This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] infected with a virus that my AVG can't recognise

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

============== Running Processes =============== C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe c:\archivos de programa\archivos comunes\logitech\lvmvfm\LVPrcSrv.exe C:\WINDOWS\system32\acs.exe svchost.exe C:\ARCHIV~1\AVG\AVG8\avgwdsvc.exe C:\Archivos de programa\TOSHIBA\ConfigFree\CFSvcs.exe C:\Archivos de programa\Archivos comunes\Microsoft Shared\VS7Debug\mdm.exe C:\ARCHIV~1\AVG\AVG8\avgam.exe C:\WINDOWS\system32\HPZipm12.exe C:\ARCHIV~1\AVG\AVG8\avgrsx.exe C:\ARCHIV~1\AVG\AVG8\avgnsx.exe C:\Archivos de programa\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe C:\WINDOWS\System32\PAStiSvc.exe C:\WINDOWS\system32\svchost.exe -k imgsvc c:\TOSHIBA\IVP\swupdate\swupdtmr.exe C:\WINDOWS\system32\TODDSrv.exe C:\WINDOWS\SYSTEM32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\Archivos de programa\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\WINDOWS\system32\TPSMain.exe C:\Archivos de programa\TOSHIBA\ConfigFree\NDSTray.exe C:\Archivos de programa\TOSHIBA\Touch and Launch\PadExe.exe C:\Archivos de programa\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe C:\WINDOWS\system32\TPSBattM.exe C:\Archivos de programa\ltmoh\Ltmoh.exe C:\WINDOWS\AGRSMMSG.exe C:\Archivos de programa\Synaptics\SynTP\SynTPEnh.exe C:\Archivos de programa\Toshiba\Windows Utilities\Hotkey.exe C:\Archivos de programa\TOSHIBA\TOSHIBA Direct Disc Writer\ddwmon.exe C:\WINDOWS\RTHDCPL.EXE C:\Archivos de programa\TOSHIBA\ConfigFree\CFSServ.exe C:\Archivos de programa\Microsoft Office\Office12\GrooveMonitor.exe C:\ARCHIV~1\AVG\AVG8\avgtray.exe C:\Archivos de programa\Archivos comunes\Nokia\MPlatform\NokiaMServer.exe C:\Archivos de programa\Archivos comunes\Logitech\LComMgr\Communications_Helper.exe C:\Archivos de programa\Archivos comunes\Logitech\LComMgr\LVComSX.exe C:\Archivos de programa\Archivos comunes\AOL\1272912125\ee\AOLSoftware.exe C:\WINDOWS\system32\ctfmon.exe C:\Archivos de programa\TOSHIBA\TOSCDSPD\toscdspd.exe C:\Archivos de programa\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Archivos de programa\Nokia\PC Internet Access\NPCIA.exe C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe C:\Archivos de programa\PC Connectivity Solution\ServiceLayer.exe C:\Archivos de programa\PC Connectivity Solution\Transports\NclRSSrv.exe C:\Archivos de programa\Archivos comunes\Microsoft Shared\Works Shared\WkCalRem.exe C:\Archivos de programa\PC Connectivity Solution\Transports\NclUSBSrv.exe C:\Archivos de programa\Nokia\Nokia Internet Modem\wellphone2.exe C:\Archivos de programa\Opera\opera.exe C:\Documents and Settings\adminis\Configuración local\Datos de programa\Opera\Opera\temporary_downloads\pcmedkit_setup.exe C:\DOCUME~1\adminis\CONFIG~1\Temp\is-3GV89.tmp\pcmedkit_setup.tmp C:\Documents and Settings\adminis\Configuración local\Datos de programa\Opera\Opera\temporary_downloads\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://www.aol.com uURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\archivos de programa\avg\avg8\toolbar\IEToolbar.dll uURLSearchHooks: H - No File uURLSearchHooks: H - No File mURLSearchHooks: AOL Toolbar Search Class: {f0e98552-8e47-4c6c-9b3a-11ab0549f94d} - c:\archivos de programa\aol toolbar\aoltb.dll mURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\archivos de programa\avg\avg8\toolbar\IEToolbar.dll BHO: Aplicación auxiliar de vínculos de Adobe PDF Reader: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\archivos de programa\archivos comunes\adobe\acrobat\activex\AcroIEHelper.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\archivos de programa\archivos comunes\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: Skype add-on (mastermind): {22bf413b-c6d2-4d91-82a9-a0f997ba588c} - c:\archivos de programa\skype\toolbars\internet explorer\SkypeIEPlugin.dll BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\archivos de programa\avg\avg8\avgssie.dll BHO: AOL Toolbar Loader: {3ef64538-8b54-4573-b48f-4d34b0238ab2} - c:\archivos de programa\aol toolbar\aoltb.dll BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\archivos de programa\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\archivos de programa\microsoft office\office12\GrooveShellExtensions.dll BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\archivos de programa\java\jre1.5.0_06\bin\ssv.dll BHO: Windows Live Aplicación auxiliar de inicio de sesión: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\archivos de programa\archivos comunes\microsoft shared\windows live\WindowsLiveLogin.dll BHO: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\archivos de programa\avg\avg8\toolbar\IEToolbar.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\archivos de programa\google\googletoolbar3.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\archivos de programa\google\googletoolbarnotifier\5.4.4525.1752\swg.dll BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\archivos de programa\windows live\toolbar\wltcore.dll TB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\archivos de programa\google\googletoolbar3.dll TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - c:\archivos de programa\avg\avg8\toolbar\IEToolbar.dll TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\archivos de programa\windows live\toolbar\wltcore.dll TB: AOL Toolbar: {ba00b7b1-0351-477a-b948-23e3ee5a73d4} - c:\archivos de programa\aol toolbar\aoltb.dll TB: {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - No File TB: &Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - TB: {10134636-E7AF-4AC5-A1DC-C7C44BB97D81} - No File TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File uRun: [CTFMON.EXE] c:\windows\system32\ctfmon.exe uRun: [TOSCDSPD] c:\archivos de programa\toshiba\toscdspd\toscdspd.exe uRun: [swg] "c:\archivos de programa\google\googletoolbarnotifier\GoogleToolbarNotifier.exe" uRun: [NokiaPCInternetAccess] "c:\archivos de programa\nokia\pc internet access\NPCIA.exe" /b uRun: [Google Update] "c:\documents and settings\adminis\configuración local\datos de programa\google\update\GoogleUpdate.exe" /c uRun: [BitComet] "c:\archivos de programa\bitcomet\BitComet.exe" /tray uRun: [PC Suite Tray] "c:\archivos de programa\nokia\nokia pc suite 7\PCSuite.exe" -onlytray uRun: [LDM] c:\archivos de programa\logitech\desktop messenger\8876480\program\LogitechDesktopMessenger.exe mRun: [ATIPTA] "c:\archivos de programa\ati technologies\ati control panel\atiptaxx.exe" mRun: [TPSMain] TPSMain.exe mRun: [NDSTray.exe] NDSTray.exe mRun: [PadTouch] c:\archivos de programa\toshiba\touch and launch\PadExe.exe mRun: [SmoothView] c:\archivos de programa\toshiba\toshiba zooming utility\SmoothView.exe mRun: [LtMoh] c:\archivos de programa\ltmoh\Ltmoh.exe mRun: [AGRSMMSG] AGRSMMSG.exe mRun: [SynTPEnh] c:\archivos de programa\synaptics\syntp\SynTPEnh.exe mRun: [Toshiba Hotkey Utility] "c:\archivos de programa\toshiba\windows utilities\Hotkey.exe" /lang ES mRun: [DDWMon] c:\archivos de programa\toshiba\toshiba direct disc writer\\ddwmon.exe mRun: [RTHDCPL] RTHDCPL.EXE mRun: [Alcmtr] ALCMTR.EXE mRun: [Pinger] c:\toshiba\ivp\ism\pinger.exe /run mRun: [CFSServ.exe] CFSServ.exe -NoClient mRun: [Adobe Photo Downloader] "c:\archivos de programa\adobe\photoshop album starter edition\3.0\apps\apdproxy.exe" mRun: [QuickTime Task] "c:\archivos de programa\quicktime\qttask.exe" -atboottime mRun: [GrooveMonitor] "c:\archivos de programa\microsoft office\office12\GrooveMonitor.exe" mRun: [AVG8_TRAY] c:\archiv~1\avg\avg8\avgtray.exe mRun: [NokiaMServer] c:\archivos de programa\archivos comunes\nokia\mplatform\NokiaMServer /watchfiles startup mRun: [NokiaMusic FastStart] "c:\archivos de programa\nokia\ovi player\NokiaOviPlayer.exe" /command:faststart mRun: [LogitechCommunicationsManager] "c:\archivos de programa\archivos comunes\logitech\lcommgr\Communications_Helper.exe" mRun: [LogitechQuickCamRibbon] "c:\archivos de programa\logitech\quickcam10\QuickCam10.exe" /hide mRun: [LVCOMSX] "c:\archivos de programa\archivos comunes\logitech\lcommgr\LVComSX.exe" mRun: [HostManager] c:\archivos de programa\archivos comunes\aol\1272912125\ee\AOLSoftware.exe mRun: [Adobe Reader Speed Launcher] "c:\archivos de programa\adobe\reader 9.0\reader\Reader_sl.exe" mRun: [Adobe ARM] "c:\archivos de programa\archivos comunes\adobe\arm\1.0\AdobeARM.exe" mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE StartupFolder: c:\docume~1\adminis\menini~1\progra~1\inicio\erunta~1.lnk - c:\archivos de programa\erunt\AUTOBACK.EXE StartupFolder: c:\docume~1\adminis\menini~1\progra~1\inicio\wkcalrem.lnk - c:\archivos de programa\archivos comunes\microsoft shared\works shared\WkCalRem.exe StartupFolder: c:\docume~1\alluse~1\menini~1\progra~1\inicio\linkma~1.lnk - c:\archivos de programa\linkmagic\LinkMagic.exe StartupFolder: c:\docume~1\alluse~1\menini~1\progra~1\inicio\logite~1.lnk - c:\archivos de programa\logitech\desktop messenger\8876480\program\LDMConf.exe uPolicies-explorer: = 0 mPolicies-explorer: hx-1 = 1 IE: E&xportar a Microsoft Excel - c:\archiv~1\micros~2\office12\EXCEL.EXE/3000 IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\archivos de programa\messenger\msmsgs.exe IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBC} - c:\archivos de programa\java\jre1.5.0_06\bin\ssv.dll IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\archivos de programa\windows live\writer\WriterBrowserExtension.dll IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\archiv~1\micros~2\office12\ONBttnIE.dll IE: {77BF5300-1474-4EC7-9980-D32B190E9B07} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\archivos de programa\skype\toolbars\internet explorer\SkypeIEPlugin.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\archiv~1\micros~2\office12\REFIEBAR.DLL DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} - hxxp://a516.g.akamai.net/f/516/25175/7d/runaware.download.akamai.com/25175/citrix/wficat-no-eula.cab DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://gfx1.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} - hxxp://www.ca.com/us/securityadvisor/virusinfo/webscan.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} - hxxps://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} - hxxp://gfx1.hotmail.com/mail/w4/pr01/photouploadcontrol/MSNPUpld.cab TCP: {9408AEA4-986B-418B-BAC6-B552E0392B3B} = 57.67.127.195 200.71.240.75 Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\archivos de programa\logitech\desktop messenger\8876480\program\GAPlugProtocol-8876480.dll Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\archivos de programa\microsoft office\office12\GrooveSystemServices.dll Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\archivos de programa\avg\avg8\avgpp.dll Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\archiv~1\archiv~1\skype\SKYPE4~1.DLL Notify: AtiExtEvent - Ati2evxx.dll Notify: avgrsstarter - avgrsstx.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\archivos de programa\microsoft office\office12\GrooveShellExtensions.dll ============= SERVICES / DRIVERS =============== R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [2009-4-16 12552] R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-4-16 335240] R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2009-4-16 27784] R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-4-16 108552] R2 avg8wd;AVG8 WatchDog;c:\archiv~1\avg\avg8\avgwdsvc.exe [2009-4-16 297752] R2 filesvc;filesvc;c:\windows\system32\config\atww\filesvc.sys [2008-2-29 9216] R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [2010-1-30 54752] R2 regfil;regfil;c:\windows\system32\config\atww\regfil.sys [2008-2-29 7552] R2 SeaPort;SeaPort;c:\archivos de programa\microsoft\search enhancement pack\seaport\SeaPort.exe [2009-5-19 240512] R2 SVKP;SVKP;c:\windows\system32\SVKP.sys [2008-8-6 2368] R2 tdudf;TOSHIBA UDF File System Driver;c:\windows\system32\drivers\tdudf.sys [2006-4-18 98816] R3 nokiappo;Nokia Internet Stick Wireless Modem Power Policy Service;c:\windows\system32\drivers\nokiappo.sys [2009-8-5 27008] R3 seehcri;Sony Ericsson seehcri Device Driver;c:\windows\system32\drivers\seehcri.sys [2010-5-11 27632] S2 gupdate;Servicio de actualización de Google (gupdate);c:\archivos de programa\google\update\GoogleUpdate.exe [2009-9-16 133104] S2 myrwwdldk;Monitor Task;c:\windows\system32\svchost.exe -k netsvcs [2006-5-3 14336] S2 Network Updating;Network Updating;c:\archivos de programa\msn gaming zone\msnpro32.exe –> c:\archivos de programa\msn gaming zone\MSNPRO32.exe [?] S2 procdrv;procdrv;c:\windows\system32\config\atww\procdrv.sys [2008-2-29 6144] S2 Ravsvrs;Ravsvrs;c:\archivos de programa\outlook express\ravsvrs.exe –> c:\archivos de programa\outlook express\Ravsvrs.exe [?] S2 udialgk;Shell Manager;c:\windows\system32\svchost.exe -k netsvcs [2006-5-3 14336] S2 Windows Networks;Windows Networks;c:\archivos de programa\netmeeting\inetsock.exe –> c:\archivos de programa\netmeeting\inetsock.exe [?] S3 cmo_bus;Data Modem @ CDMA Composite Device driver (WDM);c:\windows\system32\drivers\cmo_bus.sys [2008-1-19 58352] S3 cmo_mdfl;Data Modem @ CDMA Filter;c:\windows\system32\drivers\cmo_mdfl.sys [2008-1-19 8304] S3 cmo_mdm;Data Modem @ CDMA Drivers;c:\windows\system32\drivers\cmo_mdm.sys [2008-1-19 93904] S3 cmo_serd;Data Modem @ CDMA Diagnostic Serial Port (WDM);c:\windows\system32\drivers\cmo_serd.sys [2008-1-19 73696] S3 fsssvc;Servicio de Windows Live Protección infantil;c:\archivos de programa\windows live\family safety\fsssvc.exe [2009-8-5 704864] S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\drivers\ggflt.sys [2008-11-24 13224] S3 hwusbfake;Huawei DataCard USB Fake;c:\windows\system32\drivers\ewusbfake.sys –> c:\windows\system32\drivers\ewusbfake.sys [?] S3 nokiacpo;Nokia Internet Stick Wireless Modem Service Install;c:\windows\system32\drivers\nokiacpo.sys [2009-8-5 18688] =============== Created Last 30 ================ 2010-05-15 08:55 -cd-h— c:\windows\ie8 2010-05-15 08:54 –d-h— c:\windows\msdownld.tmp 2010-05-11 16:30 0 a—h— c:\windows\system32\drivers\Msft_Kernel_ggflt_01007.Wdf 2010-05-11 16:30 0 a—h— c:\windows\system32\drivers\Msft_Kernel_ggsemc_01007.Wdf 2010-05-11 16:22 27,632 a——- c:\windows\system32\drivers\seehcri.sys 2010-05-11 16:22 1,112,288 a——- c:\windows\system32\WdfCoInstaller01007.dll 2010-05-11 12:04 218,624 ac—— c:\windows\system32\dllcache\uxtheme.dll 2010-05-09 19:15 0 a—h— c:\windows\system32\drivers\Msft_Kernel_ggsemc_01005.Wdf 2010-05-03 14:53 10,920 a——- C:\aolconnfix.exe 2010-05-03 14:30 –d—– c:\docume~1\adminis\datosd~1\AOL 2010-05-03 14:24 –d—– c:\docume~1\alluse~1\datosd~1\Viewpoint 2010-05-03 14:24 –d—– c:\archivos de programa\Viewpoint 2010-05-03 14:24 –d—– c:\docume~1\alluse~1\datosd~1\AOL Toolbar 2010-05-03 14:24 –d—– c:\archivos de programa\AOL Toolbar 2010-05-03 14:23 –d—– c:\archivos de programa\archivos comunes\Software Update Utility 2010-05-03 14:16 33,588 a—-r– c:\windows\system32\drivers\wanatw4.sys 2010-05-03 14:10 –d—– c:\archivos de programa\archivos comunes\aolshare 2010-05-03 14:10 –d—– c:\archivos de programa\archivos comunes\aol 2010-05-03 14:10 –d—– c:\archivos de programa\AOL 9.5 2010-05-03 10:49 –d—– c:\archivos de programa\Microsoft CAPICOM 2.1.0.2 2010-05-02 12:38 0 a—h— c:\windows\system32\drivers\Msft_Kernel_ccdcmb_01009.Wdf 2010-05-02 12:38 0 a—h— c:\windows\system32\drivers\MsftWdf_Kernel_01009_Coinstaller_Critical.Wdf 2010-05-02 12:26 121,632 a—-r– c:\windows\system32\lvcoinst.dll 2010-05-02 12:26 42,594 a—-r– c:\windows\system32\lvcoinst.ini 2010-05-02 12:26 40,352 a—-r– c:\windows\system32\drivers\LVUSBSta.sys 2010-05-02 12:26 7,734 a—-r– c:\windows\system32\Repository.reg 2010-05-02 12:26 527,136 a—-r– c:\windows\system32\LVUI2RC.dll 2010-05-02 12:26 211,744 a—-r– c:\windows\system32\LVUI2.dll 2010-05-02 12:26 264,992 a—-r– c:\windows\system32\lvcodec2.dll 2010-05-02 12:26 487,328 a—-r– c:\windows\system32\drivers\LV561AV.SYS 2010-05-02 12:26 348,160 a—-r– c:\windows\system\msvcr71.dll 2010-05-02 12:24 118,784 —–r– c:\windows\bwUnin-7.2.0.157-8876480SL.exe 2010-05-02 12:17 –d—– c:\archivos de programa\archivos comunes\Logitech 2010-05-02 10:16 18,816 a——- c:\windows\system32\drivers\pccsmcfd.sys 2010-05-02 10:16 –d—– c:\archivos de programa\PC Connectivity Solution 2010-05-02 10:15 8,192 a——- c:\windows\system32\drivers\usbser_lowerfltj.sys 2010-05-02 10:15 8,192 a——- c:\windows\system32\drivers\usbser_lowerflt.sys 2010-05-02 10:15 22,528 a——- c:\windows\system32\drivers\ccdcmbo.sys 2010-05-02 10:15 662,016 a——- c:\windows\system32\nmwcdcocls.dll 2010-05-02 10:15 18,176 a——- c:\windows\system32\drivers\ccdcmb.sys 2010-05-02 10:15 1,461,992 a——- c:\windows\system32\wdfcoinstaller01009.dll 2010-05-01 19:24 167 a——- c:\windows\DelMR.bat 2010-05-01 19:00 –d—– c:\archivos de programa\archivos comunes\SmartCom 2010-04-30 10:44 316 a——- c:\docume~1\adminis\datosd~1\wklnhst.dat ==================== Find3M ==================== 2010-05-11 16:21 25,512 a——- c:\windows\system32\drivers\ggsemc.sys 2010-05-11 16:21 13,224 a——- c:\windows\system32\drivers\ggflt.sys 2010-03-10 01:46 420,352 a——- c:\windows\system32\vbscript.dll 2010-02-26 13:32 92,672 ac—— c:\windows\system32\nmwcdcls.dll 2010-02-25 01:46 916,480 a——- c:\windows\system32\wininet.dll 2010-02-17 14:07 2,192,384 a——- c:\windows\system32\ntoskrnl.exe 2008-08-06 20:28 43,344 ac—— c:\docume~1\adminis\datosd~1\GDIPFONTCACHEV1.DAT 2008-04-24 12:27 56 -c-shr– c:\windows\system32\E4F90FD591.sys 2008-04-29 20:59 952 ac-sh— c:\windows\system32\KGyGaAvL.sys 2008-04-13 21:48 1,384,479 —shr– c:\windows\system32\msvbvm60.dll 2007-08-06 23:09 10 -c-shr– c:\windows\system32\sistem.sys 2009-03-07 08:42 32,768 ac-sh— c:\windows\system32\config\systemprofile\configuración local\historial\history.ie5\mshist012009030720090308\index.dat ============= FINISH: 7:56:16.20 =============== [attachment removed]
Hello and :welcome:

I will be helping you on removing malwares on your computer. Log research takes time, so please be patient and I'd be grateful if you would note the following:
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Do not install/uninstall anything on your computer unless advised.
  • Do not run any other scanning tools other than those instructed for you to use.
  • Follow the instructions on the order they are given.
  • Stay with this thread until advised when your computer is clean. Absence of symptoms does not necessarily mean a clean computer.
  • If you are being helped regarding this problem on another forum please advice us so that we can close this thread.
  • If you do not reply within 3 days after my last response, I will be asking you whether you still need assistance and if you still don't reply within 48 hours then the topic will be closed.
  • And lastly, if you have any questions, please ask before proceeding with any of the advised fixes.

_________________________________________________


The log you posted has been cut off. Please post the succeeding logs in full. Thanks.

You are still using an outdated AVG version. The latest version is 9. Let's update it after we are done cleaning your computer.

Are you aware of Ultraview Plus? Did you or someone else installed it in your pc sometime in the past? As this software is also considered as a key logger.

–Next–

You have BitComet, a P2P/file sharing programs installed on your computer. P2P applications like it are the largest source of malware we see. You'll be doing yourself a favor by removing it.

P2P (File Sharing ) programs form a direct conduit onto your computer, their security measures are easily circumvented, and Malware writers are increasingly exploiting them to spread their wares onto your computer. Further to that, if your P2P program is not configured correctly you may be sharing more files than you realize. There have been cases where people's Passwords, Address Books and other personal, private, and financial details have been exposed to the file sharing network by a badly configured program.

Many of the programs come bundled with other unwanted programs, but even the ones free of any bundled software are not safe to use.

This article from InfoWorld illustrates the dangers of a poorly configured P2P program.
http://www.infoworld.com/d/security-centra…-p-id-theft-103

When you use them you are downloading software from an unknown source directly onto your computer, bypassing your Firewall and Anti-Virus software. Hardly surprising then that many of these Downloads are being targeted to carry infections.

I would recommend that you uninstall BitComet, via Control Panel -> Add or Remove Programs.

However, if you do not wish to remove this program please be advised not to use the said program during the course of cleaning your machine.

References for the risk of these programs can be found in these links:
http://www.esecurityguy.com/p2p_file_sharing
http://www.microsoft.com/protect/data/down…ilesharing.aspx

–Next–

Please go to VirSCAN
  • Click on Browse.
  • On the File Upload window, copy/paste the text below into the File name box:
    c:\windows\system32\sistem.sys
  • Click Upload. Allow the file to be scanned. If it says already scanned – click Reanalyze Now
Repeat the procedure with the following files:
c:\windows\system32\ctfmon.exe
c:\archivos de programa\msn gaming zone\MSNPRO32.exe
c:\archivos de programa\outlook express\Ravsvrs.exe
c:\windows\system32\E4F90FD591.sys


Please post the results in your next reply.

–Next–

Please read through these instructions to familarize yourself with what to expect when this tool runs

Download ComboFix from one of these locations:

Link 1
Link 2

* IMPORTANT !!! Save ComboFix.exe to your Desktop

——————————————————————–
IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty in properly disabling your protective programs, refer to this link - How to Disable your Security Programs
——————————————————————–
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making Internet Explorer the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Please post back with the combofix log.

To post in your next reply:
1. Regarding my questions above.
2. VirSCAN log.
3. Combofix log.
Hi, It's been several days. Do you still need help on this? This thread will be closed if you don't respond within 48 hours.
inzanity, thanks for your help, i had few days out of the web so… got my PC out of everything 'cause the infection. Right now im reading the post you wrote so… I'll be working step by step with the information you give me above.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI