The following are the log files from DDS and GMER
From DDS
Attach.txt
DDS (Ver_10-03-17.01)
Microsoft Windows 7 Ultimate
Boot Device: \Device\HarddiskVolume1
Install Date: 4/18/2010 8:58:34 PM
System Uptime: 4/28/2010 6:12:46 PM (0 hours ago)
Motherboard: MSI | | MS-7250
Processor: AMD Athlon™ 64 X2 Dual Core Processor 6400+ | CPU 1 | 3200/200mhz
==== Disk Partitions =========================
C: is FIXED (NTFS) - 190 GiB total, 144.974 GiB free.
D: is CDROM (CDFS)
E: is FIXED (NTFS) - 466 GiB total, 251.381 GiB free.
F: is FIXED (NTFS) - 466 GiB total, 197.305 GiB free.
G: is FIXED (FAT32) - 149 GiB total, 89.004 GiB free.
==== Disabled Device Manager Items =============
Class GUID: {4d36e96f-e325-11ce-bfc1-08002be10318}
Description: Microsoft PS/2 Mouse
Device ID: ACPI\PNP0F03\4&319F7F6F&0
Manufacturer: Microsoft
Name: Microsoft PS/2 Mouse
PNP Device ID: ACPI\PNP0F03\4&319F7F6F&0
Service: i8042prt
Class GUID: {4d36e96b-e325-11ce-bfc1-08002be10318}
Description: Standard PS/2 Keyboard
Device ID: ACPI\PNP0303\4&319F7F6F&0
Manufacturer: (Standard keyboards)
Name: Standard PS/2 Keyboard
PNP Device ID: ACPI\PNP0303\4&319F7F6F&0
Service: i8042prt
==== System Restore Points ===================
RP28: 4/23/2010 3:03:37 PM - Installed Adobe Reader 9.3.
RP30: 4/25/2010 7:11:27 AM - Installed DirectX
RP32: 4/25/2010 7:12:21 AM - Installed Sid Meier's Civilization 4 - Beyond the Sword
RP33: 4/28/2010 6:09:26 PM - Windows Update
==== Installed Programs ======================
Acrobat.com
Ad-Aware
Ad-Aware Email Scanner for Outlook
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 9.3.2
AVG Free 9.0
BitTorrent
Java Auto Updater
Java™ 6 Update 18
LimeWire 5.5.8
Malwarebytes' Anti-Malware
Microsoft Visual C++ 2005 Redistributable
Mozilla Firefox (3.6.3)
Security Task Manager 1.7h
Sid Meier's Civilization 4
Sid Meier's Civilization 4 - Beyond the Sword
Sid Meier's Civilization 4 - Warlords
Trillian
Ventrilo Client
Visual C++ 2008 x86 Runtime - (v9.0.30729)
Visual C++ 2008 x86 Runtime - v9.0.30729.01
Winamp
Winamp Detector Plug-in
World of Warcraft
Yahoo! BrowserPlus 2.7.0
==== Event Viewer Messages From Past Week ========
4/28/2010 6:13:09 PM, Error: atikmdag [52236] - CPLIB :: General - Invalid Parameter
4/28/2010 6:13:09 PM, Error: atikmdag [43029] - Display is not active
4/28/2010 6:10:32 PM, Error: Service Control Manager [7030] - The Lavasoft Ad-Aware Service service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.
4/26/2010 9:35:01 PM, Error: bowser [8003] - The master browser has received a server announcement from the computer JGARMON that believes that it is the master browser for the domain on transport NetBT_Tcpip_{1DDABBB3-1260-467F-A171-3A31D41B9C. The master browser is stopping or an election is being forced.
4/22/2010 10:27:57 PM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the lmhosts service.
==== End Of File ===========================
DDS.txt
DDS (Ver_10-03-17.01) - NTFSx86
Run by [removed] at 18:46:31.59 on Wed 04/28/2010
Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_18
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.1.1033.18.3071.1857 [GMT -4:00]
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\Windows\system32\lsm.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\AVG\AVG9\avgemc.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Windows\system32\atieclxx.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskhost.exe
C:\Windows\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\AVG\AVG9\avgtray.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Users\Alex\Downloads\Defogger.exe
C:\Windows\system32\conhost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\Alex\Downloads\dds.scr
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
uURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg9\toolbar\IEToolbar.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll
BHO: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg9\toolbar\IEToolbar.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - c:\program files\avg\avg9\toolbar\IEToolbar.dll
uRun: [Bykrzoq] rundll32 "c:\users\alex\appdata\roaming\srwmib.dll",Bgaiyoem
mRun: [AVG9_TRAY] c:\progra~1\avg\avg9\avgtray.exe
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRunOnce: [Malwarebytes' Anti-Malware] c:\program files\malwarebytes' anti-malware\mbamgui.exe /install /silent
StartupFolder: c:\users\alex\appdata\roaming\micros~1\windows\startm~1\programs\startup\limewi~1.lnk - c:\program files\limewire\LimeWire.exe
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - c:\program files\avg\avg9\toolbar\IEToolbar.dll
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll
AppInit_DLLs: avgrsstx.dll
================= FIREFOX ===================
FF - ProfilePath - c:\users\alex\appdata\roaming\mozilla\firefox\profiles\v9314afd.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-tyc&p=
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: browser.startup.homepage - hxxp://my.yahoo.com/
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-tyc&p=
FF - component: c:\program files\avg\avg9\firefox\components\avgssff.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npwachk.dll
FF - plugin: c:\users\alex\appdata\local\yahoo!\browserplus\2.7.0\plugins\npybrowserplus_2.7.0.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}
—- FIREFOX POLICIES —-
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
============= SERVICES / DRIVERS ===============
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2010-4-28 64288]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2010-4-18 216200]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2010-4-18 29512]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2010-4-18 242896]
R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-8-18 176128]
R2 avg9emc;AVG Free E-mail Scanner;c:\program files\avg\avg9\avgemc.exe [2010-4-18 916760]
R2 avg9wd;AVG Free WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2010-4-18 308064]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2010-2-4 1284840]
S3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files\avg\avg9\toolbar\ToolbarBroker.exe [2010-4-18 369920]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
=============== Created Last 30 ================
2010-04-28 22:44:20 0 —-a-w- c:\users\alex\defogger_reenable
2010-04-28 22:38:56 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-28 22:38:55 20824 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-04-28 22:38:55 0 d—–w- c:\programdata\Malwarebytes
2010-04-28 22:38:55 0 d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-04-28 22:18:35 0 d—–w- c:\programdata\SecTaskMan
2010-04-28 22:18:31 0 d—–w- c:\program files\Security Task Manager
2010-04-28 22:16:42 15880 —-a-w- c:\windows\system32\lsdelete.exe
2010-04-28 22:11:26 64288 —-a-w- c:\windows\system32\drivers\Lbd.sys
2010-04-28 22:11:22 95024 —-a-w- c:\windows\system32\drivers\SBREDrv.sys
2010-04-28 22:09:40 12800 —-a-w- c:\windows\system32\drivers\sffp_sd.sys
2010-04-28 22:09:21 194488 —-a-w- c:\windows\system32\drivers\fvevol.sys
2010-04-28 22:09:20 133720 —-a-w- c:\windows\system32\drivers\ksecpkg.sys
2010-04-28 22:09:20 1037312 —-a-w- c:\windows\system32\lsasrv.dll
2010-04-28 22:02:38 0 dc-h–w- c:\programdata\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}
2010-04-28 22:02:16 0 d—–w- c:\programdata\Lavasoft
2010-04-28 22:02:16 0 d—–w- c:\program files\Lavasoft
2010-04-23 19:03:35 0 d—–w- c:\programdata\Adobe
2010-04-22 02:07:37 0 d—–w- c:\programdata\NOS
2010-04-20 23:45:21 0 d–h–w- C:\$AVG
2010-04-20 08:46:42 70656 –sha-r- c:\users\alex\appdata\roaming\srwmib.dll
2010-04-20 08:35:01 0 d—–w- c:\programdata\Blizzard Entertainment
2010-04-20 08:06:07 0 d—–w- c:\users\alex\appdata\roaming\LimeWire
2010-04-20 08:00:59 0 d—–w- c:\programdata\Sun
2010-04-20 08:00:50 411368 —-a-w- c:\windows\system32\deploytk.dll
2010-04-20 08:00:11 0 d—–w- c:\program files\LimeWire
2010-04-20 07:32:04 0 d—–w- c:\programdata\Blizzard
2010-04-20 07:14:37 0 d—–w- c:\program files\Firaxis Games
2010-04-20 07:14:16 2297552 —-a-w- c:\windows\system32\d3dx9_26.dll
2010-04-20 02:56:46 0 d—–w- c:\program files\common files\Blizzard Entertainment
2010-04-19 09:14:42 0 d—–w- c:\users\alex\appdata\roaming\BitTorrent
2010-04-19 09:14:18 0 d—–w- c:\program files\BitTorrent
2010-04-19 04:49:26 0 d—–w- c:\windows\Panther
2010-04-19 04:49:14 8192 –sha-r- C:\BOOTSECT.BAK
2010-04-19 04:49:12 383562 –sha-r- C:\bootmgr
2010-04-19 04:49:12 0 d-sh–w- C:\Boot
2010-04-19 03:52:27 0 —-a-w- c:\windows\ativpsrm.bin
2010-04-19 02:27:40 2414360 —-a-w- c:\windows\system32\d3dx9_31.dll
2010-04-19 02:27:40 1892184 —-a-w- c:\windows\system32\D3DX9_42.dll
2010-04-19 02:27:27 0 d—–w- c:\program files\Winamp Detect
2010-04-19 02:27:23 0 d—–w- c:\program files\common files\PX Storage Engine
2010-04-19 02:24:43 0 d—–w- c:\users\alex\appdata\roaming\Trillian
2010-04-19 02:04:14 0 d—–w- c:\program files\Ventrilo
2010-04-19 02:04:11 262 —-a-w- c:\windows\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
2010-04-19 02:03:06 0 d—–w- c:\program files\common files\Wise Installation Wizard
2010-04-19 01:44:11 12464 —-a-w- c:\windows\system32\avgrsstx.dll
2010-04-19 01:44:10 242896 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2010-04-19 01:44:06 216200 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2010-04-19 01:44:05 0 d—–w- c:\windows\system32\drivers\Avg
2010-04-19 01:44:04 0 d—–w- c:\programdata\AVG Security Toolbar
2010-04-19 01:42:26 0 d—–w- c:\program files\AVG
2010-04-19 01:42:16 0 d—–w- c:\programdata\avg9
2010-04-19 01:41:42 0 d-sh–w- c:\windows\Installer
2010-04-19 01:17:06 257024 —-a-w- c:\windows\system32\msv1_0.dll
2010-04-19 01:15:00 181632 ——w- c:\windows\system32\MpSigStub.exe
2010-04-19 01:13:13 132608 —-a-w- c:\windows\system32\cabview.dll
2010-04-19 01:13:01 95744 —-a-w- c:\windows\system32\drivers\mrxsmb20.sys
2010-04-19 01:13:01 221696 —-a-w- c:\windows\system32\drivers\mrxsmb10.sys
2010-04-19 01:13:01 123392 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-04-19 01:03:59 713888 —-a-w- c:\windows\system32\PerfStringBackup.INI
2010-04-19 01:03:47 0 d—–w- c:\windows\system32\wbem\Performance
2010-04-19 00:58:33 171136 –sha-r- C:\grldr
2010-04-19 00:57:57 0 d-sh–w- C:\Recovery
==================== Find3M ====================
2010-03-08 21:33:56 427520 —-a-w- c:\windows\system32\vbscript.dll
2010-02-27 12:07:48 3954568 —-a-w- c:\windows\system32\ntkrnlpa.exe
2010-02-27 12:07:48 3899280 —-a-w- c:\windows\system32\ntoskrnl.exe
2010-02-23 07:56:00 977920 —-a-w- c:\windows\system32\wininet.dll
2010-02-02 07:45:54 2048 —-a-w- c:\windows\system32\tzres.dll
2009-07-14 04:56:42 31548 —-a-w- c:\windows\inf\perflib\0409\perfd.dat
2009-07-14 04:56:42 31548 —-a-w- c:\windows\inf\perflib\0409\perfc.dat
2009-07-14 04:56:42 291294 —-a-w- c:\windows\inf\perflib\0409\perfi.dat
2009-07-14 04:56:42 291294 —-a-w- c:\windows\inf\perflib\0409\perfh.dat
2009-07-14 04:41:57 174 –sha-w- c:\program files\desktop.ini
2009-07-14 00:34:40 291294 —-a-w- c:\windows\inf\perflib\0000\perfi.dat
2009-07-14 00:34:40 291294 —-a-w- c:\windows\inf\perflib\0000\perfh.dat
2009-07-14 00:34:38 31548 —-a-w- c:\windows\inf\perflib\0000\perfd.dat
2009-07-14 00:34:38 31548 —-a-w- c:\windows\inf\perflib\0000\perfc.dat
2009-06-10 21:26:35 9633792 –sha-r- c:\windows\fonts\StaticCache.dat
2009-07-14 01:14:45 396800 –sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe
============= FINISH: 18:46:42.74 ===============
GMER.txt
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-04-28 18:56:59
Windows 6.1.7600
Running: kffnhjlq.exe; Driver: C:\Users\Alex\AppData\Local\Temp\kxldrpog.sys
—- System - GMER 1.0.15 —-
INT 0x1F \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 8281EAF8
INT 0x37 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 8281E104
INT 0xC1 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 8281E3F4
INT 0xD1 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82806634
INT 0xD2 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82806898
INT 0xDF \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 8281E1DC
INT 0xE1 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 8281E958
INT 0xE3 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 8281E6F8
INT 0xFD \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 8281EF2C
INT 0xFE \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 8281F1A8
—- Kernel code sections - GMER 1.0.15 —-
.text ntkrnlpa.exe!ZwSaveKeyEx + 13AD 8287E599 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 828A2F52 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, …] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
.text C:\Windows\system32\DRIVERS\atikmdag.sys section is writeable [0x91E28000, 0x2D5378, 0xE8000020]
.text peauth.sys 98962C9D 28 Bytes [84, F3, C3, 8F, 5E, BE, D9, …]
.text peauth.sys 98962CC1 28 Bytes [84, F3, C3, 8F, 5E, BE, D9, …]
PAGE peauth.sys 98968B9B 72 Bytes [49, 06, 1A, 6E, 80, C3, 77, …]
PAGE peauth.sys 98968BEC 111 Bytes [99, B5, 31, 3B, 77, 60, C5, …]
PAGE peauth.sys 9896902C 102 Bytes [10, 8B, BD, 24, DE, E6, 30, …]
—- Devices - GMER 1.0.15 —-
Device \Driver\ACPI_HAL \Device\00000045 halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)
AttachedDevice \Driver\tdx \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume4 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume4 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
AttachedDevice \Driver\tdx \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\tdx \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
—- EOF - GMER 1.0.15 —-
Thanks for the assistance.