This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Trojan Horse Agent_r.ARN

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Getting Ping.exe living in memory and re directions to malware sites. Running AVG 2012 on XP . DDS (Ver_2011-08-26.01) - NTFSx86 Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_22 Run by [removed] at 18:38:06 on 2011-11-13 . ============== Running Processes =============== . \??\C:\PROGRA~1\AVG\AVG2012\avgrsx.exe \??\C:\Program Files\AVG\AVG2012\avgcsrvx.exe C:\WINDOWS\system32\brsvc01a.exe C:\WINDOWS\system32\brss01a.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\AVG\AVG2012\avgwdsvc.exe C:\WINDOWS\system32\FsUsbExService.Exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\Program Files\CyberLink\Shared Files\RichVideo.exe C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\8.0.1\ToolbarUpdater.exe C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe C:\WINDOWS\Explorer.EXE C:\Program Files\AVG\AVG2012\avgnsx.exe C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe C:\Program Files\CyberLink\PCM4Everio\EverioService.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Program Files\Browny02\Brother\BrStMonW.exe C:\Program Files\DivX\DivX Update\DivXUpdate.exe C:\Program Files\AVG\AVG2012\avgtray.exe C:\Program Files\AVG Secure Search\vprot.exe C:\WINDOWS\System32\alg.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Brother\ControlCenter3\brccMCtl.exe C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe C:\WINDOWS\system32\wscntfy.exe C:\Program Files\Skype\Phone\Skype.exe C:\Program Files\Browny02\BrYNSvc.exe C:\Program Files\WinZip\WZQKPICK.EXE C:\Program Files\AVG\AVG2012\avgui.exe C:\Program Files\AVG\AVG2012\avgscanx.exe \??\C:\Program Files\AVG\AVG2012\avgcsrvx.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Mozilla Firefox\plugin-container.exe C:\WINDOWS\system32\taskmgr.exe C:\WINDOWS\System32\ping.exe C:\Documents and Settings\JimC\Desktop\dds.scr C:\WINDOWS\system32\wbem\wmiprvse.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\System32\svchost.exe -k NetworkService C:\WINDOWS\System32\svchost.exe -k LocalService C:\WINDOWS\System32\svchost.exe -k LocalService C:\WINDOWS\System32\svchost.exe -k imgsvc . ============== Pseudo HJT Report =============== . mURLSearchHooks: H - No File BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg2012\avgssie.dll BHO: AVG Security Toolbar: {95b7759c-8c7f-4bf1-b163-73684a933233} - c:\program files\avg secure search\8.0.0.40\AVG Secure Search_toolbar.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.7.6406.1642\swg.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll TB: AVG Security Toolbar: {95b7759c-8c7f-4bf1-b163-73684a933233} - c:\program files\avg secure search\8.0.0.40\AVG Secure Search_toolbar.dll TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File {e7df6bff-55a5-4eb7-a673-4ed3e9456d39} EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File uRun: [CTFMON.EXE] c:\windows\system32\ctfmon.exe uRun: [TomTomHOME.exe] "c:\program files\tomtom home 2\TomTomHOMERunner.exe" uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe uRun: [AutoStartNPSAgent] c:\program files\samsung\samsung new pc studio\NPSAgent.exe uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized uRun: [{3945838D-6092-83E4-B5C6-8A7E7025933E}] "c:\documents and settings\jimc\application data\ykwaad\unadmio.exe" mRun: [HDAudDeck] c:\program files\via\viaudioi\hdadeck\HDeck.exe 1 mRun: [RemoteControl] "c:\program files\cyberlink\powerdvd\PDVDServ.exe" mRun: [SetDefPrt] c:\program files\brother\brmfl05a\BrStDvPt.exe mRun: [ControlCenter2.0] c:\program files\brother\controlcenter2\brctrcen.exe /autorun mRun: [EverioService] "c:\program files\cyberlink\pcm4everio\EverioService.exe" mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe" mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [ControlCenter3] c:\program files\brother\controlcenter3\brctrcen.exe /autorun mRun: [BrStsMon00] c:\program files\browny02\brother\BrStMonW.exe /AUTORUN mRun: [NPSStartup] mRun: [DivXUpdate] "c:\program files\divx\divx update\DivXUpdate.exe" /CHECKNOW mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [AVG_TRAY] "c:\program files\avg\avg2012\avgtray.exe" mRun: [vProt] "c:\program files\avg secure search\vprot.exe" dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000 IE: Google Sidewiki… - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL LSP: mswsock.dll Trusted Zone: microsoft.com\office Trusted Zone: microsoft.com\www.update DPF: {33564D57-0000-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} - hxxp://catalog.update.microsoft.com/v7/site/ClientControl/en/x86/MuCatalogWebControl.cab?1305195582859 DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1304946733312 DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab TCP: DhcpNameServer = 192.168.1.1 TCP: Interfaces\{844C344C-ADA9-4FE7-B9D9-94C2DC838E96} : DhcpNameServer = 192.168.1.1 Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg2012\avgpp.dll Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files\common files\avg secure search\viprotocolinstaller\8.0.1\ViProtocol.dll Notify: AtiExtEvent - Ati2evxx.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll . ================= FIREFOX =================== . FF - ProfilePath - c:\documents and settings\jimc\application data\mozilla\firefox\profiles\2k3czex1.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2769714&SearchSource=3&q={searchTerms} FF - prefs.js: browser.search.selectedEngine - AVG Secure Search FF - prefs.js: browser.startup.homepage - hxxp://www.google.com.au/ FF - prefs.js: keyword.URL - hxxp://search.avg.com/route/?d=4b89b5d1&v=6.010.006.004&i=23&tp=ab&iy=&ychte=au&lng=en-GB&q= FF - component: c:\documents and settings\jimc\application data\mozilla\firefox\profiles\2k3czex1.default\extensions\{e7f7b7dc-7dec-4e84-9a87-ece02e8a160a}\components\RadioWMPCoreGecko19.dll FF - component: c:\documents and settings\jimc\application data\mozilla\firefox\profiles\2k3czex1.default\extensions\[removed]\components\RadioWMPCoreGecko19.dll FF - component: c:\program files\avg\avg9\firefox\components\avgssff.dll FF - component: c:\program files\avg\avg9\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll FF - component: c:\program files\avg\avg9\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll FF - component: c:\program files\avg\avg9\toolbar\firefox\avg@igeared\components\xpavgtbapi.dll FF - component: c:\program files\mozilla firefox\extensions\{82af8dca-6de9-405d-bd5e-43525bdad38a}\components\SkypeFfComponent.dll FF - plugin: c:\documents and settings\jimc\application data\facebook\npfbplugin_1_0_3.dll FF - plugin: c:\program files\adobe\reader 9.0\reader\air\nppdf32.dll FF - plugin: c:\program files\divx\divx ovs helper\npovshelper.dll FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll FF - plugin: c:\program files\google\update\1.3.21.79\npGoogleUpdate3.dll FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll . —- FIREFOX POLICIES —- FF - user.js: network.cookie.cookieBehavior - 0 FF - user.js: privacy.clearOnShutdown.cookies - false FF - user.js: security.warn_viewing_mixed - false FF - user.js: security.warn_viewing_mixed.show_once - false FF - user.js: security.warn_submit_insecure - false FF - user.js: security.warn_submit_insecure.show_once - false . ============= SERVICES / DRIVERS =============== . R? gupdate;Google Update Service (gupdate) R? gupdatem;Google Update Service (gupdatem) R? sscebus;SAMSUNG USB Composite Device V2 driver (WDM) R? sscemdfl;SAMSUNG Mobile Modem V2 Filter R? sscemdm;SAMSUNG Mobile Modem V2 Drivers S? AVGIDSAgent;AVGIDSAgent S? AVGIDSDriver;AVGIDSDriver S? AVGIDSEH;AVGIDSEH S? AVGIDSFilter;AVGIDSFilter S? AVGIDSShim;AVGIDSShim S? Avgldx86;AVG AVI Loader Driver S? Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield S? Avgrkx86;AVG Anti-Rootkit Driver S? Avgtdix;AVG TDI Driver S? avgwd;AVG WatchDog S? BrYNSvc;BrYNSvc S? FsUsbExDisk;FsUsbExDisk S? FsUsbExService;FsUsbExService S? TomTomHOMEService;TomTomHOMEService S? VIAHdAudAddService;VIA High Definition Audio Driver Service S? vToolbarUpdater;vToolbarUpdater . =============== Created Last 30 ================ . 2011-11-13 07:35:08 ——– d—–w- c:\documents and settings\jimc\application data\Ykwaad 2011-11-13 07:35:08 ——– d—–w- c:\documents and settings\jimc\application data\Oqpys 2011-11-13 06:38:53 ——– d—–w- c:\documents and settings\jimc\application data\Haeciv 2011-11-13 06:38:53 ——– d—–w- c:\documents and settings\jimc\application data\Azyrud 2011-11-10 02:42:03 ——– d—–w- c:\windows\system32\cache 2011-11-08 11:10:12 ——– d—–w- C:\PEOPLES BEACH 2011-11-01 11:41:16 13865152 —-a-w- c:\program files\Firefox Setup 7.0.1.exe 2011-10-27 06:25:01 ——– d—–w- c:\documents and settings\jimc\application data\Origin 2011-10-27 06:24:41 ——– d—–w- c:\documents and settings\jimc\local settings\application data\Origin 2011-10-27 06:24:19 ——– d—–w- c:\program files\Origin Games 2011-10-27 06:24:19 ——– d—–w- c:\documents and settings\all users\application data\Origin 2011-10-27 06:24:19 ——– d—–w- c:\documents and settings\all users\application data\Electronic Arts 2011-10-27 06:23:46 ——– d—–w- c:\program files\Origin 2011-10-27 06:11:09 ——– d—–w- C:\Games . ==================== Find3M ==================== . 2011-11-01 21:42:35 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2011-10-06 22:23:48 230608 —-a-w- c:\windows\system32\drivers\avgldx86.sys 2011-10-03 22:21:42 16720 —-a-w- c:\windows\system32\drivers\AVGIDSShim.sys 2011-09-12 22:30:10 32592 —-a-w- c:\windows\system32\drivers\avgrkx86.sys 2011-01-25 10:14:41 395640 —-a-w- c:\program files\utorrent.exe 2010-12-26 08:17:50 568648 —-a-w- c:\program files\GoogleEarthSetup.exe 2010-12-17 06:48:22 173838160 —-a-w- c:\program files\New_PC_Studio_1.5.1.10064_2.exe 2009-10-06 12:33:39 93074728 —-a-w- c:\program files\iTunesSetup.exe . ============= FINISH: 18:51:45.03 ===============

Attachments:

Hi there I have two analysis programmes to run to confirm the infection type

Download OTL to your Desktop
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Select All Users
  • Under the Custom Scan box paste this in
    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    explorer.exe
    winlogon.exe
    Userinit.exe
    svchost.exe
    /md5stop
    C:\Windows\assembly\tmp\U\*.* /s
    CREATERESTOREPOINT
  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Post both logs

THEN

Download aswMBR.exe ( 1.8mb ) to your desktop.
Double click the aswMBR.exe to run it Click the "Scan" button to start scan

[external image: Posted Image]

On completion of the scan click save log, save it to your desktop and post in your next reply

[external image: Posted Image]
As requested, the created files.

Thanks for the help…..

OTL logfile created on: 15/11/2011 8:15:41 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\JimC\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy

1.99 Gb Total Physical Memory | 0.99 Gb Available Physical Memory | 49.89% Memory free
3.84 Gb Paging File | 2.78 Gb Available in Paging File | 72.38% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 195.31 Gb Total Space | 136.23 Gb Free Space | 69.75% Space Free | Partition Type: NTFS
Drive D: | 270.45 Gb Total Space | 264.09 Gb Free Space | 97.65% Space Free | Partition Type: NTFS
Drive E: | 200.79 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive H: | 298.02 Gb Total Space | 274.36 Gb Free Space | 92.06% Space Free | Partition Type: FAT32

Computer Name: JMCAIRNS | User Name: JimC | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/11/15 20:14:45 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\JimC\Desktop\OTL.exe
PRC - [2011/11/11 09:34:36 | 000,924,632 | —- | M] (Mozilla Corporation) – C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2011/10/24 20:29:16 | 002,415,456 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG2012\avgtray.exe
PRC - [2011/10/18 06:14:54 | 001,229,152 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG2012\avgnsx.exe
PRC - [2011/10/13 10:52:02 | 000,246,600 | —- | M] () – C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\8.0.1\ToolbarUpdater.exe
PRC - [2011/10/13 10:52:01 | 000,218,440 | —- | M] () – C:\Program Files\AVG Secure Search\vprot.exe
PRC - [2011/10/12 06:25:22 | 004,433,248 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe
PRC - [2011/09/08 20:53:26 | 000,743,264 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG2012\avgrsx.exe
PRC - [2011/08/15 06:21:40 | 000,337,760 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG2012\avgcsrvx.exe
PRC - [2011/08/02 06:09:08 | 000,192,776 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG2012\avgwdsvc.exe
PRC - [2011/04/15 15:50:00 | 000,610,120 | R— | M] (WinZip Computing, S.L.) – C:\Program Files\WinZip\WZQKPICK.EXE
PRC - [2011/03/22 05:10:00 | 001,230,704 | —- | M] () – C:\Program Files\DivX\DivX Update\DivXUpdate.exe
PRC - [2010/07/04 19:13:56 | 000,095,576 | —- | M] (Samsung Electronics Co., Ltd.) – C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe
PRC - [2010/07/04 19:07:40 | 000,238,952 | —- | M] (Teruten) – C:\WINDOWS\system32\FsUsbExService.Exe
PRC - [2010/02/09 16:43:16 | 002,621,440 | R— | M] (Brother Industries, Ltd.) – C:\Program Files\Browny02\Brother\BrStMonW.exe
PRC - [2010/01/25 08:22:56 | 000,245,760 | —- | M] (Brother Industries, Ltd.) – C:\Program Files\Browny02\BrYNSvc.exe
PRC - [2009/03/18 08:03:02 | 000,251,240 | —- | M] (TomTom) – C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe
PRC - [2009/03/18 08:03:02 | 000,092,008 | —- | M] (TomTom) – C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
PRC - [2008/04/14 05:42:32 | 000,017,920 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\ping.exe
PRC - [2008/04/14 05:42:20 | 001,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
PRC - [2007/11/01 17:13:26 | 000,151,552 | —- | M] (CyberLink Corp.) – C:\Program Files\CyberLink\PCM4Everio\EverioService.exe


========== Modules (No Company Name) ==========

MOD - [2011/11/11 09:34:35 | 001,989,592 | —- | M] () – C:\Program Files\Mozilla Firefox\mozjs.dll
MOD - [2011/11/02 05:42:35 | 008,522,400 | —- | M] () – C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
MOD - [2011/10/13 10:52:02 | 000,246,600 | —- | M] () – C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\8.0.1\ToolbarUpdater.exe
MOD - [2011/10/13 10:52:01 | 000,218,440 | —- | M] () – C:\Program Files\AVG Secure Search\vprot.exe
MOD - [2011/03/22 05:10:36 | 000,096,112 | —- | M] () – C:\Program Files\DivX\DivX Update\DivXUpdateCheck.dll
MOD - [2011/03/22 05:10:00 | 001,230,704 | —- | M] () – C:\Program Files\DivX\DivX Update\DivXUpdate.exe
MOD - [2009/02/27 16:38:20 | 000,139,264 | R— | M] () – C:\Program Files\Brother\BrUtilities\BrLogAPI.dll
MOD - [2008/06/21 00:02:47 | 000,245,248 | —- | M] () – \\?\globalroot\systemroot\system32\mswsock.dll
MOD - [2008/06/21 00:02:47 | 000,245,248 | —- | M] () – \\.\globalroot\systemroot\system32\mswsock.dll
MOD - [2008/04/14 05:42:00 | 000,014,336 | —- | M] () – C:\WINDOWS\system32\msdmo.dll
MOD - [2008/04/14 05:41:52 | 000,059,904 | —- | M] () – C:\WINDOWS\system32\devenum.dll
MOD - [2007/11/01 17:13:08 | 000,012,288 | —- | M] () – C:\Program Files\CyberLink\PCM4Everio\Kernel\common\CLEverioDetector.dll
MOD - [2007/07/12 21:33:58 | 000,087,552 | —- | M] () – C:\WINDOWS\system32\cpwmon2k.dll


========== Win32 Services (SafeList) ==========

SRV - [2011/10/13 10:52:02 | 000,246,600 | —- | M] () [Auto | Running] – C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\8.0.1\ToolbarUpdater.exe – (vToolbarUpdater)
SRV - [2011/10/12 06:25:22 | 004,433,248 | —- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] – C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe – (AVGIDSAgent)
SRV - [2011/08/02 06:09:08 | 000,192,776 | —- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] – C:\Program Files\AVG\AVG2012\avgwdsvc.exe – (avgwd)
SRV - [2010/07/04 19:07:40 | 000,238,952 | —- | M] (Teruten) [Auto | Running] – C:\WINDOWS\system32\FsUsbExService.Exe – (FsUsbExService)
SRV - [2010/01/25 08:22:56 | 000,245,760 | —- | M] (Brother Industries, Ltd.) [On_Demand | Running] – C:\Program Files\Browny02\BrYNSvc.exe – (BrYNSvc)
SRV - [2009/03/18 08:03:02 | 000,092,008 | —- | M] (TomTom) [Auto | Running] – C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe – (TomTomHOMEService)


========== Driver Services (SafeList) ==========

DRV - [2011/10/07 06:23:48 | 000,230,608 | —- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\avgldx86.sys – (Avgldx86)
DRV - [2011/10/04 06:21:42 | 000,016,720 | —- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\AVGIDSShim.sys – (AVGIDSShim)
DRV - [2011/09/13 06:30:10 | 000,032,592 | —- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] – C:\WINDOWS\system32\DRIVERS\avgrkx86.sys – (Avgrkx86)
DRV - [2011/08/08 06:08:58 | 000,040,016 | —- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] – C:\WINDOWS\system32\drivers\avgmfx86.sys – (Avgmfx86)
DRV - [2011/07/11 01:14:38 | 000,295,248 | —- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\avgtdix.sys – (Avgtdix)
DRV - [2011/07/11 01:14:28 | 000,024,272 | —- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\AVGIDSFilter.sys – (AVGIDSFilter)
DRV - [2011/07/11 01:14:28 | 000,023,120 | —- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys – (AVGIDSEH)
DRV - [2011/07/11 01:14:26 | 000,134,608 | —- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\AVGIDSDriver.sys – (AVGIDSDriver)
DRV - [2010/12/17 14:13:11 | 000,005,632 | —- | M] () [File_System | System | Running] – C:\WINDOWS\System32\drivers\StarOpen.sys – (StarOpen)
DRV - [2010/06/14 09:32:54 | 000,036,608 | —- | M] () [Kernel | On_Demand | Running] – C:\WINDOWS\system32\FsUsbExDisk.Sys – (FsUsbExDisk)
DRV - [2010/04/27 10:25:20 | 000,123,648 | —- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\sscemdm.sys – (sscemdm)
DRV - [2010/04/27 10:25:20 | 000,098,560 | —- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\sscebus.sys – (sscebus) SAMSUNG USB Composite Device V2 driver (WDM)
DRV - [2010/04/27 10:25:20 | 000,014,848 | —- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\sscemdfl.sys – (sscemdfl)
DRV - [2008/06/26 00:47:00 | 000,036,864 | R— | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\l1e51x86.sys – (L1e)
DRV - [2008/05/08 21:23:22 | 000,238,080 | R— | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\viahduaa.sys – (VIAHdAudAddService)
DRV - [2008/02/14 14:12:00 | 001,389,056 | R— | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\monfilt.sys – (monfilt)
DRV - [2006/02/21 20:46:26 | 001,505,792 | —- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\ati2mtag.sys – (ati2mtag)
DRV - [2004/08/13 18:56:20 | 000,005,810 | R— | M] () [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ASACPI.sys – (MTsensor)
DRV - [2004/05/02 16:47:08 | 000,023,040 | R— | M] () [Kernel | On_Demand | Stopped] – C:\WINDOWS\System32\drivers\GVCplDrv.sys – (GVCplDrv)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "AVG Secure Search"
FF - prefs.js..browser.search.defaultthis.engineName: "TranslatorBar 3.3 Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2769714&SearchSource;=3&q;={searchTerms}"
FF - prefs.js..browser.search.selectedEngine: "AVG Secure Search"
FF - prefs.js..browser.startup.homepage: "http://www.google.com.au/"
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:9.0.0.872
FF - prefs.js..extensions.enabledItems: avg@igeared:6.103.018.001
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {e7f7b7dc-7dec-4e84-9a87-ece02e8a160a}:3.3.3.2
FF - prefs.js..extensions.enabledItems: [removed]:3.3.3.2
FF - prefs.js..extensions.enabledItems: {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}:5.3.0.7280
FF - prefs.js..keyword.URL: "http://search.avg.com/route/?d=4b89b5d1&v;=6.010.006.004&i;=23&tp;=ab&iy;=&ychte;=au&lng;=en-GB&q;="


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@facebook.com/FBPlugin,version=1.0.3: C:\Documents and Settings\JimC\Application Data\Facebook\npfbplugin_1_0_3.dll ( )

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG2012\Firefox4\ [2011/11/04 09:52:29 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/11/11 09:34:36 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/07/14 15:12:49 | 000,000,000 | —D | M]

[2009/03/21 17:57:44 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\JimC\Application Data\Mozilla\Extensions
[2009/03/21 17:57:44 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\JimC\Application Data\Mozilla\Extensions\[removed]
[2011/11/10 09:25:31 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\JimC\Application Data\Mozilla\Firefox\Profiles\2k3czex1.default\extensions
[2010/04/28 10:25:24 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\JimC\Application Data\Mozilla\Firefox\Profiles\2k3czex1.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/10/11 16:27:22 | 000,000,000 | —D | M] (TranslatorBar 3.3 Community Toolbar) – C:\Documents and Settings\JimC\Application Data\Mozilla\Firefox\Profiles\2k3czex1.default\extensions\{e7f7b7dc-7dec-4e84-9a87-ece02e8a160a}
[2011/11/10 09:25:31 | 000,000,000 | —D | M] (AVG Security Toolbar) – C:\Documents and Settings\JimC\Application Data\Mozilla\Firefox\Profiles\2k3czex1.default\extensions\avg@toolbar
[2010/11/23 14:25:22 | 000,000,937 | —- | M] () – C:\Documents and Settings\JimC\Application Data\Mozilla\Firefox\Profiles\2k3czex1.default\searchplugins\conduit.xml
[2011/11/11 09:34:41 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/10/07 05:14:55 | 000,000,000 | —D | M] (Skype Click to Call) – C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2011/11/11 09:34:36 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2010/09/15 04:50:38 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011/09/30 17:54:54 | 000,001,538 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazon-en-GB.xml
[2011/09/30 17:54:54 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011/09/30 17:54:54 | 000,000,947 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\chambers-en-GB.xml
[2011/09/30 17:54:54 | 000,001,180 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay-en-GB.xml
[2011/09/30 17:54:54 | 000,001,135 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo-en-GB.xml

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}source
id=chrome&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?client=chrome&hl;={language}&q;={searchTerms}
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\13.0.782.218\pdf.dll
CHR - plugin: Google Gears 0.5.33.0 (Enabled) = C:\Program Files\Google\Chrome\Application\13.0.782.218\gears.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\13.0.782.218\gcswf32.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.220.4 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U22 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Microsoft Office 2003 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\NPOFFICE.DLL
CHR - plugin: QuickTime Plug-in 7.6.6 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.6 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.6 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.6 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.6 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.6 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.6 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Facebook Plugin (Enabled) = C:\Documents and Settings\JimC\Application Data\Facebook\npfbplugin_1_0_3.dll
CHR - plugin: DivX Web Player (Enabled) = C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.2.183.39\npGoogleOneClick8.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: Entanglement = C:\Documents and Settings\JimC\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\aciahcmjmecflokailenpkdchphgkefd\2.5.7_0\
CHR - Extension: Poppit = C:\Documents and Settings\JimC\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\mcbkbpnkkkipelfledbfocopglifcfmi\2.2_0\

Hosts file not found
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG2012\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\8.0.0.40\AVG Secure Search_toolbar.dll ()
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7018.1622\swg.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\8.0.0.40\AVG Secure Search_toolbar.dll ()
O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No CLSID value found.
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [BrStsMon00] C:\Program Files\Browny02\Brother\BrStMonW.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [ControlCenter2.0] C:\Program Files\Brother\ControlCenter2\brctrcen.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [ControlCenter3] C:\Program Files\Brother\ControlCenter3\brctrcen.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [EverioService] C:\Program Files\CyberLink\PCM4Everio\EverioService.exe (CyberLink Corp.)
O4 - HKLM..\Run: [NPSStartup] File not found
O4 - HKLM..\Run: [SetDefPrt] C:\Program Files\Brother\Brmfl05a\BrStDvPt.exe (Brother Industories, Ltd.)
O4 - HKLM..\Run: [vProt] C:\Program Files\AVG Secure Search\vprot.exe ()
O4 - HKCU..\Run: [{3945838D-6092-83E4-B5C6-8A7E7025933E}] "C:\Documents and Settings\JimC\Application Data\Ykwaad\unadmio.exe" File not found
O4 - HKCU..\Run: [AutoStartNPSAgent] C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe (Samsung Electronics Co., Ltd.)
O4 - HKCU..\Run: [TomTomHOME.exe] C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe (TomTom)
O4 - HKCU..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\System32\Macromed\Flash\FlashUtil10h_ActiveX.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE (WinZip Computing, S.L.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - mswsock.dll File not found
O15 - HKCU\..Trusted Domains: microsoft.com ([office] http in Trusted sites)
O15 - HKCU\..Trusted Domains: microsoft.com ([www.update] http in Trusted sites)
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} http://download.microsoft.com/download/F/6…922/wmv9VCM.CAB (Reg Error: Key error.)
O16 - DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} http://catalog.update.microsoft.com/v7/sit…b?1305195582859 (MUCatalogWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1304946733312 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{844C344C-ADA9-4FE7-B9D9-94C2DC838E96}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{844C344C-ADA9-4FE7-B9D9-94C2DC838E96}: Domain = bigpond.net.au
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\8.0.1\ViProtocol.dll ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\JimC\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\JimC\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/02/16 19:56:41 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2007/07/25 15:13:12 | 000,000,039 | R— | M] () - E:\autorun.inf – [ CDFS ]
O32 - AutoRun File - [2008/02/15 20:57:14 | 000,000,000 | —D | M] - H:\autorun – [ FAT32 ]
O32 - AutoRun File - [2007/05/18 10:37:12 | 000,000,069 | RH– | M] () - H:\autorun.inf – [ FAT32 ]
O33 - MountPoints2\{1f71163b-04db-11e0-b683-0022158720a5}\Shell - "" = AutoRun
O33 - MountPoints2\{1f71163b-04db-11e0-b683-0022158720a5}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{1f71163b-04db-11e0-b683-0022158720a5}\Shell\AutoRun\command - "" = "H:\WD SmartWare.exe" autoplay=true
O33 - MountPoints2\{38f0ab5a-3472-11de-9d49-0022158720a5}\Shell - "" = AutoRun
O33 - MountPoints2\{38f0ab5a-3472-11de-9d49-0022158720a5}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{38f0ab5a-3472-11de-9d49-0022158720a5}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{bf2465a6-fc61-11dd-9e7e-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{bf2465a6-fc61-11dd-9e7e-806d6172696f}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{bf2465a6-fc61-11dd-9e7e-806d6172696f}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL spare_parts.pdf
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG2012\avgrsx.exe /sync /restart)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/11/15 20:14:45 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Documents and Settings\JimC\Desktop\OTL.exe
[2011/11/15 11:35:39 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Sun
[2011/11/13 18:37:31 | 000,607,260 | R— | C] (Swearware) – C:\Documents and Settings\JimC\Desktop\dds.scr
[2011/11/13 15:35:08 | 000,000,000 | —D | C] – C:\Documents and Settings\JimC\Application Data\Ykwaad
[2011/11/13 15:35:08 | 000,000,000 | —D | C] – C:\Documents and Settings\JimC\Application Data\Oqpys
[2011/11/13 14:43:40 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Apple Computer
[2011/11/13 14:38:53 | 000,000,000 | —D | C] – C:\Documents and Settings\JimC\Application Data\Haeciv
[2011/11/13 14:38:53 | 000,000,000 | —D | C] – C:\Documents and Settings\JimC\Application Data\Azyrud
[2011/11/13 14:20:13 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2011/11/13 14:19:51 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Adobe
[2011/11/12 15:40:31 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Google Earth
[2011/11/10 10:42:03 | 000,000,000 | —D | C] – C:\WINDOWS\System32\cache
[2011/11/08 19:10:12 | 000,000,000 | —D | C] – C:\PEOPLES BEACH
[2011/11/01 19:41:16 | 013,865,152 | —- | C] (Mozilla) – C:\Program Files\Firefox Setup 7.0.1.exe
[2011/10/27 14:25:01 | 000,000,000 | —D | C] – C:\Documents and Settings\JimC\Application Data\Origin
[2011/10/27 14:24:41 | 000,000,000 | —D | C] – C:\Documents and Settings\JimC\Local Settings\Application Data\Origin
[2011/10/27 14:24:19 | 000,000,000 | —D | C] – C:\Program Files\Origin Games
[2011/10/27 14:24:19 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Origin
[2011/10/27 14:24:19 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Electronic Arts
[2011/10/27 14:23:46 | 000,000,000 | —D | C] – C:\Program Files\Origin
[2011/10/27 14:11:09 | 000,000,000 | —D | C] – C:\Games
[2011/01/25 18:14:41 | 000,395,640 | —- | C] (BitTorrent, Inc.) – C:\Program Files\utorrent.exe
[2010/12/26 16:17:49 | 000,568,648 | —- | C] (Google Inc.) – C:\Program Files\GoogleEarthSetup.exe
[2009/10/06 20:24:15 | 093,074,728 | —- | C] (Apple Inc.) – C:\Program Files\iTunesSetup.exe
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\Documents and Settings\JimC\Desktop\*.tmp files -> C:\Documents and Settings\JimC\Desktop\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/11/15 20:22:52 | 000,001,324 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/11/15 20:14:45 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\JimC\Desktop\OTL.exe
[2011/11/15 19:39:00 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/11/15 16:09:25 | 000,000,400 | -H– | M] () – C:\WINDOWS\tasks\Norton Security Scan for JimC.job
[2011/11/15 11:39:00 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/11/15 08:36:46 | 109,787,197 | —- | M] () – C:\WINDOWS\System32\drivers\AVG\incavi.avm
[2011/11/15 05:58:46 | 000,444,358 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/11/15 05:58:46 | 000,072,108 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/11/15 05:55:06 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/11/15 05:54:20 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/11/13 18:54:42 | 000,003,070 | —- | M] () – C:\attach.zip
[2011/11/13 18:37:35 | 000,607,260 | R— | M] (Swearware) – C:\Documents and Settings\JimC\Desktop\dds.scr
[2011/11/12 16:52:25 | 000,065,024 | —- | M] () – C:\Documents and Settings\JimC\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/11/11 11:39:56 | 000,001,813 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
[2011/11/10 17:19:47 | 000,168,124 | —- | M] () – C:\WINDOWS\System32\drivers\AVG\iavichjg.avm
[2011/11/10 14:33:02 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/11/10 07:58:13 | 000,000,601 | —- | M] () – C:\WINDOWS\MYOBP.INI
[2011/11/10 07:58:03 | 000,000,039 | —- | M] () – C:\WINDOWS\MYOB.INI
[2011/11/04 09:52:29 | 000,000,702 | —- | M] () – C:\Documents and Settings\All Users\Desktop\AVG 2012.lnk
[2011/11/01 19:39:21 | 000,001,729 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2011/11/01 19:33:23 | 000,001,602 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2011/10/27 14:47:07 | 000,049,514 | —- | M] () – C:\Documents and Settings\JimC\Desktop\Inheritance.jpg
[2011/10/27 14:25:07 | 000,000,552 | —- | M] () – C:\WINDOWS\System32\d3d8caps.dat
[2011/10/27 14:24:23 | 000,000,654 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Origin.lnk
[2011/10/25 07:20:17 | 000,000,000 | —- | M] () – C:\Documents and Settings\JimC\Local Settings\Application Data\prvlcl.dat
[2011/10/17 10:44:53 | 000,058,692 | —- | M] () – C:\Documents and Settings\JimC\Desktop\Bunnings Scan Book Oct 2011.pdf
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\Documents and Settings\JimC\Desktop\*.tmp files -> C:\Documents and Settings\JimC\Desktop\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/11/13 18:54:42 | 000,003,070 | —- | C] () – C:\attach.zip
[2011/10/27 14:47:04 | 000,049,514 | —- | C] () – C:\Documents and Settings\JimC\Desktop\Inheritance.jpg
[2011/10/27 14:25:07 | 000,000,552 | —- | C] () – C:\WINDOWS\System32\d3d8caps.dat
[2011/10/27 14:24:23 | 000,000,654 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Origin.lnk
[2011/10/17 10:44:51 | 000,058,692 | —- | C] () – C:\Documents and Settings\JimC\Desktop\Bunnings Scan Book Oct 2011.pdf
[2011/05/08 11:32:32 | 000,015,126 | -HS- | C] () – C:\Documents and Settings\JimC\Local Settings\Application Data\0l4r11h0262p4ynt6hr30xn10gvmdndhw3r4
[2011/05/08 11:32:32 | 000,015,126 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\0l4r11h0262p4ynt6hr30xn10gvmdndhw3r4
[2011/03/13 19:39:47 | 000,000,056 | -H– | C] () – C:\WINDOWS\System32\ezsidmv.dat
[2010/12/17 16:13:14 | 000,110,592 | —- | C] () – C:\WINDOWS\System32\FsUsbExDevice.Dll
[2010/12/17 16:13:14 | 000,036,608 | —- | C] () – C:\WINDOWS\System32\FsUsbExDisk.Sys
[2010/12/17 16:13:09 | 000,002,528 | —- | C] () – C:\Documents and Settings\JimC\Application Data\$_hpcst$.hpc
[2010/12/17 14:24:19 | 173,838,160 | —- | C] () – C:\Program Files\New_PC_Studio_1.5.1.10064_2.exe
[2010/12/17 14:09:28 | 000,005,632 | —- | C] () – C:\WINDOWS\System32\drivers\StarOpen.sys
[2010/12/16 10:42:19 | 000,000,000 | —- | C] () – C:\Documents and Settings\All Users\Application Data\LauncherAccess.dt
[2010/11/22 21:06:03 | 000,000,050 | —- | C] () – C:\WINDOWS\System32\BRIDF10A.DAT
[2010/03/19 10:08:57 | 000,000,000 | —- | C] () – C:\Documents and Settings\JimC\Local Settings\Application Data\prvlcl.dat
[2009/08/20 13:10:56 | 000,198,144 | —- | C] () – C:\WINDOWS\System32\_psisdecd.dll
[2009/07/17 17:19:19 | 000,000,010 | —- | C] () – C:\WINDOWS\WININIT.INI
[2009/07/16 13:28:37 | 000,000,663 | —- | C] () – C:\WINDOWS\openrda.ini
[2009/07/16 13:28:28 | 000,000,000 | —- | C] () – C:\WINDOWS\drvxl32.INI
[2009/07/16 13:28:27 | 000,000,000 | —- | C] () – C:\WINDOWS\drvwd32.INI
[2009/06/05 08:13:13 | 000,065,024 | —- | C] () – C:\Documents and Settings\JimC\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/04/17 12:42:48 | 000,001,324 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2009/04/13 15:25:38 | 000,000,000 | —- | C] () – C:\WINDOWS\ativpsrm.bin
[2009/03/21 18:49:47 | 000,000,516 | —- | C] () – C:\WINDOWS\BRWMARK.INI
[2009/03/21 18:49:47 | 000,000,027 | —- | C] () – C:\WINDOWS\BRPP2KA.INI
[2009/03/21 18:49:46 | 000,000,030 | —- | C] () – C:\WINDOWS\System32\brss01a.ini
[2009/03/21 18:49:02 | 000,000,294 | —- | C] () – C:\WINDOWS\Brpfx04a.ini
[2009/03/21 18:49:02 | 000,000,094 | —- | C] () – C:\WINDOWS\brpcfx.ini
[2009/03/21 18:49:02 | 000,000,050 | —- | C] () – C:\WINDOWS\System32\bridf05a.dat
[2009/03/21 18:48:47 | 000,106,496 | —- | C] () – C:\WINDOWS\System32\BrMuSNMP.dll
[2009/03/21 18:48:47 | 000,000,000 | —- | C] () – C:\WINDOWS\brdfxspd.dat
[2009/03/21 18:26:05 | 000,087,552 | —- | C] () – C:\WINDOWS\System32\cpwmon2k.dll
[2009/03/21 18:05:47 | 000,000,601 | —- | C] () – C:\WINDOWS\MYOBP.INI
[2009/03/21 18:05:47 | 000,000,119 | —- | C] () – C:\WINDOWS\SwDrvs.ini
[2009/03/21 18:05:47 | 000,000,039 | —- | C] () – C:\WINDOWS\MYOB.INI
[2009/02/22 11:47:01 | 000,000,127 | —- | C] () – C:\Documents and Settings\JimC\Local Settings\Application Data\fusioncache.dat
[2009/02/22 11:41:14 | 000,023,040 | R— | C] () – C:\WINDOWS\System32\drivers\GVCplDrv.sys
[2009/02/22 10:42:29 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2009/02/22 10:41:06 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2009/02/18 19:36:59 | 000,011,979 | —- | C] () – C:\WINDOWS\Ascd_log.ini
[2009/02/18 19:36:09 | 000,005,810 | R— | C] () – C:\WINDOWS\System32\drivers\ASACPI.sys
[2009/02/18 19:36:00 | 000,011,736 | —- | C] () – C:\WINDOWS\Ascd_tmp.ini
[2009/02/18 19:36:00 | 000,010,296 | —- | C] () – C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2009/02/17 03:46:27 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2009/02/17 03:45:38 | 000,266,208 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/02/16 19:57:56 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2009/02/16 19:54:34 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2006/12/31 07:57:08 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2006/05/05 18:26:00 | 000,335,872 | —- | C] () – C:\WINDOWS\System32\ctreestd.dll
[2006/02/13 13:29:26 | 000,121,995 | —- | C] () – C:\WINDOWS\System32\atiicdxx.dat
[2003/03/31 20:00:00 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2003/03/31 20:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2003/03/31 20:00:00 | 000,444,358 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2003/03/31 20:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2003/03/31 20:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2003/03/31 20:00:00 | 000,072,108 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2003/03/31 20:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2003/03/31 20:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2003/03/31 20:00:00 | 000,004,463 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2003/03/31 20:00:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2003/03/31 20:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2003/01/07 15:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2000/01/31 07:02:00 | 000,047,104 | —- | C] () – C:\WINDOWS\System32\Wh2Robo.dll

========== LOP Check ==========

[2011/11/13 15:35:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG2012
[2011/10/13 10:40:37 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg9
[2011/03/15 08:02:34 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Common Files
[2010/02/24 21:45:09 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DriverCure
[2011/07/10 07:24:54 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Easybits GO
[2011/10/27 14:24:19 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Electronic Arts
[2011/11/15 08:36:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MFAData
[2009/03/22 17:36:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\OfficeRecovery
[2011/10/27 14:32:53 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Origin
[2009/08/19 16:23:49 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ParetoLogic
[2010/10/23 13:22:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ReviverSoft
[2010/12/17 16:13:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Samsung
[2011/10/13 10:32:54 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2009/04/15 12:48:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TomTom
[2011/06/05 19:46:54 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WinZip
[2011/10/13 10:52:05 | 000,000,000 | —D | M] – C:\Documents and Settings\JimC\Application Data\AVG Secure Search
[2011/10/13 10:53:01 | 000,000,000 | —D | M] – C:\Documents and Settings\JimC\Application Data\AVG2012
[2011/11/13 15:35:23 | 000,000,000 | —D | M] – C:\Documents and Settings\JimC\Application Data\Azyrud
[2009/05/12 09:35:42 | 000,000,000 | —D | M] – C:\Documents and Settings\JimC\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2009/08/20 13:16:43 | 000,000,000 | —D | M] – C:\Documents and Settings\JimC\Application Data\DriverCure
[2010/06/13 19:59:21 | 000,000,000 | —D | M] – C:\Documents and Settings\JimC\Application Data\Facebook
[2011/07/10 07:24:45 | 000,000,000 | —D | M] – C:\Documents and Settings\JimC\Application Data\go
[2011/11/13 15:02:29 | 000,000,000 | —D | M] – C:\Documents and Settings\JimC\Application Data\Haeciv
[2011/11/14 20:12:52 | 000,000,000 | —D | M] – C:\Documents and Settings\JimC\Application Data\Oqpys
[2011/10/27 14:30:34 | 000,000,000 | —D | M] – C:\Documents and Settings\JimC\Application Data\Origin
[2010/12/17 16:13:05 | 000,000,000 | —D | M] – C:\Documents and Settings\JimC\Application Data\Samsung
[2009/03/21 17:57:42 | 000,000,000 | —D | M] – C:\Documents and Settings\JimC\Application Data\TomTom
[2011/11/14 12:00:35 | 000,000,000 | —D | M] – C:\Documents and Settings\JimC\Application Data\Ykwaad

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >
[2009/06/24 21:26:05 | 000,052,539 | —- | M] () – C:\AFU236U.exe


< MD5 for: EXPLORER.EXE >
[2008/04/14 05:42:20 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\explorer.exe
[2008/04/14 05:42:20 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2003/03/31 20:00:00 | 001,004,032 | —- | M] (Microsoft Corporation) MD5=A82B28BFC2E4455FE43022A498C0EF0A – C:\WINDOWS\$NtServicePackUninstall$\explorer.exe

< MD5 for: SVCHOST.EXE >
[2003/03/31 20:00:00 | 000,012,800 | —- | M] (Microsoft Corporation) MD5=0F7D9C87B0CE1FA520473119752C6F79 – C:\WINDOWS\$NtServicePackUninstall$\svchost.exe
[2008/04/14 05:42:38 | 000,014,336 | —- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 – C:\WINDOWS\ServicePackFiles\i386\svchost.exe
[2008/04/14 05:42:38 | 000,014,336 | —- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 – C:\WINDOWS\system32\svchost.exe

< MD5 for: USERINIT.EXE >
[2008/04/14 05:42:40 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 – C:\WINDOWS\ServicePackFiles\i386\userinit.exe
[2008/04/14 05:42:40 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 – C:\WINDOWS\system32\userinit.exe
[2003/03/31 20:00:00 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=E931E0A2B8BF0019DB902E98D03662CB – C:\WINDOWS\$NtServicePackUninstall$\userinit.exe

< MD5 for: WINLOGON.EXE >
[2003/03/31 20:00:00 | 000,516,608 | —- | M] (Microsoft Corporation) MD5=2246D8D8F4714A2CEDB21AB9B1849ABB – C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2008/04/14 05:42:40 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008/04/14 05:42:40 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\system32\winlogon.exe

< C:\Windows\assembly\tmp\U\*.* /s >

========== Alternate Data Streams ==========

@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D1B5B4F1

< End of report >

Attachments:

OK that has given me the data I need - it is a consrv.dll infection

Download and Install Combofix

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
  • Accept the disclaimer and allow to update if it asks

    [external image: Posted Image]

    [external image: Posted Image]
  • When finished, it shall produce a log for you.
  • Please include the C:\ComboFix.txt in your next reply.

Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.


Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now
Ok, ran combofix ONCE and once only. Came up with a message that the TCP/IP stack was infected. it did a reboot, on it's own. Came back up and ran in the blue box again. Got to about stage 43 ?? and BSOD'd. As this is my brother in law's computer, the bios is set for immeadiate reboot so I did not catch any of the BSOD info. So, no idea what to do next. There is no PING.exe running as a process, which is a good sign ?? Please let me know the next step. Thanks again for your instructions….
OK could you run a fresh OTL scan for me - combofix may have removed the main element allready

Script to use in the OTL scan

  • .
  • Select All Users
  • Under the Custom Scan box paste this in
    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    consrv.dll
    explorer.exe
    winlogon.exe
    Userinit.exe
    svchost.exe
    /md5stop
    C:\Windows\assembly\tmp\U\*.* /s
    CREATERESTOREPOINT

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI