Equitywiz
Topic Starter
Hello
My computer has been infected with the above malware. I have tried every type of malware removal and anti-virus to no avail. My google is still re-directing to a page I believe is a copy of the google site which does not carry a security certificate. It also doesn't funtion properly. I do tend to use google.com.mt (Malta) and this seems to work a little better although on occasions, I will search for something in google and when I choose the selected website from the list provided, it re-directs to a totally different website. Not sure if this is one or two problems.
I know I was not supposed to but i didn't realise until after but I already ran combofix. it got to 50 and the blue screen came up. I understand this could have something to do with the RAM? Not sure what else to do here so awaiting your advise
Anyway I have the files requested. I appreciate any help I can get.
DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 14:17:00.10 on 18/04/2010
Internet Explorer: 8.0.6001.18904 BrowserJavaVersion: 1.6.0_20
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2037.911 [GMT 2:00]
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Program Files\Microsoft Security Essentials\MsMpEng.exe
C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Acer\ALaunch\ALaunchSvc.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\AVG\AVG9\avgfws9.exe
C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
C:\Windows\RtHDVCpl.exe
C:\Acer\Empowering Technology\eDataSecurity\eDSLoader.exe
C:\Windows\System32\igfxpers.exe
C:\Windows\system32\igfxsrvc.exe
C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe
C:\Acer\Empowering Technology\eNet\eNet Service.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Acer\Mobility Center\MobilityService.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
C:\Acer\Empowering Technology\ePower\ePowerSvc.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\Users\Audrey\AppData\Local\Temp\RtkBtMnt.exe
C:\Program Files\AVG\AVG9\avgemc.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Launch Manager\LManager.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Trusteer\Rapport\bin\RapportService.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Acer\Empowering Technology\eAudio\eAudio.exe
C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe
C:\Program Files\AVG\AVG9\avgtray.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Windows\system32\igfxext.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Microsoft Security Essentials\msseces.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Acer\Empowering Technology\ENET\ENMTRAY.EXE
C:\Acer\Empowering Technology\EPOWER\EPOWER_DMC.EXE
C:\Acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE
C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
C:\Program Files\Apoint2K\ApMsgFwd.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Windows\system32\conime.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\Audrey\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.facebook.com/
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
mStart Page = hxxp://en.us.acer.yahoo.com
mDefault_Page_URL = hxxp://en.us.acer.yahoo.com
uInternet Settings,ProxyOverride = 127.0.0.1
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} -
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Skype add-on (mastermind): {22bf413b-c6d2-4d91-82a9-a0f997ba588c} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: ShowBarObj Class: {83a2f9b1-01a2-4aa5-87d1-45b6b8505e96} - c:\windows\system32\ActiveToolBand.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: Acer eDataSecurity Management: {5cbe3b7c-1e47-477e-a7dd-396db0476e29} - c:\windows\system32\eDStoolbar.dll
uRun: [Acer Tour Reminder] c:\acer\acertour\Reminder.exe
uRun: [MsnMsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: [Anti Trojan Elite] c:\program files\anti trojan elite\TJEnder.exe :NO
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [ALaunch] c:\acer\alaunch\AlaunchClient.exe
mRun: [RtHDVCpl] RtHDVCpl.exe
mRun: [eDataSecurity Loader] c:\acer\empowering technology\edatasecurity\eDSloader.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [PLFSetL] c:\windows\PLFSetL.exe
mRun: [LManager] c:\progra~1\launch~1\LManager.exe
mRun: [IAAnotif] "c:\program files\intel\intel matrix storage manager\Iaanotif.exe"
mRun: [Apoint] c:\program files\apoint2k\Apoint.exe
mRun: [eRecoveryService]
mRun: [Acer Tour Reminder] c:\acer\acertour\Reminder.exe
mRun: [WarReg_PopUp] c:\acer\wr_popup\WarReg_PopUp.exe
mRun: [SetPanel] c:\acer\apanel\APanel.cmd
mRun: [eAudio] "c:\acer\empowering technology\eaudio\eAudio.exe"
mRun: [Nikon Transfer Monitor] c:\program files\common files\nikon\monitor\NkMonitor.exe
mRun: [Skytel] Skytel.exe
mRun: [AVG9_TRAY] c:\progra~1\avg\avg9\avgtray.exe
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [MSSE] "c:\program files\microsoft security essentials\msseces.exe" -hide -runkey
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
dRun: [cbssreg] c:\windows\temp\yrng.tmp\svchost.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\empowe~1.lnk - c:\acer\empowering technology\eAPLauncher.exe
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {5067A26B-1337-4436-8AFE-EE169C2DA79F} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
IE: {77BF5300-1474-4EC7-9980-D32B190E9B07} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
Trusted Zone: alipay.com
Trusted Zone: alisoft.com
Trusted Zone: taobao.com
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: igfxcui - igfxdev.dll
AppInit_DLLs: c:\windows\system32\avgrsstx.dll c:\windows\system32\eNetHook.dll eNetHook.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
================= FIREFOX ===================
FF - ProfilePath - c:\users\audrey\appdata\roaming\mozilla\firefox\profiles\h3izmxml.default\
FF - component: c:\program files\avg\avg9\firefox\components\avgssff.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npww.dll
FF - plugin: c:\program files\veetle\player\npvlc.dll
FF - plugin: c:\program files\veetle\plugins\npVeetle.dll
FF - plugin: c:\program files\veetle\vlcbroadcast\npvbp.dll
FF - plugin: c:\users\audrey\appdata\roaming\mozilla\plugins\npatgpc.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: LoudMo Contextual Ad Assistant: No Registry Reference - c:\program files\mozilla firefox\extensions\{1d2c8ffd-87e0-2852-a805-d9d35b92d758}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
—- FIREFOX POLICIES —-
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", "-1");
c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35"); // now unused
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.delay", 50);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
============= SERVICES / DRIVERS ===============
R0 AVGIDSErHrvtx;AVG9IDSErHr;c:\windows\system32\drivers\AVGIDSvx.sys [2010-3-20 25096]
R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [2010-3-20 52872]
R1 Avgfwfd;AVG network filter service;c:\windows\system32\drivers\avgfwd6x.sys [2010-3-20 24856]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2010-3-20 216200]
R1 AvgTdiX;AVG Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2010-3-20 242696]
R1 RapportKELL;RapportKELL;c:\program files\trusteer\rapport\bin\RapportKELL.sys [2010-3-23 58984]
R1 RapportPG;RapportPG;c:\program files\trusteer\rapport\bin\RapportPG.sys [2010-3-23 125160]
R2 ALaunchService;ALaunch Service;c:\acer\alaunch\ALaunchSvc.exe [2007-8-9 50688]
R2 avg9emc;AVG E-mail Scanner;c:\program files\avg\avg9\avgemc.exe [2010-3-21 916760]
R2 avg9wd;AVG WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2010-3-21 308064]
R2 avgfws9;AVG Firewall;c:\program files\avg\avg9\avgfws9.exe [2010-3-21 2325816]
R2 RapportMgmtService;Rapport Management Service;c:\program files\trusteer\rapport\bin\RapportMgmtService.exe [2010-3-23 779496]
R3 AVGIDSDrivervtx;AVG9IDSDriver;c:\program files\avg\avg9\identity protection\agent\driver\platform_vista\AVGIDSDriver.sys [2010-3-20 122376]
R3 AVGIDSFiltervtx;AVG9IDSFilter;c:\program files\avg\avg9\identity protection\agent\driver\platform_vista\AVGIDSFilter.sys [2010-3-20 30216]
R3 AVGIDSShimvtx;AVG9IDSShim;c:\program files\avg\avg9\identity protection\agent\driver\platform_vista\AVGIDSShim.sys [2010-3-20 27144]
R3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2007-8-8 179712]
R3 enecir;ENE CIR Receiver;c:\windows\system32\drivers\enecir.sys [2007-8-8 32256]
R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\drivers\MpNWMon.sys [2009-12-2 42368]
S2 AVGIDSAgent;AVG9IDSAgent;c:\program files\avg\avg9\identity protection\agent\bin\AVGIDSAgent.exe [2010-3-21 5888008]
S2 gupdate1ca2e27f656cb70;Google Update Service (gupdate1ca2e27f656cb70);c:\program files\google\update\GoogleUpdate.exe [2009-9-5 133104]
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-10-1 21504]
=============== Created Last 30 ================
2010-04-18 04:11 –ds—- C:\ComboFix
2010-04-18 02:58 292,874,929 a——- c:\windows\MEMORY.DMP
2010-04-18 02:08 411,368 a——- c:\windows\system32\deployJava1.dll
2010-04-18 01:29 –d-h— C:\$AVG
2010-04-18 01:02 –d—– c:\program files\TrendMicro
2010-04-17 21:37 –d—– c:\program files\Microsoft Security Essentials
2010-04-17 19:35 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-17 19:35 20,824 a——- c:\windows\system32\drivers\mbam.sys
2010-04-17 19:35 –d—– c:\program files\Malwarebytes' Anti-Malware
2010-04-17 17:23 304,920 a——- c:\windows\system32\drivers\IASTOR.SYS
2010-04-17 11:31 165,376 a——- c:\windows\system32\unrar.dll
2010-04-17 11:31 839,680 a——- c:\windows\system32\lameACM.acm
2010-04-17 11:31 217,088 a——- c:\windows\system32\yv12vfw.dll
2010-04-17 11:31 151,552 a——- c:\windows\system32\ac3acm.acm
2010-04-17 11:31 414 a——- c:\windows\system32\lame_acm.xml
2010-04-17 11:31 38 a——- c:\windows\avisplitter.ini
2010-04-17 11:31 881,664 a——- c:\windows\system32\xvidcore.dll
2010-04-17 11:31 205,824 a——- c:\windows\system32\xvidvfw.dll
2010-04-17 11:30 85,504 a——- c:\windows\system32\ff_vfw.dll
2010-04-17 11:30 547 a——- c:\windows\system32\ff_vfw.dll.manifest
2010-04-17 11:30 –d—– c:\program files\K-Lite Codec Pack
2010-04-16 16:30 –d—– c:\programdata\NOS
2010-04-16 02:35 –d—– c:\windows\system32\MpEngineStore
2010-04-16 02:34 212,992 a——- c:\windows\system32\drivers\mrxsmb10.sys
2010-04-16 02:34 79,360 a——- c:\windows\system32\drivers\mrxsmb20.sys
2010-04-16 02:34 106,496 a——- c:\windows\system32\drivers\mrxsmb.sys
2010-04-16 02:34 3,548,040 a——- c:\windows\system32\ntoskrnl.exe
2010-04-16 02:34 3,600,776 a——- c:\windows\system32\ntkrnlpa.exe
2010-04-16 02:34 420,352 a——- c:\windows\system32\vbscript.dll
2010-04-16 02:34 220,672 a——- c:\windows\system32\l3codecp.acm
2010-04-16 02:34 62,464 a——- c:\windows\system32\l3codeca.acm
2010-04-16 02:27 206 a——- c:\windows\system32\MRT.INI
2010-04-16 01:22 –d—– c:\program files\trend micro
2010-04-16 01:11 172,032 a——- c:\windows\system32\wintrust.dll
2010-04-16 01:08 904,576 a——- c:\windows\system32\drivers\tcpip.sys
2010-04-16 01:08 25,088 a——- c:\windows\system32\drivers\tunnel.sys
2010-04-16 01:08 200,704 a——- c:\windows\system32\iphlpsvc.dll
2010-04-16 01:08 98,304 a——- c:\windows\system32\cabview.dll
2010-04-10 21:00 –d—– c:\program files\Microsoft Visual Studio 8
2010-04-09 17:48 –d—– c:\users\audrey\appdata\roaming\Trusteer
2010-04-09 17:48 –d—– c:\program files\Trusteer
2010-04-09 17:46 –d—– c:\programdata\Trusteer
2010-04-09 17:46 –d—– c:\progra~2\Trusteer
2010-04-06 04:07 –d—– c:\windows\system32\aliedit
2010-04-06 04:07 –d—– c:\program files\trademanager
2010-04-01 03:00 293,376 a——- c:\windows\system32\browserchoice.exe
2010-03-26 02:51 –d—– c:\programdata\Apple Computer
2010-03-26 02:49 –d—– c:\programdata\Apple
2010-03-24 15:45 60,744 a——- c:\users\audrey\g2mdlhlpx.exe
2010-03-23 03:31 –d—– c:\users\audrey\KironRaceViewer
2010-03-22 19:49 –d—– c:\users\audrey\appdata\roaming\AVG9
2010-03-21 11:01 12,464 a——- c:\windows\system32\avgrsstx.dll
2010-03-20 18:50 52,872 a——- c:\windows\system32\drivers\avgrkx86.sys
2010-03-20 18:50 25,096 a——- c:\windows\system32\drivers\AVGIDSvx.sys
2010-03-20 18:50 242,696 a——- c:\windows\system32\drivers\avgtdix.sys
2010-03-20 18:50 216,200 a——- c:\windows\system32\drivers\avgldx86.sys
2010-03-20 18:50 –d—– c:\windows\system32\drivers\Avg
2010-03-20 18:49 24,856 a——- c:\windows\system32\drivers\avgfwd6x.sys
2010-03-20 18:49 –d—– c:\programdata\avg9
2010-03-20 18:49 –d—– c:\progra~2\avg9
==================== Find3M ====================
2010-03-20 18:49 143,360 a——- c:\windows\inf\infstrng.dat
2010-03-20 18:49 86,016 a——- c:\windows\inf\infpub.dat
2010-03-20 18:49 143,360 a——- c:\windows\inf\infstor.dat
2010-03-20 16:30 20 —-h— c:\programdata\PKP_DLdu.DAT
2010-03-20 16:30 20 —-h— c:\progra~2\PKP_DLdu.DAT
2010-02-24 10:16 181,632 ——– c:\windows\system32\MpSigStub.exe
2010-02-23 08:39 916,480 a——- c:\windows\system32\wininet.dll
2010-02-23 08:33 109,056 a——- c:\windows\system32\iesysprep.dll
2010-02-23 08:33 71,680 a——- c:\windows\system32\iesetup.dll
2010-02-23 06:55 133,632 a——- c:\windows\system32\ieUnatt.exe
2010-02-21 01:06 24,064 a——- c:\windows\system32\nshhttp.dll
2010-02-21 01:05 30,720 a——- c:\windows\system32\httpapi.dll
2010-02-20 22:53 411,648 a——- c:\windows\system32\drivers\http.sys
2010-02-07 04:31 665,600 a——- c:\windows\inf\drvindex.dat
2010-01-25 14:00 471,552 a——- c:\windows\system32\secproc_isv.dll
2010-01-25 14:00 152,576 a——- c:\windows\system32\secproc_ssp_isv.dll
2010-01-25 14:00 152,064 a——- c:\windows\system32\secproc_ssp.dll
2010-01-25 14:00 471,552 a——- c:\windows\system32\secproc.dll
2010-01-25 13:58 332,288 a——- c:\windows\system32\msdrm.dll
2010-01-25 10:21 526,336 a——- c:\windows\system32\RMActivate_isv.exe
2010-01-25 10:21 346,624 a——- c:\windows\system32\RMActivate_ssp_isv.exe
2010-01-25 10:21 518,144 a——- c:\windows\system32\RMActivate.exe
2010-01-25 10:21 347,136 a——- c:\windows\system32\RMActivate_ssp.exe
2010-01-23 11:26 2,048 a——- c:\windows\system32\tzres.dll
2009-12-22 19:13 174 a–sh— c:\program files\desktop.ini
2009-12-04 01:41 20 —-h— c:\programdata\PKP_DLdw.DAT
2009-12-04 01:41 20 —-h— c:\progra~2\PKP_DLdw.DAT
2009-08-22 17:12 56 a—h— c:\programdata\ezsidmv.dat
2009-08-22 17:12 56 a—h— c:\progra~2\ezsidmv.dat
2006-11-02 14:42 287,440 a——- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 14:42 287,440 a——- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 14:42 30,674 a——- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 14:42 30,674 a——- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 11:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 11:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 11:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 11:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat
2009-11-30 22:44 16,384 a–sh— c:\windows\serviceprofiles\networkservice\appdata\local\microsoft\windows\history\history.ie5\index.dat
2009-11-30 22:44 32,768 a–sh— c:\windows\serviceprofiles\networkservice\appdata\local\microsoft\windows\temporary internet files\content.ie5\index.dat
2009-11-30 22:44 16,384 a–sh— c:\windows\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\cookies\index.dat
============= FINISH: 14:18:08.26 ===============
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-04-18 14:48:25
Windows 6.0.6002 Service Pack 2
Running: bogylyb2.exe; Driver: C:\Users\Audrey\AppData\Local\Temp\kwlyqpob.sys
—- System - GMER 1.0.15 —-
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwAssignProcessToJobObject [0x8D6F7D92]
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwCreateFile [0x8D6F849E]
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwDeleteFile [0x8D6F85EA]
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwDeleteKey [0x8D6FBD58]
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwDeleteValueKey [0x8D6FBD8A]
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwOpenFile [0x8D6F854E]
SSDT \??\C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_Vista\AVGIDSShim.sys ZwOpenProcess [0x8D782730]
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwOpenThread [0x8D6F80C8]
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwProtectVirtualMemory [0x8D6F81FA]
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwQueryValueKey [0x8D6FBE62]
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwRenameKey [0x8D6FBDCC]
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwReplaceKey [0x8D6FBDFE]
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwRestoreKey [0x8D6FBE30]
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwSetContextThread [0x8D6F7D40]
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwSetInformationFile [0x8D6F864A]
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwSetValueKey [0x8D6FBCF0]
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwSuspendThread [0x8D6F7CE4]
SSDT \??\C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_Vista\AVGIDSShim.sys ZwTerminateProcess [0x8D7827E0]
SSDT \??\C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_Vista\AVGIDSShim.sys ZwTerminateThread [0x8D782880]
SSDT \??\C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_Vista\AVGIDSShim.sys ZwWriteVirtualMemory [0x8D782920]
—- Kernel code sections - GMER 1.0.15 —-
.text ntoskrnl.exe!KeInsertQueue + 381 8208B978 4 Bytes [92, 7D, 6F, 8D]
.text ntoskrnl.exe!KeInsertQueue + 3C9 8208B9C0 4 Bytes [9E, 84, 6F, 8D] {SAHF ; TEST [EDI-0x73], CH}
.text ntoskrnl.exe!KeInsertQueue + 4C1 8208BAB8 8 Bytes JMP 588D6F85
.text ntoskrnl.exe!KeInsertQueue + 4D1 8208BAC8 4 Bytes [8A, BD, 6F, 8D]
.text ntoskrnl.exe!KeInsertQueue + 5C1 8208BBB8 4 Bytes [4E, 85, 6F, 8D] {DEC ESI; TEST [EDI-0x73], EBP}
.text …
—- User code sections - GMER 1.0.15 —-
.text C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe[1348] ntdll.dll!KiUserApcDispatcher 77515D18 5 Bytes JMP 00412220 C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe (RapportMgmtService/Trusteer Ltd.)
.text C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe[1348] USER32.dll!InSendMessageEx + 3B1 76D3E6B0 6 Bytes JMP 716E001E
.text C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe[1348] WS2_32.dll!getaddrinfo 7761418A 5 Bytes JMP 71640022
.text C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe[1348] WS2_32.dll!gethostbyname 776262D4 5 Bytes JMP 71670022
.text C:\Program Files\Trusteer\Rapport\bin\RapportService.exe[4784] ntdll.dll!KiUserApcDispatcher 77515D18 5 Bytes JMP 00439530 C:\Program Files\Trusteer\Rapport\bin\RapportService.exe (RapportService/Trusteer Ltd.)
.text C:\Program Files\Trusteer\Rapport\bin\RapportService.exe[4784] WS2_32.dll!getaddrinfo 7761418A 5 Bytes JMP 71670022
.text C:\Program Files\Trusteer\Rapport\bin\RapportService.exe[4784] WS2_32.dll!gethostbyname 776262D4 5 Bytes JMP 716E0022
.text C:\Program Files\Mozilla Firefox\firefox.exe[7676] ntdll.dll!LdrLoadDll 774D9390 5 Bytes JMP 000C13F0 C:\Program Files\Mozilla Firefox\firefox.exe (Firefox/Mozilla Corporation)
.text C:\Program Files\Mozilla Firefox\firefox.exe[7676] ntdll.dll!KiUserApcDispatcher 77515D18 5 Bytes JMP 022F6060 c:\program files\trusteer\rapport\bin\rooksdol.dll (Rooks/Dolomite/Trusteer Ltd.)
.text C:\Program Files\Mozilla Firefox\firefox.exe[7676] kernel32.dll!SetUnhandledExceptionFilter 76DFA84F 6 Bytes PUSH 71510022; RET
.text C:\Program Files\Mozilla Firefox\firefox.exe[7676] USER32.dll!DdeInitializeW 76D37921 6 Bytes PUSH 714E0022; RET
.text C:\Program Files\Mozilla Firefox\firefox.exe[7676] USER32.dll!RegisterClassExW 76D3DA30 6 Bytes PUSH 716E0022; RET
.text C:\Program Files\Mozilla Firefox\firefox.exe[7676] USER32.dll!GetMessageW 76D4FEF7 6 Bytes PUSH 71480022; RET
.text C:\Program Files\Mozilla Firefox\firefox.exe[7676] USER32.dll!TranslateMessage 76D501AD 6 Bytes PUSH 71410022; RET
.text C:\Program Files\Mozilla Firefox\firefox.exe[7676] USER32.dll!GetClipboardData 76D7715A 6 Bytes PUSH 714B0022; RET
.text C:\Program Files\Mozilla Firefox\firefox.exe[7676] GDI32.dll!BitBlt 776C70A6 6 Bytes PUSH 71540022; RET
—- Devices - GMER 1.0.15 —-
AttachedDevice \Driver\tdx \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\tdx \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\tdx \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
—- EOF - GMER 1.0.15 —-
For the record, I have uninstalled uTorrent since this scan.
Thank you
Daniel
My computer has been infected with the above malware. I have tried every type of malware removal and anti-virus to no avail. My google is still re-directing to a page I believe is a copy of the google site which does not carry a security certificate. It also doesn't funtion properly. I do tend to use google.com.mt (Malta) and this seems to work a little better although on occasions, I will search for something in google and when I choose the selected website from the list provided, it re-directs to a totally different website. Not sure if this is one or two problems.
I know I was not supposed to but i didn't realise until after but I already ran combofix. it got to 50 and the blue screen came up. I understand this could have something to do with the RAM? Not sure what else to do here so awaiting your advise
Anyway I have the files requested. I appreciate any help I can get.
DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 14:17:00.10 on 18/04/2010
Internet Explorer: 8.0.6001.18904 BrowserJavaVersion: 1.6.0_20
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2037.911 [GMT 2:00]
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Program Files\Microsoft Security Essentials\MsMpEng.exe
C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Acer\ALaunch\ALaunchSvc.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\AVG\AVG9\avgfws9.exe
C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
C:\Windows\RtHDVCpl.exe
C:\Acer\Empowering Technology\eDataSecurity\eDSLoader.exe
C:\Windows\System32\igfxpers.exe
C:\Windows\system32\igfxsrvc.exe
C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe
C:\Acer\Empowering Technology\eNet\eNet Service.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Acer\Mobility Center\MobilityService.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
C:\Acer\Empowering Technology\ePower\ePowerSvc.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\Users\Audrey\AppData\Local\Temp\RtkBtMnt.exe
C:\Program Files\AVG\AVG9\avgemc.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Launch Manager\LManager.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Trusteer\Rapport\bin\RapportService.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Acer\Empowering Technology\eAudio\eAudio.exe
C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe
C:\Program Files\AVG\AVG9\avgtray.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Windows\system32\igfxext.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Microsoft Security Essentials\msseces.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Acer\Empowering Technology\ENET\ENMTRAY.EXE
C:\Acer\Empowering Technology\EPOWER\EPOWER_DMC.EXE
C:\Acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE
C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
C:\Program Files\Apoint2K\ApMsgFwd.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Windows\system32\conime.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\Audrey\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.facebook.com/
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
mStart Page = hxxp://en.us.acer.yahoo.com
mDefault_Page_URL = hxxp://en.us.acer.yahoo.com
uInternet Settings,ProxyOverride = 127.0.0.1
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} -
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Skype add-on (mastermind): {22bf413b-c6d2-4d91-82a9-a0f997ba588c} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: ShowBarObj Class: {83a2f9b1-01a2-4aa5-87d1-45b6b8505e96} - c:\windows\system32\ActiveToolBand.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: Acer eDataSecurity Management: {5cbe3b7c-1e47-477e-a7dd-396db0476e29} - c:\windows\system32\eDStoolbar.dll
uRun: [Acer Tour Reminder] c:\acer\acertour\Reminder.exe
uRun: [MsnMsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: [Anti Trojan Elite] c:\program files\anti trojan elite\TJEnder.exe :NO
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [ALaunch] c:\acer\alaunch\AlaunchClient.exe
mRun: [RtHDVCpl] RtHDVCpl.exe
mRun: [eDataSecurity Loader] c:\acer\empowering technology\edatasecurity\eDSloader.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [PLFSetL] c:\windows\PLFSetL.exe
mRun: [LManager] c:\progra~1\launch~1\LManager.exe
mRun: [IAAnotif] "c:\program files\intel\intel matrix storage manager\Iaanotif.exe"
mRun: [Apoint] c:\program files\apoint2k\Apoint.exe
mRun: [eRecoveryService]
mRun: [Acer Tour Reminder] c:\acer\acertour\Reminder.exe
mRun: [WarReg_PopUp] c:\acer\wr_popup\WarReg_PopUp.exe
mRun: [SetPanel] c:\acer\apanel\APanel.cmd
mRun: [eAudio] "c:\acer\empowering technology\eaudio\eAudio.exe"
mRun: [Nikon Transfer Monitor] c:\program files\common files\nikon\monitor\NkMonitor.exe
mRun: [Skytel] Skytel.exe
mRun: [AVG9_TRAY] c:\progra~1\avg\avg9\avgtray.exe
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [MSSE] "c:\program files\microsoft security essentials\msseces.exe" -hide -runkey
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
dRun: [cbssreg] c:\windows\temp\yrng.tmp\svchost.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\empowe~1.lnk - c:\acer\empowering technology\eAPLauncher.exe
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {5067A26B-1337-4436-8AFE-EE169C2DA79F} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
IE: {77BF5300-1474-4EC7-9980-D32B190E9B07} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
Trusted Zone: alipay.com
Trusted Zone: alisoft.com
Trusted Zone: taobao.com
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: igfxcui - igfxdev.dll
AppInit_DLLs: c:\windows\system32\avgrsstx.dll c:\windows\system32\eNetHook.dll eNetHook.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
================= FIREFOX ===================
FF - ProfilePath - c:\users\audrey\appdata\roaming\mozilla\firefox\profiles\h3izmxml.default\
FF - component: c:\program files\avg\avg9\firefox\components\avgssff.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npww.dll
FF - plugin: c:\program files\veetle\player\npvlc.dll
FF - plugin: c:\program files\veetle\plugins\npVeetle.dll
FF - plugin: c:\program files\veetle\vlcbroadcast\npvbp.dll
FF - plugin: c:\users\audrey\appdata\roaming\mozilla\plugins\npatgpc.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: LoudMo Contextual Ad Assistant: No Registry Reference - c:\program files\mozilla firefox\extensions\{1d2c8ffd-87e0-2852-a805-d9d35b92d758}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
—- FIREFOX POLICIES —-
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", "-1");
c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35"); // now unused
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.delay", 50);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
============= SERVICES / DRIVERS ===============
R0 AVGIDSErHrvtx;AVG9IDSErHr;c:\windows\system32\drivers\AVGIDSvx.sys [2010-3-20 25096]
R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [2010-3-20 52872]
R1 Avgfwfd;AVG network filter service;c:\windows\system32\drivers\avgfwd6x.sys [2010-3-20 24856]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2010-3-20 216200]
R1 AvgTdiX;AVG Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2010-3-20 242696]
R1 RapportKELL;RapportKELL;c:\program files\trusteer\rapport\bin\RapportKELL.sys [2010-3-23 58984]
R1 RapportPG;RapportPG;c:\program files\trusteer\rapport\bin\RapportPG.sys [2010-3-23 125160]
R2 ALaunchService;ALaunch Service;c:\acer\alaunch\ALaunchSvc.exe [2007-8-9 50688]
R2 avg9emc;AVG E-mail Scanner;c:\program files\avg\avg9\avgemc.exe [2010-3-21 916760]
R2 avg9wd;AVG WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2010-3-21 308064]
R2 avgfws9;AVG Firewall;c:\program files\avg\avg9\avgfws9.exe [2010-3-21 2325816]
R2 RapportMgmtService;Rapport Management Service;c:\program files\trusteer\rapport\bin\RapportMgmtService.exe [2010-3-23 779496]
R3 AVGIDSDrivervtx;AVG9IDSDriver;c:\program files\avg\avg9\identity protection\agent\driver\platform_vista\AVGIDSDriver.sys [2010-3-20 122376]
R3 AVGIDSFiltervtx;AVG9IDSFilter;c:\program files\avg\avg9\identity protection\agent\driver\platform_vista\AVGIDSFilter.sys [2010-3-20 30216]
R3 AVGIDSShimvtx;AVG9IDSShim;c:\program files\avg\avg9\identity protection\agent\driver\platform_vista\AVGIDSShim.sys [2010-3-20 27144]
R3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2007-8-8 179712]
R3 enecir;ENE CIR Receiver;c:\windows\system32\drivers\enecir.sys [2007-8-8 32256]
R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\drivers\MpNWMon.sys [2009-12-2 42368]
S2 AVGIDSAgent;AVG9IDSAgent;c:\program files\avg\avg9\identity protection\agent\bin\AVGIDSAgent.exe [2010-3-21 5888008]
S2 gupdate1ca2e27f656cb70;Google Update Service (gupdate1ca2e27f656cb70);c:\program files\google\update\GoogleUpdate.exe [2009-9-5 133104]
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-10-1 21504]
=============== Created Last 30 ================
2010-04-18 04:11 –ds—- C:\ComboFix
2010-04-18 02:58 292,874,929 a——- c:\windows\MEMORY.DMP
2010-04-18 02:08 411,368 a——- c:\windows\system32\deployJava1.dll
2010-04-18 01:29 –d-h— C:\$AVG
2010-04-18 01:02 –d—– c:\program files\TrendMicro
2010-04-17 21:37 –d—– c:\program files\Microsoft Security Essentials
2010-04-17 19:35 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-17 19:35 20,824 a——- c:\windows\system32\drivers\mbam.sys
2010-04-17 19:35 –d—– c:\program files\Malwarebytes' Anti-Malware
2010-04-17 17:23 304,920 a——- c:\windows\system32\drivers\IASTOR.SYS
2010-04-17 11:31 165,376 a——- c:\windows\system32\unrar.dll
2010-04-17 11:31 839,680 a——- c:\windows\system32\lameACM.acm
2010-04-17 11:31 217,088 a——- c:\windows\system32\yv12vfw.dll
2010-04-17 11:31 151,552 a——- c:\windows\system32\ac3acm.acm
2010-04-17 11:31 414 a——- c:\windows\system32\lame_acm.xml
2010-04-17 11:31 38 a——- c:\windows\avisplitter.ini
2010-04-17 11:31 881,664 a——- c:\windows\system32\xvidcore.dll
2010-04-17 11:31 205,824 a——- c:\windows\system32\xvidvfw.dll
2010-04-17 11:30 85,504 a——- c:\windows\system32\ff_vfw.dll
2010-04-17 11:30 547 a——- c:\windows\system32\ff_vfw.dll.manifest
2010-04-17 11:30 –d—– c:\program files\K-Lite Codec Pack
2010-04-16 16:30 –d—– c:\programdata\NOS
2010-04-16 02:35 –d—– c:\windows\system32\MpEngineStore
2010-04-16 02:34 212,992 a——- c:\windows\system32\drivers\mrxsmb10.sys
2010-04-16 02:34 79,360 a——- c:\windows\system32\drivers\mrxsmb20.sys
2010-04-16 02:34 106,496 a——- c:\windows\system32\drivers\mrxsmb.sys
2010-04-16 02:34 3,548,040 a——- c:\windows\system32\ntoskrnl.exe
2010-04-16 02:34 3,600,776 a——- c:\windows\system32\ntkrnlpa.exe
2010-04-16 02:34 420,352 a——- c:\windows\system32\vbscript.dll
2010-04-16 02:34 220,672 a——- c:\windows\system32\l3codecp.acm
2010-04-16 02:34 62,464 a——- c:\windows\system32\l3codeca.acm
2010-04-16 02:27 206 a——- c:\windows\system32\MRT.INI
2010-04-16 01:22 –d—– c:\program files\trend micro
2010-04-16 01:11 172,032 a——- c:\windows\system32\wintrust.dll
2010-04-16 01:08 904,576 a——- c:\windows\system32\drivers\tcpip.sys
2010-04-16 01:08 25,088 a——- c:\windows\system32\drivers\tunnel.sys
2010-04-16 01:08 200,704 a——- c:\windows\system32\iphlpsvc.dll
2010-04-16 01:08 98,304 a——- c:\windows\system32\cabview.dll
2010-04-10 21:00 –d—– c:\program files\Microsoft Visual Studio 8
2010-04-09 17:48 –d—– c:\users\audrey\appdata\roaming\Trusteer
2010-04-09 17:48 –d—– c:\program files\Trusteer
2010-04-09 17:46 –d—– c:\programdata\Trusteer
2010-04-09 17:46 –d—– c:\progra~2\Trusteer
2010-04-06 04:07 –d—– c:\windows\system32\aliedit
2010-04-06 04:07 –d—– c:\program files\trademanager
2010-04-01 03:00 293,376 a——- c:\windows\system32\browserchoice.exe
2010-03-26 02:51 –d—– c:\programdata\Apple Computer
2010-03-26 02:49 –d—– c:\programdata\Apple
2010-03-24 15:45 60,744 a——- c:\users\audrey\g2mdlhlpx.exe
2010-03-23 03:31 –d—– c:\users\audrey\KironRaceViewer
2010-03-22 19:49 –d—– c:\users\audrey\appdata\roaming\AVG9
2010-03-21 11:01 12,464 a——- c:\windows\system32\avgrsstx.dll
2010-03-20 18:50 52,872 a——- c:\windows\system32\drivers\avgrkx86.sys
2010-03-20 18:50 25,096 a——- c:\windows\system32\drivers\AVGIDSvx.sys
2010-03-20 18:50 242,696 a——- c:\windows\system32\drivers\avgtdix.sys
2010-03-20 18:50 216,200 a——- c:\windows\system32\drivers\avgldx86.sys
2010-03-20 18:50 –d—– c:\windows\system32\drivers\Avg
2010-03-20 18:49 24,856 a——- c:\windows\system32\drivers\avgfwd6x.sys
2010-03-20 18:49 –d—– c:\programdata\avg9
2010-03-20 18:49 –d—– c:\progra~2\avg9
==================== Find3M ====================
2010-03-20 18:49 143,360 a——- c:\windows\inf\infstrng.dat
2010-03-20 18:49 86,016 a——- c:\windows\inf\infpub.dat
2010-03-20 18:49 143,360 a——- c:\windows\inf\infstor.dat
2010-03-20 16:30 20 —-h— c:\programdata\PKP_DLdu.DAT
2010-03-20 16:30 20 —-h— c:\progra~2\PKP_DLdu.DAT
2010-02-24 10:16 181,632 ——– c:\windows\system32\MpSigStub.exe
2010-02-23 08:39 916,480 a——- c:\windows\system32\wininet.dll
2010-02-23 08:33 109,056 a——- c:\windows\system32\iesysprep.dll
2010-02-23 08:33 71,680 a——- c:\windows\system32\iesetup.dll
2010-02-23 06:55 133,632 a——- c:\windows\system32\ieUnatt.exe
2010-02-21 01:06 24,064 a——- c:\windows\system32\nshhttp.dll
2010-02-21 01:05 30,720 a——- c:\windows\system32\httpapi.dll
2010-02-20 22:53 411,648 a——- c:\windows\system32\drivers\http.sys
2010-02-07 04:31 665,600 a——- c:\windows\inf\drvindex.dat
2010-01-25 14:00 471,552 a——- c:\windows\system32\secproc_isv.dll
2010-01-25 14:00 152,576 a——- c:\windows\system32\secproc_ssp_isv.dll
2010-01-25 14:00 152,064 a——- c:\windows\system32\secproc_ssp.dll
2010-01-25 14:00 471,552 a——- c:\windows\system32\secproc.dll
2010-01-25 13:58 332,288 a——- c:\windows\system32\msdrm.dll
2010-01-25 10:21 526,336 a——- c:\windows\system32\RMActivate_isv.exe
2010-01-25 10:21 346,624 a——- c:\windows\system32\RMActivate_ssp_isv.exe
2010-01-25 10:21 518,144 a——- c:\windows\system32\RMActivate.exe
2010-01-25 10:21 347,136 a——- c:\windows\system32\RMActivate_ssp.exe
2010-01-23 11:26 2,048 a——- c:\windows\system32\tzres.dll
2009-12-22 19:13 174 a–sh— c:\program files\desktop.ini
2009-12-04 01:41 20 —-h— c:\programdata\PKP_DLdw.DAT
2009-12-04 01:41 20 —-h— c:\progra~2\PKP_DLdw.DAT
2009-08-22 17:12 56 a—h— c:\programdata\ezsidmv.dat
2009-08-22 17:12 56 a—h— c:\progra~2\ezsidmv.dat
2006-11-02 14:42 287,440 a——- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 14:42 287,440 a——- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 14:42 30,674 a——- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 14:42 30,674 a——- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 11:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 11:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 11:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 11:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat
2009-11-30 22:44 16,384 a–sh— c:\windows\serviceprofiles\networkservice\appdata\local\microsoft\windows\history\history.ie5\index.dat
2009-11-30 22:44 32,768 a–sh— c:\windows\serviceprofiles\networkservice\appdata\local\microsoft\windows\temporary internet files\content.ie5\index.dat
2009-11-30 22:44 16,384 a–sh— c:\windows\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\cookies\index.dat
============= FINISH: 14:18:08.26 ===============
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-04-18 14:48:25
Windows 6.0.6002 Service Pack 2
Running: bogylyb2.exe; Driver: C:\Users\Audrey\AppData\Local\Temp\kwlyqpob.sys
—- System - GMER 1.0.15 —-
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwAssignProcessToJobObject [0x8D6F7D92]
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwCreateFile [0x8D6F849E]
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwDeleteFile [0x8D6F85EA]
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwDeleteKey [0x8D6FBD58]
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwDeleteValueKey [0x8D6FBD8A]
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwOpenFile [0x8D6F854E]
SSDT \??\C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_Vista\AVGIDSShim.sys ZwOpenProcess [0x8D782730]
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwOpenThread [0x8D6F80C8]
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwProtectVirtualMemory [0x8D6F81FA]
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwQueryValueKey [0x8D6FBE62]
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwRenameKey [0x8D6FBDCC]
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwReplaceKey [0x8D6FBDFE]
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwRestoreKey [0x8D6FBE30]
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwSetContextThread [0x8D6F7D40]
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwSetInformationFile [0x8D6F864A]
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwSetValueKey [0x8D6FBCF0]
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwSuspendThread [0x8D6F7CE4]
SSDT \??\C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_Vista\AVGIDSShim.sys ZwTerminateProcess [0x8D7827E0]
SSDT \??\C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_Vista\AVGIDSShim.sys ZwTerminateThread [0x8D782880]
SSDT \??\C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_Vista\AVGIDSShim.sys ZwWriteVirtualMemory [0x8D782920]
—- Kernel code sections - GMER 1.0.15 —-
.text ntoskrnl.exe!KeInsertQueue + 381 8208B978 4 Bytes [92, 7D, 6F, 8D]
.text ntoskrnl.exe!KeInsertQueue + 3C9 8208B9C0 4 Bytes [9E, 84, 6F, 8D] {SAHF ; TEST [EDI-0x73], CH}
.text ntoskrnl.exe!KeInsertQueue + 4C1 8208BAB8 8 Bytes JMP 588D6F85
.text ntoskrnl.exe!KeInsertQueue + 4D1 8208BAC8 4 Bytes [8A, BD, 6F, 8D]
.text ntoskrnl.exe!KeInsertQueue + 5C1 8208BBB8 4 Bytes [4E, 85, 6F, 8D] {DEC ESI; TEST [EDI-0x73], EBP}
.text …
—- User code sections - GMER 1.0.15 —-
.text C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe[1348] ntdll.dll!KiUserApcDispatcher 77515D18 5 Bytes JMP 00412220 C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe (RapportMgmtService/Trusteer Ltd.)
.text C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe[1348] USER32.dll!InSendMessageEx + 3B1 76D3E6B0 6 Bytes JMP 716E001E
.text C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe[1348] WS2_32.dll!getaddrinfo 7761418A 5 Bytes JMP 71640022
.text C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe[1348] WS2_32.dll!gethostbyname 776262D4 5 Bytes JMP 71670022
.text C:\Program Files\Trusteer\Rapport\bin\RapportService.exe[4784] ntdll.dll!KiUserApcDispatcher 77515D18 5 Bytes JMP 00439530 C:\Program Files\Trusteer\Rapport\bin\RapportService.exe (RapportService/Trusteer Ltd.)
.text C:\Program Files\Trusteer\Rapport\bin\RapportService.exe[4784] WS2_32.dll!getaddrinfo 7761418A 5 Bytes JMP 71670022
.text C:\Program Files\Trusteer\Rapport\bin\RapportService.exe[4784] WS2_32.dll!gethostbyname 776262D4 5 Bytes JMP 716E0022
.text C:\Program Files\Mozilla Firefox\firefox.exe[7676] ntdll.dll!LdrLoadDll 774D9390 5 Bytes JMP 000C13F0 C:\Program Files\Mozilla Firefox\firefox.exe (Firefox/Mozilla Corporation)
.text C:\Program Files\Mozilla Firefox\firefox.exe[7676] ntdll.dll!KiUserApcDispatcher 77515D18 5 Bytes JMP 022F6060 c:\program files\trusteer\rapport\bin\rooksdol.dll (Rooks/Dolomite/Trusteer Ltd.)
.text C:\Program Files\Mozilla Firefox\firefox.exe[7676] kernel32.dll!SetUnhandledExceptionFilter 76DFA84F 6 Bytes PUSH 71510022; RET
.text C:\Program Files\Mozilla Firefox\firefox.exe[7676] USER32.dll!DdeInitializeW 76D37921 6 Bytes PUSH 714E0022; RET
.text C:\Program Files\Mozilla Firefox\firefox.exe[7676] USER32.dll!RegisterClassExW 76D3DA30 6 Bytes PUSH 716E0022; RET
.text C:\Program Files\Mozilla Firefox\firefox.exe[7676] USER32.dll!GetMessageW 76D4FEF7 6 Bytes PUSH 71480022; RET
.text C:\Program Files\Mozilla Firefox\firefox.exe[7676] USER32.dll!TranslateMessage 76D501AD 6 Bytes PUSH 71410022; RET
.text C:\Program Files\Mozilla Firefox\firefox.exe[7676] USER32.dll!GetClipboardData 76D7715A 6 Bytes PUSH 714B0022; RET
.text C:\Program Files\Mozilla Firefox\firefox.exe[7676] GDI32.dll!BitBlt 776C70A6 6 Bytes PUSH 71540022; RET
—- Devices - GMER 1.0.15 —-
AttachedDevice \Driver\tdx \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\tdx \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\tdx \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
—- EOF - GMER 1.0.15 —-
For the record, I have uninstalled uTorrent since this scan.
Thank you
Daniel