This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Am I Infected?

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi everyone,

I have recently upgraded my broadband connection from 8mb to 24mb but when i run a speed test at speedtest.net or anywhere else i am only getting 6.5mb. I contacted my ISP and they sent out an engineer who checked my connection and said there was at least 15mb speed coming off it. He then told me that it was my computer that must be infected with a virus thats preventing me from getting a better speed. So I ran a hijack this and these are the results. Am i infected with a virus? Any help would be appreciated. Thanks.

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:02:58, on 07/04/2011
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.19019)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\DellTPad\Apoint.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\SigmaTel\C-Major Audio\WDM\sttray.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\AVG\AVG10\avgtray.exe
C:\Program Files\DivX\DivX Update\DivXUpdate.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer provided by Dell
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: Increase performance and video formats for your HTML5 - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll
O2 - BHO: Use the DivX Plus Web Player to watch web videos with less interruptions and smoother playback on supported sites - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\sttray.exe
O4 - HKLM\..\Run: [NVHotkey] rundll32.exe C:\Windows\system32\nvHotkey.dll,Start
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] c:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKLM\..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG10\avgtray.exe
O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: QuickSet.lnk = C:\Program Files\Dell\QuickSet\quickset.exe
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\system32\aestsrv.exe
O23 - Service: AVG Security Toolbar Service - Unknown owner - C:\Program Files\AVG\AVG10\Toolbar\ToolbarBroker.exe
O23 - Service: AVG Firewall (avgfws) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG10\avgfws.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG10\avgwdsvc.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: SigmaTel Audio Service (STacSV) - IDT, Inc. - C:\Windows\system32\STacSV.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

–
End of file - 7064 bytes
Hello and Posted Image

My name is patndoris. I will be glad to take a look at your log and help you with solving any malware problems. It will be very helpful if you follow these guidelines:
  • Malware logs are often lengthy and can take a lot of time to research and interpret. Please be patient while I review your logs.
  • Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to get your system clean.
  • Please make sure to carefully read any instruction that I give you. If you're not sure, or if something unexpected happens, do NOT continue! Stop and ask!
  • Please follow my instructions carefully and in the order they are posted. You may also find it helpful to print out the instructions you receive.
  • Please do not run any scans or install/uninstall any applications or delete anything without being directed to do so.
  • Remember, absence of symptoms does not mean the infection is all gone. Please stick with me till you're given the "all clear".
  • Please do not use the Attachment feature for any log file. Do a Copy/Paste of the entire contents of the log file and submit it inside your post.
  • Please reply within 3 days. If I do not hear back from you in that time frame, I will post a reminder for you. Topics with no reply in 4 days are closed!




HijackThis has largely been replaced by other tools. Since being acquired by TrendMicro, HijackThis has not been regularly updated. Many infections are now able to hide partly, or completely from a HijackThis scan. DDS includes all the scan locations of HijackThis and more.


Download and Run DDS by sUBs

Please download DDS and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.scr to run the tool.
  • When done, DDS.txt will open.
  • Click Yes at the next prompt for Optional Scan.
  • Save both reports to your desktop.
—————————————————

Please Please copy / paste the scan reults.

DDS.txt

Please attach the second file; Attach.txt. To attach a file, do the following:
  • Under the reply panel is the Attachments Panel
  • Browse for the attachment file you want to upload, then click the green Upload button
  • Once it has uploaded, click the Manage Current Attachments drop down box
  • Click on [external image: Posted Image] to insert the attachment into your post




Scan With RootKitUnHooker

  • Please choose one link and download Rootkit Unhooker and save it to your desktop.

    Link 1
    Link 2
    Link 3
  • Now double-click on RKUnhookerLE.exe to run it.
  • Click the Report tab, then click Scan.
  • Check (Tick) Drivers and Stealth
  • Uncheck the rest. then click OK
  • When prompted to Select Disks for Scan, make sure C:/ is checked and click OK
  • Wait till the scanner has finished and then click File > Save Report.
  • Save the report somewhere where you can find it. Click Close.
  • Copy the entire contents of the report and paste it in your next reply.

Note** you may get the following warning, just click OK and continue.

"Rootkit Unhooker has detected a parasite inside itself!
It is recommended to remove parasite, okay?"
Hi patndoris, Thanks for the reply, Here is the results of the DDS and RootKitUnHooker Scans. Hope i did everything right! DDS (Ver_09-06-26.01) - NTFSx86 Run by [removed] at 19:24:53.27 on 08/04/2011 Internet Explorer: 8.0.6001.19019 BrowserJavaVersion: 1.6.0_24 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.353.1033.18.2045.929 [GMT 1:00] SP: Lavasoft Ad-Watch Live! *disabled* (Updated) {67844DAE-4F77-4D69-9457-98E8CFFDAA22} SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} ============== Running Processes =============== C:\PROGRA~1\AVG\AVG10\avgchsvx.exe C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\nvvsvc.exe C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\system32\nvvsvc.exe C:\Windows\system32\WLANExt.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\aestsrv.exe C:\Windows\system32\svchost.exe -k apphost C:\Program Files\AVG\AVG10\avgfws.exe C:\Program Files\AVG\AVG10\avgwdsvc.exe C:\Program Files\Intel\Wireless\Bin\EvtEng.exe C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe C:\Program Files\AVG\AVG10\avgam.exe C:\Program Files\AVG\AVG10\avgnsx.exe C:\Windows\system32\PnkBstrA.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe C:\Windows\system32\STacSV.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\system32\svchost.exe -k iissvcs C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\DRIVERS\xaudio.exe C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe C:\Windows\System32\alg.exe C:\Program Files\AVG\AVG10\avgemcx.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Windows\system32\taskeng.exe C:\Windows\Explorer.EXE C:\Program Files\DellTPad\Apoint.exe C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe C:\Program Files\SigmaTel\C-Major Audio\WDM\sttray.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Program Files\AVG\AVG10\avgtray.exe C:\Program Files\DivX\DivX Update\DivXUpdate.exe C:\Program Files\DAEMON Tools Lite\daemon.exe C:\Program Files\Dell\QuickSet\quickset.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Program Files\AVG\AVG10\avgcsrvx.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Program Files\DellTPad\ApMsgFwd.exe C:\Program Files\DellTPad\Apntex.exe C:\Program Files\DellTPad\HidFind.exe C:\Program Files\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Mozilla Firefox\plugin-container.exe C:\PROGRA~1\AVG\AVG10\avgrsx.exe C:\Program Files\AVG\AVG10\avgcsrvx.exe C:\Windows\system32\taskeng.exe C:\Windows\explorer.exe C:\Users\Eugrulz\Downloads\dds.scr C:\Windows\system32\conime.exe C:\Windows\system32\wbem\wmiprvse.exe ============== Pseudo HJT Report =============== uWindow Title = Internet Explorer provided by Dell uURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg10\toolbar\IEToolbar.dll mURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg10\toolbar\IEToolbar.dll BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\programdata\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll BHO: DivX Plus Web Player HTML5 : {326e768d-4182-46fd-9c16-1449a49795f4} - c:\program files\divx\divx plus web player\npdivx32.dll BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg10\avgssie.dll BHO: DivX HiQ: {593ddec6-7468-4cdd-90e1-42dadaa222e9} - c:\program files\divx\divx plus web player\npdivx32.dll BHO: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg10\toolbar\IEToolbar.dll BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\dell\bae\BAE.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - c:\program files\avg\avg10\toolbar\IEToolbar.dll uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe uRun: [DAEMON Tools Lite] "c:\program files\daemon tools lite\daemon.exe" -autorun mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide mRun: [Apoint] c:\program files\delltpad\Apoint.exe mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start mRun: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\sttray.exe mRun: [NVHotkey] rundll32.exe c:\windows\system32\nvHotkey.dll,Start mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\isuspm.exe -startup mRun: [AVG_TRAY] c:\program files\avg\avg10\avgtray.exe mRun: [DivXUpdate] "c:\program files\divx\divx update\DivXUpdate.exe" /CHECKNOW StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\quickset.lnk - c:\program files\dell\quickset\quickset.exe mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0) mPolicies-system: EnableLUA = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} - hxxp://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - c:\program files\avg\avg10\toolbar\IEToolbar.dll Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg10\avgpp.dll ================= FIREFOX =================== FF - ProfilePath - c:\users\eugrulz\appdata\roaming\mozilla\firefox\profiles\567jb457.default\ FF - prefs.js: browser.search.selectedEngine - AVG Secure Search FF - prefs.js: browser.startup.homepage - www.yahoo.ie FF - prefs.js: keyword.URL - hxxp://search.avg.com/route/?d=4d95b238&v;=6.103.018.001&i;=23&tp;=ab&iy;=&ychte;=us&lng;=en-GB&q;= FF - component: c:\program files\avg\avg10\firefox4\components\avgssff4.dll FF - component: c:\program files\avg\avg10\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll FF - component: c:\program files\avg\avg10\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll FF - component: c:\program files\avg\avg10\toolbar\firefox\avg@igeared\components\xpavgtbapi.dll FF - plugin: c:\program files\divx\divx ovs helper\npovshelper.dll FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\program files\microsoft silverlight\4.0.60129.0\npctrlui.dll FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll FF - plugin: c:\program files\mozilla firefox\plugins\npganymedenet.dll FF - plugin: c:\programdata\real\realplayer\browserrecordplugin\mozillaplugins\nprphtml5videoshim.dll FF - plugin: c:\users\eugrulz\appdata\locallow\unity\webplayer\loader\npUnity3D32.dll FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} ============= SERVICES / DRIVERS =============== R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [2010-9-13 25680] R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2010-9-7 26064] R1 Avgfwfd;AVG network filter service;c:\windows\system32\drivers\avgfwd6x.sys [2010-7-12 54112] R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2010-12-8 251728] R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [2010-11-12 299984] R2 AESTFilters;Andrea ST Filters Service;c:\windows\system32\AEstSrv.exe [2010-7-3 73728] R2 avgfws;AVG Firewall;c:\program files\avg\avg10\avgfws.exe [2010-11-22 3226632] R2 AVGIDSAgent;AVGIDSAgent;c:\program files\avg\avg10\identity protection\agent\bin\AVGIDSAgent.exe [2011-1-6 6128720] R2 avgwd;AVG WatchDog;c:\program files\avg\avg10\avgwdsvc.exe [2010-10-22 265400] R2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-9-17 21504] R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [2010-8-3 123472] R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [2010-8-3 30288] R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [2010-8-3 27216] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files\avg\avg10\toolbar\ToolbarBroker.exe [2011-4-1 947528] S3 DrmRDriverV32;DrmRDriverV32;c:\windows\system32\drivers\DrmRDriverV32.sys [2007-12-31 23096] S3 DrmRVideo32;DrmRVideo32;c:\windows\system32\drivers\DrmRVideo32.sys [2007-12-31 3768] S3 PCDSRVC{E9D79540-57D5953E-06020101}_0;PCDSRVC{E9D79540-57D5953E-06020101}_0 - PCDR Kernel Mode Service Helper Driver;c:\program files\dell support center\pcdsrvc.pkms [2010-11-18 21744] S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504] ============== File Associations =============== regfile="regedit.exe" "%1" =============== Created Last 30 ================ 2011-04-07 11:55 –d—– c:\program files\Trend Micro 2011-04-03 12:18 –d—– c:\users\eugrulz\appdata\roaming\Intel 2011-04-03 12:18 –d—– c:\users\eugrulz\Roaming 2011-04-03 12:18 –d—– c:\programdata\Roaming 2011-04-03 12:18 –d—– c:\progra~2\Roaming 2011-04-03 12:17 56 a——- c:\windows\system32\IHV_Install.bat 2011-04-03 12:17 –d—– c:\programdata\Intel 2011-04-03 12:17 –d—– c:\program files\Cisco 2011-04-02 20:34 –d—– C:\inetpub 2011-04-02 13:32 2,560 a——- c:\windows\_MSRSTRT.EXE 2011-04-01 15:14 –d—– c:\program files\Panda Security 2011-04-01 12:08 –d—– c:\programdata\AVG Security Toolbar 2011-04-01 12:08 –d—– c:\progra~2\AVG Security Toolbar 2011-04-01 12:04 –d—– c:\windows\system32\drivers\AVG 2011-03-30 12:21 –d—– C:\Project69_Cache 2011-03-26 11:45 –d—– C:\MyAudio 2011-03-23 22:54 –d—– c:\program files\XCC 2011-03-23 20:10 –d—– c:\program files\FinalAlert 2 Yuri's Revenge 2011-03-23 12:02 1,068,544 a——- c:\windows\system32\DWrite.dll 2011-03-23 12:02 797,696 a——- c:\windows\system32\FntCache.dll 2011-03-23 12:02 288,768 a——- c:\windows\system32\XpsGdiConverter.dll 2011-03-15 12:12 –d—– c:\windows\Patches 2011-03-15 11:42 4 a——- c:\windows\system32\msdbcrpt.kar.{5eff6ca1-b420-463c-b4d2-68d7c920122e} 2011-03-15 11:42 4 a——- c:\windows\system32\fsdbcrpt.kar.{5eff6ca1-b420-463c-b4d2-68d7c920122e} 2011-03-15 00:49 4 a——- c:\windows\system32\msdbcrpt.kar.{09111bd4-a357-312b-a385-1f8ebc574559} 2011-03-15 00:49 4 a——- c:\windows\system32\fsdbcrpt.kar.{09111bd4-a357-312b-a385-1f8ebc574559} 2011-03-15 00:48 –d—– c:\windows\3F67FD4A380F4081A5061D2C0091A93E.TMP 2011-03-15 00:44 –d—– c:\program files\common files\GFI 2011-03-15 00:31 –d—– c:\program files\GFI 2011-03-12 23:33 –d—– c:\program files\DivX ==================== Find3M ==================== 2011-04-08 16:07 56,437 a——- c:\programdata\nvModes.dat 2011-04-08 16:07 56,437 a——- c:\progra~2\nvModes.dat 2011-04-03 12:16 143,360 a——- c:\windows\inf\infstrng.dat 2011-04-03 12:16 51,200 a——- c:\windows\inf\infpub.dat 2011-04-03 12:15 143,360 a——- c:\windows\inf\infstor.dat 2011-03-01 23:20 249,856 ——– c:\windows\Setup1.exe 2011-03-01 23:20 73,216 a——- c:\windows\ST6UNST.EXE 2011-02-02 22:40 472,808 a——- c:\windows\system32\deployJava1.dll 2011-02-02 19:11 222,080 ——– c:\windows\system32\MpSigStub.exe 2011-01-20 17:08 478,720 a——- c:\windows\system32\dxgi.dll 2011-01-20 17:08 1,029,120 a——- c:\windows\system32\d3d10.dll 2011-01-20 17:08 219,648 a——- c:\windows\system32\d3d10_1core.dll 2011-01-20 17:08 189,952 a——- c:\windows\system32\d3d10core.dll 2011-01-20 17:08 160,768 a——- c:\windows\system32\d3d10_1.dll 2011-01-20 17:07 37,376 a——- c:\windows\system32\cdd.dll 2011-01-20 17:07 258,048 a——- c:\windows\system32\winspool.drv 2011-01-20 17:07 586,240 a——- c:\windows\system32\stobject.dll 2011-01-20 17:06 2,873,344 a——- c:\windows\system32\mf.dll 2011-01-20 17:06 26,112 a——- c:\windows\system32\printfilterpipelineprxy.dll 2011-01-20 17:04 209,920 a——- c:\windows\system32\mfplat.dll 2011-01-20 17:04 98,816 a——- c:\windows\system32\mfps.dll 2011-01-20 15:28 1,554,432 a——- c:\windows\system32\xpsservices.dll 2011-01-20 15:27 876,032 a——- c:\windows\system32\XpsPrint.dll 2011-01-20 15:26 667,648 a——- c:\windows\system32\printfilterpipelinesvc.exe 2011-01-20 15:25 847,360 a——- c:\windows\system32\OpcServices.dll 2011-01-20 15:24 135,680 a——- c:\windows\system32\XpsRasterService.dll 2011-01-20 15:15 979,456 a——- c:\windows\system32\MFH264Dec.dll 2011-01-20 15:14 357,376 a——- c:\windows\system32\MFHEAACdec.dll 2011-01-20 15:14 302,592 a——- c:\windows\system32\mfmp4src.dll 2011-01-20 15:14 261,632 a——- c:\windows\system32\mfreadwrite.dll 2011-01-20 15:12 1,172,480 a——- c:\windows\system32\d3d10warp.dll 2011-01-20 15:11 486,400 a——- c:\windows\system32\d3d10level9.dll 2011-01-20 14:47 683,008 a——- c:\windows\system32\d2d1.dll 2010-12-08 14:26 117 a——- c:\users\eugrulz\jagex_runescape_preferences2.dat 2010-12-08 13:14 46 a——- c:\users\eugrulz\jagex_runescape_preferences.dat 2010-05-01 11:10 56 a—h— c:\programdata\ezsidmv.dat 2010-05-01 11:10 56 a—h— c:\progra~2\ezsidmv.dat 2009-11-17 14:26 665,600 a——- c:\windows\inf\drvindex.dat 2009-07-26 21:56 22,328 a——- c:\users\eugrulz\appdata\roaming\PnkBstrK.sys 2009-07-03 15:04 27,525 a——- c:\users\eugrulz\appdata\roaming\nvModes.dat 2009-01-02 17:38 424 a——- c:\users\eugrulz\appdata\roaming\wklnhst.dat 2008-10-07 22:38 174 a–sh— c:\program files\desktop.ini 2008-04-12 22:51 952 a–sh— c:\programdata\KGyGaAvL.sys 2008-04-12 22:51 952 a–sh— c:\progra~2\KGyGaAvL.sys 2008-04-12 22:51 88 —shr– c:\programdata\D5A8E2CE11.sys 2008-04-12 22:51 88 —shr– c:\progra~2\D5A8E2CE11.sys 2006-11-02 13:42 287,440 a——- c:\windows\inf\perflib\0409\perfi.dat 2006-11-02 13:42 287,440 a——- c:\windows\inf\perflib\0409\perfh.dat 2006-11-02 13:42 30,674 a——- c:\windows\inf\perflib\0409\perfd.dat 2006-11-02 13:42 30,674 a——- c:\windows\inf\perflib\0409\perfc.dat 2006-11-02 10:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat 2006-11-02 10:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat 2006-11-02 10:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat 2006-11-02 10:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat 2010-08-13 22:27 262,144 a–sh— c:\windows\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\ietldcache\index.dat 2007-03-09 08:12 27,648 a–sh— c:\windows\system32\AVSredirect.dll ============= FINISH: 19:25:48.05 =============== RkU Version: 3.8.388.590, Type LE (SR2) ============================================== OS Name: Windows Vista Version 6.0.6002 (Service Pack 2) Number of processors #2 ============================================== >Drivers ============================================== 0xBE40D000 C:\Windows\system32\DRIVERS\nvlddmkm.sys 11001856 bytes (NVIDIA Corporation, NVIDIA Windows Kernel Mode Driver, Version 258.96 ) 0xE2A0C000 C:\Windows\system32\ntkrnlpa.exe 3907584 bytes (Microsoft Corporation, NT Kernel & System) 0xE2A0C000 PnpManager 3907584 bytes 0xE2A0C000 RAW 3907584 bytes 0xE2A0C000 WMIxWDM 3907584 bytes 0xBF203000 C:\Windows\system32\DRIVERS\NETw4v32.sys 2289664 bytes (Intel Corporation, Intel® Wireless WiFi Link Driver) 0xCB450000 Win32k 2109440 bytes 0xCB450000 C:\Windows\System32\win32k.sys 2109440 bytes (Microsoft Corporation, Multi-User Win32 Driver) 0xBA867000 C:\Windows\System32\Drivers\Ntfs.sys 1114112 bytes (Microsoft Corporation, NT File System Driver) 0xBA6D7000 C:\Windows\system32\drivers\ndis.sys 1093632 bytes (Microsoft Corporation, NDIS 6.0 wrapper driver) 0xC1208000 C:\Windows\system32\DRIVERS\HSX_DPV.sys 1060864 bytes (Conexant Systems, Inc., HSF_DP driver) 0xBA291000 PCI_PNP0762 1036288 bytes 0xBA291000 C:\Windows\System32\Drivers\spnr.sys 1036288 bytes 0xBA291000 sptd 1036288 bytes 0xC160F000 C:\Windows\System32\drivers\tcpip.sys 958464 bytes (Microsoft Corporation, TCP/IP Driver) 0xBA0D4000 C:\Windows\system32\CI.dll 917504 bytes (Microsoft Corporation, Code Integrity Module) 0xD38ED000 C:\Windows\system32\drivers\peauth.sys 909312 bytes (Microsoft Corporation, Protected Environment Authentication and Authorization Export Driver) 0xBAA46000 C:\Windows\System32\Drivers\dump_iaStor.sys 778240 bytes 0xBA531000 C:\Windows\system32\drivers\iastor.sys 778240 bytes (Intel Corporation, Intel Matrix Storage Manager driver - ia32) 0xC130B000 C:\Windows\system32\DRIVERS\HSX_CNXT.sys 737280 bytes (Conexant Systems, Inc., HSF_CNXT driver) 0xD2007000 C:\Windows\system32\drivers\spsys.sys 720896 bytes (Microsoft Corporation, security processor) 0xBEE8D000 C:\Windows\System32\drivers\dxgkrnl.sys 655360 bytes (Microsoft Corporation, DirectX Graphics Kernel) 0xBA491000 C:\Windows\system32\drivers\iastorv.sys 655360 bytes (Intel Corporation, Intel Matrix Storage Manager driver (base)) 0xBAB34000 C:\Windows\system32\DRIVERS\HDAudBus.sys 577536 bytes (Microsoft Corporation, High Definition Audio Bus Driver) 0xBA208000 C:\Windows\system32\drivers\Wdf01000.sys 507904 bytes (Microsoft Corporation, WDF Dynamic) 0xBA666000 C:\Windows\System32\Drivers\ksecdd.sys 462848 bytes (Microsoft Corporation, Kernel Security Support Provider Interface) 0xBA00A000 C:\Windows\system32\mcupdate_GenuineIntel.dll 458752 bytes (Microsoft Corporation, Intel Microcode Update Library) 0xD210E000 C:\Windows\system32\drivers\HTTP.sys 446464 bytes (Microsoft Corporation, HTTP Protocol Stack) 0xBF55F000 C:\Windows\System32\Drivers\ac3y15nf.SYS 413696 bytes (Microsoft Corporation, ATAPI IDE Miniport Driver) 0xBFAB4000 C:\Windows\system32\drivers\stwrt.sys 348160 bytes (IDT, Inc., NDHF) 0xBF49C000 C:\Windows\system32\DRIVERS\rixdptsk.sys 331776 bytes (REDC, RICOH XD SM Driver) 0xD3806000 C:\Windows\System32\DRIVERS\srv.sys 319488 bytes (Microsoft Corporation, Server driver) 0xBA41B000 C:\Windows\System32\drivers\volmgrx.sys 303104 bytes (Microsoft Corporation, Volume Manager Extension Driver) 0xC1A02000 C:\Windows\system32\drivers\afd.sys 294912 bytes (Microsoft Corporation, Ancillary Function Driver for WinSock) 0xC174F000 C:\Windows\system32\DRIVERS\avgtdix.sys 294912 bytes (AVG Technologies CZ, s.r.o., AVG Network connection watcher) 0xBA1B4000 C:\Windows\system32\drivers\acpi.sys 286720 bytes (Microsoft Corporation, ACPI Driver for NT) 0xD386C000 C:\Windows\system32\DRIVERS\atksgt.sys 274432 bytes 0xBA093000 C:\Windows\system32\CLFS.SYS 266240 bytes (Microsoft Corporation, Common Log File System Driver) 0xBEF91000 C:\Windows\system32\DRIVERS\storport.sys 266240 bytes (Microsoft Corporation, Microsoft Storage Port Driver) 0xBEF44000 C:\Windows\system32\DRIVERS\USBPORT.SYS 253952 bytes (Microsoft Corporation, USB 1.1 & 2.0 Port Driver) 0xBFB5B000 C:\Windows\system32\DRIVERS\HSXHWAZL.sys 249856 bytes (Conexant Systems, Inc., HSF_HWAZL WDM driver) 0xC1B15000 C:\Windows\system32\DRIVERS\avgldx86.sys 245760 bytes (AVG Technologies CZ, s.r.o., AVG AVI Loader Driver) 0xC1A81000 C:\Windows\system32\DRIVERS\rdbss.sys 245760 bytes (Microsoft Corporation, Redirected Drive Buffering SubSystem Driver) 0xBA82C000 C:\Windows\system32\drivers\NETIO.SYS 241664 bytes (Microsoft Corporation, Network I/O Subsystem) 0xC1BA2000 C:\Windows\system32\DRIVERS\mrxsmb10.sys 233472 bytes (Microsoft Corporation, Longhorn SMB Downlevel SubRdr) 0xBA977000 C:\Windows\system32\drivers\volsnap.sys 233472 bytes (Microsoft Corporation, Volume Shadow Copy Driver) 0xBFA6E000 C:\Windows\system32\DRIVERS\usbhub.sys 217088 bytes (Microsoft Corporation, Default Hub Driver for USB) 0xE2DC6000 ACPI_HAL 208896 bytes 0xE2DC6000 C:\Windows\system32\hal.dll 208896 bytes (Microsoft Corporation, Hardware Abstraction Layer DLL) 0xD6A6A000 C:\Windows\System32\Drivers\RDPWD.SYS 208896 bytes (Microsoft Corporation, RDP Terminal Stack Driver) 0xBA624000 C:\Windows\system32\drivers\fltmgr.sys 204800 bytes (Microsoft Corporation, Microsoft Filesystem Filter Manager) 0xC1797000 C:\Windows\System32\DRIVERS\netbt.sys 204800 bytes (Microsoft Corporation, MBT Transport driver) 0xBF5D1000 C:\Windows\system32\DRIVERS\msiscsi.sys 192512 bytes (Microsoft Corporation, Microsoft iSCSI Initiator Driver) 0xBFB09000 C:\Windows\system32\drivers\portcls.sys 184320 bytes (Microsoft Corporation, Port Class (Class Driver for Port/Miniport Devices)) 0xBF500000 C:\Windows\system32\DRIVERS\Apfiltr.sys 180224 bytes (Alps Electric Co., Ltd., Alps Touch Pad Driver) 0xBA801000 C:\Windows\system32\drivers\msrpc.sys 176128 bytes (Microsoft Corporation, Kernel Remote Procedure Call Provider) 0xBFA2D000 C:\Windows\system32\DRIVERS\ks.sys 172032 bytes (Microsoft Corporation, Kernel CSA Library) 0xD20C7000 C:\Windows\system32\DRIVERS\nwifi.sys 172032 bytes (Microsoft Corporation, NativeWiFi Miniport Driver) 0xD6A05000 C:\Windows\system32\DRIVERS\AVGIDSDriver.Sys 163840 bytes (AVG Technologies CZ, s.r.o. , IDS Application Activity Monitor Driver.) 0xD38C5000 C:\Windows\System32\Drivers\fastfat.SYS 163840 bytes (Microsoft Corporation, Fast FAT File System Driver) 0xC17C9000 C:\Windows\System32\DRIVERS\srv2.sys 163840 bytes (Microsoft Corporation, Smb 2.0 Server driver) 0xBA9C7000 C:\Windows\System32\drivers\ecache.sys 159744 bytes (Microsoft Corporation, Special Memory Device Cache) 0xBA3C5000 C:\Windows\system32\drivers\pci.sys 159744 bytes (Microsoft Corporation, NT Plug and Play PCI Enumerator) 0xD6A2D000 C:\Windows\system32\DRIVERS\ipnat.sys 155648 bytes (Microsoft Corporation, IP Network Address Translator) 0xBA397000 C:\Windows\System32\Drivers\SCSIPORT.SYS 155648 bytes (Microsoft Corporation, SCSI Port Driver) 0xBFB36000 C:\Windows\system32\drivers\drmk.sys 151552 bytes (Microsoft Corporation, Microsoft Kernel DRM Descrambler Filter) 0xBABC1000 C:\Windows\system32\DRIVERS\ndiswan.sys 143360 bytes (Microsoft Corporation, MS PPP Framing Driver (Strong Encryption)) 0xBAA0E000 C:\Windows\system32\drivers\CLASSPNP.SYS 135168 bytes (Microsoft Corporation, SCSI Class System Dll) 0xD21B1000 C:\Windows\system32\drivers\mrxdav.sys 135168 bytes (Microsoft Corporation, Windows NT WebDav Minirdr) 0xBFB98000 C:\Windows\System32\drivers\VIDEOPRT.SYS 135168 bytes (Microsoft Corporation, Video Port Driver) 0xD21D2000 C:\Windows\system32\DRIVERS\mrxsmb.sys 126976 bytes (Microsoft Corporation, Windows NT SMB Minirdr) 0xBA606000 C:\Windows\system32\drivers\ataport.SYS 122880 bytes (Microsoft Corporation, ATAPI Driver Extension) 0xD217B000 C:\Windows\System32\DRIVERS\srvnet.sys 118784 bytes (Microsoft Corporation, Server Network driver) 0xC16F9000 C:\Windows\System32\drivers\fwpkclnt.sys 110592 bytes (Microsoft Corporation, FWP/IPsec Kernel-Mode API) 0xC1B7F000 C:\Windows\system32\drivers\luafv.sys 110592 bytes (Microsoft Corporation, LUA File Virtualization Filter Driver) 0xBF460000 C:\Windows\system32\DRIVERS\sdbus.sys 106496 bytes (Microsoft Corporation, SecureDigital Bus Driver) 0xD2198000 C:\Windows\system32\DRIVERS\bowser.sys 102400 bytes (Microsoft Corporation, NT Lan Manager Datagram Receiver Driver) 0xBF542000 C:\Windows\system32\DRIVERS\cdrom.sys 98304 bytes (Microsoft Corporation, SCSI CD-ROM Driver) 0xC1BDB000 C:\Windows\system32\DRIVERS\mrxsmb20.sys 98304 bytes (Microsoft Corporation, Longhorn SMB 2.0 Redirector) 0xC1ADC000 C:\Windows\System32\Drivers\dfsc.sys 94208 bytes (Microsoft Corporation, DFS Namespace Client Driver) 0xBEFDD000 C:\Windows\system32\DRIVERS\rasl2tp.sys 94208 bytes (Microsoft Corporation, RAS L2TP mini-port/call-manager driver) 0xD6A9D000 C:\Windows\system32\DRIVERS\cdfs.sys 90112 bytes (Microsoft Corporation, CD-ROM File System Driver) 0xC1A4A000 C:\Windows\system32\DRIVERS\pacer.sys 90112 bytes (Microsoft Corporation, QoS Packet Scheduler) 0xC1725000 C:\Windows\system32\DRIVERS\tdx.sys 90112 bytes (Microsoft Corporation, TDI Translation Driver) 0xC1AC7000 C:\Program Files\UltraISO\drivers\ISODrive.sys 86016 bytes (EZB Systems, Inc., ISO DVD/CD-ROM Device Driver) 0xBFA06000 C:\Windows\system32\DRIVERS\rassstp.sys 86016 bytes (Microsoft Corporation, RAS SSTP Miniport Call Manager) 0xBA7E2000 C:\Windows\system32\DRIVERS\raspptp.sys 81920 bytes (Microsoft Corporation, Peer-to-Peer Tunneling Protocol) 0xBF488000 C:\Windows\system32\DRIVERS\rimsptsk.sys 81920 bytes (REDC, RICOH MS Driver) 0xC173B000 C:\Windows\system32\DRIVERS\smb.sys 81920 bytes (Microsoft Corporation, SMB Transport driver) 0xBF4ED000 C:\Windows\system32\DRIVERS\i8042prt.sys 77824 bytes (Microsoft Corporation, i8042 Port Driver) 0xD20FB000 C:\Windows\system32\DRIVERS\rspndr.sys 77824 bytes (Microsoft Corporation, Link-Layer Topology Responder Driver for NDIS 6) 0xC1A6E000 C:\Windows\system32\DRIVERS\wanarp.sys 77824 bytes (Microsoft Corporation, MS Remote Access and Routing ARP Driver) 0xC1714000 C:\Windows\system32\DRIVERS\avgfwd6x.sys 69632 bytes (AVG Technologies CZ, s.r.o., AVG Filter Driver) 0xBA9EE000 C:\Windows\system32\drivers\disk.sys 69632 bytes (Microsoft Corporation, PnP Disk Driver) 0xBFAA3000 C:\Windows\System32\Drivers\NDProxy.SYS 69632 bytes (Microsoft Corporation, NDIS Proxy) 0xBA07A000 C:\Windows\system32\PSHED.dll 69632 bytes (Microsoft Corporation, Platform Specific Hardware Error Driver) 0xBF432000 C:\Windows\system32\DRIVERS\bcm4sbxp.sys 65536 bytes (Broadcom Corporation, Broadcom Corporation NDIS 5.1 ethernet driver) 0xBA656000 C:\Windows\system32\drivers\fileinfo.sys 65536 bytes (Microsoft Corporation, FileInfo Filter Driver) 0xC1AFC000 C:\Windows\system32\DRIVERS\HIDCLASS.SYS 65536 bytes (Microsoft Corporation, Hid Class Library) 0xD20B7000 C:\Windows\system32\DRIVERS\lltdio.sys 65536 bytes (Microsoft Corporation, Link-Layer Topology Mapper I/O Driver) 0xBA481000 C:\Windows\System32\drivers\mountmgr.sys 65536 bytes (Microsoft Corporation, Mount Point Manager) 0xBF442000 C:\Windows\system32\DRIVERS\ohci1394.sys 65536 bytes (Microsoft Corporation, 1394 OpenHCI Port Driver) 0xBFA1B000 C:\Windows\system32\DRIVERS\termdd.sys 65536 bytes (Microsoft Corporation, Terminal Server Driver) 0xBAB25000 C:\Windows\system32\DRIVERS\intelppm.sys 61440 bytes (Microsoft Corporation, Processor Device Driver) 0xC1B70000 C:\Windows\system32\DRIVERS\monitor.sys 61440 bytes (Microsoft Corporation, Monitor Driver) 0xBA9B8000 C:\Windows\System32\Drivers\mup.sys 61440 bytes (Microsoft Corporation, Multiple UNC Provider driver) 0xBA3EC000 C:\Windows\System32\drivers\partmgr.sys 61440 bytes (Microsoft Corporation, Partition Management Driver) 0xBABE4000 C:\Windows\system32\DRIVERS\raspppoe.sys 61440 bytes (Microsoft Corporation, RAS PPPoE mini-port/call-manager driver) 0xBEF82000 C:\Windows\system32\DRIVERS\usbehci.sys 61440 bytes (Microsoft Corporation, EHCI eUSB Miniport Driver) 0xBA40C000 C:\Windows\system32\drivers\volmgr.sys 61440 bytes (Microsoft Corporation, Volume Manager Driver) 0xBF452000 C:\Windows\system32\DRIVERS\1394BUS.SYS 57344 bytes (Microsoft Corporation, 1394 Bus Device Driver) 0xCB690000 C:\Windows\System32\cdd.dll 57344 bytes (Microsoft Corporation, Canonical Display Driver) 0xC1A60000 C:\Windows\system32\DRIVERS\netbios.sys 57344 bytes (Microsoft Corporation, NetBIOS interface driver) 0xBFBCC000 C:\Windows\System32\Drivers\Npfs.SYS 57344 bytes (Microsoft Corporation, NPFS Driver) 0xBA46C000 C:\Windows\system32\DRIVERS\PCIIDEX.SYS 57344 bytes (Microsoft Corporation, PCI IDE Bus Driver Extension) 0xBF47A000 C:\Windows\system32\DRIVERS\rimmptsk.sys 57344 bytes (REDC, RICOH MMC Driver) 0xC1B59000 C:\Windows\System32\Drivers\crashdmp.sys 53248 bytes (Microsoft Corporation, Crash Dump Driver) 0xC13BF000 C:\Windows\system32\drivers\modem.sys 53248 bytes (Microsoft Corporation, Modem Device Driver) 0xBFA61000 C:\Windows\system32\DRIVERS\umbus.sys 53248 bytes (Microsoft Corporation, User-Mode Bus Enumerator) 0xBA284000 C:\Windows\system32\drivers\WDFLDR.SYS 53248 bytes (Microsoft Corporation, WDFLDR) 0xC13CC000 C:\Windows\system32\DRIVERS\avgmfx86.sys 49152 bytes (AVG Technologies CZ, s.r.o., AVG Resident Shield Minifilter Driver) 0xD39D5000 C:\Windows\System32\drivers\tcpipreg.sys 49152 bytes (Microsoft Corporation, TCP/IP Registry Compatibility Driver) 0xD6A5E000 C:\Windows\System32\DRIVERS\tssecsrv.sys 49152 bytes (Microsoft Corporation, TS Security Filter Driver) 0xC13EF000 C:\Windows\System32\drivers\vga.sys 49152 bytes (Microsoft Corporation, VGA/Super VGA Video Driver) 0xBEF2D000 C:\Windows\System32\drivers\watchdog.sys 49152 bytes (Microsoft Corporation, Watchdog Driver) 0xD38AF000 C:\Windows\system32\DRIVERS\AVGIDSShim.Sys 45056 bytes (AVG Technologies CZ, s.r.o. , IDS Application Activity Monitor Loader Driver.) 0xBF537000 C:\Windows\system32\DRIVERS\kbdclass.sys 45056 bytes (Microsoft Corporation, Keyboard Class Driver) 0xBF52C000 C:\Windows\system32\DRIVERS\mouclass.sys 45056 bytes (Microsoft Corporation, Mouse Class Driver) 0xBFBC1000 C:\Windows\System32\Drivers\Msfs.SYS 45056 bytes (Microsoft Corporation, Mailslot driver) 0xBEFF4000 C:\Windows\system32\DRIVERS\ndistapi.sys 45056 bytes (Microsoft Corporation, NDIS 3.0 connection wrapper driver) 0xBEFD2000 C:\Windows\system32\DRIVERS\TDI.SYS 45056 bytes (Microsoft Corporation, TDI Wrapper) 0xD6A53000 C:\Windows\system32\drivers\tdtcp.sys 45056 bytes (Microsoft Corporation, TCP Transport Driver) 0xBAB11000 C:\Windows\system32\DRIVERS\tunnel.sys 45056 bytes (Microsoft Corporation, Microsoft Tunnel Interface Driver) 0xBEF39000 C:\Windows\system32\DRIVERS\usbuhci.sys 45056 bytes (Microsoft Corporation, UHCI USB Miniport Driver) 0xD39E9000 C:\Windows\system32\DRIVERS\AVGIDSFilter.Sys 40960 bytes (AVG Technologies CZ, s.r.o. , IDS Application Activity Monitor Filter Driver.) 0xBA402000 C:\Windows\system32\DRIVERS\BATTC.SYS 40960 bytes (Microsoft Corporation, Battery Class Driver) 0xC1B66000 C:\Windows\System32\drivers\Dxapi.sys 40960 bytes (Microsoft Corporation, DirectX API Driver) 0xBFA57000 C:\Windows\system32\DRIVERS\mssmbios.sys 40960 bytes (Microsoft Corporation, System Management BIOS Driver) 0xD20F1000 C:\Windows\system32\DRIVERS\ndisuio.sys 40960 bytes (Microsoft Corporation, NDIS User mode I/O driver) 0xC1ABD000 C:\Windows\system32\drivers\nsiproxy.sys 40960 bytes (Microsoft Corporation, NSI Proxy) 0xD39CB000 C:\Windows\System32\Drivers\secdrv.SYS 40960 bytes (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K., Macrovision SECURITY Driver) 0xBAA3D000 C:\Windows\system32\DRIVERS\AVGIDSEH.Sys 36864 bytes (AVG Technologies CZ, s.r.o. , IDS Application Activity Monitor Helper Driver.) 0xBAA2F000 C:\Windows\system32\drivers\crcdisk.sys 36864 bytes (Microsoft Corporation, Disk Block Verification Filter Driver) 0xC13D8000 C:\Windows\System32\Drivers\Fs_Rec.SYS 36864 bytes (Microsoft Corporation, File System Recognizer Driver) 0xC1AF3000 C:\Windows\system32\DRIVERS\hidusb.sys 36864 bytes (Microsoft Corporation, USB Miniport Driver for Input Devices) 0xD6AB3000 C:\Windows\System32\Drivers\Normandy.SYS 36864 bytes (RKU Driver) 0xBFBDA000 C:\Windows\System32\DRIVERS\rasacd.sys 36864 bytes (Microsoft Corporation, RAS Automatic Connection Driver) 0xCB670000 C:\Windows\System32\TSDDD.dll 36864 bytes (Microsoft Corporation, Framebuffer Display Driver) 0xBAB1C000 C:\Windows\system32\DRIVERS\tunmp.sys 36864 bytes (Microsoft Corporation, Microsoft Tunnel Interface Driver) 0xBF5C8000 C:\Windows\system32\DRIVERS\wmiacpi.sys 36864 bytes (Microsoft Corporation, Windows Management Interface for ACPI) 0xBA38E000 C:\Windows\System32\Drivers\WMILIB.SYS 36864 bytes (Microsoft Corporation, WMILIB WMI support library Dll) 0xBA5EF000 C:\Windows\system32\drivers\atapi.sys 32768 bytes (Microsoft Corporation, ATAPI IDE Miniport Driver) 0xBA08B000 C:\Windows\system32\BOOTVID.dll 32768 bytes (Microsoft Corporation, VGA Boot Driver) 0xC1B51000 C:\Windows\system32\DRIVERS\mouhid.sys 32768 bytes (Microsoft Corporation, HID Mouse Filter Driver) 0xBA3BD000 C:\Windows\system32\drivers\msisadrv.sys 32768 bytes (Microsoft Corporation, ISA Driver) 0xC1200000 C:\Windows\System32\DRIVERS\RDPCDD.sys 32768 bytes (Microsoft Corporation, RDP Miniport) 0xBFBB9000 C:\Windows\system32\drivers\rdpencdd.sys 32768 bytes (Microsoft Corporation, RDP Miniport) 0xBA9B0000 C:\Windows\System32\Drivers\spldr.sys 32768 bytes (Microsoft Corporation, loader for security processor) 0xD39E1000 C:\Windows\system32\DRIVERS\xaudio.sys 32768 bytes (Conexant Systems, Inc., Modem Audio Device Driver) 0xC13E8000 C:\Windows\System32\Drivers\Beep.SYS 28672 bytes (Microsoft Corporation, BEEP Driver) 0xC1B0C000 C:\Windows\system32\DRIVERS\HIDPARSE.SYS 28672 bytes (Microsoft Corporation, Hid Parsing Library) 0xBA465000 C:\Windows\system32\DRIVERS\intelide.sys 28672 bytes (Microsoft Corporation, Intel PCI IDE Driver) 0xBA003000 C:\Windows\system32\kdcom.dll 28672 bytes (Microsoft Corporation, Kernel Debugger HW Extension DLL) 0xC13E1000 C:\Windows\System32\Drivers\Null.SYS 28672 bytes (Microsoft Corporation, NULL Driver) 0xBA47A000 C:\Windows\system32\drivers\pciide.sys 28672 bytes (Microsoft Corporation, Generic PCI IDE Bus Driver) 0xBAA38000 C:\Windows\system32\DRIVERS\avgrkx86.sys 20480 bytes (AVG Technologies CZ, s.r.o., AVG Anti-Rootkit Driver) 0xBF55A000 C:\Windows\System32\Drivers\GEARAspiWDM.sys 20480 bytes (GEAR Software Inc., CD DVD Filter) 0xD38BC000 C:\Windows\system32\DRIVERS\lirsgt.sys 20480 bytes 0xBF5C4000 C:\Windows\system32\DRIVERS\CmBatt.sys 16384 bytes (Microsoft Corporation, Control Method Battery Driver) 0xD38C1000 C:\Windows\system32\DRIVERS\mdmxsdk.sys 16384 bytes (Conexant, Diagnostic Interface x86 Driver) 0xBA3FB000 C:\Windows\system32\DRIVERS\compbatt.sys 12288 bytes (Microsoft Corporation, Composite Battery Driver) 0xD38BA000 C:\Windows\system32\DRIVERS\dsunidrv.sys 8192 bytes (Gteko Ltd., GUniDriver) 0xBEE8B000 C:\Windows\system32\DRIVERS\nvBridge.kmd 8192 bytes (NVIDIA Corporation, NVIDIA Compatible Windows Vista Kernel Mode Driver, Version 258.96 ) 0xBFA2B000 C:\Windows\system32\DRIVERS\swenum.sys 8192 bytes (Microsoft Corporation, Plug and Play Software Device Enumerator) 0xC1B13000 C:\Windows\system32\DRIVERS\USBD.SYS 8192 bytes (Microsoft Corporation, Universal Serial Bus Driver) 0xB701A1F8 unknown_irp_handler 3592 bytes 0xD402B1F8 unknown_irp_handler 3592 bytes 0xB70171F8 unknown_irp_handler 3592 bytes 0xB8A5E1F8 unknown_irp_handler 3592 bytes 0xB70191F8 unknown_irp_handler 3592 bytes 0xB8AE11F8 unknown_irp_handler 3592 bytes 0xB89131F8 unknown_irp_handler 3592 bytes 0xC10C01F8 unknown_irp_handler 3592 bytes 0xC10A91F8 unknown_irp_handler 3592 bytes 0xB8A621F8 unknown_irp_handler 3592 bytes 0xB66821F8 unknown_irp_handler 3592 bytes 0xB88891F8 unknown_irp_handler 3592 bytes 0xB886D1F8 unknown_irp_handler 3592 bytes 0xB67B61F8 unknown_irp_handler 3592 bytes ============================================== >Stealth ============================================== WARNING: File locked for read access [C:\Windows\system32\drivers\sptd.sys] 📎Attach.txt
Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
I did as you said, here's the results. Malwarebytes' Anti-Malware 1.50.1.1100 www.malwarebytes.org Database version: 6315 Windows 6.0.6002 Service Pack 2 Internet Explorer 8.0.6001.19019 08/04/2011 22:42:03 mbam-log-2011-04-08 (22-42-03).txt Scan type: Quick scan Objects scanned: 171766 Time elapsed: 5 minute(s), 48 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 4 Registry Values Infected: 1 Registry Data Items Infected: 1 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A078F691-9C07-4AF2-BF43-35E79EECF8B7} (Adware.Softomate) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\473D1B29F95B96241830B6A6ADE19368 (Rogue.RegistryBot) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5A144BD76064D1645B6E74C0734EE406 (Rogue.RegistryBot) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\965DCC82BC551DF439B28676F8AB79E0 (Rogue.RegistryBot) -> Quarantined and deleted successfully. Registry Values Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\OLE\Windows Registry Name (Backdoor.IRCBot) -> Value: Windows Registry Name -> Quarantined and deleted successfully. Registry Data Items Infected: HKEY_CLASSES_ROOT\regfile\shell\open\command\(default) (Broken.OpenCommand) -> Bad: ("regedit.exe" "%1") Good: (regedit.exe "%1") -> Quarantined and deleted successfully. Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
Download and Install Combofix

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]
  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.

Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now
Hi Patndoris,

I uninstalled my AVG antivirus and the combofix scan ran. Here are the results.

ComboFix 11-04-10.01 - Eugrulz 10/04/2011 21:48:36.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.353.1033.18.2045.1202 [GMT 1:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\install.exe
c:\programdata\PCDr\5744\Downloads\2da1393a-9d2c-436b-a660-c3dd133e9836.dll
c:\programdata\PCDr\5744\Downloads\48edbc2f-6595-43d2-a911-c3713e9b499f.dll
c:\programdata\PCDr\5744\Downloads\5275e755-7d9f-4ddb-a61e-645d687f55e1.dll
c:\programdata\PCDr\5744\Downloads\86fa80c6-799b-4d0b-a3f5-f7886c10db2c.dll
c:\programdata\PCDr\5744\Downloads\f6b10855-5837-4857-9c20-c7b6a6dc2589.dll
.
.
((((((((((((((((((((((((( Files Created from 2011-03-10 to 2011-04-10 )))))))))))))))))))))))))))))))
.
.
2011-04-10 20:57 . 2011-04-10 20:57 ——– d—–w- c:\users\Default\AppData\Local\temp
2011-04-10 20:57 . 2011-04-10 20:57 ——– d—–w- c:\users\Eugrulz\AppData\Local\temp
2011-04-08 21:31 . 2011-04-08 21:31 ——– d—–w- c:\users\Eugrulz\AppData\Roaming\Malwarebytes
2011-04-08 21:31 . 2010-12-20 17:09 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-04-08 21:31 . 2011-04-08 21:31 ——– d—–w- c:\programdata\Malwarebytes
2011-04-08 21:31 . 2011-04-08 21:31 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2011-04-08 21:31 . 2010-12-20 17:08 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-04-07 10:56 . 2011-04-07 10:56 388096 —-a-r- c:\users\Eugrulz\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-04-07 10:55 . 2011-04-07 10:55 ——– d—–w- c:\program files\Trend Micro
2011-04-03 11:18 . 2011-04-03 11:18 ——– d—–w- c:\users\Eugrulz\AppData\Roaming\Intel
2011-04-03 11:18 . 2011-04-03 11:18 ——– d—–w- c:\users\Public\Roaming
2011-04-03 11:18 . 2011-04-03 11:18 ——– d—–w- c:\users\Eugrulz\Roaming
2011-04-03 11:18 . 2011-04-03 11:18 ——– d—–w- c:\users\emma\Roaming
2011-04-03 11:18 . 2011-04-03 11:18 ——– d—–w- c:\users\Default\Roaming
2011-04-03 11:18 . 2011-04-03 11:18 ——– d—–w- c:\programdata\Roaming
2011-04-03 11:17 . 2011-04-03 11:17 56 —-a-w- c:\windows\system32\IHV_Install.bat
2011-04-03 11:17 . 2011-04-03 11:17 ——– d—–w- c:\programdata\Intel
2011-04-03 11:17 . 2011-04-03 11:17 ——– d—–w- c:\program files\Cisco
2011-04-03 11:15 . 2011-04-03 11:15 ——– d—–w- c:\program files\Intel
2011-04-03 10:59 . 2011-04-03 10:59 ——– d—–w- c:\users\Eugrulz\AppData\Roaming\InstallShield
2011-04-02 19:34 . 2011-04-02 19:34 ——– d—–w- C:\inetpub
2011-04-02 18:43 . 2011-04-02 18:43 ——– d—–w- c:\users\Eugrulz\AppData\Local\BVRP Software
2011-04-02 12:32 . 2011-04-02 12:32 2560 —-a-w- c:\windows\_MSRSTRT.EXE
2011-04-01 23:42 . 2011-03-18 17:57 142296 —-a-w- c:\program files\Mozilla Firefox\components\browsercomps.dll
2011-04-01 23:42 . 2011-03-18 17:57 781272 —-a-w- c:\program files\Mozilla Firefox\mozsqlite3.dll
2011-04-01 23:42 . 2011-03-18 17:57 728024 —-a-w- c:\program files\Mozilla Firefox\libGLESv2.dll
2011-04-01 23:42 . 2011-03-18 17:57 1893336 —-a-w- c:\program files\Mozilla Firefox\d3dx9_42.dll
2011-04-01 23:42 . 2011-03-18 17:57 1874904 —-a-w- c:\program files\Mozilla Firefox\mozjs.dll
2011-04-01 23:42 . 2011-03-18 17:57 15832 —-a-w- c:\program files\Mozilla Firefox\mozalloc.dll
2011-04-01 23:42 . 2011-03-18 17:57 142296 —-a-w- c:\program files\Mozilla Firefox\libEGL.dll
2011-04-01 23:42 . 2011-03-18 17:57 1975768 —-a-w- c:\program files\Mozilla Firefox\D3DCompiler_42.dll
2011-04-01 14:14 . 2011-04-02 12:15 ——– d—–w- c:\program files\Panda Security
2011-04-01 09:22 . 2011-03-15 04:05 6792528 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{2D96003E-AF6B-497C-8DF4-7081AE752C76}\mpengine.dll
2011-03-30 11:21 . 2011-03-30 11:28 ——– d—–w- C:\Project69_Cache
2011-03-26 10:45 . 2011-03-26 13:04 ——– d—–w- C:\MyAudio
2011-03-26 10:40 . 2011-03-26 10:40 ——– d—–w- c:\windows\Sun
2011-03-24 22:41 . 2011-04-03 11:18 ——– d—–w- c:\users\USEFUL STUFF
2011-03-23 21:54 . 2011-03-23 21:54 ——– d—–w- c:\program files\XCC
2011-03-23 19:10 . 2011-04-02 12:14 ——– d—–w- c:\program files\FinalAlert 2 Yuri's Revenge
2011-03-23 11:02 . 2011-02-22 13:33 1068544 —-a-w- c:\windows\system32\DWrite.dll
2011-03-23 11:02 . 2011-02-22 14:13 288768 —-a-w- c:\windows\system32\XpsGdiConverter.dll
2011-03-23 11:02 . 2011-02-22 13:33 797696 —-a-w- c:\windows\system32\FntCache.dll
2011-03-15 15:41 . 2011-04-03 11:18 ——– d—–w- c:\users\Administrator
2011-03-15 11:30 . 2011-03-15 11:30 ——– d—–w- c:\program files\Common Files\Adobe
2011-03-15 11:29 . 2011-03-15 11:30 ——– d—–w- c:\users\Default\AppData\Local\Adobe
2011-03-15 11:12 . 2011-04-01 23:43 ——– d—–w- c:\windows\Patches
2011-03-14 23:48 . 2011-03-14 23:48 ——– d—–w- c:\windows\3F67FD4A380F4081A5061D2C0091A93E.TMP
2011-03-14 23:44 . 2011-03-14 23:44 ——– d—–w- c:\program files\Common Files\GFI
2011-03-14 23:31 . 2011-04-02 14:23 ——– d—–w- c:\program files\GFI
2011-03-12 22:40 . 2011-03-12 22:40 ——– d—–w- c:\users\Eugrulz\AppData\Local\DDMSettings
2011-03-12 22:33 . 2011-04-06 11:23 ——– d—–w- c:\program files\DivX
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-03-01 22:20 . 2011-03-01 22:20 249856 ——w- c:\windows\Setup1.exe
2011-03-01 22:20 . 2011-03-01 22:20 73216 —-a-w- c:\windows\ST6UNST.EXE
2011-02-02 21:40 . 2010-04-26 12:53 472808 —-a-w- c:\windows\system32\deployJava1.dll
2011-02-02 18:11 . 2010-07-29 08:25 222080 ——w- c:\windows\system32\MpSigStub.exe
2011-01-20 16:37 . 2011-02-09 17:28 638336 —-a-w- c:\windows\system32\drivers\dxgkrnl.sys
2011-01-20 16:08 . 2011-02-09 17:28 478720 —-a-w- c:\windows\system32\dxgi.dll
2011-01-20 16:08 . 2011-02-09 17:28 219648 —-a-w- c:\windows\system32\d3d10_1core.dll
2011-01-20 16:08 . 2011-02-09 17:28 160768 —-a-w- c:\windows\system32\d3d10_1.dll
2011-01-20 16:08 . 2011-02-09 17:28 1029120 —-a-w- c:\windows\system32\d3d10.dll
2011-01-20 16:08 . 2011-02-09 17:28 189952 —-a-w- c:\windows\system32\d3d10core.dll
2011-01-20 16:07 . 2011-02-09 17:28 37376 —-a-w- c:\windows\system32\cdd.dll
2011-01-20 16:07 . 2011-02-09 17:28 258048 —-a-w- c:\windows\system32\winspool.drv
2011-01-20 16:07 . 2011-02-09 17:28 586240 —-a-w- c:\windows\system32\stobject.dll
2011-01-20 16:06 . 2011-02-09 17:28 2873344 —-a-w- c:\windows\system32\mf.dll
2011-01-20 16:06 . 2011-02-09 17:28 26112 —-a-w- c:\windows\system32\printfilterpipelineprxy.dll
2011-01-20 16:04 . 2011-02-09 17:28 209920 —-a-w- c:\windows\system32\mfplat.dll
2011-01-20 16:04 . 2011-02-09 17:28 98816 —-a-w- c:\windows\system32\mfps.dll
2011-01-20 14:28 . 2011-02-09 17:28 1554432 —-a-w- c:\windows\system32\xpsservices.dll
2011-01-20 14:27 . 2011-02-09 17:28 876032 —-a-w- c:\windows\system32\XpsPrint.dll
2011-01-20 14:26 . 2011-02-09 17:28 667648 —-a-w- c:\windows\system32\printfilterpipelinesvc.exe
2011-01-20 14:25 . 2011-02-09 17:28 847360 —-a-w- c:\windows\system32\OpcServices.dll
2011-01-20 14:24 . 2011-02-09 17:28 135680 —-a-w- c:\windows\system32\XpsRasterService.dll
2011-01-20 14:15 . 2011-02-09 17:28 979456 —-a-w- c:\windows\system32\MFH264Dec.dll
2011-01-20 14:14 . 2011-02-09 17:28 357376 —-a-w- c:\windows\system32\MFHEAACdec.dll
2011-01-20 14:14 . 2011-02-09 17:28 302592 —-a-w- c:\windows\system32\mfmp4src.dll
2011-01-20 14:14 . 2011-02-09 17:28 261632 —-a-w- c:\windows\system32\mfreadwrite.dll
2011-01-20 14:12 . 2011-02-09 17:28 1172480 —-a-w- c:\windows\system32\d3d10warp.dll
2011-01-20 14:11 . 2011-02-09 17:28 486400 —-a-w- c:\windows\system32\d3d10level9.dll
2011-01-20 13:47 . 2011-02-09 17:28 683008 —-a-w- c:\windows\system32\d2d1.dll
2011-03-18 17:57 . 2011-04-01 23:42 142296 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
2007-03-09 07:12 27648 –sha-w- c:\windows\System32\AVSredirect.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-02-13 486856]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2007-04-18 159744]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-10-03 81920]
"NVHotkey"="c:\windows\system32\nvHotkey.dll" [2010-07-09 261736]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe" [2006-10-03 221184]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2011-03-21 1230704]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
QuickSet.lnk - c:\program files\Dell\QuickSet\quickset.exe [2008-2-22 1193240]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer"=wdmaud.drv
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Digital Line Detect.lnk]
backup=c:\windows\pss\Digital Line Detect.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKLM\~\startupfolder\C:^Users^Eugrulz^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.1.lnk]
backup=c:\windows\pss\OpenOffice.org 3.1.lnk.Startup
backupExtension=.Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-09-21 18:37 932288 —-a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2011-01-22 05:05 40368 —-a-w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AppleSyncNotifier]
2010-03-16 20:58 47392 —-a-w- c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2008-02-13 23:09 486856 —-a-w- c:\program files\DAEMON Tools Lite\daemon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ECenter]
2007-05-25 06:03 17920 —-a-w- c:\dell\E-Center\EULALauncher.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCMService]
2007-04-16 15:10 184320 ——w- c:\program files\Dell\MediaDirect\PCMService.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-12-25 09:34 421888 —-a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2010-06-21 12:56 202256 —-a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"FirewallOverride"=dword:00000001
.
R0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [x]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 DrmRDriverV32;DrmRDriverV32;c:\windows\system32\drivers\DrmRDriverV32.sys [2007-12-24 23096]
R3 DrmRVideo32;DrmRVideo32;c:\windows\system32\DRIVERS\DrmRVideo32.sys [2007-12-24 3768]
R3 PCDSRVC{E9D79540-57D5953E-06020101}_0;PCDSRVC{E9D79540-57D5953E-06020101}_0 - PCDR Kernel Mode Service Helper Driver;c:\program files\dell support center\pcdsrvc.pkms [2010-11-18 21744]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2008-02-14 716272]
S2 AESTFilters;Andrea ST Filters Service;c:\windows\system32\aestsrv.exe [2007-09-20 73728]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder
.
2011-03-19 c:\windows\Tasks\PCDoctorBackgroundMonitorTask.job
- c:\program files\Dell Support Center\uaclauncher.exe [2010-11-18 15:13]
.
2011-04-10 c:\windows\Tasks\SystemToolsDailyTest.job
- c:\program files\Dell Support Center\pcdrcui.exe [2010-11-18 15:13]
.
.
——- Supplementary Scan ——-
.
FF - ProfilePath - c:\users\Eugrulz\AppData\Roaming\Mozilla\Firefox\Profiles\567jb457.default\
FF - prefs.js: browser.search.selectedEngine - AVG Secure Search
FF - prefs.js: browser.startup.homepage - www.yahoo.ie
FF - prefs.js: keyword.URL - hxxp://search.avg.com/route/?d=4d95b238&v;=6.103.018.001&i;=23&tp;=ab&iy;=&ychte;=us&lng;=en-GB&q;=
.
- - - - ORPHANS REMOVED - - - -
.
URLSearchHooks-{A3BC75A2-1F87-4686-AA43-5347D756017C} - (no file)
Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
HKLM-Run-SigmatelSysTrayApp - %ProgramFiles%\SigmaTel\C-Major Audio\WDM\sttray.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-04-10 21:57
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PCDSRVC{E9D79540-57D5953E-06020101}_0]
"ImagePath"="\??\c:\program files\dell support center\pcdsrvc.pkms"
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-3127798504-1892947320-518830544-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:37,19,d6,63,56,66,43,50,7b,f1,58,57,b9,ea,77,c1,78,3c,af,5e,ec,6b,e2,
24,f3,11,7c,ff,61,c2,53,4b,e0,25,fb,71,9b,93,dc,03,8a,50,29,14,e3,cd,63,ef,\
"??"=hex:a1,5e,47,db,25,65,bb,27,8b,92,55,34,10,3f,d9,49
.
[HKEY_USERS\S-1-5-21-3127798504-1892947320-518830544-1000\Software\SecuROM\License information*]
"datasecu"=hex:77,18,1c,46,16,1e,3b,f7,4f,e0,75,49,67,d7,8f,c1,15,9f,05,15,9c,
06,d6,f5,9d,4a,f8,51,63,b3,dc,3e,20,b4,90,1f,d0,18,ff,bc,db,4d,89,57,47,63,\
"rkeysecu"=hex:27,14,5d,c0,8d,38,37,a6,c5,13,56,73,1c,14,84,9f
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:00000057
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2011-04-10 22:00:41
ComboFix-quarantined-files.txt 2011-04-10 21:00
.
Pre-Run: 50,125,402,112 bytes free
Post-Run: 50,343,251,968 bytes free
.
- - End Of File - - 6922352B9BF81837FF2F8350D7EABDED


My computer seems to be running fine. Thanks for the help :)
I'm glad to hear things are running better. We still have a little more to do so please stick with me.


We need some file informantion
  • Make sure to use Internet Explorer for this
  • Please go to: VirusTotal

    [external image: Posted Image]
  • Copy and paste the following file path, one at a time if more than file is listed, into the box next to "Browse" in the middle of the page:


    c:\windows\Setup1.exe
  • Then click Send File
  • Please be patient while the file is scanned.
  • Please ensure the scan is complete and the results saved before submitting the next.
  • If a notice appears saying the file has been scanned already, please select Reanalyze now.
  • Once the Scan is completed, Copy and Paste the results of each scan into your next reply.
When i click on the virustotal link its says the link is broken so i typed www.virustotal.com into my url but it won't let me paste the file into the box beside browse.
Alright i clicked browse and found the file on my computer but when i click send in internet explorer an error comes in the bottom left hand corner. It says 'tagname is null or not an object'
That seems to be some kind of a scripting error from what I can find. It's hard for me to tell if that is related to your browser or the webpage itself. Let's try a different scanner.


Please go to http://virusscan.jotti.org, click on Browse, and upload the following file for analysis:

c:\windows\Setup1.exe

Then click Submit. Allow the file to be scanned, and then please copy and paste the results here for me to see.
  • Then click Send File
  • Please be patient while the file is scanned.
  • Please ensure the scan is complete and the results saved before submitting the next.
  • If a notice appears saying the file has been scanned already, please select Reanalyze now.
  • Once the Scan is completed, Copy and Paste the results of each scan into your next reply.
Yeah that site worked. Here are the results. Jotti's malware scan Filename: Setup1.exe Status: Scan finished. 0 out of 20 scanners reported malware. Scan taken on: Mon 11 Apr 2011 11:44:18 (CET) Permalink Additional info File size: 249856 bytes Filetype: PE32 executable for MS Windows (GUI) Intel 80386 32-bit MD5: c6264b17629f6f9f0bd2ba7671ceff69 SHA1: 67a6b419740c1d6b780789bffcfcc83129e36d1b Scanners 2011-04-11 Found nothing 2011-04-11 Found nothing 2011-04-11 Found nothing 2011-04-11 Found nothing 2011-04-11 Found nothing 2011-04-11 Found nothing 2011-04-11 Found nothing 2011-04-11 Found nothing 2011-04-11 Found nothing 2011-04-10 Found nothing 2011-04-10 Found nothing 2011-04-10 Found nothing 2011-04-11 Found nothing 2011-04-11 Found nothing 2011-04-11 Found nothing 2011-04-11 Found nothing 2011-04-11 Found nothing 2011-04-10 Found nothing 2011-04-10 Found nothing 2011-04-10 Found nothing
If you haven't already done so, please reinstall your AVG.


Since you already have Malwarebytes already on your machine, let's do another quick scan to make sure we are clear there.. Please run it by right clicking and choosing run as administrator on the icon on the desktop.
  • Click on the tab labeled Update and then click on the button Check for updates.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.



Go here to run an online scannner from ESET.
  • Note: You will need to use Internet explorer for this scan
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • Use notepad to open the logfile located at C:\Program Files\Eset\Eset Online Scanner\log.txt
  • Copy and paste that log as a reply to this topic and also let me know how things are now.
Here are the scan results. Malwarebytes' Anti-Malware 1.50.1.1100 www.malwarebytes.org Database version: 6331 Windows 6.0.6002 Service Pack 2 Internet Explorer 8.0.6001.19019 11/04/2011 13:23:34 mbam-log-2011-04-11 (13-23-34).txt Scan type: Quick scan Objects scanned: 179830 Time elapsed: 7 minute(s), 42 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) ESETSmartInstaller@High as CAB hook log: OnlineScanner.ocx - registred OK # version=7 # iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339) # OnlineScanner.ocx=1.0.0.6425 # api_version=3.0.2 # EOSSerial=f8c6af162523914cad94312c76280890 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=true # antistealth_checked=true # utc_time=2011-04-11 03:46:07 # local_time=2011-04-11 04:46:07 (+0000, GMT Daylight Time) # country="Ireland" # lang=1033 # osver=6.0.6002 NT Service Pack 2 # compatibility_mode=512 16777215 100 0 351295 351295 0 0 # compatibility_mode=1032 16777213 100 97 10733 45815445 0 0 # compatibility_mode=5892 16776574 100 100 875297 140057781 0 0 # compatibility_mode=8192 67108863 100 0 176 176 0 0 # scanned=270239 # found=6 # cleaned=0 # scan_time=11713 C:\ProgramData\Spybot - Search & Destroy\Recovery\WinPhdet.zip Win32/Bagle.gen.zip worm (unable to clean) 00000000000000000000000000000000 I C:\ProgramData\Spybot - Search & Destroy\Recovery\WinPhdet1.zip Win32/Bagle.gen.zip worm (unable to clean) 00000000000000000000000000000000 I C:\ProgramData\Spybot - Search & Destroy\Recovery\WinPhdet2.zip Win32/Bagle.gen.zip worm (unable to clean) 00000000000000000000000000000000 I C:\Users\All Users\Spybot - Search & Destroy\Recovery\WinPhdet.zip Win32/Bagle.gen.zip worm (unable to clean) 00000000000000000000000000000000 I C:\Users\All Users\Spybot - Search & Destroy\Recovery\WinPhdet1.zip Win32/Bagle.gen.zip worm (unable to clean) 00000000000000000000000000000000 I C:\Users\All Users\Spybot - Search & Destroy\Recovery\WinPhdet2.zip Win32/Bagle.gen.zip worm (unable to clean) 00000000000000000000000000000000 I My computers running great :thumbup:

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI