This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Infected please help!

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

HIJACKTHIS
——————
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:30:13, on 24/02/2011
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18999)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\AVG\AVG8\avgtray.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\Program Files\SigmaTel\C-Major Audio\WDM\sttray.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Windows\ehome\ehtray.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10c.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\hijackthis\Trend Micro\HiJackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
R3 - URLSearchHook: uTorrentBar Toolbar - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files\uTorrentBar\tbuTor.dll
O1 - Hosts: ::1 localhost
O2 - BHO: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll
O2 - BHO: uTorrentBar Toolbar - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files\uTorrentBar\tbuTor.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: uTorrentBar Toolbar - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files\uTorrentBar\tbuTor.dll
O3 - Toolbar: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes\mbam.exe" /runcleanupscript
O4 - HKLM\..\Run: [SigmatelSysTrayApp] C:\Program Files\SigmaTel\C-Major Audio\WDM\sttray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [{3391CDA6-5746-3CF7-1687-8775C3B5ECB8}] C:\Users\User\AppData\Roaming\Oxmyto\olewi.exe
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} (get_atlcom Class) - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: AVG Security Toolbar Service - Unknown owner - C:\Program Files\AVG\AVG8\Toolbar\ToolbarBroker.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Roxio\Roxio MyDVD Premier\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Windows\system32\STacSV.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe

–
End of file - 7699 bytes






OTL
——

OTL logfile created on: 24/02/2011 21:31:24 - Run 2
OTL by OldTimer - Version 3.2.21.0 Folder = C:\Users\User\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18999)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 53.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 78.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 596.18 Gb Total Space | 397.10 Gb Free Space | 66.61% Space Free | Partition Type: NTFS
Drive D: | 2.84 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: DESKTOP1 | User Name: User | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/02/24 21:10:35 | 000,577,024 | —- | M] (OldTimer Tools) – C:\Users\User\Desktop\OTL.exe
PRC - [2010/07/08 17:09:34 | 002,048,352 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgtray.exe
PRC - [2010/04/16 07:33:40 | 000,144,672 | —- | M] (Apple Inc.) – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
PRC - [2009/08/31 21:44:46 | 000,693,016 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgcsrvx.exe
PRC - [2009/08/31 21:44:46 | 000,486,680 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgrsx.exe
PRC - [2009/08/31 21:44:39 | 000,595,736 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgnsx.exe
PRC - [2009/08/31 21:44:38 | 000,297,752 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgwdsvc.exe
PRC - [2009/08/31 21:44:37 | 000,908,056 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgemc.exe
PRC - [2009/07/27 02:37:50 | 000,180,224 | —- | M] (PowerISO Computing, Inc.) – C:\Program Files\PowerISO\PWRISOVM.EXE
PRC - [2009/07/18 03:12:12 | 000,257,440 | R— | M] (Adobe Systems, Inc.) – C:\Windows\System32\Macromed\Flash\FlashUtil10c.exe
PRC - [2009/04/10 22:27:38 | 002,926,592 | —- | M] (Microsoft Corporation) – C:\Windows\explorer.exe
PRC - [2009/03/05 15:07:20 | 002,260,480 | RHS- | M] (Safer-Networking Ltd.) – C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
PRC - [2009/01/26 14:31:10 | 001,153,368 | —- | M] (Safer Networking Ltd.) – C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
PRC - [2008/01/18 22:38:40 | 001,008,184 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Defender\MSASCui.exe
PRC - [2007/05/06 16:11:36 | 000,094,208 | —- | M] (SigmaTel, Inc.) – C:\Windows\System32\stacsv.exe
PRC - [2007/05/06 16:10:44 | 000,405,504 | —- | M] (SigmaTel, Inc.) – C:\Program Files\SigmaTel\C-Major Audio\WDM\sttray.exe
PRC - [2006/09/11 03:40:32 | 000,218,032 | —- | M] (Macrovision Corporation) – C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe


========== Modules (SafeList) ==========

MOD - [2011/02/24 21:10:35 | 000,577,024 | —- | M] (OldTimer Tools) – C:\Users\User\Desktop\OTL.exe
MOD - [2010/08/31 15:43:52 | 001,686,016 | —- | M] (Microsoft Corporation) – C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll
MOD - [2009/08/31 21:44:46 | 000,011,952 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\avgrsstx.dll


========== Win32 Services (SafeList) ==========

SRV - [2011/02/24 20:50:21 | 000,407,336 | —- | M] (Valve Corporation) [On_Demand | Stopped] – C:\Program Files\Common Files\Steam\SteamService.exe – (Steam Client Service)
SRV - [2010/10/06 10:31:48 | 000,517,448 | —- | M] () [On_Demand | Stopped] – C:\Program Files\AVG\AVG8\Toolbar\ToolbarBroker.exe – (AVG Security Toolbar Service)
SRV - [2010/04/16 07:33:40 | 000,144,672 | —- | M] (Apple Inc.) [Auto | Running] – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe – (Apple Mobile Device)
SRV - [2009/08/31 21:44:38 | 000,297,752 | —- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] – C:\Program Files\AVG\AVG8\avgwdsvc.exe – (avg8wd)
SRV - [2009/08/31 21:44:37 | 000,908,056 | —- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] – C:\Program Files\AVG\AVG8\avgemc.exe – (avg8emc)
SRV - [2009/08/07 11:43:04 | 000,045,816 | —- | M] (NOS Microsystems Ltd.) [On_Demand | Stopped] – C:\Program Files\NOS\bin\getPlus_Helper.dll – (getPlusHelper) getPlus®
SRV - [2009/01/26 14:31:10 | 001,153,368 | —- | M] (Safer Networking Ltd.) [Auto | Running] – C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe – (SBSDWSCService)
SRV - [2008/01/18 22:38:26 | 000,272,952 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV - [2007/05/06 16:11:36 | 000,094,208 | —- | M] (SigmaTel, Inc.) [Auto | Running] – C:\Windows\System32\stacsv.exe – (STacSV)
SRV - [2004/10/22 02:24:18 | 000,073,728 | —- | M] (Macrovision Corporation) [On_Demand | Stopped] – C:\Program Files\Roxio\Roxio MyDVD Premier\InstallShield\Driver\1050\Intel 32\IDriverT.exe – (IDriverT)


========== Driver Services (SafeList) ==========

DRV - [2009/10/04 16:39:07 | 000,721,904 | —- | M] () [Kernel | Boot | Running] – C:\Windows\System32\Drivers\sptd.sys – (sptd)
DRV - [2009/08/31 21:44:46 | 000,335,240 | —- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] – C:\Windows\System32\Drivers\avgldx86.sys – (AvgLdx86)
DRV - [2009/08/31 21:44:46 | 000,027,784 | —- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] – C:\Windows\System32\Drivers\avgmfx86.sys – (AvgMfx86)
DRV - [2009/08/31 21:44:39 | 000,108,552 | —- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] – C:\Windows\System32\Drivers\avgtdix.sys – (AvgTdiX)
DRV - [2009/07/27 02:43:18 | 000,058,908 | —- | M] (PowerISO Computing, Inc.) [Kernel | System | Running] – C:\Windows\System32\drivers\scdemu.sys – (SCDEmu)
DRV - [2009/04/10 20:42:54 | 000,031,616 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\winusb.sys – (WinUsb)
DRV - [2008/08/22 23:35:00 | 007,475,488 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\nvlddmkm.sys – (nvlddmkm)
DRV - [2008/01/18 22:42:52 | 000,235,064 | —- | M] (Intel Corporation) [Kernel | Boot | Running] – C:\Windows\system32\drivers\iastorv.sys – (iaStorV)
DRV - [2008/01/18 14:16:28 | 000,100,648 | —- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\a016obex.sys – (a016obex)
DRV - [2008/01/18 14:16:26 | 000,110,504 | —- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\a016mdm.sys – (a016mdm)
DRV - [2008/01/18 14:16:26 | 000,104,488 | —- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\a016mgmt.sys – (a016mgmt) Sony Ericsson Device A016 USB WMC Device Management Drivers (WDM)
DRV - [2008/01/18 14:16:24 | 000,015,016 | —- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\a016mdfl.sys – (a016mdfl)
DRV - [2008/01/18 14:16:22 | 000,083,880 | —- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\a016bus.sys – (a016bus) Sony Ericsson Device A016 driver (WDM)
DRV - [2007/05/06 16:12:02 | 000,326,656 | —- | M] (SigmaTel, Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\stwrt.sys – (STHDA)
DRV - [2007/04/13 12:22:56 | 000,228,224 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\e1e6032.sys – (e1express) Intel®
DRV - [2006/11/02 09:51:45 | 000,900,712 | —- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\ql2300.sys – (ql2300)
DRV - [2006/11/02 09:51:38 | 000,420,968 | —- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\adp94xx.sys – (adp94xx)
DRV - [2006/11/02 09:51:34 | 000,316,520 | —- | M] (Emulex) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\elxstor.sys – (elxstor)
DRV - [2006/11/02 09:51:32 | 000,297,576 | —- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\adpahci.sys – (adpahci)
DRV - [2006/11/02 09:51:25 | 000,235,112 | —- | M] (ULi Electronics Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\uliahci.sys – (uliahci)
DRV - [2006/11/02 09:51:00 | 000,147,048 | —- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\adpu320.sys – (adpu320)
DRV - [2006/11/02 09:50:45 | 000,115,816 | —- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\ulsata2.sys – (ulsata2)
DRV - [2006/11/02 09:50:41 | 000,112,232 | —- | M] (VIA Technologies Inc.,Ltd) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\vsmraid.sys – (vsmraid)
DRV - [2006/11/02 09:50:35 | 000,106,088 | —- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\ql40xx.sys – (ql40xx)
DRV - [2006/11/02 09:50:35 | 000,098,408 | —- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\ulsata.sys – (UlSata)
DRV - [2006/11/02 09:50:35 | 000,098,408 | —- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\adpu160m.sys – (adpu160m)
DRV - [2006/11/02 09:50:24 | 000,088,680 | —- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\nvraid.sys – (nvraid)
DRV - [2006/11/02 09:50:19 | 000,045,160 | —- | M] (IBM Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\nfrd960.sys – (nfrd960)
DRV - [2006/11/02 09:50:17 | 000,041,576 | —- | M] (Intel Corp./ICP vortex GmbH) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\iirsp.sys – (iirsp)
DRV - [2006/11/02 09:50:16 | 000,071,784 | —- | M] (Silicon Integrated Systems) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\sisraid4.sys – (SiSRaid4)
DRV - [2006/11/02 09:50:13 | 000,040,040 | —- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\nvstor.sys – (nvstor)
DRV - [2006/11/02 09:50:11 | 000,071,272 | —- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\djsvs.sys – (aic78xx)
DRV - [2006/11/02 09:50:10 | 000,067,688 | —- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\arcsas.sys – (arcsas)
DRV - [2006/11/02 09:50:10 | 000,065,640 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\lsi_scsi.sys – (LSI_SCSI)
DRV - [2006/11/02 09:50:10 | 000,038,504 | —- | M] (Silicon Integrated Systems Corp.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\sisraid2.sys – (SiSRaid2)
DRV - [2006/11/02 09:50:10 | 000,037,480 | —- | M] (Hewlett-Packard Company) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\hpcisss.sys – (HpCISSs)
DRV - [2006/11/02 09:50:09 | 000,067,688 | —- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\arc.sys – (arc)
DRV - [2006/11/02 09:50:09 | 000,035,944 | —- | M] (Integrated Technology Express, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\iteraid.sys – (iteraid)
DRV - [2006/11/02 09:50:07 | 000,035,944 | —- | M] (Integrated Technology Express, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\iteatapi.sys – (iteatapi)
DRV - [2006/11/02 09:50:05 | 000,065,640 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\lsi_sas.sys – (LSI_SAS)
DRV - [2006/11/02 09:50:05 | 000,035,944 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\symc8xx.sys – (Symc8xx)
DRV - [2006/11/02 09:50:04 | 000,065,640 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\lsi_fc.sys – (LSI_FC)
DRV - [2006/11/02 09:50:03 | 000,034,920 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\sym_u3.sys – (Sym_u3)
DRV - [2006/11/02 09:49:59 | 000,033,384 | —- | M] (LSI Logic Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\mraid35x.sys – (Mraid35x)
DRV - [2006/11/02 09:49:56 | 000,031,848 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\sym_hi.sys – (Sym_hi)
DRV - [2006/11/02 09:49:53 | 000,028,776 | —- | M] (LSI Logic Corporation) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\megasas.sys – (megasas)
DRV - [2006/11/02 09:49:30 | 000,017,512 | —- | M] (VIA Technologies, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\viaide.sys – (viaide)
DRV - [2006/11/02 09:49:28 | 000,016,488 | —- | M] (CMD Technology, Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\cmdide.sys – (cmdide)
DRV - [2006/11/02 09:49:20 | 000,014,952 | —- | M] (Acer Laboratories Inc.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\aliide.sys – (aliide)
DRV - [2006/11/02 08:25:24 | 000,071,808 | —- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\brserid.sys – (Brserid) Brother MFC Serial Port Interface Driver (WDM)
DRV - [2006/11/02 08:24:47 | 000,011,904 | —- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] – C:\Windows\system32\drivers\brusbser.sys – (BrUsbSer)
DRV - [2006/11/02 08:24:46 | 000,005,248 | —- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] – C:\Windows\system32\drivers\brfiltup.sys – (BrFiltUp)
DRV - [2006/11/02 08:24:45 | 000,013,568 | —- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] – C:\Windows\system32\drivers\brfiltlo.sys – (BrFiltLo)
DRV - [2006/11/02 08:24:44 | 000,062,336 | —- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\brserwdm.sys – (BrSerWdm)
DRV - [2006/11/02 08:24:44 | 000,012,160 | —- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\brusbmdm.sys – (BrUsbMdm)
DRV - [2006/11/02 07:36:50 | 000,020,608 | —- | M] (N-trig Innovative Technologies) [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\ntrigdigi.sys – (ntrigdigi)
DRV - [2006/11/02 07:30:54 | 000,117,760 | —- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\E1G60I32.sys – (E1G60) Intel®
DRV - [2003/11/28 17:34:40 | 000,011,264 | —- | M] (Pinnacle Systems GmbH) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\asapiW2k.sys – (ASAPIW2K)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\URLSearchHook: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files\uTorrentBar\tbuTor.dll (Conduit Ltd.)

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://uk.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-gb
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = B8 61 0B F7 94 2D CA 01 [binary data]
IE - HKCU\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll ()
IE - HKCU\..\URLSearchHook: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files\uTorrentBar\tbuTor.dll (Conduit Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



O1 HOSTS File: ([2009/08/31 21:44:40 | 000,325,948 | R— | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 11155 more lines…
O2 - BHO: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll (Conduit Ltd.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (AVG Security Toolbar BHO) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll ()
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll (Google Inc.)
O2 - BHO: (uTorrentBar Toolbar) - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files\uTorrentBar\tbuTor.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (uTorrentBar Toolbar) - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files\uTorrentBar\tbuTor.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (uTorrentBar Toolbar) - {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - C:\Program Files\uTorrentBar\tbuTor.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll ()
O4 - HKLM..\Run: [AVG8_TRAY] C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE (PowerISO Computing, Inc.)
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\Program Files\SigmaTel\C-Major Audio\WDM\sttray.exe (SigmaTel, Inc.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [{3391CDA6-5746-3CF7-1687-8775C3B5ECB8}] File not found
O4 - HKCU..\Run: [ISUSPM] C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe (Macrovision Corporation)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\Run: [Steam] C:\Program Files\Steam\Steam.exe (Valve Corporation)
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll (Google Inc.)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (get_atlcom Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 [removed] [removed]
O18 - Protocol\Handler\avgsecuritytoolbar {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll ()
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - AppInit_DLLs: (avgrsstx.dll) - C:\Windows\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img22.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img22.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 21:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [2006/11/02 20:00:00 | 000,000,043 | R— | M] () - D:\AUTORUN.INF – [ CDFS ]
O33 - MountPoints2\I\Shell - "" = AutoRun
O33 - MountPoints2\I\Shell\AutoRun\command - "" = I:\AutoRunMorrowind.exe
O33 - MountPoints2\I\Shell\install\command - "" = I:\Setup.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/02/25 04:58:15 | 000,000,000 | —D | C] – C:\Boot
[2011/02/25 04:57:14 | 000,000,000 | —D | C] – C:\$WINDOWS.~BT
[2011/02/24 21:28:42 | 000,000,000 | —D | C] – C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HiJackThis
[2011/02/24 21:28:42 | 000,000,000 | —D | C] – C:\Program Files\hijackthis
[2011/02/24 21:10:30 | 000,577,024 | —- | C] (OldTimer Tools) – C:\Users\User\Desktop\OTL.exe

========== Files - Modified Within 30 Days ==========

[2011/02/25 04:57:24 | 268,435,456 | -HS- | M] () – C:\WinPEpge.sys
[2011/02/24 21:29:45 | 000,002,651 | —- | M] () – C:\Users\User\Desktop\HiJackThis.lnk
[2011/02/24 21:22:57 | 001,402,880 | —- | M] () – C:\Users\User\Desktop\HiJackThis.msi
[2011/02/24 21:13:00 | 000,000,884 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/02/24 21:11:01 | 000,359,929 | —- | M] () – C:\Users\User\Desktop\dds.scr
[2011/02/24 21:10:35 | 000,577,024 | —- | M] (OldTimer Tools) – C:\Users\User\Desktop\OTL.exe
[2011/02/24 21:05:55 | 000,599,942 | —- | M] () – C:\Windows\System32\perfh009.dat
[2011/02/24 21:05:55 | 000,105,448 | —- | M] () – C:\Windows\System32\perfc009.dat
[2011/02/24 21:00:00 | 000,004,848 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/02/24 21:00:00 | 000,004,848 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/02/24 21:00:00 | 000,000,880 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/02/24 20:59:57 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/02/24 20:59:33 | 3219,046,400 | -HS- | M] () – C:\hiberfil.sys
[2011/02/24 20:47:32 | 071,644,520 | —- | M] () – C:\Windows\System32\drivers\Avg\incavi.avm
[2011/02/20 02:47:41 | 035,582,620 | —- | M] () – C:\Users\User\Desktop\High.wav
[2011/02/12 09:04:03 | 000,986,016 | —- | M] () – C:\Users\User\Desktop\experimental_hangover_dude3.wav

========== Files Created - No Company Name ==========

[2011/02/25 04:57:18 | 268,435,456 | -HS- | C] () – C:\WinPEpge.sys
[2011/02/24 21:28:42 | 000,002,651 | —- | C] () – C:\Users\User\Desktop\HiJackThis.lnk
[2011/02/24 21:22:51 | 001,402,880 | —- | C] () – C:\Users\User\Desktop\HiJackThis.msi
[2011/02/24 21:10:56 | 000,359,929 | —- | C] () – C:\Users\User\Desktop\dds.scr
[2011/02/20 02:47:39 | 035,582,620 | —- | C] () – C:\Users\User\Desktop\High.wav
[2011/02/12 09:04:01 | 000,986,016 | —- | C] () – C:\Users\User\Desktop\experimental_hangover_dude3.wav
[2009/10/04 16:39:07 | 000,721,904 | —- | C] () – C:\Windows\System32\drivers\sptd.sys
[2009/09/28 21:33:10 | 000,000,025 | —- | C] () – C:\Windows\cdplayer.ini
[2009/09/12 21:11:26 | 000,000,680 | —- | C] () – C:\Users\User\AppData\Local\d3d9caps.dat
[2009/09/06 22:18:25 | 000,072,192 | —- | C] () – C:\Users\User\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/09/01 09:15:39 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2006/11/02 12:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 07:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini

< End of report >




DDS
——–



DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 21:33:22.80 on 24/02/2011
Internet Explorer: 8.0.6001.18999
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.44.1033.18.3069.1650 [GMT 0:00]

AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: AVG Anti-Virus Free *enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: Spybot - Search and Destroy *enabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\rundll32.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\STacSV.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\AVG\AVG8\avgtray.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\Program Files\SigmaTel\C-Major Audio\WDM\sttray.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Windows\system32\WUDFHost.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Windows\ehome\ehtray.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10c.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\System32\svchost.exe -k swprv
C:\Windows\system32\msiexec.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\User\Desktop\dds.scr
C:\Windows\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.co.uk/
uURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg8\toolbar\IEToolbar.dll
uURLSearchHooks: uTorrentBar Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - c:\program files\utorrentbar\tbuTor.dll
mURLSearchHooks: uTorrentBar Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - c:\program files\utorrentbar\tbuTor.dll
mURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg8\toolbar\IEToolbar.dll
BHO: Conduit Engine: {30f9b915-b755-4826-820b-08fba6bd249d} - c:\program files\conduitengine\ConduitEngine.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg8\toolbar\IEToolbar.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.6.5805.1910\swg.dll
BHO: uTorrentBar Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - c:\program files\utorrentbar\tbuTor.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - c:\program files\avg\avg8\toolbar\IEToolbar.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: uTorrentBar Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - c:\program files\utorrentbar\tbuTor.dll
TB: Conduit Engine: {30f9b915-b755-4826-820b-08fba6bd249d} - c:\program files\conduitengine\ConduitEngine.dll
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
uRun: [ISUSPM] "c:\program files\common files\installshield\updateservice\ISUSPM.exe" -scheduler
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
uRun: [Steam] "c:\program files\steam\Steam.exe" -silent
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [{3391CDA6-5746-3CF7-1687-8775C3B5ECB8}] c:\users\user\appdata\roaming\oxmyto\olewi.exe
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [PWRISOVM.EXE] c:\program files\poweriso\PWRISOVM.EXE
mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes\mbam.exe" /runcleanupscript
mRun: [SigmatelSysTrayApp] c:\program files\sigmatel\c-major audio\wdm\sttray.exe
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Google Sidewiki… - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - c:\program files\avg\avg8\toolbar\IEToolbar.dll
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
AppInit_DLLs: avgrsstx.dll

============= SERVICES / DRIVERS ===============

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-9-12 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-9-12 108552]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\avg\avg8\avgemc.exe [2009-8-31 908056]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2009-8-31 297752]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search & destroy\SDWinSec.exe [2009-8-31 1153368]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-1-30 135664]
S3 a016bus;Sony Ericsson Device A016 driver (WDM);c:\windows\system32\drivers\a016bus.sys [2009-9-6 83880]
S3 a016mdfl;Sony Ericsson Device A016 USB WMC Modeme Filter;c:\windows\system32\drivers\a016mdfl.sys [2009-9-6 15016]
S3 a016mdm;Sony Ericsson Device A016 USB WMC Modem Driver;c:\windows\system32\drivers\a016mdm.sys [2009-9-6 110504]
S3 a016mgmt;Sony Ericsson Device A016 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\a016mgmt.sys [2009-9-6 104488]
S3 a016obex;Sony Ericsson Device A016 USB WMC OBEX Interface;c:\windows\system32\drivers\a016obex.sys [2009-9-6 100648]
S3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files\avg\avg8\toolbar\ToolbarBroker.exe [2010-10-26 517448]
S3 getPlusHelper;getPlus® Helper;c:\windows\system32\svchost.exe -k getPlusHelper [2009-9-1 21504]

=============== Created Last 30 ================


==================== Find3M ====================

2010-05-13 18:30 143,360 a——- c:\windows\inf\infstrng.dat
2010-05-13 18:30 143,360 a——- c:\windows\inf\infstor.dat
2010-05-13 18:30 51,200 a——- c:\windows\inf\infpub.dat
2009-09-01 09:26 665,600 a——- c:\windows\inf\drvindex.dat
2009-09-01 09:09 174 a–sh— c:\program files\desktop.ini
2006-11-02 12:42 287,440 a——- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 12:42 287,440 a——- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 12:42 30,674 a——- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 12:42 30,674 a——- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 09:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 09:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 09:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 09:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat
2010-05-11 20:16 16,384 a–sh— c:\windows\serviceprofiles\localservice\appdata\local\temp\cookies\index.dat
2010-05-11 20:16 16,384 a–sh— c:\windows\serviceprofiles\localservice\appdata\local\temp\history\history.ie5\index.dat
2010-05-11 20:16 32,768 a–sh— c:\windows\serviceprofiles\localservice\appdata\local\temp\temporary internet files\content.ie5\index.dat
2010-08-15 21:06 262,144 a–sh— c:\windows\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\ietldcache\index.dat

============= FINISH: 21:33:52.19 ===============
Hello Danny_Boy and welcome to the WTT forum.

My name is Satchfan and I would be glad to help you with your computer problem. Please read the following guidelines which will help to make cleaning your machine easier:
• Please do not install/uninstall any programs unless asked to.
• Please do not run any scans other than those requested
• Please follow all instructions in the order posted
• Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
• If you don't understand something, please don't hesitate to ask for clarification before proceeding
• The fixes are specific to your problem and should only be used for this issue on this machine.
• Please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!
Please note that I am still in training and my replies need to be checked by an expert in order for you to receive the best possible advice. This may result in a small delay between my posts but I shall try to keep this to a minimum.

I am looking through your logs now and will reply as soon as possible.

Satchfan
Hello again Danny Boy

P2P - I see you have P2P software, (uTorrent, ), installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infection. If your computer is infected, it almost certainly contributed to your current situation.

Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are more often than not, infected. The bad guys use P2P file-sharing as a major conduit to spread their wares.

Please see this topic for more information:

Perils of P2P File Sharing.

I would strongly recommend that you uninstall it now. You can do so via Control Panel, Programs, and then Programs and Features.

Should you decide to keep it, please don’t use it until we have finished up here.

===================================================


There is sign of infection on your computer and we’ll have to disable some of your programs plus run some more scans to get to the root of the problem. Please be patient and follow the instruction in the order they are given
.
Meanwhile, please don’t install/uninstall anything, (except uTorrent if you choose to), or run any security programs unless asked.

===================================================

Please disable these programs and leave them disabled until we are finished.

Spybot's TeaTimer
  • Launch Spybot S&D, go to the Mode menu and make sure "Advanced Mode" is selected.
  • On the left hand side, click on Tools, then click on the Resident Icon in the list.
  • Uncheck the Resident TeaTimer (Protection of overall system settings) active box.
  • Click on the System Startup icon in the List
  • Uncheck the "TeaTimer" box and click OK at any prompts.
  • If Teatimer gives you a warning that changes were made, click Allow Change when prompted.
  • Exit Spybot S&D.
(When we are finished, you can re-enable Teatimer using the same steps but this time place a check next to "Resident TeaTimer" and check the "TeaTimer" box in System Startup).

Windows Defender• open Windows Defender
• click on Tools, General Settings
• scroll down and uncheck Turn on real-time protection (recommended)
• when you have unchecked this, click on the Save button and close Windows Defender.
You can re-enable it when your computer is clean; I will let you know!


Please download DeFogger to your desktop.

Double click DeFogger to run the tool.
  • The application window will appear
  • Click the Disable button to disable your CD Emulation drivers
  • Click Yes to continue
  • A 'Finished!' message will appear
  • Click OK
  • DeFogger will now ask to reboot the machine - click OK
IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_disable which will appear on your desktop.

Do not re-enable these drivers until otherwise instructed.


Run OTL

  • Double click on the icon to run it.
  • Copy/paste ALL the following text written inside the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :OTL
    O4 - HKCU..\Run: [{3391CDA6-5746-3CF7-1687-8775C3B5ECB8}] File not found
    
    :Commands
    [purity]
    [emptytemp]
    [Reboot]

  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log (don't check the boxes beside LOP Check or Purity this time)

Download the GMER Rootkit Scanner

[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • All drives/partitions except C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries



There should be a file on your desktop called OTL.txt. Please include that in your post.

Also, can you please tell me what is happening with your computer that made you think it may be infected.

Logs to include with next post:

OTL fix log
New OTL log
Extras.txt
Gmer.txt


Thanks

Satchfan
These were the only logs. Gmer kept crashing so I don't have the log for that. Also in Spybot SD there was no teatimer box in the start up list and in Windows Defender there was no Turn on real-time protection (recommended) box.



All processes killed
========== SERVICES/DRIVERS ==========
========== OTL ==========
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\{3391CDA6-5746-3CF7-1687-8775C3B5ECB8} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3391CDA6-5746-3CF7-1687-8775C3B5ECB8}\ not found.
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Public

User: User
->Temp folder emptied: 74644442 bytes
->Temporary Internet Files folder emptied: 493600288 bytes
->Java cache emptied: 52476881 bytes
->Flash cache emptied: 14228 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 5240 bytes
RecycleBin emptied: 2449505026 bytes

Total Files Cleaned = 2,928.00 mb


OTL by OldTimer - Version 3.2.21.0 log created on 02282011_190853

Files\Folders moved on Reboot…
File\Folder C:\Users\User\AppData\Local\Temp\~DF4AC8.tmp not found!
File\Folder C:\Users\User\AppData\Local\Temp\~DF4AD1.tmp not found!
File\Folder C:\Users\User\AppData\Local\Temp\~DF4B1A.tmp not found!
File\Folder C:\Users\User\AppData\Local\Temp\~DF4B1F.tmp not found!
File\Folder C:\Users\User\AppData\Local\Temp\~DF4B44.tmp not found!
File\Folder C:\Users\User\AppData\Local\Temp\~DF4B49.tmp not found!
File\Folder C:\Users\User\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low(80)\Content.IE5\ULY96698\cgTNFgplm4,Wwpk-Usp3lQRklbR0UINm9DUbIr7ueK0po_7ETTR5C7aEuaJoN_k7BF0jXeuVpKcO8ekHHOkhgSmDEruaTROz
AcrYlIn4vBwjF-FC6BPtQWzAl3nvQ&callback=google.LU[1].loadFeaturemap not found!
File\Folder C:\Users\User\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low(80)\Content.IE5\M98JVGG8\X4eGqlMJY9dGWwxRSYpLlzqUISGhQdVy6jqtS6E3hsANKwpNBOi0cMBG7pRq8fc-vqA4sya_tgj1LokzNMVqqfro5WdvfA6fmeuN-Ez_Rsd7DpFZ93YIP4ew2UuclMbJnRRqwuJNXICJM54_skOBpQ5pTcg[1].gif not found!
C:\Users\User\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\TZVVDETH\iframe[2].htm moved successfully.
C:\Users\User\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\TZVVDETH\index[2].htm moved successfully.
C:\Users\User\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\4AEQDOKQ\like[1].htm moved successfully.
C:\Users\User\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\MSIMGSIZ.DAT moved successfully.

Registry entries deleted on Reboot…








OTL Extras logfile created on: 24/02/2011 21:13:05 - Run 1
OTL by OldTimer - Version 3.2.21.0 Folder = C:\Users\User\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18999)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 56.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 78.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 596.18 Gb Total Space | 398.33 Gb Free Space | 66.81% Space Free | Partition Type: NTFS
Drive D: | 2.84 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: DESKTOP1 | User Name: User | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile – Reg Error: Key error.
htmlfile [print] – rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"VistaSp2" = Reg Error: Unknown registry data type – File not found

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0E0332DB-2F9D-4CD6-A523-21C4158767DB}" = dir=in | app=c:\program files\avg\avg8\avgemc.exe |
"{233ED826-A415-40A3-AD76-43A74C87695A}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{29F5E6F4-CE65-4B32-815F-4A35C0744162}" = protocol=17 | dir=in | app=c:\program files\games\fm08\fm.exe |
"{37E4A3F7-DA33-433B-A2D7-86423E073796}" = protocol=6 | dir=in | app=c:\program files\games\fm10\fm.exe |
"{56D88942-82BC-4DE9-9629-8F5E7A96EBF7}" = protocol=17 | dir=in | app=c:\program files\utorrent\utorrent.exe |
"{A6802DB3-F079-4AC7-A202-0A1D47C69E5D}" = protocol=17 | dir=in | app=c:\program files\games\fm10\fm.exe |
"{AF9FD73B-C6EC-4BF4-8F78-FFC04A0E6DA1}" = protocol=6 | dir=in | app=c:\program files\utorrent\utorrent.exe |
"{CD768AC0-3B39-435C-A168-83B9590EA96B}" = dir=in | app=c:\program files\avg\avg8\avgupd.exe |
"{D718E387-D408-4C8D-800E-44AA2B012549}" = protocol=17 | dir=in | app=c:\program files\itunes\itunes.exe |
"{DBA39337-F500-4487-9E41-030CC00F3705}" = protocol=6 | dir=in | app=c:\program files\itunes\itunes.exe |
"{DF78C81E-D4E1-4A42-8777-45AFAC253A12}" = dir=in | app=c:\program files\avg\avg8\avgnsx.exe |
"{DFED0539-3BBF-4529-9C1F-19BEE36A2A99}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{FFF583B2-8F81-47B6-A070-5FCAE580EDF0}" = protocol=6 | dir=in | app=c:\program files\games\fm08\fm.exe |
"TCP Query User{1FD99A2C-2390-4651-8E26-1828E68647E7}C:\windows\explorer.exe" = protocol=6 | dir=in | app=c:\windows\explorer.exe |
"TCP Query User{35560D3C-9CFC-4229-8D10-AAE8D13CA25F}C:\program files\utorrent\utorrent.exe" = protocol=6 | dir=in | app=c:\program files\utorrent\utorrent.exe |
"TCP Query User{7F95AF6C-F7B3-40CE-82E0-38AB909E5909}C:\program files\steam\steamapps\dannytwist\team fortress 2\hl2.exe" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\dannytwist\team fortress 2\hl2.exe |
"TCP Query User{ADED7016-39BF-49F8-B847-C431E4DFBFFD}C:\program files\steam\steamapps\dannytwist\team fortress 2\hl2.exe" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\dannytwist\team fortress 2\hl2.exe |
"TCP Query User{E4FE3D7A-E1F3-49C1-9F22-1E2C9BB69758}C:\windows\system32\taskeng.exe" = protocol=6 | dir=in | app=c:\windows\system32\taskeng.exe |
"UDP Query User{09674F36-EDA1-4854-81E2-66C9B6596F06}C:\windows\system32\taskeng.exe" = protocol=17 | dir=in | app=c:\windows\system32\taskeng.exe |
"UDP Query User{4E3412C2-3D6A-4719-BDF2-CF95D4148BB3}C:\program files\steam\steamapps\dannytwist\team fortress 2\hl2.exe" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\dannytwist\team fortress 2\hl2.exe |
"UDP Query User{779CEECF-962F-449D-B09E-B08E531C433B}C:\program files\utorrent\utorrent.exe" = protocol=17 | dir=in | app=c:\program files\utorrent\utorrent.exe |
"UDP Query User{9FAE3C74-7AD8-45A0-9EB7-3B025E95AEB6}C:\windows\explorer.exe" = protocol=17 | dir=in | app=c:\windows\explorer.exe |
"UDP Query User{FE19D1CB-B8F7-4E15-9027-6109970701E4}C:\program files\steam\steamapps\dannytwist\team fortress 2\hl2.exe" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\dannytwist\team fortress 2\hl2.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{13F3917B56CD4C25848BDC69916971BB}" = DivX Converter
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83216016FF}" = Java™ 6 Update 17
"{3FC7CBBC4C1E11DCA1A752EA55D89593}" = DivX Version Checker
"{42929F0F-CE14-47AF-9FC7-FF297A603021}" = Dell Resource CD
"{43602F34-1AA3-44FB-AEB2-D08C2C73743F}" = Paint.NET v3.36
"{553255F3-78FD-40F1-A6F8-6882140265FE}" = Apple Application Support
"{5ECB3A3C-980B-4D12-9724-25DCB07A1F47}" = iTunes
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{767CC44C-9BBC-438D-BAD3-FD4595DD148B}" = VC80CRTRedist - 8.0.50727.762
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
"{8A253629-0511-4854-8B4E-46E57E66005C}" = Bonjour
"{8A7E941F-2BB4-47D0-B732-8AE5F3513B68}" = ASAPI
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9DE1BE03-AFE2-4CDB-BFEB-D06D736CD01A}" = Apple Mobile Device Support
"{A462213D-EED4-42C2-9A60-7BDD4D4B0B17}" = SigmaTel Audio
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A96E97134CA649888820BCDE5E300BBD}" = H.264 Decoder
"{AAC389499AEF40428987B3D30CFC76C9}" = MKV Splitter
"{AEF9DC35ADDF4825B049ACBFD1C6EB37}" = AAC Decoder
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{C325F588-D6B1-4A7F-B6A2-914C75DDA348}" = Morrowind
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{DB3C800B-081B-4146-B4E3-EFB5B77AA913}" = TES Construction Set
"{E2883E8F-472F-4fb0-9522-AC9BF37916A7}" = Adobe Download Manager
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"AmbientKeys_is1" = Ambient Keys 1.5
"AVG8Uninstall" = AVG Free 8.5
"CCleaner" = CCleaner
"Collab" = Collab
"conduitEngine" = Conduit Engine
"Defraggler" = Defraggler
"DivX Plus DirectShow Filters" = DivX Plus DirectShow Filters
"Fallout2" = Fallout2
"FL Studio 8" = FL Studio 8
"Football Manager 2010" = Football Manager 2010
"HijackThis" = HijackThis 2.0.2
"IL Download Manager" = IL Download Manager
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Native Instruments Massive v1.0.1.008 VSTi DXi RTAS" = Native Instruments Massive v1.0.1.008 VSTi DXi RTAS
"NVIDIA Drivers" = NVIDIA Drivers
"PoiZone" = PoiZone
"PowerISO" = PowerISO
"PROSet" = Intel® PRO Network Connections Drivers
"Steam App 440" = Team Fortress 2
"Toxic Biohazard" = Toxic Biohazard
"uTorrent" = µTorrent
"uTorrentBar Toolbar" = uTorrentBar Toolbar
"WavePad" = WavePad Sound Editor
"WinRAR archiver" = WinRAR archiver

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 21/02/2011 13:58:00 | Computer Name = Desktop1 | Source = Winlogon | ID = 4103
Description = Windows license activation failed. Error 0x00000000.

Error - 21/02/2011 15:15:08 | Computer Name = Desktop1 | Source = Software Licensing Service | ID = 8198
Description = License Activation (SLUI.exe) failed with the following error code:
0x80070057

Error - 22/02/2011 14:22:52 | Computer Name = Desktop1 | Source = Winlogon | ID = 4103
Description = Windows license activation failed. Error 0x00000000.

Error - 22/02/2011 14:25:47 | Computer Name = Desktop1 | Source = Software Licensing Service | ID = 8198
Description = License Activation (SLUI.exe) failed with the following error code:
0x80070057

Error - 23/02/2011 13:31:22 | Computer Name = Desktop1 | Source = Winlogon | ID = 4103
Description = Windows license activation failed. Error 0x00000000.

Error - 23/02/2011 13:34:16 | Computer Name = Desktop1 | Source = Software Licensing Service | ID = 8198
Description = License Activation (SLUI.exe) failed with the following error code:
0x80070057

Error - 24/02/2011 14:13:42 | Computer Name = Desktop1 | Source = Software Licensing Service | ID = 8198
Description = License Activation (SLUI.exe) failed with the following error code:
0x80070057

Error - 24/02/2011 16:45:12 | Computer Name = Desktop1 | Source = Winlogon | ID = 4103
Description = Windows license activation failed. Error 0x00000000.

Error - 24/02/2011 16:49:15 | Computer Name = Desktop1 | Source = Software Licensing Service | ID = 8198
Description = License Activation (SLUI.exe) failed with the following error code:
0x80070057

Error - 24/02/2011 17:00:07 | Computer Name = Desktop1 | Source = Winlogon | ID = 4103
Description = Windows license activation failed. Error 0x00000000.

[ System Events ]
Error - 17/02/2011 15:56:12 | Computer Name = Desktop1 | Source = iaStorV | ID = 262153
Description = The device, \Device\Ide\iaStor0, did not respond within the timeout
period.

Error - 17/02/2011 15:56:16 | Computer Name = Desktop1 | Source = iaStorV | ID = 262153
Description = The device, \Device\Ide\iaStor0, did not respond within the timeout
period.

Error - 17/02/2011 15:56:20 | Computer Name = Desktop1 | Source = iaStorV | ID = 262153
Description = The device, \Device\Ide\iaStor0, did not respond within the timeout
period.

Error - 17/02/2011 15:56:24 | Computer Name = Desktop1 | Source = iaStorV | ID = 262153
Description = The device, \Device\Ide\iaStor0, did not respond within the timeout
period.

Error - 17/02/2011 15:56:28 | Computer Name = Desktop1 | Source = iaStorV | ID = 262153
Description = The device, \Device\Ide\iaStor0, did not respond within the timeout
period.

Error - 17/02/2011 15:59:45 | Computer Name = Desktop1 | Source = EventLog | ID = 6008
Description = The previous system shutdown at 19:57:35 on 17/02/2011 was unexpected.

Error - 17/02/2011 15:59:58 | Computer Name = Desktop1 | Source = Service Control Manager | ID = 7026
Description =

Error - 18/02/2011 02:50:57 | Computer Name = Desktop1 | Source = Service Control Manager | ID = 7026
Description =

Error - 18/02/2011 13:47:37 | Computer Name = Desktop1 | Source = Service Control Manager | ID = 7026
Description =

Error - 19/02/2011 03:17:08 | Computer Name = Desktop1 | Source = Service Control Manager | ID = 7026
Description =


< End of report >

in Spybot SD there was no teatimer box in the start up list

Right click Spybot's TeaTimer System Tray Icon > click Exit Spybot-S&D Resident

in Windows Defender there was no Turn on real-time protection (recommended) box.

Look under Tools, Options

Gmer kept crashing

Please run GMER again, but this time uncheck everything EXCEPT "Sections" and "C:\" .


If it still doesn’t work:

Scan With RKUnHooker• Please Download Rootkit Unhooker Save it to your desktop
• Double-click on RKUnhookerLE.exe to run it
• Click the Report tab, then click Scan
• Check (tick) Drivers, Stealth. Uncheck the rest. then Click OK
• Wait till the scanner has finished and then click File, Save Report
• Save the report somewhere where you can find it. Click Close
Copy the entire contents of the report and paste it in a reply here.

Note** you may get this warning:

"Rootkit Unhooker has detected a parasite inside itself!
It is recommended to remove parasite, okay?"


It is ok, just ignore it


Run OTL • Open OTL again and click the Quick Scan button (don't check the boxes beside LOP Check or Purity this time)
• Post the OTL.txt log it produces in your next reply.
Please post back with the log

===================================================

Can you please answer the following:• What made you think your computer was infected?
• How is it behaving now?
Satchfan
Hello Danny Boy It has been several days since I asked you to follow some steps to help with your computer problems. Please let me know if you still need help. Thanks Satchfan

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI