Storms
Topic Starter
Firefox keeps opening up error404.com tab when I use it, and I'm worried that my computer is infected with a virus, Trojan, malware software, and/or something nasty. I have since read through this forum, and taken all the recommended steps to self-removal, which includes running the ATF Cleaner and the Malwarebyte's Anti-Malware software. I've also made a backup of my registry with ERUNT. I'm just not very computer savvy so I'm unsure as to whether or not I've fixed the problem. I've included the RootRepeal, DDS, and the Malwarebyte Logs. I thank you in advance because I'm pretty worried.
RootRepeal -
ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2009/11/12 11:02
Program Version: Version 1.3.5.0
Windows Version: Windows Vista SP2
==================================================
Drivers
——————-
Name: dump_dumpata.sys
Image Path: C:\Windows\System32\Drivers\dump_dumpata.sys
Address: 0x8F37C000 Size: 45056 File Visible: No Signed: -
Status: -
Name: dump_msahci.sys
Image Path: C:\Windows\System32\Drivers\dump_msahci.sys
Address: 0x8F387000 Size: 40960 File Visible: No Signed: -
Status: -
Name: rootrepeal.sys
Image Path: C:\Windows\system32\drivers\rootrepeal.sys
Address: 0x9E5CF000 Size: 49152 File Visible: No Signed: -
Status: -
Processes
——————-
Path: System
PID: 4 Status: Locked to the Windows API!
Path: C:\Windows\System32\audiodg.exe
PID: 1528 Status: Locked to the Windows API!
SSDT
——————-
#: 194 Function Name: NtOpenProcess
Status: Hooked by "C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_Vista\AVGIDSShim.sys" at address 0x99714620
#: 334 Function Name: NtTerminateProcess
Status: Hooked by "C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_Vista\AVGIDSShim.sys" at address 0x997146d0
#: 335 Function Name: NtTerminateThread
Status: Hooked by "C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_Vista\AVGIDSShim.sys" at address 0x99714770
#: 358 Function Name: NtWriteVirtualMemory
Status: Hooked by "C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_Vista\AVGIDSShim.sys" at address 0x99714810
==EOF==
DDS Log -
DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 11:05:34.15 on Thu 11/12/2009
Internet Explorer: 7.0.6002.18005
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3066.1804 [GMT -5:00]
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\Windows\system32\lsm.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Program Files\Fingerprint Sensor\AtService.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_2ba5baa4\STacSV.exe
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\Ati2evxx.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\WLTRYSVC.EXE
C:\Windows\System32\bcmwltry.exe
C:\Windows\system32\WLANExt.exe
C:\Windows\System32\spoolsv.exe
C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe
C:\Program Files\DigitalPersona\Bin\DpHostW.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_2ba5baa4\aestsrv.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\DellTPad\Apoint.exe
C:\Windows\System32\WLTRAY.EXE
C:\Program Files\DigitalPersona\Bin\DpAgent.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\IDT\WDM\sttray.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Windows\system32\svchost.exe -k HPService
C:\Windows\system32\vssvc.exe
C:\Windows\System32\svchost.exe -k swprv
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\AVG\AVG9\avgam.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\Program Files\AVG\AVG9\avgemc.exe
C:\Program Files\AVG\AVG9\avgfws9.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\AVG\AVG9\avgtray.exe
C:\Program Files\AVG\AVG9\Identity Protection\agent\bin\avgidsmonitor.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Users\Josh\Desktop\RootRepeal.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\AVG\AVG9\avgui.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\Josh\Desktop\dds.scr
C:\Windows\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.com/
uWindow Title = Internet Explorer provided by Dell
uDefault_Page_URL = hxxp://www.dell.com
mDefault_Page_URL = hxxp://www.dell.com
uURLSearchHooks: H - No File
uURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg9\toolbar\IEToolbar.dll
mURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg9\toolbar\IEToolbar.dll
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_07\bin\ssv.dll
BHO: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg9\toolbar\IEToolbar.dll
TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - c:\program files\avg\avg9\toolbar\IEToolbar.dll
TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [Apoint] c:\program files\delltpad\Apoint.exe
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [Broadcom Wireless Manager UI] c:\windows\system32\WLTRAY.exe
mRun: [DpAgent] c:\program files\digitalpersona\bin\dpagent.exe
mRun: [AVG9_TRAY] c:\progra~1\avg\avg9\avgtray.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [SysTrayApp] %ProgramFiles%\IDT\WDM\sttray.exe
mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC} - c:\progra~1\java\jre16~1.0_0\bin\ssv.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll
Notify: GoToAssist - c:\program files\citrix\gotoassist\514\G2AWinLogon.dll
AppInit_DLLs: avgrsstx.dll
LSA: Notification Packages = scecli DPPWDFLT
================= FIREFOX ===================
FF - ProfilePath - c:\users\josh\appdata\roaming\mozilla\firefox\profiles\tuxos97j.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.newhaven.edu/15/
FF - component: c:\program files\avg\avg9\firefox\components\avgssff.dll
FF - component: c:\program files\avg\avg9\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\avg\avg9\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\avg\avg9\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\avg\avg9\toolbar\firefox\avg@igeared\components\xpavgtbapi.dll
FF - component: c:\program files\digitalpersona\bin\firefoxext\components\dpffcli.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
============= SERVICES / DRIVERS ===============
R0 AVGIDSErHrvtx;AVG9IDSErHr;c:\windows\system32\drivers\AVGIDSvx.sys [2009-11-5 25608]
R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [2009-1-21 161800]
R1 Avgfwfd;AVG network filter service;c:\windows\system32\drivers\avgfwd6x.sys [2009-1-21 24856]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-1-21 333192]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-1-21 360584]
R1 NEOFLTR_600_13319;Juniper Networks TDI Filter Driver (NEOFLTR_600_13319);c:\windows\system32\drivers\NEOFLTR_600_13319.sys [2008-6-24 64160]
R2 AESTFilters;Andrea ST Filters Service;c:\windows\system32\driverstore\filerepository\stwrt.inf_2ba5baa4\AEstSrv.exe [2009-1-14 73728]
R2 ATService;AuthenTec Fingerprint Service;c:\program files\fingerprint sensor\AtService.exe [2008-5-5 1168632]
R2 avg9emc;AVG E-mail Scanner;c:\program files\avg\avg9\avgemc.exe [2009-11-5 906520]
R2 avg9wd;AVG WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2009-11-5 285392]
R2 avgfws9;AVG Firewall;c:\program files\avg\avg9\avgfws9.exe [2009-11-9 2304192]
R2 AVGIDSAgent;AVG9IDSAgent;c:\program files\avg\avg9\identity protection\agent\bin\AVGIDSAgent.exe [2009-11-5 5832712]
R3 ATSwpWDF;AuthenTec TruePrint USB WDF Driver;c:\windows\system32\drivers\ATSwpWDF.sys [2009-1-14 475136]
R3 AVGIDSDrivervtx;AVG9IDSDriver;c:\program files\avg\avg9\identity protection\agent\driver\platform_vista\AVGIDSDriver.sys [2009-11-5 122376]
R3 AVGIDSFiltervtx;AVG9IDSFilter;c:\program files\avg\avg9\identity protection\agent\driver\platform_vista\AVGIDSFilter.sys [2009-11-5 30216]
R3 AVGIDSShimvtx;AVG9IDSShim;c:\program files\avg\avg9\identity protection\agent\driver\platform_vista\AVGIDSShim.sys [2009-11-5 27800]
R3 OA001Ufd;Creative Camera OA001 Upper Filter Driver;c:\windows\system32\drivers\OA001Ufd.sys [2009-3-6 133632]
R3 OA001Vid;Creative Camera OA001 Function Driver;c:\windows\system32\drivers\OA001Vid.sys [2009-3-8 280096]
S3 itecir;ITECIR Infrared Receiver;c:\windows\system32\drivers\itecir.sys [2009-1-14 54784]
S3 k57nd60x;Broadcom NetLink ™ Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\k57nd60x.sys [2009-1-14 203264]
S3 WSDPrintDevice;WSD Print Support via UMB;c:\windows\system32\drivers\WSDPrint.sys [2008-1-20 16896]
S4 DockLoginService;Dock Login Service;c:\program files\dell\delldock\DockLogin.exe [2008-9-23 155648]
=============== Created Last 30 ================
2009-11-12 10:40 –d—– c:\users\josh\appdata\roaming\Malwarebytes
2009-11-12 10:40 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2009-11-12 10:40 19,160 a——- c:\windows\system32\drivers\mbam.sys
2009-11-12 10:40 –d—– c:\programdata\Malwarebytes
2009-11-12 10:40 –d—– c:\program files\Malwarebytes' Anti-Malware
2009-11-12 10:40 –d—– c:\progra~2\Malwarebytes
2009-11-11 18:20 –d—– c:\program files\Microsoft Windows 7 Upgrade Advisor
2009-11-11 18:18 1,908 a——- c:\windows\diagwrn.xml
2009-11-11 18:18 1,908 a——- c:\windows\diagerr.xml
2009-11-11 09:46 2,036,736 a——- c:\windows\system32\win32k.sys
2009-11-11 09:46 355,328 a——- c:\windows\system32\WSDApi.dll
2009-11-09 22:29 –d—– c:\programdata\Defence
2009-11-09 22:29 –d—– c:\progra~2\Defence
2009-11-06 08:37 2,421,760 a——- c:\windows\system32\wucltux.dll
2009-11-06 08:36 87,552 a——- c:\windows\system32\wudriver.dll
2009-11-06 08:27 171,608 a——- c:\windows\system32\wuwebv.dll
2009-11-06 08:27 33,792 a——- c:\windows\system32\wuapp.exe
2009-11-06 00:22 –d—– c:\windows\system32\eu-ES
2009-11-06 00:22 –d—– c:\windows\system32\ca-ES
2009-11-06 00:22 –d—– c:\windows\system32\vi-VN
2009-11-05 14:14 –d—– c:\windows\system32\EventProviders
2009-11-05 08:55 –d-h— C:\$AVG
2009-11-05 08:54 25,608 a——- c:\windows\system32\drivers\AVGIDSvx.sys
2009-11-05 08:53 –d—– c:\programdata\avg9
2009-11-05 08:53 –d—– c:\progra~2\avg9
2009-11-04 21:54 –d—– c:\programdata\Microsoft Help
2009-10-27 21:26 310,784 a——- c:\windows\system32\unregmp2.exe
2009-10-27 21:26 8,147,456 a——- c:\windows\system32\wmploc.DLL
2009-10-14 16:14 60,928 a——- c:\windows\system32\msasn1.dll
2009-10-14 16:14 218,624 a——- c:\windows\system32\msv1_0.dll
2009-10-14 16:14 834,048 a——- c:\windows\system32\wininet.dll
2009-10-14 16:14 78,336 a——- c:\windows\system32\ieencode.dll
2009-10-14 16:14 3,600,456 a——- c:\windows\system32\ntkrnlpa.exe
2009-10-14 16:14 3,548,216 a——- c:\windows\system32\ntoskrnl.exe
2009-10-14 16:13 144,896 a——- c:\windows\system32\drivers\srv2.sys
2009-10-14 16:13 604,672 a——- c:\windows\system32\WMSPDMOD.DLL
==================== Find3M ====================
2009-11-09 08:23 360,584 a——- c:\windows\system32\drivers\avgtdix.sys
2009-11-06 00:31 143,360 a——- c:\windows\inf\infstrng.dat
2009-11-06 00:31 86,016 a——- c:\windows\inf\infstor.dat
2009-11-06 00:31 51,200 a——- c:\windows\inf\infpub.dat
2009-11-06 00:21 665,600 a——- c:\windows\inf\drvindex.dat
2009-11-05 08:55 333,192 a——- c:\windows\system32\drivers\avgldx86.sys
2009-11-05 08:54 12,464 a——- c:\windows\system32\avgrsstx.dll
2009-11-05 08:54 161,800 a——- c:\windows\system32\drivers\avgrkx86.sys
2009-11-05 08:53 24,856 a——- c:\windows\system32\drivers\avgfwd6x.sys
2009-10-01 09:29 195,440 ——– c:\windows\system32\MpSigStub.exe
2009-08-28 21:30 173,056 a——- c:\windows\apppatch\AcXtrnal.dll
2009-08-28 21:30 458,752 a——- c:\windows\apppatch\AcSpecfc.dll
2009-08-28 21:30 2,159,616 a——- c:\windows\apppatch\AcGenral.dll
2009-08-28 21:30 542,720 a——- c:\windows\apppatch\AcLayers.dll
2009-08-28 19:27 4,240,384 a——- c:\windows\system32\GameUXLegacyGDFs.dll
2009-08-28 19:14 28,672 a——- c:\windows\system32\Apphlpdm.dll
2009-08-17 23:33 1,193,832 a——- c:\windows\system32\FM20.DLL
2009-01-27 01:09 0 a——- c:\users\josh\appdata\roaming\wklnhst.dat
2008-01-20 21:43 174 a–sh— c:\program files\desktop.ini
2006-11-02 07:42 287,440 a——- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 07:42 287,440 a——- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 07:42 30,674 a——- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 07:42 30,674 a——- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 04:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 04:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 04:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 04:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat
2009-01-14 22:19 76 —shr– c:\windows\CT4CET.bin
============= FINISH: 11:05:57.32 ===============
Malwarebyte Anti-Malware -
Malwarebytes' Anti-Malware 1.41
Database version: 3155
Windows 6.0.6002 Service Pack 2
11/12/2009 10:47:08 AM
mbam-log-2009-11-12 (10-47-08).txt
Scan type: Quick Scan
Objects scanned: 89779
Time elapsed: 3 minute(s), 54 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\defence (Trojan.Agent) -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\ProgramData\Defence\smss.exe (Trojan.Agent) -> Delete on reboot.
RootRepeal -
ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2009/11/12 11:02
Program Version: Version 1.3.5.0
Windows Version: Windows Vista SP2
==================================================
Drivers
——————-
Name: dump_dumpata.sys
Image Path: C:\Windows\System32\Drivers\dump_dumpata.sys
Address: 0x8F37C000 Size: 45056 File Visible: No Signed: -
Status: -
Name: dump_msahci.sys
Image Path: C:\Windows\System32\Drivers\dump_msahci.sys
Address: 0x8F387000 Size: 40960 File Visible: No Signed: -
Status: -
Name: rootrepeal.sys
Image Path: C:\Windows\system32\drivers\rootrepeal.sys
Address: 0x9E5CF000 Size: 49152 File Visible: No Signed: -
Status: -
Processes
——————-
Path: System
PID: 4 Status: Locked to the Windows API!
Path: C:\Windows\System32\audiodg.exe
PID: 1528 Status: Locked to the Windows API!
SSDT
——————-
#: 194 Function Name: NtOpenProcess
Status: Hooked by "C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_Vista\AVGIDSShim.sys" at address 0x99714620
#: 334 Function Name: NtTerminateProcess
Status: Hooked by "C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_Vista\AVGIDSShim.sys" at address 0x997146d0
#: 335 Function Name: NtTerminateThread
Status: Hooked by "C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_Vista\AVGIDSShim.sys" at address 0x99714770
#: 358 Function Name: NtWriteVirtualMemory
Status: Hooked by "C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_Vista\AVGIDSShim.sys" at address 0x99714810
==EOF==
DDS Log -
DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 11:05:34.15 on Thu 11/12/2009
Internet Explorer: 7.0.6002.18005
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3066.1804 [GMT -5:00]
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\Windows\system32\lsm.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Program Files\Fingerprint Sensor\AtService.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_2ba5baa4\STacSV.exe
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\Ati2evxx.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\WLTRYSVC.EXE
C:\Windows\System32\bcmwltry.exe
C:\Windows\system32\WLANExt.exe
C:\Windows\System32\spoolsv.exe
C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe
C:\Program Files\DigitalPersona\Bin\DpHostW.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_2ba5baa4\aestsrv.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\DellTPad\Apoint.exe
C:\Windows\System32\WLTRAY.EXE
C:\Program Files\DigitalPersona\Bin\DpAgent.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\IDT\WDM\sttray.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Windows\system32\svchost.exe -k HPService
C:\Windows\system32\vssvc.exe
C:\Windows\System32\svchost.exe -k swprv
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\AVG\AVG9\avgam.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\Program Files\AVG\AVG9\avgemc.exe
C:\Program Files\AVG\AVG9\avgfws9.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\AVG\AVG9\avgtray.exe
C:\Program Files\AVG\AVG9\Identity Protection\agent\bin\avgidsmonitor.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Users\Josh\Desktop\RootRepeal.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\AVG\AVG9\avgui.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\Josh\Desktop\dds.scr
C:\Windows\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.com/
uWindow Title = Internet Explorer provided by Dell
uDefault_Page_URL = hxxp://www.dell.com
mDefault_Page_URL = hxxp://www.dell.com
uURLSearchHooks: H - No File
uURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg9\toolbar\IEToolbar.dll
mURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg9\toolbar\IEToolbar.dll
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_07\bin\ssv.dll
BHO: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg9\toolbar\IEToolbar.dll
TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - c:\program files\avg\avg9\toolbar\IEToolbar.dll
TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [Apoint] c:\program files\delltpad\Apoint.exe
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [Broadcom Wireless Manager UI] c:\windows\system32\WLTRAY.exe
mRun: [DpAgent] c:\program files\digitalpersona\bin\dpagent.exe
mRun: [AVG9_TRAY] c:\progra~1\avg\avg9\avgtray.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [SysTrayApp] %ProgramFiles%\IDT\WDM\sttray.exe
mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC} - c:\progra~1\java\jre16~1.0_0\bin\ssv.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll
Notify: GoToAssist - c:\program files\citrix\gotoassist\514\G2AWinLogon.dll
AppInit_DLLs: avgrsstx.dll
LSA: Notification Packages = scecli DPPWDFLT
================= FIREFOX ===================
FF - ProfilePath - c:\users\josh\appdata\roaming\mozilla\firefox\profiles\tuxos97j.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.newhaven.edu/15/
FF - component: c:\program files\avg\avg9\firefox\components\avgssff.dll
FF - component: c:\program files\avg\avg9\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\avg\avg9\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\avg\avg9\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\avg\avg9\toolbar\firefox\avg@igeared\components\xpavgtbapi.dll
FF - component: c:\program files\digitalpersona\bin\firefoxext\components\dpffcli.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
============= SERVICES / DRIVERS ===============
R0 AVGIDSErHrvtx;AVG9IDSErHr;c:\windows\system32\drivers\AVGIDSvx.sys [2009-11-5 25608]
R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [2009-1-21 161800]
R1 Avgfwfd;AVG network filter service;c:\windows\system32\drivers\avgfwd6x.sys [2009-1-21 24856]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-1-21 333192]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-1-21 360584]
R1 NEOFLTR_600_13319;Juniper Networks TDI Filter Driver (NEOFLTR_600_13319);c:\windows\system32\drivers\NEOFLTR_600_13319.sys [2008-6-24 64160]
R2 AESTFilters;Andrea ST Filters Service;c:\windows\system32\driverstore\filerepository\stwrt.inf_2ba5baa4\AEstSrv.exe [2009-1-14 73728]
R2 ATService;AuthenTec Fingerprint Service;c:\program files\fingerprint sensor\AtService.exe [2008-5-5 1168632]
R2 avg9emc;AVG E-mail Scanner;c:\program files\avg\avg9\avgemc.exe [2009-11-5 906520]
R2 avg9wd;AVG WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2009-11-5 285392]
R2 avgfws9;AVG Firewall;c:\program files\avg\avg9\avgfws9.exe [2009-11-9 2304192]
R2 AVGIDSAgent;AVG9IDSAgent;c:\program files\avg\avg9\identity protection\agent\bin\AVGIDSAgent.exe [2009-11-5 5832712]
R3 ATSwpWDF;AuthenTec TruePrint USB WDF Driver;c:\windows\system32\drivers\ATSwpWDF.sys [2009-1-14 475136]
R3 AVGIDSDrivervtx;AVG9IDSDriver;c:\program files\avg\avg9\identity protection\agent\driver\platform_vista\AVGIDSDriver.sys [2009-11-5 122376]
R3 AVGIDSFiltervtx;AVG9IDSFilter;c:\program files\avg\avg9\identity protection\agent\driver\platform_vista\AVGIDSFilter.sys [2009-11-5 30216]
R3 AVGIDSShimvtx;AVG9IDSShim;c:\program files\avg\avg9\identity protection\agent\driver\platform_vista\AVGIDSShim.sys [2009-11-5 27800]
R3 OA001Ufd;Creative Camera OA001 Upper Filter Driver;c:\windows\system32\drivers\OA001Ufd.sys [2009-3-6 133632]
R3 OA001Vid;Creative Camera OA001 Function Driver;c:\windows\system32\drivers\OA001Vid.sys [2009-3-8 280096]
S3 itecir;ITECIR Infrared Receiver;c:\windows\system32\drivers\itecir.sys [2009-1-14 54784]
S3 k57nd60x;Broadcom NetLink ™ Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\k57nd60x.sys [2009-1-14 203264]
S3 WSDPrintDevice;WSD Print Support via UMB;c:\windows\system32\drivers\WSDPrint.sys [2008-1-20 16896]
S4 DockLoginService;Dock Login Service;c:\program files\dell\delldock\DockLogin.exe [2008-9-23 155648]
=============== Created Last 30 ================
2009-11-12 10:40 –d—– c:\users\josh\appdata\roaming\Malwarebytes
2009-11-12 10:40 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2009-11-12 10:40 19,160 a——- c:\windows\system32\drivers\mbam.sys
2009-11-12 10:40 –d—– c:\programdata\Malwarebytes
2009-11-12 10:40 –d—– c:\program files\Malwarebytes' Anti-Malware
2009-11-12 10:40 –d—– c:\progra~2\Malwarebytes
2009-11-11 18:20 –d—– c:\program files\Microsoft Windows 7 Upgrade Advisor
2009-11-11 18:18 1,908 a——- c:\windows\diagwrn.xml
2009-11-11 18:18 1,908 a——- c:\windows\diagerr.xml
2009-11-11 09:46 2,036,736 a——- c:\windows\system32\win32k.sys
2009-11-11 09:46 355,328 a——- c:\windows\system32\WSDApi.dll
2009-11-09 22:29 –d—– c:\programdata\Defence
2009-11-09 22:29 –d—– c:\progra~2\Defence
2009-11-06 08:37 2,421,760 a——- c:\windows\system32\wucltux.dll
2009-11-06 08:36 87,552 a——- c:\windows\system32\wudriver.dll
2009-11-06 08:27 171,608 a——- c:\windows\system32\wuwebv.dll
2009-11-06 08:27 33,792 a——- c:\windows\system32\wuapp.exe
2009-11-06 00:22 –d—– c:\windows\system32\eu-ES
2009-11-06 00:22 –d—– c:\windows\system32\ca-ES
2009-11-06 00:22 –d—– c:\windows\system32\vi-VN
2009-11-05 14:14 –d—– c:\windows\system32\EventProviders
2009-11-05 08:55 –d-h— C:\$AVG
2009-11-05 08:54 25,608 a——- c:\windows\system32\drivers\AVGIDSvx.sys
2009-11-05 08:53 –d—– c:\programdata\avg9
2009-11-05 08:53 –d—– c:\progra~2\avg9
2009-11-04 21:54 –d—– c:\programdata\Microsoft Help
2009-10-27 21:26 310,784 a——- c:\windows\system32\unregmp2.exe
2009-10-27 21:26 8,147,456 a——- c:\windows\system32\wmploc.DLL
2009-10-14 16:14 60,928 a——- c:\windows\system32\msasn1.dll
2009-10-14 16:14 218,624 a——- c:\windows\system32\msv1_0.dll
2009-10-14 16:14 834,048 a——- c:\windows\system32\wininet.dll
2009-10-14 16:14 78,336 a——- c:\windows\system32\ieencode.dll
2009-10-14 16:14 3,600,456 a——- c:\windows\system32\ntkrnlpa.exe
2009-10-14 16:14 3,548,216 a——- c:\windows\system32\ntoskrnl.exe
2009-10-14 16:13 144,896 a——- c:\windows\system32\drivers\srv2.sys
2009-10-14 16:13 604,672 a——- c:\windows\system32\WMSPDMOD.DLL
==================== Find3M ====================
2009-11-09 08:23 360,584 a——- c:\windows\system32\drivers\avgtdix.sys
2009-11-06 00:31 143,360 a——- c:\windows\inf\infstrng.dat
2009-11-06 00:31 86,016 a——- c:\windows\inf\infstor.dat
2009-11-06 00:31 51,200 a——- c:\windows\inf\infpub.dat
2009-11-06 00:21 665,600 a——- c:\windows\inf\drvindex.dat
2009-11-05 08:55 333,192 a——- c:\windows\system32\drivers\avgldx86.sys
2009-11-05 08:54 12,464 a——- c:\windows\system32\avgrsstx.dll
2009-11-05 08:54 161,800 a——- c:\windows\system32\drivers\avgrkx86.sys
2009-11-05 08:53 24,856 a——- c:\windows\system32\drivers\avgfwd6x.sys
2009-10-01 09:29 195,440 ——– c:\windows\system32\MpSigStub.exe
2009-08-28 21:30 173,056 a——- c:\windows\apppatch\AcXtrnal.dll
2009-08-28 21:30 458,752 a——- c:\windows\apppatch\AcSpecfc.dll
2009-08-28 21:30 2,159,616 a——- c:\windows\apppatch\AcGenral.dll
2009-08-28 21:30 542,720 a——- c:\windows\apppatch\AcLayers.dll
2009-08-28 19:27 4,240,384 a——- c:\windows\system32\GameUXLegacyGDFs.dll
2009-08-28 19:14 28,672 a——- c:\windows\system32\Apphlpdm.dll
2009-08-17 23:33 1,193,832 a——- c:\windows\system32\FM20.DLL
2009-01-27 01:09 0 a——- c:\users\josh\appdata\roaming\wklnhst.dat
2008-01-20 21:43 174 a–sh— c:\program files\desktop.ini
2006-11-02 07:42 287,440 a——- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 07:42 287,440 a——- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 07:42 30,674 a——- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 07:42 30,674 a——- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 04:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 04:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 04:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 04:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat
2009-01-14 22:19 76 —shr– c:\windows\CT4CET.bin
============= FINISH: 11:05:57.32 ===============
Malwarebyte Anti-Malware -
Malwarebytes' Anti-Malware 1.41
Database version: 3155
Windows 6.0.6002 Service Pack 2
11/12/2009 10:47:08 AM
mbam-log-2009-11-12 (10-47-08).txt
Scan type: Quick Scan
Objects scanned: 89779
Time elapsed: 3 minute(s), 54 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\defence (Trojan.Agent) -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\ProgramData\Defence\smss.exe (Trojan.Agent) -> Delete on reboot.