This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Infected

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:37:23, on 05/09/2009
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18813)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\mobsync.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\AVG\AVG8\avgtray.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Windows\System32\wsqmcons.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10c.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O1 - Hosts: ::1 localhost
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O13 - Gopher Prefix:
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} (get_atlcom Class) - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Roxio\Roxio MyDVD Premier\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe

–
End of file - 5623 bytes
Hello and welcome to WTT.

I apologize for the delay in response.

If you still require assistance provide a description of any remaining problems or symptoms you may still have please.

Download and run DDS

We need to see some information about what is happening in your machine. Please perform the following scan:
  • Download DDS by sUBs from one of the following links. Save it to your desktop.
    • DDS.scr
    • DDS.pif
  • Double click on the DDS icon, allow it to run.
  • A small box will open, with an explanation about the tool. No input is needed, the scan is running.
  • Notepad will open with the results soon.
  • Follow the instructions that pop up for posting the results and then click Ok.
  • The black and message box window shall then disappear.
  • Please save both log files on your desktop and post the DDS.txt and zip up and attach Attach.txt as instructed.
Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet. Information on A/V control HERE

Then, please run RootRepeal:

Download and run RootRepeal CR

Please download RootRepeal to your desktop
Alternative Download Link 2
Alternative Download Link 3
  • Physically disconnect your machine from the internet as your system will be unprotected.
  • Unzip it to it's own folder
  • Close/Disable all other programs especially your security programs (anti-spyware, anti-virus, and firewall) Refer to this page, if you are unsure how.
  • Double-click on RootRepeal.exe to run it. If you are using Vista, please right-click and run as Administrator…
  • Click the Report tab at the bottom.
  • Now click the Scan button in the Report Tab. [external image: Posted Image]
  • A box will pop up, check the boxes beside ALL Seven options/scan area
    🖼Click to load external image (Posted Image)
  • Now click OK.
  • Another box will open, check the boxes beside all the drives, eg : C:\, then click OK.
  • The scan will take a little while to run, so let it go unhindered.
  • Once it is done, click the Save Report button. [external image: Posted Image]
  • Save it as RepealScan and save it to your desktop
  • Reconnect to the internet.
  • Post the contents of that log in your reply please.

For your next reply I would like to see:
-The DDS logs
—DDS.txt and Attach logs
-RootRepeal logs
-Description of any remaining problems you may still have.


With Regards,
Extremeboy
DDS LOG


DDS (Ver_09-07-30.01) - NTFSx86
Run by [removed] at 18:55:02.98 on 09/09/2009
Internet Explorer: 8.0.6001.18813
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.44.1033.18.3069.1849 [GMT 1:00]

AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: AVG Anti-Virus Free *enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: Spybot - Search and Destroy *disabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\rundll32.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\WUDFHost.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\AVG\AVG8\avgtray.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10c.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\DllHost.exe
C:\Windows\System32\svchost.exe -k swprv
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\User\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JN895R96\dds[1].pif

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.co.uk/
uURLSearchHooks: H - No File
uURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg8\toolbar\IEToolbar.dll
mURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg8\toolbar\IEToolbar.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg8\toolbar\IEToolbar.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.3572\swg.dll
BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll
TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - c:\program files\avg\avg8\toolbar\IEToolbar.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
uRun: [ISUSPM] "c:\program files\common files\installshield\updateservice\ISUSPM.exe" -scheduler
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
uRun: [Sony Ericsson PC Suite] "c:\program files\sony ericsson\sony ericsson pc suite\SEPCSuite.exe" /systray /nologon
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [PWRISOVM.EXE] c:\program files\poweriso\PWRISOVM.EXE
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
AppInit_DLLs: avgrsstx.dll

============= SERVICES / DRIVERS ===============

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-9-12 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-9-12 108552]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\avg\avg8\avgemc.exe [2009-8-31 908056]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2009-8-31 297752]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search & destroy\SDWinSec.exe [2009-8-31 1153368]
S3 a016bus;Sony Ericsson Device A016 driver (WDM);c:\windows\system32\drivers\a016bus.sys [2009-9-6 83880]
S3 a016mdfl;Sony Ericsson Device A016 USB WMC Modeme Filter;c:\windows\system32\drivers\a016mdfl.sys [2009-9-6 15016]
S3 a016mdm;Sony Ericsson Device A016 USB WMC Modem Driver;c:\windows\system32\drivers\a016mdm.sys [2009-9-6 110504]
S3 a016mgmt;Sony Ericsson Device A016 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\a016mgmt.sys [2009-9-6 104488]
S3 a016obex;Sony Ericsson Device A016 USB WMC OBEX Interface;c:\windows\system32\drivers\a016obex.sys [2009-9-6 100648]
S3 getPlusHelper;getPlus® Helper;c:\windows\system32\svchost.exe -k getPlusHelper [2009-9-1 21504]

============== File Associations ===============

regfile="regedit.exe" "%1"

=============== Created Last 30 ================

2009-09-08 17:46 –d—– c:\programdata\Sports Interactive
2009-09-08 17:46 –d—– c:\progra~2\Sports Interactive
2009-09-08 17:33 –d—– c:\program files\PowerISO
2009-09-07 19:30 –d—– c:\users\user\appdata\roaming\Sports Interactive
2009-09-07 19:22 –d-h— c:\program files\Zero G Registry
2009-09-07 19:22 –d—– c:\program files\Games
2009-09-07 19:20 –d-h— c:\users\user\InstallAnywhere
2009-09-06 14:35 –d—– c:\programdata\BVRP Software
2009-09-06 14:35 –d—– c:\program files\Avanquest update
2009-09-06 14:02 100,648 a——- c:\windows\system32\drivers\a016obex.sys
2009-09-06 14:02 12,200 a——- c:\windows\system32\drivers\a016whnt.sys
2009-09-06 14:02 12,200 a——- c:\windows\system32\drivers\a016wh.sys
2009-09-06 14:02 110,504 a——- c:\windows\system32\drivers\a016mdm.sys
2009-09-06 14:02 104,488 a——- c:\windows\system32\drivers\a016mgmt.sys
2009-09-06 14:02 83,880 a——- c:\windows\system32\drivers\a016bus.sys
2009-09-06 14:02 15,016 a——- c:\windows\system32\drivers\a016mdfl.sys
2009-09-06 14:02 12,200 a——- c:\windows\system32\drivers\a016cmnt.sys
2009-09-06 14:02 12,200 a——- c:\windows\system32\drivers\a016cm.sys
2009-09-06 14:02 –d—– c:\programdata\Sony Ericsson
2009-09-06 14:02 –d—– c:\program files\Sony Ericsson
2009-09-06 14:02 –d—– c:\progra~2\Sony Ericsson
2009-09-05 10:37 –d—– c:\program files\Trend Micro
2009-09-05 10:07 225,280 a——- c:\windows\system32\rewire.dll
2009-09-05 10:07 –d—– c:\program files\VstPlugins
2009-09-05 10:07 1,294,336 a——- c:\windows\system32\vorbis.acm
2009-09-05 10:06 –d—– c:\program files\Outsim
2009-09-05 10:06 –d—– c:\program files\Image-Line
2009-09-05 08:49 –d—– c:\programdata\Google
2009-09-05 08:48 –d—– c:\programdata\NOS
2009-09-04 21:41 –d—– c:\program files\uTorrent
2009-09-04 21:38 –d—– c:\users\user\appdata\roaming\uTorrent
2009-09-04 20:43 –d-h— C:\$AVG8.VAULT$
2009-09-04 20:24 4,240,384 a——- c:\windows\system32\GameUXLegacyGDFs.dll
2009-09-04 20:24 28,672 a——- c:\windows\system32\Apphlpdm.dll
2009-09-01 10:27 –d—– c:\windows\system32\eu-ES
2009-09-01 10:27 –d—– c:\windows\system32\ca-ES
2009-09-01 10:26 –d—– c:\windows\system32\vi-VN
2009-09-01 10:26 0 a—h— c:\windows\system32\drivers\Msft_User_WpdFs_01_00_00.Wdf
2009-09-01 10:26 0 a—h— c:\windows\system32\drivers\Msft_User_AuxiliaryDisplayEnhancedDriver_01_00_00.Wdf
2009-09-01 10:25 –d—– c:\windows\system32\SPReview
2009-09-01 09:59 –d—– C:\PerfLogs
2009-09-01 09:34 193,024 a——- c:\windows\system32\recdisc.exe
2009-09-01 09:34 6,656 a——- c:\windows\system32\sdspres.dll
2009-09-01 09:34 28,160 a——- c:\windows\system32\sxproxy.dll
2009-09-01 09:32 2,585,088 a——- c:\windows\system32\FirewallControlPanel.exe
2009-09-01 09:30 327,680 a——- c:\windows\SPInstall.etl
2009-09-01 09:29 –d—– c:\windows\system32\EventProviders
2009-08-31 23:48 2,048 a——- c:\windows\system32\tzres.dll
2009-08-31 23:47 272,896 a——- c:\windows\system32\polstore.dll
2009-08-31 23:47 61,440 a——- c:\windows\system32\winipsec.dll
2009-08-31 23:46 1,820 a——- c:\windows\system32\rasctrnm.h
2009-08-31 23:43 69,632 a——- c:\windows\system32\Mpeg2Data.ax
2009-08-31 23:41 12,880 a——- c:\windows\system32\wbem\wlan.mof
2009-08-31 23:40 2,034,688 a——- c:\windows\system32\win32k.sys
2009-08-31 23:39 156,672 a——- c:\windows\system32\t2embed.dll
2009-08-31 23:39 289,792 a——- c:\windows\system32\atmfd.dll
2009-08-31 23:39 72,704 a——- c:\windows\system32\fontsub.dll
2009-08-31 23:39 34,304 a——- c:\windows\system32\atmlib.dll
2009-08-31 23:39 23,552 a——- c:\windows\system32\lpk.dll
2009-08-31 23:39 10,240 a——- c:\windows\system32\dciman32.dll
2009-08-31 23:35 71,680 a——- c:\windows\system32\atl.dll
2009-08-31 23:29 160,256 a——- c:\windows\system32\wkssvc.dll
2009-08-31 23:28 136,192 a——- c:\windows\system32\aaclient.dll
2009-08-31 23:28 2,066,432 a——- c:\windows\system32\mstscax.dll
2009-08-31 23:28 53,248 a——- c:\windows\system32\tsgqec.dll
2009-08-31 23:26 2,048 a——- c:\windows\system32\msxml3r.dll
2009-08-31 23:21 623,616 a——- c:\windows\system32\localspl.dll
2009-08-31 23:20 123,904 a——- c:\windows\system32\msvfw32.dll
2009-08-31 23:20 91,136 a——- c:\windows\system32\avifil32.dll
2009-08-31 23:20 65,024 a——- c:\windows\system32\avicap32.dll
2009-08-31 23:20 82,944 a——- c:\windows\system32\mciavi32.dll
2009-08-31 23:20 31,232 a——- c:\windows\system32\msvidc32.dll
2009-08-31 23:20 12,800 a——- c:\windows\system32\msrle32.dll
2009-08-31 23:15 175,104 a——- c:\windows\system32\wdigest.dll
2009-08-31 23:15 1,259,008 a——- c:\windows\system32\lsasrv.dll
2009-08-31 23:15 499,712 a——- c:\windows\system32\kerberos.dll
2009-08-31 23:15 439,864 a——- c:\windows\system32\drivers\ksecdd.sys
2009-08-31 23:15 218,624 a——- c:\windows\system32\msv1_0.dll
2009-08-31 23:15 72,704 a——- c:\windows\system32\secur32.dll
2009-08-31 23:15 9,728 a——- c:\windows\system32\lsass.exe
2009-08-31 23:15 270,848 a——- c:\windows\system32\schannel.dll
2009-08-31 23:15 13,780 a——- c:\windows\system32\wbem\lsasrv.mof
2009-08-31 23:11 4,497,408 a——- c:\windows\system32\NlsData0019.dll
2009-08-31 23:09 6,656 a——- c:\windows\system32\kbd106n.dll
2009-08-31 23:00 37,888 a——- c:\windows\system32\printcom.dll
2009-08-31 23:00 14,848 a——- c:\windows\system32\wshrm.dll
2009-08-31 22:59 313,344 a——- c:\windows\system32\wmpdxm.dll
2009-08-31 22:59 8,147,456 a——- c:\windows\system32\wmploc.DLL
2009-08-31 22:59 43,520 a——- c:\windows\system32\msdxm.tlb
2009-08-31 22:59 18,432 a——- c:\windows\system32\amcompat.tlb
2009-08-31 22:59 7,680 a——- c:\windows\system32\spwmp.dll
2009-08-31 22:59 4,096 a——- c:\windows\system32\msdxm.ocx
2009-08-31 22:59 4,096 a——- c:\windows\system32\dxmasf.dll
2009-08-31 22:51 19,857,408 a——- c:\windows\ocsetup_install_NetFx3.etl
2009-08-31 22:51 262,144 a——- c:\windows\ocsetup_cbs_install_NetFx3.perf
2009-08-31 22:51 65,536 a——- c:\windows\ocsetup_cbs_install_NetFx3.dpx
2009-08-31 22:49 41,984 a——- c:\windows\system32\netfxperf.dll
2009-08-31 22:45 84,480 a——- c:\windows\system32\INETRES.dll
2009-08-31 22:45 784,896 a——- c:\windows\system32\rpcrt4.dll
2009-08-31 22:44 –d—– c:\programdata\AVG Security Toolbar
2009-08-31 22:44 –d—– c:\progra~2\AVG Security Toolbar
2009-08-31 22:44 2,048 a——- c:\windows\system32\msxml6r.dll
2009-08-31 22:41 –d—– c:\programdata\Spybot - Search & Destroy
2009-08-31 22:41 –d—– c:\program files\Spybot - Search & Destroy
2009-08-31 22:41 –d—– c:\progra~2\Spybot - Search & Destroy

==================== Find3M ====================

2009-09-06 14:35 143,360 a——- c:\windows\inf\infstrng.dat
2009-09-06 14:35 143,360 a——- c:\windows\inf\infstor.dat
2009-09-06 14:35 51,200 a——- c:\windows\inf\infpub.dat
2009-09-01 10:26 665,600 a——- c:\windows\inf\drvindex.dat
2009-09-01 10:09 174 a–sh— c:\program files\desktop.ini
2009-09-01 09:51 101,888 a——- c:\windows\system32\ifxcardm.dll
2009-09-01 09:50 82,432 a——- c:\windows\system32\axaltocm.dll
2009-08-31 23:27 52,736 a——- c:\windows\apppatch\iebrshim.dll
2009-08-31 23:11 2,599,936 a——- c:\windows\system32\NlsData0001.dll
2009-08-31 22:44 335,240 a——- c:\windows\system32\drivers\avgldx86.sys
2009-08-31 22:44 11,952 a——- c:\windows\system32\avgrsstx.dll
2009-08-31 22:44 108,552 a——- c:\windows\system32\drivers\avgtdix.sys
2009-08-29 03:30 173,056 a——- c:\windows\apppatch\AcXtrnal.dll
2009-08-29 03:30 458,752 a——- c:\windows\apppatch\AcSpecfc.dll
2009-08-29 03:30 2,159,616 a——- c:\windows\apppatch\AcGenral.dll
2009-08-29 03:30 542,720 a——- c:\windows\apppatch\AcLayers.dll
2009-07-27 03:43 58,908 a——- c:\windows\system32\drivers\scdemu.sys
2009-07-21 22:52 915,456 a——- c:\windows\system32\wininet.dll
2009-07-21 22:47 109,056 a——- c:\windows\system32\iesysprep.dll
2009-07-21 22:47 71,680 a——- c:\windows\system32\iesetup.dll
2009-07-21 21:13 133,632 a——- c:\windows\system32\ieUnatt.exe
2006-11-02 13:42 287,440 a——- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 13:42 287,440 a——- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 13:42 30,674 a——- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 13:42 30,674 a——- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 10:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 10:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 10:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 10:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat

============= FINISH: 18:55:28.98 ===============


Root Repeal Log

ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2009/09/09 19:25
Program Version: Version 1.3.5.0
Windows Version: Windows Vista SP2
==================================================

Drivers
——————-
Name: dump_iaStorV.sys
Image Path: C:\Windows\System32\Drivers\dump_iaStorV.sys
Address: 0x8FA0F000 Size: 659456 File Visible: No Signed: -
Status: -

Name: rootrepeal.sys
Image Path: C:\Windows\system32\drivers\rootrepeal.sys
Address: 0x9C318000 Size: 49152 File Visible: No Signed: -
Status: -

Hidden/Locked Files
——————-
Path: C:\hiberfil.sys
Status: Locked to the Windows API!

Path: C:\System Volume Information\{2ed9dd9b-9fe2-11de-a19d-001d09243a98}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{57f7ef5d-9fe4-11de-a19d-001d09243a98}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{57f7ef7b-9fe4-11de-a19d-001d09243a98}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{d1bb7eb1-9ad9-11de-8f83-001d09243a98}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{d1bb7ed5-9ad9-11de-8f83-001d09243a98}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{d1bb7ef9-9ad9-11de-8f83-001d09243a98}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{d1bb7f26-9ad9-11de-8f83-001d09243a98}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{d1bb7f4a-9ad9-11de-8f83-001d09243a98}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{67e7d407-9c95-11de-b4d8-001d09243a98}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{b3cd4703-9bc9-11de-aaf2-001d09243a98}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{bcf47b78-96d6-11de-89b2-001d09243a98}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{d1bb7e9d-9ad9-11de-8f83-001d09243a98}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{d1bb7ea1-9ad9-11de-8f83-001d09243a98}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{d1bb7ea5-9ad9-11de-8f83-001d09243a98}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{d1bb7ea9-9ad9-11de-8f83-001d09243a98}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{d1bb7ead-9ad9-11de-8f83-001d09243a98}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{d1bb7eb5-9ad9-11de-8f83-001d09243a98}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{d1bb7eb9-9ad9-11de-8f83-001d09243a98}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{d1bb7ebd-9ad9-11de-8f83-001d09243a98}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{d1bb7ec1-9ad9-11de-8f83-001d09243a98}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{d1bb7ec5-9ad9-11de-8f83-001d09243a98}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{d1bb7ec9-9ad9-11de-8f83-001d09243a98}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{d1bb7ecd-9ad9-11de-8f83-001d09243a98}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{d1bb7ed1-9ad9-11de-8f83-001d09243a98}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{d1bb7ed9-9ad9-11de-8f83-001d09243a98}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{d1bb7edd-9ad9-11de-8f83-001d09243a98}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{d1bb7ee1-9ad9-11de-8f83-001d09243a98}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{d1bb7ee5-9ad9-11de-8f83-001d09243a98}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{d1bb7ee9-9ad9-11de-8f83-001d09243a98}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{d1bb7eed-9ad9-11de-8f83-001d09243a98}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{d1bb7ef1-9ad9-11de-8f83-001d09243a98}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{d1bb7ef5-9ad9-11de-8f83-001d09243a98}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{e0921c1b-9987-11de-a418-001d09243a98}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{e28fc593-99ef-11de-84cf-001d09243a98}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{f7332e91-9680-11de-a5ca-001d09243a98}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{f7332e98-9680-11de-a5ca-001d09243a98}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{fa105f6f-96d9-11de-8f46-001d09243a98}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{d1bb7efd-9ad9-11de-8f83-001d09243a98}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{d1bb7f01-9ad9-11de-8f83-001d09243a98}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{d1bb7f05-9ad9-11de-8f83-001d09243a98}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{d1bb7f12-9ad9-11de-8f83-001d09243a98}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{d1bb7f16-9ad9-11de-8f83-001d09243a98}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{d1bb7f1a-9ad9-11de-8f83-001d09243a98}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{d1bb7f1e-9ad9-11de-8f83-001d09243a98}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{d1bb7f22-9ad9-11de-8f83-001d09243a98}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{d1bb7f2a-9ad9-11de-8f83-001d09243a98}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{d1bb7f2e-9ad9-11de-8f83-001d09243a98}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{d1bb7f32-9ad9-11de-8f83-001d09243a98}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{d1bb7f36-9ad9-11de-8f83-001d09243a98}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{d1bb7f3a-9ad9-11de-8f83-001d09243a98}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{d1bb7f3e-9ad9-11de-8f83-001d09243a98}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{d1bb7f42-9ad9-11de-8f83-001d09243a98}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{d1bb7f46-9ad9-11de-8f83-001d09243a98}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{d1bb7f4e-9ad9-11de-8f83-001d09243a98}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{d1bb7f52-9ad9-11de-8f83-001d09243a98}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{d1bb7f56-9ad9-11de-8f83-001d09243a98}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{d1bb7f5a-9ad9-11de-8f83-001d09243a98}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{d1bb7f5e-9ad9-11de-8f83-001d09243a98}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{d1bb7f62-9ad9-11de-8f83-001d09243a98}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{d1bb7f66-9ad9-11de-8f83-001d09243a98}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{d1bb7f6a-9ad9-11de-8f83-001d09243a98}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{d1bb7f6e-9ad9-11de-8f83-001d09243a98}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{d1bb7f72-9ad9-11de-8f83-001d09243a98}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: C:\System Volume Information\{d1bb7f76-9ad9-11de-8f83-001d09243a98}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Locked to the Windows API!

Path: c:\programdata\avg8\temp\c36e1654-667f-4447-ad08-7b072730c913.tmp
Status: Allocation size mismatch (API: 32, Raw: 0)

Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.762_none_9193a
620671dde41.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.762_none_0c178a139ee2a7ed
.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.openmp_1fc8b3b9a1e18e3b_8.0.50727.762_none_7b33aa7d21850
4d2.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.openmp_1fc8b3b9a1e18e3b_8.0.50727.762_none_ab
ac38a907ee8801.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.762_none_10b2f55f9bffb8f8
.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.762_none_43efccf17831d
131.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.762_none_11ecb0ab9b2caf3c
.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.21022.8_none_bcb86ed6ac711f91.c
at
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.762_none_8e053
e8c6967ba9d.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.762_none_8d
d7dea5d5a7a18a.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.762_none_8a14c
0566bec5b24.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.9.0.microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.21022.8_none_60a5df5
6e60dc5df.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-a..atibility-assistant_31bf3856ad364e35_6.0.6000.16386_none_318fc418263bf156\$$DeleteMe.pcadm.dll.01ca2ae32c56795b.00e4
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-a..atibility-assistant_31bf3856ad364e35_6.0.6000.16386_none_318fc418263bf156\$$DeleteMe.pcasvc.dll.01ca2ae3002e177b.0096
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-a..dcredentialprovider_31bf3856ad364e35_6.0.6001.18000_none_420aa4b9c28d5162\$$DeleteMe.SmartcardCredentialProvider.dll.01ca2ae67e2d881b.0062
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-a..ence-infrastructure_31bf3856ad364e35_6.0.6000.16386_none_d2da41c24fcec5ef\$$DeleteMe.apphelp.dll.01ca2ae3203d9c7b.00d0
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-a..ence-infrastructure_31bf3856ad364e35_6.0.6001.18000_none_d51103be4cb9d6c3\$$DeleteMe.apphelp.dll.01ca2ae6837333bb.008a
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-a..terface-ldapc-layer_31bf3856ad364e35_6.0.6000.16386_none_5cfbb23d699248a8\$$DeleteMe.adsldpc.dll.01ca2ae2d19f92db.0056
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-a..terface-ldapc-layer_31bf3856ad364e35_6.0.6001.18000_none_5f327439667d597c\$$DeleteMe.adsldpc.dll.01ca2ae66ee4339b.0032
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-a..dcredentialprovider_31bf3856ad364e35_6.0.6000.16386_none_3fd3e2bdc5a2408e\$$DeleteMe.SmartcardCredentialProvider.dll.01ca2ae3076c669b.00a3
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-atl_31bf3856ad364e35_6.0.6000.16889_none_a8ec88265cc499db\$$DeleteMe.atl.dll.01ca2ae307e82e1b.00a5
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-atl_31bf3856ad364e35_6.0.6001.18293_none_aac1f52459f8aeb3\$$DeleteMe.atl.dll.01ca2ae67e690a7b.0064
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-audio-mmecore-acm_31bf3856ad364e35_6.0.6000.16386_none_deaec722e41e5e07\$$DeleteMe.msacm32.dll.01ca2ae2999e993b.0013
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-audio-mmecore-base_31bf3856ad364e35_6.0.6000.16386_none_b3a8fa3e54c50ab3\$$DeleteMe.winmm.dll.01ca2ae3152a96db.00b7
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-authentication-authui_31bf3856ad364e35_6.0.6000.16513_none_0a056d7cf846bbd5\$$DeleteMe.authui.dll.01ca2ae2fe4d41bb.008f
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-authentication-authui_31bf3856ad364e35_6.0.6001.18000_none_0bf37d16f567e1f7\$$DeleteMe.authui.dll.01ca2ae67c0c6d3b.0056
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-authentication-logonui_31bf3856ad364e35_6.0.6000.16386_none_635c5092764d99de\$$DeleteMe.LogonUI.exe.01ca2ae2fc7ab43b.008a
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-audio-mmecore-base_31bf3856ad364e35_6.0.6001.18000_none_b5dfbc3a51b01b87\$$DeleteMe.winmm.dll.01ca2ae680d18e9b.0074
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-bcrypt-dll_31bf3856ad364e35_6.0.6000.16386_none_ec55d170f27a97bb\$$DeleteMe.bcrypt.dll.01ca2ae2bad085fb.0032
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-bcrypt-dll_31bf3856ad364e35_6.0.6001.18000_none_ee8c936cef65a88f\$$DeleteMe.bcrypt.dll.01ca2ae6648ad93b.001d
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-bits-igdsearcher_31bf3856ad364e35_6.0.6001.18000_none_b16c3d098f004f58\$$DeleteMe.bitsigd.dll.01ca2ae677ca377b.0049
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-c..complus-eventsystem_31bf3856ad364e35_6.0.6000.16386_none_0ab6dd2154d28f55\$$DeleteMe.es.dll.01ca2ae31d9995fb.00c5
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-c..complus-eventsystem_31bf3856ad364e35_6.0.6001.18000_none_0ced9f1d51bda029\$$DeleteMe.es.dll.01ca2ae6825f143b.0080
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-c..complus-runtime-qfe_31bf3856ad364e35_6.0.6000.16386_none_692c6c857ba3c205\$$DeleteMe.clbcatq.dll.01ca2ae32774c77b.00df
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-c..ent-indexing-common_31bf3856ad364e35_6.0.6000.16386_none_047d4bceda254122\$$DeleteMe.Query.dll.01ca2ae2ec1fa19b.007c
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-c..ent-indexing-common_31bf3856ad364e35_6.0.6001.18000_none_06b40dcad71051f6\$$DeleteMe.Query.dll.01ca2ae678dbf59b.004c
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-c..rformance-xperfcore_31bf3856ad364e35_6.0.6000.16386_none_d4dab19871ad5771\$$DeleteMe.diagperf.dll.01ca2ae33412f15b.00e9
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-c..rformance-xperfcore_31bf3856ad364e35_6.0.6001.18000_none_d71173946e986845\$$DeleteMe.diagperf.dll.01ca2ae688a372fb.009b
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-c..tionauthorityclient_31bf3856ad364e35_6.0.6001.18000_none_d77db57c3ca78826\$$DeleteMe.certcli.dll.01ca2ae6708be85b.0037
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-cabinet_31bf3856ad364e35_6.0.6000.16386_none_35088f20e500a372\$$DeleteMe.cabinet.dll.01ca2ae318c62c5b.00ba
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-c..tionauthorityclient_31bf3856ad364e35_6.0.6000.16386_none_d546f3803fbc7752\$$DeleteMe.certcli.dll.01ca2ae2d403543b.005a
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-cbsapi_31bf3856ad364e35_6.0.6000.16386_none_4c2b1119f37be620\$$DeleteMe.CbsApi.dll.01ca2ae0c70bb2d0.0001
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-cmi_31bf3856ad364e35_6.0.6000.16386_none_a797884c5d9fcdc5\$$DeleteMe.cmiv2.dll.01ca2ae34626625b.0100
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-cmi_31bf3856ad364e35_6.0.6001.18000_none_a9ce4a485a8ade99\$$DeleteMe.cmiv2.dll.01ca2ae68d6fb87b.00ae
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-coreos_31bf3856ad364e35_6.0.6000.16470_none_2320546141637f8f\$$DeleteMe.imagehlp.dll.01ca2ae32414b45b.00d6
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-coreusermodepnp_31bf3856ad364e35_6.0.6000.16609_none_75246f2a2fbd4c23\$$DeleteMe.umpnpmgr.dll.01ca2ae3258ccd9b.00db
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-coreusermodepnp_31bf3856ad364e35_6.0.6001.18000_none_7701ab362cebf905\$$DeleteMe.umpnpmgr.dll.01ca2ae684e68a3b.0093
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-credui_31bf3856ad364e35_6.0.6000.16386_none_d9008ac592026334\$$DeleteMe.credui.dll.01ca2ae298e4edfb.0011
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-cryptdll-dll_31bf3856ad364e35_6.0.6000.16386_none_0367c3eab0da6051\$$DeleteMe.cryptdll.dll.01ca2ae2ffe6ae3b.0094
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-csrss_31bf3856ad364e35_6.0.6000.16386_none_56ad21dbe72a9d78\$$DeleteMe.csrss.exe.01ca2ae293f7553b.0008
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-credui_31bf3856ad364e35_6.0.6001.18000_none_db374cc18eed7408\$$DeleteMe.credui.dll.01ca2ae65db5469b.000a
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-crypt32-dll_31bf3856ad364e35_6.0.6000.16425_none_5978e103e0b8f230\$$DeleteMe.crypt32.dll.01ca2ae30e314f9b.00ab
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-crypt32-dll_31bf3856ad364e35_6.0.6001.18000_none_5b6fc1dbddd3c6da\$$DeleteMe.crypt32.dll.01ca2ae67f78673b.0069
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.0.6000.16386_none_73c8d7689de43d15\$$DeleteMe.cryptsvc.dll.01ca2ae2d91e271b.0062
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.0.6001.18000_none_75ff99649acf4de9\$$DeleteMe.cryptsvc.dll.01ca2ae671f0f69b.003c
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-csrsrv_31bf3856ad364e35_6.0.6000.16445_none_c77ab655a8530501\$$DeleteMe.csrsrv.dll.01ca2ae2942bb37b.000a
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-d..frameworks-usermode_31bf3856ad364e35_6.0.6000.16386_none_9adace8ff858851e\$$DeleteMe.WUDFHost.exe.01ca2ae339ae4e7b.00f1
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-d..frameworks-usermode_31bf3856ad364e35_6.0.6000.16386_none_9adace8ff858851e\$$DeleteMe.WUDFPlatform.dll.01ca2ae2e1ac181b.006a
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-d..frameworks-usermode_31bf3856ad364e35_6.0.6000.16386_none_9adace8ff858851e\$$DeleteMe.WUDFSvc.dll.01ca2ae2ae2413db.002a
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-d..frameworks-usermode_31bf3856ad364e35_6.0.6000.16386_none_9adace8ff858851e\$$DeleteMe.WUDFx.dll.01ca2ae2d0a803db.0052
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-d..oryservices-ntdsapi_31bf3856ad364e35_6.0.6000.16386_none_cca68469f44b4003\$$DeleteMe.ntdsapi.dll.01ca2ae2c8b72d9b.0044
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-deltapackageexpander_31bf3856ad364e35_6.0.6000.16609_none_68015a2337d92e69\$$DeleteMe.dpx.dll.01ca2ae3000f259b.0095
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-dhcp-client-dll_31bf3856ad364e35_6.0.6000.16512_none_d56b19bc316f9001\$$DeleteMe.dhcpcsvc.dll.01ca2ae32468047b.00d8
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-dhcp-client-dll_31bf3856ad364e35_6.0.6000.16512_none_d56b19bc316f9001\$$DeleteMe.dhcpcsvc6.dll.01ca2ae29cccaf7b.0015
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-dhcp-client-dll_31bf3856ad364e35_6.0.6001.18000_none_d75a29a02e8fcf7a\$$DeleteMe.dhcpcsvc.dll.01ca2ae68420f81b.0090
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-dhcp-client-dll_31bf3856ad364e35_6.0.6001.18000_none_d75a29a02e8fcf7a\$$DeleteMe.dhcpcsvc6.dll.01ca2ae65e2eacbb.000d
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-dims_31bf3856ad364e35_6.0.6000.16386_none_a74c11b71e09911f\$$DeleteMe.dimsjob.dll.01ca2ae31be5fa5b.00bf
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-directory-services-sam_31bf3856ad364e35_6.0.6000.16386_none_afb79761a4097d90\$$DeleteMe.samlib.dll.01ca2ae2eba178bb.007b
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-directory-services-sam_31bf3856ad364e35_6.0.6000.16386_none_afb79761a4097d90\$$DeleteMe.samsrv.dll.01ca2ae2ae7763fb.002b
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-directory-services-sam_31bf3856ad364e35_6.0.6001.18000_none_b1ee595da0f48e64\$$DeleteMe.samlib.dll.01ca2ae678aebb7b.004b
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-directory-services-sam_31bf3856ad364e35_6.0.6001.18000_none_b1ee595da0f48e64\$$DeleteMe.samsrv.dll.01ca2ae6614c195b.0017
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-dns-client-winrnr_31bf3856ad364e35_6.0.6000.16386_none_571790f3532b2696\$$DeleteMe.winrnr.dll.01ca2ae6895398bb.009f
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-dns-client_31bf3856ad364e35_6.0.6000.16615_none_dff66fbd85366d1e\$$DeleteMe.dnsapi.dll.01ca2ae2aa29475b.0027
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-dns-client_31bf3856ad364e35_6.0.6000.16615_none_dff66fbd85366d1e\$$DeleteMe.dnsrslvr.dll.01ca2ae2ce019bfb.004c
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-duser_31bf3856ad364e35_6.0.6000.16386_none_583dec4cff8f7125\$$DeleteMe.duser.dll.01ca2ae327dfe55b.00e1
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-e..-protocol-host-peer_31bf3856ad364e35_6.0.6000.16386_none_61dcc930c67f1797\$$DeleteMe.eappcfg.dll.01ca2ae2a0090dfb.0017
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-e..-protocol-host-peer_31bf3856ad364e35_6.0.6000.16386_none_61dcc930c67f1797\$$DeleteMe.eappprxy.dll.01ca2ae2fa33835b.0087
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-e..-protocol-host-peer_31bf3856ad364e35_6.0.6001.18000_none_64138b2cc36a286b\$$DeleteMe.eappcfg.dll.01ca2ae65e3f565b.000e
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-dns-client_31bf3856ad364e35_6.0.6001.18000_none_e1e27cdd8259636b\$$DeleteMe.dnsapi.dll.01ca2ae66014453b.0015
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-dns-client_31bf3856ad364e35_6.0.6001.18000_none_e1e27cdd8259636b\$$DeleteMe.dnsrslvr.dll.01ca2ae66da79cbb.002c
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-e..emorydevicesservice_31bf3856ad364e35_6.0.6000.16386_none_9c552a52f9cf5068\$$DeleteMe.emdmgmt.dll.01ca2ae30e9a0c1b.00ac
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-e..emorydevicesservice_31bf3856ad364e35_6.0.6001.18000_none_9e8bec4ef6ba613c\$$DeleteMe.emdmgmt.dll.01ca2ae67faa641b.006b
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-e..estorageengine-isam_31bf3856ad364e35_6.0.6001.18000_none_f1e446e12c0bbf09\$$DeleteMe.esent.dll.01ca2ae67cb0ac1b.0059
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-e..estorageengine-isam_31bf3856ad364e35_6.0.6000.16386_none_efad84e52f20ae35\$$DeleteMe.esent.dll.01ca2ae2ff9a823b.0092
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-eventlog-api_31bf3856ad364e35_6.0.6000.16386_none_a9fa4020685f2193\$$DeleteMe.wevtapi.dll.01ca2ae2a052d89b.0019
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-eventlog-api_31bf3856ad364e35_6.0.6001.18000_none_ac31021c654a3267\$$DeleteMe.wevtapi.dll.01ca2ae65e467a7b.000f
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-eventlog_31bf3856ad364e35_6.0.6001.18000_none_dcc45c1a12d92f84\$$DeleteMe.wevtsvc.dll.01ca2ae661ca423b.0018
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-errorreportingcore_31bf3856ad364e35_6.0.6000.16386_none_1e3ff01a08f92b15\$$DeleteMe.wer.dll.01ca2ae2de89e8bb.0067
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-eventlog_31bf3856ad364e35_6.0.6000.16386_none_da8d9a1e15ee1eb0\$$DeleteMe.wevtsvc.dll.01ca2ae2af99cbbb.002d
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-failovercluster-client_31bf3856ad364e35_6.0.6000.16386_none_a4186fca55bd3a26\$$DeleteMe.clusapi.dll.01ca2ae2e38106fb.006f
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-failovercluster-client_31bf3856ad364e35_6.0.6000.16386_none_a4186fca55bd3a26\$$DeleteMe.resutils.dll.01ca2ae3064c603b.009c
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-grouppolicy-base_31bf3856ad364e35_6.0.6000.16386_none_25ec9fe2ea179531\$$DeleteMe.gpapi.dll.01ca2ae2ec7ed89b.007e
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-grouppolicy-base_31bf3856ad364e35_6.0.6000.16386_none_25ec9fe2ea179531\$$DeleteMe.gpsvc.dll.01ca2ae3119d499b.00b5
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-grouppolicy-base_31bf3856ad364e35_6.0.6001.18000_none_282361dee702a605\$$DeleteMe.gpapi.dll.01ca2ae6790df27b.004e
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-grouppolicy-base_31bf3856ad364e35_6.0.6001.18000_none_282361dee702a605\$$DeleteMe.gpsvc.dll.01ca2ae680771a5b.0072
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-spp-main_31bf3856ad364e35_6.0.6000.16386_none_e21034c5aff1bf39\$$DeleteMe.spp.dll.01ca2ae3271cb49b.00dd
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-http-api_31bf3856ad364e35_6.0.6000.16386_none_f3757b03a060c8ff\$$DeleteMe.httpapi.dll.01ca2ae31fe5899b.00ce
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-i..oexistencemigration_31bf3856ad364e35_6.0.6000.16501_none_0ffdd2907f32f6e5\$$DeleteMe.iphlpsvc.dll.01ca2ae293f2927b.0007
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-i..oexistencemigration_31bf3856ad364e35_6.0.6001.18000_none_11e312d27c5a6ba6\$$DeleteMe.iphlpsvc.dll.01ca2ae65a27f95b.0004
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-Processes
——————-
Path: System
PID: 4 Status: Locked to the Windows API!

Path: C:\Windows\System32\audiodg.exe
PID: 1292 Status: Locked to the Windows API!

==EOF==


The only problems i have had is that AVG is detecting a trojan and when i use my internet browser AVG keeps on popping up detecting a trojan.

Thanks for the help.

Attachments:

  • [attachment removed: Attach.zip]
Hello.

The only problems i have had is that AVG is detecting a trojan and when i use my internet browser AVG keeps on popping up detecting a trojan.

What is this file/trojan that AVG detects. Please show me a screenshot with the filename and location of it in question please in your next reply.

Download and run MalwareBytes Anti-Malware

Please download Malwarebytes Anti-Malware and save it to your desktop.
alternate download link 1
  • Make sure you are connected to the Internet.
  • Double-click on Download_mbam-setup.exe to install the application.
  • When the installation begins, follow the prompts and do not make any changes to default settings.
  • When installation has finished, make sure you leave both of these checked:
    • Update Malwarebytes' Anti-Malware
    • Launch Malwarebytes' Anti-Malware
  • Then click Finish.
  • MBAM will automatically start and you will be asked to update the program before performing a scan. If an update is found, the program will automatically update itself. Press the OK button to close that box and continue. If you encounter any problems while downloading the updates, manually download them from here and just double-click on mbam-rules.exe to install.
  • On the Scanner tab:
    • Make sure the "Perform Quick Scan" option is selected.
    • Then click on the Scan button.
  • If asked to select the drives to scan, leave all the drives selected and click on the Start Scan button.
  • The scan will begin and "Scan in progress" will show at the top. It may take some time to complete so please be patient.
  • When the scan is finished, a message box will say "The scan completed successfully. Click 'Show Results' to display all objects found".
  • Click OK to close the message box and continue with the removal process.
  • Back at the main Scanner screen, click on the Show Results button to see a list of any malware that was found.
  • Make sure that everything is checked, and click Remove Selected.
  • When removal is completed, a log report will open in Notepad and you may be prompted to restart your computer. (see Note below)
  • The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the contents of that report in your next reply and exit MBAM.
Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.

For complete or visual instructions on installing and running Malwarebytes Anti-Malware please read this link

Run GMER as well…

Download and Run Scan with GMER

We will use GMER to scan for rootkits. This version will download a zip file you will need to extract first. If you use this mirror, please extract the zip file to your desktop. Unzip/extract the file to its own folder. (Click here for information on how to do this if not sure. Win 2000 users click here.

  • Close any and all open programs, as this process may crash your computer.
  • Double click [external image: Posted Image] or [external image: Posted Image] on your desktop.
  • When you have done this, close all running programs.
    There is a small chance this application may crash your computer so save any work you have open.
  • Double-click on Gmer.exe to start the program. Right-click and select Run As Administrator… if you are using Vista
  • Allow the gmer.sys driver to load if asked.
    If it detects rootkit activity, you will receive a prompt (refer below) to run a full scan. Click NO..
    [external image: Posted Image]

  • In the right panel, you will see several boxes that have been checked. Please UNCHECK the following:
    • Sections
    • IAT/EAT
    • Registry
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show all (Don't miss this one!)
  • Click on [external image: Posted Image] and wait for the scan to finish.
  • If you see a rootkit warning window, click OK.
  • Push [external image: Posted Image] and save the logfile to your desktop.
  • Copy and Paste the contents of that file in your next post.

If GMER doesn't work in Normal Mode try running it in Safe Mode

Note: Do Not run any program while GMER is running
*Note*: Rootkit scans often produce false positives. Do NOT take any actions on "<— ROOKIT" entries

Thanks.

With Regards,
Extremeboy
Hello.

Are you still there?

If you are please follow the instructions in my previous post.

If you still need help, follow the instructions I have given in my response. If you have since had your problem solved, we would appreciate you letting us know so we can close the topic.

Please reply back telling us so. If you don't reply within 5-7 from the last day I replied initially, the topic will need to be closed.

Thanks for understanding.

With Regards,
Extremeboy
Malwarebytes' Anti-Malware 1.41 Database version: 2792 Windows 6.0.6002 Service Pack 2 13/09/2009 21:24:35 mbam-log-2009-09-13 (21-24-29).txt Scan type: Quick Scan Objects scanned: 78626 Time elapsed: 4 minute(s), 11 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 1 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: HKEY_CLASSES_ROOT\regfile\shell\open\command\(default) (Broken.OpenCommand) -> Bad: ("regedit.exe" "%1") Good: (regedit.exe "%1") -> No action taken. Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) I done the scan with the GMER program but the log was blank. i have attached the screen dump.

Attachments:

Hello. Don't worry about GMER then. Just take a new DDS run and post back with the logs once they are done and answer my question I asked above. How's your computer running now? Thanks. ~Extremeboy
DDS (Ver_09-07-30.01) - NTFSx86 Run by [removed] at 18:15:13.99 on 14/09/2009 Internet Explorer: 8.0.6001.18813 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.44.1033.18.3069.1792 [GMT 1:00] AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} SP: AVG Anti-Virus Free *enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} SP: Spybot - Search and Destroy *enabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9} SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} ============== Running Processes =============== C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\nvvsvc.exe C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k secsvcs C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\system32\rundll32.exe C:\Windows\system32\WUDFHost.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\system32\SearchIndexer.exe C:\PROGRA~1\AVG\AVG8\avgrsx.exe C:\Windows\system32\WUDFHost.exe C:\PROGRA~1\AVG\AVG8\avgnsx.exe C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe C:\Windows\system32\taskeng.exe C:\Program Files\Windows Defender\MSASCui.exe C:\Program Files\AVG\AVG8\avgtray.exe C:\Windows\System32\rundll32.exe C:\Program Files\PowerISO\PWRISOVM.EXE C:\PROGRA~1\AVG\AVG8\avgemc.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe C:\Program Files\AVG\AVG8\avgcsrvx.exe C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe C:\Windows\System32\mobsync.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe C:\Windows\system32\taskeng.exe C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe C:\Windows\system32\Macromed\Flash\FlashUtil10c.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\servicing\TrustedInstaller.exe C:\Windows\system32\vssvc.exe C:\Windows\System32\svchost.exe -k swprv \\?\C:\Windows\system32\wbem\WMIADAP.EXE C:\Windows\system32\wbem\wmiprvse.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Windows\system32\DllHost.exe C:\Users\User\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QPIPWLS3\dds[1].pif ============== Pseudo HJT Report =============== uStart Page = hxxp://www.google.co.uk/ uURLSearchHooks: H - No File uURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg8\toolbar\IEToolbar.dll mURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg8\toolbar\IEToolbar.dll BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll BHO: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg8\toolbar\IEToolbar.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.2.4204.1700\swg.dll BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_B7C5AC242193BB3E.dll TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - c:\program files\avg\avg8\toolbar\IEToolbar.dll TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun uRun: [ISUSPM] "c:\program files\common files\installshield\updateservice\ISUSPM.exe" -scheduler uRun: [Sony Ericsson PC Suite] "c:\program files\sony ericsson\sony ericsson pc suite\SEPCSuite.exe" /systray /nologon uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit mRun: [PWRISOVM.EXE] c:\program files\poweriso\PWRISOVM.EXE mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes\mbam.exe" /runcleanupscript mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll AppInit_DLLs: avgrsstx.dll ============= SERVICES / DRIVERS =============== R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-9-12 335240] R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-9-12 108552] R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\avg\avg8\avgemc.exe [2009-8-31 908056] R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2009-8-31 297752] R2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search & destroy\SDWinSec.exe [2009-8-31 1153368] S3 a016bus;Sony Ericsson Device A016 driver (WDM);c:\windows\system32\drivers\a016bus.sys [2009-9-6 83880] S3 a016mdfl;Sony Ericsson Device A016 USB WMC Modeme Filter;c:\windows\system32\drivers\a016mdfl.sys [2009-9-6 15016] S3 a016mdm;Sony Ericsson Device A016 USB WMC Modem Driver;c:\windows\system32\drivers\a016mdm.sys [2009-9-6 110504] S3 a016mgmt;Sony Ericsson Device A016 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\a016mgmt.sys [2009-9-6 104488] S3 a016obex;Sony Ericsson Device A016 USB WMC OBEX Interface;c:\windows\system32\drivers\a016obex.sys [2009-9-6 100648] S3 getPlusHelper;getPlus® Helper;c:\windows\system32\svchost.exe -k getPlusHelper [2009-9-1 21504] =============== Created Last 30 ================ 2009-09-13 21:17 –d—– c:\users\user\appdata\roaming\Malwarebytes 2009-09-13 21:17 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-09-13 21:17 19,160 a——- c:\windows\system32\drivers\mbam.sys 2009-09-13 21:17 –d—– c:\programdata\Malwarebytes 2009-09-13 21:17 –d—– c:\program files\Malwarebytes 2009-09-13 21:17 –d—– c:\progra~2\Malwarebytes 2009-09-13 21:12 218,320,406 a——- c:\windows\MEMORY.DMP 2009-09-13 07:02 –d—– c:\windows\Panther 2009-09-13 07:02 8,192 a–s-r– C:\BOOTSECT.BAK 2009-09-13 07:02 333,257 a–shr– C:\bootmgr 2009-09-13 07:02 –dsh— C:\Boot 2009-09-12 22:39 108,552 a——- c:\windows\system32\drivers\avgtdix.sys 2009-09-12 22:39 11,952 a——- c:\windows\system32\avgrsstx.dll 2009-09-12 22:39 335,240 a——- c:\windows\system32\drivers\avgldx86.sys 2009-09-12 22:39 –d—– c:\windows\system32\drivers\Avg 2009-09-12 22:38 –d—– c:\programdata\avg8 2009-09-12 22:38 –d—– c:\program files\AVG 2009-09-12 22:38 –d—– c:\progra~2\avg8 2009-09-12 22:30 –d—– c:\programdata\InstallShield 2009-09-12 22:30 –d—– c:\program files\Roxio 2009-09-12 22:26 1,524,736 a——- c:\windows\system32\wucltux.dll 2009-09-12 22:26 83,456 a——- c:\windows\system32\wudriver.dll 2009-09-12 22:26 162,064 a——- c:\windows\system32\wuwebv.dll 2009-09-12 22:26 31,232 a——- c:\windows\system32\wuapp.exe 2009-09-12 22:24 –d—– C:\Intel 2009-09-12 22:23 1,904 ——– c:\windows\system32\SetupBD.din 2009-09-12 22:23 228,224 a——- c:\windows\system32\drivers\e1e6032.sys 2009-09-12 22:23 179,048 a——- c:\windows\system32\e1000msg.dll 2009-09-12 22:23 154,496 a——- c:\windows\system32\Prounstl.exe 2009-09-12 22:23 39,288 a——- c:\windows\system32\NicInE6.dll 2009-09-12 22:23 28,536 a——- c:\windows\system32\NicCo6.dll 2009-09-12 22:23 2,689 a——- c:\windows\system32\e1e6032.din 2009-09-12 22:22 –d—– C:\dell 2009-09-12 22:21 –d—– c:\programdata\NVIDIA 2009-09-12 22:20 1,079,840 a——- c:\windows\system32\nvcpluir.dll 2009-09-12 22:20 768,544 a——- c:\windows\system32\nvcplui.exe 2009-09-12 22:20 420,384 a——- c:\windows\system32\nvcpl.cpl 2009-09-12 22:20 313,888 a——- c:\windows\system32\nvexpbar.dll 2009-09-12 22:20 453,152 a——- c:\windows\system32\nvuninst.exe 2009-09-12 22:12 –d—– c:\windows\system32\vmm32 2009-09-12 22:12 –d—– c:\program files\Dell 2009-09-12 22:12 –dsh— c:\windows\Installer 2009-09-12 22:11 –d—– c:\users\User 2009-09-08 17:46 –d—– c:\programdata\Sports Interactive 2009-09-08 17:46 –d—– c:\progra~2\Sports Interactive 2009-09-08 17:44 507,400 a——- c:\windows\system32\XAudio2_1.dll 2009-09-08 17:33 –d—– c:\program files\PowerISO 2009-09-07 19:30 –d—– c:\users\user\appdata\roaming\Sports Interactive 2009-09-07 19:22 –d-h— c:\program files\Zero G Registry 2009-09-07 19:22 –d—– c:\program files\Games 2009-09-07 19:20 –d-h— c:\users\user\InstallAnywhere 2009-09-06 14:35 –d—– c:\programdata\BVRP Software 2009-09-06 14:35 –d—– c:\program files\Avanquest update 2009-09-06 14:02 100,648 a——- c:\windows\system32\drivers\a016obex.sys 2009-09-06 14:02 12,200 a——- c:\windows\system32\drivers\a016whnt.sys 2009-09-06 14:02 12,200 a——- c:\windows\system32\drivers\a016wh.sys 2009-09-06 14:02 110,504 a——- c:\windows\system32\drivers\a016mdm.sys 2009-09-06 14:02 104,488 a——- c:\windows\system32\drivers\a016mgmt.sys 2009-09-06 14:02 83,880 a——- c:\windows\system32\drivers\a016bus.sys 2009-09-06 14:02 15,016 a——- c:\windows\system32\drivers\a016mdfl.sys 2009-09-06 14:02 12,200 a——- c:\windows\system32\drivers\a016cmnt.sys 2009-09-06 14:02 12,200 a——- c:\windows\system32\drivers\a016cm.sys 2009-09-06 14:02 –d—– c:\programdata\Sony Ericsson 2009-09-06 14:02 –d—– c:\program files\Sony Ericsson 2009-09-06 14:02 –d—– c:\progra~2\Sony Ericsson 2009-09-05 10:37 –d—– c:\program files\Trend Micro 2009-09-05 10:07 225,280 a——- c:\windows\system32\rewire.dll 2009-09-05 10:07 –d—– c:\program files\VstPlugins 2009-09-05 10:07 1,294,336 a——- c:\windows\system32\vorbis.acm 2009-09-05 10:06 –d—– c:\program files\Outsim 2009-09-05 10:06 –d—– c:\program files\Image-Line 2009-09-05 08:49 –d—– c:\programdata\Google 2009-09-05 08:48 –d—– c:\programdata\NOS 2009-09-04 21:41 –d—– c:\program files\uTorrent 2009-09-04 21:38 –d—– c:\users\user\appdata\roaming\uTorrent 2009-09-04 20:43 –d-h— C:\$AVG8.VAULT$ 2009-09-04 20:24 4,240,384 a——- c:\windows\system32\GameUXLegacyGDFs.dll 2009-09-04 20:24 28,672 a——- c:\windows\system32\Apphlpdm.dll 2009-09-01 10:27 –d—– c:\windows\system32\eu-ES 2009-09-01 10:27 –d—– c:\windows\system32\ca-ES 2009-09-01 10:26 –d—– c:\windows\system32\vi-VN 2009-09-01 10:26 0 a—h— c:\windows\system32\drivers\Msft_User_WpdFs_01_00_00.Wdf 2009-09-01 10:26 0 a—h— c:\windows\system32\drivers\Msft_User_AuxiliaryDisplayEnhancedDriver_01_00_00.Wdf 2009-09-01 10:25 –d—– c:\windows\system32\SPReview 2009-09-01 09:59 –d—– C:\PerfLogs 2009-09-01 09:34 193,024 a——- c:\windows\system32\recdisc.exe 2009-09-01 09:34 6,656 a——- c:\windows\system32\sdspres.dll 2009-09-01 09:34 28,160 a——- c:\windows\system32\sxproxy.dll 2009-09-01 09:32 2,585,088 a——- c:\windows\system32\FirewallControlPanel.exe 2009-09-01 09:30 327,680 a——- c:\windows\SPInstall.etl 2009-09-01 09:29 –d—– c:\windows\system32\EventProviders 2009-08-31 23:48 2,048 a——- c:\windows\system32\tzres.dll 2009-08-31 23:47 272,896 a——- c:\windows\system32\polstore.dll 2009-08-31 23:47 61,440 a——- c:\windows\system32\winipsec.dll 2009-08-31 23:46 1,820 a——- c:\windows\system32\rasctrnm.h 2009-08-31 23:43 69,632 a——- c:\windows\system32\Mpeg2Data.ax 2009-08-31 23:41 12,880 a——- c:\windows\system32\wbem\wlan.mof 2009-08-31 23:40 2,034,688 a——- c:\windows\system32\win32k.sys 2009-08-31 23:39 156,672 a——- c:\windows\system32\t2embed.dll 2009-08-31 23:39 289,792 a——- c:\windows\system32\atmfd.dll 2009-08-31 23:39 72,704 a——- c:\windows\system32\fontsub.dll 2009-08-31 23:39 34,304 a——- c:\windows\system32\atmlib.dll 2009-08-31 23:39 23,552 a——- c:\windows\system32\lpk.dll 2009-08-31 23:39 10,240 a——- c:\windows\system32\dciman32.dll 2009-08-31 23:35 71,680 a——- c:\windows\system32\atl.dll 2009-08-31 23:29 160,256 a——- c:\windows\system32\wkssvc.dll 2009-08-31 23:28 136,192 a——- c:\windows\system32\aaclient.dll 2009-08-31 23:28 2,066,432 a——- c:\windows\system32\mstscax.dll 2009-08-31 23:28 53,248 a——- c:\windows\system32\tsgqec.dll 2009-08-31 23:26 2,048 a——- c:\windows\system32\msxml3r.dll 2009-08-31 23:21 623,616 a——- c:\windows\system32\localspl.dll 2009-08-31 23:20 123,904 a——- c:\windows\system32\msvfw32.dll 2009-08-31 23:20 91,136 a——- c:\windows\system32\avifil32.dll 2009-08-31 23:20 65,024 a——- c:\windows\system32\avicap32.dll 2009-08-31 23:20 82,944 a——- c:\windows\system32\mciavi32.dll 2009-08-31 23:20 31,232 a——- c:\windows\system32\msvidc32.dll 2009-08-31 23:20 12,800 a——- c:\windows\system32\msrle32.dll 2009-08-31 23:15 175,104 a——- c:\windows\system32\wdigest.dll 2009-08-31 23:15 1,259,008 a——- c:\windows\system32\lsasrv.dll 2009-08-31 23:15 499,712 a——- c:\windows\system32\kerberos.dll 2009-08-31 23:15 439,864 a——- c:\windows\system32\drivers\ksecdd.sys 2009-08-31 23:15 218,624 a——- c:\windows\system32\msv1_0.dll 2009-08-31 23:15 72,704 a——- c:\windows\system32\secur32.dll 2009-08-31 23:15 9,728 a——- c:\windows\system32\lsass.exe 2009-08-31 23:15 270,848 a——- c:\windows\system32\schannel.dll 2009-08-31 23:15 13,780 a——- c:\windows\system32\wbem\lsasrv.mof 2009-08-31 23:11 4,497,408 a——- c:\windows\system32\NlsData0019.dll 2009-08-31 23:09 6,656 a——- c:\windows\system32\kbd106n.dll 2009-08-31 23:00 37,888 a——- c:\windows\system32\printcom.dll 2009-08-31 23:00 14,848 a——- c:\windows\system32\wshrm.dll 2009-08-31 22:59 313,344 a——- c:\windows\system32\wmpdxm.dll 2009-08-31 22:59 8,147,456 a——- c:\windows\system32\wmploc.DLL 2009-08-31 22:59 43,520 a——- c:\windows\system32\msdxm.tlb 2009-08-31 22:59 18,432 a——- c:\windows\system32\amcompat.tlb 2009-08-31 22:59 7,680 a——- c:\windows\system32\spwmp.dll 2009-08-31 22:59 4,096 a——- c:\windows\system32\msdxm.ocx 2009-08-31 22:59 4,096 a——- c:\windows\system32\dxmasf.dll 2009-08-31 22:51 19,857,408 a——- c:\windows\ocsetup_install_NetFx3.etl 2009-08-31 22:51 262,144 a——- c:\windows\ocsetup_cbs_install_NetFx3.perf 2009-08-31 22:51 65,536 a——- c:\windows\ocsetup_cbs_install_NetFx3.dpx 2009-08-31 22:49 41,984 a——- c:\windows\system32\netfxperf.dll 2009-08-31 22:45 84,480 a——- c:\windows\system32\INETRES.dll 2009-08-31 22:45 784,896 a——- c:\windows\system32\rpcrt4.dll 2009-08-31 22:44 –d—– c:\programdata\AVG Security Toolbar 2009-08-31 22:44 –d—– c:\progra~2\AVG Security Toolbar 2009-08-31 22:44 2,048 a——- c:\windows\system32\msxml6r.dll 2009-08-31 22:41 –d—– c:\programdata\Spybot - Search & Destroy 2009-08-31 22:41 –d—– c:\program files\Spybot - Search & Destroy 2009-08-31 22:41 –d—– c:\progra~2\Spybot - Search & Destroy ==================== Find3M ==================== 2009-09-06 14:35 143,360 a——- c:\windows\inf\infstrng.dat 2009-09-06 14:35 143,360 a——- c:\windows\inf\infstor.dat 2009-09-06 14:35 51,200 a——- c:\windows\inf\infpub.dat 2009-09-01 10:26 665,600 a——- c:\windows\inf\drvindex.dat 2009-09-01 10:09 174 a–sh— c:\program files\desktop.ini 2009-09-01 09:51 101,888 a——- c:\windows\system32\ifxcardm.dll 2009-09-01 09:50 82,432 a——- c:\windows\system32\axaltocm.dll 2009-08-31 23:27 52,736 a——- c:\windows\apppatch\iebrshim.dll 2009-08-31 23:11 2,599,936 a——- c:\windows\system32\NlsData0001.dll 2009-08-29 03:30 173,056 a——- c:\windows\apppatch\AcXtrnal.dll 2009-08-29 03:30 458,752 a——- c:\windows\apppatch\AcSpecfc.dll 2009-08-29 03:30 2,159,616 a——- c:\windows\apppatch\AcGenral.dll 2009-08-29 03:30 542,720 a——- c:\windows\apppatch\AcLayers.dll 2009-08-14 17:27 904,776 a——- c:\windows\system32\drivers\tcpip.sys 2009-08-14 16:53 17,920 a——- c:\windows\system32\netevent.dll 2009-08-14 14:49 9,728 a——- c:\windows\system32\TCPSVCS.EXE 2009-08-14 14:49 17,920 a——- c:\windows\system32\ROUTE.EXE 2009-08-14 14:49 11,264 a——- c:\windows\system32\MRINFO.EXE 2009-08-14 14:49 27,136 a——- c:\windows\system32\NETSTAT.EXE 2009-08-14 14:49 19,968 a——- c:\windows\system32\ARP.EXE 2009-08-14 14:49 8,704 a——- c:\windows\system32\HOSTNAME.EXE 2009-08-14 14:49 10,240 a——- c:\windows\system32\finger.exe 2009-08-14 14:48 30,720 a——- c:\windows\system32\drivers\tcpipreg.sys 2009-08-14 14:48 105,984 a——- c:\windows\system32\netiohlp.dll 2009-07-27 03:43 58,908 a——- c:\windows\system32\drivers\scdemu.sys 2009-07-21 22:52 915,456 a——- c:\windows\system32\wininet.dll 2009-07-21 22:47 109,056 a——- c:\windows\system32\iesysprep.dll 2009-07-21 22:47 71,680 a——- c:\windows\system32\iesetup.dll 2009-07-21 21:13 133,632 a——- c:\windows\system32\ieUnatt.exe 2009-07-11 20:01 513,536 a——- c:\windows\system32\wlansvc.dll 2009-07-11 20:01 302,592 a——- c:\windows\system32\wlansec.dll 2009-07-11 20:01 293,376 a——- c:\windows\system32\wlanmsm.dll 2009-07-11 20:01 65,024 a——- c:\windows\system32\wlanapi.dll 2009-07-11 18:03 127,488 a——- c:\windows\system32\L2SecHC.dll 2006-11-02 13:42 287,440 a——- c:\windows\inf\perflib\0409\perfi.dat 2006-11-02 13:42 287,440 a——- c:\windows\inf\perflib\0409\perfh.dat 2006-11-02 13:42 30,674 a——- c:\windows\inf\perflib\0409\perfd.dat 2006-11-02 13:42 30,674 a——- c:\windows\inf\perflib\0409\perfc.dat 2006-11-02 10:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat 2006-11-02 10:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat 2006-11-02 10:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat 2006-11-02 10:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat ============= FINISH: 18:16:23.74 =============== UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_09-07-30.01) Microsoft® Windows Vista™ Home Premium Boot Device: \Device\HarddiskVolume1 Install Date: 12/09/2009 22:07:22 System Uptime: 14/09/2009 18:09:35 (0 hours ago) Motherboard: Dell Inc. | | 0TP406 Processor: Intel® Core™2 Quad CPU Q6600 @ 2.40GHz | CPU | 2394/1066mhz ==== Disk Partitions ========================= C: is FIXED (NTFS) - 596 GiB total, 523.697 GiB free. D: is CDROM (CDFS) E: is Removable F: is Removable G: is Removable H: is Removable I: is CDROM () ==== Disabled Device Manager Items ============= ==== System Restore Points =================== ==== Installed Programs ====================== Adobe Download Manager Adobe Flash Player 10 ActiveX Ambient Keys 1.5 µTorrent Avanquest update AVG Free 8.5 Collab Dell Resource CD FL Studio 8 Football Manager 2009 Google Toolbar for Internet Explorer HijackThis 2.0.2 Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) IL Download Manager Intel® PRO Network Connections Drivers Malwarebytes' Anti-Malware Microsoft .NET Framework 3.5 SP1 Microsoft Visual C++ 2005 Redistributable NVIDIA Drivers PoiZone PowerISO Sony Ericsson PC Suite 3.204.00 Spybot - Search & Destroy Toxic Biohazard Update for Microsoft .NET Framework 3.5 SP1 (KB963707) WinRAR archiver ==== End Of File =========================== AVG still detectsthe infected file, I also had a few blue screens but that may have something to do with the GMER scan. My computer also mysteriously restarted. Which was the other question u wanted me to answer? Cheers
Hello.

Sorry for the delay.

AVG still detectsthe infected file, I also had a few blue screens but that may have something to do with the GMER scan. My computer also mysteriously restarted. Which was the other question u wanted me to answer?

Yes this is the question I wanted you to answer. Which infected file is this? Location and file name please. Does the restart happen everyday? Please elaborate.

I want you to run an online scan…

Run Scan with Kaspersky

Please do a scan with Kaspersky Online Scanner. Please note: Kaspersky requires Java Runtime Environment (JRE) be installed before scanning for malware, as ActiveX is no longer being used.)

If you are using Windows Vista, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.


  • Open the Kaspersky WebScanner
    page.
  • Click on the 🖼Click to load external image (Posted Image) button on the main page.
  • The program will launch and fill in the Information section on the left.
  • Read the "Requirements and Limitations" then press the 🖼Click to load external image (Posted Image) button.
  • The program will begin downloading the latest program and definition files. It may take a while so please be patient and let it finish.
  • Once the files have been downloaded, click on the 🖼Click to load external image (Posted Image) …button.
    In the scan settings make sure the following are selected:
    • Detect malicious programs of the following categories:
      Viruses, Worms, Trojan Horses, Rootkits
      Spyware, Adware, Dialers and other potentially dangerous programs
    • Scan compound files (doesn't apply to the File scan area):
      Archives
      Mail databases
      By default the above items should already be checked.
    • Click the 🖼Click to load external image (Posted Image) button, if you made any changes.
  • Now under the Scan section on the left:

    Select My Computer
  • The program will now start and scan your system. This will run for a while, be patient and let it finish.
  • Once the scan is complete, click on View scan report
  • Now, click on the Save Report as button.
  • Save the file to your desktop.
  • Copy and paste that information in your next post.
You can refer to this animation by sundavis if needed.

With Regards,
Extremeby

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI