This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

multiplying trojan (according to AVG)

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Dear all,

Since today AVG shows me messages of trojan files. The strange thing is, these files are created in de c:\windows\system32\ directory and are .exe files. What is even stranger, I can practically see these files being created out of nowhere. Everytime I get the message of AVG REsident Shield that there is a Trojan (BackDoor.Agent.AJLL) i delete the files straight away.

It seems these strange names come back when i delete them. When I don't delete them there seems an endless variation of names (Like fservu.exe, ccodr.exe, jwinz.exe)

Thanks in advance for your expert help.

Greets from the Netherlands

I used OTR:

Extras.txt

OTL Extras logfile created on: 14-12-2010 20:27:11 - Run 1
OTL by OldTimer - Version 3.2.17.3 Folder = C:\hijackthis
Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000413 | Country: Nederland | Language: NLD | Date Format: d-M-yyyy

3,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 63,00% Memory free
6,00 Gb Paging File | 5,00 Gb Available in Paging File | 82,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 59,25 Gb Total Space | 34,08 Gb Free Space | 57,52% Space Free | Partition Type: NTFS
Drive D: | 10,00 Gb Total Space | 5,49 Gb Free Space | 54,92% Space Free | Partition Type: NTFS
Drive E: | 931,04 Gb Total Space | 435,30 Gb Free Space | 46,75% Space Free | Partition Type: NTFS

Computer Name: MEDIASERV-2010 | User Name: Gebruiker | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – C:\Program Files\VideoLAN\VLC\vlc.exe –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Open Command Prompt Here] – cmd.exe /T:4F /K cd %1 (Microsoft Corporation)
Directory [PlayWithVLC] – C:\Program Files\VideoLAN\VLC\vlc.exe –started-from-file –no-playlist-enqueue "%1" ()
Directory [runas] – cmd.exe /c takeown /f "%1" /r /d y && icacls "%1" /grant administrators:F /t (Microsoft Corporation)
Directory [Winamp.Bookmark] – "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] – "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] – "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\IEPro\MiniDM.exe" = C:\Program Files\IEPro\MiniDM.exe:*:Enabled:MiniDM – (IE7Pro.com)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}" = PDFCreator
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{2617FA1F-0C04-3ABB-AF64-7D5B6620C341}" = Microsoft .NET Framework 4 Client Profile NLD Language Pack
"{2624B969-7135-4EB1-B0F6-2D8C397B45F7}_is1" = Media Player Classic - Home Cinema v. 1.3.1249.0
"{26A24AE4-039D-4CA4-87B4-2F83216018FF}" = Java™ 6 Update 18
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3D3E663D-4E7E-4577-A560-7ECDDD45548A}" = PVSonyDll
"{458B07C5-AE86-4422-AEE9-12099CFB5673}" = Adobe Shockwave 11.5.6.606
"{5AD96CF5-2627-4F29-9D2D-72FCD85F6355}" = AVG 2011
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90120000-0015-0413-0000-0000000FF1CE}" = Microsoft Office Access MUI (Dutch) 2007
"{90120000-0015-0413-0000-0000000FF1CE}_ENTERPRISE_{DC387AA5-94A6-4920-B004-D59846526D81}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0016-0413-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Dutch) 2007
"{90120000-0016-0413-0000-0000000FF1CE}_ENTERPRISE_{DC387AA5-94A6-4920-B004-D59846526D81}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0018-0413-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Dutch) 2007
"{90120000-0018-0413-0000-0000000FF1CE}_ENTERPRISE_{DC387AA5-94A6-4920-B004-D59846526D81}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0019-0413-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Dutch) 2007
"{90120000-0019-0413-0000-0000000FF1CE}_ENTERPRISE_{DC387AA5-94A6-4920-B004-D59846526D81}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-001A-0413-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Dutch) 2007
"{90120000-001A-0413-0000-0000000FF1CE}_ENTERPRISE_{DC387AA5-94A6-4920-B004-D59846526D81}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-001B-0413-0000-0000000FF1CE}" = Microsoft Office Word MUI (Dutch) 2007
"{90120000-001B-0413-0000-0000000FF1CE}_ENTERPRISE_{DC387AA5-94A6-4920-B004-D59846526D81}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007
"{90120000-001F-0407-0000-0000000FF1CE}_ENTERPRISE_{A0516415-ED61-419A-981D-93596DA74165}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-001F-0413-0000-0000000FF1CE}" = Microsoft Office Proof (Dutch) 2007
"{90120000-001F-0413-0000-0000000FF1CE}_ENTERPRISE_{D66D5A44-E480-4BA4-B4F2-C554F6B30EBB}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-002C-0413-0000-0000000FF1CE}" = Microsoft Office Proofing (Dutch) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0044-0413-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (Dutch) 2007
"{90120000-0044-0413-0000-0000000FF1CE}_ENTERPRISE_{DC387AA5-94A6-4920-B004-D59846526D81}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-006E-0413-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Dutch) 2007
"{90120000-006E-0413-0000-0000000FF1CE}_ENTERPRISE_{89C8E56A-90D8-4598-B0E6-EB28F6270E07}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-00A1-0413-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (Dutch) 2007
"{90120000-00A1-0413-0000-0000000FF1CE}_ENTERPRISE_{DC387AA5-94A6-4920-B004-D59846526D81}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-00B0-0413-0000-0000000FF1CE}" = Microsoft-invoegtoepassing Opslaan als PDF voor 2007 Microsoft Office-programma's
"{90120000-00B2-0413-0000-0000000FF1CE}" = Microsoft-invoegtoepassing Opslaan als PDF of XPS voor 2007 Microsoft Office-programma's
"{90120000-00BA-0413-0000-0000000FF1CE}" = Microsoft Office Groove MUI (Dutch) 2007
"{90120000-00BA-0413-0000-0000000FF1CE}_ENTERPRISE_{DC387AA5-94A6-4920-B004-D59846526D81}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{A23061AF-5361-433C-B7F0-CE5F79A22C49}" = AVG 2011
"{CCA5EAAD-92F4-4B7A-B5EE-14294C66AB61}" = PlayReady PC Runtime x86
"{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC}" = TuneUp Utilities
"{FE3997D3-6B56-4AC4-A99C-9DDFC45359BF}" = TuneUp Utilities Language Pack (en-US)
"7-Zip" = 7-Zip 4.65
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"AVG" = AVG 2011
"AviSynth" = AviSynth 2.5
"CloneDVD2" = CloneDVD2
"CPLBonus" = W7 en Vista x86 CPL Bonus Pack!
"CPUID CPU-Z_is1" = CPUID CPU-Z 1.55
"ENTERPRISE" = Microsoft Office Enterprise 2007
"IE7Pro" = IE7Pro
"KLiteCodecPack_is1" = K-Lite Mega Codec Pack 6.4.0
"MediaInfo.dll" = MediaInfo.dll 0.7.35
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile NLD Language Pack" = Taalpakket voor Microsoft .NET Framework 4 Client Profile - NLD
"Nero8Lite_is1" = Nero 8 Lite
"NewsLeecher_is1" = NewsLeecher v3.9 Final
"Notepad++" = Notepad++
"NVIDIA Display Control Panel" = NVIDIA Display Control Panel
"NVIDIA Drivers" = NVIDIA Drivers
"PS3 Media Server" = PS3 Media Server
"qt7lite_is1" = QT Lite 3.1.1
"QuickPar" = QuickPar 0.9
"Registry Clean Expert_is1" = Registry Clean Expert
"Registry Mechanic_is1" = Registry Mechanic 9.0
"SystemRequirementsLab" = System Requirements Lab
"TuneUp Utilities" = TuneUp Utilities
"VLC media player" = VLC media player 0.9.8
"Winamp" = Winamp
"WinRAR archiver" = WinRAR archiver
"YU2010_is1" = Your Uninstaller! 2010

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 20-9-2010 11:42:26 | Computer Name = Mediaserv-2010 | Source = Application Error | ID = 1000
Description = Naam van toepassing met fout: tsMuxeR.exe, versie: 0.0.0.0, tijdstempel:
0x4a077b02 Naam van module met fout: unknown, versie: 0.0.0.0, tijdstempel: 0x00000000
Uitzonderingscode:
0xc0000005 Foutoffset: 0xe15700d0 Id van proces met fout: 0xcc0 Starttijd van toepassing
met fout: 0x01cb58da6c72b136 Pad naar toepassing met fout: C:\Program Files\PS3
Media Server\win32\tsMuxeR.exe Pad naar module met fout: unknown Rapport-id: aac621ac-c4cd-11df-8acc-0019dbb34fe3

Error - 20-9-2010 12:07:39 | Computer Name = Mediaserv-2010 | Source = Application Error | ID = 1000
Description = Naam van toepassing met fout: tsMuxeR.exe, versie: 0.0.0.0, tijdstempel:
0x4a077b02 Naam van module met fout: unknown, versie: 0.0.0.0, tijdstempel: 0x00000000
Uitzonderingscode:
0xc0000005 Foutoffset: 0xe15700d0 Id van proces met fout: 0x8b4 Starttijd van toepassing
met fout: 0x01cb58ddf0303305 Pad naar toepassing met fout: C:\Program Files\PS3
Media Server\win32\tsMuxeR.exe Pad naar module met fout: unknown Rapport-id: 307d1603-c4d1-11df-8acc-0019dbb34fe3

Error - 20-9-2010 12:08:16 | Computer Name = Mediaserv-2010 | Source = Application Error | ID = 1000
Description = Naam van toepassing met fout: tsMuxeR.exe, versie: 0.0.0.0, tijdstempel:
0x4a077b02 Naam van module met fout: ntdll.dll, versie: 6.1.7600.20745, tijdstempel:
0x4c2adf9b Uitzonderingscode: 0xc0000005 Foutoffset: 0x00028cb6 Id van proces met
fout: 0xa28 Starttijd van toepassing met fout: 0x01cb58de067c16cf Pad naar toepassing
met fout: C:\Program Files\PS3 Media Server\win32\tsMuxeR.exe Pad naar module met
fout: C:\Windows\SYSTEM32\ntdll.dll Rapport-id: 466b8ba6-c4d1-11df-8acc-0019dbb34fe3

Error - 20-9-2010 12:09:03 | Computer Name = Mediaserv-2010 | Source = Application Error | ID = 1000
Description = Naam van toepassing met fout: tsMuxeR.exe, versie: 0.0.0.0, tijdstempel:
0x4a077b02 Naam van module met fout: ntdll.dll, versie: 6.1.7600.20745, tijdstempel:
0x4c2adf9b Uitzonderingscode: 0xc0000005 Foutoffset: 0x00028cb6 Id van proces met
fout: 0x1540 Starttijd van toepassing met fout: 0x01cb58de2425b889 Pad naar toepassing
met fout: C:\Program Files\PS3 Media Server\win32\tsMuxeR.exe Pad naar module met
fout: C:\Windows\SYSTEM32\ntdll.dll Rapport-id: 6263d9fa-c4d1-11df-8acc-0019dbb34fe3

Error - 20-9-2010 12:18:26 | Computer Name = Mediaserv-2010 | Source = Application Error | ID = 1000
Description = Naam van toepassing met fout: tsMuxeR.exe, versie: 0.0.0.0, tijdstempel:
0x4a077b02 Naam van module met fout: ntdll.dll, versie: 6.1.7600.20745, tijdstempel:
0x4c2adf9b Uitzonderingscode: 0xc0000005 Foutoffset: 0x00028cb6 Id van proces met
fout: 0x13bc Starttijd van toepassing met fout: 0x01cb58df735a3ada Pad naar toepassing
met fout: C:\Program Files\PS3 Media Server\win32\tsMuxeR.exe Pad naar module met
fout: C:\Windows\SYSTEM32\ntdll.dll Rapport-id: b20ef94a-c4d2-11df-8acc-0019dbb34fe3

Error - 20-9-2010 12:42:34 | Computer Name = Mediaserv-2010 | Source = Application Error | ID = 1000
Description = Naam van toepassing met fout: tsMuxeR.exe, versie: 0.0.0.0, tijdstempel:
0x4a077b02 Naam van module met fout: unknown, versie: 0.0.0.0, tijdstempel: 0x00000000
Uitzonderingscode:
0xc0000005 Foutoffset: 0xe15700d0 Id van proces met fout: 0x10d0 Starttijd van toepassing
met fout: 0x01cb58e2d2ffad09 Pad naar toepassing met fout: C:\Program Files\PS3
Media Server\win32\tsMuxeR.exe Pad naar module met fout: unknown Rapport-id: 1122d5e0-c4d6-11df-8acc-0019dbb34fe3

Error - 20-9-2010 12:48:40 | Computer Name = Mediaserv-2010 | Source = Application Error | ID = 1000
Description = Naam van toepassing met fout: tsMuxeR.exe, versie: 0.0.0.0, tijdstempel:
0x4a077b02 Naam van module met fout: unknown, versie: 0.0.0.0, tijdstempel: 0x00000000
Uitzonderingscode:
0xc0000005 Foutoffset: 0xe15700d0 Id van proces met fout: 0x1030 Starttijd van toepassing
met fout: 0x01cb58e3ac798b1b Pad naar toepassing met fout: C:\Program Files\PS3
Media Server\win32\tsMuxeR.exe Pad naar module met fout: unknown Rapport-id: eb49b495-c4d6-11df-8acc-0019dbb34fe3

Error - 21-9-2010 8:20:06 | Computer Name = Mediaserv-2010 | Source = Application Error | ID = 1000
Description = Naam van toepassing met fout: wmplayer.exe, versie: 12.0.7600.20686,
tijdstempel: 0x4bbd4fdc Naam van module met fout: ntdll.dll, versie: 6.1.7600.20745,
tijdstempel: 0x4c2adf9b Uitzonderingscode: 0xc0000005 Foutoffset: 0x00046b70 Id van
proces met fout: 0x1520 Starttijd van toepassing met fout: 0x01cb59864496ad2a Pad
naar toepassing met fout: C:\Program Files\Windows Media Player\wmplayer.exe Pad
naar module met fout: C:\Windows\SYSTEM32\ntdll.dll Rapport-id: 91585088-c57a-11df-ae9a-0019dbb34fe3

Error - 21-9-2010 9:14:46 | Computer Name = Mediaserv-2010 | Source = Application Error | ID = 1000
Description = Naam van toepassing met fout: tsMuxeR.exe, versie: 0.0.0.0, tijdstempel:
0x4a077b02 Naam van module met fout: ntdll.dll, versie: 6.1.7600.20745, tijdstempel:
0x4c2adf9b Uitzonderingscode: 0xc0000005 Foutoffset: 0x00028cb6 Id van proces met
fout: 0x10f4 Starttijd van toepassing met fout: 0x01cb598ef55c2178 Pad naar toepassing
met fout: C:\Program Files\PS3 Media Server\win32\tsMuxeR.exe Pad naar module met
fout: C:\Windows\SYSTEM32\ntdll.dll Rapport-id: 342dee90-c582-11df-ae9a-0019dbb34fe3

Error - 1-10-2010 12:37:29 | Computer Name = Mediaserv-2010 | Source = Application Hang | ID = 1002
Description = Het programma iexplore.exe, versie 8.0.7600.16385 reageert niet meer
op Windows en is afgesloten. Als u wilt zien of er meer informatie over het probleem
beschikbaar is, raadpleegt u de probleemgeschiedenis in het onderdeel Onderhoudscentrum
in het Configuratiescherm. Proces-id: 168c Starttijd: 01cb6186b74fc05c Eindtijd: 43

Toepassingspad:
C:\Program Files\Internet Explorer\iexplore.exe Rapport-id: 2d167be1-cd7a-11df-be83-0019dbb34fe3


[ System Events ]
Error - 14-12-2010 15:27:48 | Computer Name = Mediaserv-2010 | Source = Service Control Manager | ID = 7006
Description = ScRegSetValueExW-oproep voor ImagePath is niet geslaagd vanwege deze
fout: %%5.

Error - 14-12-2010 15:27:52 | Computer Name = Mediaserv-2010 | Source = Service Control Manager | ID = 7006
Description = ScRegSetValueExW-oproep voor ImagePath is niet geslaagd vanwege deze
fout: %%5.

Error - 14-12-2010 15:27:55 | Computer Name = Mediaserv-2010 | Source = Service Control Manager | ID = 7006
Description = ScRegSetValueExW-oproep voor ImagePath is niet geslaagd vanwege deze
fout: %%5.

Error - 14-12-2010 15:27:58 | Computer Name = Mediaserv-2010 | Source = Service Control Manager | ID = 7006
Description = ScRegSetValueExW-oproep voor ImagePath is niet geslaagd vanwege deze
fout: %%5.

Error - 14-12-2010 15:28:05 | Computer Name = Mediaserv-2010 | Source = Service Control Manager | ID = 7006
Description = ScRegSetValueExW-oproep voor ImagePath is niet geslaagd vanwege deze
fout: %%5.

Error - 14-12-2010 15:28:08 | Computer Name = Mediaserv-2010 | Source = Service Control Manager | ID = 7006
Description = ScRegSetValueExW-oproep voor ImagePath is niet geslaagd vanwege deze
fout: %%5.

Error - 14-12-2010 15:28:11 | Computer Name = Mediaserv-2010 | Source = Service Control Manager | ID = 7006
Description = ScRegSetValueExW-oproep voor ImagePath is niet geslaagd vanwege deze
fout: %%5.

Error - 14-12-2010 15:28:14 | Computer Name = Mediaserv-2010 | Source = Service Control Manager | ID = 7006
Description = ScRegSetValueExW-oproep voor ImagePath is niet geslaagd vanwege deze
fout: %%5.

Error - 14-12-2010 15:28:17 | Computer Name = Mediaserv-2010 | Source = Service Control Manager | ID = 7006
Description = ScRegSetValueExW-oproep voor ImagePath is niet geslaagd vanwege deze
fout: %%5.

Error - 14-12-2010 15:28:21 | Computer Name = Mediaserv-2010 | Source = Service Control Manager | ID = 7006
Description = ScRegSetValueExW-oproep voor ImagePath is niet geslaagd vanwege deze
fout: %%5.


< End of report >

OTL.TXT

OTL logfile created on: 14-12-2010 20:27:11 - Run 1
OTL by OldTimer - Version 3.2.17.3 Folder = C:\hijackthis
Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000413 | Country: Nederland | Language: NLD | Date Format: d-M-yyyy

3,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 63,00% Memory free
6,00 Gb Paging File | 5,00 Gb Available in Paging File | 82,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 59,25 Gb Total Space | 34,08 Gb Free Space | 57,52% Space Free | Partition Type: NTFS
Drive D: | 10,00 Gb Total Space | 5,49 Gb Free Space | 54,92% Space Free | Partition Type: NTFS
Drive E: | 931,04 Gb Total Space | 435,30 Gb Free Space | 46,75% Space Free | Partition Type: NTFS

Computer Name: MEDIASERV-2010 | User Name: Gebruiker | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\hijackthis\OTL.exe (OldTimer Tools)
PRC - E:\Series\ATF-Cleaner.exe (Atribune.org)
PRC - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSMonitor.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgemcx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
PRC - C:\Windows\System32\conhost.exe (Microsoft Corporation)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe (TuneUp Software)
PRC - C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe (TuneUp Software)
PRC - C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe (PC Tools)
PRC - C:\Program Files\Common Files\PC Tools\sMonitor\SSDMonitor.exe (PC Tools)
PRC - C:\Program Files\Registry Clean Expert\RCHelper.exe (iExpert Software)
PRC - C:\Windows\System32\atieclxx.exe (AMD)
PRC - C:\Windows\System32\atiesrxx.exe (AMD)


========== Modules (SafeList) ==========

MOD - C:\hijackthis\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.20787_none_2b43b51e45274037\comctl32.dll (Microsoft Corporation)
MOD - C:\Windows\System32\sspicli.dll (Microsoft Corporation)
MOD - C:\Windows\System32\KernelBase.dll (Microsoft Corporation)
MOD - C:\Windows\System32\sechost.dll (Microsoft Corporation)
MOD - C:\Windows\System32\profapi.dll (Microsoft Corporation)
MOD - C:\Windows\System32\dwmapi.dll (Microsoft Corporation)
MOD - C:\Windows\System32\devobj.dll (Microsoft Corporation)
MOD - C:\Windows\System32\cryptbase.dll (Microsoft Corporation)
MOD - C:\Windows\System32\cfgmgr32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (RemShutDownSvc) – C:\Windows\System32\remsdnsv.exe ()
SRV - (AVGIDSAgent) – C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
SRV - (avgwd) – C:\Program Files\AVG\AVG10\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (TuneUp.Defrag) – C:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe (TuneUp Software)
SRV - (FontCache) – C:\Windows\System32\FntCache.dll (Microsoft Corporation)
SRV - (Themes) – C:\Windows\System32\themeservice.dll (Microsoft Corporation)
SRV - (PNRPsvc) – C:\Windows\System32\pnrpsvc.dll (Microsoft Corporation)
SRV - (p2pimsvc) – C:\Windows\System32\pnrpsvc.dll (Microsoft Corporation)
SRV - (HomeGroupListener) – C:\Windows\System32\ListSvc.dll (Microsoft Corporation)
SRV - (HomeGroupProvider) – C:\Windows\System32\provsvc.dll (Microsoft Corporation)
SRV - (sppsvc) – C:\Windows\System32\sppsvc.exe (Microsoft Corporation)
SRV - (WatAdminSvc) – C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (TuneUp.UtilitiesSvc) – C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe (TuneUp Software)
SRV - (UxTuneUp) – C:\Windows\System32\uxtuneup.dll (TuneUp Software)
SRV - (PS3 Media Server) – C:\Program Files\PS3 Media Server\win32\service\wrapper.exe ()
SRV - (PCToolsSSDMonitorSvc) – C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe (PC Tools)
SRV - (AMD External Events Utility) – C:\Windows\System32\atiesrxx.exe (AMD)
SRV - (WwanSvc) – C:\Windows\System32\wwansvc.dll (Microsoft Corporation)
SRV - (WbioSrvc) – C:\Windows\System32\wbiosrvc.dll (Microsoft Corporation)
SRV - (Power) – C:\Windows\System32\umpo.dll (Microsoft Corporation)
SRV - (sppuinotify) – C:\Windows\System32\sppuinotify.dll (Microsoft Corporation)
SRV - (RpcEptMapper) – C:\Windows\System32\RpcEpMap.dll (Microsoft Corporation)
SRV - (SensrSvc) – C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (PeerDistSvc) – C:\Windows\System32\PeerDistSvc.dll (Microsoft Corporation)
SRV - (PNRPAutoReg) – C:\Windows\System32\pnrpauto.dll (Microsoft Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (Dhcp) – C:\Windows\System32\dhcpcore.dll (Microsoft Corporation)
SRV - (defragsvc) – C:\Windows\System32\defragsvc.dll (Microsoft Corporation)
SRV - (BDESVC) – C:\Windows\System32\bdesvc.dll (Microsoft Corporation)
SRV - (AxInstSV) ActiveX Installer (AxInstSV) – C:\Windows\System32\AxInstSv.dll (Microsoft Corporation)
SRV - (AppIDSvc) – C:\Windows\System32\appidsvc.dll (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (GPU-Z) – C:\Users\GEBRUI~1\AppData\Local\Temp\GPU-Z.sys File not found
DRV - (Avgtdix) – C:\Windows\System32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (sptd) – C:\Windows\System32\Drivers\sptd.sys ()
DRV - (AVGIDSEH) – C:\Windows\system32\DRIVERS\AVGIDSEH.Sys (AVG Technologies CZ, s.r.o. )
DRV - (Avgmfx86) – C:\Windows\System32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgldx86) – C:\Windows\System32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgrkx86) – C:\Windows\system32\DRIVERS\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSDriver) – C:\Windows\System32\drivers\AVGIDSDriver.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSFilter) – C:\Windows\System32\drivers\AVGIDSFilter.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSShim) – C:\Windows\System32\drivers\AVGIDSShim.sys (AVG Technologies CZ, s.r.o. )
DRV - (KSecPkg) – C:\Windows\System32\Drivers\ksecpkg.sys (Microsoft Corporation)
DRV - (1394ohci) – C:\Windows\system32\DRIVERS\1394ohci.sys (Microsoft Corporation)
DRV - (CompositeBus) – C:\Windows\System32\drivers\CompositeBus.sys (Microsoft Corporation)
DRV - (AppID) – C:\Windows\system32\drivers\appid.sys (Microsoft Corporation)
DRV - (vhdmp) – C:\Windows\system32\DRIVERS\vhdmp.sys (Microsoft Corporation)
DRV - (amdsata) – C:\Windows\system32\DRIVERS\amdsata.sys (Advanced Micro Devices)
DRV - (amdxata) – C:\Windows\system32\DRIVERS\amdxata.sys (Advanced Micro Devices)
DRV - (nvstor) – C:\Windows\system32\DRIVERS\nvstor.sys (NVIDIA Corporation)
DRV - (nvraid) – C:\Windows\system32\DRIVERS\nvraid.sys (NVIDIA Corporation)
DRV - (vmbus) – C:\Windows\system32\DRIVERS\vmbus.sys (Microsoft Corporation)
DRV - (iaStorV) – C:\Windows\system32\DRIVERS\iaStorV.sys (Intel Corporation)
DRV - (rdyboost) – C:\Windows\System32\drivers\rdyboost.sys (Microsoft Corporation)
DRV - (nvlddmkm) – C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (cpuz134) – C:\Windows\System32\drivers\cpuz134_x32.sys (Windows ® Win 7 DDK provider)
DRV - (TuneUpUtilitiesDrv) – C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys (TuneUp Software)
DRV - (ElbyCDIO) – C:\Windows\System32\drivers\ElbyCDIO.sys (Elaborate Bytes AG)
DRV - (atikmdag) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (cmdide) – C:\Windows\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (adpahci) – C:\Windows\system32\DRIVERS\adpahci.sys (Adaptec, Inc.)
DRV - (adp94xx) – C:\Windows\system32\DRIVERS\adp94xx.sys (Adaptec, Inc.)
DRV - (amdsbs) – C:\Windows\system32\DRIVERS\amdsbs.sys (AMD Technologies Inc.)
DRV - (adpu320) – C:\Windows\system32\DRIVERS\adpu320.sys (Adaptec, Inc.)
DRV - (arcsas) – C:\Windows\system32\DRIVERS\arcsas.sys (Adaptec, Inc.)
DRV - (arc) – C:\Windows\system32\DRIVERS\arc.sys (Adaptec, Inc.)
DRV - (aliide) – C:\Windows\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (nfrd960) – C:\Windows\system32\DRIVERS\nfrd960.sys (IBM Corporation)
DRV - (LSI_SAS) – C:\Windows\system32\DRIVERS\lsi_sas.sys (LSI Corporation)
DRV - (MegaSR) – C:\Windows\system32\DRIVERS\MegaSR.sys (LSI Corporation, Inc.)
DRV - (LSI_SCSI) – C:\Windows\system32\DRIVERS\lsi_scsi.sys (LSI Corporation)
DRV - (LSI_FC) – C:\Windows\system32\DRIVERS\lsi_fc.sys (LSI Corporation)
DRV - (LSI_SAS2) – C:\Windows\system32\DRIVERS\lsi_sas2.sys (LSI Corporation)
DRV - (iirsp) – C:\Windows\system32\DRIVERS\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (megasas) – C:\Windows\system32\DRIVERS\megasas.sys (LSI Corporation)
DRV - (hwpolicy) – C:\Windows\System32\drivers\hwpolicy.sys (Microsoft Corporation)
DRV - (elxstor) – C:\Windows\system32\DRIVERS\elxstor.sys (Emulex)
DRV - (aic78xx) – C:\Windows\system32\DRIVERS\djsvs.sys (Adaptec, Inc.)
DRV - (HpSAMD) – C:\Windows\system32\DRIVERS\HpSAMD.sys (Hewlett-Packard Company)
DRV - (FsDepends) – C:\Windows\System32\drivers\fsdepends.sys (Microsoft Corporation)
DRV - (vsmraid) – C:\Windows\system32\DRIVERS\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (storflt) – C:\Windows\system32\DRIVERS\vmstorfl.sys (Microsoft Corporation)
DRV - (vdrvroot) – C:\Windows\system32\DRIVERS\vdrvroot.sys (Microsoft Corporation)
DRV - (storvsc) – C:\Windows\system32\DRIVERS\storvsc.sys (Microsoft Corporation)
DRV - (WIMMount) – C:\Windows\System32\drivers\wimmount.sys (Microsoft Corporation)
DRV - (viaide) – C:\Windows\system32\DRIVERS\viaide.sys (VIA Technologies, Inc.)
DRV - (ql2300) – C:\Windows\system32\DRIVERS\ql2300.sys (QLogic Corporation)
DRV - (ql40xx) – C:\Windows\system32\DRIVERS\ql40xx.sys (QLogic Corporation)
DRV - (SiSRaid4) – C:\Windows\system32\DRIVERS\sisraid4.sys (Silicon Integrated Systems)
DRV - (pcw) – C:\Windows\System32\drivers\pcw.sys (Microsoft Corporation)
DRV - (SiSRaid2) – C:\Windows\system32\DRIVERS\SiSRaid2.sys (Silicon Integrated Systems Corp.)
DRV - (stexstor) – C:\Windows\system32\DRIVERS\stexstor.sys (Promise Technology)
DRV - (CNG) – C:\Windows\System32\Drivers\cng.sys (Microsoft Corporation)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) – C:\Windows\System32\Drivers\Brserid.sys (Brother Industries Ltd.)
DRV - (rdpbus) – C:\Windows\System32\drivers\rdpbus.sys (Microsoft Corporation)
DRV - (RDPREFMP) – C:\Windows\System32\drivers\RDPREFMP.sys (Microsoft Corporation)
DRV - (RasAgileVpn) WAN Miniport (IKEv2) – C:\Windows\System32\drivers\agilevpn.sys (Microsoft Corporation)
DRV - (WfpLwf) – C:\Windows\System32\drivers\wfplwf.sys (Microsoft Corporation)
DRV - (NdisCap) – C:\Windows\System32\drivers\ndiscap.sys (Microsoft Corporation)
DRV - (vwifibus) – C:\Windows\System32\drivers\vwifibus.sys (Microsoft Corporation)
DRV - (UmPass) – C:\Windows\system32\DRIVERS\umpass.sys (Microsoft Corporation)
DRV - (mshidkmdf) – C:\Windows\System32\drivers\mshidkmdf.sys (Microsoft Corporation)
DRV - (MTConfig) – C:\Windows\system32\DRIVERS\MTConfig.sys (Microsoft Corporation)
DRV - (scfilter) – C:\Windows\System32\drivers\scfilter.sys (Microsoft Corporation)
DRV - (s3cap) – C:\Windows\system32\DRIVERS\vms3cap.sys (Microsoft Corporation)
DRV - (VMBusHID) – C:\Windows\system32\DRIVERS\VMBusHID.sys (Microsoft Corporation)
DRV - (discache) – C:\Windows\System32\drivers\discache.sys (Microsoft Corporation)
DRV - (AcpiPmi) – C:\Windows\system32\DRIVERS\acpipmi.sys (Microsoft Corporation)
DRV - (AmdPPM) – C:\Windows\system32\DRIVERS\amdppm.sys (Microsoft Corporation)
DRV - (hcw85cir) – C:\Windows\system32\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV - (BrUsbMdm) – C:\Windows\System32\Drivers\BrUsbMdm.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) – C:\Windows\System32\Drivers\BrUsbSer.sys (Brother Industries Ltd.)
DRV - (BrSerWdm) – C:\Windows\System32\Drivers\BrSerWdm.sys (Brother Industries Ltd.)
DRV - (BrFiltLo) – C:\Windows\system32\DRIVERS\BrFiltLo.sys (Brother Industries, Ltd.)
DRV - (BrFiltUp) – C:\Windows\system32\DRIVERS\BrFiltUp.sys (Brother Industries, Ltd.)
DRV - (b57nd60x) – C:\Windows\System32\drivers\b57nd60x.sys (Broadcom Corporation)
DRV - (ebdrv) – C:\Windows\system32\DRIVERS\evbdx.sys (Broadcom Corporation)
DRV - (b06bdrv) – C:\Windows\system32\DRIVERS\bxvbdx.sys (Broadcom Corporation)
DRV - (RTL8167) – C:\Windows\System32\drivers\Rt86win7.sys (Realtek Corporation )
DRV - (WinRing0_1_2_0) – C:\Program Files\realtemp\WinRing0.sys (OpenLibSys.org)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.nl
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.nl
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.nl/ig?hl=nl
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG10\Firefox\ [2010-11-26 21:26:45 | 000,000,000 | —D | M]


O1 HOSTS File: ([2010-09-18 17:55:31 | 000,000,853 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 www.tune-up.com
O2 - BHO: (IE7Pro BHO) - {00011268-E188-40DF-A514-835FCD78B1BF} - C:\Program Files\IEPro\IEPro.dll (IE7Pro.com)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll (AVG Technologies CZ, s.r.o.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Grab Pro) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files\IEPro\IEProRecorder.dll ()
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [SSDMonitor] C:\Program Files\Common Files\PC Tools\sMonitor\SSDMonitor.exe (PC Tools)
O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKCU..\Run: [PS3 Mediaserver] C:\Program Files\PS3 Media Server\PMS.exe (A. Brochard)
O4 - HKCU..\Run: [RegClean Expert Scheduler] C:\Program Files\Registry Clean Expert\RCHelper.exe (iExpert Software)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoInternetOpenWith = 1
O13 - gopher Prefix: missing
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} http://www.nvidia.com/content/DriverDownlo…sreqlab_nvd.cab (System Requirements Lab Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O30 - LSA: Security Packages - (pku2u) - C:\Windows\System32\pku2u.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009-06-10 22:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (C:\Program Files\AVG\AVG10\avgchsvx.exe /sync) - C:\Program Files\AVG\AVG10\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
O34 - HKLM BootExecute: (C:\Program Files\AVG\AVG10\avgrsx.exe /sync /restart) - C:\Program Files\AVG\AVG10\avgrsx.exe (AVG Technologies CZ, s.r.o.)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: UxTuneUp - C:\Windows\System32\uxtuneup.dll (TuneUp Software)
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
NetSvcs: Themes - C:\Windows\System32\themeservice.dll (Microsoft Corporation)
NetSvcs: BDESVC - C:\Windows\System32\bdesvc.dll (Microsoft Corporation)

Drivers32: msacm.ac3acm - C:\Windows\System32\ac3acm.acm (fccHandler)
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3fhg - C:\Windows\System32\mp3fhg.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FFDS - C:\Windows\System32\ff_vfw.dll ()
Drivers32: VIDC.XVID - C:\Windows\System32\xvidvfw.dll ()
Drivers32: VIDC.YV12 - C:\Windows\System32\yv12vfw.dll (www.helixcommunity.org)


========== Files/Folders - Created Within 30 Days ==========

[2010-12-14 20:16:57 | 000,000,000 | -H-D | C] – C:\Windows\PIF
[2010-12-14 19:34:34 | 000,000,000 | —D | C] – C:\hijackthis
[2010-11-30 22:01:01 | 000,000,000 | —D | C] – C:\Windows\Sun
[2010-11-28 18:47:27 | 000,000,000 | —D | C] – C:\Users\Gebruiker\AppData\Roaming\Easeware
[2010-11-28 18:47:17 | 000,000,000 | —D | C] – C:\Program Files\asus
[2010-11-26 21:44:02 | 000,000,000 | -H-D | C] – C:\$AVG
[2010-11-26 21:34:30 | 000,000,000 | —D | C] – C:\Users\Gebruiker\AppData\Roaming\AVG10
[2010-11-26 21:27:14 | 000,000,000 | -H-D | C] – C:\ProgramData\Common Files
[2010-11-26 21:26:41 | 000,000,000 | —D | C] – C:\ProgramData\AVG10
[2010-11-26 21:26:41 | 000,000,000 | —D | C] – C:\Windows\System32\drivers\AVG
[2010-11-26 21:22:33 | 000,000,000 | —D | C] – C:\ProgramData\MFAData

========== Files - Modified Within 30 Days ==========

[2010-12-14 18:27:12 | 101,792,458 | —- | M] () – C:\Windows\System32\drivers\AVG\incavi.avm
[2010-12-14 18:23:00 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010-12-12 20:28:01 | 000,000,280 | —- | M] () – C:\Users\Gebruiker\AppData\Local\IndexIE_7F68A003.il
[2010-12-01 09:38:17 | 000,000,069 | —- | M] () – C:\Windows\NeroDigital.ini
[2010-12-01 09:38:16 | 000,062,976 | —- | M] () – C:\Users\Gebruiker\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010-11-28 11:37:39 | 000,007,649 | —- | M] () – C:\Users\Gebruiker\AppData\Local\resmon.resmoncfg

========== Files Created - No Company Name ==========

[2010-12-14 20:27:13 | 000,022,016 | —- | C] () – C:\Windows\System32\jwinz.exe
[2010-12-14 18:27:12 | 101,792,458 | —- | C] () – C:\Windows\System32\drivers\AVG\incavi.avm
[2010-10-01 16:45:58 | 000,000,069 | —- | C] () – C:\Windows\NeroDigital.ini
[2010-09-21 14:54:08 | 000,000,038 | —- | C] () – C:\Windows\avisplitter.ini
[2010-09-21 14:54:07 | 000,790,528 | —- | C] () – C:\Windows\System32\xvidcore.dll
[2010-09-21 14:54:07 | 000,134,144 | —- | C] () – C:\Windows\System32\xvidvfw.dll
[2010-09-21 14:54:07 | 000,108,032 | —- | C] () – C:\Windows\System32\ff_vfw.dll
[2010-09-21 13:14:23 | 000,062,976 | —- | C] () – C:\Users\Gebruiker\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010-09-18 17:54:50 | 000,000,280 | —- | C] () – C:\Users\Gebruiker\AppData\Local\IndexIE_7F68A003.il
[2010-09-18 16:22:33 | 000,007,649 | —- | C] () – C:\Users\Gebruiker\AppData\Local\resmon.resmoncfg
[2010-09-18 15:55:09 | 000,001,536 | —- | C] () – C:\Windows\System32\OGAAddin.dll
[2010-09-18 15:55:05 | 000,667,136 | —- | C] () – C:\Windows\System32\OGACheckControl.dll
[2010-09-18 13:32:07 | 000,116,224 | —- | C] () – C:\Windows\System32\pdfcmnnt.dll
[2010-09-18 12:38:53 | 000,165,376 | —- | C] () – C:\Windows\System32\unrar.dll
[2010-09-17 19:46:56 | 000,691,696 | —- | C] () – C:\Windows\System32\drivers\sptd.sys
[2009-07-14 00:51:43 | 000,073,728 | —- | C] () – C:\Windows\System32\BthpanContextHandler.dll
[2009-07-14 00:42:10 | 000,064,000 | —- | C] () – C:\Windows\System32\BWContextHandler.dll
[1996-04-03 20:33:26 | 000,005,248 | —- | C] () – C:\Windows\System32\giveio.sys

========== LOP Check ==========

[2010-11-26 21:34:30 | 000,000,000 | —D | M] – C:\Users\Gebruiker\AppData\Roaming\AVG10
[2010-09-18 13:41:51 | 000,000,000 | —D | M] – C:\Users\Gebruiker\AppData\Roaming\DAEMON Tools Lite
[2010-11-28 18:47:27 | 000,000,000 | —D | M] – C:\Users\Gebruiker\AppData\Roaming\Easeware
[2010-09-18 15:45:34 | 000,000,000 | —D | M] – C:\Users\Gebruiker\AppData\Roaming\GrabPro
[2010-09-18 15:58:28 | 000,000,000 | —D | M] – C:\Users\Gebruiker\AppData\Roaming\iExpert Software
[2010-09-18 16:57:46 | 000,000,000 | —D | M] – C:\Users\Gebruiker\AppData\Roaming\MiniDm
[2010-09-18 18:58:37 | 000,000,000 | —D | M] – C:\Users\Gebruiker\AppData\Roaming\NewsLeecher
[2010-09-18 16:03:09 | 000,000,000 | —D | M] – C:\Users\Gebruiker\AppData\Roaming\Notepad++
[2010-11-30 21:04:31 | 000,000,000 | —D | M] – C:\Users\Gebruiker\AppData\Roaming\Registry Mechanic
[2010-09-18 17:55:24 | 000,000,000 | —D | M] – C:\Users\Gebruiker\AppData\Roaming\TuneUp Software
[2010-09-18 15:55:58 | 000,000,000 | —D | M] – C:\Users\Gebruiker\AppData\Roaming\URSoft
[2009-07-14 05:53:46 | 000,031,726 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2009-06-10 22:42:20 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2010-03-21 15:13:14 | 000,383,582 | RHS- | M] () – C:\bootmgr
[2010-09-17 20:36:21 | 000,008,192 | RHS- | M] () – C:\BOOTSECT.BAK
[2009-06-10 22:42:20 | 000,000,010 | —- | M] () – C:\config.sys
[2008-08-29 02:40:21 | 000,181,408 | RHS- | M] () – C:\grldr
[2010-10-08 23:17:09 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010-10-08 23:17:09 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2010-12-14 18:22:57 | 3488,919,552 | -HS- | M] () – C:\pagefile.sys
[2010-09-17 19:46:43 | 000,248,558 | RHS- | M] () – C:\TYBAR
[2007-03-08 06:52:55 | 000,168,736 | RHS- | M] () – C:\vstaldr1
[2007-03-08 06:53:29 | 000,012,298 | RHS- | M] () – C:\vstaldr2
[2010-09-17 19:46:43 | 000,000,020 | RHS- | M] () – C:\win7.ld

< %systemroot%\Fonts\*.com >

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009-06-10 22:31:19 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2009-07-14 02:15:35 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\jnwppr.dll
[2006-10-26 18:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\msonpppr.dll
[2009-07-14 02:16:19 | 000,029,696 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\winprint.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >
[2010-09-02 02:03:44 | 000,740,188 | —- | M] () – C:\Windows\System32\splash.jpg

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009-07-14 05:41:57 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010-09-18 08:06:28 | 000,000,221 | -HS- | M] () – C:\Users\Gebruiker\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-11-23 19:16:34

========== Alternate Data Streams ==========

@Alternate Data Stream - 159 bytes -> C:\ProgramData\TEMP:1CE11B51
@Alternate Data Stream - 153 bytes -> C:\ProgramData\TEMP:D1B5B4F1

< End of report >
Please download Rootkit Unhooker and save it on your desktop.
  • Disable your security programs
  • Double click RKUnhookerLE.exe to run it
  • Click the Report tab, then click Scan
  • Check Drivers and Stealth Code,
  • Uncheck the rest, then click OK
  • When prompted to Select Disks for Scan, make sure C:\ is checked and click OK
  • Wait till the scanner has finished then go File > Save Report
  • Save the report somewhere you can find it. Click Close
  • Copy the entire contents of the report and paste it in your next reply.
Note - You may get this warning, it is ok, just ignore it:

"Rootkit Unhooker has detected a parasite inside itself!
It is recommended to remove parasite, okay?"

Run this instead




[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


If GMER won't run try with devices unchecked.If still no go try in safe mode.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI