This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Virus on Vista machine ("my computer online scan")

19 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hey there. Hope you can help…i am getting a lot of Pop ups in internet explorer with online computer scans"….I can tell its a virus.

Would really appreciate some help, Cheers.




Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:30:32 PM, on 26/01/2011
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18999)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Toshiba\ConfigFree\NDSTray.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Toshiba\Power Saver\TPwrMain.exe
C:\Program Files\Toshiba\SmoothView\SmoothView.exe
C:\Program Files\Toshiba\FlashCards\TCrdMain.exe
C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe
C:\Program Files\HP\Digital Imaging\bin\HpqSRmon.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
C:\Program Files\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\AVG\AVG10\avgtray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Toshiba\TOSCDSPD\TOSCDSPD.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
C:\Program Files\Toshiba\ConfigFree\CFSwMgr.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe
C:\Program Files\Vodafone\Vodafone Mobile Connect\Optimization Client\bmctl.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10l_ActiveX.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKLM\..\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
O4 - HKLM\..\Run: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe
O4 - HKLM\..\Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
O4 - HKLM\..\Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
O4 - HKLM\..\Run: [Camera Assistant Software] "C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe"
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [Skytel] Skytel.exe
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [MobileConnect] C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe /silent
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
O4 - HKLM\..\Run: [IJNetworkScanUtility] C:\Program Files\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe
O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG10\avgtray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [TOSCDSPD] TOSCDSPD.EXE
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Pareto_Update] C:\Program Files\Common Files\ParetoLogic\UUS2\Pareto_Update.exe
O4 - HKCU\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe"
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files\Windows Live\Companion\companioncore.dll
O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{BF991A0C-E330-4FD6-84B2-5985D1E25F5F}: NameServer = 203.21.112.40 202.124.65.18
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: AVG Firewall (avgfws) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG10\avgfws.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG10\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: TOSHIBA Navi Support Service (TNaviSrv) - TOSHIBA Corporation - C:\Program Files\Toshiba\TOSHIBA HD DVD PLAYER\TNaviSrv.exe
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe
O23 - Service: TomTomHOMEService - TomTom - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: Vodafone Mobile Connect Service (VMCService) - Vodafone - C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe

–
End of file - 10444 bytes
Hello and Posted Image

My name is patndoris. I will be glad to take a look at your log and help you with solving any malware problems. It will be very helpful if you follow these guidelines:
  • Malware logs are often lengthy and can take a lot of time to research and interpret. Please be patient while I review your logs.
  • Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to get your system clean.
  • Please make sure to carefully read any instruction that I give you. If you're not sure, or if something unexpected happens, do NOT continue! Stop and ask!
  • Please follow my instructions carefully and in the order they are posted. You may also find it helpful to print out the instructions you receive.
  • Please do not run any scans or install/uninstall any applications or delete anything without being directed to do so.
  • Remember, absence of symptoms does not mean the infection is all gone. Please stick with me till you're given the "all clear".
  • Please do not use the Attachment feature for any log file. Do a Copy/Paste of the entire contents of the log file and submit it inside your post.
  • Please reply within 3 days. If I do not hear back from you in that time frame, I will post a reminder for you. Topics with no reply in 4 days are closed!



Vista users:
Since you have Vista, you will always want to right-click and choose "run as administrator" to launch any tools we use.

1. These tools MUST be run from the executable. (.exe) every time you run them
2. With Admin Rights (Right click, choose "Run as Administrator")




HijackThis has largely been replaced by other tools. Since being acquired by TrendMicro, HijackThis has not been regularly updated. Many infections are now able to hide partly, or completely from a HijackThis scan. DDS includes all the scan locations of HijackThis and more.



Download and Run DDS by sUBs

Please download DDS by sUBs from one of the following links and save it to your desktop.
    • DDS.scr
    • DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Right-click and choose Run as Administrator on the DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments, attach.txt will open in a second window.
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.



Scan With RootKitUnHooker

  • Please Download Rootkit Unhooker and save it to your desktop.
  • Right-click and choose Run as Administrator on RKUnhookerLE.exe to run it.
  • Click the Report tab, then click Scan.
  • Check (Tick) Drivers and Stealth
  • Uncheck the rest. then click OK
  • When prompted to Select Disks for Scan, make sure C:\ is checked and click OK
  • Wait till the scanner has finished and then click File > Save Report.
  • Save the report somewhere where you can find it. Click Close.
  • Copy the entire contents of the report and paste it in your next reply.

Note** you may get the following warning, just click OK and continue.

"Rootkit Unhooker has detected a parasite inside itself!
It is recommended to remove parasite, okay?"
Thankyou patndoris! I am away for a couple of days over the weekend but I will try and get back to you with the logs as soon as I can. Cheers.
Here are the logs as promised :)

When you mean "disabling any script protection", I assume you are referring to deactivating my AVG Resident Shield?

When I downloaded RootKit UnHooker I couldn't save it to my desktop because it said I didn't have permission? This isn't right is it? I then saved it to a documents fodler which was fine but I couldn't even move the application to the desktop after that? I then tried running the program but my AVG kept detecting a Malware so it would delete the .exe file. Should I click on ignore and contiue with the .exe anyway?


DDS

DDS (Ver_10-12-12.01) - NTFSx86
Run by [removed] at 18:14:20.03 on Mon 31/01/2011
Internet Explorer: 8.0.6001.18999
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.61.1033.18.2046.693 [GMT 8:00]

SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
AV: AVG Internet Security 2011 *Disabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
SP: AVG Internet Security 2011 *Disabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: AVG Firewall *Enabled* {621CC794-9486-F902-D092-0484E8EA828B}

============== Running Processes ===============

C:\PROGRA~1\AVG\AVG10\avgchsvx.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\WLANExt.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\Ati2evxx.exe
C:\Windows\system32\agrsmsvc.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\AVG\AVG10\avgfws.exe
C:\Program Files\Protector Suite QL\upeksvr.exe
C:\Program Files\AVG\AVG10\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Windows\system32\svchost.exe -k hpdevmgmt
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Toshiba\TOSHIBA HD DVD PLAYER\TNaviSrv.exe
C:\Windows\system32\TODDSrv.exe
C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\AVG\AVG10\avgam.exe
C:\Program Files\AVG\AVG10\avgnsx.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
C:\Program Files\Toshiba\ConfigFree\NDSTray.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Toshiba\Power Saver\TPwrMain.exe
C:\Program Files\Toshiba\SmoothView\SmoothView.exe
C:\Program Files\Toshiba\FlashCards\TCrdMain.exe
C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe
C:\Program Files\HP\Digital Imaging\bin\HpqSRmon.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
C:\Program Files\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\AVG\AVG10\avgtray.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Toshiba\TOSCDSPD\TOSCDSPD.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
C:\Program Files\Toshiba\ConfigFree\CFSwMgr.exe
C:\Program Files\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Vodafone\Vodafone Mobile Connect\Optimization Client\bmctl.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10l_ActiveX.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\iTunes\iTunes.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceHelper.exe
C:\Program Files\Common Files\Apple\Apple Application Support\distnoted.exe
C:\PROGRA~1\AVG\AVG10\avgrsx.exe
C:\Program Files\AVG\AVG10\avgcsrvx.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\Dim\Desktop\dds.pif

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\programdata\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg10\avgssie.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - c:\program files\windows live\companion\companioncore.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
uRun: [TOSCDSPD] TOSCDSPD.EXE
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [MsnMsgr] "c:\program files\windows live\messenger\MsnMsgr.Exe" /background
uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized
uRun: [Pareto_Update] c:\program files\common files\paretologic\uus2\Pareto_Update.exe
uRun: [TomTomHOME.exe] "c:\program files\tomtom home 2\TomTomHOMERunner.exe"
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [NDSTray.exe] NDSTray.exe
mRun: [RtHDVCpl] RtHDVCpl.exe
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe"
mRun: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
mRun: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe
mRun: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
mRun: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
mRun: [Camera Assistant Software] "c:\program files\camera assistant software for toshiba\traybar.exe"
mRun: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
mRun: [Skytel] Skytel.exe
mRun: [hpqSRMon] c:\program files\hp\digital imaging\bin\hpqSRMon.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [MobileConnect] c:\program files\vodafone\vodafone mobile connect\bin\MobileConnect.exe /silent
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [CanonMyPrinter] c:\program files\canon\myprinter\BJMyPrt.exe /logon
mRun: [IJNetworkScanUtility] c:\program files\canon\canon ij network scan utility\CNMNSUT.exe
mRun: [itype] "c:\program files\microsoft intellitype pro\itype.exe"
mRun: [IntelliPoint] "c:\program files\microsoft intellipoint\ipoint.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [AVG_TRAY] c:\program files\avg\avg10\avgtray.exe
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: DisableCAD = 1 (0x1)
IE: E&xport; to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - c:\program files\windows live\companion\companioncore.dll
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg10\avgpp.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
Notify: psfus - c:\windows\system32\psqlpwd.dll
SEH: {114A72AF-007E-461D-89FF-864728C749C5} - No File
LSA: Notification Packages = scecli psqlpwd

============= SERVICES / DRIVERS ===============

R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [2010-9-13 25680]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2010-9-7 26064]
R0 BMLoad;Bytemobile Boot Time Load Driver;c:\windows\system32\drivers\BMLoad.sys [2010-3-11 13184]
R1 Avgfwfd;AVG network filter service;c:\windows\system32\drivers\avgfwd6x.sys [2010-7-12 54112]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2010-12-8 251728]
R1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2010-9-7 34384]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [2010-11-12 299984]
R2 avgfws;AVG Firewall;c:\program files\avg\avg10\avgfws.exe [2010-11-22 3226632]
R2 AVGIDSAgent;AVGIDSAgent;c:\program files\avg\avg10\identity protection\agent\bin\AVGIDSAgent.exe [2011-1-6 6128720]
R2 avgwd;AVG WatchDog;c:\program files\avg\avg10\avgwdsvc.exe [2010-10-22 265400]
R2 TomTomHOMEService;TomTomHOMEService;c:\program files\tomtom home 2\TomTomHOMEService.exe [2009-11-13 92008]
R2 VMCService;Vodafone Mobile Connect Service;c:\program files\vodafone\vodafone mobile connect\bin\VMCService.exe [2010-3-25 9216]
R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [2010-8-19 123472]
R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [2010-8-19 30288]
R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [2010-8-19 27216]
R3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-6-24 21504]
R3 FwLnk;FwLnk Driver;c:\windows\system32\drivers\FwLnk.sys [2007-6-14 7168]
R3 vodafone_K3805-z_dc_enum;vodafone_K3805-z_dc_enum;c:\windows\system32\drivers\vodafone_K3805-z_dc_enum.sys [2010-3-2 80000]
R3 winbondcir;Winbond IR Transceiver;c:\windows\system32\drivers\winbondcir.sys [2007-3-28 43008]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S3 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr.sys [2010-10-20 39272]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2010-9-23 1493352]
S3 massfilter;ZTE Mass Storage Filter Driver;c:\windows\system32\drivers\massfilter.sys [2009-8-18 9216]
S3 NinjaUSB;Freecom Turbo USB 2.0;c:\windows\system32\drivers\NinjaUSB.sys [2010-2-25 24704]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
S4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\windows live\mesh\wlcrasvc.exe [2010-9-22 51040]

=============== Created Last 30 ================

2011-01-26 14:28:13 388096 —-a-r- c:\users\dim\appdata\roaming\microsoft\installer\{45a66726-69bc-466b-a7a4-12fcba4883d7}\HiJackThis.exe
2011-01-26 14:28:12 ——– d—–w- c:\program files\Trend Micro
2011-01-13 09:25:13 ——– d—–w- c:\progra~2\TomTom
2011-01-13 09:24:55 ——– d—–w- c:\users\dim\appdata\roaming\TomTom
2011-01-13 09:24:55 ——– d—–w- c:\users\dim\appdata\local\TomTom
2011-01-13 09:23:12 ——– d—–w- c:\program files\TomTom International B.V
2011-01-13 09:22:38 ——– d—–w- c:\program files\TomTom HOME 2
2011-01-13 09:17:47 ——– d—–w- c:\program files\TomTom DesktopSuite
2011-01-12 02:21:13 708608 —-a-w- c:\program files\common files\system\ado\msado15.dll
2011-01-12 02:21:13 57344 —-a-w- c:\program files\common files\system\msadc\msadcs.dll
2011-01-12 02:21:13 413696 —-a-w- c:\windows\system32\odbc32.dll
2011-01-12 02:21:13 253952 —-a-w- c:\program files\common files\system\ado\msadox.dll
2011-01-12 02:21:13 241664 —-a-w- c:\program files\common files\system\ado\msadomd.dll
2011-01-12 02:21:13 180224 —-a-w- c:\program files\common files\system\msadc\msadco.dll
2011-01-12 02:21:11 1169408 —-a-w- c:\windows\system32\sdclt.exe
2011-01-11 07:54:45 ——– d—–w- c:\progra~2\Sports Interactive
2011-01-11 07:53:29 ——– d—–w- c:\users\dim\appdata\roaming\Sports Interactive
2011-01-11 07:53:28 ——– d—–w- c:\users\dim\appdata\local\Sports Interactive
2011-01-11 07:33:12 ——– d–h–w- c:\program files\Zero G Registry
2011-01-11 07:33:12 ——– d—–w- c:\program files\Sports Interactive
2011-01-11 07:32:16 ——– d–h–w- c:\users\dim\InstallAnywhere
2011-01-10 07:40:52 ——– d–h–w- c:\progra~2\CanonIJScan
2011-01-08 05:52:06 ——– d—–w- c:\program files\iPod
2011-01-08 05:52:04 ——– d—–w- c:\program files\iTunes
2011-01-08 05:40:57 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin7.dll
2011-01-08 05:40:57 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin6.dll
2011-01-08 05:40:57 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin5.dll
2011-01-08 05:40:57 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin4.dll
2011-01-08 05:40:57 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin3.dll
2011-01-08 05:40:57 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin2.dll
2011-01-08 05:40:57 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin.dll

==================== Find3M ====================

2010-11-29 09:38:30 94208 —-a-w- c:\windows\system32\QuickTimeVR.qtx
2010-11-29 09:38:30 69632 —-a-w- c:\windows\system32\QuickTime.qts
2010-11-12 10:53:06 472808 —-a-w- c:\windows\system32\deployJava1.dll
2010-11-04 18:56:07 345600 —-a-w- c:\windows\system32\wmicmiplugin.dll
2010-11-04 18:55:38 352768 —-a-w- c:\windows\system32\taskschd.dll
2010-11-04 18:55:38 270336 —-a-w- c:\windows\system32\taskcomp.dll
2010-11-04 18:55:12 601600 —-a-w- c:\windows\system32\schedsvc.dll
2010-11-04 16:34:06 171520 —-a-w- c:\windows\system32\taskeng.exe

============= FINISH: 18:15:18.51 ===============



Rootkit Unhooker:


awaiting further instruction. cheers

Attachments:

When you mean "disabling any script protection", I assume you are referring to deactivating my AVG Resident Shield?

Yes, you are correct, when running the scans you want to disable your AVG.

When I downloaded RootKit UnHooker I couldn't save it to my desktop because it said I didn't have permission? This isn't right is it?

Please make sure you are logged into the computer as an administrator.

If you are still unable to get it on the desktop, please boot into Safe mode:


Boot your computer in Safe Mode
  • Turn the computer on or Restart the computer
  • As soon as BIOS is loaded, start tapping the F8 key.
  • The Windows Advanced Options Menu appears.
    If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
  • Use the arrow keys to select the Safe Mode menu option.
  • Press Enter.
  • The computer then begins to start in Safe mode.
  • Log into your usual account and try Rootkit Unhooker as per the previous instructions
  • When you are finished with all troubleshooting, close all programs and restart the computer as you normally would.


If you are still unable to get it onto your desktop, please let me know before continuing on.
Cheers for the quick reply :)

A system restart did the trick…I could save the file to the desktop without any problem…computers are strange species sometimes!

Here is the report from RootKitUnHooker:

RkU Version: 3.8.388.590, Type LE (SR2)
==============================================
OS Name: Windows Vista
Version 6.0.6002 (Service Pack 2)
Number of processors #2
==============================================
>Drivers
==============================================
0x8D606000 C:\Windows\system32\DRIVERS\atikmdag.sys 7651328 bytes (ATI Technologies Inc., ATI Radeon Kernel Mode Driver)
0x8284A000 C:\Windows\system32\ntkrnlpa.exe 3903488 bytes (Microsoft Corporation, NT Kernel & System)
0x8284A000 PnpManager 3903488 bytes
0x8284A000 RAW 3903488 bytes
0x8284A000 WMIxWDM 3903488 bytes
0x8E207000 C:\Windows\system32\DRIVERS\NETw4v32.sys 2289664 bytes (Intel Corporation, Intel® Wireless WiFi Link Driver)
0x81A80000 Win32k 2109440 bytes
0x81A80000 C:\Windows\System32\win32k.sys 2109440 bytes (Microsoft Corporation, Multi-User Win32 Driver)
0x8FE01000 C:\Windows\system32\drivers\RTKVHDA.sys 1765376 bytes (Realtek Semiconductor Corp., Realtek® High Definition Audio Function Driver)
0x90202000 C:\Windows\system32\DRIVERS\AGRSM.sys 1163264 bytes (Agere Systems, SoftModem Device Driver)
0x88C00000 C:\Windows\System32\Drivers\Ntfs.sys 1114112 bytes (Microsoft Corporation, NT File System Driver)
0x88807000 C:\Windows\system32\drivers\ndis.sys 1093632 bytes (Microsoft Corporation, NDIS 6.0 wrapper driver)
0x88A03000 C:\Windows\System32\drivers\tcpip.sys 958464 bytes (Microsoft Corporation, TCP/IP Driver)
0x804D3000 C:\Windows\system32\CI.dll 917504 bytes (Microsoft Corporation, Code Integrity Module)
0x9F2F9000 C:\Windows\system32\drivers\peauth.sys 909312 bytes (Microsoft Corporation, Protected Environment Authentication and Authorization Export Driver)
0x88B32000 C:\Windows\System32\Drivers\dump_iaStor.sys 778240 bytes
0x82E09000 C:\Windows\system32\DRIVERS\iaStor.sys 778240 bytes (Intel Corporation, Intel Matrix Storage Manager driver - ia32)
0x9E003000 C:\Windows\system32\drivers\spsys.sys 720896 bytes (Microsoft Corporation, security processor)
0x8DD52000 C:\Windows\System32\drivers\dxgkrnl.sys 659456 bytes (Microsoft Corporation, DirectX Graphics Kernel)
0x8E00F000 C:\Windows\system32\DRIVERS\HDAudBus.sys 577536 bytes (Microsoft Corporation, High Definition Audio Bus Driver)
0x82F41000 C:\Windows\System32\Drivers\ksecdd.sys 462848 bytes (Microsoft Corporation, Kernel Security Support Provider Interface)
0x8060B000 C:\Windows\system32\drivers\Wdf01000.sys 462848 bytes (Microsoft Corporation, Kernel Mode Driver Framework Runtime)
0x80409000 C:\Windows\system32\mcupdate_GenuineIntel.dll 458752 bytes (Microsoft Corporation, Intel Microcode Update Library)
0x9E10A000 C:\Windows\system32\drivers\HTTP.sys 446464 bytes (Microsoft Corporation, HTTP Protocol Stack)
0x9F288000 C:\Windows\System32\DRIVERS\srv.sys 319488 bytes (Microsoft Corporation, Server driver)
0x81CD0000 C:\Windows\System32\ATMFD.DLL 315392 bytes (Adobe Systems Incorporated, Windows NT OpenType/Type 1 Font Driver)
0x8E454000 C:\Windows\system32\drivers\tifm21.sys 311296 bytes (Texas Instruments, tifm21.sys)
0x88D4E000 C:\Windows\system32\DRIVERS\tos_sps32.sys 307200 bytes (TOSHIBA Corporation, tos_sps2)
0x80733000 C:\Windows\System32\drivers\volmgrx.sys 303104 bytes (Microsoft Corporation, Volume Manager Extension Driver)
0x90847000 C:\Windows\system32\drivers\afd.sys 294912 bytes (Microsoft Corporation, Ancillary Function Driver for WinSock)
0x8FFB0000 C:\Windows\system32\DRIVERS\avgtdix.sys 294912 bytes (AVG Technologies CZ, s.r.o., AVG Network connection watcher)
0x8068A000 C:\Windows\system32\drivers\acpi.sys 286720 bytes (Microsoft Corporation, ACPI Driver for NT)
0x80492000 C:\Windows\system32\CLFS.SYS 266240 bytes (Microsoft Corporation, Common Log File System Driver)
0x8E582000 C:\Windows\system32\DRIVERS\storport.sys 266240 bytes (Microsoft Corporation, Microsoft Storage Port Driver)
0x82FB2000 C:\Windows\system32\drivers\HdAudio.sys 258048 bytes (Microsoft Corporation, High Definition Audio Function Driver)
0x8E0A7000 C:\Windows\system32\DRIVERS\USBPORT.SYS 253952 bytes (Microsoft Corporation, USB 1.1 & 2.0 Port Driver)
0x90929000 C:\Windows\system32\DRIVERS\avgldx86.sys 245760 bytes (AVG Technologies CZ, s.r.o., AVG AVI Loader Driver)
0x908CC000 C:\Windows\system32\DRIVERS\rdbss.sys 245760 bytes (Microsoft Corporation, Redirected Drive Buffering SubSystem Driver)
0x8893D000 C:\Windows\system32\drivers\NETIO.SYS 241664 bytes (Microsoft Corporation, Network I/O Subsystem)
0x9F20F000 C:\Windows\system32\DRIVERS\mrxsmb10.sys 233472 bytes (Microsoft Corporation, Longhorn SMB Downlevel SubRdr)
0x88D10000 C:\Windows\system32\drivers\volsnap.sys 233472 bytes (Microsoft Corporation, Volume Shadow Copy Driver)
0x8E0F4000 C:\Windows\system32\DRIVERS\yk60x86.sys 233472 bytes (Marvell, NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller)
0x889AF000 C:\Windows\system32\DRIVERS\usbhub.sys 217088 bytes (Microsoft Corporation, Default Hub Driver for USB)
0x82817000 ACPI_HAL 208896 bytes
0x82817000 C:\Windows\system32\hal.dll 208896 bytes (Microsoft Corporation, Hardware Abstraction Layer DLL)
0x82EF6000 C:\Windows\system32\drivers\fltmgr.sys 204800 bytes (Microsoft Corporation, Microsoft Filesystem Filter Manager)
0x90801000 C:\Windows\System32\DRIVERS\netbt.sys 204800 bytes (Microsoft Corporation, MBT Transport driver)
0x8E4ED000 C:\Windows\system32\DRIVERS\SynTP.sys 196608 bytes (Synaptics, Inc., Synaptics Touchpad Driver)
0x8E553000 C:\Windows\system32\DRIVERS\msiscsi.sys 192512 bytes (Microsoft Corporation, Microsoft iSCSI Initiator Driver)
0x80792000 C:\Windows\system32\DRIVERS\pcmcia.sys 184320 bytes (Microsoft Corporation, PCMCIA Bus Driver)
0x807CF000 C:\Windows\system32\drivers\portcls.sys 184320 bytes (Microsoft Corporation, Port Class (Class Driver for Port/Miniport Devices))
0x88912000 C:\Windows\system32\drivers\msrpc.sys 176128 bytes (Microsoft Corporation, Kernel Remote Procedure Call Provider)
0x8E1AF000 C:\Windows\system32\DRIVERS\ks.sys 172032 bytes (Microsoft Corporation, Kernel CSA Library)
0x9E0C3000 C:\Windows\system32\DRIVERS\nwifi.sys 172032 bytes (Microsoft Corporation, NativeWiFi Miniport Driver)
0xA4C05000 C:\Windows\system32\DRIVERS\AVGIDSDriver.Sys 163840 bytes (AVG Technologies CZ, s.r.o. , IDS Application Activity Monitor Driver.)
0x9F260000 C:\Windows\System32\DRIVERS\srv2.sys 163840 bytes (Microsoft Corporation, Smb 2.0 Server driver)
0x88DB0000 C:\Windows\System32\drivers\ecache.sys 159744 bytes (Microsoft Corporation, Special Memory Device Cache)
0x806E1000 C:\Windows\system32\drivers\pci.sys 159744 bytes (Microsoft Corporation, NT Plug and Play PCI Enumerator)
0x805B3000 C:\Windows\system32\drivers\drmk.sys 151552 bytes (Microsoft Corporation, Microsoft Kernel DRM Descrambler Filter)
0x8E138000 C:\Windows\system32\DRIVERS\ndiswan.sys 143360 bytes (Microsoft Corporation, MS PPP Framing Driver (Strong Encryption))
0x88B08000 C:\Windows\system32\drivers\CLASSPNP.SYS 135168 bytes (Microsoft Corporation, SCSI Class System Dll)
0x9E1C2000 C:\Windows\system32\drivers\mrxdav.sys 135168 bytes (Microsoft Corporation, Windows NT WebDav Minirdr)
0x90380000 C:\Windows\System32\drivers\VIDEOPRT.SYS 135168 bytes (Microsoft Corporation, Video Port Driver)
0x805D8000 C:\Windows\system32\DRIVERS\mrxsmb.sys 126976 bytes (Microsoft Corporation, Windows NT SMB Minirdr)
0x82ECF000 C:\Windows\system32\drivers\ataport.SYS 122880 bytes (Microsoft Corporation, ATAPI Driver Extension)
0x9E177000 C:\Windows\System32\DRIVERS\srvnet.sys 118784 bytes (Microsoft Corporation, Server Network driver)
0x88AED000 C:\Windows\System32\drivers\fwpkclnt.sys 110592 bytes (Microsoft Corporation, FWP/IPsec Kernel-Mode API)
0x909C1000 C:\Windows\system32\drivers\luafv.sys 110592 bytes (Microsoft Corporation, LUA File Virtualization Filter Driver)
0x8E4A0000 C:\Windows\system32\DRIVERS\sdbus.sys 106496 bytes (Microsoft Corporation, SecureDigital Bus Driver)
0x9E194000 C:\Windows\system32\DRIVERS\bowser.sys 102400 bytes (Microsoft Corporation, NT Lan Manager Datagram Receiver Driver)
0x8E52E000 C:\Windows\system32\DRIVERS\cdrom.sys 98304 bytes (Microsoft Corporation, SCSI CD-ROM Driver)
0x9F248000 C:\Windows\system32\DRIVERS\mrxsmb20.sys 98304 bytes (Microsoft Corporation, Longhorn SMB 2.0 Redirector)
0x90912000 C:\Windows\System32\Drivers\dfsc.sys 94208 bytes (Microsoft Corporation, DFS Namespace Client Driver)
0x8E5E3000 C:\Windows\system32\DRIVERS\rasl2tp.sys 94208 bytes (Microsoft Corporation, RAS L2TP mini-port/call-manager driver)
0x90970000 C:\Windows\system32\DRIVERS\usbccgp.sys 94208 bytes (Microsoft Corporation, USB Common Class Generic Parent Driver)
0xA4C2D000 C:\Windows\system32\DRIVERS\cdfs.sys 90112 bytes (Microsoft Corporation, CD-ROM File System Driver)
0x9088F000 C:\Windows\system32\DRIVERS\pacer.sys 90112 bytes (Microsoft Corporation, QoS Packet Scheduler)
0x903E4000 C:\Windows\system32\DRIVERS\tdx.sys 90112 bytes (Microsoft Corporation, TDI Translation Driver)
0x9E1AD000 C:\Windows\System32\drivers\mpsdrv.sys 86016 bytes (Microsoft Corporation, Microsoft Protection Service Driver)
0x8E17E000 C:\Windows\system32\DRIVERS\rassstp.sys 86016 bytes (Microsoft Corporation, RAS SSTP Miniport Call Manager)
0x8E4BA000 C:\Windows\system32\DRIVERS\winbondcir.sys 86016 bytes (Winbond Electronics Corporation, Winbond MCE CIR Port Driver)
0x8E16A000 C:\Windows\system32\DRIVERS\raspptp.sys 81920 bytes (Microsoft Corporation, Peer-to-Peer Tunneling Protocol)
0x90833000 C:\Windows\system32\DRIVERS\smb.sys 81920 bytes (Microsoft Corporation, SMB Transport driver)
0x8899B000 C:\Windows\system32\DRIVERS\vodafone_K3805-z_dc_enum.sys 81920 bytes (Vodafone, DC Class Enumerator Driver)
0x8E4CF000 C:\Windows\system32\DRIVERS\i8042prt.sys 77824 bytes (Microsoft Corporation, i8042 Port Driver)
0x9E0F7000 C:\Windows\system32\DRIVERS\rspndr.sys 77824 bytes (Microsoft Corporation, Link-Layer Topology Responder Driver for NDIS 6)
0x908B9000 C:\Windows\system32\DRIVERS\wanarp.sys 77824 bytes (Microsoft Corporation, MS Remote Access and Routing ARP Driver)
0x903D3000 C:\Windows\system32\DRIVERS\avgfwd6x.sys 69632 bytes (AVG Technologies CZ, s.r.o., AVG Filter Driver)
0x88DD7000 C:\Windows\system32\drivers\disk.sys 69632 bytes (Microsoft Corporation, PnP Disk Driver)
0x889E4000 C:\Windows\System32\Drivers\NDProxy.SYS 69632 bytes (Microsoft Corporation, NDIS Proxy)
0x80479000 C:\Windows\system32\PSHED.dll 69632 bytes (Microsoft Corporation, Platform Specific Hardware Error Driver)
0x82F28000 C:\Windows\system32\drivers\fileinfo.sys 65536 bytes (Microsoft Corporation, FileInfo Filter Driver)
0x90329000 C:\Windows\system32\DRIVERS\HIDCLASS.SYS 65536 bytes (Microsoft Corporation, Hid Class Library)
0x9E0B3000 C:\Windows\system32\DRIVERS\lltdio.sys 65536 bytes (Microsoft Corporation, Link-Layer Topology Mapper I/O Driver)
0x807BF000 C:\Windows\System32\drivers\mountmgr.sys 65536 bytes (Microsoft Corporation, Mount Point Manager)
0x8E436000 C:\Windows\system32\DRIVERS\ohci1394.sys 65536 bytes (Microsoft Corporation, 1394 OpenHCI Port Driver)
0x8E19F000 C:\Windows\system32\DRIVERS\termdd.sys 65536 bytes (Microsoft Corporation, Terminal Server Driver)
0x8898C000 C:\Windows\system32\DRIVERS\intelppm.sys 61440 bytes (Microsoft Corporation, Processor Device Driver)
0x909B2000 C:\Windows\system32\DRIVERS\monitor.sys 61440 bytes (Microsoft Corporation, Monitor Driver)
0x88DA1000 C:\Windows\System32\Drivers\mup.sys 61440 bytes (Microsoft Corporation, Multiple UNC Provider driver)
0x80708000 C:\Windows\System32\drivers\partmgr.sys 61440 bytes (Microsoft Corporation, Partition Management Driver)
0x8E15B000 C:\Windows\system32\DRIVERS\raspppoe.sys 61440 bytes (Microsoft Corporation, RAS PPPoE mini-port/call-manager driver)
0x8E0E5000 C:\Windows\system32\DRIVERS\usbehci.sys 61440 bytes (Microsoft Corporation, EHCI eUSB Miniport Driver)
0x80724000 C:\Windows\system32\drivers\volmgr.sys 61440 bytes (Microsoft Corporation, Volume Manager Driver)
0x8E446000 C:\Windows\system32\DRIVERS\1394BUS.SYS 57344 bytes (Microsoft Corporation, 1394 Bus Device Driver)
0x81CC0000 C:\Windows\System32\cdd.dll 57344 bytes (Microsoft Corporation, Canonical Display Driver)
0x8E1D9000 C:\Windows\system32\DRIVERS\circlass.sys 57344 bytes (Microsoft Corporation, Consumer IR Class Driver for eHome)
0x908A5000 C:\Windows\system32\DRIVERS\netbios.sys 57344 bytes (Microsoft Corporation, NetBIOS interface driver)
0x903BC000 C:\Windows\System32\Drivers\Npfs.SYS 57344 bytes (Microsoft Corporation, NPFS Driver)
0x80784000 C:\Windows\system32\drivers\PCIIDEX.SYS 57344 bytes (Microsoft Corporation, PCI IDE Bus Driver Extension)
0x8067C000 C:\Windows\system32\drivers\WDFLDR.SYS 57344 bytes (Microsoft Corporation, Kernel Mode Driver Framework Loader)
0x9099B000 C:\Windows\System32\Drivers\crashdmp.sys 53248 bytes (Microsoft Corporation, Crash Dump Driver)
0x8E5D6000 C:\Windows\system32\drivers\modem.sys 53248 bytes (Microsoft Corporation, Modem Device Driver)
0x8E1F1000 C:\Windows\system32\DRIVERS\umbus.sys 53248 bytes (Microsoft Corporation, User-Mode Bus Enumerator)
0x90351000 C:\Windows\system32\DRIVERS\avgmfx86.sys 49152 bytes (AVG Technologies CZ, s.r.o., AVG Resident Shield Minifilter Driver)
0x8E193000 C:\Windows\System32\Drivers\pcouffin.sys 49152 bytes (VSO Software, low level access layer for CD/DVD/BD devices)
0x9F3E1000 C:\Windows\System32\drivers\tcpipreg.sys 49152 bytes (Microsoft Corporation, TCP/IP Registry Compatibility Driver)
0x90374000 C:\Windows\System32\drivers\vga.sys 49152 bytes (Microsoft Corporation, VGA/Super VGA Video Driver)
0x8DDF3000 C:\Windows\System32\drivers\watchdog.sys 49152 bytes (Microsoft Corporation, Watchdog Driver)
0x9F2EE000 C:\Windows\system32\DRIVERS\AVGIDSShim.Sys 45056 bytes (AVG Technologies CZ, s.r.o. , IDS Application Activity Monitor Loader Driver.)
0x9031E000 C:\Windows\system32\DRIVERS\hidir.sys 45056 bytes (Microsoft Corporation, Infrared Miniport Driver for Input Devices)
0x8E4E2000 C:\Windows\system32\DRIVERS\kbdclass.sys 45056 bytes (Microsoft Corporation, Keyboard Class Driver)
0x8E51F000 C:\Windows\system32\DRIVERS\mouclass.sys 45056 bytes (Microsoft Corporation, Mouse Class Driver)
0x903B1000 C:\Windows\System32\Drivers\Msfs.SYS 45056 bytes (Microsoft Corporation, Mailslot driver)
0x8E12D000 C:\Windows\system32\DRIVERS\ndistapi.sys 45056 bytes (Microsoft Corporation, NDIS 3.0 connection wrapper driver)
0x90990000 C:\Windows\system32\DRIVERS\point32k.sys 45056 bytes (Microsoft Corporation, Point32k.sys)
0x90965000 C:\Windows\System32\Drivers\tcusb.sys 45056 bytes (UPEK Inc., TouchChip USB Kernel Driver)
0x8E5C3000 C:\Windows\system32\DRIVERS\TDI.SYS 45056 bytes (Microsoft Corporation, TDI Wrapper)
0x88978000 C:\Windows\system32\DRIVERS\tunnel.sys 45056 bytes (Microsoft Corporation, Microsoft Tunnel Interface Driver)
0x8E09C000 C:\Windows\system32\DRIVERS\usbuhci.sys 45056 bytes (Microsoft Corporation, UHCI USB Miniport Driver)
0x9F3ED000 C:\Windows\system32\DRIVERS\AVGIDSFilter.Sys 40960 bytes (AVG Technologies CZ, s.r.o. , IDS Application Activity Monitor Filter Driver.)
0x8071A000 C:\Windows\system32\DRIVERS\BATTC.SYS 40960 bytes (Microsoft Corporation, Battery Class Driver)
0x909A8000 C:\Windows\System32\drivers\Dxapi.sys 40960 bytes (Microsoft Corporation, DirectX API Driver)
0x8E1E7000 C:\Windows\system32\DRIVERS\mssmbios.sys 40960 bytes (Microsoft Corporation, System Management BIOS Driver)
0x9E0ED000 C:\Windows\system32\DRIVERS\ndisuio.sys 40960 bytes (Microsoft Corporation, NDIS User mode I/O driver)
0x90908000 C:\Windows\system32\drivers\nsiproxy.sys 40960 bytes (Microsoft Corporation, NSI Proxy)
0x9F3D7000 C:\Windows\System32\Drivers\secdrv.SYS 40960 bytes (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K., Macrovision SECURITY Driver)
0x88B29000 C:\Windows\system32\DRIVERS\AVGIDSEH.Sys 36864 bytes (AVG Technologies CZ, s.r.o. , IDS Application Activity Monitor Helper Driver.)
0x88DE8000 C:\Windows\system32\drivers\crcdisk.sys 36864 bytes (Microsoft Corporation, Disk Block Verification Filter Driver)
0x9035D000 C:\Windows\System32\Drivers\Fs_Rec.SYS 36864 bytes (Microsoft Corporation, File System Recognizer Driver)
0x90987000 C:\Windows\system32\DRIVERS\hidusb.sys 36864 bytes (Microsoft Corporation, USB Miniport Driver for Input Devices)
0x90340000 C:\Windows\system32\DRIVERS\kbdhid.sys 36864 bytes (Microsoft Corporation, HID Keyboard Filter Driver)
0x82EED000 C:\Windows\system32\drivers\msahci.sys 36864 bytes (Microsoft Corporation, MS AHCI 1.0 Standard Driver)
0xA4C43000 C:\Windows\System32\Drivers\Normandy.SYS 36864 bytes (RKU Driver)
0x82F38000 C:\Windows\system32\Drivers\PxHelp20.sys 36864 bytes (Sonic Solutions, Px Engine Device Driver for Windows 2000/XP)
0x903CA000 C:\Windows\System32\DRIVERS\rasacd.sys 36864 bytes (Microsoft Corporation, RAS Automatic Connection Driver)
0x81CA0000 C:\Windows\System32\TSDDD.dll 36864 bytes (Microsoft Corporation, Framebuffer Display Driver)
0x88983000 C:\Windows\system32\DRIVERS\tunmp.sys 36864 bytes (Microsoft Corporation, Microsoft Tunnel Interface Driver)
0x806D0000 C:\Windows\system32\drivers\WMILIB.SYS 36864 bytes (Microsoft Corporation, WMILIB WMI support library Dll)
0x82EC7000 C:\Windows\system32\drivers\atapi.sys 32768 bytes (Microsoft Corporation, ATAPI IDE Miniport Driver)
0x8048A000 C:\Windows\system32\BOOTVID.dll 32768 bytes (Microsoft Corporation, VGA Boot Driver)
0x88DF8000 C:\Windows\system32\DRIVERS\FwLnk.sys 32768 bytes (TOSHIBA Corporation, TOSHIBA Firmware Linkage 32-bit Driver)
0x90349000 C:\Windows\system32\DRIVERS\mouhid.sys 32768 bytes (Microsoft Corporation, HID Mouse Filter Driver)
0x806D9000 C:\Windows\system32\drivers\msisadrv.sys 32768 bytes (Microsoft Corporation, ISA Driver)
0x903A1000 C:\Windows\System32\DRIVERS\RDPCDD.sys 32768 bytes (Microsoft Corporation, RDP Miniport)
0x903A9000 C:\Windows\system32\drivers\rdpencdd.sys 32768 bytes (Microsoft Corporation, RDP Miniport)
0x8E5CE000 C:\Windows\System32\Drivers\RootMdm.sys 32768 bytes (Microsoft Corporation, Legacy Non-Pnp Modem Device Driver)
0x88D99000 C:\Windows\System32\Drivers\spldr.sys 32768 bytes (Microsoft Corporation, loader for security processor)
0x9036D000 C:\Windows\System32\Drivers\Beep.SYS 28672 bytes (Microsoft Corporation, BEEP Driver)
0x90339000 C:\Windows\system32\DRIVERS\HIDPARSE.SYS 28672 bytes (Microsoft Corporation, Hid Parsing Library)
0x8077D000 C:\Windows\system32\drivers\intelide.sys 28672 bytes (Microsoft Corporation, Intel PCI IDE Driver)
0x80402000 C:\Windows\system32\kdcom.dll 28672 bytes (Microsoft Corporation, Kernel Debugger HW Extension DLL)
0x90366000 C:\Windows\System32\Drivers\Null.SYS 28672 bytes (Microsoft Corporation, NULL Driver)
0x8E200000 C:\Windows\system32\DRIVERS\RimSerial.sys 28672 bytes (Research in Motion Ltd, RIM Virtual Serial Driver)
0x8E546000 C:\Windows\System32\Drivers\GEARAspiWDM.sys 24576 bytes (GEAR Software Inc., CD DVD Filter)
0x908B3000 C:\Windows\System32\Drivers\StarOpen.SYS 24576 bytes
0x88DF3000 C:\Windows\system32\DRIVERS\avgrkx86.sys 20480 bytes (AVG Technologies CZ, s.r.o., AVG Anti-Rootkit Driver)
0x903FA000 C:\Windows\system32\drivers\tcpipBM.sys 20480 bytes (Bytemobile, Inc., Bytemobile Kernel Network Provider)
0x88D49000 C:\Windows\system32\DRIVERS\TVALZ_O.SYS 20480 bytes (TOSHIBA Corporation, TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Driver)
0x8E54C000 C:\Windows\system32\DRIVERS\CmBatt.sys 16384 bytes (Microsoft Corporation, Control Method Battery Driver)
0x8E52A000 C:\Windows\system32\DRIVERS\tdcmdpst.sys 16384 bytes (TOSHIBA Corporation., Toshiba ODD Writing Driver For x86.)
0x80717000 C:\Windows\system32\DRIVERS\compbatt.sys 12288 bytes (Microsoft Corporation, Composite Battery Driver)
0x8E550000 C:\Windows\system32\DRIVERS\tosrfec.sys 12288 bytes (TOSHIBA Corporation, TOSHIBA Bluetooth EC Driver)
0x88DF1000 C:\Windows\system32\drivers\BMLoad.sys 8192 bytes (Bytemobile, Inc., Bytemobile Kernel Driver Loader)
0x8E5FA000 C:\Windows\system32\DRIVERS\swenum.sys 8192 bytes (Microsoft Corporation, Plug and Play Software Device Enumerator)
0x8E51D000 C:\Windows\system32\DRIVERS\USBD.SYS 8192 bytes (Microsoft Corporation, Universal Serial Bus Driver)
==============================================
>Stealth
==============================================
0x01040000 Hidden Image–>Interop.FNCClient11Lib.dll [ EPROCESS 0xA17568A0 ] PID: 3932, 102400 bytes
0x00B90000 Hidden Image–>Interop.FNCClient11Lib.dll [ EPROCESS 0xA5100628 ] PID: 708, 102400 bytes
0x06C10000 Hidden Image–>CLI.Aspect.Radeon3D.Graphics.Wizard.DLL [ EPROCESS 0x850E7B88 ] PID: 4892, 102400 bytes
0x00830000 Hidden Image–>MOM.Implementation.DLL [ EPROCESS 0xA50713F0 ] PID: 4256, 110592 bytes
0x00BE0000 Hidden Image–>MOM.Implementation.DLL [ EPROCESS 0x850E7B88 ] PID: 4892, 110592 bytes
0x00FF0000 Hidden Image–>CancelAutoPlay.dll [ EPROCESS 0xA5100628 ] PID: 708, 118784 bytes
0x05E70000 Hidden Image–>CLI.Aspect.DisplaysOptions.Graphics.Dashboard.DLL [ EPROCESS 0x850E7B88 ] PID: 4892, 126976 bytes
0x05D90000 Hidden Image–>CLI.Aspect.Welcome.Graphics.Dashboard.DLL [ EPROCESS 0x850E7B88 ] PID: 4892, 143360 bytes
0x07620000 Hidden Image–>CLI.Aspect.PowerPlayDPPE.Graphics.Dashboard.DLL [ EPROCESS 0x850E7B88 ] PID: 4892, 151552 bytes
0x07DB0000 Hidden Image–>CLI.Component.Dashboard.DLL [ EPROCESS 0x850E7B88 ] PID: 4892, 1519616 bytes
0x00B60000 Hidden Image–>VMC.UI.CommonDialogs.dll [ EPROCESS 0xA5100628 ] PID: 708, 167936 bytes
0x08B40000 Hidden Image–>CLI.Aspect.DisplaysManager.Graphics.Wizard.DLL [ EPROCESS 0x850E7B88 ] PID: 4892, 1683456 bytes
0x01060000 Hidden Image–>VMC.ConnectionServicesInterface.dll [ EPROCESS 0xA17568A0 ] PID: 3932, 176128 bytes
0x00A40000 Hidden Image–>VMC.ConnectionServicesInterface.dll [ EPROCESS 0xA5100628 ] PID: 708, 176128 bytes
0x00FB0000 Hidden Image–>VMC.BaseServices.DataAccessor.dll [ EPROCESS 0xA17568A0 ] PID: 3932, 184320 bytes
0x00810000 Hidden Image–>VMC.BaseServices.DataAccessor.dll [ EPROCESS 0xA5100628 ] PID: 708, 184320 bytes
0x06DC0000 Hidden Image–>CLI.Aspect.InfoCentre.Graphics.Wizard.DLL [ EPROCESS 0x850E7B88 ] PID: 4892, 208896 bytes
0x05DC0000 Hidden Image–>CLI.Aspect.InfoCentre.Graphics.Dashboard.DLL [ EPROCESS 0x850E7B88 ] PID: 4892, 225280 bytes
0x053E0000 Hidden Image–>CLI.Caste.Graphics.Runtime.DLL [ EPROCESS 0x850E7B88 ] PID: 4892, 258048 bytes
0x057D0000 Hidden Image–>VMC.UI.CommonDialogs.resources.dll [ EPROCESS 0xA5100628 ] PID: 708, 28672 bytes
0x01B40000 Hidden Image–>MOM.Foundation.DLL [ EPROCESS 0xA50713F0 ] PID: 4256, 28672 bytes
0x03C70000 Hidden Image–>LOG.Foundation.Implementation.Private.DLL [ EPROCESS 0xA50713F0 ] PID: 4256, 28672 bytes
0x009A0000 Hidden Image–>MOM.Foundation.DLL [ EPROCESS 0x850E7B88 ] PID: 4892, 28672 bytes
0x009C0000 Hidden Image–>LOG.Foundation.Implementation.Private.DLL [ EPROCESS 0x850E7B88 ] PID: 4892, 28672 bytes
0x00CC0000 Hidden Image–>CLI.Component.Runtime.Shared.DLL [ EPROCESS 0x850E7B88 ] PID: 4892, 28672 bytes
0x04B60000 Hidden Image–>DEM.Graphics.DLL [ EPROCESS 0x850E7B88 ] PID: 4892, 28672 bytes
0x01CA0000 Hidden Image–>CLI.Component.Runtime.Extension.EEU.DLL [ EPROCESS 0x850E7B88 ] PID: 4892, 28672 bytes
0x01CC0000 Hidden Image–>AEM.Plugin.EEU.Shared.DLL [ EPROCESS 0x850E7B88 ] PID: 4892, 28672 bytes
0x03FD0000 Hidden Image–>AEM.Server.Shared.DLL [ EPROCESS 0x850E7B88 ] PID: 4892, 28672 bytes
0x04B20000 Hidden Image–>AEM.Plugin.Hotkeys.Shared.DLL [ EPROCESS 0x850E7B88 ] PID: 4892, 28672 bytes
0x04A10000 Hidden Image–>AEM.Plugin.DPPE.Shared.DLL [ EPROCESS 0x850E7B88 ] PID: 4892, 28672 bytes
0x04B50000 Hidden Image–>DEM.Foundation.DLL [ EPROCESS 0x850E7B88 ] PID: 4892, 28672 bytes
0x05490000 Hidden Image–>AEM.Actions.CCAA.Shared.DLL [ EPROCESS 0x850E7B88 ] PID: 4892, 28672 bytes
0x05440000 Hidden Image–>DEM.OS.I0602.DLL [ EPROCESS 0x850E7B88 ] PID: 4892, 28672 bytes
0x05450000 Hidden Image–>DEM.OS.DLL [ EPROCESS 0x850E7B88 ] PID: 4892, 28672 bytes
0x05770000 Hidden Image–>CLI.Caste.Graphics.Runtime.Shared.Private.DLL [ EPROCESS 0x850E7B88 ] PID: 4892, 28672 bytes
0x05530000 Hidden Image–>CLI.Aspect.HotkeysHandling.Graphics.Runtime.DLL [ EPROCESS 0x850E7B88 ] PID: 4892, 28672 bytes
0x05740000 Hidden Image–>CLI.Aspect.HotkeysHandling.Graphics.Shared.DLL [ EPROCESS 0x850E7B88 ] PID: 4892, 28672 bytes
0x057B0000 Hidden Image–>DEM.Graphics.I0706.DLL [ EPROCESS 0x850E7B88 ] PID: 4892, 28672 bytes
0x05BA0000 Hidden Image–>AEM.Plugin.GD.Shared.DLL [ EPROCESS 0x850E7B88 ] PID: 4892, 28672 bytes
0x066A0000 Hidden Image–>APM.Foundation.DLL [ EPROCESS 0x850E7B88 ] PID: 4892, 28672 bytes
0x069B0000 Hidden Image–>CLI.Component.Client.Shared.DLL [ EPROCESS 0x850E7B88 ] PID: 4892, 28672 bytes
0x069C0000 Hidden Image–>CLI.Component.Wizard.Shared.DLL [ EPROCESS 0x850E7B88 ] PID: 4892, 28672 bytes
0x06BE0000 Hidden Image–>CLI.Caste.Graphics.Wizard.Shared.DLL [ EPROCESS 0x850E7B88 ] PID: 4892, 28672 bytes
0x07000000 Hidden Image–>Branding.dll [ EPROCESS 0x850E7B88 ] PID: 4892, 28672 bytes
0x07240000 Hidden Image–>CLI.Component.Dashboard.Shared.DLL [ EPROCESS 0x850E7B88 ] PID: 4892, 28672 bytes
0x07230000 Hidden Image–>atixclib.DLL [ EPROCESS 0x850E7B88 ] PID: 4892, 28672 bytes
0x07250000 Hidden Image–>CLI.Component.Dashboard.Shared.Private.DLL [ EPROCESS 0x850E7B88 ] PID: 4892, 28672 bytes
0x07280000 Hidden Image–>CLI.Caste.Graphics.Dashboard.Shared.DLL [ EPROCESS 0x850E7B88 ] PID: 4892, 28672 bytes
0x00FF0000 Hidden Image–>VMC.BaseServices.XmlSerializers.dll [ EPROCESS 0xA17568A0 ] PID: 3932, 290816 bytes
0x012B0000 Hidden Image–>VMC.BaseServices.XmlSerializers.dll [ EPROCESS 0xA5100628 ] PID: 708, 290816 bytes
0x07660000 Hidden Image–>CLI.Aspect.DeviceLCD.Graphics.Wizard.DLL [ EPROCESS 0x850E7B88 ] PID: 4892, 315392 bytes
0x01090000 Hidden Image–>VMC.BaseServices.Platform.dll [ EPROCESS 0xA17568A0 ] PID: 3932, 323584 bytes
0x009F0000 Hidden Image–>VMC.BaseServices.Platform.dll [ EPROCESS 0xA5100628 ] PID: 708, 323584 bytes
0x060D0000 Hidden Image–>CLI.Aspect.Radeon3D.Graphics.Dashboard.DLL [ EPROCESS 0x850E7B88 ] PID: 4892, 339968 bytes
0x06070000 Hidden Image–>CLI.Aspect.DeviceDFP.Graphics.Dashboard.DLL [ EPROCESS 0x850E7B88 ] PID: 4892, 339968 bytes
0x041A0000 Hidden Image–>VMC.WwanWrapper.dll [ EPROCESS 0xA5100628 ] PID: 708, 356352 bytes
0x00FE0000 Hidden Image–>VMC.BaseServices.OutlookConnector.dll [ EPROCESS 0xA17568A0 ] PID: 3932, 36864 bytes
0x007D0000 Hidden Image–>VMC.ConnectionServices.TrafficOptimiser.dll [ EPROCESS 0xA5100628 ] PID: 708, 36864 bytes
0x00840000 Hidden Image–>VMC.BaseServices.OutlookConnector.dll [ EPROCESS 0xA5100628 ] PID: 708, 36864 bytes
0x04630000 Hidden Image–>NEWAEM.Foundation.DLL [ EPROCESS 0xA50713F0 ] PID: 4256, 36864 bytes
0x00C10000 Hidden Image–>CLI.Foundation.XManifest.DLL [ EPROCESS 0x850E7B88 ] PID: 4892, 36864 bytes
0x01C90000 Hidden Image–>NEWAEM.Foundation.DLL [ EPROCESS 0x850E7B88 ] PID: 4892, 36864 bytes
0x01CB0000 Hidden Image–>AEM.Foundation.DLL [ EPROCESS 0x850E7B88 ] PID: 4892, 36864 bytes
0x051D0000 Hidden Image–>ACE.Graphics.DisplaysManager.Shared.DLL [ EPROCESS 0x850E7B88 ] PID: 4892, 36864 bytes
0x05790000 Hidden Image–>CLI.Aspect.CustomFormats.Graphics.Shared.DLL [ EPROCESS 0x850E7B88 ] PID: 4892, 36864 bytes
0x05BB0000 Hidden Image–>CLI.Aspect.DisplaysColour2.Graphics.Shared.DLL [ EPROCESS 0x850E7B88 ] PID: 4892, 36864 bytes
0x05BD0000 Hidden Image–>CLI.Aspect.DisplaysOptions.Graphics.Shared.DLL [ EPROCESS 0x850E7B88 ] PID: 4892, 36864 bytes
0x05C40000 Hidden Image–>CLI.Aspect.DeviceLCD.Graphics.Shared.DLL [ EPROCESS 0x850E7B88 ] PID: 4892, 36864 bytes
0x06670000 Hidden Image–>CLI.Aspect.PowerPlayDPPE.Graphics.Shared.DLL [ EPROCESS 0x850E7B88 ] PID: 4892, 36864 bytes
0x069A0000 Hidden Image–>CLI.Component.Wizard.Shared.Private.DLL [ EPROCESS 0x850E7B88 ] PID: 4892, 36864 bytes
0x07D50000 Hidden Image–>CLI.Aspect.DeviceTV.Graphics.Wizard.DLL [ EPROCESS 0x850E7B88 ] PID: 4892, 372736 bytes
0x05F10000 Hidden Image–>CLI.Aspect.DeviceLCD.Graphics.Dashboard.DLL [ EPROCESS 0x850E7B88 ] PID: 4892, 413696 bytes
0x07CE0000 Hidden Image–>CLI.Aspect.MMVideo.Graphics.Wizard.DLL [ EPROCESS 0x850E7B88 ] PID: 4892, 413696 bytes
0x00860000 Hidden Image–>VMC.ConnectionServices.dll [ EPROCESS 0xA5100628 ] PID: 708, 421888 bytes
0x05E00000 Hidden Image–>CLI.Aspect.DisplaysManager.Graphics.Dashboard.DLL [ EPROCESS 0x850E7B88 ] PID: 4892, 446464 bytes
0x009E0000 Hidden Image–>VMC.WindowsService.Messaging.dll [ EPROCESS 0xA17568A0 ] PID: 3932, 45056 bytes
0x007E0000 Hidden Image–>VMC.WindowsService.Messaging.dll [ EPROCESS 0xA5100628 ] PID: 708, 45056 bytes
0x01A90000 Hidden Image–>LOG.Foundation.DLL [ EPROCESS 0xA50713F0 ] PID: 4256, 45056 bytes
0x01AB0000 Hidden Image–>LOG.Foundation.Private.DLL [ EPROCESS 0xA50713F0 ] PID: 4256, 45056 bytes
0x00960000 Hidden Image–>CCC.Implementation.DLL [ EPROCESS 0x850E7B88 ] PID: 4892, 45056 bytes
0x00990000 Hidden Image–>LOG.Foundation.DLL [ EPROCESS 0x850E7B88 ] PID: 4892, 45056 bytes
0x00A00000 Hidden Image–>LOG.Foundation.Private.DLL [ EPROCESS 0x850E7B88 ] PID: 4892, 45056 bytes
0x00CD0000 Hidden Image–>ATICCCom.DLL [ EPROCESS 0x850E7B88 ] PID: 4892, 45056 bytes
0x03FE0000 Hidden Image–>AEM.Plugin.Source.Kit.Server.DLL [ EPROCESS 0x850E7B88 ] PID: 4892, 45056 bytes
0x057D0000 Hidden Image–>CLI.Aspect.DeviceProperty.Graphics.Shared.DLL [ EPROCESS 0x850E7B88 ] PID: 4892, 45056 bytes
0x057A0000 Hidden Image–>CLI.Aspect.DeviceProperty.Graphics.Runtime.DLL [ EPROCESS 0x850E7B88 ] PID: 4892, 45056 bytes
0x05BC0000 Hidden Image–>CLI.Aspect.DisplaysOptions.Graphics.Runtime.DLL [ EPROCESS 0x850E7B88 ] PID: 4892, 45056 bytes
0x05C20000 Hidden Image–>CLI.Aspect.DeviceLCD.Graphics.Runtime.DLL [ EPROCESS 0x850E7B88 ] PID: 4892, 45056 bytes
0x06D40000 Hidden Image–>CLI.Component.Systemtray.DLL [ EPROCESS 0x850E7B88 ] PID: 4892, 471040 bytes
0x079C0000 Hidden Image–>CLI.Component.Wizard.DLL [ EPROCESS 0x850E7B88 ] PID: 4892, 479232 bytes
0x05E90000 Hidden Image–>CLI.Aspect.DeviceCRT.Graphics.Dashboard.DLL [ EPROCESS 0x850E7B88 ] PID: 4892, 487424 bytes
0x07B60000 Hidden Image–>CLI.Aspect.TransCode.Graphics.Wizard.DLL [ EPROCESS 0x850E7B88 ] PID: 4892, 495616 bytes
0x06280000 Hidden Image–>msvcm80.dll [ EPROCESS 0xA5100628 ] PID: 708, 507904 bytes
0x04620000 Hidden Image–>AEM.Server.DLL [ EPROCESS 0xA50713F0 ] PID: 4256, 53248 bytes
0x00CB0000 Hidden Image–>CLI.Foundation.Private.DLL [ EPROCESS 0x850E7B88 ] PID: 4892, 53248 bytes
0x00CA0000 Hidden Image–>CLI.Component.Runtime.Shared.Private.DLL [ EPROCESS 0x850E7B88 ] PID: 4892, 53248 bytes
0x00CE0000 Hidden Image–>AEM.Server.DLL [ EPROCESS 0x850E7B88 ] PID: 4892, 53248 bytes
0x04B30000 Hidden Image–>DEM.Graphics.I0601.DLL [ EPROCESS 0x850E7B88 ] PID: 4892, 53248 bytes
0x05780000 Hidden Image–>CLI.Aspect.DeviceCV.Graphics.Shared.DLL [ EPROCESS 0x850E7B88 ] PID: 4892, 53248 bytes
0x05B90000 Hidden Image–>CLI.Aspect.DisplaysColour2.Graphics.Runtime.DLL [ EPROCESS 0x850E7B88 ] PID: 4892, 53248 bytes
0x05BE0000 Hidden Image–>CLI.Aspect.DeviceCRT.Graphics.Runtime.DLL [ EPROCESS 0x850E7B88 ] PID: 4892, 53248 bytes
0x06620000 Hidden Image–>CLI.Aspect.MMVideo.Graphics.Shared.DLL [ EPROCESS 0x850E7B88 ] PID: 4892, 53248 bytes
0x06580000 Hidden Image–>CLI.Aspect.DeviceDFP.Graphics.Shared.DLL [ EPROCESS 0x850E7B88 ] PID: 4892, 53248 bytes
0x06660000 Hidden Image–>CLI.Aspect.PowerPlayDPPE.Graphics.Runtime.DLL [ EPROCESS 0x850E7B88 ] PID: 4892, 53248 bytes
0x06690000 Hidden Image–>APM.Server.DLL [ EPROCESS 0x850E7B88 ] PID: 4892, 53248 bytes
0x06980000 Hidden Image–>CLI.Component.Client.Shared.Private.DLL [ EPROCESS 0x850E7B88 ] PID: 4892, 53248 bytes
0x06BD0000 Hidden Image–>CLI.Caste.Graphics.Wizard.DLL [ EPROCESS 0x850E7B88 ] PID: 4892, 53248 bytes
0x07220000 Hidden Image–>CLI.Aspect.TransCode.Graphics.Shared.DLL [ EPROCESS 0x850E7B88 ] PID: 4892, 53248 bytes
0x07290000 Hidden Image–>CLI.Aspect.DisplaysColour2.Graphics.Dashboard.DLL [ EPROCESS 0x850E7B88 ] PID: 4892, 602112 bytes
0x00A70000 Hidden Image–>VMC.CsUtil.dll [ EPROCESS 0xA5100628 ] PID: 708, 61440 bytes
0x01010000 Hidden Image–>Interop.Shell32.dll [ EPROCESS 0xA5100628 ] PID: 708, 61440 bytes
0x009B0000 Hidden Image–>CLI.Foundation.DLL [ EPROCESS 0x850E7B88 ] PID: 4892, 61440 bytes
0x05C00000 Hidden Image–>CLI.Aspect.DeviceCRT.Graphics.Shared.DLL [ EPROCESS 0x850E7B88 ] PID: 4892, 61440 bytes
0x06590000 Hidden Image–>CLI.Aspect.Radeon3D.Graphics.Shared.DLL [ EPROCESS 0x850E7B88 ] PID: 4892, 61440 bytes
0x01AC0000 Hidden Image–>LOG.Foundation.Implementation.DLL [ EPROCESS 0xA50713F0 ] PID: 4256, 69632 bytes
0x009D0000 Hidden Image–>LOG.Foundation.Implementation.DLL [ EPROCESS 0x850E7B88 ] PID: 4892, 69632 bytes
0x05420000 Hidden Image–>CLI.Caste.Graphics.Shared.DLL [ EPROCESS 0x850E7B88 ] PID: 4892, 69632 bytes
0x06560000 Hidden Image–>CLI.Aspect.DeviceDFP.Graphics.Runtime.DLL [ EPROCESS 0x850E7B88 ] PID: 4892, 69632 bytes
0x065B0000 Hidden Image–>CLI.Aspect.Radeon3D.Graphics.Runtime.DLL [ EPROCESS 0x850E7B88 ] PID: 4892, 69632 bytes
0x05470000 Hidden Image–>ATIDEMOS.DLL [ EPROCESS 0x850E7B88 ] PID: 4892, 77824 bytes
0x05750000 Hidden Image–>CLI.Aspect.DeviceCV.Graphics.Runtime.DLL [ EPROCESS 0x850E7B88 ] PID: 4892, 77824 bytes
0x05950000 Hidden Image–>CLI.Aspect.DeviceTV.Graphics.Shared.DLL [ EPROCESS 0x850E7B88 ] PID: 4892, 77824 bytes
0x06600000 Hidden Image–>CLI.Aspect.MMVideo.Graphics.Runtime.DLL [ EPROCESS 0x850E7B88 ] PID: 4892, 77824 bytes
0x07550000 Hidden Image–>CLI.Aspect.MMVideo.Graphics.Dashboard.DLL [ EPROCESS 0x850E7B88 ] PID: 4892, 806912 bytes
0x009C0000 Hidden Image–>VMC.WindowsService.Core.dll [ EPROCESS 0xA17568A0 ] PID: 3932, 86016 bytes
0x007F0000 Hidden Image–>VMC.WindowsService.Core.dll [ EPROCESS 0xA5100628 ] PID: 708, 86016 bytes
0x057F0000 Hidden Image–>MobileConnect.resources.dll [ EPROCESS 0xA5100628 ] PID: 708, 86016 bytes
0x00C80000 Hidden Image–>CLI.Component.Runtime.DLL [ EPROCESS 0x850E7B88 ] PID: 4892, 86016 bytes
0x05930000 Hidden Image–>CLI.Aspect.DeviceTV.Graphics.Runtime.DLL [ EPROCESS 0x850E7B88 ] PID: 4892, 86016 bytes
0x07260000 Hidden Image–>CLI.Caste.Graphics.Dashboard.DLL [ EPROCESS 0x850E7B88 ] PID: 4892, 86016 bytes
0x05F80000 Hidden Image–>CLI.Aspect.DeviceTV.Graphics.Dashboard.DLL [ EPROCESS 0x850E7B88 ] PID: 4892, 913408 bytes
0x03ED0000 Hidden Image–>TCrdMain.resources.dll [ EPROCESS 0x949FE878 ] PID: 2256, 978944 bytes
I see you have Malwarebytes already on your machine. Please run it by double clicking the icon on the desktop.
  • Click on the tab labeled Update and then click on the button Check for updates.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.


http://www.eset.eu/online-scanner
Go here to run an online scannner from ESET.
Click the green ESET Online Scanner button.
Read the End User License Agreement and check the box: YES, I accept the Terms of Use.
Click on the Start button next to it.
You may receive an alert on the address bar that "This site might require the following ActiveX control…Click here to install…". Click on that alert and then click Insall ActiveX component.
A new window will appear asking "Do you want to install this software?"".
Answer Yes to download and install the ActiveX controls that allows the scan to run.
Click Start.
Check Remove found threats and Scan potentially unwanted applications.
Click Scan to begin.
If offered the option to get information or buy software. Just close the window.
Wait for the scan to finish
Use notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
Copy and paste that log as a reply to this topic.
I have had it on my machine for a while just as an addition to AVG…I run it from time to time. I did run it twice before initially posting my thread on WTT.


Here are the results from the scan on 01/02/11 (today):

Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Database version: 5651

Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.18999

1/02/2011 11:11:07 AM
mbam-log-2011-02-01 (11-11-07).txt

Scan type: Quick scan
Objects scanned: 155158
Time elapsed: 4 minute(s), 44 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


Here are the results from the scan I did on 27/01/11:

Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Database version: 5594

Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.18999

27/01/2011 8:49:15 PM
mbam-log-2011-01-27 (20-49-15).txt

Scan type: Quick scan
Objects scanned: 49735
Time elapsed: 3 minute(s), 18 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)



Here are the results from the scan I did on 25/01/11:

Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Database version: 5594

Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.18999

25/01/2011 10:08:36 PM
mbam-log-2011-01-25 (22-08-36).txt

Scan type: Full scan (C:\|D:\|)
Objects scanned: 327841
Time elapsed: 1 hour(s), 30 minute(s), 55 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


With the ESET Online Scanner did you want me to disable my AVG Resident Shield like I did for the DSS? I disabled it when I ran the ESET Scan just in case it interferred with the results.

ESET Results:


C:\Users\Dim\AppData\Roaming\AVG\Rescue\PC Tuneup 2011\101213213826698.rsc a variant of Java/Rowindal.C trojan deleted - quarantined
C:\Users\Dim\AppData\Roaming\AVG\Rescue\PC Tuneup 2011\101226151212493.rsc multiple threats deleted - quarantined



Is that all of the log?
Yes, that is the whole ESET log, and it was good to disable AVG when you ran it :) . It appears there were some threats that were contained in the PC Tuneup Rescue files.

OTL

Download OTL to your Desktop
Run OTL.exe by right clicking it and choosing Run as Administrator
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :Files
    C:\Users\Dim\AppData\Roaming\AVG\Rescue\PC Tuneup 2011\101213213826698.rsc	
    C:\Users\Dim\AppData\Roaming\AVG\Rescue\PC Tuneup 2011\101226151212493.rsc	
    
    :Commands
    [resethosts]
    [purity]
    [emptytemp]
    [emptyflash]
    [createrestorepoint]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Please post the resulting log file




Then, copy and paste these lines in Note pad.

@Echo on
pushd\windows\system32\drivers\etc
attrib -h -s -r hosts
echo 127.0.0.1 localhost>HOSTS
attrib +r +h +s hosts
popd
ipconfig /release
ipconfig /renew
ipconfig /flushdns
netsh winsock reset all
netsh int ip reset all
shutdown -r -t 1
del %0


Save as flush.bat to your desktop. Right click and choose to "run as Administrator" .. the computer will reboot itself.



I would also like to have you reset your router. Most routers have a reset pin hole on the back.

1. With the unit on, place an straightend paperclip into the hole on the back on the unit labeled Reset.
2. Hold the paperclip/reset down for 10 seconds and then release it.
3. The unit will reboot on its own.
4. As soon as the lights stop blinking, the unit is ready.
5. You will need to reinstall the router to regain your internet access.

Note: If you changed your password, it will be gone so refer to your user's guide for your router..
If you had not changed your password from the default, I would strongly recommend you do so now.


Can you please spend some time browsing after you have completed these steps, and let me know how the computer is behaving now. There are still a few things we need to do, but hopefully you will see an improvement after these steps.
Cheers…I will follow up what you have told me to do. May I ask the reasoning behind resetting the router? We have a network at home with another few PC's/laptops on it….hopefully the virus isn't on the network is it? The browsing of my internet seems to be fine. I have noticed however that when I save a website to favourites the little icon that displays is sometimes not what it should be…like it had a cat picture on it instead of say the facebook "f' symbol….this wasn't the favourite affected but just to give you an indication. But overall my web browsing is fine :S
You had indicated in your first post that you were having lots of pop-ups in internet explorer for fake virus scans. I did not see anything in the logs that would have been the cause of this, so I was moving forward with the steps to address DNS and reset the router - as routers can become infected. If you are no longer having the initial problem, then I need to know what symptoms you are still experiencing at this time. I do still need you to do the OTL step as that is for confirmation the infected files found by ESET have been fully removed. If you have not done the DNS flush or reset the router, you can hold up on those until you let me know what you are still having issues with. Often times, the Favicons for a website will not necessarily appear correctly when you favorite/save the site in your browser.. Clearing internet caches will often fix this and they will rebuild as you visit the sites. I have this problem sometimes with some of the sites I have saved, but it isn't necessarily related to any kind of malware.
I ran OTL and below is the log. I did the reconfig notepad task also. Interestingly, on reboot I recognised that the log file I saved on my desktop automatically moved to my C drive inside an OTL named folder. Is this the norm?

Also, before I reset my router I would like to ask what you mean by "re-installing the router" and whether this is a complex. I have not done this before. I don't want to do it and then not be able to connect back to the net :)


OTL:

All processes killed
========== SERVICES/DRIVERS ==========
========== FILES ==========
File\Folder C:\Users\Dim\AppData\Roaming\AVG\Rescue\PC Tuneup 2011\101213213826698.rsc not found.
File\Folder C:\Users\Dim\AppData\Roaming\AVG\Rescue\PC Tuneup 2011\101226151212493.rsc not found.
========== COMMANDS ==========
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes

User: Dim
->Temp folder emptied: 376200692 bytes
->Java cache emptied: 0 bytes
->Apple Safari cache emptied: 14336 bytes
->Flash cache emptied: 3358 bytes

User: Public

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 222332 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 19833544 bytes

Total Files Cleaned = 378.00 mb


[EMPTYFLASH]

User: All Users

User: Default

User: Default User

User: Dim
->Flash cache emptied: 0 bytes

User: Public

Total Flash Files Cleaned = 0.00 mb



OTL by OldTimer - Version 3.2.20.6 log created on 02012011_225947

Files\Folders moved on Reboot…

Registry entries deleted on Reboot…

You had indicated in your first post that you were having lots of pop-ups in internet explorer for fake virus scans. I did not see anything in the logs that would have been the cause of this, so I was moving forward with the steps to address DNS and reset the router - as routers can become infected. If you are no longer having the initial problem, then I need to know what symptoms you are still experiencing at this time.

I do still need you to do the OTL step as that is for confirmation the infected files found by ESET have been fully removed. If you have not done the DNS flush or reset the router, you can hold up on those until you let me know what you are still having issues with.

Often times, the Favicons for a website will not necessarily appear correctly when you favorite/save the site in your browser.. Clearing internet caches will often fix this and they will rebuild as you visit the sites. I have this problem sometimes with some of the sites I have saved, but it isn't necessarily related to any kind of malware.


As far as internet explorer pop ups go I have not experienced any problems of late. I do have the pop up blocker on but it does not appear to be blocking any content at the moment so I think I am fine. The fake virus scans have also seemed to have disappeared :) None of the other computers using the same router has experienced any problems so I do not think it is a router issue…I'm not an expert so I wouldn't know any better so I shall listen to your advice if you want me to reset it :)

haha, cheers for clearing that up. "Favicons"….I have learnt some new terminology :P
If you are not experiencing any more issues with the pop-ups or fake virus scans then it is not necessary to reset the router.


Now to remove most of the tools that we have used in fixing your machine:
  • Run OTL.exe
  • This time, click on the CleanUp button.

If you notice any remaining tools or files you can delete them by right clicking and choosing delete.



Update Adobe Reader
There have been updates to Adobe Reader to address security vulnerabilities. You should download the latest version from the Adobe website. You appear to have an old version on your machine and I would suggest updating.


Please let me know when you have completed these steps. There are no logs to post.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI