MarilynM
Topic Starter
Hi,
Recently, when I open up Internet Explorer, sometimes multiple windows would pop up, and the only way I can stop it is by ending iexplore.exe on my Task Manager.
I'm not sure if I'm infected or not, and I would really appreciate some help.
Thanks so much!
Below are DDS.txt and my GMER.txt, and attached is my Attach.txt.
DDS.txt
DDS (Ver_10-03-17.01) - NTFSx86
Run by [removed] at 22:43:21.95 on 29/04/2010
Internet Explorer: 7.0.6002.18005 BrowserJavaVersion: 1.6.0_13
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.2.1033.18.2813.1470 [GMT -7:00]
AV: nProtect GameGuard Personal 2007 *On-access scanning enabled* (Updated) {7D36BE97-9969-4C9F-9DC1-282DB4E1FBEA}
SP: Spybot - Search and Destroy *disabled* (Updated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_e7ea6efc\STacSV.exe
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\Ati2evxx.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\Hpservice.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\WLANExt.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_e7ea6efc\aestsrv.exe
C:\Windows\system32\agrsmsvc.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Norton Internet Security\Engine\16.0.0.125\ccSvcHst.exe
C:\Windows\system32\INCAinternet\nProtect Security Platform 2007\nspsvc.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\SMINST\BLService.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Hewlett-Packard\Media\TV\Kernel\TV\TVCapSvc.exe
C:\Program Files\Hewlett-Packard\Media\TV\Kernel\TV\TVSched.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
C:\Windows\system32\taskeng.exe
C:\Windows\System32\INCAInternet\nProtect Security Platform 2007\nspupsvc.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\IDT\WDM\sttray.exe
C:\Program Files\AVG\AVG9\avgtray.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Crawler\Notes\CNotes.exe
c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
C:\Program Files\Apoint2K\ApMsgFwd.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Windows\system32\conime.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Hewlett-Packard\Shared\hpqToaster.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Windows\system32\svchost.exe -k SDRSVC
C:\Program Files\INCAInternet\nProtect Security Platform 2007\nspupdt.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Program Files\Internet Explorer\ieuser.exe
c:\Program Files\MSN\Toolbar\3.0.0541.0\msntask.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10e.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\System32\svchost.exe -k swprv
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Marilyn Mach\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JFGQLNBM\dds[1].scr
C:\Windows\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.ca/
uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_ca&c=91&bd=Pavilion&pf=cnnb
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_ca&c=91&bd=Pavilion&pf=cnnb
mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_ca&c=91&bd=Pavilion&pf=cnnb
uInternet Settings,ProxyOverride = *.local
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\norton internet security\engine\16.0.0.125\coIEPlg.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton internet security\engine\16.0.0.125\IPSBHO.DLL
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Microsoft Live Search Toolbar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files\msn\toolbar\3.0.0541.0\msneshellx.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\norton internet security\engine\16.0.0.125\coIEPlg.dll
TB: Microsoft Live Search Toolbar: {1e61ed7c-7cb8-49d6-b9e9-ab4c880c8414} - c:\program files\msn\toolbar\3.0.0541.0\msneshellx.dll
TB: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File
TB: {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
uRun: [LightScribe Control Panel] c:\program files\common files\lightscribe\LightScribeControlPanel.exe -hidden
uRun: [MsnMsgr] "c:\program files\windows live\messenger\MsnMsgr.Exe" /background
uRun: [Aim6]
uRun: [BitTorrent DNA] "c:\users\marilyn mach\program files\dna\btdna.exe"
uRun: [CrawlerNotes] c:\progra~1\crawler\notes\cnotes.exe /notesshow
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
uRun: [AdobeUpdater6] "c:\program files\common files\adobe\updater6\Adobe_Updater.exe"
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [Apoint] c:\program files\apoint2k\Apoint.exe
mRun: [DVDAgent] "c:\program files\hewlett-packard\media\dvd\DVDAgent.exe"
mRun: [TSMAgent] "c:\program files\hewlett-packard\touchsmart\media\TSMAgent.exe"
mRun: [CLMLServer for HP TouchSmart] "c:\program files\hewlett-packard\touchsmart\media\kernel\clml\CLMLSvc.exe"
mRun: [TVAgent] "c:\program files\hewlett-packard\media\tv\TVAgent.exe"
mRun: [SmartMenu] %ProgramFiles%\Hewlett-Packard\HP MediaSmart\SmartMenu.exe
mRun: [UpdateLBPShortCut] "c:\program files\cyberlink\labelprint\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\labelprint" updatewithcreateonce "software\cyberlink\labelprint\2.5"
mRun: [UpdatePSTShortCut] "c:\program files\cyberlink\dvd suite\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\dvd suite" updatewithcreateonce "software\cyberlink\PowerStarter"
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [QlbCtrl.exe] c:\program files\hewlett-packard\hp quick launch buttons\QlbCtrl.exe /Start
mRun: [UpdateP2GoShortCut] "c:\program files\cyberlink\power2go\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\power2go" updatewithcreateonce "software\cyberlink\power2go\6.0"
mRun: [UpdatePDIRShortCut] "c:\program files\cyberlink\powerdirector\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\powerdirector" updatewithcreateonce "software\cyberlink\powerdirector\7.0"
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [HP Health Check Scheduler] c:\program files\hewlett-packard\hp health check\HPHC_Scheduler.exe
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [WirelessAssistant] c:\program files\hewlett-packard\hp wireless assistant\HPWAMain.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [UCam_Menu] "c:\program files\hewlett-packard\media\webcam\muitransfer\muistartmenu.exe" "c:\program files\hewlett-packard\media\webcam" update "software\hewlett-packard\media\Webcam"
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [nProtect Security Platform 2007] c:\program files\incainternet\nprotect security platform 2007\nspmain.exe -tray
mRun: [SysTrayApp] %ProgramFiles%\IDT\WDM\sttray.exe
mRun: []
mRun: [RoxWatchTray] "c:\program files\common files\roxio shared\9.0\sharedcom\RoxWatchTray9.exe"
mRun: [DivXUpdate] "c:\program files\divx\divx update\DivXUpdate.exe" /CHECKNOW
mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [AVG9_TRAY] c:\progra~1\avg\avg9\avgtray.exe
StartupFolder: c:\users\marily~1\appdata\roaming\micros~1\windows\startm~1\programs\startup\magicd~1.lnk - c:\program files\magicdisc\MagicDisc.exe
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: &AIM Toolbar Search
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} - hxxp://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
DPF: {48DD0448-9209-4F81-9F6D-D83562940134} - hxxp://lads.myspace.com/upload/MySpaceUploader1006.cab
DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://gfx1.hotmail.com/mail/w3/resources/VistaMSNPUplden-ca.cab
DPF: {5D6F45B3-9043-443D-A792-115447494D24} - hxxp://messenger.zone.msn.com/MessengerGamesContent/GameContent/Default/uno1/GAME_UNO1.cab
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {9C23D886-43CB-43DE-B2DB-112A68D7E10A} - hxxp://lads.myspace.com/upload/MySpaceUploader2.cab
DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_10-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {DAF7E6E6-D53A-439A-B28D-12271406B8A9} - hxxp://mobileapps.blackberry.com/devicesoftware/AxLoader.cab
DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} - hxxp://gfx1.hotmail.com/mail/w4/pr01/photouploadcontrol/VistaMSNPUplden-ca.cab
DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} - hxxp://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll
AppInit_DLLs: avgrsstx.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "c:\program files\common files\lightscribe\LSRunOnce.exe"
================= FIREFOX ===================
FF - ProfilePath - c:\users\marily~1\appdata\roaming\mozilla\firefox\profiles\ci5f330q.default\
FF - prefs.js: browser.search.defaulturl - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType=tb50fftrie7&query=
FF - prefs.js: browser.search.selectedEngine - AIM Search
FF - prefs.js: browser.startup.homepage - hxxp://www.google.ca
FF - prefs.js: keyword.URL - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType=tb50fftrab&query=
FF - component: c:\program files\avg\avg9\firefox\components\avgssff.dll
FF - component: c:\program files\real\realplayer\browserrecord\components\nprpbrowserrecordplugin.dll
FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npijjiautoinstallpluginff.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\viewpoint\viewpoint media player\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
============= SERVICES / DRIVERS ===============
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2010-4-16 216200]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2010-4-16 29512]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2010-4-16 242896]
R2 {55662437-DA8C-40c0-AADA-2C816A897A49};Power Control [2009/03/14 02:35:35];c:\program files\hewlett-packard\media\dvd\000.fcl [2008-11-28 87536]
R2 AESTFilters;Andrea ST Filters Service;c:\windows\system32\driverstore\filerepository\stwrt.inf_e7ea6efc\AEstSrv.exe [2009-3-14 77824]
R2 avg9wd;AVG Free WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2010-4-16 308064]
R2 hpsrv;HP Service;c:\windows\system32\hpservice.exe [2008-3-18 19456]
R3 enecir;ENE CIR Receiver;c:\windows\system32\drivers\enecir.sys [2008-1-24 52736]
R3 TKFsAc;TKFsAc;c:\windows\system32\TKFsAc2k.sys [2009-5-15 87776]
R3 TKFsFt;TKFsFt;c:\windows\system32\TKFsFt2k.sys [2009-5-15 82016]
R3 TKRgAc;TKRgAc;c:\windows\system32\TKRgAc2k.sys [2009-5-15 41984]
R3 TKRgFt;TKRgFt;c:\windows\system32\TKRgFtXp.sys [2009-5-15 24704]
R3 usbfilter;AMD USB Filter Driver;c:\windows\system32\drivers\usbfilter.sys [2009-4-2 22072]
S3 Com4QLBEx;Com4QLBEx;c:\program files\hewlett-packard\hp quick launch buttons\Com4QLBEx.exe [2009-3-7 222512]
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 21504]
S3 JMCR;JMCR;c:\windows\system32\drivers\jmcr.sys [2008-7-21 100184]
S3 TKFsAv;TKFsAv;c:\windows\system32\TKFsAv2k.sys [2009-5-15 55776]
=============== Created Last 30 ================
2010-04-30 05:43:44 0 d—–w- c:\temp\Update
2010-04-23 05:01:12 505104 —-a-w- c:\windows\system32\msxml.dll
2010-04-23 05:01:12 115016 —-a-w- c:\windows\system32\MSINET.OCX
2010-04-23 05:01:10 89360 —-a-w- c:\windows\system32\VB5DB.DLL
2010-04-23 05:01:10 69632 —-a-w- c:\windows\system32\xmltok.dll
2010-04-23 05:01:10 36864 —-a-w- c:\windows\system32\xmlparse.dll
2010-04-23 05:01:10 35840 —-a-w- c:\windows\system32\comdlg32.oca
2010-04-23 05:01:10 29184 —-a-w- c:\windows\system32\MSINET.oca
2010-04-23 05:01:10 28432 —-a-w- c:\windows\system32\msxmlr.dll
2010-04-23 05:01:10 26088 —-a-w- c:\windows\system32\xmlinst.exe
2010-04-23 05:01:10 24576 —-a-w- c:\windows\system32\msxml3a.dll
2010-04-23 05:01:08 0 d—–w- c:\program files\directx
2010-04-22 22:08:49 0 d—–w- c:\users\marily~1\appdata\roaming\BitTorrent
2010-04-22 05:08:29 297 —-a-w- c:\windows\EReg077.dat
2010-04-22 05:07:36 289280 —-a-w- c:\windows\uninst.exe
2010-04-22 04:57:04 0 d–h–w- C:\$AVG
2010-04-16 19:39:33 12464 —-a-w- c:\windows\system32\avgrsstx.dll
2010-04-16 19:39:30 242896 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2010-04-16 19:39:23 216200 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2010-04-16 19:39:20 0 d—–w- c:\windows\system32\drivers\Avg
2010-04-16 19:35:58 0 d—–w- c:\programdata\avg9
2010-04-15 00:53:32 3600776 —-a-w- c:\windows\system32\ntkrnlpa.exe
2010-04-15 00:53:32 3548040 —-a-w- c:\windows\system32\ntoskrnl.exe
2010-04-15 00:53:28 79360 —-a-w- c:\windows\system32\drivers\mrxsmb20.sys
2010-04-15 00:53:28 212992 —-a-w- c:\windows\system32\drivers\mrxsmb10.sys
2010-04-15 00:53:28 106496 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-04-15 00:52:13 430080 —-a-w- c:\windows\system32\vbscript.dll
2010-04-15 00:51:58 62464 —-a-w- c:\windows\system32\l3codeca.acm
2010-04-15 00:51:58 220672 —-a-w- c:\windows\system32\l3codecp.acm
2010-04-15 00:50:00 904576 —-a-w- c:\windows\system32\drivers\tcpip.sys
2010-04-15 00:49:59 25088 —-a-w- c:\windows\system32\drivers\tunnel.sys
2010-04-15 00:49:59 200704 —-a-w- c:\windows\system32\iphlpsvc.dll
2010-04-13 21:20:34 172032 —-a-w- c:\windows\system32\wintrust.dll
2010-04-13 21:20:32 98304 —-a-w- c:\windows\system32\cabview.dll
2010-04-04 06:37:58 86683 —-a-w- c:\windows\system32\pthreadGC2.dll
2010-04-04 06:37:56 0 d—–w- c:\program files\AoA Audio Extractor
2010-04-02 07:17:09 0 d—–w- c:\program files\AVG
==================== Find3M ====================
2010-04-30 01:08:44 672380 —-a-w- c:\windows\system32\perfh00C.dat
2010-04-30 01:08:44 132080 —-a-w- c:\windows\system32\perfc00C.dat
2010-04-13 17:04:04 82016 —-a-w- c:\windows\system32\TKFsFt2k.sys
2010-04-13 17:04:04 81002 —-a-w- c:\windows\system32\TKFsFtNt4.sys
2010-04-13 17:04:04 69382 —-a-w- c:\windows\system32\TKFsAvNt4.sys
2010-04-13 17:04:04 65632 —-a-w- c:\windows\system32\TKFsAv2k64.sys
2010-04-13 17:04:04 63584 —-a-w- c:\windows\system32\TKFsFt2k64.sys
2010-04-13 17:04:04 55776 —-a-w- c:\windows\system32\TKFsAv2k.sys
2010-04-13 17:04:04 41476 —-a-w- c:\windows\system32\TKToolNt4.sys
2010-04-13 17:04:04 27232 —-a-w- c:\windows\system32\TKTool2k64.sys
2010-04-13 17:04:04 236544 —-a-w- c:\windows\system32\TKTool64.dll
2010-04-13 17:04:04 19456 —-a-w- c:\windows\system32\TKTool2k.sys
2010-04-12 08:14:58 13844 —-a-w- c:\users\marily~1\appdata\roaming\wklnhst.dat
2010-03-22 20:39:32 454656 —-a-w- c:\windows\system32\nspavxml.dll
2010-03-22 20:37:20 93792 —-a-w- c:\windows\system32\TKFsAc2k64.sys
2010-03-22 20:37:20 87776 —-a-w- c:\windows\system32\TKFsAc2k.sys
2010-03-22 20:37:20 318048 —-a-w- c:\windows\system32\TKFsAv.dll
2010-03-22 20:37:20 219744 —-a-w- c:\windows\system32\TKFsAv64.dll
2010-03-22 20:37:20 162700 —-a-w- c:\windows\system32\TKFsAcNt4.sys
2010-03-09 16:25:21 78336 —-a-w- c:\windows\system32\ieencode.dll
2010-03-09 15:42:17 834048 —-a-w- c:\windows\system32\wininet.dll
2010-02-24 17:16:06 181632 ——w- c:\windows\system32\MpSigStub.exe
2010-02-20 23:06:41 24064 —-a-w- c:\windows\system32\nshhttp.dll
2010-02-20 23:05:14 30720 —-a-w- c:\windows\system32\httpapi.dll
2010-01-27 04:43:38 51200 —-a-w- c:\windows\inf\infpub.dat
2010-01-27 04:43:38 143360 —-a-w- c:\windows\inf\infstrng.dat
2009-10-30 05:23:49 665600 —-a-w- c:\windows\inf\drvindex.dat
2009-10-30 05:23:48 86016 —-a-w- c:\windows\inf\infstor.dat
2009-03-07 12:47:43 37390 —-a-w- c:\windows\inf\perflib\040c\perfd.dat
2009-03-07 12:47:43 37390 —-a-w- c:\windows\inf\perflib\040c\perfc.dat
2009-03-07 12:47:43 340236 —-a-w- c:\windows\inf\perflib\040c\perfi.dat
2009-03-07 12:47:43 340236 —-a-w- c:\windows\inf\perflib\040c\perfh.dat
2008-01-21 02:43:21 174 –sha-w- c:\program files\desktop.ini
2006-11-02 12:42:02 30674 —-a-w- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 12:42:02 30674 —-a-w- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 12:42:02 287440 —-a-w- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 12:42:02 287440 —-a-w- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 09:20:21 287440 —-a-w- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 09:20:21 287440 —-a-w- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 09:20:19 30674 —-a-w- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 09:20:19 30674 —-a-w- c:\windows\inf\perflib\0000\perfc.dat
2009-12-30 00:05:54 16384 –sha-w- c:\windows\serviceprofiles\localservice\appdata\local\temp\cookies\index.dat
2009-12-30 00:05:54 16384 –sha-w- c:\windows\serviceprofiles\localservice\appdata\local\temp\history\history.ie5\index.dat
2009-12-30 00:05:54 32768 –sha-w- c:\windows\serviceprofiles\localservice\appdata\local\temp\temporary internet files\content.ie5\index.dat
2009-03-07 13:06:03 8192 –sha-w- c:\windows\users\default\NTUSER.DAT
============= FINISH: 22:46:41.56 ===============
GMER.txt
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-04-30 18:03:14
Windows 6.0.6002 Service Pack 2
Running: broxrisu.exe; Driver: C:\Users\MARILY~1\AppData\Local\Temp\agdcafoc.sys
—- System - GMER 1.0.15 —-
SSDT \??\C:\Windows\system32\TKFsFt2k.sys ZwTerminateProcess [0xB0E39BE0]
—- Kernel code sections - GMER 1.0.15 —-
.text ntkrnlpa.exe!KeSetEvent + 621 820C6D84 4 Bytes [E0, 9B, E3, B0] {LOOPNZ 0xffffffffffffff9d; JECXZ 0xffffffffffffffb4}
.text C:\Windows\system32\DRIVERS\atikmdag.sys section is writeable [0x9F80B000, 0x23100A, 0xE8000020]
.text C:\Program Files\Hewlett-Packard\Media\DVD\000.fcl section is writeable [0xB0E06000, 0x2892, 0xE8000020]
.vmp2 C:\Program Files\Hewlett-Packard\Media\DVD\000.fcl entry point in ".vmp2" section [0xB0E29050]
—- User code sections - GMER 1.0.15 —-
.text C:\Program Files\Internet Explorer\iexplore.exe[5740] USER32.dll!DialogBoxParamW 766210B0 5 Bytes JMP 6D9FBF9F C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5740] USER32.dll!DialogBoxIndirectParamW 76622EF5 5 Bytes JMP 6DB3B45A C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5740] USER32.dll!DialogBoxParamA 76638152 5 Bytes JMP 6DB3B41F C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5740] USER32.dll!DialogBoxIndirectParamA 7663847D 5 Bytes JMP 6DB3B495 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5740] USER32.dll!MessageBoxIndirectA 7664D4D9 5 Bytes JMP 6DB3B3DB C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5740] USER32.dll!MessageBoxIndirectW 7664D5D3 5 Bytes JMP 6DB3B397 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5740] USER32.dll!MessageBoxExA 7664D639 5 Bytes JMP 6DB3B35D C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5740] USER32.dll!MessageBoxExW 7664D65D 5 Bytes JMP 6DB3B323 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5740] SHELL32.dll!SHRestricted + D95 76768988 4 Bytes [99, 0B, D0, 72]
.text C:\Program Files\Internet Explorer\iexplore.exe[5740] SHELL32.dll!SHRestricted + D9D 76768990 8 Bytes [A7, 0A, D0, 72, A4, 32, CF, …]
.text C:\Program Files\Internet Explorer\iexplore.exe[5740] ole32.dll!OleLoadFromStream 77331E12 5 Bytes JMP 6DB3B657 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
—- Devices - GMER 1.0.15 —-
AttachedDevice \FileSystem\Ntfs \Ntfs TKFsFt2k.sys
AttachedDevice \Driver\tdx \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\tdx \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\tdx \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
—- Registry - GMER 1.0.15 —-
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\002186b8a8bc
Reg HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\002186b8a8bc (not active ControlSet)
—- EOF - GMER 1.0.15 —-
– Thanks again!
Recently, when I open up Internet Explorer, sometimes multiple windows would pop up, and the only way I can stop it is by ending iexplore.exe on my Task Manager.
I'm not sure if I'm infected or not, and I would really appreciate some help.
Thanks so much!
Below are DDS.txt and my GMER.txt, and attached is my Attach.txt.
DDS.txt
DDS (Ver_10-03-17.01) - NTFSx86
Run by [removed] at 22:43:21.95 on 29/04/2010
Internet Explorer: 7.0.6002.18005 BrowserJavaVersion: 1.6.0_13
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.2.1033.18.2813.1470 [GMT -7:00]
AV: nProtect GameGuard Personal 2007 *On-access scanning enabled* (Updated) {7D36BE97-9969-4C9F-9DC1-282DB4E1FBEA}
SP: Spybot - Search and Destroy *disabled* (Updated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_e7ea6efc\STacSV.exe
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\Ati2evxx.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\Hpservice.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\WLANExt.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_e7ea6efc\aestsrv.exe
C:\Windows\system32\agrsmsvc.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Norton Internet Security\Engine\16.0.0.125\ccSvcHst.exe
C:\Windows\system32\INCAinternet\nProtect Security Platform 2007\nspsvc.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\SMINST\BLService.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Hewlett-Packard\Media\TV\Kernel\TV\TVCapSvc.exe
C:\Program Files\Hewlett-Packard\Media\TV\Kernel\TV\TVSched.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
C:\Windows\system32\taskeng.exe
C:\Windows\System32\INCAInternet\nProtect Security Platform 2007\nspupsvc.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\IDT\WDM\sttray.exe
C:\Program Files\AVG\AVG9\avgtray.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Crawler\Notes\CNotes.exe
c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
C:\Program Files\Apoint2K\ApMsgFwd.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Windows\system32\conime.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Hewlett-Packard\Shared\hpqToaster.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Windows\system32\svchost.exe -k SDRSVC
C:\Program Files\INCAInternet\nProtect Security Platform 2007\nspupdt.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Program Files\Internet Explorer\ieuser.exe
c:\Program Files\MSN\Toolbar\3.0.0541.0\msntask.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10e.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\System32\svchost.exe -k swprv
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Marilyn Mach\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JFGQLNBM\dds[1].scr
C:\Windows\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.ca/
uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_ca&c=91&bd=Pavilion&pf=cnnb
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_ca&c=91&bd=Pavilion&pf=cnnb
mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_ca&c=91&bd=Pavilion&pf=cnnb
uInternet Settings,ProxyOverride = *.local
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\norton internet security\engine\16.0.0.125\coIEPlg.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton internet security\engine\16.0.0.125\IPSBHO.DLL
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Microsoft Live Search Toolbar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files\msn\toolbar\3.0.0541.0\msneshellx.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\norton internet security\engine\16.0.0.125\coIEPlg.dll
TB: Microsoft Live Search Toolbar: {1e61ed7c-7cb8-49d6-b9e9-ab4c880c8414} - c:\program files\msn\toolbar\3.0.0541.0\msneshellx.dll
TB: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File
TB: {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
uRun: [LightScribe Control Panel] c:\program files\common files\lightscribe\LightScribeControlPanel.exe -hidden
uRun: [MsnMsgr] "c:\program files\windows live\messenger\MsnMsgr.Exe" /background
uRun: [Aim6]
uRun: [BitTorrent DNA] "c:\users\marilyn mach\program files\dna\btdna.exe"
uRun: [CrawlerNotes] c:\progra~1\crawler\notes\cnotes.exe /notesshow
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
uRun: [AdobeUpdater6] "c:\program files\common files\adobe\updater6\Adobe_Updater.exe"
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [Apoint] c:\program files\apoint2k\Apoint.exe
mRun: [DVDAgent] "c:\program files\hewlett-packard\media\dvd\DVDAgent.exe"
mRun: [TSMAgent] "c:\program files\hewlett-packard\touchsmart\media\TSMAgent.exe"
mRun: [CLMLServer for HP TouchSmart] "c:\program files\hewlett-packard\touchsmart\media\kernel\clml\CLMLSvc.exe"
mRun: [TVAgent] "c:\program files\hewlett-packard\media\tv\TVAgent.exe"
mRun: [SmartMenu] %ProgramFiles%\Hewlett-Packard\HP MediaSmart\SmartMenu.exe
mRun: [UpdateLBPShortCut] "c:\program files\cyberlink\labelprint\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\labelprint" updatewithcreateonce "software\cyberlink\labelprint\2.5"
mRun: [UpdatePSTShortCut] "c:\program files\cyberlink\dvd suite\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\dvd suite" updatewithcreateonce "software\cyberlink\PowerStarter"
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [QlbCtrl.exe] c:\program files\hewlett-packard\hp quick launch buttons\QlbCtrl.exe /Start
mRun: [UpdateP2GoShortCut] "c:\program files\cyberlink\power2go\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\power2go" updatewithcreateonce "software\cyberlink\power2go\6.0"
mRun: [UpdatePDIRShortCut] "c:\program files\cyberlink\powerdirector\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\powerdirector" updatewithcreateonce "software\cyberlink\powerdirector\7.0"
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [HP Health Check Scheduler] c:\program files\hewlett-packard\hp health check\HPHC_Scheduler.exe
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [WirelessAssistant] c:\program files\hewlett-packard\hp wireless assistant\HPWAMain.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [UCam_Menu] "c:\program files\hewlett-packard\media\webcam\muitransfer\muistartmenu.exe" "c:\program files\hewlett-packard\media\webcam" update "software\hewlett-packard\media\Webcam"
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [nProtect Security Platform 2007] c:\program files\incainternet\nprotect security platform 2007\nspmain.exe -tray
mRun: [SysTrayApp] %ProgramFiles%\IDT\WDM\sttray.exe
mRun: []
mRun: [RoxWatchTray] "c:\program files\common files\roxio shared\9.0\sharedcom\RoxWatchTray9.exe"
mRun: [DivXUpdate] "c:\program files\divx\divx update\DivXUpdate.exe" /CHECKNOW
mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [AVG9_TRAY] c:\progra~1\avg\avg9\avgtray.exe
StartupFolder: c:\users\marily~1\appdata\roaming\micros~1\windows\startm~1\programs\startup\magicd~1.lnk - c:\program files\magicdisc\MagicDisc.exe
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: &AIM Toolbar Search
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} - hxxp://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
DPF: {48DD0448-9209-4F81-9F6D-D83562940134} - hxxp://lads.myspace.com/upload/MySpaceUploader1006.cab
DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://gfx1.hotmail.com/mail/w3/resources/VistaMSNPUplden-ca.cab
DPF: {5D6F45B3-9043-443D-A792-115447494D24} - hxxp://messenger.zone.msn.com/MessengerGamesContent/GameContent/Default/uno1/GAME_UNO1.cab
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {9C23D886-43CB-43DE-B2DB-112A68D7E10A} - hxxp://lads.myspace.com/upload/MySpaceUploader2.cab
DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_10-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {DAF7E6E6-D53A-439A-B28D-12271406B8A9} - hxxp://mobileapps.blackberry.com/devicesoftware/AxLoader.cab
DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} - hxxp://gfx1.hotmail.com/mail/w4/pr01/photouploadcontrol/VistaMSNPUplden-ca.cab
DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} - hxxp://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll
AppInit_DLLs: avgrsstx.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "c:\program files\common files\lightscribe\LSRunOnce.exe"
================= FIREFOX ===================
FF - ProfilePath - c:\users\marily~1\appdata\roaming\mozilla\firefox\profiles\ci5f330q.default\
FF - prefs.js: browser.search.defaulturl - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType=tb50fftrie7&query=
FF - prefs.js: browser.search.selectedEngine - AIM Search
FF - prefs.js: browser.startup.homepage - hxxp://www.google.ca
FF - prefs.js: keyword.URL - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType=tb50fftrab&query=
FF - component: c:\program files\avg\avg9\firefox\components\avgssff.dll
FF - component: c:\program files\real\realplayer\browserrecord\components\nprpbrowserrecordplugin.dll
FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npijjiautoinstallpluginff.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\viewpoint\viewpoint media player\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
============= SERVICES / DRIVERS ===============
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2010-4-16 216200]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2010-4-16 29512]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2010-4-16 242896]
R2 {55662437-DA8C-40c0-AADA-2C816A897A49};Power Control [2009/03/14 02:35:35];c:\program files\hewlett-packard\media\dvd\000.fcl [2008-11-28 87536]
R2 AESTFilters;Andrea ST Filters Service;c:\windows\system32\driverstore\filerepository\stwrt.inf_e7ea6efc\AEstSrv.exe [2009-3-14 77824]
R2 avg9wd;AVG Free WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2010-4-16 308064]
R2 hpsrv;HP Service;c:\windows\system32\hpservice.exe [2008-3-18 19456]
R3 enecir;ENE CIR Receiver;c:\windows\system32\drivers\enecir.sys [2008-1-24 52736]
R3 TKFsAc;TKFsAc;c:\windows\system32\TKFsAc2k.sys [2009-5-15 87776]
R3 TKFsFt;TKFsFt;c:\windows\system32\TKFsFt2k.sys [2009-5-15 82016]
R3 TKRgAc;TKRgAc;c:\windows\system32\TKRgAc2k.sys [2009-5-15 41984]
R3 TKRgFt;TKRgFt;c:\windows\system32\TKRgFtXp.sys [2009-5-15 24704]
R3 usbfilter;AMD USB Filter Driver;c:\windows\system32\drivers\usbfilter.sys [2009-4-2 22072]
S3 Com4QLBEx;Com4QLBEx;c:\program files\hewlett-packard\hp quick launch buttons\Com4QLBEx.exe [2009-3-7 222512]
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 21504]
S3 JMCR;JMCR;c:\windows\system32\drivers\jmcr.sys [2008-7-21 100184]
S3 TKFsAv;TKFsAv;c:\windows\system32\TKFsAv2k.sys [2009-5-15 55776]
=============== Created Last 30 ================
2010-04-30 05:43:44 0 d—–w- c:\temp\Update
2010-04-23 05:01:12 505104 —-a-w- c:\windows\system32\msxml.dll
2010-04-23 05:01:12 115016 —-a-w- c:\windows\system32\MSINET.OCX
2010-04-23 05:01:10 89360 —-a-w- c:\windows\system32\VB5DB.DLL
2010-04-23 05:01:10 69632 —-a-w- c:\windows\system32\xmltok.dll
2010-04-23 05:01:10 36864 —-a-w- c:\windows\system32\xmlparse.dll
2010-04-23 05:01:10 35840 —-a-w- c:\windows\system32\comdlg32.oca
2010-04-23 05:01:10 29184 —-a-w- c:\windows\system32\MSINET.oca
2010-04-23 05:01:10 28432 —-a-w- c:\windows\system32\msxmlr.dll
2010-04-23 05:01:10 26088 —-a-w- c:\windows\system32\xmlinst.exe
2010-04-23 05:01:10 24576 —-a-w- c:\windows\system32\msxml3a.dll
2010-04-23 05:01:08 0 d—–w- c:\program files\directx
2010-04-22 22:08:49 0 d—–w- c:\users\marily~1\appdata\roaming\BitTorrent
2010-04-22 05:08:29 297 —-a-w- c:\windows\EReg077.dat
2010-04-22 05:07:36 289280 —-a-w- c:\windows\uninst.exe
2010-04-22 04:57:04 0 d–h–w- C:\$AVG
2010-04-16 19:39:33 12464 —-a-w- c:\windows\system32\avgrsstx.dll
2010-04-16 19:39:30 242896 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2010-04-16 19:39:23 216200 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2010-04-16 19:39:20 0 d—–w- c:\windows\system32\drivers\Avg
2010-04-16 19:35:58 0 d—–w- c:\programdata\avg9
2010-04-15 00:53:32 3600776 —-a-w- c:\windows\system32\ntkrnlpa.exe
2010-04-15 00:53:32 3548040 —-a-w- c:\windows\system32\ntoskrnl.exe
2010-04-15 00:53:28 79360 —-a-w- c:\windows\system32\drivers\mrxsmb20.sys
2010-04-15 00:53:28 212992 —-a-w- c:\windows\system32\drivers\mrxsmb10.sys
2010-04-15 00:53:28 106496 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-04-15 00:52:13 430080 —-a-w- c:\windows\system32\vbscript.dll
2010-04-15 00:51:58 62464 —-a-w- c:\windows\system32\l3codeca.acm
2010-04-15 00:51:58 220672 —-a-w- c:\windows\system32\l3codecp.acm
2010-04-15 00:50:00 904576 —-a-w- c:\windows\system32\drivers\tcpip.sys
2010-04-15 00:49:59 25088 —-a-w- c:\windows\system32\drivers\tunnel.sys
2010-04-15 00:49:59 200704 —-a-w- c:\windows\system32\iphlpsvc.dll
2010-04-13 21:20:34 172032 —-a-w- c:\windows\system32\wintrust.dll
2010-04-13 21:20:32 98304 —-a-w- c:\windows\system32\cabview.dll
2010-04-04 06:37:58 86683 —-a-w- c:\windows\system32\pthreadGC2.dll
2010-04-04 06:37:56 0 d—–w- c:\program files\AoA Audio Extractor
2010-04-02 07:17:09 0 d—–w- c:\program files\AVG
==================== Find3M ====================
2010-04-30 01:08:44 672380 —-a-w- c:\windows\system32\perfh00C.dat
2010-04-30 01:08:44 132080 —-a-w- c:\windows\system32\perfc00C.dat
2010-04-13 17:04:04 82016 —-a-w- c:\windows\system32\TKFsFt2k.sys
2010-04-13 17:04:04 81002 —-a-w- c:\windows\system32\TKFsFtNt4.sys
2010-04-13 17:04:04 69382 —-a-w- c:\windows\system32\TKFsAvNt4.sys
2010-04-13 17:04:04 65632 —-a-w- c:\windows\system32\TKFsAv2k64.sys
2010-04-13 17:04:04 63584 —-a-w- c:\windows\system32\TKFsFt2k64.sys
2010-04-13 17:04:04 55776 —-a-w- c:\windows\system32\TKFsAv2k.sys
2010-04-13 17:04:04 41476 —-a-w- c:\windows\system32\TKToolNt4.sys
2010-04-13 17:04:04 27232 —-a-w- c:\windows\system32\TKTool2k64.sys
2010-04-13 17:04:04 236544 —-a-w- c:\windows\system32\TKTool64.dll
2010-04-13 17:04:04 19456 —-a-w- c:\windows\system32\TKTool2k.sys
2010-04-12 08:14:58 13844 —-a-w- c:\users\marily~1\appdata\roaming\wklnhst.dat
2010-03-22 20:39:32 454656 —-a-w- c:\windows\system32\nspavxml.dll
2010-03-22 20:37:20 93792 —-a-w- c:\windows\system32\TKFsAc2k64.sys
2010-03-22 20:37:20 87776 —-a-w- c:\windows\system32\TKFsAc2k.sys
2010-03-22 20:37:20 318048 —-a-w- c:\windows\system32\TKFsAv.dll
2010-03-22 20:37:20 219744 —-a-w- c:\windows\system32\TKFsAv64.dll
2010-03-22 20:37:20 162700 —-a-w- c:\windows\system32\TKFsAcNt4.sys
2010-03-09 16:25:21 78336 —-a-w- c:\windows\system32\ieencode.dll
2010-03-09 15:42:17 834048 —-a-w- c:\windows\system32\wininet.dll
2010-02-24 17:16:06 181632 ——w- c:\windows\system32\MpSigStub.exe
2010-02-20 23:06:41 24064 —-a-w- c:\windows\system32\nshhttp.dll
2010-02-20 23:05:14 30720 —-a-w- c:\windows\system32\httpapi.dll
2010-01-27 04:43:38 51200 —-a-w- c:\windows\inf\infpub.dat
2010-01-27 04:43:38 143360 —-a-w- c:\windows\inf\infstrng.dat
2009-10-30 05:23:49 665600 —-a-w- c:\windows\inf\drvindex.dat
2009-10-30 05:23:48 86016 —-a-w- c:\windows\inf\infstor.dat
2009-03-07 12:47:43 37390 —-a-w- c:\windows\inf\perflib\040c\perfd.dat
2009-03-07 12:47:43 37390 —-a-w- c:\windows\inf\perflib\040c\perfc.dat
2009-03-07 12:47:43 340236 —-a-w- c:\windows\inf\perflib\040c\perfi.dat
2009-03-07 12:47:43 340236 —-a-w- c:\windows\inf\perflib\040c\perfh.dat
2008-01-21 02:43:21 174 –sha-w- c:\program files\desktop.ini
2006-11-02 12:42:02 30674 —-a-w- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 12:42:02 30674 —-a-w- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 12:42:02 287440 —-a-w- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 12:42:02 287440 —-a-w- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 09:20:21 287440 —-a-w- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 09:20:21 287440 —-a-w- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 09:20:19 30674 —-a-w- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 09:20:19 30674 —-a-w- c:\windows\inf\perflib\0000\perfc.dat
2009-12-30 00:05:54 16384 –sha-w- c:\windows\serviceprofiles\localservice\appdata\local\temp\cookies\index.dat
2009-12-30 00:05:54 16384 –sha-w- c:\windows\serviceprofiles\localservice\appdata\local\temp\history\history.ie5\index.dat
2009-12-30 00:05:54 32768 –sha-w- c:\windows\serviceprofiles\localservice\appdata\local\temp\temporary internet files\content.ie5\index.dat
2009-03-07 13:06:03 8192 –sha-w- c:\windows\users\default\NTUSER.DAT
============= FINISH: 22:46:41.56 ===============
GMER.txt
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-04-30 18:03:14
Windows 6.0.6002 Service Pack 2
Running: broxrisu.exe; Driver: C:\Users\MARILY~1\AppData\Local\Temp\agdcafoc.sys
—- System - GMER 1.0.15 —-
SSDT \??\C:\Windows\system32\TKFsFt2k.sys ZwTerminateProcess [0xB0E39BE0]
—- Kernel code sections - GMER 1.0.15 —-
.text ntkrnlpa.exe!KeSetEvent + 621 820C6D84 4 Bytes [E0, 9B, E3, B0] {LOOPNZ 0xffffffffffffff9d; JECXZ 0xffffffffffffffb4}
.text C:\Windows\system32\DRIVERS\atikmdag.sys section is writeable [0x9F80B000, 0x23100A, 0xE8000020]
.text C:\Program Files\Hewlett-Packard\Media\DVD\000.fcl section is writeable [0xB0E06000, 0x2892, 0xE8000020]
.vmp2 C:\Program Files\Hewlett-Packard\Media\DVD\000.fcl entry point in ".vmp2" section [0xB0E29050]
—- User code sections - GMER 1.0.15 —-
.text C:\Program Files\Internet Explorer\iexplore.exe[5740] USER32.dll!DialogBoxParamW 766210B0 5 Bytes JMP 6D9FBF9F C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5740] USER32.dll!DialogBoxIndirectParamW 76622EF5 5 Bytes JMP 6DB3B45A C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5740] USER32.dll!DialogBoxParamA 76638152 5 Bytes JMP 6DB3B41F C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5740] USER32.dll!DialogBoxIndirectParamA 7663847D 5 Bytes JMP 6DB3B495 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5740] USER32.dll!MessageBoxIndirectA 7664D4D9 5 Bytes JMP 6DB3B3DB C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5740] USER32.dll!MessageBoxIndirectW 7664D5D3 5 Bytes JMP 6DB3B397 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5740] USER32.dll!MessageBoxExA 7664D639 5 Bytes JMP 6DB3B35D C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5740] USER32.dll!MessageBoxExW 7664D65D 5 Bytes JMP 6DB3B323 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5740] SHELL32.dll!SHRestricted + D95 76768988 4 Bytes [99, 0B, D0, 72]
.text C:\Program Files\Internet Explorer\iexplore.exe[5740] SHELL32.dll!SHRestricted + D9D 76768990 8 Bytes [A7, 0A, D0, 72, A4, 32, CF, …]
.text C:\Program Files\Internet Explorer\iexplore.exe[5740] ole32.dll!OleLoadFromStream 77331E12 5 Bytes JMP 6DB3B657 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
—- Devices - GMER 1.0.15 —-
AttachedDevice \FileSystem\Ntfs \Ntfs TKFsFt2k.sys
AttachedDevice \Driver\tdx \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\tdx \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\tdx \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
—- Registry - GMER 1.0.15 —-
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\002186b8a8bc
Reg HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\002186b8a8bc (not active ControlSet)
—- EOF - GMER 1.0.15 —-
– Thanks again!