This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] 4-5-6 clicks to use the mouse 'baseline' after malwar

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hey folks and thanks for being this resource!

I have had a continuing reduction of usability in this windows vista, HP 8300f, desktop. Have had various security programs running and had received warnings about wild tangent games and ignored these warnings after contact with wild tangent. I have attempted to delete all the auto-downloader games and still have 2 that won't uninstall. the remote control will work for a day and then error with a 'previous version of driver in memory' error. no way to fix except reboot. Are we evedently infected with something? AVG identified a downloader, 'zlob', and some tracking cookies. I've gone through the malware removal process, reports copied below. The symptoms now are that clicking on a connection is problematic. i can click 4 or 5 or 6 times and the computer seems not to recognize the pushing of the button. the mouse seems to be ok as the cursor will move around the screen but won't 'click'?? is there some way of checking for a hardware problem with the left button on the mouse?

This is a family computer with games, pictures and music used for facebook, myspace, e-mail and streaming music through both last.fm and pandora. i do NOT use it for any financial information and all purchases are through Paypal on e-bay or Amazon.

Following is the HijackThis file and attached are the dds and rootrepeal. I've run Malwarebytes' Anti-Malware program and it identified and removed files. these logs are also included.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:24:30 AM, on 9/16/2009
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18813)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\hp\support\hpsysdrv.exe
C:\Windows\system32\schtasks.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Windows\WindowsMobile\wmdc.exe
C:\Windows\System32\wpcumi.exe
C:\Program Files\AVG\AVG8\avgtray.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - MRI_DISABLED - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [hpsysdrv] "c:\hp\support\hpsysdrv.exe"
O4 - HKLM\..\Run: [SunJavaUpdateReg] "C:\Windows\system32\jureg.exe"
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [Windows Mobile Device Center] "C:\Windows\WindowsMobile\wmdc.exe"
O4 - HKLM\..\Run: [WPCUMI] "C:\Windows\system32\WpcUmi.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'NETWORK SERVICE')
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: MRI_DISABLED
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O13 - Gopher Prefix:
O16 - DPF: {2042B57E-6336-459E-B7CE-2A0F6C9E6AF8} (IEPlayInterface Class) - file:///F:/win/setup/iaieplay.dll
O16 - DPF: {8B67B37E-1AE2-4B99-B8CF-55AF4D58DF0D} (IAMCE Class) - file:///F:/win/setup/iamce.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

–
End of file - 8969 bytes

***** here are the MWBAM scans (original)******

Malwarebytes' Anti-Malware 1.41
Database version: 2808
Windows 6.0.6002 Service Pack 2

9/15/2009 10:51:53 PM
mbam-log-2009-09-15 (22-51-53).txt

Scan type: Quick Scan
Objects scanned: 100816
Time elapsed: 5 minute(s), 47 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 1
Folders Infected: 0
Files Infected: 3

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowSearch (Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Users\Owner\downloads\WebfettiSetup2.3.50.45.ZKfox000.exe (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Users\Owner\downloads\WebfettiSetup2.3.50.45.ZKfox000(2).exe (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Users\Owner\downloads\WebfettiSetup2.3.50.45.ZKfox000(3).exe (Adware.MyWebSearch) -> Quarantined and deleted successfully.


****and then the most recent*****

Malwarebytes' Anti-Malware 1.41
Database version: 2809
Windows 6.0.6002 Service Pack 2

9/16/2009 6:31:32 AM
mbam-log-2009-09-16 (06-31-32).txt

Scan type: Quick Scan
Objects scanned: 99647
Time elapsed: 5 minute(s), 10 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

**** thanks for any wisdom you can provide!*****

Wow! clicking was a hardware problem, and it's solved! New logitech mouse solved the mouse problem. Can broadband connection be 'shaved'? Can't stream last.fm. loading of pages through firefox seems like dial-up connection.
Hi,

It would appear as if Malwarebytes cleaned up your computer as there is nothing obvious in the logs,

but lets do an online scan just to make sure.

Using Internet Explorer or Firefox, visit Kaspersky Online Scanner:

1. Click Accept, when prompted to download and install the program files and database of malware definitions.


2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan

3. Click Run at the Security prompt. The program will then begin downloading and installing and will also update the database. Please be patient as this can take several minutes.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.

    [external image: Posted Image]

  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply
Kaspersky showed no infections, AVG log showed last scan interrupted. previous scan shows no problems. Hard drive light was constantly running, is there a way of checking for current condition? The light is off this morning. Malwarebyte's anti-malware program is blocked from loading by Vista. Is this normal? Should i uninstall it? Thanks for your help.

Malwarebyte's anti-malware program is blocked from loading by Vista. Is this normal?


no that is not normal…what message are you getting?

please run the following scans.

  • Please save Win32kDiag to your desktop.
  • Double-click on it to run a scan.
  • When it's finished, there will be a log called Win32kDiag.txt on your desktop.
  • Please open it with notepad and post the contents here.


NEXT


Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.pif to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.

NEXT


[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your next reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
message is: Vista security center has prevented a program from loading. It then gives me a opportunity to select and manually load the program. it seems to load successfully. also there is a temp file 'diylog.txt" it is 0 bytes and was modified 10.06.08 that cannot be deleted. I have used cc cleaner and the one in your malware removal process, without success. i also have 2 games that have loaded through the HP-Wild Tangent port that i cannot uninstall. will post logs you requested tonight.
CB,

ok more info and conditions. there are three users on this computer: Owner, Administrator, and Joshua. the Owner user is what is normally running. i set up the administrator account to let 'spybot sd' run as an administrator.

under the Owner id: today the hard drive would go into super fast 'whirring' periodically while i was using Firefox online.Tonight as i rebooted from windows update, Malwarebyte's was prevented from loading by windows and now a NEW condition: windows security center shows AVG as disabled and the only choices are to uninstall or download another program from the internet!?

i am running these new scans under the administrator id as it is having none of these problems. should i run the scans under the OWNER id also? . i have a game that doesn't recognize my owner key under the Admin id. how concrete are the separations for a user id, could a malware infection be localized to only one id? did i just answer my own question! you do want new scans under the owner id! please start over with the list, if so.

thanks for your help on this

R

*******
Win32kDiag.txt

Running from: C:\Users\[removed]\Desktop\Win32kDiag.exe

Log file at : C:\Users\Administrator\Desktop\Win32kDiag.txt

WARNING: Could not get backup privileges!

Searching 'C:\Windows'…



Cannot access: C:\Windows\bthservsdp.dat

[1] 2009-09-22 20:07:41 12 C:\Windows\bthservsdp.dat (

******************
DDS (Ver_09-07-30.01) - NTFSx86
Run by [removed] at 20:28:10.97 on Tue 09/22/2009
Internet Explorer: 8.0.6001.18813 BrowserJavaVersion: 1.6.0_15
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2942.1539 [GMT -6:00]

SP: Spybot - Search and Destroy *enabled* (Updated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\nvvsvc.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k hpdevmgmt
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\Smith Micro\StuffIt 2009\ArcNameService.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\hp\support\hpsysdrv.exe
C:\Windows\system32\schtasks.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Windows\WindowsMobile\wmdc.exe
C:\Windows\System32\wpcumi.exe
C:\Program Files\AVG\AVG8\avgtray.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\System32\mobsync.exe
C:\Windows\system32\svchost.exe -k WindowsMobile
C:\Windows\ehome\ehsched.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\ehome\ehRecvr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\RacAgent.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\explorer.exe
C:\Users\Administrator\Desktop\malware removal\dds.pif
C:\Windows\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=desktop
uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=desktop
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=desktop
mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=desktop
uURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg8\toolbar\IEToolbar.dll
uURLSearchHooks: H - No File
BHO: MRI_DISABLED - No File
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - No File
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg8\toolbar\IEToolbar.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.3572\swg.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
TB: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - c:\program files\avg\avg8\toolbar\IEToolbar.dll
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide
mRun: [hpsysdrv] "c:\hp\support\hpsysdrv.exe"
mRun: [SunJavaUpdateReg] "c:\windows\system32\jureg.exe"
mRun: [RtHDVCpl] RtHDVCpl.exe
mRun: [HP Software Update] "c:\program files\hp\hp software update\HPWuSchd2.exe"
mRun: [Windows Mobile Device Center] "c:\windows\windowsmobile\wmdc.exe"
mRun: [WPCUMI] "c:\windows\system32\WpcUmi.exe"
mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
StartupFolder: c:\users\admini~1\appdata\roaming\micros~1\windows\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\mri_di~1\snapfi~1.lnk - c:\program files\snapfish picture mover\SnapfishMediaDetector.exe
uPolicies-explorer: NoDesktopCleanupWizard = 1 (0x1)
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll
IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\windows\windowsmobile\INetRepl.dll
IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\windows\windowsmobile\INetRepl.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
LSP: c:\windows\system32\wpclsp.dll
DPF: {2042B57E-6336-459E-B7CE-2A0F6C9E6AF8} - file:///F:/win/setup/iaieplay.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {8B67B37E-1AE2-4B99-B8CF-55AF4D58DF0D} - file:///F:/win/setup/iamce.dll
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
AppInit_DLLs: avgrsstx.dll

================= FIREFOX ===================

FF - ProfilePath - c:\users\admini~1\appdata\roaming\mozilla\firefox\profiles\0nmd4l7d.default\
FF - component: c:\program files\avg\avg8\firefox\components\avgssff.dll
FF - plugin: c:\program files\google\google updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\microsoft\office live\npOLW.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npatgpc.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}

—- FIREFOX POLICIES —-
c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\mozilla firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");

============= SERVICES / DRIVERS ===============

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-8-26 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-8-26 108552]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2009-8-26 297752]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search & destroy\SDWinSec.exe [2009-8-28 1153368]
R2 Stuffit Archive Name Service;Stuffit Archive Name Service;c:\program files\smith micro\stuffit 2009\ArcNameService.exe [2008-12-19 199000]
R3 HCW85BDA;Hauppauge WinTV 885 Video Capture;c:\windows\system32\drivers\HCW85BDA.sys [2008-12-3 1426304]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2009-9-15 38224]
S3 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr.sys [2008-12-22 55264]
S3 fsssvc;Windows Live Family Safety;c:\program files\windows live\family safety\fsssvc.exe [2008-12-8 533344]
S3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\drivers\motccgp.sys [2007-11-2 18176]
S3 motccgpfl;MotCcgpFlService;c:\windows\system32\drivers\motccgpfl.sys [2007-1-22 7680]
S3 MotDev;Motorola Inc. USB Device;c:\windows\system32\drivers\motodrv.sys [2007-10-10 42112]
S3 motport;Motorola USB Diagnostic Port;c:\windows\system32\drivers\motport.sys [2007-6-18 23680]

=============== Created Last 30 ================

2009-09-22 18:20 4,984 a——- c:\windows\system32\drivers\nvphy.bin
2009-09-22 18:20 –d—– c:\windows\nvtmpinst
2009-09-21 04:40 –d—– c:\programdata\Smith Micro
2009-09-21 04:40 –d—– c:\progra~2\Smith Micro
2009-09-21 04:40 –d—– c:\program files\Smith Micro
2009-09-16 06:39 15 a——- c:\windows\system32\settings.dat
2009-09-15 23:42 –d—– c:\program files\Trend Micro
2009-09-15 22:39 –d—– c:\users\admini~1\appdata\roaming\Malwarebytes
2009-09-15 22:39 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-15 22:39 19,160 a——- c:\windows\system32\drivers\mbam.sys
2009-09-15 22:39 –d—– c:\programdata\Malwarebytes
2009-09-15 22:39 –d—– c:\program files\Malwarebytes' Anti-Malware
2009-09-15 22:39 –d—– c:\progra~2\Malwarebytes
2009-09-14 10:04 107,368 a——- c:\windows\system32\GEARAspi.dll
2009-09-14 10:04 26,600 a——- c:\windows\system32\drivers\GEARAspiWDM.sys
2009-09-14 10:03 –d—– c:\program files\iPod
2009-09-14 10:03 –d—– c:\programdata\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-09-14 10:03 –d—– c:\progra~2\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-09-14 10:03 –d—– c:\program files\iTunes
2009-09-14 10:03 –d—– c:\program files\Bonjour
2009-09-14 10:02 –d—– c:\programdata\Apple Computer
2009-09-08 22:42 –dsh— c:\windows\system32\%APPDATA%
2009-09-05 01:54 94,208 a——- c:\windows\system32\QuickTimeVR.qtx
2009-09-05 01:54 69,632 a——- c:\windows\system32\QuickTime.qts
2009-09-02 12:31 83,927 a——- c:\programdata\nvModes.dat
2009-09-02 12:31 83,927 a——- c:\progra~2\nvModes.dat
2009-09-02 12:07 28,672 a——- c:\windows\system32\Apphlpdm.dll
2009-09-02 12:07 4,240,384 a——- c:\windows\system32\GameUXLegacyGDFs.dll
2009-09-02 11:39 –d—– C:\NVIDIA
2009-09-02 11:22 –d—– c:\program files\SystemRequirementsLab
2009-09-02 11:07 54,156 a—h— c:\windows\QTFont.qfn
2009-09-02 11:07 1,409 a——- c:\windows\QTFont.for
2009-09-02 08:24 –d—– c:\users\Administrator
2009-08-29 06:50 411,368 a——- c:\windows\system32\deploytk.dll
2009-08-28 11:00 –d—– c:\programdata\Spybot - Search & Destroy
2009-08-28 11:00 –d—– c:\program files\Spybot - Search & Destroy
2009-08-28 11:00 –d—– c:\progra~2\Spybot - Search & Destroy
2009-08-28 10:29 –d—– c:\program files\SpywareBlaster
2009-08-28 03:28 55,656 a——- c:\windows\system32\drivers\avgntflt.sys
2009-08-27 06:40 –d—– c:\program files\CCleaner
2009-08-26 23:09 –d-h— C:\$AVG8.VAULT$
2009-08-26 22:12 108,552 a——- c:\windows\system32\drivers\avgtdix.sys
2009-08-26 22:12 11,952 a——- c:\windows\system32\avgrsstx.dll
2009-08-26 22:12 335,240 a——- c:\windows\system32\drivers\avgldx86.sys
2009-08-26 22:12 –d—– c:\windows\system32\drivers\Avg
2009-08-26 22:11 –d—– c:\programdata\AVG Security Toolbar
2009-08-26 22:11 –d—– c:\progra~2\AVG Security Toolbar
2009-08-26 22:11 –d—– c:\programdata\avg8
2009-08-26 22:11 –d—– c:\program files\AVG
2009-08-26 22:11 –d—– c:\progra~2\avg8
2009-08-26 03:14 –dsh— C:\found.001
2009-08-26 03:01 2,048 a——- c:\windows\system32\tzres.dll

==================== Find3M ====================

2009-09-22 20:06 143,360 a——- c:\windows\inf\infstrng.dat
2009-09-22 20:06 51,200 a——- c:\windows\inf\infpub.dat
2009-09-22 18:21 143,360 a——- c:\windows\inf\infstor.dat
2009-08-28 20:30 173,056 a——- c:\windows\apppatch\AcXtrnal.dll
2009-08-28 20:30 458,752 a——- c:\windows\apppatch\AcSpecfc.dll
2009-08-28 20:30 2,159,616 a——- c:\windows\apppatch\AcGenral.dll
2009-08-28 20:30 542,720 a——- c:\windows\apppatch\AcLayers.dll
2009-08-17 02:42 2,173,472 a——- c:\windows\system32\nvcplui.exe
2009-08-17 02:42 1,346,080 a——- c:\windows\system32\nvsvs.dll
2009-08-17 02:41 3,176,992 a——- c:\windows\system32\nvwss.dll
2009-08-17 02:41 4,033,056 a——- c:\windows\system32\nvvitvs.dll
2009-08-17 02:41 1,292,832 a——- c:\windows\system32\nvmobls.dll
2009-08-17 02:41 195,104 a——- c:\windows\system32\nvmccss.dll
2009-08-17 02:41 3,553,824 a——- c:\windows\system32\nvgames.dll
2009-08-17 02:41 13,904,416 a——- c:\windows\system32\nvcpl.dll
2009-08-17 02:41 4,930,080 a——- c:\windows\system32\nvdisps.dll
2009-08-17 02:41 764,448 a——- c:\windows\system32\nvsvc.dll
2009-08-17 02:41 215,584 a——- c:\windows\system32\nvvsvc.exe
2009-08-17 02:41 143,360 a——- c:\windows\system32\nvshext.dll
2009-08-17 02:41 92,704 a——- c:\windows\system32\nvmctray.dll
2009-08-17 00:57 10,858,496 a——- c:\windows\system32\nvoglv32.dll
2009-08-17 00:57 9,545,152 a——- c:\windows\system32\drivers\nvlddmkm.sys
2009-08-17 00:57 7,569,920 a——- c:\windows\system32\nvd3dum.dll
2009-08-17 00:57 2,169,376 a——- c:\windows\system32\nvcuvid.dll
2009-08-17 00:57 1,985,536 a——- c:\windows\system32\nvcuda.dll
2009-08-17 00:57 1,706,528 a——- c:\windows\system32\nvcuvenc.dll
2009-08-17 00:57 1,044,992 a——- c:\windows\system32\nvapi.dll
2009-08-17 00:57 485,920 a——- c:\windows\system32\nvudisp.exe
2009-08-17 00:57 155,648 a——- c:\windows\system32\nvcod162.dll
2009-08-17 00:57 155,648 a——- c:\windows\system32\nvcod.dll
2009-08-17 00:57 4,224 a——- c:\windows\system32\drivers\nvBridge.kmd
2009-08-14 11:07 0 a—h— c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
2009-08-14 10:27 904,776 a——- c:\windows\system32\drivers\tcpip.sys
2009-08-14 09:53 17,920 a——- c:\windows\system32\netevent.dll
2009-08-14 07:49 9,728 a——- c:\windows\system32\TCPSVCS.EXE
2009-08-14 07:49 17,920 a——- c:\windows\system32\ROUTE.EXE
2009-08-14 07:49 11,264 a——- c:\windows\system32\MRINFO.EXE
2009-08-14 07:49 27,136 a——- c:\windows\system32\NETSTAT.EXE
2009-08-14 07:49 19,968 a——- c:\windows\system32\ARP.EXE
2009-08-14 07:49 8,704 a——- c:\windows\system32\HOSTNAME.EXE
2009-08-14 07:49 10,240 a——- c:\windows\system32\finger.exe
2009-08-14 07:48 30,720 a——- c:\windows\system32\drivers\tcpipreg.sys
2009-08-14 07:48 105,984 a——- c:\windows\system32\netiohlp.dll
2009-08-11 12:35 485,920 a——- c:\windows\system32\nvuninst.exe
2009-08-04 09:48 2,744,800 a——- c:\windows\system32\drivers\RTKVHDA.sys
2009-08-04 09:17 1,265,696 a——- c:\windows\system32\RtkPgExt.dll
2009-08-04 09:17 52,256 a——- c:\windows\system32\RtkCoInst.dll
2009-08-04 09:17 133,664 a——- c:\windows\RTKAUDIOSERVICE.EXE
2009-08-04 09:17 2,898,464 a——- c:\windows\system32\RtkAPO.dll
2009-08-04 09:17 326,176 a——- c:\windows\system32\RtkApoApi.dll
2009-08-03 15:07 403,816 a——- c:\windows\system32\OGACheckControl.dll
2009-08-03 15:07 322,928 a——- c:\windows\system32\OGAAddin.dll
2009-08-03 15:07 230,768 a——- c:\windows\system32\OGAEXEC.exe
2009-07-21 15:52 915,456 a——- c:\windows\system32\wininet.dll
2009-07-21 15:47 109,056 a——- c:\windows\system32\iesysprep.dll
2009-07-21 15:47 71,680 a——- c:\windows\system32\iesetup.dll
2009-07-21 14:13 133,632 a——- c:\windows\system32\ieUnatt.exe
2009-07-21 14:01 266,240 a——- c:\windows\system32\FMAPO.dll
2009-07-17 07:54 71,680 a——- c:\windows\system32\atl.dll
2009-07-15 06:40 8,147,456 a——- c:\windows\system32\wmploc.DLL
2009-07-15 06:39 313,344 a——- c:\windows\system32\wmpdxm.dll
2009-07-15 06:39 4,096 a——- c:\windows\system32\dxmasf.dll
2009-07-15 06:39 7,680 a——- c:\windows\system32\spwmp.dll
2009-07-11 13:01 513,536 a——- c:\windows\system32\wlansvc.dll
2009-07-11 13:01 302,592 a——- c:\windows\system32\wlansec.dll
2009-07-11 13:01 293,376 a——- c:\windows\system32\wlanmsm.dll
2009-07-11 13:01 65,024 a——- c:\windows\system32\wlanapi.dll
2009-07-11 11:03 127,488 a——- c:\windows\system32\L2SecHC.dll
2009-06-30 01:39 665,600 a——- c:\windows\inf\drvindex.dat
2008-06-07 13:52 174 a–sh— c:\program files\desktop.ini
2006-11-02 06:42 287,440 a——- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 06:42 287,440 a——- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 06:42 30,674 a——- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 06:42 30,674 a——- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 03:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 03:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 03:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 03:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat
2009-06-20 21:54 16,384 a–sh— c:\windows\serviceprofiles\networkservice\appdata\local\temp\cookies\index.dat
2009-06-20 21:54 16,384 a–sh— c:\windows\serviceprofiles\networkservice\appdata\local\temp\history\history.ie5\index.dat
2009-06-20 21:54 32,768 a–sh— c:\windows\serviceprofiles\networkservice\appdata\local\temp\temporary internet files\content.ie5\index.dat
2009-06-11 03:16 245,760 a–sh— c:\windows\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\ietldcache\index.dat
2007-11-23 12:01 8,192 a–sh— c:\windows\users\default\NTUSER.DAT

============= FINISH: 20:29:47.58 ===============
*******
GMER 1.0.15.15087 - http://www.gmer.net
Rootkit scan 2009-09-22 21:57:27
Windows 6.0.6002 Service Pack 2
Running: gmer.exe; Driver: C:\Users\ADMINI~1\AppData\Local\Temp\kwlcapow.sys


—- Devices - GMER 1.0.15 —-

AttachedDevice \Driver\tdx \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\tdx \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\tdx \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

—- Registry - GMER 1.0.15 —-

Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Media Center\Service\Scheduler@Heartbeat 0x50 0x7F 0x14 0xEC …

—- EOF - GMER 1.0.15 —-

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI