcome to the WTT Forums. My username is Raktor, and I would be glad to help you with your malware issues. I'd be grateful if you would note the following:

  • Absence of symptoms does not always mean the computer is clean
  • Please do not run any scans or fixes without my direction.
  • Finally, stay with this topic until I give you the final 'All clear' post.

If you are a Vista user, please run our tools by Right Clicking on them and selecting Run as Administrator

Note: If a scan fails, try redownloading the program and saving it with a different name, ie. REMG.exe instead of GMER.exe
You can also try safe mode:

  • Restart your computer.
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually.
  • Instead of Windows loading as normal, a menu with options should appear.
  • Select the first option, to run Windows in Safe Mode, then press Enter.
  • Choose your usual account.

If the scan still doesn't work, skip it and go to the next one.


1) DDS
[external image: Posted Image]
Please download DDS and save it to your desktop from here or here or here.
Disable any script blocker, and then double click dds.scr to run the tool.
  • When done, DDS will open two (2) logs:
    • DDS.txt
    • Attach.txt
  • Save both reports to your desktop.

2) GMER
Please download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and put it in your next reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


3) RR
Please download RootRepeal.zip.
Save it to your Desktop. Alternate download links here or here.
Please print these instructions, you will not have an Internet connection!
If you have a 3rd party "unzipping" program…use it to open the zipped file…then skip to Step 5. Otherwise…
  • Right click on RootRepeal.zip and select "Extract All"….
  • Click Next on the "Welcome to the Compressed (zipped) Folders Extraction Wizard."
  • Click on the Browse…button, then click on Desktop, then click OK.
  • Once done, check (tick) the Show extracted files box and click Finish.
  • Before running RootRepeal:
    • Disconnect from the Internet as your system will be unprotected while using this tool.
      Close all programs and temporarily disable your anti-virus, Firewall and any anti-malware real-time protection before performing a scan.
  • Open the RootRepeal folder and double-click on RootRepeal.exe to launch it.
  • When the program opens, click the Report tab at the bottom, then click the Scan button.
  • In the Select Scan, dialog which asks What do you want to include in the scan?, check ALL the boxes.
    🖼Click to load external image (Posted Image)
  • Click OK.
  • In the Select Drives, dialog Please select drives to scan: select all drives showing, then click OK.
    The scan can take some time to finish. Do not use the computer while the scan is running.
    When the scan has completed, a list of files will be generated in the RootRepeal window.
  • Click on the Save Report button and save it as "rootrepeal.txt" to your desktop.
  • Close and exit RootRepeal
  • Double-click on the file rootrepeal.txt… Notepad will open… copy/paste the file contents in your next reply.

Make sure to enable your anti-virus, Firewall and any other security programs you disabled.
Note: If RootRepeal cannot complete a scan and results in a crash report, try repeating the scan in "safe mode".

4) Batch File
Launch Notepad, and copy/paste everything in the codebox below into the new document. Go up to "File Save As" and click the drop-down box to change the "Save As Type" to "All Files" and save it to your desktop as runme.bat.

@ECHO OFF
DIR /a/s C:\WINDOWS\scecli.dll C:\WINDOWS\sceclt.dll C:\WINDOWS\netlogon.dll C:\WINDOWS\ntelogon.dll >Log.txt
START Log.txt
DEL /Q %0

Locate runme.bat on your Desktop and double-click on it. Post the contents of Log.txt.

5) What You Will Need To Post:
  • DDS logs
  • GMER log
  • RR log
  • Log.txt
Sorry for the delayed reply. I have had a busy weekend.

I was unable to run RootRepeal. It says it is initializing and to wait but I let it run a full 12 hours and it never moved forward from there. I tried to run it in safe mode but my computer will not run in safe mode. Each time I try to start in safe mode my computer crashes and I get a blue screen error that says windows was unable to start.

I saved the runme.bat file to my desktop but when I double click it it only opens that same text file with Notepad and nothing else happens.

Following are the two logs I was able to get from DDS and Gmer. I have also attached the second log from DDS just in case you may need it.

Thanks.


DDS (Ver_09-07-30.01) - NTFSx86
Run by [removed] at 15:17:24.50 on Sun 08/23/2009
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.282 [GMT -6:00]

AV: AVG Anti-Virus *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: *disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe
svchost.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\PROGRA~1\AVG\AVG8\avgam.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\WINDOWS\ehome\RMSvc.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
svchost.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
c:\WINDOWS\system32\ZuneBusEnum.exe
C:\Program Files\Pure Networks\Network Magic\nmsrvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Pure Networks\Network Magic\nmapp.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Logitech\QuickCam10\QuickCam10.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\Zune\ZuneLauncher.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\LVComSX.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\Program Files\BitComet\BitComet.exe
C:\WINDOWS\system32\HPZinw12.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Opera\opera.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Documents and Settings\TEMP\Desktop\dds.com

============== Pseudo HJT Report ===============

uSearch Page = hxxp://www.google.com/hws/sb/dell-usuk/en/side.html?channel=us
uSearch Bar = hxxp://www.google.com/hws/sb/dell-usuk/en/side.html?channel=us
uDefault_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=1060915
uInternet Settings,ProxyOverride = *.local
mSearchAssistant = hxxp://www.google.com/ie
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\progra~1\yahoo!\companion\installs\cpn\yt.dll
uURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg8\toolbar\IEToolbar.dll
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\progra~1\yahoo!\companion\installs\cpn\yt.dll
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: BitComet Helper: {39f7e362-828a-4b5a-bcaf-5b79bfdfea60} - c:\program files\bitcomet\tools\BitCometBHO_1.3.3.2.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\program files\spybot - search & destroy\SDHelper.dll
BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\tfswshx.dll
BHO: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg8\toolbar\IEToolbar.dll
BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\bae\BAE.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\progra~1\yahoo!\companion\installs\cpn\YTSingleInstance.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\progra~1\yahoo!\companion\installs\cpn\yt.dll
TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - c:\program files\avg\avg8\toolbar\IEToolbar.dll
EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll
uRun: [DellSupport] "c:\program files\dellsupport\DSAgnt.exe" /startup
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [H/PC Connection Agent] "c:\program files\microsoft activesync\wcescomm.exe"
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
mRun: [ehTray] c:\windows\ehome\ehtray.exe
mRun: [igfxtray] c:\windows\system32\igfxtray.exe
mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe
mRun: [igfxpers] c:\windows\system32\igfxpers.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [Broadcom Wireless Manager UI] c:\windows\system32\WLTRAY.exe
mRun: [SigmatelSysTrayApp] stsystra.exe
mRun: [DVDLauncher] "c:\program files\cyberlink\powerdvd\DVDLauncher.exe"
mRun: [ISUSPM Startup] "c:\program files\common files\installshield\updateservice\isuspm.exe" -startup
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: []
mRun: [dla] c:\windows\system32\dla\tfswctrl.exe
mRun: [MSKDetectorExe] c:\program files\mcafee\spamkiller\MSKDetct.exe /uninstall
mRun: [nmapp] "c:\program files\pure networks\network magic\nmapp.exe" -autorun -nosplash
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [LogitechQuickCamRibbon] "c:\program files\logitech\quickcam10\QuickCam10.exe" /hide
mRun: [LogitechCommunicationsManager] "c:\program files\common files\logishrd\lcommgr\Communications_Helper.exe"
mRun: [Zune Launcher] "c:\program files\zune\ZuneLauncher.exe"
mRun: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
mRun: [dscactivate] "c:\program files\dell support center\gs_agent\custom\dsca.exe"
mRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe
mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\extend~1.lnk - c:\windows\ehome\RMSysTry.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpphot~1.lnk - c:\program files\hp\digital imaging\bin\hpqthb08.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\logite~1.lnk - c:\program files\logitech\desktop messenger\8876480\program\LogitechDesktopMessenger.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\servic~1.lnk - c:\program files\microsoft sql server\80\tools\binn\sqlmangr.exe
uPolicies-system: EnableProfileQuota = 1 (0x1)
IE: &D&ownload &with BitComet - c:\program files\bitcomet\BitComet.exe/AddLink.htm
IE: &D&ownload all video with BitComet - c:\program files\bitcomet\BitComet.exe/AddVideo.htm
IE: &D&ownload all with BitComet - c:\program files\bitcomet\BitComet.exe/AddAllLink.htm
IE: E&xport to Microsoft Excel - c:\progra~1\mi1933~1\office11\EXCEL.EXE/3000
IE: {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://c:\program files\bitcomet\tools\BitCometBHO_1.3.3.2.dll/206
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\mi3aa1~1\INetRepl.dll
IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\mi3aa1~1\INetRepl.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\mi1933~1\office11\REFIEBAR.DLL
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll
Trusted Zone: musicmatch.com\online
DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - hxxp://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {ED28050F-D713-43BA-A376-DCC5C35407D5} - hxxp://entimg.msn.com/client/msnmusax4929.cab
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\logitech\desktop messenger\8876480\program\GAPlugProtocol-8876480.dll
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
Handler: pure-go - {4746C79A-2042-4332-8650-48966E44ABA8} - c:\program files\common files\pure networks shared\puresp3.dll
Notify: avgrsstarter - avgrsstx.dll
Notify: igfxcui - igfxdev.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

============= SERVICES / DRIVERS ===============

R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [2009-8-2 12552]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-8-2 335240]
R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2009-8-2 27784]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-8-2 108552]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2009-8-2 297752]
R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\McrdSvc.exe [2005-10-20 96256]
R3 ndisrd;WinpkFilter Service;c:\windows\system32\drivers\ndisrd.sys [2009-6-23 20480]
S2 srenum;srenum;c:\windows\system32\drivers\srenum.sys –> c:\windows\system32\drivers\srenum.sys [?]
S3 adxapie;adxapie;c:\docume~1\eddie\locals~1\temp\adxapie.sys [2005-3-29 15872]
S3 JL2005C;Dual Mode Camera;c:\windows\system32\drivers\jl2005c.sys [2007-1-26 68954]

=============== Created Last 30 ================

2009-08-18 22:45 –d—– c:\program files\Trend Micro
2009-08-18 19:48 410,984 a——- c:\windows\system32\deploytk.dll
2009-08-15 14:03 1,089,593 ——– c:\windows\system32\dllcache\ntprint.cat
2009-08-15 03:34 –d—– c:\windows\system32\XPSViewer
2009-08-15 03:30 117,760 ——– c:\windows\system32\prntvpt.dll
2009-08-15 03:30 89,088 ——– c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-08-15 03:30 597,504 ——– c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-08-15 03:30 575,488 ——– c:\windows\system32\xpsshhdr.dll
2009-08-15 03:30 575,488 ——– c:\windows\system32\dllcache\xpsshhdr.dll
2009-08-15 03:29 1,676,288 ——– c:\windows\system32\xpssvcs.dll
2009-08-15 03:29 1,676,288 ——– c:\windows\system32\dllcache\xpssvcs.dll
2009-08-15 03:26 –d—– c:\windows\SxsCaPendDel
2009-08-12 00:26 128,512 ——– c:\windows\system32\dllcache\dhtmled.ocx
2009-08-12 00:25 1,315,328 ——– c:\windows\system32\dllcache\msoe.dll
2009-08-07 10:04 –d-h— c:\windows\PIF
2009-08-07 10:02 38,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-07 10:02 19,096 a——- c:\windows\system32\drivers\mbam.sys
2009-08-07 10:02 –d—– c:\program files\Malwarebytes' Anti-Malware
2009-08-05 03:01 204,800 ——– c:\windows\system32\dllcache\mswebdvd.dll
2009-08-02 22:23 221 a——- c:\windows\NCLogConfig.ini
2009-08-02 19:37 –d-h— C:\$AVG8.VAULT$
2009-08-02 18:49 11,952 a——- c:\windows\system32\avgrsstx.dll
2009-08-02 18:49 108,552 a——- c:\windows\system32\drivers\avgtdix.sys
2009-08-02 18:49 12,552 a——- c:\windows\system32\drivers\avgrkx86.sys
2009-08-02 18:49 335,240 a——- c:\windows\system32\drivers\avgldx86.sys
2009-08-02 18:49 –d—– c:\windows\system32\drivers\Avg
2009-08-02 18:49 –d—– c:\docume~1\alluse~1\applic~1\AVG Security Toolbar
2009-08-02 18:48 –d—– c:\program files\AVG
2009-08-02 18:48 –d—– c:\docume~1\alluse~1\applic~1\avg8
2009-08-02 18:22 –d—– c:\docume~1\temp\applic~1\AVG8
2009-08-02 17:42 –d—– c:\docume~1\temp\applic~1\Malwarebytes
2009-08-02 17:42 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-07-31 10:09 –d—– c:\program files\sFX
2009-07-30 13:19 568 a——- c:\windows\system32\msexcr.ini
2009-07-27 22:32 –d—– c:\program files\Microsoft WSE
2009-07-26 16:21 –d—– c:\program files\CDisplay

==================== Find3M ====================

2009-08-22 23:37 3,558 a–sh— c:\windows\system32\KGyGaAvL.sys
2009-08-05 03:01 204,800 a——- c:\windows\system32\mswebdvd.dll
2009-07-22 19:57 43,008 a——- C:\mavj.exe
2009-07-19 18:48 11,067,392 ——– c:\windows\system32\dllcache\ieframe.dll
2009-07-19 07:18 5,937,152 ——– c:\windows\system32\dllcache\mshtml.dll
2009-07-17 13:01 58,880 a——- c:\windows\system32\atl.dll
2009-07-17 13:01 58,880 ——– c:\windows\system32\dllcache\atl.dll
2009-07-13 23:43 286,208 a——- c:\windows\system32\wmpdxm.dll
2009-07-13 23:43 10,841,088 ——– c:\windows\system32\dllcache\wmp.dll
2009-07-13 23:43 286,208 ——– c:\windows\system32\dllcache\wmpdxm.dll
2009-07-03 11:09 915,456 a——- c:\windows\system32\wininet.dll
2009-07-03 11:09 915,456 ——– c:\windows\system32\dllcache\wininet.dll
2009-07-03 11:09 12,800 ——– c:\windows\system32\dllcache\xpshims.dll
2009-07-03 11:09 206,848 a——- c:\windows\system32\dllcache\occache.dll
2009-07-03 11:09 1,208,832 ——– c:\windows\system32\dllcache\urlmon.dll
2009-07-03 11:09 594,432 a——- c:\windows\system32\dllcache\msfeeds.dll
2009-07-03 11:09 55,296 a——- c:\windows\system32\dllcache\msfeedsbs.dll
2009-07-03 11:09 1,985,536 ——– c:\windows\system32\dllcache\iertutil.dll
2009-07-03 11:09 25,600 ——– c:\windows\system32\dllcache\jsproxy.dll
2009-07-03 11:09 184,320 a——- c:\windows\system32\dllcache\iepeers.dll
2009-07-03 11:09 246,272 ——– c:\windows\system32\dllcache\ieproxy.dll
2009-07-03 11:09 386,048 ——– c:\windows\system32\dllcache\iedkcs32.dll
2009-07-03 05:01 173,056 ——– c:\windows\system32\dllcache\ie4uinit.exe
2009-06-16 08:36 119,808 a——- c:\windows\system32\t2embed.dll
2009-06-16 08:36 81,920 a——- c:\windows\system32\fontsub.dll
2009-06-16 08:36 119,808 ——– c:\windows\system32\dllcache\t2embed.dll
2009-06-16 08:36 81,920 ——– c:\windows\system32\dllcache\fontsub.dll
2009-06-12 06:31 80,896 a——- c:\windows\system32\tlntsess.exe
2009-06-12 06:31 80,896 ——– c:\windows\system32\dllcache\tlntsess.exe
2009-06-12 06:31 76,288 a——- c:\windows\system32\telnet.exe
2009-06-12 06:31 76,288 ——– c:\windows\system32\dllcache\telnet.exe
2009-06-10 09:19 2,066,432 a——- c:\windows\system32\mstscax.dll
2009-06-10 09:19 2,066,432 ——– c:\windows\system32\dllcache\mstscax.dll
2009-06-10 08:13 84,992 a——- c:\windows\system32\avifil32.dll
2009-06-10 08:13 84,992 ——– c:\windows\system32\dllcache\avifil32.dll
2009-06-10 00:14 132,096 a——- c:\windows\system32\wkssvc.dll
2009-06-10 00:14 132,096 ——– c:\windows\system32\dllcache\wkssvc.dll
2009-06-05 11:42 2,060,288 a——- c:\windows\system32\usbaaplrc.dll
2009-06-03 13:09 1,291,264 a——- c:\windows\system32\quartz.dll
2009-06-03 13:09 1,291,264 ——– c:\windows\system32\dllcache\quartz.dll
2009-06-02 04:12 102,912 ——– c:\windows\system32\dllcache\iecompat.dll
2009-05-28 20:46 117,092 ac—— c:\windows\hpoins11.dat
2008-09-20 03:08 32,768 ac-sh— c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008092020080921\index.dat

============= FINISH: 15:18:26.41 ===============




GMER 1.0.15.15077 [gmer.exe] - http://www.gmer.net
Rootkit scan 2009-08-23 22:15:52
Windows 5.1.2600 Service Pack 3


—- Devices - GMER 1.0.15 —-

AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

Device \FileSystem\Fastfat \Fat A7B34D20

AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

Device \FileSystem\Cdfs \Cdfs tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
—- Processes - GMER 1.0.15 —-

Library \\?\globalroot\Device\__max++>\F8AA1E84.x86.dll (*** hidden *** ) @ C:\WINDOWS\system32\svchost.exe [224] 0x35670000
Library \\?\globalroot\Device\__max++>\F8AA1E84.x86.dll (*** hidden *** ) @ C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [308] 0x35670000
Library \\?\globalroot\Device\__max++>\F8AA1E84.x86.dll (*** hidden *** ) @ C:\Program Files\Bonjour\mDNSResponder.exe [492] 0x35670000
Library \\?\globalroot\Device\__max++>\F8AA1E84.x86.dll (*** hidden *** ) @ C:\WINDOWS\eHome\ehSched.exe [744] 0x35670000
Library \\?\globalroot\Device\__max++>\F8AA1E84.x86.dll (*** hidden *** ) @ C:\Program Files\Java\jre6\bin\jqs.exe [916] 0x35670000
Library \\?\globalroot\Device\__max++>\F8AA1E84.x86.dll (*** hidden *** ) @ C:\PROGRA~1\AVG\AVG8\avgnsx.exe [1228] 0x35670000
Library \\?\globalroot\Device\__max++>\F8AA1E84.x86.dll (*** hidden *** ) @ C:\WINDOWS\system32\svchost.exe [1264] 0x35670000
Library \\?\globalroot\Device\__max++>\F8AA1E84.x86.dll (*** hidden *** ) @ C:\Program Files\Microsoft ActiveSync\wcescomm.exe [1288] 0x35670000
Library \\?\globalroot\Device\__max++>\F8AA1E84.x86.dll (*** hidden *** ) @ C:\WINDOWS\System32\svchost.exe [1304] 0x35670000
Library \\?\globalroot\Device\__max++>\F8AA1E84.x86.dll (*** hidden *** ) @ C:\WINDOWS\system32\svchost.exe [1412] 0x35670000
Library \\?\globalroot\Device\__max++>\F8AA1E84.x86.dll (*** hidden *** ) @ C:\WINDOWS\system32\svchost.exe [1576] 0x35670000
Library \\?\globalroot\Device\__max++>\F8AA1E84.x86.dll (*** hidden *** ) @ C:\WINDOWS\system32\spoolsv.exe [1844] 0x35670000
Library \\?\globalroot\Device\__max++>\F8AA1E84.x86.dll (*** hidden *** ) @ C:\Program Files\iTunes\iTunesHelper.exe [2140] 0x35670000
Library \\?\globalroot\Device\__max++>\F8AA1E84.x86.dll (*** hidden *** ) @ C:\Program Files\Dell Support Center\bin\sprtcmd.exe [2256] 0x35670000
Library \\?\globalroot\Device\__max++>\F8AA1E84.x86.dll (*** hidden *** ) @ C:\Program Files\Dell Support Center\bin\sprtsvc.exe [2320] 0x35670000
Library \\?\globalroot\Device\__max++>\F8AA1E84.x86.dll (*** hidden *** ) @ C:\WINDOWS\system32\svchost.exe [2384] 0x35670000
Library \\?\globalroot\Device\__max++>\F8AA1E84.x86.dll (*** hidden *** ) @ c:\WINDOWS\system32\ZuneBusEnum.exe [2480] 0x35670000
Library \\?\globalroot\Device\__max++>\F8AA1E84.x86.dll (*** hidden *** ) @ C:\WINDOWS\ehome\McrdSvc.exe [2740] 0x35670000
Library \\?\globalroot\Device\__max++>\F8AA1E84.x86.dll (*** hidden *** ) @ C:\Program Files\Pure Networks\Network Magic\nmsrvc.exe [2768] 0x35670000
Library \\?\globalroot\Device\__max++>\F8AA1E84.x86.dll (*** hidden *** ) @ C:\WINDOWS\Explorer.EXE [2844] 0x35670000
Library \\?\globalroot\Device\__max++>\F8AA1E84.x86.dll (*** hidden *** ) @ C:\Program Files\DellSupport\DSAgnt.exe [2884] 0x35670000
Library \\?\globalroot\Device\__max++>\F8AA1E84.x86.dll (*** hidden *** ) @ c:\Program Files\Zune\ZuneNss.exe [3352] 0x35670000
Library \\?\globalroot\Device\__max++>\F8AA1E84.x86.dll (*** hidden *** ) @ C:\Program Files\Pure Networks\Network Magic\nmapp.exe [4084] 0x35670000
Library \\?\globalroot\Device\__max++>\F8AA1E84.x86.dll (*** hidden *** ) @ C:\WINDOWS\System32\alg.exe [4092] 0x35670000
Library \\?\globalroot\Device\__max++>\F8AA1E84.x86.dll (*** hidden *** ) @ C:\Program Files\Opera\opera.exe [5284] 0x35670000
Library \\?\globalroot\Device\__max++>\F8AA1E84.x86.dll (*** hidden *** ) @ C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [5848] 0x35670000
Library \\?\globalroot\Device\__max++>\F8AA1E84.x86.dll (*** hidden *** ) @ C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [5964] 0x35670000
Library \\?\globalroot\Device\__max++>\F8AA1E84.x86.dll (*** hidden *** ) @ C:\Program Files\Internet Explorer\iexplore.exe [9160] 0x35670000
Library \\?\globalroot\Device\__max++>\F8AA1E84.x86.dll (*** hidden *** ) @ C:\WINDOWS\system32\HPZinw12.exe [9764] 0x35670000
Library \\?\globalroot\Device\__max++>\F8AA1E84.x86.dll (*** hidden *** ) @ C:\Program Files\Internet Explorer\iexplore.exe [11856] 0x35670000

—- Files - GMER 1.0.15 —-

ADS C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP486\A0091580.sys:1 8192 bytes executable
ADS C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP486\A0091614.sys:1 8192 bytes executable
ADS C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP490\A0092620.sys:1 8192 bytes executable
ADS C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP493\A0092766.sys:1 8192 bytes executable
ADS C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP494\A0092773.sys:1 8192 bytes executable
ADS C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP496\A0093774.sys:1 8192 bytes executable
ADS C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP496\A0094773.sys:1 8192 bytes executable
ADS C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP498\A0094796.sys:1 8192 bytes executable
ADS C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP498\A0095796.sys:1 8192 bytes executable
ADS C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP498\A0096796.sys:1 8192 bytes executable
ADS C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP498\A0097796.sys:1 8192 bytes executable
ADS C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP498\A0098796.sys:1 8192 bytes executable
ADS C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP500\A0099801.sys:1 8192 bytes executable
ADS C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP504\A0099852.sys:1 8192 bytes executable
ADS C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP505\A0100852.sys:1 8192 bytes executable
ADS C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP505\A0101852.sys:1 8192 bytes executable
ADS C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP505\A0102852.sys:1 8192 bytes executable
ADS C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP507\A0103852.sys:1 8192 bytes executable
ADS C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP508\A0103884.sys:1 8192 bytes executable
ADS C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP510\A0103933.sys:1 8192 bytes executable
ADS C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP510\A0103960.sys:1 8192 bytes executable
ADS C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP512\A0104010.sys:1 8192 bytes executable
ADS C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP514\A0104044.sys:1 8192 bytes executable

—- EOF - GMER 1.0.15 —-

Attachments:

robgil,

Please download ad13's win32ksys to your desktop
  • Double click to run it
  • A black window will appear, let this run
  • On completion a log will appear on your desktop called Win32kDiag.txt please post this in your next reply.
Here is the requested log. Log file is located at: C:\Documents and Settings\TEMP\Desktop\Win32kDiag.txt WARNING: Could not get backup privileges! Searching 'C:\WINDOWS'… Cannot access: C:\WINDOWS\system32\dumprep.exe [1] 2004-08-10 04:00:00 10752 C:\WINDOWS\$NtServicePackUninstall$\dumprep.exe (Microsoft Corporation) [1] 2008-04-13 18:12:18 10752 C:\WINDOWS\ServicePackFiles\i386\dumprep.exe (Microsoft Corporation) [1] 2008-04-13 18:12:18 10752 C:\WINDOWS\system32\dumprep.exe () [1] 2004-08-10 04:00:00 10752 C:\i386\dumprep.exe (Microsoft Corporation) Cannot access: C:\WINDOWS\system32\MRT.exe [1] 2009-07-29 18:49:14 24281536 C:\WINDOWS\system32\MRT.exe () [2] 2009-06-01 10:51:12 23635392 C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP471\A0080975.exe (Microsoft Corporation) [2] 2009-07-07 09:10:56 24539592 C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP472\A0082175.exe (Microsoft Corporation) [2] 2009-06-01 10:51:12 23635392 C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP473\A0082742.exe (Microsoft Corporation) [2] 2009-07-07 09:10:56 24539592 C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP493\A0092709.exe (Microsoft Corporation) [1] 2006-10-04 13:03:46 9639336 C:\i386\MRT.exe (Microsoft Corporation) Cannot access: C:\WINDOWS\system32\scecli.dll [1] 2004-08-10 04:00:00 180224 C:\WINDOWS\$NtServicePackUninstall$\scecli.dll (Microsoft Corporation) [1] 2008-04-13 18:12:05 181248 C:\WINDOWS\ServicePackFiles\i386\scecli.dll (Microsoft Corporation) [1] 2008-04-13 18:12:05 60928 C:\WINDOWS\system32\scecli.dll () [2] 2008-04-13 18:12:05 181248 C:\WINDOWS\system32\sceclt.dll (Microsoft Corporation) [1] 2004-08-10 04:00:00 180224 C:\i386\scecli.dll (Microsoft Corporation) Cannot access: C:\WINDOWS\system32\wbem\SET25BD.tmp [1] 2009-02-06 04:10:02 227840 C:\WINDOWS\system32\wbem\SET25BD.tmp () Cannot access: C:\WINDOWS\system32\wbem\wmiprvse.exe [1] 2009-02-06 04:15:13 227840 C:\WINDOWS\$hf_mig$\KB956572\SP3QFE\wmiprvse.exe (Microsoft Corporation) [1] 2004-08-10 04:00:00 218112 C:\WINDOWS\$NtServicePackUninstall$\wmiprvse.exe (Microsoft Corporation) [1] 2008-04-13 18:12:40 218112 C:\WINDOWS\$NtUninstallKB956572$\wmiprvse.exe (Microsoft Corporation) [1] 2008-04-13 18:12:40 218112 C:\WINDOWS\ServicePackFiles\i386\wmiprvse.exe (Microsoft Corporation) [1] 2009-02-06 10:39:29 227840 C:\WINDOWS\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP2GDR\wmiprvse.exe (Microsoft Corporation) [1] 2009-02-06 03:41:05 227840 C:\WINDOWS\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP2QFE\wmiprvse.exe (Microsoft Corporation) [1] 2009-02-06 04:10:02 227840 C:\WINDOWS\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP3GDR\wmiprvse.exe (Microsoft Corporation) [1] 2009-02-06 04:15:13 227840 C:\WINDOWS\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP3QFE\wmiprvse.exe (Microsoft Corporation) [1] 2009-02-06 04:10:02 227840 C:\WINDOWS\system32\dllcache\wmiprvse.exe (Microsoft Corporation) [1] 2009-02-06 04:10:02 227840 C:\WINDOWS\system32\wbem\wmiprvse.exe () [1] 2004-08-10 04:00:00 218112 C:\i386\wmiprvse.exe (Microsoft Corporation) Finished!
Please read through the instructions to familiarize yourself with what to expect when the tool runs.

Please download Combofix from either of the links below, and save it to your desktop.
You must rename it before saving it. Save it as Combo-Fix.exe.

[external image: Posted Image]

Link 1
Link 2

**Note: It is important that it is saved directly to your desktop**

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link:How to Disable your Security Programs
  • Double click on Combo-Fix.exe & follow the prompts. Close all browsers/windows first.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Here is the requested log.
ComboFix 09-09-02.02 - Gilbert 09/02/2009 19:07.1.2 - NTFSx86
Running from: c:\documents and settings\[removed]\Desktop\Combo-Fix.exe
AV: AVG Anti-Virus *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: *disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\driver
c:\program files\sFX
c:\windows\Installer\51b1509.msp
c:\windows\kb913800.exe
c:\windows\prxid93ps.dat
c:\windows\system32\drivers\ndisrd.sys
c:\windows\th823567.dat

Infected copy of c:\windows\system32\scecli.dll was found and disinfected
Restored copy from - c:\windows\system32\sceclt.dll

c:\windows\system32\proquota.exe . . . is missing!!

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_DRIVER
——-\Legacy_DRIVERDRV
——-\Legacy_SFX
——-\Legacy_SFXDRV
——-\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226ED}
——-\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226EE}
——-\Service_ndisrd
——-\Service_SfX


((((((((((((((((((((((((( Files Created from 2009-08-03 to 2009-09-03 )))))))))))))))))))))))))))))))
.

2009-08-25 01:07 . 2006-12-15 05:36 936864 —-a-r- c:\windows\system32\drivers\LV302V32.SYS
2009-08-22 20:13 . 2009-08-22 20:13 ——– d—–w- c:\documents and settings\Eddie\Local Settings\Application Data\Opera
2009-08-22 19:30 . 2009-08-22 19:30 ——– d—–w- c:\documents and settings\Eddie\Local Settings\Application Data\Apple
2009-08-19 04:45 . 2009-08-19 04:45 ——– d—–w- c:\program files\Trend Micro
2009-08-19 01:48 . 2009-08-19 01:47 410984 —-a-w- c:\windows\system32\deploytk.dll
2009-08-15 09:36 . 2009-08-15 09:36 ——– d-sh–w- c:\documents and settings\Default User\IETldCache
2009-08-15 09:34 . 2009-08-15 09:34 ——– d—–w- c:\windows\system32\XPSViewer
2009-08-15 09:33 . 2009-08-15 09:33 ——– d—–w- c:\program files\MSBuild
2009-08-15 09:33 . 2009-08-15 09:33 ——– d—–w- c:\program files\Reference Assemblies
2009-08-15 09:30 . 2008-07-06 12:06 89088 ——w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-08-15 09:30 . 2008-07-06 12:06 117760 ——w- c:\windows\system32\prntvpt.dll
2009-08-15 09:30 . 2008-07-06 10:50 597504 ——w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-08-15 09:30 . 2008-07-06 12:06 575488 ——w- c:\windows\system32\xpsshhdr.dll
2009-08-15 09:30 . 2008-07-06 12:06 575488 ——w- c:\windows\system32\dllcache\xpsshhdr.dll
2009-08-15 09:29 . 2008-07-06 12:06 1676288 ——w- c:\windows\system32\xpssvcs.dll
2009-08-15 09:29 . 2008-07-06 12:06 1676288 ——w- c:\windows\system32\dllcache\xpssvcs.dll
2009-08-15 09:26 . 2009-08-16 04:28 ——– d—–w- c:\windows\SxsCaPendDel
2009-08-12 06:25 . 2009-07-10 13:27 1315328 ——w- c:\windows\system32\dllcache\msoe.dll
2009-08-07 16:04 . 2009-08-07 16:04 ——– d–h–w- c:\windows\PIF
2009-08-07 16:02 . 2009-08-03 19:36 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-07 16:02 . 2009-08-19 04:20 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-08-07 16:02 . 2009-08-03 19:36 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-08-05 09:01 . 2009-08-05 09:01 204800 ——w- c:\windows\system32\dllcache\mswebdvd.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-03 00:47 . 2009-08-03 00:48 ——– d—–w- c:\documents and settings\All Users\Application Data\avg8
2009-09-02 09:03 . 2009-06-18 01:55 ——– d—–w- c:\program files\BitComet
2009-08-30 21:10 . 2008-10-20 03:14 ——– d—–w- c:\documents and settings\TEMP\Application Data\OpenOffice.org2
2009-08-23 05:37 . 2007-05-25 03:40 3558 –sha-w- c:\windows\system32\KGyGaAvL.sys
2009-08-23 05:37 . 2007-05-25 03:40 88 –sh–r- c:\windows\system32\9CAC2A3D1C.sys
2009-08-22 20:04 . 2009-01-21 07:11 ——– d—–w- c:\documents and settings\Eddie\Application Data\Apple Computer
2009-08-21 04:32 . 2008-01-04 04:18 ——– d—–w- c:\documents and settings\Nora\Application Data\OpenOffice.org2
2009-08-21 03:01 . 2007-05-25 00:18 80808 —-a-w- c:\documents and settings\Nora\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-20 04:25 . 2009-06-20 04:32 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-08-19 04:36 . 2009-06-20 04:32 ——– d—–w- c:\program files\Spybot - Search & Destroy
2009-08-19 01:47 . 2006-09-15 21:28 ——– d—–w- c:\program files\Java
2009-08-18 19:32 . 2007-06-01 18:30 80808 —-a-w- c:\documents and settings\Eddie\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-16 04:31 . 2008-08-17 16:13 80808 —-a-w- c:\documents and settings\TEMP\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-13 22:48 . 2009-08-03 00:49 ——– d—–w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2009-08-13 21:45 . 2009-01-15 02:28 ——– d—–w- c:\program files\Warcraft III
2009-08-10 16:31 . 2006-09-15 21:48 ——– d—–w- c:\program files\Google
2009-08-07 14:42 . 2006-09-15 21:36 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-08-05 09:01 . 2005-08-16 09:18 204800 —-a-w- c:\windows\system32\mswebdvd.dll
2009-08-03 19:22 . 2009-08-03 19:22 ——– d—–w- c:\documents and settings\Eddie\Application Data\Malwarebytes
2009-08-03 04:23 . 2008-08-17 16:16 ——– d—–w- c:\documents and settings\TEMP\Application Data\HP
2009-08-03 02:22 . 2005-08-17 01:54 ——– d—–w- c:\program files\DIGStream
2009-08-03 00:49 . 2009-08-03 00:49 11952 —-a-w- c:\windows\system32\avgrsstx.dll
2009-08-03 00:49 . 2009-08-03 00:49 12552 —-a-w- c:\windows\system32\drivers\avgrkx86.sys
2009-08-03 00:49 . 2009-08-03 00:49 108552 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2009-08-03 00:49 . 2009-08-03 00:49 335240 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2009-08-03 00:49 . 2009-08-03 00:49 27784 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-08-03 00:48 . 2009-08-03 00:48 ——– d—–w- c:\program files\AVG
2009-08-03 00:22 . 2009-08-03 00:22 ——– d—–w- c:\documents and settings\TEMP\Application Data\AVG8
2009-08-02 23:42 . 2009-08-02 23:42 ——– d—–w- c:\documents and settings\TEMP\Application Data\Malwarebytes
2009-08-02 23:42 . 2009-08-02 23:42 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-07-28 04:32 . 2009-07-28 04:32 ——– d—–w- c:\program files\Microsoft WSE
2009-07-26 22:21 . 2009-07-26 22:21 ——– d—–w- c:\program files\CDisplay
2009-07-23 01:57 . 2009-07-23 01:57 43008 —-a-w- C:\mavj.exe
2009-07-17 19:01 . 2005-08-16 09:18 58880 —-a-w- c:\windows\system32\atl.dll
2009-07-15 04:19 . 2009-07-15 04:19 ——– d—–w- c:\documents and settings\TEMP\Application Data\Corel Photo Album
2009-07-15 04:03 . 2009-07-15 04:03 ——– d—–w- c:\program files\Datel
2009-07-14 05:43 . 2005-08-16 09:19 286208 —-a-w- c:\windows\system32\wmpdxm.dll
2009-07-03 17:09 . 2005-08-16 09:18 915456 —-a-w- c:\windows\system32\wininet.dll
2009-06-16 14:36 . 2005-08-16 09:18 119808 —-a-w- c:\windows\system32\t2embed.dll
2009-06-16 14:36 . 2005-08-16 09:18 81920 —-a-w- c:\windows\system32\fontsub.dll
2009-06-12 12:31 . 2005-08-16 09:18 80896 —-a-w- c:\windows\system32\tlntsess.exe
2009-06-12 12:31 . 2005-08-16 09:18 76288 —-a-w- c:\windows\system32\telnet.exe
2009-06-10 15:19 . 2005-08-16 09:37 2066432 —-a-w- c:\windows\system32\mstscax.dll
2009-06-10 14:13 . 2005-08-16 09:18 84992 —-a-w- c:\windows\system32\avifil32.dll
2009-06-10 06:14 . 2005-08-16 09:18 132096 —-a-w- c:\windows\system32\wkssvc.dll
2009-06-05 17:42 . 2009-03-13 18:50 2060288 —-a-w- c:\windows\system32\usbaaplrc.dll
2009-06-05 17:42 . 2008-12-27 04:18 39424 —-a-w- c:\windows\system32\drivers\usbaapl.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-07-24 1062144]

[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-07-24 15:56 1062144 —-a-w- c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-07-24 1062144]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-07-24 1062144]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\wcescomm.exe" [2006-06-21 1207080]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-14 206064]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UserFaultCheck"="c:\windows\system32\dumprep 0 -u" [X]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-29 67584]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-12-13 98304]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-12-13 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-12-13 118784]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-08 761947]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2005-12-19 1347584]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-12-10 49152]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 249856]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2005-05-31 122941]
"MSKDetectorExe"="c:\program files\McAfee\SpamKiller\MSKDetct.exe" [2005-07-13 1117184]
"nmapp"="c:\program files\Pure Networks\Network Magic\nmapp.exe" [2006-11-01 321088]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 49152]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-08-19 148888]
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam10\QuickCam10.exe" [2006-12-22 756248]
"LogitechCommunicationsManager"="c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2006-12-22 497176]
"Zune Launcher"="c:\program files\Zune\ZuneLauncher.exe" [2008-01-12 166304]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-14 206064]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-05-26 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-06-05 292136]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-08-12 2007832]
"SigmatelSysTrayApp"="stsystra.exe" - c:\windows\stsystra.exe [2006-03-24 282624]

c:\documents and settings\Nora\Start Menu\Programs\Startup\
OpenOffice.org 2.3.lnk - c:\program files\OpenOffice.org 2.3\program\quickstart.exe [2007-8-17 393216]

c:\documents and settings\Gilbert\Start Menu\Programs\Startup\
OpenOffice.org 2.3.lnk - c:\program files\OpenOffice.org 2.3\program\quickstart.exe [2007-8-17 393216]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2006-9-15 24576]
Extender Resource Monitor.lnk - c:\windows\ehome\RMSysTry.exe [2005-10-20 18432]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2006-2-19 288472]
HP Photosmart Premier Fast Start.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2006-2-10 73728]
Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2007-11-20 67128]
Service Manager.lnk - c:\program files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe [2005-5-3 81920]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-08-03 00:49 11952 —-a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\SecondLife\\SecondLife.exe"=
"c:\\Program Files\\America Online 9.0\\waol.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\Warcraft III\\Warcraft III.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Program Files\\BitComet\\BitComet.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgam.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgdiag.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgdiagex.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"67:UDP"= 67:UDP:DHCP Discovery Service
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"3776:UDP"= 3776:UDP:Media Center Extender Service
"3390:TCP"= 3390:TCP:Remote Media Center Experience
"56308:TCP"= 56308:TCP:Pando Media Booster
"56308:UDP"= 56308:UDP:Pando Media Booster
"7030:TCP"= 7030:TCP:BitComet 7030 TCP
"7030:UDP"= 7030:UDP:BitComet 7030 UDP

R2 srenum;srenum;c:\windows\system32\DRIVERS\srenum.sys [x]
R3 adxapie;adxapie;c:\docume~1\Eddie\LOCALS~1\Temp\adxapie.sys [x]
S0 AvgRkx86;avgrkx86.sys;c:\windows\System32\Drivers\avgrkx86.sys [2009-08-03 12552]
S1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\System32\Drivers\avgldx86.sys [2009-08-03 335240]
S1 AvgTdiX;AVG8 Network Redirector;c:\windows\System32\Drivers\avgtdix.sys [2009-08-03 108552]
S2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-08-03 297752]


[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
QWAVE REG_MULTI_SZ QWAVE

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder

2009-09-03 c:\windows\Tasks\User_Feed_Synchronization-{BBF2214D-DCDA-463D-A318-8450DE3910BE}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 10:31]

2009-08-26 c:\windows\Tasks\WebReg Photosmart C6100 series.job
- c:\program files\HP\Digital Imaging\bin\hpqwrg.exe [2006-02-19 11:09]
.
.
——- Supplementary Scan ——-
.
uInternet Settings,ProxyOverride = *.local
IE: &D;&ownload; &with; BitComet - c:\program files\BitComet\BitComet.exe/AddLink.htm
IE: &D;&ownload; all video with BitComet - c:\program files\BitComet\BitComet.exe/AddVideo.htm
IE: &D;&ownload; all with BitComet - c:\program files\BitComet\BitComet.exe/AddAllLink.htm
IE: E&xport; to Microsoft Excel - c:\progra~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
Trusted Zone: musicmatch.com\online
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-09-02 19:33
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …


**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(140)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\WLTRYSVC.EXE
c:\windows\system32\BCMWLTRY.EXE
c:\progra~1\COMMON~1\AOL\ACS\AOLacsd.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\ehome\ehrecvr.exe
c:\windows\ehome\ehSched.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe
c:\program files\Dell\QuickSet\NicConfigSvc.exe
c:\windows\ehome\RMSvc.exe
c:\program files\Dell Support Center\bin\sprtsvc.exe
c:\windows\system32\ZuneBusEnum.exe
c:\windows\ehome\McrdSvc.exe
c:\program files\Pure Networks\Network Magic\nmsrvc.exe
c:\program files\Zune\ZuneNss.exe
c:\windows\system32\dllhost.exe
c:\windows\system32\igfxsrvc.exe
c:\windows\ehome\ehmsas.exe
c:\progra~1\MI3AA1~1\rapimgr.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Common Files\LogiShrd\LComMgr\LVComSX.exe
c:\program files\HP\Digital Imaging\bin\hpqimzone.exe
c:\program files\HP\Digital Imaging\bin\hpqnrs08.exe
c:\program files\Common Files\LogiShrd\LQCVFX\COCIManager.exe
.
**************************************************************************
.
Completion time: 2009-09-03 19:44 - machine was rebooted
ComboFix-quarantined-files.txt 2009-09-03 01:43

Pre-Run: 9,389,821,952 bytes free
Post-Run: 10,175,242,240 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect

307 — E O F — 2009-09-02 09:03



Additionally, since running ComboFix I have been unable to go online with that computer. I have tried restarting and connecting both wirelessly and via ethernet cable but neither one works. Please let me know where to enable my connection. Thanks.
Try this, Rob.

  • Click on the Start button.
  • Click on the Settings menu option.
  • Click on the Control Panel option.
  • When the Control Panel opens, double-click on the Network Connections icon. If your Control Panel is set to Category View, then double-click on Network and Internet Connections and then click on Network Connections at the bottom.
  • You will now see a list of available network connections. Locate the connection for your Wireless or Lan adapter and right-click on it.
  • Click on the Repair menu option.
[external image: Posted Image]

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI