This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

ping.exe, av protection 2012 [Solved]

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

i recently had av protection 2012 come up on my computer and since then ive noticed the ping.exe using up all the cpu usage. i recently ran TDSSKiller and the ping.exe doesnt seem to be a problem anymore but i wanted someone to check my logs to see if i need to address anything else.

thank you for your help.

here are my dds logs and my gmer log
.
DDS (Ver_2011-06-23.01) - NTFSx86
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_26
Run by [removed] at 20:45:55 on 2011-11-28
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2037.748 [GMT -5:00]
.
AV: AVG Anti-Virus Free Edition 2012 *Enabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
SP: AVG Anti-Virus Free Edition 2012 *Enabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\PROGRA~1\AVG\AVG2012\avgrsx.exe
C:\Program Files\AVG\AVG2012\avgcsrvx.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\AVG\AVG2012\avgwdsvc.exe
C:\Program Files\Carbonite\Carbonite Backup\carboniteservice.exe
C:\Program Files\AVG\AVG2012\avgnsx.exe
C:\Windows\system32\svchost.exe -k hpdevmgmt
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Program Files\Nuance\PDF Professional 6\PDFProFiltSrv.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe
C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Real\RealPlayer\Update\realsched.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Nuance\PDF Professional 6\PdfPro6Hook.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Windows\System32\hkcmd.exe
C:\Program Files\AVG\AVG2012\avgtray.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Carbonite\Carbonite Backup\CarboniteUI.exe
C:\Program Files\Analogue Vista Clock\Analogue Vista Clock.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Apoint2K\ApMsgFwd.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
C:\Windows\system32\svchost.exe -k WindowsMobile
C:\Windows\system32\Taskmgr.exe
C:\Windows\system32\wuauclt.exe
C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\rundll32.exe
C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\vssvc.exe
C:\Windows\System32\svchost.exe -k swprv
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://firstfinancialsecurity.com/
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uDefault_Search_URL = hxxp://www.google.com/ie
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=73&bd=PRESARIO&pf=laptop
mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=73&bd=PRESARIO&pf=laptop
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mURLSearchHooks: H - No File
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\programdata\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg2012\avgssie.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\program files\spybot - search & destroy\SDHelper.dll
BHO: PlusIEEventHelper Class: {551a852f-39a6-44a7-9c13-afbec9185a9d} - c:\program files\nuance\pdf professional 6\bin\PlusIEContextMenu.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Nero Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
BHO: ZeonIEEventHelper Class: {da986d7d-ccaf-47b2-84fe-bfa1549bebf9} - c:\program files\nuance\pdf professional 6\bin\ZeonIEFavClient.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - No File
TB: ShopAtHome Toolbar: {98279c38-de4b-4bcf-93c9-8ec26069d6f4} - c:\program files\selectrebates\toolbar\ShopAtHomeToolbar.dll
TB: Nero Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
TB: Nuance PDF: {e3286bf1-e654-42ff-b4a6-5e111731df6b} - c:\program files\nuance\pdf professional 6\bin\ZeonIEFavClient.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
uRun: [Analogue Vista Clock] c:\program files\analogue vista clock\Analogue Vista Clock.exe
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [DW6] "c:\program files\the weather channel fw\desktop\DesktopWeather.exe"
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [Google Update] "c:\users\jspencer\appdata\local\google\update\GoogleUpdate.exe" /c
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [WAWifiMessage] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
mRun: [TkBellExe] "c:\program files\real\realplayer\update\realsched.exe" -osboot
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [QPService] "c:\program files\hp\quickplay\QPService.exe"
mRun: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [PDFHook] c:\program files\nuance\pdf professional 6\pdfpro6hook.exe
mRun: [PDF6 Registry Controller] c:\program files\nuance\pdf professional 6\RegistryController.exe
mRun: [Nuance PDF Professional 6-reminder] "c:\program files\nuance\pdf professional 6\ereg\ereg.exe" -r "c:\programdata\nuance\pdf professional 6\ereg\Ereg.ini"
mRun: [IntelliPoint] "c:\program files\microsoft intellipoint\ipoint.exe"
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [hpWirelessAssistant] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [AVG_TRAY] "c:\program files\avg\avg2012\avgtray.exe"
mRun: [Apoint] c:\program files\apoint2k\Apoint.exe
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [Intuit SyncManager] c:\program files\common files\intuit\sync\IntuitSyncManager.exe startup
mRun: [Carbonite Backup] c:\program files\carbonite\carbonite backup\CarboniteUI.exe
mRunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\quickb~1.lnk - c:\program files\common files\intuit\quickbooks\qbupdate\qbupdate.exe
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Append the content of the link to existing PDF file - c:\program files\nuance\pdf professional 6\bin\ZeonIEFavClient.dll/ZeonIEAppend.HTML
IE: Append the content of the selected links to existing PDF file - c:\program files\nuance\pdf professional 6\bin\ZeonIEFavClient.dll/ZeonIEAppendSelLinks.HTML
IE: Append to existing PDF file - c:\program files\nuance\pdf professional 6\bin\ZeonIEFavClient.dll/ZeonIEAppend.HTML
IE: Create PDF file - c:\program files\nuance\pdf professional 6\bin\ZeonIEFavClient.dll/ZeonIECapture.HTML
IE: Create PDF file from the content of the link - c:\program files\nuance\pdf professional 6\bin\ZeonIEFavClient.dll/ZeonIECapture.HTML
IE: Create PDF files from the selected links - c:\program files\nuance\pdf professional 6\bin\ZeonIEFavClient.dll/ZeonIECaptureSelLinks.HTML
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office11\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html
IE: Open with Nuance PDF Converter 6.0 - c:\program files\nuance\pdf professional 6\cnvres_eng.dll /100
IE: Open with PDF Professional 6 - c:\program files\nuance\pdf professional 6\bin\PlusIEContextMenu.dll/PlusIEContextMenu.htm
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C}
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office11\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll
LSP: mswsock.dll
Trusted Zone: charlestoncounty.org\imgweb
Trusted Zone: experienceretirement.com\www
Trusted Zone: investprogram.com\www
Trusted Zone: nationalife.com\www
Trusted Zone: nationallife.com\www
DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} - hxxp://pcpitstop.com/betapit/PCPitStop.CAB
DPF: {531C8059-ED3C-481E-B46C-558CF2862F6B} - hxxp://imgweb.charlestoncounty.org/AppNet/activex/OBXWebSelect.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {93D532DD-85FC-4A92-8254-8DB5437D8690} - hxxp://imgweb.charlestoncounty.org/AppNet/activex/OBXPopup.cab
DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
TCP: DhcpNameServer = [removed] [removed]
TCP: Interfaces\{9BF869BE-E641-49EF-A6A1-342BD3339243} : DhcpNameServer = [removed] [removed]
TCP: Interfaces\{C35F5C38-1486-4B24-BB49-E83F68466F23} : DhcpNameServer = [removed] [removed]
Handler: intu-help-qb3 - {c5e479ea-0a65-4b05-8c6c-2fc8cc682eb4} - c:\program files\intuit\quickbooks 2010\HelpAsyncPluggableProtocol.dll
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg2012\avgpp.dll
Handler: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - c:\windows\system32\mscoree.dll
Notify: igfxcui - igfxdev.dll
mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "c:\program files\common files\lightscribe\LSRunOnce.exe"
Hosts: 127.0.0.1 www.spywareinfo.com
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\jspencer\appdata\roaming\mozilla\firefox\profiles\eylpa8ce.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - google.com
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&type=524517&p=
FF - component: c:\program files\avg\avg10\firefox4\components\avgssff4.dll
FF - component: c:\program files\common files\spigot\wtxpcom\components\WidgiToolbarFF.dll
FF - component: c:\programdata\real\realplayer\browserrecordplugin\firefox\ext\components\nprpffbrowserrecordext.dll
FF - component: c:\programdata\real\realplayer\browserrecordplugin\firefox\ext\components\nprpffbrowserrecordlegacyext.dll
FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\google\update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\google\update\1.3.21.53\npGoogleUpdate3.dll
FF - plugin: c:\program files\google\update\1.3.21.57\npGoogleUpdate3.dll
FF - plugin: c:\program files\google\update\1.3.21.65\npGoogleUpdate3.dll
FF - plugin: c:\program files\google\update\1.3.21.69\npGoogleUpdate3.dll
FF - plugin: c:\program files\google\update\1.3.21.79\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\microsoft silverlight\4.0.60531.0\npctrlui.dll
FF - plugin: c:\program files\mozilla firefox\plugins\NPcol400.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npCouponPrinter.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npMozCouponPrinter.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\nuance\pdf professional 6\bin\nppdf.dll
FF - plugin: c:\program files\nuance\pdf professional 6\bin\nppdf.dll
FF - plugin: c:\program files\pando networks\media booster\npPandoWebPlugin.dll
FF - plugin: c:\program files\viewpoint\viewpoint media player\npViewpoint.dll
FF - plugin: c:\programdata\nexonus\ngm\npNxGameUS.dll
FF - plugin: c:\programdata\real\realplayer\browserrecordplugin\mozillaplugins\nprphtml5videoshim.dll
FF - plugin: c:\users\jspencer\appdata\local\google\update\1.3.21.79\npGoogleUpdate3.dll
FF - plugin: c:\users\jspencer\appdata\locallow\unity\webplayer\loader\npUnity3D32.dll
FF - plugin: c:\users\jspencer\appdata\roaming\move networks\plugins\npqmp071500000347.dll
FF - plugin: c:\users\jspencer\appdata\roaming\move networks\plugins\npqmp071503000010.dll
FF - plugin: c:\users\jspencer\appdata\roaming\mozilla\plugins\npgoogletalk.dll
FF - plugin: c:\users\jspencer\appdata\roaming\mozilla\plugins\npgtpo3dautoplugin.dll
.
—- FIREFOX POLICIES —-
FF - user.js: yahoo.ytff.general.dontshowhpoffer - true
============= SERVICES / DRIVERS ===============
.
R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [2011-7-11 23120]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2011-9-13 32592]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2011-10-7 230608]
R1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2011-8-8 40016]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [2011-7-11 295248]
R2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\common files\adobe\arm\1.0\armsvc.exe [2011-6-6 64952]
R2 AVGIDSAgent;AVGIDSAgent;c:\program files\avg\avg2012\AVGIDSAgent.exe [2011-10-12 4433248]
R2 avgwd;AVG WatchDog;c:\program files\avg\avg2012\avgwdsvc.exe [2011-8-2 192776]
R2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-6-24 21504]
R2 PDFProFiltSrv;PDFProFiltSrv;c:\program files\nuance\pdf professional 6\PDFProFiltSrv.exe [2009-7-27 134944]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search & destroy\SDWinSec.exe [2008-8-22 1153368]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2008-9-21 24652]
R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [2011-7-11 134736]
R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [2011-7-11 24272]
R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [2011-10-4 16720]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-6-23 135664]
S2 SqlCSS;SQL Server EXPRESS;c:\windows\system32\svchost.exe -k Sqlses [2008-6-24 21504]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2010-6-23 135664]
S3 TYKEY;Triple S PC/SC Reader Service;c:\windows\system32\drivers\Triplesp.sys [2009-6-7 17920]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
.
=============== Created Last 30 ================
.
2011-11-28 05:39:18 ——– d—–w- c:\programdata\Carbonite
2011-11-27 04:43:23 388096 —-a-r- c:\users\jspencer\appdata\roaming\microsoft\installer\{45a66726-69bc-466b-a7a4-12fcba4883d7}\HiJackThis.exe
2011-11-20 06:47:09 ——– dc-h–w- C:\$AVG
2011-11-20 06:46:20 ——– d—–w- c:\users\jspencer\appdata\roaming\NDD3nF4amH5WJdE
2011-11-20 06:46:19 ——– d—–w- c:\users\jspencer\appdata\roaming\GkkUUVelOBtP0cS
2011-11-20 06:45:58 ——– d—–w- c:\users\jspencer\appdata\roaming\giFpGQ6W7RgXjYe
2011-11-20 06:45:56 ——– d—–w- c:\users\jspencer\appdata\roaming\ix1iba6J7E8CVlB
.
==================== Find3M ====================
.
2011-11-29 01:14:54 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-11-29 01:11:34 66560 —-a-w- c:\windows\system32\drivers\smb.sys
2011-10-07 10:23:48 230608 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2011-10-04 10:21:16 16720 —-a-w- c:\windows\system32\drivers\AVGIDSShim.sys
2011-09-13 10:30:10 32592 —-a-w- c:\windows\system32\drivers\avgrkx86.sys
.
============= FINISH: 20:47:45.45 ===============




UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-06-23.01)
.
Microsoft® Windows Vista™ Home Premium
Boot Device: \Device\HarddiskVolume1
Install Date: 10/15/2007 11:52:19 AM
System Uptime: 11/28/2011 8:11:24 PM (0 hours ago)
.
Motherboard: Hewlett-Packard | | 30D9
Processor: Intel® Pentium® Dual CPU T2310 @ 1.46GHz | CPU | 1467/533mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 66 GiB total, 17.173 GiB free.
D: is FIXED (NTFS) - 8 GiB total, 1.32 GiB free.
E: is CDROM ()
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP1165: 11/26/2011 11:42:17 PM - Installed HiJackThis
RP1166: 11/28/2011 1:25:35 PM - Scheduled Checkpoint
.
==== Installed Programs ======================
.
.
32 Bit HP CIO Components Installer
Adobe Flash Player 10 ActiveX
Adobe Flash Player 11 Plugin
Adobe Reader X (10.1.1)
Adobe Shockwave Player 11.6
Advertising Center
AIO_CDB_ProductContext
AIO_CDB_Software
AIO_Scan
Analogue Vista Clock 1.29
AnswerWorks 5.0 English Runtime
Ask Toolbar
AVG 2012
AVG PC Tuneup 2011
Bandisoft MPEG-1 Decoder
BufferChm
Canon Inkjet Printer Driver Add-On Module
Canon MP Navigator 1.0
Canon MP750
Canon ScanGear Starter
Carbonite
Carbonite Online Backup Setup
CCleaner (remove only)
Compatibility Pack for the 2007 Office system
Conexant HD Audio
Copy
Coupon Printer for Windows
CustomerResearchQFolder
Destination Component
DeviceDiscovery
DeviceManagementQFolder
DivX Web Player
DocProc
DocProcQFolder
eSupportQFolder
F300
F300_Help
F300Trb
Fax
Google Chrome
Google Talk Plugin
Google Toolbar for Internet Explorer
Google Update Helper
GoToMeeting 4.8.0.723
Hewlett-Packard Active Check for Health Check
HiJackThis
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
HP Customer Participation Program 8.0
HP Imaging Device Functions 8.0
HP OCR Software 8.0
HP Photosmart, Officejet, PSC and Deskjet All-In-One Driver Software 8.0.B
HP Print Diagnostic Utility
HP Product Assistant
HP Solution Center 8.0
HP Update
HPDiagnosticAlert
HPProductAssistant
HPSSupply
IC Solutions
Java Auto Updater
Java™ 6 Update 26
MarketResearch
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 4 Client Profile
Microsoft IntelliPoint 6.3
Microsoft Office 2003 Primary Interop Assemblies
Microsoft Office Converter Pack
Microsoft Office File Validation Add-In
Microsoft Office Professional Edition 2003
Microsoft Silverlight
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Visual Studio 2005 Tools for Office Runtime
Microsoft Works
Move Media Player
Mozilla Firefox 8.0 (x86 en-US)
MSVC80_x86
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MSXML 4.0 SP2 Parser and SDK
Nero 9 Lite
Nero ControlCenter
Nero Installer
Nero Online Upgrade
neroxml
Netflix in Windows Media Center
Nexon Game Manager
Nuance PDF Professional 6
Pando Media Booster
PC Connectivity Solution
Photo Pos Pro
QuickBooks
QuickBooks Pro 2010
RealNetworks - Microsoft Visual C++ 2008 Runtime
RealPlayer
RealUpgrade 1.1
Revo Uninstaller 1.88
Scan
Scansoft PDF Professional
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
SolutionCenter
Spybot - Search & Destroy
Status
swMSM
The Weather Channel Desktop 6
Toolbox
Touch Pad Driver
TrayApp
Triple S PC/SC Reader Driver
TurboTax 2008
TurboTax 2008 WinPerFedFormset
TurboTax 2008 WinPerProgramHelp
TurboTax 2008 WinPerReleaseEngine
TurboTax 2008 WinPerTaxSupport
TurboTax 2008 WinPerUserEducation
TurboTax 2008 wrapper
TurboTax 2008 wsciper
Uniblue ProcessQuickLink 2
Unity Web Player
UnloadSupport
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
VC 9.0 Runtime
VC80CRTRedist - 8.0.50727.762
Viewpoint Media Player
WebReg
Windows Driver Package - Nokia pccsmcfd (08/22/2008 7.0.0.0)
.
==== End Of File ===========================



GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2011-11-28 21:58:43
Windows 6.0.6002 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0 Hitachi_ rev.SB2O
Running: gmer.exe; Driver: C:\Users\JSPENCER\AppData\Local\Temp\awddrkow.sys


—- System - GMER 1.0.15 —-

SSDT \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwOpenProcess [0xAB50FF3C]
SSDT \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwTerminateProcess [0xAB50FFE4]
SSDT \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwTerminateThread [0xAB510080]
SSDT \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwWriteVirtualMemory [0xAB51011C]

—- Kernel code sections - GMER 1.0.15 —-

.text ntkrnlpa.exe!KeSetEvent + 3F1 822BAB74 4 Bytes [3C, FF, 50, AB] {CMP AL, 0xff; PUSH EAX; STOSD }
.text ntkrnlpa.exe!KeSetEvent + 621 822BADA4 8 Bytes [E4, FF, 50, AB, 80, 00, 51, …] {IN AL, 0xff; PUSH EAX; STOSD ; ADD BYTE [EAX], 0x51; STOSD }
.text ntkrnlpa.exe!KeSetEvent + 681 822BAE04 4 Bytes [1C, 01, 51, AB] {SBB AL, 0x1; PUSH ECX; STOSD }
? system32\drivers\64551234.sys The system cannot find the path specified. !
? C:\Users\JSPENCER\AppData\Local\Temp\mbr.sys The system cannot find the file specified. !

—- User code sections - GMER 1.0.15 —-

.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[1492] ntdll.dll!NtCreateFile + 6 77C0422A 4 Bytes [28, 00, 06, 00]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[1492] ntdll.dll!NtCreateFile + B 77C0422F 1 Byte [E2]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[1492] ntdll.dll!NtMapViewOfSection + 6 77C0497A 1 Byte [28]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[1492] ntdll.dll!NtMapViewOfSection + 6 77C0497A 4 Bytes [28, 03, 06, 00]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[1492] ntdll.dll!NtMapViewOfSection + B 77C0497F 1 Byte [E2]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[1492] ntdll.dll!NtOpenFile + 6 77C04A0A 4 Bytes [68, 00, 06, 00]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[1492] ntdll.dll!NtOpenFile + B 77C04A0F 1 Byte [E2]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[1492] ntdll.dll!NtOpenProcess + 6 77C04A8A 4 Bytes [A8, 01, 06, 00]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[1492] ntdll.dll!NtOpenProcess + B 77C04A8F 1 Byte [E2]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[1492] ntdll.dll!NtOpenProcessToken + 6 77C04A9A 4 Bytes CALL 76C050A0 C:\Windows\system32\MSCTF.dll (MSCTF Server DLL/Microsoft Corporation)
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[1492] ntdll.dll!NtOpenProcessToken + B 77C04A9F 1 Byte [E2]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[1492] ntdll.dll!NtOpenProcessTokenEx + 6 77C04AAA 4 Bytes [A8, 02, 06, 00]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[1492] ntdll.dll!NtOpenProcessTokenEx + B 77C04AAF 1 Byte [E2]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[1492] ntdll.dll!NtOpenThread + 6 77C04AFA 4 Bytes [68, 01, 06, 00]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[1492] ntdll.dll!NtOpenThread + B 77C04AFF 1 Byte [E2]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[1492] ntdll.dll!NtOpenThreadToken + 6 77C04B0A 4 Bytes [68, 02, 06, 00]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[1492] ntdll.dll!NtOpenThreadToken + B 77C04B0F 1 Byte [E2]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[1492] ntdll.dll!NtOpenThreadTokenEx + 6 77C04B1A 4 Bytes CALL 76C05121 C:\Windows\system32\MSCTF.dll (MSCTF Server DLL/Microsoft Corporation)
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[1492] ntdll.dll!NtOpenThreadTokenEx + B 77C04B1F 1 Byte [E2]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[1492] ntdll.dll!NtQueryAttributesFile + 6 77C04BAA 4 Bytes [A8, 00, 06, 00]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[1492] ntdll.dll!NtQueryAttributesFile + B 77C04BAF 1 Byte [E2]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[1492] ntdll.dll!NtQueryFullAttributesFile + 6 77C04C5A 4 Bytes CALL 76C0525F C:\Windows\system32\MSCTF.dll (MSCTF Server DLL/Microsoft Corporation)
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[1492] ntdll.dll!NtQueryFullAttributesFile + B 77C04C5F 1 Byte [E2]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[1492] ntdll.dll!NtSetInformationFile + 6 77C0513A 4 Bytes [28, 01, 06, 00]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[1492] ntdll.dll!NtSetInformationFile + B 77C0513F 1 Byte [E2]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[1492] ntdll.dll!NtSetInformationThread + 6 77C0518A 4 Bytes [28, 02, 06, 00]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[1492] ntdll.dll!NtSetInformationThread + B 77C0518F 1 Byte [E2]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[1492] ntdll.dll!NtUnmapViewOfSection + 6 77C0542A 1 Byte [68]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[1492] ntdll.dll!NtUnmapViewOfSection + 6 77C0542A 4 Bytes [68, 03, 06, 00]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[1492] ntdll.dll!NtUnmapViewOfSection + B 77C0542F 1 Byte [E2]
.text C:\Program Files\Real\RealPlayer\Update\realsched.exe[2168] kernel32.dll!SetUnhandledExceptionFilter 76F0A8C5 5 Bytes [33, C0, C2, 04, 00] {XOR EAX, EAX; RET 0x4}
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[3752] ntdll.dll!NtCreateFile + 6 77C0422A 4 Bytes [28, 00, 06, 00]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[3752] ntdll.dll!NtCreateFile + B 77C0422F 1 Byte [E2]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[3752] ntdll.dll!NtMapViewOfSection + 6 77C0497A 1 Byte [28]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[3752] ntdll.dll!NtMapViewOfSection + 6 77C0497A 4 Bytes [28, 03, 06, 00]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[3752] ntdll.dll!NtMapViewOfSection + B 77C0497F 1 Byte [E2]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[3752] ntdll.dll!NtOpenFile + 6 77C04A0A 4 Bytes [68, 00, 06, 00]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[3752] ntdll.dll!NtOpenFile + B 77C04A0F 1 Byte [E2]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[3752] ntdll.dll!NtOpenProcess + 6 77C04A8A 4 Bytes [A8, 01, 06, 00]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[3752] ntdll.dll!NtOpenProcess + B 77C04A8F 1 Byte [E2]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[3752] ntdll.dll!NtOpenProcessToken + 6 77C04A9A 4 Bytes CALL 76C050A0 C:\Windows\system32\MSCTF.dll (MSCTF Server DLL/Microsoft Corporation)
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[3752] ntdll.dll!NtOpenProcessToken + B 77C04A9F 1 Byte [E2]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[3752] ntdll.dll!NtOpenProcessTokenEx + 6 77C04AAA 4 Bytes [A8, 02, 06, 00]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[3752] ntdll.dll!NtOpenProcessTokenEx + B 77C04AAF 1 Byte [E2]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[3752] ntdll.dll!NtOpenThread + 6 77C04AFA 4 Bytes [68, 01, 06, 00]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[3752] ntdll.dll!NtOpenThread + B 77C04AFF 1 Byte [E2]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[3752] ntdll.dll!NtOpenThreadToken + 6 77C04B0A 4 Bytes [68, 02, 06, 00]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[3752] ntdll.dll!NtOpenThreadToken + B 77C04B0F 1 Byte [E2]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[3752] ntdll.dll!NtOpenThreadTokenEx + 6 77C04B1A 4 Bytes CALL 76C05121 C:\Windows\system32\MSCTF.dll (MSCTF Server DLL/Microsoft Corporation)
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[3752] ntdll.dll!NtOpenThreadTokenEx + B 77C04B1F 1 Byte [E2]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[3752] ntdll.dll!NtQueryAttributesFile + 6 77C04BAA 4 Bytes [A8, 00, 06, 00]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[3752] ntdll.dll!NtQueryAttributesFile + B 77C04BAF 1 Byte [E2]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[3752] ntdll.dll!NtQueryFullAttributesFile + 6 77C04C5A 4 Bytes CALL 76C0525F C:\Windows\system32\MSCTF.dll (MSCTF Server DLL/Microsoft Corporation)
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[3752] ntdll.dll!NtQueryFullAttributesFile + B 77C04C5F 1 Byte [E2]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[3752] ntdll.dll!NtSetInformationFile + 6 77C0513A 4 Bytes [28, 01, 06, 00]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[3752] ntdll.dll!NtSetInformationFile + B 77C0513F 1 Byte [E2]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[3752] ntdll.dll!NtSetInformationThread + 6 77C0518A 4 Bytes [28, 02, 06, 00]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[3752] ntdll.dll!NtSetInformationThread + B 77C0518F 1 Byte [E2]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[3752] ntdll.dll!NtUnmapViewOfSection + 6 77C0542A 1 Byte [68]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[3752] ntdll.dll!NtUnmapViewOfSection + 6 77C0542A 4 Bytes [68, 03, 06, 00]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[3752] ntdll.dll!NtUnmapViewOfSection + B 77C0542F 1 Byte [E2]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[3816] ntdll.dll!NtCreateFile + 6 77C0422A 4 Bytes [28, 00, 06, 00]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[3816] ntdll.dll!NtCreateFile + B 77C0422F 1 Byte [E2]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[3816] ntdll.dll!NtMapViewOfSection + 6 77C0497A 1 Byte [28]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[3816] ntdll.dll!NtMapViewOfSection + 6 77C0497A 4 Bytes [28, 03, 06, 00]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[3816] ntdll.dll!NtMapViewOfSection + B 77C0497F 1 Byte [E2]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[3816] ntdll.dll!NtOpenFile + 6 77C04A0A 4 Bytes [68, 00, 06, 00]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[3816] ntdll.dll!NtOpenFile + B 77C04A0F 1 Byte [E2]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[3816] ntdll.dll!NtOpenProcess + 6 77C04A8A 4 Bytes [A8, 01, 06, 00]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[3816] ntdll.dll!NtOpenProcess + B 77C04A8F 1 Byte [E2]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[3816] ntdll.dll!NtOpenProcessToken + 6 77C04A9A 4 Bytes CALL 76C050A0 C:\Windows\system32\MSCTF.dll (MSCTF Server DLL/Microsoft Corporation)
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[3816] ntdll.dll!NtOpenProcessToken + B 77C04A9F 1 Byte [E2]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[3816] ntdll.dll!NtOpenProcessTokenEx + 6 77C04AAA 4 Bytes [A8, 02, 06, 00]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[3816] ntdll.dll!NtOpenProcessTokenEx + B 77C04AAF 1 Byte [E2]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[3816] ntdll.dll!NtOpenThread + 6 77C04AFA 4 Bytes [68, 01, 06, 00]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[3816] ntdll.dll!NtOpenThread + B 77C04AFF 1 Byte [E2]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[3816] ntdll.dll!NtOpenThreadToken + 6 77C04B0A 4 Bytes [68, 02, 06, 00]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[3816] ntdll.dll!NtOpenThreadToken + B 77C04B0F 1 Byte [E2]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[3816] ntdll.dll!NtOpenThreadTokenEx + 6 77C04B1A 4 Bytes CALL 76C05121 C:\Windows\system32\MSCTF.dll (MSCTF Server DLL/Microsoft Corporation)
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[3816] ntdll.dll!NtOpenThreadTokenEx + B 77C04B1F 1 Byte [E2]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[3816] ntdll.dll!NtQueryAttributesFile + 6 77C04BAA 4 Bytes [A8, 00, 06, 00]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[3816] ntdll.dll!NtQueryAttributesFile + B 77C04BAF 1 Byte [E2]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[3816] ntdll.dll!NtQueryFullAttributesFile + 6 77C04C5A 4 Bytes CALL 76C0525F C:\Windows\system32\MSCTF.dll (MSCTF Server DLL/Microsoft Corporation)
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[3816] ntdll.dll!NtQueryFullAttributesFile + B 77C04C5F 1 Byte [E2]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[3816] ntdll.dll!NtSetInformationFile + 6 77C0513A 4 Bytes [28, 01, 06, 00]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[3816] ntdll.dll!NtSetInformationFile + B 77C0513F 1 Byte [E2]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[3816] ntdll.dll!NtSetInformationThread + 6 77C0518A 4 Bytes [28, 02, 06, 00]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[3816] ntdll.dll!NtSetInformationThread + B 77C0518F 1 Byte [E2]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[3816] ntdll.dll!NtUnmapViewOfSection + 6 77C0542A 1 Byte [68]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[3816] ntdll.dll!NtUnmapViewOfSection + 6 77C0542A 4 Bytes [68, 03, 06, 00]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[3816] ntdll.dll!NtUnmapViewOfSection + B 77C0542F 1 Byte [E2]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[4228] ntdll.dll!NtCreateFile + 6 77C0422A 4 Bytes [28, 00, 06, 00]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[4228] ntdll.dll!NtCreateFile + B 77C0422F 1 Byte [E2]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[4228] ntdll.dll!NtMapViewOfSection + 6 77C0497A 1 Byte [28]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[4228] ntdll.dll!NtMapViewOfSection + 6 77C0497A 4 Bytes [28, 03, 06, 00]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[4228] ntdll.dll!NtMapViewOfSection + B 77C0497F 1 Byte [E2]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[4228] ntdll.dll!NtOpenFile + 6 77C04A0A 4 Bytes [68, 00, 06, 00]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[4228] ntdll.dll!NtOpenFile + B 77C04A0F 1 Byte [E2]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[4228] ntdll.dll!NtOpenProcess + 6 77C04A8A 4 Bytes [A8, 01, 06, 00]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[4228] ntdll.dll!NtOpenProcess + B 77C04A8F 1 Byte [E2]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[4228] ntdll.dll!NtOpenProcessToken + 6 77C04A9A 4 Bytes CALL 76C050A0 C:\Windows\system32\MSCTF.dll (MSCTF Server DLL/Microsoft Corporation)
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[4228] ntdll.dll!NtOpenProcessToken + B 77C04A9F 1 Byte [E2]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[4228] ntdll.dll!NtOpenProcessTokenEx + 6 77C04AAA 4 Bytes [A8, 02, 06, 00]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[4228] ntdll.dll!NtOpenProcessTokenEx + B 77C04AAF 1 Byte [E2]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[4228] ntdll.dll!NtOpenThread + 6 77C04AFA 4 Bytes [68, 01, 06, 00]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[4228] ntdll.dll!NtOpenThread + B 77C04AFF 1 Byte [E2]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[4228] ntdll.dll!NtOpenThreadToken + 6 77C04B0A 4 Bytes [68, 02, 06, 00]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[4228] ntdll.dll!NtOpenThreadToken + B 77C04B0F 1 Byte [E2]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[4228] ntdll.dll!NtOpenThreadTokenEx + 6 77C04B1A 4 Bytes CALL 76C05121 C:\Windows\system32\MSCTF.dll (MSCTF Server DLL/Microsoft Corporation)
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[4228] ntdll.dll!NtOpenThreadTokenEx + B 77C04B1F 1 Byte [E2]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[4228] ntdll.dll!NtQueryAttributesFile + 6 77C04BAA 4 Bytes [A8, 00, 06, 00]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[4228] ntdll.dll!NtQueryAttributesFile + B 77C04BAF 1 Byte [E2]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[4228] ntdll.dll!NtQueryFullAttributesFile + 6 77C04C5A 4 Bytes CALL 76C0525F C:\Windows\system32\MSCTF.dll (MSCTF Server DLL/Microsoft Corporation)
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[4228] ntdll.dll!NtQueryFullAttributesFile + B 77C04C5F 1 Byte [E2]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[4228] ntdll.dll!NtSetInformationFile + 6 77C0513A 4 Bytes [28, 01, 06, 00]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[4228] ntdll.dll!NtSetInformationFile + B 77C0513F 1 Byte [E2]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[4228] ntdll.dll!NtSetInformationThread + 6 77C0518A 4 Bytes [28, 02, 06, 00]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[4228] ntdll.dll!NtSetInformationThread + B 77C0518F 1 Byte [E2]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[4228] ntdll.dll!NtUnmapViewOfSection + 6 77C0542A 1 Byte [68]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[4228] ntdll.dll!NtUnmapViewOfSection + 6 77C0542A 4 Bytes [68, 03, 06, 00]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[4228] ntdll.dll!NtUnmapViewOfSection + B 77C0542F 1 Byte [E2]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[4664] ntdll.dll!NtCreateFile + 6 77C0422A 4 Bytes [28, 00, 06, 00]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[4664] ntdll.dll!NtCreateFile + B 77C0422F 1 Byte [E2]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[4664] ntdll.dll!NtMapViewOfSection + 6 77C0497A 1 Byte [28]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[4664] ntdll.dll!NtMapViewOfSection + 6 77C0497A 4 Bytes [28, 03, 06, 00]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[4664] ntdll.dll!NtMapViewOfSection + B 77C0497F 1 Byte [E2]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[4664] ntdll.dll!NtOpenFile + 6 77C04A0A 4 Bytes [68, 00, 06, 00]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[4664] ntdll.dll!NtOpenFile + B 77C04A0F 1 Byte [E2]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[4664] ntdll.dll!NtOpenProcess + 6 77C04A8A 4 Bytes [A8, 01, 06, 00]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[4664] ntdll.dll!NtOpenProcess + B 77C04A8F 1 Byte [E2]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[4664] ntdll.dll!NtOpenProcessToken + 6 77C04A9A 4 Bytes CALL 76C050A0 C:\Windows\system32\MSCTF.dll (MSCTF Server DLL/Microsoft Corporation)
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[4664] ntdll.dll!NtOpenProcessToken + B 77C04A9F 1 Byte [E2]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[4664] ntdll.dll!NtOpenProcessTokenEx + 6 77C04AAA 4 Bytes [A8, 02, 06, 00]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[4664] ntdll.dll!NtOpenProcessTokenEx + B 77C04AAF 1 Byte [E2]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[4664] ntdll.dll!NtOpenThread + 6 77C04AFA 4 Bytes [68, 01, 06, 00]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[4664] ntdll.dll!NtOpenThread + B 77C04AFF 1 Byte [E2]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[4664] ntdll.dll!NtOpenThreadToken + 6 77C04B0A 4 Bytes [68, 02, 06, 00]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[4664] ntdll.dll!NtOpenThreadToken + B 77C04B0F 1 Byte [E2]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[4664] ntdll.dll!NtOpenThreadTokenEx + 6 77C04B1A 4 Bytes CALL 76C05121 C:\Windows\system32\MSCTF.dll (MSCTF Server DLL/Microsoft Corporation)
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[4664] ntdll.dll!NtOpenThreadTokenEx + B 77C04B1F 1 Byte [E2]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[4664] ntdll.dll!NtQueryAttributesFile + 6 77C04BAA 4 Bytes [A8, 00, 06, 00]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[4664] ntdll.dll!NtQueryAttributesFile + B 77C04BAF 1 Byte [E2]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[4664] ntdll.dll!NtQueryFullAttributesFile + 6 77C04C5A 4 Bytes CALL 76C0525F C:\Windows\system32\MSCTF.dll (MSCTF Server DLL/Microsoft Corporation)
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[4664] ntdll.dll!NtQueryFullAttributesFile + B 77C04C5F 1 Byte [E2]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[4664] ntdll.dll!NtSetInformationFile + 6 77C0513A 4 Bytes [28, 01, 06, 00]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[4664] ntdll.dll!NtSetInformationFile + B 77C0513F 1 Byte [E2]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[4664] ntdll.dll!NtSetInformationThread + 6 77C0518A 4 Bytes [28, 02, 06, 00]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[4664] ntdll.dll!NtSetInformationThread + B 77C0518F 1 Byte [E2]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[4664] ntdll.dll!NtUnmapViewOfSection + 6 77C0542A 1 Byte [68]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[4664] ntdll.dll!NtUnmapViewOfSection + 6 77C0542A 4 Bytes [68, 03, 06, 00]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[4664] ntdll.dll!NtUnmapViewOfSection + B 77C0542F 1 Byte [E2]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[5652] ntdll.dll!NtCreateFile + 6 77C0422A 4 Bytes [28, 00, 06, 00]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[5652] ntdll.dll!NtCreateFile + B 77C0422F 1 Byte [E2]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[5652] ntdll.dll!NtMapViewOfSection + 6 77C0497A 1 Byte [28]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[5652] ntdll.dll!NtMapViewOfSection + 6 77C0497A 4 Bytes [28, 03, 06, 00]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[5652] ntdll.dll!NtMapViewOfSection + B 77C0497F 1 Byte [E2]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[5652] ntdll.dll!NtOpenFile + 6 77C04A0A 4 Bytes [68, 00, 06, 00]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[5652] ntdll.dll!NtOpenFile + B 77C04A0F 1 Byte [E2]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[5652] ntdll.dll!NtOpenProcess + 6 77C04A8A 4 Bytes [A8, 01, 06, 00]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[5652] ntdll.dll!NtOpenProcess + B 77C04A8F 1 Byte [E2]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[5652] ntdll.dll!NtOpenProcessToken + 6 77C04A9A 4 Bytes CALL 76C050A0 C:\Windows\system32\MSCTF.dll (MSCTF Server DLL/Microsoft Corporation)
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[5652] ntdll.dll!NtOpenProcessToken + B 77C04A9F 1 Byte [E2]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[5652] ntdll.dll!NtOpenProcessTokenEx + 6 77C04AAA 4 Bytes [A8, 02, 06, 00]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[5652] ntdll.dll!NtOpenProcessTokenEx + B 77C04AAF 1 Byte [E2]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[5652] ntdll.dll!NtOpenThread + 6 77C04AFA 4 Bytes [68, 01, 06, 00]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[5652] ntdll.dll!NtOpenThread + B 77C04AFF 1 Byte [E2]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[5652] ntdll.dll!NtOpenThreadToken + 6 77C04B0A 4 Bytes [68, 02, 06, 00]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[5652] ntdll.dll!NtOpenThreadToken + B 77C04B0F 1 Byte [E2]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[5652] ntdll.dll!NtOpenThreadTokenEx + 6 77C04B1A 4 Bytes CALL 76C05121 C:\Windows\system32\MSCTF.dll (MSCTF Server DLL/Microsoft Corporation)
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[5652] ntdll.dll!NtOpenThreadTokenEx + B 77C04B1F 1 Byte [E2]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[5652] ntdll.dll!NtQueryAttributesFile + 6 77C04BAA 4 Bytes [A8, 00, 06, 00]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[5652] ntdll.dll!NtQueryAttributesFile + B 77C04BAF 1 Byte [E2]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[5652] ntdll.dll!NtQueryFullAttributesFile + 6 77C04C5A 4 Bytes CALL 76C0525F C:\Windows\system32\MSCTF.dll (MSCTF Server DLL/Microsoft Corporation)
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[5652] ntdll.dll!NtQueryFullAttributesFile + B 77C04C5F 1 Byte [E2]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[5652] ntdll.dll!NtSetInformationFile + 6 77C0513A 4 Bytes [28, 01, 06, 00]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[5652] ntdll.dll!NtSetInformationFile + B 77C0513F 1 Byte [E2]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[5652] ntdll.dll!NtSetInformationThread + 6 77C0518A 4 Bytes [28, 02, 06, 00]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[5652] ntdll.dll!NtSetInformationThread + B 77C0518F 1 Byte [E2]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[5652] ntdll.dll!NtUnmapViewOfSection + 6 77C0542A 1 Byte [68]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[5652] ntdll.dll!NtUnmapViewOfSection + 6 77C0542A 4 Bytes [68, 03, 06, 00]
.text C:\Users\JSPENCER\AppData\Local\Google\Chrome\Application\chrome.exe[5652] ntdll.dll!NtUnmapViewOfSection + B 77C0542F 1 Byte [E2]

—- Devices - GMER 1.0.15 —-

AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 eabfiltr.sys (QLB PS/2 Keyboard filter driver/Hewlett-Packard Development Company, L.P.)
AttachedDevice \Driver\tdx \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\tdx \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\tdx \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

—- Files - GMER 1.0.15 —-

File C:\Windows\$NtUninstallKB62280$\4126961970 0 bytes
File C:\Windows\$NtUninstallKB62280$\485945278 0 bytes
File C:\Windows\$NtUninstallKB62280$\485945278\@ 2048 bytes
File C:\Windows\$NtUninstallKB62280$\485945278\bckfg.tmp 764 bytes
File C:\Windows\$NtUninstallKB62280$\485945278\cfg.ini 207 bytes
File C:\Windows\$NtUninstallKB62280$\485945278\Desktop.ini 4608 bytes
File C:\Windows\$NtUninstallKB62280$\485945278\keywords 67 bytes
File C:\Windows\$NtUninstallKB62280$\485945278\kwrd.dll 223744 bytes
File C:\Windows\$NtUninstallKB62280$\485945278\L 0 bytes
File C:\Windows\$NtUninstallKB62280$\485945278\L\qnbwvoto 66560 bytes
File C:\Windows\$NtUninstallKB62280$\485945278\lsflt7.ver 5176 bytes
File C:\Windows\$NtUninstallKB62280$\485945278\U 0 bytes
File C:\Windows\$NtUninstallKB62280$\485945278\U\00000001.@ 1536 bytes
File C:\Windows\$NtUninstallKB62280$\485945278\U\00000002.@ 224768 bytes
File C:\Windows\$NtUninstallKB62280$\485945278\U\00000004.@ 1024 bytes
File C:\Windows\$NtUninstallKB62280$\485945278\U\80000000.@ 1024 bytes
File C:\Windows\$NtUninstallKB62280$\485945278\U\80000004.@ 12800 bytes
File C:\Windows\$NtUninstallKB62280$\485945278\U\80000032.@ 98304 bytes

—- EOF - GMER 1.0.15 —-
Hi,

Please do the following

Refer to the ComboFix User's Guide

  • Download ComboFix from one of these locations:

    Link 1
    Link 2

    * IMPORTANT !!! Place ComboFix.exe on your Desktop
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with ComboFix.
    You can get help on disabling your protection programs here
  • Double click on ComboFix.exe & follow the prompts.
  • Your desktop may go blank. This is normal. It will return when ComboFix is done. ComboFix may reboot your machine. This is normal.
  • When finished, it shall produce a log for you. Post that log in your next reply

    Note:
    Do not mouseclick combofix's window whilst it's running. That may cause it to stall.


    ———————————————————————————————
  • Ensure your AntiVirus and AntiSpyware applications are re-enabled.

    ———————————————————————————————

NOTE: If you encounter a message "illegal operation attempted on registry key that has been marked for deletion" and no programs will run - please just reboot and that will resolve that error.
here is the resulting log from combofix



ComboFix 11-11-30.03 - JSPENCER 11/30/2011 16:52:42.2.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2037.1173 [GMT -5:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
SP: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
—- Previous Run ——-
.
c:\program files\SelectRebates
c:\program files\SelectRebates\FFToolbar\chrome.manifest
c:\program files\SelectRebates\FFToolbar\chrome\sahtoolbar.jar
c:\program files\SelectRebates\FFToolbar\defaults\preferences\sahtoolbar.js
c:\program files\SelectRebates\FFToolbar\install.rdf
c:\program files\SelectRebates\SahImages\bg-gradient.gif
c:\program files\SelectRebates\SahImages\button-close.gif
c:\program files\SelectRebates\SahImages\sah-logopop.gif
c:\program files\SelectRebates\SelectAlerts.dat
c:\program files\SelectRebates\SelectRebates.ini
c:\program files\SelectRebates\SelectRebatesA.dat
c:\program files\SelectRebates\SelectRebatesApi.exe
c:\program files\SelectRebates\SelectRebatesB.dat
c:\program files\SelectRebates\SelectRebatesBT.dat
c:\program files\SelectRebates\SelectRebatesDownload.exe
c:\program files\SelectRebates\SRebates.dll
c:\program files\SelectRebates\SRFF3.dll
c:\program files\SelectRebates\Toolbar\basis.xml
c:\program files\SelectRebates\Toolbar\basis.xml.bak
c:\program files\SelectRebates\Toolbar\Basis.xml.dym
c:\program files\SelectRebates\Toolbar\Blank.bmp
c:\program files\SelectRebates\Toolbar\CashBack.bmp
c:\program files\SelectRebates\Toolbar\Coupons.bmp
c:\program files\SelectRebates\Toolbar\GroceryCoupon.bmp
c:\program files\SelectRebates\Toolbar\i_magnifying.bmp
c:\program files\SelectRebates\Toolbar\icons.bmp
c:\program files\SelectRebates\Toolbar\ImageCache\alert-red.bmp
c:\program files\SelectRebates\Toolbar\logo.bmp
c:\program files\SelectRebates\Toolbar\logo_24.bmp
c:\program files\SelectRebates\Toolbar\logo_HotSpots.bmp
c:\program files\SelectRebates\Toolbar\ReviewSite.bmp
c:\program files\SelectRebates\Toolbar\RightControls.dym
c:\program files\SelectRebates\Toolbar\Scissors.bmp
c:\program files\SelectRebates\Toolbar\ShOPathometoolbar.dll
c:\users\JSPENCER\AppData\Roaming\ldr.ini
c:\users\JSPENCER\GoToAssistDownloadHelper.exe
c:\windows\$NtUninstallKB62280$
c:\windows\$NtUninstallKB62280$\4126961970
c:\windows\$NtUninstallKB62280$\485945278\@
c:\windows\$NtUninstallKB62280$\485945278\bckfg.tmp
c:\windows\$NtUninstallKB62280$\485945278\cfg.ini
c:\windows\$NtUninstallKB62280$\485945278\Desktop.ini
c:\windows\$NtUninstallKB62280$\485945278\keywords
c:\windows\$NtUninstallKB62280$\485945278\kwrd.dll
c:\windows\$NtUninstallKB62280$\485945278\L\qnbwvoto
c:\windows\$NtUninstallKB62280$\485945278\lsflt7.ver
c:\windows\$NtUninstallKB62280$\485945278\U\00000001.@
c:\windows\$NtUninstallKB62280$\485945278\U\00000002.@
c:\windows\$NtUninstallKB62280$\485945278\U\00000004.@
c:\windows\$NtUninstallKB62280$\485945278\U\80000000.@
c:\windows\$NtUninstallKB62280$\485945278\U\80000004.@
c:\windows\$NtUninstallKB62280$\485945278\U\80000032.@
c:\windows\system32\BSTIEPrintCtl1.dll
c:\windows\system32\certstore.dat
c:\windows\system32\Temp
.
.
((((((((((((((((((((((((( Files Created from 2011-10-28 to 2011-11-30 )))))))))))))))))))))))))))))))
.
.
2011-11-30 22:01 . 2011-11-30 22:01 ——– d—–w- c:\users\Mcx1\AppData\Local\temp
2011-11-30 22:01 . 2011-11-30 22:01 ——– d—–w- c:\users\Guest\AppData\Local\temp
2011-11-30 22:01 . 2011-11-30 22:01 ——– d—–w- c:\users\Default\AppData\Local\temp
2011-11-30 21:28 . 2011-11-30 22:01 ——– d—–w- c:\users\JSPENCER\AppData\Local\temp
2011-11-28 05:39 . 2011-11-28 05:39 ——– d—–w- c:\programdata\Carbonite
2011-11-27 04:43 . 2011-11-27 04:43 388096 —-a-r- c:\users\JSPENCER\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-11-20 06:47 . 2011-11-20 06:47 ——– dc—-w- C:\$AVG
2011-11-20 06:46 . 2011-11-20 06:46 ——– d—–w- c:\users\JSPENCER\AppData\Roaming\GkkUUVelOBtP0cS
2011-11-20 06:45 . 2011-11-20 06:45 ——– d—–w- c:\users\JSPENCER\AppData\Roaming\giFpGQ6W7RgXjYe
2011-11-20 06:45 . 2011-11-20 06:45 ——– d—–w- c:\users\JSPENCER\AppData\Roaming\ix1iba6J7E8CVlB
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-29 01:14 . 2011-06-19 20:19 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-11-29 01:11 . 2009-10-20 20:10 66560 —-a-w- c:\windows\system32\drivers\smb.sys
2011-10-07 10:23 . 2011-10-07 10:23 230608 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2011-10-04 10:21 . 2011-10-04 10:21 16720 —-a-w- c:\windows\system32\drivers\AVGIDSShim.sys
2011-09-13 10:30 . 2011-09-13 10:30 32592 —-a-w- c:\windows\system32\drivers\avgrkx86.sys
2011-11-23 17:06 . 2011-04-01 14:28 134104 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2011-05-17 17:29 1490312 -c–a-w- c:\program files\Ask.com\GenericAskToolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2011-05-17 1490312]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2011-05-17 1490312]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Green]
@="{95A27763-F62A-4114-9072-E81D87DE3B68}"
[HKEY_CLASSES_ROOT\CLSID\{95A27763-F62A-4114-9072-E81D87DE3B68}]
2011-10-29 23:04 1005712 -c–a-r- c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Partial]
@="{E300CD91-100F-4E67-9AF3-1384A6124015}"
[HKEY_CLASSES_ROOT\CLSID\{E300CD91-100F-4E67-9AF3-1384A6124015}]
2011-10-29 23:04 1005712 -c–a-r- c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Yellow]
@="{5E529433-B50E-4bef-A63B-16A6B71B071A}"
[HKEY_CLASSES_ROOT\CLSID\{5E529433-B50E-4bef-A63B-16A6B71B071A}]
2011-10-29 23:04 1005712 -c–a-r- c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Analogue Vista Clock"="c:\program files\Analogue Vista Clock\Analogue Vista Clock.exe" [2010-12-02 512480]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"DW6"="c:\program files\The Weather Channel FW\Desktop\DesktopWeather.exe" [2011-06-08 822456]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-10-08 39408]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WAWifiMessage"="c:\program files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe" [2007-01-10 317128]
"TkBellExe"="c:\program files\Real\RealPlayer\update\realsched.exe" [2010-12-19 274608]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-07-06 413696]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2007-03-29 176128]
"QlbCtrl"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2007-06-11 184320]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-06-06 138008]
"PDFHook"="c:\program files\Nuance\PDF Professional 6\pdfpro6hook.exe" [2009-07-27 1275168]
"PDF6 Registry Controller"="c:\program files\Nuance\PDF Professional 6\RegistryController.exe" [2009-07-27 110880]
"Nuance PDF Professional 6-reminder"="c:\program files\Nuance\PDF Professional 6\Ereg\Ereg.exe" [2008-11-03 54560]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2008-06-10 1406024]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-06-06 142104]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-03-01 472776]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2006-12-11 49152]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-06-06 154392]
"AVG_TRAY"="c:\program files\AVG\AVG2012\avgtray.exe" [2011-10-25 2415456]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2006-11-07 159744]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696]
"Intuit SyncManager"="c:\program files\Common Files\Intuit\Sync\IntuitSyncManager.exe" [2009-08-31 996616]
"Carbonite Backup"="c:\program files\Carbonite\Carbonite Backup\CarboniteUI.exe" [2011-10-29 1063056]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Launcher"="c:\windows\SMINST\launcher.exe" [2006-11-08 44128]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2009-9-3 1153824]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~1\AVG\AVG2012\avgrsx.exe /sync /restart
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
backup=c:\windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup
backupExtension=.CommonStartup
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^QuickBooks Update Agent.lnk]
backup=c:\windows\pss\QuickBooks Update Agent.lnk.CommonStartup
backupExtension=.CommonStartup
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ApnUpdater]
2011-05-17 17:29 395144 -c–a-w- c:\program files\Ask.com\Updater\Updater.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Mobile-based device management]
2006-11-02 09:45 215552 —-a-w- c:\windows\WindowsMobile\wmdSync.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
"AntiSpywareOverride"=dword:00000001
.
R2 AVGIDSAgent;AVGIDSAgent;c:\program files\AVG\AVG2012\AVGIDSAgent.exe [2011-10-12 4433248]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-06-23 135664]
R2 SqlCSS;SQL Server EXPRESS;c:\windows\System32\svchost.exe [2008-01-19 21504]
R3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2010-06-23 135664]
R3 TYKEY;Triple S PC/SC Reader Service;c:\windows\system32\Drivers\Triplesp.sys [2005-04-20 17920]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S0 AVGIDSEH;AVGIDSEH;c:\windows\system32\DRIVERS\AVGIDSEH.Sys [2011-07-11 23120]
S0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\DRIVERS\avgrkx86.sys [2011-09-13 32592]
S1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\DRIVERS\avgldx86.sys [2011-10-07 230608]
S1 Avgtdix;AVG TDI Driver;c:\windows\system32\DRIVERS\avgtdix.sys [2011-07-11 295248]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
S2 avgwd;AVG WatchDog;c:\program files\AVG\AVG2012\avgwdsvc.exe [2011-08-02 192776]
S2 PDFProFiltSrv;PDFProFiltSrv;c:\program files\Nuance\PDF Professional 6\PDFProFiltSrv.exe [2009-07-27 134944]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
S2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2007-01-04 24652]
S3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\DRIVERS\AVGIDSDriver.Sys [2011-07-11 134736]
S3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\DRIVERS\AVGIDSFilter.Sys [2011-07-11 24272]
S3 AVGIDSShim;AVGIDSShim;c:\windows\system32\DRIVERS\AVGIDSShim.Sys [2011-10-04 16720]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
Sqlses REG_MULTI_SZ SqlCSS
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2007-04-19 20:23 452136 —-a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder
.
2011-11-28 c:\windows\Tasks\Carbonite Installer - Start Carbonite UI.job
- c:\program files\Carbonite\Carbonite Backup\CarboniteUI.exe [2011-10-29 23:04]
.
2011-11-30 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-06-23 14:08]
.
2011-11-30 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-06-23 14:08]
.
2011-11-30 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3395706147-3244153660-2302503657-1000Core.job
- c:\users\JSPENCER\AppData\Local\Google\Update\GoogleUpdate.exe [2010-08-30 03:30]
.
2011-11-30 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3395706147-3244153660-2302503657-1000UA.job
- c:\users\JSPENCER\AppData\Local\Google\Update\GoogleUpdate.exe [2010-08-30 03:30]
.
2011-04-26 c:\windows\Tasks\User_Feed_Synchronization-{2298A777-CFC3-4FC7-816D-3C48BE195F7A}.job
- c:\windows\system32\msfeedssync.exe [2011-07-14 04:17]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://firstfinancialsecurity.com/
uDefault_Search_URL = hxxp://www.google.com/ie
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=73&bd=PRESARIO&pf=laptop
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Append the content of the link to existing PDF file - c:\program files\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll/ZeonIEAppend.HTML
IE: Append the content of the selected links to existing PDF file - c:\program files\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll/ZeonIEAppendSelLinks.HTML
IE: Append to existing PDF file - c:\program files\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll/ZeonIEAppend.HTML
IE: Create PDF file - c:\program files\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll/ZeonIECapture.HTML
IE: Create PDF file from the content of the link - c:\program files\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll/ZeonIECapture.HTML
IE: Create PDF files from the selected links - c:\program files\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll/ZeonIECaptureSelLinks.HTML
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html
IE: Open with Nuance PDF Converter 6.0 - c:\program files\Nuance\PDF Professional 6\cnvres_eng.dll /100
IE: Open with PDF Professional 6 - c:\program files\Nuance\PDF Professional 6\Bin\PlusIEContextMenu.dll/PlusIEContextMenu.htm
Trusted Zone: charlestoncounty.org\imgweb
Trusted Zone: experienceretirement.com\www
Trusted Zone: investprogram.com\www
Trusted Zone: nationalife.com\www
Trusted Zone: nationallife.com\www
TCP: DhcpNameServer = [removed] [removed]
DPF: {531C8059-ED3C-481E-B46C-558CF2862F6B} - hxxp://imgweb.charlestoncounty.org/AppNet/activex/OBXWebSelect.cab
DPF: {93D532DD-85FC-4A92-8254-8DB5437D8690} - hxxp://imgweb.charlestoncounty.org/AppNet/activex/OBXPopup.cab
FF - ProfilePath - c:\users\JSPENCER\AppData\Roaming\Mozilla\Firefox\Profiles\eylpa8ce.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - google.com
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&type=524517&p=
FF - user.js: yahoo.ytff.general.dontshowhpoffer - true
.
- - - - ORPHANS REMOVED - - - -
.
SafeBoot-76285594.sys
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-11-30 17:01
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2011-11-30 17:05:25
ComboFix-quarantined-files.txt 2011-11-30 22:05
.
Pre-Run: 18,274,054,144 bytes free
Post-Run: 18,108,186,624 bytes free
.
- - End Of File - - 260E3B4205590B1BB97767EC9AF6F2FC
Hi,

Please do the following:

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

Folder::
c:\users\JSPENCER\AppData\Roaming\GkkUUVelOBtP0cS
c:\users\JSPENCER\AppData\Roaming\giFpGQ6W7RgXjYe
c:\users\JSPENCER\AppData\Roaming\ix1iba6J7E8CVlB

ClearJavaCache::

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"


Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix may request an update; please allow it.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.



NEXT



Please download Malwarebytes' Anti-Malware
  • Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT


Go here to run an online scanner from ESET.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activeX control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • When the scan completes, press the LIST OF THREATS FOUND button
  • Press EXPORT TO TEXT FILE , name the file ESETSCAN and save it to your desktop
  • Include the contents of this report in your next reply.
  • Press the BACK button.
  • Press Finish
ok… for the combofix i created a notepad file from the text you gave me and drug it to the combofix icon and it did its initial scan. then it rebooted the computer and went to the blue c-prompt screen with everything else black. on the screen it just said "please wait" and was like that for about 30 min. i figured it froze so i manually rebooted the computer. now i get to the main windows screen and the c-prompt screen opens and closes real fast across my screen and wont stop. i have rebooted my computer 2 more times to no avail. it keeps just opening and closing real fast. im now in safe mode so i can at least post this. please advise
reboot the machine as the computer starts to boot > tap F8 repeatedly until an option menu appears > arrow up to "Last Known Good Configuration" > hit enter the computer should boot normally
Please let me know that you are able to boot normally again, then just run DDS so i can see what malware remains on your machine, post the fresh log from DDS
Hi

please do this

  • When you boot your machine, press F8 to list the startup options, exactly as you would if you were trying to enter Safe Mode
  • Select "Disable Automatic Restart on System Failure", as shown here:

    [external image: Posted Image]
  • When your system BSODs, write down the STOP error code, as well as any written out error message back here.
    The STOP error will always appear, but the message may not.


let me know what message you are getting when you try and boot normally
that did not change anything, my computer did not BSOD. it boots to the normal screen with my wallpaper and icons then the command prompt keeps opening and closing by itself real fast across the screen. i watched the task manager under the applications menu and these are the applications that kept opening and closing by themselves: command prompt combofix command prompt C:/combofix/pev.3xe command prompt C:/combofix/CF12956.3xe
oh, OK, I misunderstood what you were describing

ComboFix was interrupted during it's run so it hasn't closed properly

Open task manager and end task on the C:/combofix/CF12956.3xe process



Now reboot and just let the computer sit for 30 minutes to an hour, see if ComboFix completes itself
so when i reboot and the cprompt starts opening and closing real fast i should just let it for about an hour? can i just uninstall and reinstall combofix
That won't make a difference as it has unpacked it's processes, yes, just let it sit there it won't harm the machine by flashing the command window, it's processes have been interrupted and it just needs to settle down

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI