This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

k8l.info [Solved]

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

When I boot up my computer, near the end of the bootup sequence, a message appears stating avg has blocked access to website k8l.info, even though internet explorer hasn't even opened up. Also, this message appears most times when I do open up internet explorer, and sometimes randomly after that while browsing the web. I am not trying to access this site. AVG states it is a known malicious site. Thanks in advance.



Log from Hijackthis

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 9:17:13 AM, on 11/29/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\Program Files\AVG\AVG2012\AVGRSX.EXE
C:\Program Files\AVG\AVG2012\avgcsrvx.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AVG\AVG2012\avgwdsvc.exe
C:\Acer\Empowering Technology\admServ.exe
C:\Program Files\AVG\AVG2012\avgnsx.exe
C:\Program Files\ATI\Catalyst Media Center\Kernel\TV\CLCapSvc.exe
C:\Program Files\ATI\Catalyst Media Center\Kernel\CLML_NTService\CLMLServer.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\8.0.1\ToolbarUpdater.exe
C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Launch Manager\LaunchAp.exe
C:\Program Files\Launch Manager\HotkeyApp.exe
C:\Program Files\Launch Manager\OSDCtrl.exe
C:\Program Files\Launch Manager\Wbutton.exe
C:\acer\Empowering Technology\ePower\epm-dm.exe
C:\Acer\Empowering Technology\eRecovery\Monitor.exe
C:\Acer\Empowering Technology\admtray.exe
C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
C:\WINDOWS\tsnp2std.exe
C:\WINDOWS\vsnp2std.exe
C:\Program Files\ATI\Catalyst Media Center\CMCService.exe
C:\Program Files\Brownie\BrstsWnd.exe
C:\Program Files\AVG\AVG2012\avgtray.exe
C:\Program Files\Messenger\msmsgs.exe
D:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
D:\Documents and Settings\Real\Local Settings\Application Data\TheWeatherNetwork\WeatherEye\WeatherEye.exe
C:\Program Files\Brownie\brpjp04a.exe
C:\Program Files\USB TV\EM28XX\BDARemote.exe
C:\Program Files\REALTEK\11n USB Wireless LAN Utility\RtWLan.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
D:\Hijack this\HiJackThis.exe
C:\WINDOWS\system32\NOTEPAD.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?

LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG10

\Toolbar\IEToolbar.dll
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: (no name) - {025C9902-B55C-4739-BD41-808BFBD23FF7} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common

Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program

Files\AVG\AVG2012\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {A3A9F3A6-E5B7-4666-A0B9-7901988AF11F} - (no file)
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG10

\Toolbar\IEToolbar.dll
O2 - BHO: (no name) - {AFEB5E5A-1C21-40BD-BCBC-E50860DC4000} - (no file)
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6

\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6

\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: (no name) - {FF64059D-4D2A-4D6B-AA0F-2EE4A2FE3856} - (no file)
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\WINDOWS\system32

\eDStoolbar.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG10

\Toolbar\IEToolbar.dll
O3 - Toolbar: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - (no file)
O4 - HKLM\..\Run: [preload] C:\Windows\RUNXMLPL.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [LaunchAp] "C:\Program Files\Launch Manager\LaunchAp.exe"
O4 - HKLM\..\Run: [LManager] "C:\Program Files\Launch Manager\HotkeyApp.exe"
O4 - HKLM\..\Run: [CtrlVol] "C:\Program Files\Launch Manager\CtrlVol.exe"
O4 - HKLM\..\Run: [LMgrOSD] "C:\Program Files\Launch Manager\OSDCtrl.exe"
O4 - HKLM\..\Run: [Wbutton] "C:\Program Files\Launch Manager\Wbutton.exe"
O4 - HKLM\..\Run: [EPM-DM] c:\acer\Empowering Technology\ePower\epm-dm.exe
O4 - HKLM\..\Run: [Acer ePower Management] C:\Acer\Empowering Technology\ePower\Acer ePower Management.exe boot
O4 - HKLM\..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\Monitor.exe
O4 - HKLM\..\Run: [ADMTray.exe] "C:\Acer\Empowering Technology\admtray.exe"
O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
O4 - HKLM\..\Run: [tsnp2std] C:\WINDOWS\tsnp2std.exe
O4 - HKLM\..\Run: [snp2std] C:\WINDOWS\vsnp2std.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [CMCService] "C:\Program Files\ATI\Catalyst Media Center\CMCService.exe"
O4 - HKLM\..\Run: [Media Codec Update Service] D:\Program Files\Essentials Codec Pack\update.exe -silent
O4 - HKLM\..\Run: [BrStsWnd] C:\Program Files\Brownie\BrstsWnd.exe Autorun
O4 - HKLM\..\Run: [AVG_TRAY] "C:\Program Files\AVG\AVG2012\avgtray.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] D:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [WeatherEye] D:\Documents and Settings\Real\Local Settings\Application

Data\TheWeatherNetwork\WeatherEye\WeatherEye.exe
O4 - Global Startup: BDARemote.lnk = ?
O4 - Global Startup: REALTEK 11n USB Wireless LAN Utility.lnk = C:\Program Files\REALTEK\11n USB Wireless LAN

Utility\RtWLan.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6

\bin\jp2iexp.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} -

D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network

Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program

Files\Messenger\msmsgs.exe
O18 - Protocol: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files\AVG\AVG10

\Toolbar\IEToolbar.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll
O18 - Protocol: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure

Search\ViProtocolInstaller\8.0.1\ViProtocol.dll
O20 - Winlogon Notify: byxxyyv - byxxyyv.dll (file missing)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32

\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} -

C:\WINDOWS\system32\browseui.dll
O23 - Service: AVG Security Toolbar Service - Unknown owner - C:\Program Files\AVG\AVG10\Toolbar\ToolbarBroker.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2012\avgwdsvc.exe
O23 - Service: AdminWorks Agent X6 (AWService) - Avocent Inc. - C:\Acer\Empowering Technology\admServ.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program

Files\ATI\Catalyst Media Center\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\ATI\Catalyst Media

Center\Kernel\TV\CLSched.exe
O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\ATI\Catalyst Media

Center\Kernel\CLML_NTService\CLMLServer.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program

Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6

\bin\jqs.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program

Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program

Files\WinPcap\rpcapd.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program

Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Sentinel Protection Server (SentinelProtectionServer) - SafeNet, Inc - C:\Program Files\Common

Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe
O23 - Service: vToolbarUpdater - Unknown owner - C:\Program Files\Common Files\AVG Secure

Search\vToolbarUpdater\8.0.1\ToolbarUpdater.exe
O24 - Desktop Component 0: (no name) - C:\Program Files\ComPlus Applications\wuoryro.html

–
End of file - 11568 bytes
Hi,

Please do the following:

Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.


NEXT

Please download aswMBR to your desktop.
  • Double click the aswMBR.exe icon to run it
  • When asked if you want to download Avast's virus definitions please select Yes.
  • Click the Scan button to start the scan
  • On completion of the scan, click the save log button, save it to your desktop and post it in your next reply.
as long as your security programs are disabled, then you should be fine as script blocking is usually included with security programs
ok, so here are the text files from the scan results requested. However, since I posted the first message about this problem, the appearances of these avg message boxes seem to have miraculously reduced to a few sporadic appearances. Plus, interestingly enough, as all this happened, internet explorer now automatically goes to an "avg secure search page" when I open a new tab after the initial opening of the browser. Makes me think AVG orchestrated the whole thing. So my thoughts are, if you do not find a solution immediately from the files I am going to post now, to let the issue go. I can always ask again if it becomes a real problem again. Here is the DDS text file . DDS (Ver_2011-08-26.01) - FAT32x86 Internet Explorer: 8.0.6001.18702 Run by [removed] at 18:18:22 on 2011-12-03 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.502.33 [GMT -8:00] . AV: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF} . ============== Running Processes =============== . C:\Program Files\AVG\AVG2012\AVGRSX.EXE C:\Program Files\AVG\AVG2012\avgcsrvx.exe C:\WINDOWS\system32\svchost -k DcomLaunch SVCHOST.EXE C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup C:\Program Files\Intel\Wireless\Bin\EvtEng.exe C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe C:\WINDOWS\Explorer.EXE SVCHOST.EXE SVCHOST.EXE C:\WINDOWS\system32\spoolsv.exe SVCHOST.EXE C:\Program Files\AVG\AVG2012\avgwdsvc.exe C:\Acer\Empowering Technology\admServ.exe C:\Program Files\AVG\AVG2012\avgnsx.exe C:\Program Files\ATI\Catalyst Media Center\Kernel\TV\CLCapSvc.exe C:\Program Files\ATI\Catalyst Media Center\Kernel\CLML_NTService\CLMLServer.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\9.0.1\ToolbarUpdater.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\system32\igfxtray.exe C:\WINDOWS\system32\hkcmd.exe C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\system32\igfxpers.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\WINDOWS\SOUNDMAN.EXE C:\Program Files\Launch Manager\LaunchAp.exe C:\Program Files\Launch Manager\HotkeyApp.exe C:\Program Files\Launch Manager\OSDCtrl.exe C:\Program Files\Launch Manager\Wbutton.exe C:\acer\Empowering Technology\ePower\epm-dm.exe C:\Acer\Empowering Technology\eRecovery\Monitor.exe C:\Acer\Empowering Technology\admtray.exe C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe C:\WINDOWS\tsnp2std.exe C:\WINDOWS\vsnp2std.exe C:\Program Files\ATI\Catalyst Media Center\CMCService.exe C:\Program Files\Brownie\BrstsWnd.exe C:\Program Files\AVG\AVG2012\avgtray.exe C:\Program Files\AVG Secure Search\vprot.exe C:\Program Files\Messenger\msmsgs.exe D:\Program Files\Spybot - Search & Destroy\TeaTimer.exe D:\Documents and Settings\Real\Local Settings\Application Data\TheWeatherNetwork\WeatherEye\WeatherEye.exe C:\Program Files\Brownie\brpjp04a.exe C:\Program Files\USB TV\EM28XX\BDARemote.exe C:\Program Files\REALTEK\11n USB Wireless LAN Utility\RtWLan.exe C:\Program Files\AVG\AVG2012\avgscanx.exe C:\Program Files\AVG\AVG2012\avgcsrvx.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\system32\NOTEPAD.EXE C:\WINDOWS\system32\wuauclt.exe . ============== Pseudo HJT Report =============== . uStart Page = about:blank uSearch Page = hxxp://www.google.com uSearch Bar = hxxp://www.google.com/ie uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s mSearchAssistant = hxxp://www.google.com/ie uURLSearchHooks: H - No File mURLSearchHooks: H - No File BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File BHO: {025C9902-B55C-4739-BD41-808BFBD23FF7} - No File BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg2012\avgssie.dll BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - d:\progra~1\spybot~1\SDHelper.dll BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll BHO: AVG Security Toolbar: {95b7759c-8c7f-4bf1-b163-73684a933233} - c:\program files\avg secure search\9.0.0.18\AVG Secure Search_toolbar.dll BHO: {A3A9F3A6-E5B7-4666-A0B9-7901988AF11F} - No File BHO: {AFEB5E5A-1C21-40BD-BCBC-E50860DC4000} - No File BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll BHO: {FF64059D-4D2A-4D6B-AA0F-2EE4A2FE3856} - No File TB: Acer eDataSecurity Management: {5cbe3b7c-1e47-477e-a7dd-396db0476e29} - c:\windows\system32\eDStoolbar.dll TB: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File TB: AVG Security Toolbar: {95b7759c-8c7f-4bf1-b163-73684a933233} - c:\program files\avg secure search\9.0.0.18\AVG Secure Search_toolbar.dll TB: {C4069E3A-68F1-403E-B40E-20066696354B} - No File TB: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No File {e7df6bff-55a5-4eb7-a673-4ed3e9456d39} uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [SpybotSD TeaTimer] d:\program files\spybot - search & destroy\TeaTimer.exe uRun: [WeatherEye] d:\documents and settings\real\local settings\application data\theweathernetwork\weathereye\WeatherEye.exe mRun: [preload] c:\windows\RUNXMLPL.exe mRun: [IMJPMIG8.1] "c:\windows\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 mRun: [MSPY2002] c:\windows\system32\ime\pintlgnt\ImScInst.exe /SYNC mRun: [PHIME2002ASync] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /SYNC mRun: [PHIME2002A] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /IMEName mRun: [igfxtray] c:\windows\system32\igfxtray.exe mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe mRun: [igfxpers] c:\windows\system32\igfxpers.exe mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe mRun: [SoundMan] SOUNDMAN.EXE mRun: [LaunchAp] "c:\program files\launch manager\LaunchAp.exe" mRun: [LManager] "c:\program files\launch manager\HotkeyApp.exe" mRun: [CtrlVol] "c:\program files\launch manager\CtrlVol.exe" mRun: [LMgrOSD] "c:\program files\launch manager\OSDCtrl.exe" mRun: [Wbutton] "c:\program files\launch manager\Wbutton.exe" mRun: [EPM-DM] c:\acer\empowering technology\epower\epm-dm.exe mRun: [Acer ePower Management] c:\acer\empowering technology\epower\Acer ePower Management.exe boot mRun: [eRecoveryService] c:\acer\empowering technology\erecovery\Monitor.exe mRun: [ADMTray.exe] "c:\acer\empowering technology\admtray.exe" mRun: [eDataSecurity Loader] c:\acer\empowering technology\edatasecurity\eDSloader.exe mRun: [tsnp2std] c:\windows\tsnp2std.exe mRun: [snp2std] c:\windows\vsnp2std.exe mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe" mRun: [CMCService] "c:\program files\ati\catalyst media center\CMCService.exe" mRun: [Media Codec Update Service] d:\program files\essentials codec pack\update.exe -silent mRun: [BrStsWnd] c:\program files\brownie\BrstsWnd.exe Autorun mRun: [AVG_TRAY] "c:\program files\avg\avg2012\avgtray.exe" mRun: [vProt] "c:\program files\avg secure search\vprot.exe" StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\bdarem~1.lnk - c:\program files\usb tv\em28xx\BDARemote.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\realte~1.lnk - c:\program files\realtek\11n usb wireless lan utility\RtWLan.exe IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000 IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBC} - c:\program files\java\jre6\bin\jp2iexp.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - d:\progra~1\spybot~1\SDHelper.dll DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg2012\avgpp.dll Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files\common files\avg secure search\viprotocolinstaller\9.0.1\ViProtocol.dll Notify: byxxyyv - byxxyyv.dll Notify: igfxcui - igfxdev.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: {FF64059D-4D2A-4D6B-AA0F-2EE4A2FE3856} - No File LSA: Authentication Packages = msv1_0 c:\windows\system32\mllmj.dll . ============= SERVICES / DRIVERS =============== . R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [2010-9-13 23120] R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2010-9-7 32592] R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2010-9-7 230608] R1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2010-9-7 40016] R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [2010-9-7 295248] R2 avgwd;AVG WatchDog;c:\program files\avg\avg2012\avgwdsvc.exe [2011-8-2 192776] R2 AWService;AdminWorks Agent X6;c:\acer\empowering technology\admServ.exe [2005-10-24 1314816] R2 vToolbarUpdater;vToolbarUpdater;c:\program files\common files\avg secure search\vtoolbarupdater\9.0.1\ToolbarUpdater.exe [2011-11-30 855904] R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [2010-8-19 134608] R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [2010-8-19 24272] R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [2010-8-19 16720] S1 mailKmd;mailKmd; [x] S3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files\avg\avg10\toolbar\ToolbarBroker.exe [2011-4-14 1025352] S3 AVGIDSAgent;AVGIDSAgent;c:\program files\avg\avg2012\AVGIDSAgent.exe [2011-10-12 4433248] S3 ewusbnet;HUAWEI USB-NDIS miniport;c:\windows\system32\drivers\ewusbnet.sys [2010-2-10 113280] S3 hwusbdev;Huawei DataCard USB PNP Device;c:\windows\system32\drivers\ewusbdev.sys [2010-2-10 100736] S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2006-12-26 32512] S3 Revoflt;Revoflt;c:\windows\system32\drivers\revoflt.sys [2011-10-15 27064] S3 RTL8192su;Realtek RTL8192SU Wireless LAN 802.11n USB 2.0 Network Adapter;c:\windows\system32\drivers\rtl8192su.sys [2010-4-26 563840] . =============== Created Last 30 ================ . 2011-11-30 19:03:08 ——– d—–w- c:\documents and settings\real\application data\AVG Secure Search 2011-11-30 18:51:09 ——– d—–w- c:\windows\system32\cache 2011-11-30 18:50:48 ——– d—–w- c:\documents and settings\all users\application data\AVG Secure Search . ==================== Find3M ==================== . 2011-11-16 06:17:38 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2011-10-10 14:22:42 692736 —-a-w- c:\windows\system32\inetcomm.dll 2011-10-07 14:23:48 230608 —-a-w- c:\windows\system32\drivers\avgldx86.sys 2011-10-04 14:21:42 16720 —-a-w- c:\windows\system32\drivers\AVGIDSShim.sys 2011-09-28 07:06:50 599040 —-a-w- c:\windows\system32\crypt32.dll 2011-09-26 19:41:20 611328 ——w- c:\windows\system32\uiautomationcore.dll 2011-09-26 19:41:20 220160 —-a-w- c:\windows\system32\oleacc.dll 2011-09-26 19:41:14 20480 —-a-w- c:\windows\system32\oleaccrc.dll 2011-09-13 14:30:10 32592 —-a-w- c:\windows\system32\drivers\avgrkx86.sys 2011-09-06 14:20:52 1858944 —-a-w- c:\windows\system32\win32k.sys . ============= FINISH: 18:19:55.26 =============== Here is the dds attach text file . UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_2011-08-26.01) . Microsoft Windows XP Home Edition Boot Device: \Device\HarddiskVolume2 Install Date: 12/26/2006 12:15:37 PM System Uptime: 12/3/2011 5:51:56 PM (1 hours ago) . Motherboard: Acer | | Garda-910 Processor: Intel® Pentium® M processor 1.73GHz | U1 | 1729/133mhz . ==== Disk Partitions ========================= . C: is FIXED (FAT32) - 26 GiB total, 6.134 GiB free. D: is FIXED (FAT32) - 26 GiB total, 6.466 GiB free. E: is CDROM () . ==== Disabled Device Manager Items ============= . ==== System Restore Points =================== . RP939: 10/13/2011 6:46:02 PM - System Checkpoint RP940: 10/15/2011 10:06:38 AM - System Checkpoint RP941: 10/15/2011 10:44:06 AM - Installed AVG 2012 RP942: 10/15/2011 10:44:20 AM - Removed AVG 2011 RP943: 10/15/2011 10:44:43 AM - Installed AVG 2012 RP944: 10/15/2011 10:52:44 AM - Removed AVG 2011 RP945: 10/15/2011 12:28:49 PM - Revo Uninstaller Pro's restore point - MagicDisc 2.7.106 RP946: 10/17/2011 9:47:16 PM - System Checkpoint RP947: 10/19/2011 5:01:06 PM - System Checkpoint RP948: 10/20/2011 5:10:42 PM - System Checkpoint RP949: 10/21/2011 8:44:28 PM - System Checkpoint RP950: 10/22/2011 11:27:58 PM - System Checkpoint RP951: 10/24/2011 4:25:15 PM - System Checkpoint RP952: 10/25/2011 4:34:02 PM - System Checkpoint RP953: 10/26/2011 5:49:38 PM - System Checkpoint RP954: 10/27/2011 5:58:55 PM - System Checkpoint RP955: 10/27/2011 8:05:36 PM - Software Distribution Service 3.0 RP956: 10/27/2011 8:33:48 PM - Software Distribution Service 3.0 RP957: 10/30/2011 4:49:59 PM - System Checkpoint RP958: 11/1/2011 4:48:21 PM - System Checkpoint RP959: 11/2/2011 5:03:01 PM - System Checkpoint RP960: 11/4/2011 10:45:40 PM - System Checkpoint RP961: 11/7/2011 4:36:28 PM - System Checkpoint RP962: 11/8/2011 4:38:55 PM - System Checkpoint RP963: 11/8/2011 9:41:02 PM - Software Distribution Service 3.0 RP964: 11/10/2011 5:22:40 PM - System Checkpoint RP965: 11/10/2011 6:36:43 PM - Software Distribution Service 3.0 RP966: 11/12/2011 1:05:38 PM - System Checkpoint RP967: 11/13/2011 7:18:15 PM - System Checkpoint RP968: 11/15/2011 4:32:53 PM - System Checkpoint RP969: 11/17/2011 3:23:35 PM - System Checkpoint RP970: 11/19/2011 10:07:13 AM - System Checkpoint RP971: 11/21/2011 4:34:55 PM - System Checkpoint RP972: 11/23/2011 4:14:18 PM - System Checkpoint RP973: 11/25/2011 3:32:10 PM - System Checkpoint RP974: 11/27/2011 11:21:53 AM - System Checkpoint RP975: 11/29/2011 10:12:06 AM - System Checkpoint RP976: 11/30/2011 11:28:24 AM - System Checkpoint RP977: 12/2/2011 10:54:11 AM - System Checkpoint . ==== Installed Programs ====================== . µTorrent Acer eDataSecurity Management Acer eDataSecurity Management 1.00.26 Acer eLock Management Acer Empowering Technology framework Acer eNet Management Acer ePerformance Management Acer ePower Management Acer ePresentation Management Acer eSettings Management Acer GridVista Adobe Flash Player 11 ActiveX Adobe Reader 8.1.3 ATI - Software Uninstall Utility ATI AVIVO Codecs AVG 2012 Brother HL-2140 CASISuite60 Catalyst Media Center Catalyst Media Center DVD Authoring Module CCleaner Cisco Connect ConvertXtoDVD [removed] CoolTick Stock Ticker 8.62 Free NaturalReader getPlus®_ocx Hotfix for Windows Media Format 11 SDK (KB929399) Hotfix for Windows Media Player 11 (KB939683) Hotfix for Windows XP (KB2570791) Hotfix for Windows XP (KB952287) Hotfix for Windows XP (KB979306) Hotfix for Windows XP (KB981793) Intel® Graphics Media Accelerator Driver for Mobile Intel® PROSet/Wireless Software InterActual Player IrfanView (remove only) Java Auto Updater Java™ 6 Update 24 Launch Manager V1.1.0.1 mCore Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Security Update (KB2572067) Microsoft .NET Framework 1.1 Security Update (KB979906) Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Office Professional Edition 2003 Microsoft User-Mode Driver Framework Feature Pack 1.0 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 mMHouse Mobile Internet Key mPfMgr mProSafe MSXML 4.0 SP2 (KB936181) MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) mWlsSafe mXML NTI Backup NOW! 4 NTI CD & DVD-Maker OJOsoft Total Video Converter PowerDVD Realtek AC'97 Audio REALTEK Wireless LAN Driver and Utility Revo Uninstaller Pro 2.5.5 Security Update for Microsoft Windows (KB2564958) Security Update for Windows Internet Explorer 8 (KB2497640) Security Update for Windows Internet Explorer 8 (KB2510531) Security Update for Windows Internet Explorer 8 (KB2530548) Security Update for Windows Internet Explorer 8 (KB2544521) Security Update for Windows Internet Explorer 8 (KB2559049) Security Update for Windows Internet Explorer 8 (KB2586448) Security Update for Windows Internet Explorer 8 (KB971961) Security Update for Windows Internet Explorer 8 (KB972260) Security Update for Windows Internet Explorer 8 (KB981332) Security Update for Windows Internet Explorer 8 (KB982381) Security Update for Windows Media Player (KB2378111) Security Update for Windows Media Player (KB911564) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player (KB954155) Security Update for Windows Media Player (KB968816) Security Update for Windows Media Player (KB973540) Security Update for Windows Media Player (KB975558) Security Update for Windows Media Player (KB978695) Security Update for Windows Media Player 11 (KB936782) Security Update for Windows Media Player 11 (KB954154) Security Update for Windows Media Player 6.4 (KB925398) Security Update for Windows Media Player 9 (KB936782) Security Update for Windows XP (KB2079403) Security Update for Windows XP (KB2115168) Security Update for Windows XP (KB2121546) Security Update for Windows XP (KB2229593) Security Update for Windows XP (KB2296011) Security Update for Windows XP (KB2347290) Security Update for Windows XP (KB2360937) Security Update for Windows XP (KB2387149) Security Update for Windows XP (KB2393802) Security Update for Windows XP (KB2412687) Security Update for Windows XP (KB2419632) Security Update for Windows XP (KB2423089) Security Update for Windows XP (KB2440591) Security Update for Windows XP (KB2443105) Security Update for Windows XP (KB2476490) Security Update for Windows XP (KB2478960) Security Update for Windows XP (KB2478971) Security Update for Windows XP (KB2479943) Security Update for Windows XP (KB2481109) Security Update for Windows XP (KB2483185) Security Update for Windows XP (KB2485663) Security Update for Windows XP (KB2491683) Security Update for Windows XP (KB2506212) Security Update for Windows XP (KB2507618) Security Update for Windows XP (KB2507938) Security Update for Windows XP (KB2508272) Security Update for Windows XP (KB2508429) Security Update for Windows XP (KB2509553) Security Update for Windows XP (KB2535512) Security Update for Windows XP (KB2536276-v2) Security Update for Windows XP (KB2544893-v2) Security Update for Windows XP (KB2544893) Security Update for Windows XP (KB2562937) Security Update for Windows XP (KB2566454) Security Update for Windows XP (KB2567053) Security Update for Windows XP (KB2567680) Security Update for Windows XP (KB2570222) Security Update for Windows XP (KB2570947) Security Update for Windows XP (KB2592799) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB938464) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950759) Security Update for Windows XP (KB950760) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951066) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB954600) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956391) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956744) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB956844) Security Update for Windows XP (KB958215) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958869) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960225) Security Update for Windows XP (KB960714) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB960859) Security Update for Windows XP (KB961501) Security Update for Windows XP (KB963027) Security Update for Windows XP (KB969059) Security Update for Windows XP (KB969947) Security Update for Windows XP (KB970238) Security Update for Windows XP (KB970430) Security Update for Windows XP (KB971468) Security Update for Windows XP (KB971657) Security Update for Windows XP (KB972270) Security Update for Windows XP (KB973346) Security Update for Windows XP (KB973354) Security Update for Windows XP (KB973507) Security Update for Windows XP (KB973869) Security Update for Windows XP (KB973904) Security Update for Windows XP (KB974112) Security Update for Windows XP (KB974318) Security Update for Windows XP (KB974392) Security Update for Windows XP (KB974571) Security Update for Windows XP (KB975025) Security Update for Windows XP (KB975467) Security Update for Windows XP (KB975560) Security Update for Windows XP (KB975561) Security Update for Windows XP (KB975562) Security Update for Windows XP (KB975713) Security Update for Windows XP (KB977816) Security Update for Windows XP (KB977914) Security Update for Windows XP (KB978037) Security Update for Windows XP (KB978262) Security Update for Windows XP (KB978338) Security Update for Windows XP (KB978542) Security Update for Windows XP (KB978601) Security Update for Windows XP (KB978706) Security Update for Windows XP (KB979309) Security Update for Windows XP (KB979482) Security Update for Windows XP (KB979559) Security Update for Windows XP (KB979683) Security Update for Windows XP (KB979687) Security Update for Windows XP (KB980195) Security Update for Windows XP (KB980218) Security Update for Windows XP (KB980232) Security Update for Windows XP (KB980436) Security Update for Windows XP (KB981322) Security Update for Windows XP (KB981997) Security Update for Windows XP (KB982132) Security Update for Windows XP (KB982665) Send To Phone 2.1 Sentinel Protection Installer 7.1.0 Soft Data Fax Modem with SmartCP SoftV90 Data Fax Modem with SmartCP Spybot - Search & Destroy Spybot - Search & Destroy 1.5.2.20 SpywareBlaster 4.0 Synaptics Pointing Device Driver TickerTape 1.3 UDoTaxes2010 Ultra DVD Ripper 3.0.1203 Update for Windows Internet Explorer 8 (KB976662) Update for Windows Internet Explorer 8 (KB980182) Update for Windows XP (KB2345886) Update for Windows XP (KB2541763) Update for Windows XP (KB2616676-v2) Update for Windows XP (KB2641690) Update for Windows XP (KB951978) Update for Windows XP (KB955759) Update for Windows XP (KB967715) Update for Windows XP (KB968389) Update for Windows XP (KB971029) Update for Windows XP (KB971737) Update for Windows XP (KB973687) Update for Windows XP (KB973815) USB Video Driver USB2.0 PC Camera (SN9C201&202) VLC media player 0.9.8a WeatherEye WebFldrs XP WinAVI Video Converter Windows Driver Package - Advanced Micro Devices, Inc. (USB28xxBGA) Media (08/31/2007 5.7.0831.0) Windows Driver Package - eMPIA Technology Inc, (emAudio) MEDIA (08/31/2007 5.7.0831.0) Windows Essentials Media Codec Pack 1.0 Windows Internet Explorer 8 Windows Media Format 11 runtime Windows Media Player 11 Windows XP Service Pack 3 Yahoo! Install Manager Yahoo! Internet Mail Yahoo! Messenger . ==== Event Viewer Messages From Past Week ======== . 12/3/2011 6:18:25 PM, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751) 11/30/2011 10:45:44 AM, error: Service Control Manager [7022] - The CyberLink Background Capture Service (CBCS) service hung on starting. 11/30/2011 10:45:44 AM, error: Service Control Manager [7001] - The CyberLink Task Scheduler (CTS) service depends on the CyberLink Background Capture Service (CBCS) service which failed to start because of the following error: After starting, the service hung in a start-pending state. 11/29/2011 7:14:59 AM, error: sr [1] - The System Restore filter encountered the unexpected error '0xC0000001' while processing the file '' on the volume 'HarddiskVolume2'. It has stopped monitoring the volume. 11/29/2011 7:14:38 AM, error: Dhcp [1002] - The IP address lease 192.168.1.109 for the Network Card with network address 00166FA1A2E4 has been denied by the DHCP server 192.168.33.1 (The DHCP Server sent a DHCPNACK message). 11/29/2011 10:51:50 PM, error: Dhcp [1002] - The IP address lease 192.168.1.109 for the Network Card with network address 00166FA1A2E4 has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message). . ==== End Of File =========================== Here is the aswMBR text file aswMBR version 0.9.8.986 Copyright© 2011 AVAST Software Run date: 2011-12-03 20:51:50 —————————– 20:51:50.037 OS Version: Windows 5.1.2600 Service Pack 3 20:51:50.037 Number of processors: 1 586 0xD08 20:51:50.037 ComputerName: ACER-684C9A655D UserName: Real 20:51:50.880 Initialize success 20:57:41.099 AVAST engine defs: 11120302 20:58:34.396 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-4 20:58:34.396 Disk 0 Vendor: HTS541060G9AT00 MB3OA60A Size: 57231MB BusType: 3 20:58:36.427 Disk 0 MBR read successfully 20:58:36.427 Disk 0 MBR scan 20:58:36.537 Disk 0 unknown MBR code 20:58:36.537 Disk 0 scanning sectors +117194175 20:58:36.568 Disk 0 scanning C:\WINDOWS\system32\drivers 20:58:47.427 Service scanning 20:58:48.693 Modules scanning 20:58:53.646 Disk 0 trace - called modules: 20:58:53.677 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys PCIIDEX.SYS 20:58:53.677 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x82f3f4d8] 20:58:53.677 3 CLASSPNP.SYS[f8694fd7] -> nt!IofCallDriver -> \Device\000000a6[0x82fce290] 20:58:53.677 5 ACPI.sys[f848b620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-4[0x82fce7d8] 20:58:54.224 AVAST engine scan C:\WINDOWS 20:59:05.271 AVAST engine scan C:\WINDOWS\system32 21:00:44.302 AVAST engine scan C:\WINDOWS\system32\drivers 21:00:56.037 AVAST engine scan C:\Documents and Settings\Real 21:03:52.287 AVAST engine scan C:\Documents and Settings\All Users 21:04:27.334 Scan finished successfully 21:04:56.193 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Real\Desktop\MBR.dat" 21:04:56.209 The log file has been saved successfully to "C:\Documents and Settings\Real\Desktop\aswMBR.txt"
Hi,

Please do the following:



Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • Press Start Scan
    • Only if Malicious objects are found then ensure Cure is selected
    • Then click Continue > Reboot now
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)


NEXT



Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
Hello again,

Looks like you want to persevere, so I'll persevere too. Thanks, appreciate that.

Ran the programs TDS Killer and ComboFix. I noticed ComboFix did remove files and folders. The AVG message box appeared tonight, when I was booting up the computer to run these two programs. First time in two days. Anyway, here's the logs from both programs

TDSkiller log


19:47:20.0296 3152 TDSS rootkit removing tool 2.6.21.0 Nov 24 2011 12:32:44
19:47:20.0781 3152 ============================================================
19:47:20.0781 3152 Current date / time: 2011/12/04 19:47:20.0781
19:47:20.0781 3152 SystemInfo:
19:47:20.0781 3152
19:47:20.0781 3152 OS Version: 5.1.2600 ServicePack: 3.0
19:47:20.0781 3152 Product type: Workstation
19:47:20.0859 3152 ComputerName: ACER-684C9A655D
19:47:20.0859 3152 UserName: Real
19:47:20.0859 3152 Windows directory: C:\WINDOWS
19:47:20.0859 3152 System windows directory: C:\WINDOWS
19:47:20.0859 3152 Processor architecture: Intel x86
19:47:20.0859 3152 Number of processors: 1
19:47:20.0859 3152 Page size: 0x1000
19:47:20.0859 3152 Boot type: Normal boot
19:47:20.0859 3152 ============================================================
19:47:23.0328 3152 Initialize success
19:47:52.0218 2216 ============================================================
19:47:52.0218 2216 Scan started
19:47:52.0218 2216 Mode: Manual;
19:47:52.0218 2216 ============================================================
19:47:53.0109 2216 Abiosdsk - ok
19:47:53.0234 2216 abp480n5 (6abb91494fe6c59089b9336452ab2ea3) C:\WINDOWS\system32\DRIVERS\ABP480N5.SYS
19:47:53.0421 2216 abp480n5 - ok
19:47:53.0546 2216 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys
19:47:53.0828 2216 ACPI - ok
19:47:53.0937 2216 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\DRIVERS\ACPIEC.sys
19:47:54.0187 2216 ACPIEC - ok
19:47:54.0343 2216 adpu160m (9a11864873da202c996558b2106b0bbc) C:\WINDOWS\system32\DRIVERS\adpu160m.sys
19:47:54.0500 2216 adpu160m - ok
19:47:54.0703 2216 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
19:47:54.0703 2216 aec - ok
19:47:54.0828 2216 AegisP (30bb1bde595ca65fd5549462080d94e5) C:\WINDOWS\system32\DRIVERS\AegisP.sys
19:47:55.0031 2216 AegisP - ok
19:47:55.0156 2216 AFD (1e44bc1e83d8fd2305f8d452db109cf9) C:\WINDOWS\System32\drivers\afd.sys
19:47:55.0328 2216 AFD - ok
19:47:55.0437 2216 agp440 (08fd04aa961bdc77fb983f328334e3d7) C:\WINDOWS\system32\DRIVERS\agp440.sys
19:47:55.0625 2216 agp440 - ok
19:47:55.0750 2216 agpCPQ (03a7e0922acfe1b07d5db2eeb0773063) C:\WINDOWS\system32\DRIVERS\agpCPQ.sys
19:47:55.0937 2216 agpCPQ - ok
19:47:56.0078 2216 Aha154x (c23ea9b5f46c7f7910db3eab648ff013) C:\WINDOWS\system32\DRIVERS\aha154x.sys
19:47:56.0250 2216 Aha154x - ok
19:47:56.0343 2216 aic78u2 (19dd0fb48b0c18892f70e2e7d61a1529) C:\WINDOWS\system32\DRIVERS\aic78u2.sys
19:47:56.0484 2216 aic78u2 - ok
19:47:56.0578 2216 aic78xx (b7fe594a7468aa0132deb03fb8e34326) C:\WINDOWS\system32\DRIVERS\aic78xx.sys
19:47:56.0718 2216 aic78xx - ok
19:47:57.0015 2216 ALCXWDM (95aa37bec6c72c277c2caeaee736dd2d) C:\WINDOWS\system32\drivers\ALCXWDM.SYS
19:47:57.0218 2216 ALCXWDM - ok
19:47:57.0359 2216 AliIde (1140ab9938809700b46bb88e46d72a96) C:\WINDOWS\system32\DRIVERS\aliide.sys
19:47:57.0500 2216 AliIde - ok
19:47:57.0656 2216 alim1541 (cb08aed0de2dd889a8a820cd8082d83c) C:\WINDOWS\system32\DRIVERS\alim1541.sys
19:47:57.0765 2216 alim1541 - ok
19:47:57.0828 2216 amdagp (95b4fb835e28aa1336ceeb07fd5b9398) C:\WINDOWS\system32\DRIVERS\amdagp.sys
19:47:58.0000 2216 amdagp - ok
19:47:58.0125 2216 amsint (79f5add8d24bd6893f2903a3e2f3fad6) C:\WINDOWS\system32\DRIVERS\amsint.sys
19:47:58.0296 2216 amsint - ok
19:47:58.0421 2216 Arp1394 (b5b8a80875c1dededa8b02765642c32f) C:\WINDOWS\system32\DRIVERS\arp1394.sys
19:47:58.0609 2216 Arp1394 - ok
19:47:58.0734 2216 asc (62d318e9a0c8fc9b780008e724283707) C:\WINDOWS\system32\DRIVERS\asc.sys
19:47:58.0843 2216 asc - ok
19:47:58.0937 2216 asc3350p (69eb0cc7714b32896ccbfd5edcbea447) C:\WINDOWS\system32\DRIVERS\asc3350p.sys
19:47:59.0078 2216 asc3350p - ok
19:47:59.0203 2216 asc3550 (5d8de112aa0254b907861e9e9c31d597) C:\WINDOWS\system32\DRIVERS\asc3550.sys
19:47:59.0359 2216 asc3550 - ok
19:47:59.0562 2216 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
19:47:59.0765 2216 AsyncMac - ok
19:47:59.0906 2216 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
19:47:59.0906 2216 atapi - ok
19:48:00.0078 2216 Atdisk - ok
19:48:00.0140 2216 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
19:48:00.0281 2216 Atmarpc - ok
19:48:00.0390 2216 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
19:48:00.0578 2216 audstub - ok
19:48:00.0828 2216 AVGIDSDriver (4fa401b33c1b50c816486f6951244a14) C:\WINDOWS\system32\DRIVERS\AVGIDSDriver.Sys
19:48:01.0000 2216 AVGIDSDriver - ok
19:48:01.0171 2216 AVGIDSEH (69578bc9d43d614c6b3455db4af19762) C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys
19:48:01.0296 2216 AVGIDSEH - ok
19:48:01.0468 2216 AVGIDSFilter (6df528406aa22201f392b9b19121cd6f) C:\WINDOWS\system32\DRIVERS\AVGIDSFilter.Sys
19:48:01.0593 2216 AVGIDSFilter - ok
19:48:01.0843 2216 AVGIDSShim (1e01c2166b5599802bcd61b9691f7476) C:\WINDOWS\system32\DRIVERS\AVGIDSShim.Sys
19:48:02.0015 2216 AVGIDSShim - ok
19:48:02.0187 2216 Avgldx86 (bf8118cd5e2255387b715b534d64acd1) C:\WINDOWS\system32\DRIVERS\avgldx86.sys
19:48:02.0375 2216 Avgldx86 - ok
19:48:02.0562 2216 Avgmfx86 (1c77ef67f196466adc9924cb288afe87) C:\WINDOWS\system32\DRIVERS\avgmfx86.sys
19:48:02.0765 2216 Avgmfx86 - ok
19:48:02.0828 2216 Avgrkx86 (f2038ed7284b79dcef581468121192a9) C:\WINDOWS\system32\DRIVERS\avgrkx86.sys
19:48:03.0000 2216 Avgrkx86 - ok
19:48:03.0140 2216 Avgtdix (a6d562b612216d8d02a35ebeb92366bd) C:\WINDOWS\system32\DRIVERS\avgtdix.sys
19:48:03.0296 2216 Avgtdix - ok
19:48:03.0437 2216 BCM43XX (38ca1443660d0f5f06887c6a2e692aeb) C:\WINDOWS\system32\DRIVERS\bcmwl5.sys
19:48:03.0593 2216 BCM43XX - ok
19:48:03.0687 2216 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
19:48:03.0843 2216 Beep - ok
19:48:04.0046 2216 BrScnUsb (92a964547b96d697e5e9ed43b4297f5a) C:\WINDOWS\system32\DRIVERS\BrScnUsb.sys
19:48:04.0187 2216 BrScnUsb - ok
19:48:04.0218 2216 cbidf (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\DRIVERS\cbidf2k.sys
19:48:04.0406 2216 cbidf - ok
19:48:04.0500 2216 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
19:48:04.0500 2216 cbidf2k - ok
19:48:04.0640 2216 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
19:48:04.0765 2216 CCDECODE - ok
19:48:04.0859 2216 cd20xrnt (f3ec03299634490e97bbce94cd2954c7) C:\WINDOWS\system32\DRIVERS\cd20xrnt.sys
19:48:04.0968 2216 cd20xrnt - ok
19:48:05.0000 2216 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
19:48:05.0171 2216 Cdaudio - ok
19:48:05.0281 2216 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
19:48:05.0500 2216 Cdfs - ok
19:48:05.0562 2216 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
19:48:05.0703 2216 Cdrom - ok
19:48:05.0921 2216 Changer - ok
19:48:06.0031 2216 CmBatt (0f6c187d38d98f8df904589a5f94d411) C:\WINDOWS\system32\DRIVERS\CmBatt.sys
19:48:06.0203 2216 CmBatt - ok
19:48:06.0296 2216 CmdIde (e5dcb56c533014ecbc556a8357c929d5) C:\WINDOWS\system32\DRIVERS\cmdide.sys
19:48:06.0437 2216 CmdIde - ok
19:48:06.0500 2216 Compbatt (6e4c9f21f0fae8940661144f41b13203) C:\WINDOWS\system32\DRIVERS\compbatt.sys
19:48:06.0671 2216 Compbatt - ok
19:48:06.0812 2216 Cpqarray (3ee529119eed34cd212a215e8c40d4b6) C:\WINDOWS\system32\DRIVERS\cpqarray.sys
19:48:07.0000 2216 Cpqarray - ok
19:48:07.0109 2216 dac2w2k (e550e7418984b65a78299d248f0a7f36) C:\WINDOWS\system32\DRIVERS\dac2w2k.sys
19:48:07.0281 2216 dac2w2k - ok
19:48:07.0375 2216 dac960nt (683789caa3864eb46125ae86ff677d34) C:\WINDOWS\system32\DRIVERS\dac960nt.sys
19:48:07.0500 2216 dac960nt - ok
19:48:07.0625 2216 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
19:48:07.0765 2216 Disk - ok
19:48:07.0875 2216 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys
19:48:08.0125 2216 dmboot - ok
19:48:08.0296 2216 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys
19:48:08.0468 2216 dmio - ok
19:48:08.0515 2216 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
19:48:08.0718 2216 dmload - ok
19:48:08.0890 2216 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
19:48:08.0937 2216 DMusic - ok
19:48:09.0078 2216 dpti2o (40f3b93b4e5b0126f2f5c0a7a5e22660) C:\WINDOWS\system32\DRIVERS\dpti2o.sys
19:48:09.0218 2216 dpti2o - ok
19:48:09.0296 2216 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
19:48:09.0328 2216 drmkaud - ok
19:48:09.0484 2216 EpmPsd (d68564fcfbdfc04280cdbbb37cf7ef7f) C:\WINDOWS\system32\drivers\epm-psd.sys
19:48:09.0656 2216 EpmPsd - ok
19:48:09.0875 2216 EpmShd (2d0c4a7077f6c68449479f5444c580a7) C:\WINDOWS\system32\drivers\epm-shd.sys
19:48:10.0015 2216 EpmShd - ok
19:48:10.0187 2216 ewusbnet (6295a7a4cb6a85a2d9cecb69c67511bb) C:\WINDOWS\system32\DRIVERS\ewusbnet.sys
19:48:10.0312 2216 ewusbnet - ok
19:48:10.0390 2216 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
19:48:10.0546 2216 Fastfat - ok
19:48:10.0656 2216 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\drivers\Fdc.sys
19:48:10.0765 2216 Fdc - ok
19:48:10.0859 2216 FETNDIS (e9648254056bce81a85380c0c3647dc4) C:\WINDOWS\system32\DRIVERS\fetnd5.sys
19:48:11.0000 2216 FETNDIS - ok
19:48:11.0078 2216 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys
19:48:11.0171 2216 Fips - ok
19:48:11.0312 2216 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\drivers\Flpydisk.sys
19:48:11.0484 2216 Flpydisk - ok
19:48:11.0609 2216 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
19:48:11.0875 2216 FltMgr - ok
19:48:12.0015 2216 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
19:48:12.0140 2216 Fs_Rec - ok
19:48:12.0250 2216 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
19:48:12.0421 2216 Ftdisk - ok
19:48:12.0578 2216 gagp30kx (3a74c423cf6bcca6982715878f450a3b) C:\WINDOWS\system32\DRIVERS\gagp30kx.sys
19:48:12.0750 2216 gagp30kx - ok
19:48:12.0953 2216 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
19:48:13.0062 2216 Gpc - ok
19:48:13.0171 2216 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
19:48:13.0281 2216 HidUsb - ok
19:48:13.0421 2216 Hotkey (8b566ea71d5b76157a9cdb78f25a5731) C:\WINDOWS\system32\drivers\Hotkey.sys
19:48:13.0625 2216 Hotkey - ok
19:48:13.0765 2216 hpn (b028377dea0546a5fcfba928a8aefae0) C:\WINDOWS\system32\DRIVERS\hpn.sys
19:48:13.0906 2216 hpn - ok
19:48:14.0062 2216 HSFHWICH (9e99aad9cfea338cef2eb6bcf2d9b524) C:\WINDOWS\system32\DRIVERS\HSFHWICH.sys
19:48:14.0218 2216 HSFHWICH - ok
19:48:14.0390 2216 HSF_DP (dfa8f86c0dbca7db948043aa3be6793b) C:\WINDOWS\system32\DRIVERS\HSF_DP.sys
19:48:14.0609 2216 HSF_DP - ok
19:48:14.0875 2216 HSF_DPV (5a5a7721d9c62d77fc0faba9b2cf5be9) C:\WINDOWS\system32\DRIVERS\HSF_DPV.sys
19:48:15.0062 2216 HSF_DPV - ok
19:48:15.0171 2216 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
19:48:15.0234 2216 HTTP - ok
19:48:15.0375 2216 hwdatacard (20330198554b7ddb44403af21d6ae179) C:\WINDOWS\system32\DRIVERS\ewusbmdm.sys
19:48:15.0562 2216 hwdatacard - ok
19:48:15.0718 2216 hwusbdev (922065957563d851b5a68b95aadac6ad) C:\WINDOWS\system32\DRIVERS\ewusbdev.sys
19:48:15.0859 2216 hwusbdev - ok
19:48:15.0984 2216 i2omgmt (9368670bd426ebea5e8b18a62416ec28) C:\WINDOWS\system32\drivers\i2omgmt.sys
19:48:16.0156 2216 i2omgmt - ok
19:48:16.0296 2216 i2omp (f10863bf1ccc290babd1a09188ae49e0) C:\WINDOWS\system32\DRIVERS\i2omp.sys
19:48:16.0453 2216 i2omp - ok
19:48:16.0546 2216 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
19:48:16.0734 2216 i8042prt - ok
19:48:16.0984 2216 ialm (afa7c99d211a2aff21a287bc4264cde6) C:\WINDOWS\system32\DRIVERS\ialmnt5.sys
19:48:17.0156 2216 ialm - ok
19:48:17.0218 2216 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
19:48:17.0312 2216 Imapi - ok
19:48:17.0421 2216 ini910u (4a40e045faee58631fd8d91afc620719) C:\WINDOWS\system32\DRIVERS\ini910u.sys
19:48:17.0593 2216 ini910u - ok
19:48:17.0625 2216 int15.sys - ok
19:48:17.0703 2216 IntelIde (b5466a9250342a7aa0cd1fba13420678) C:\WINDOWS\system32\DRIVERS\intelide.sys
19:48:17.0875 2216 IntelIde - ok
19:48:17.0968 2216 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys
19:48:18.0140 2216 intelppm - ok
19:48:18.0265 2216 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
19:48:18.0421 2216 Ip6Fw - ok
19:48:18.0484 2216 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
19:48:18.0671 2216 IpFilterDriver - ok
19:48:18.0859 2216 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
19:48:18.0984 2216 IpInIp - ok
19:48:19.0078 2216 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
19:48:19.0187 2216 IpNat - ok
19:48:19.0281 2216 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
19:48:19.0390 2216 IPSec - ok
19:48:19.0562 2216 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
19:48:19.0687 2216 IRENUM - ok
19:48:19.0828 2216 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys
19:48:20.0000 2216 isapnp - ok
19:48:20.0140 2216 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
19:48:20.0296 2216 Kbdclass - ok
19:48:20.0484 2216 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
19:48:20.0515 2216 kmixer - ok
19:48:20.0593 2216 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
19:48:20.0812 2216 KSecDD - ok
19:48:20.0984 2216 lbrtfdc - ok
19:48:21.0156 2216 mailKmd - ok
19:48:21.0312 2216 mcdbus - ok
19:48:21.0468 2216 mdmxsdk (e246a32c445056996074a397da56e815) C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys
19:48:21.0656 2216 mdmxsdk - ok
19:48:21.0765 2216 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
19:48:21.0890 2216 mnmdd - ok
19:48:22.0000 2216 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys
19:48:22.0125 2216 Modem - ok
19:48:22.0187 2216 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys
19:48:22.0296 2216 Mouclass - ok
19:48:22.0500 2216 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys
19:48:22.0625 2216 mouhid - ok
19:48:22.0718 2216 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
19:48:22.0875 2216 MountMgr - ok
19:48:22.0937 2216 MPE (c0f8e0c2c3c0437cf37c6781896dc3ec) C:\WINDOWS\system32\DRIVERS\MPE.sys
19:48:23.0062 2216 MPE - ok
19:48:23.0187 2216 mraid35x (3f4bb95e5a44f3be34824e8e7caf0737) C:\WINDOWS\system32\DRIVERS\mraid35x.sys
19:48:23.0328 2216 mraid35x - ok
19:48:23.0484 2216 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
19:48:23.0531 2216 MRxDAV - ok
19:48:23.0625 2216 MRxSmb (7d304a5eb4344ebeeab53a2fe3ffb9f0) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
19:48:23.0781 2216 MRxSmb - ok
19:48:23.0890 2216 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
19:48:24.0078 2216 Msfs - ok
19:48:24.0203 2216 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
19:48:24.0328 2216 MSKSSRV - ok
19:48:24.0421 2216 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
19:48:24.0515 2216 MSPCLOCK - ok
19:48:24.0703 2216 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
19:48:24.0828 2216 MSPQM - ok
19:48:25.0000 2216 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
19:48:25.0187 2216 mssmbios - ok
19:48:25.0265 2216 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys
19:48:25.0390 2216 MSTEE - ok
19:48:25.0578 2216 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys
19:48:25.0718 2216 Mup - ok
19:48:25.0781 2216 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
19:48:25.0968 2216 NABTSFEC - ok
19:48:26.0093 2216 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
19:48:26.0250 2216 NDIS - ok
19:48:26.0375 2216 NdisFilt (1f76996253071cbae0a5ab5d8551ef88) C:\WINDOWS\system32\Drivers\NdisFilt.sys
19:48:26.0531 2216 NdisFilt - ok
19:48:26.0687 2216 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys
19:48:26.0843 2216 NdisIP - ok
19:48:27.0078 2216 NdisTapi (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
19:48:27.0265 2216 NdisTapi - ok
19:48:27.0328 2216 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
19:48:27.0343 2216 Ndisuio - ok
19:48:27.0359 2216 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
19:48:27.0468 2216 NdisWan - ok
19:48:27.0531 2216 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
19:48:27.0640 2216 NDProxy - ok
19:48:27.0765 2216 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
19:48:27.0875 2216 NetBIOS - ok
19:48:27.0953 2216 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
19:48:28.0078 2216 NetBT - ok
19:48:28.0250 2216 NETMNT (6a25f27202f3122a44a6b74ee46e7a76) C:\WINDOWS\system32\DRIVERS\NETMNT.sys
19:48:28.0406 2216 NETMNT - ok
19:48:28.0531 2216 NIC1394 (e9e47cfb2d461fa0fc75b7a74c6383ea) C:\WINDOWS\system32\DRIVERS\nic1394.sys
19:48:28.0656 2216 NIC1394 - ok
19:48:28.0812 2216 NPF (d21fee8db254ba762656878168ac1db6) C:\WINDOWS\system32\drivers\npf.sys
19:48:28.0906 2216 NPF - ok
19:48:29.0046 2216 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
19:48:29.0125 2216 Npfs - ok
19:48:29.0265 2216 NSCIRDA (2adc0ca9945c65284b3d19bc18765974) C:\WINDOWS\system32\DRIVERS\nscirda.sys
19:48:29.0390 2216 NSCIRDA - ok
19:48:29.0500 2216 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
19:48:29.0656 2216 Ntfs - ok
19:48:29.0796 2216 NTIDrvr (7f1c1f78d709c4a54cbb46ede7e0b48d) C:\WINDOWS\system32\DRIVERS\NTIDrvr.sys
19:48:29.0937 2216 NTIDrvr - ok
19:48:30.0031 2216 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
19:48:30.0156 2216 Null - ok
19:48:30.0218 2216 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
19:48:30.0375 2216 NwlnkFlt - ok
19:48:30.0421 2216 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
19:48:30.0515 2216 NwlnkFwd - ok
19:48:30.0640 2216 ohci1394 (ca33832df41afb202ee7aeb05145922f) C:\WINDOWS\system32\DRIVERS\ohci1394.sys
19:48:30.0750 2216 ohci1394 - ok
19:48:30.0890 2216 OsaFsLoc (26c4a4b64d1dd8e6fdfb2f4897be029c) C:\WINDOWS\system32\drivers\OsaFsLoc.sys
19:48:30.0953 2216 OsaFsLoc - ok
19:48:31.0125 2216 osaio (9d1177c2a8de936b33d85ff75e8cbf1a) C:\WINDOWS\system32\drivers\osaio.sys
19:48:31.0281 2216 osaio - ok
19:48:31.0453 2216 osanbm (3245bee5176697faf0744a2e1288dc77) C:\WINDOWS\system32\drivers\osanbm.sys
19:48:31.0546 2216 osanbm - ok
19:48:31.0609 2216 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\DRIVERS\parport.sys
19:48:31.0734 2216 Parport - ok
19:48:31.0875 2216 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
19:48:32.0046 2216 PartMgr - ok
19:48:32.0140 2216 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys
19:48:32.0140 2216 ParVdm - ok
19:48:32.0250 2216 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys
19:48:32.0375 2216 PCI - ok
19:48:32.0546 2216 PCIDump - ok
19:48:32.0687 2216 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys
19:48:32.0843 2216 PCIIde - ok
19:48:33.0046 2216 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\DRIVERS\pcmcia.sys
19:48:33.0187 2216 Pcmcia - ok
19:48:33.0265 2216 pcouffin (5b6c11de7e839c05248ced8825470fef) C:\WINDOWS\system32\Drivers\pcouffin.sys
19:48:33.0375 2216 pcouffin - ok
19:48:33.0546 2216 PDCOMP - ok
19:48:33.0718 2216 PDFRAME - ok
19:48:33.0890 2216 PDRELI - ok
19:48:34.0062 2216 PDRFRAME - ok
19:48:34.0156 2216 perc2 (6c14b9c19ba84f73d3a86dba11133101) C:\WINDOWS\system32\DRIVERS\perc2.sys
19:48:34.0250 2216 perc2 - ok
19:48:34.0375 2216 perc2hib (f50f7c27f131afe7beba13e14a3b9416) C:\WINDOWS\system32\DRIVERS\perc2hib.sys
19:48:34.0484 2216 perc2hib - ok
19:48:34.0625 2216 pfc (444f122e68db44c0589227781f3c8b3f) C:\WINDOWS\system32\drivers\pfc.sys
19:48:34.0750 2216 pfc - ok
19:48:34.0906 2216 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
19:48:35.0046 2216 PptpMiniport - ok
19:48:35.0156 2216 Processor (a32bebaf723557681bfc6bd93e98bd26) C:\WINDOWS\system32\DRIVERS\processr.sys
19:48:35.0234 2216 Processor - ok
19:48:35.0296 2216 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
19:48:35.0375 2216 PSched - ok
19:48:35.0421 2216 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
19:48:35.0546 2216 Ptilink - ok
19:48:35.0656 2216 ql1080 (0a63fb54039eb5662433caba3b26dba7) C:\WINDOWS\system32\DRIVERS\ql1080.sys
19:48:35.0781 2216 ql1080 - ok
19:48:35.0937 2216 Ql10wnt (6503449e1d43a0ff0201ad5cb1b8c706) C:\WINDOWS\system32\DRIVERS\ql10wnt.sys
19:48:36.0125 2216 Ql10wnt - ok
19:48:36.0218 2216 ql12160 (156ed0ef20c15114ca097a34a30d8a01) C:\WINDOWS\system32\DRIVERS\ql12160.sys
19:48:36.0359 2216 ql12160 - ok
19:48:36.0468 2216 ql1240 (70f016bebde6d29e864c1230a07cc5e6) C:\WINDOWS\system32\DRIVERS\ql1240.sys
19:48:36.0562 2216 ql1240 - ok
19:48:36.0703 2216 ql1280 (907f0aeea6bc451011611e732bd31fcf) C:\WINDOWS\system32\DRIVERS\ql1280.sys
19:48:36.0781 2216 ql1280 - ok
19:48:36.0812 2216 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
19:48:36.0953 2216 RasAcd - ok
19:48:37.0062 2216 Rasirda (0207d26ddf796a193ccd9f83047bb5fc) C:\WINDOWS\system32\DRIVERS\rasirda.sys
19:48:37.0187 2216 Rasirda - ok
19:48:37.0312 2216 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
19:48:37.0406 2216 Rasl2tp - ok
19:48:37.0484 2216 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
19:48:37.0640 2216 RasPppoe - ok
19:48:37.0687 2216 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
19:48:37.0781 2216 Raspti - ok
19:48:37.0968 2216 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
19:48:38.0093 2216 Rdbss - ok
19:48:38.0125 2216 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
19:48:38.0234 2216 RDPCDD - ok
19:48:38.0390 2216 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
19:48:38.0515 2216 rdpdr - ok
19:48:38.0734 2216 RDPWD (fc105dd312ed64eb66bff111e8ec6eac) C:\WINDOWS\system32\drivers\RDPWD.sys
19:48:38.0796 2216 RDPWD - ok
19:48:38.0906 2216 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys
19:48:39.0062 2216 redbook - ok
19:48:39.0125 2216 Revoflt (8b5b8a11306190c6963d3473f052d3c8) C:\WINDOWS\system32\DRIVERS\revoflt.sys
19:48:39.0281 2216 Revoflt - ok
19:48:39.0296 2216 rpcapd - ok
19:48:39.0468 2216 RTL8023xp (4a0ae7891fcf74acc848b109294cb80f) C:\WINDOWS\system32\DRIVERS\Rtlnicxp.sys
19:48:39.0578 2216 RTL8023xp - ok
19:48:39.0750 2216 RTL8192su (5fcca99c136fddf8ce819d75e940d64b) C:\WINDOWS\system32\DRIVERS\RTL8192su.sys
19:48:39.0890 2216 RTL8192su - ok
19:48:40.0031 2216 s24trans (1cc074e0d48383d4e9bffc6a26c2a58a) C:\WINDOWS\system32\DRIVERS\s24trans.sys
19:48:40.0171 2216 s24trans - ok
19:48:40.0312 2216 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
19:48:40.0312 2216 Secdrv - ok
19:48:40.0484 2216 Sentinel (412a3a8a9043616b9246bfefc376e933) C:\WINDOWS\System32\Drivers\SENTINEL.SYS
19:48:40.0656 2216 Sentinel - ok
19:48:40.0734 2216 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\drivers\Serial.sys
19:48:40.0828 2216 Serial - ok
19:48:40.0968 2216 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\DRIVERS\sfloppy.sys
19:48:41.0109 2216 Sfloppy - ok
19:48:41.0328 2216 Simbad - ok
19:48:41.0500 2216 sisagp (6b33d0ebd30db32e27d1d78fe946a754) C:\WINDOWS\system32\DRIVERS\sisagp.sys
19:48:41.0593 2216 sisagp - ok
19:48:41.0656 2216 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys
19:48:41.0781 2216 SLIP - ok
19:48:42.0406 2216 SNP2STD (e7e68ecb968c9812d9faf68517426673) C:\WINDOWS\system32\DRIVERS\snp2sxp.sys
19:48:43.0046 2216 SNP2STD - ok
19:48:43.0218 2216 SNTNLUSB (054c6d41933b3bdb09dca17de08a97b2) C:\WINDOWS\system32\DRIVERS\SNTNLUSB.SYS
19:48:43.0359 2216 SNTNLUSB - ok
19:48:43.0468 2216 Sparrow (83c0f71f86d3bdaf915685f3d568b20e) C:\WINDOWS\system32\DRIVERS\sparrow.sys
19:48:43.0546 2216 Sparrow - ok
19:48:43.0656 2216 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
19:48:43.0656 2216 splitter - ok
19:48:43.0796 2216 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys
19:48:44.0328 2216 sr - ok
19:48:44.0468 2216 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys
19:48:44.0640 2216 Srv - ok
19:48:44.0796 2216 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys
19:48:44.0937 2216 streamip - ok
19:48:45.0062 2216 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
19:48:45.0171 2216 swenum - ok
19:48:45.0343 2216 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
19:48:45.0359 2216 swmidi - ok
19:48:45.0468 2216 swmsflt (e6c797b33a454840245c0c96e7f08b0a) C:\WINDOWS\System32\drivers\swmsflt.sys
19:48:45.0593 2216 swmsflt - ok
19:48:45.0828 2216 SWMX00 - ok
19:48:45.0984 2216 SWNC5E00 - ok
19:48:46.0156 2216 SWUMX20 - ok
19:48:46.0312 2216 symc810 (1ff3217614018630d0a6758630fc698c) C:\WINDOWS\system32\DRIVERS\symc810.sys
19:48:46.0390 2216 symc810 - ok
19:48:46.0500 2216 symc8xx (070e001d95cf725186ef8b20335f933c) C:\WINDOWS\system32\DRIVERS\symc8xx.sys
19:48:46.0609 2216 symc8xx - ok
19:48:46.0718 2216 sym_hi (80ac1c4abbe2df3b738bf15517a51f2c) C:\WINDOWS\system32\DRIVERS\sym_hi.sys
19:48:46.0890 2216 sym_hi - ok
19:48:46.0984 2216 sym_u3 (bf4fab949a382a8e105f46ebb4937058) C:\WINDOWS\system32\DRIVERS\sym_u3.sys
19:48:47.0093 2216 sym_u3 - ok
19:48:47.0250 2216 SynTP (062e75f20d9bdca40344d85262f74748) C:\WINDOWS\system32\DRIVERS\SynTP.sys
19:48:47.0375 2216 SynTP - ok
19:48:47.0515 2216 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
19:48:47.0531 2216 sysaudio - ok
19:48:47.0625 2216 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
19:48:47.0750 2216 Tcpip - ok
19:48:47.0890 2216 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
19:48:48.0062 2216 TDPIPE - ok
19:48:48.0203 2216 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
19:48:48.0312 2216 TDTCP - ok
19:48:48.0421 2216 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
19:48:48.0625 2216 TermDD - ok
19:48:48.0734 2216 TosIde (f2790f6af01321b172aa62f8e1e187d9) C:\WINDOWS\system32\DRIVERS\toside.sys
19:48:48.0859 2216 TosIde - ok
19:48:49.0062 2216 UBHelper (e0c67be430c6de490d6ccaecfa071f9e) C:\WINDOWS\system32\drivers\UBHelper.sys
19:48:49.0203 2216 UBHelper - ok
19:48:49.0312 2216 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
19:48:49.0390 2216 Udfs - ok
19:48:49.0500 2216 ultra (1b698a51cd528d8da4ffaed66dfc51b9) C:\WINDOWS\system32\DRIVERS\ultra.sys
19:48:49.0640 2216 ultra - ok
19:48:49.0875 2216 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
19:48:50.0031 2216 Update - ok
19:48:50.0203 2216 USB28xxBGA (0e84c25604249a02457579cfe9373a44) C:\WINDOWS\system32\DRIVERS\emBDA.sys
19:48:50.0328 2216 USB28xxBGA - ok
19:48:50.0484 2216 USB28xxOEM (b383551fbb1c2bf62be93064cf1f4270) C:\WINDOWS\system32\DRIVERS\emOEM.sys
19:48:50.0656 2216 USB28xxOEM - ok
19:48:50.0718 2216 usbaudio (e919708db44ed8543a7c017953148330) C:\WINDOWS\system32\drivers\usbaudio.sys
19:48:50.0843 2216 usbaudio - ok
19:48:50.0968 2216 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
19:48:51.0093 2216 usbccgp - ok
19:48:51.0625 2216 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
19:48:51.0828 2216 usbehci - ok
19:48:51.0984 2216 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
19:48:52.0171 2216 usbhub - ok
19:48:52.0328 2216 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys
19:48:52.0609 2216 usbprint - ok
19:48:52.0734 2216 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
19:48:52.0859 2216 usbscan - ok
19:48:53.0000 2216 usbstor (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
19:48:53.0140 2216 usbstor - ok
19:48:53.0218 2216 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
19:48:53.0343 2216 usbuhci - ok
19:48:53.0531 2216 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
19:48:53.0640 2216 VgaSave - ok
19:48:53.0812 2216 viaagp (754292ce5848b3738281b4f3607eaef4) C:\WINDOWS\system32\DRIVERS\viaagp.sys
19:48:53.0890 2216 viaagp - ok
19:48:53.0968 2216 ViaIde (3b3efcda263b8ac14fdf9cbdd0791b2e) C:\WINDOWS\system32\DRIVERS\viaide.sys
19:48:54.0093 2216 ViaIde - ok
19:48:54.0203 2216 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys
19:48:54.0343 2216 VolSnap - ok
19:48:54.0687 2216 w29n51 (9ee38ffcb4cbe5bee6c305700ddc4725) C:\WINDOWS\system32\DRIVERS\w29n51.sys
19:48:54.0828 2216 w29n51 - ok
19:48:55.0031 2216 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
19:48:55.0156 2216 Wanarp - ok
19:48:55.0328 2216 Wbutton - ok
19:48:55.0500 2216 WDICA - ok
19:48:55.0625 2216 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
19:48:55.0656 2216 wdmaud - ok
19:48:55.0828 2216 winachsf (e0a00b06ea067c84e124b407dffa1af1) C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys
19:48:56.0000 2216 winachsf - ok
19:48:56.0250 2216 WmiAcpi (c42584fd66ce9e17403aebca199f7bdb) C:\WINDOWS\system32\DRIVERS\wmiacpi.sys
19:48:56.0375 2216 WmiAcpi - ok
19:48:56.0468 2216 WpdUsb (cf4def1bf66f06964dc0d91844239104) C:\WINDOWS\system32\DRIVERS\wpdusb.sys
19:48:56.0625 2216 WpdUsb - ok
19:48:56.0718 2216 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
19:48:56.0812 2216 WSTCODEC - ok
19:48:57.0015 2216 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
19:48:57.0140 2216 WudfPf - ok
19:48:57.0281 2216 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
19:48:57.0375 2216 WudfRd - ok
19:48:57.0453 2216 MBR (0x1B8) (99852d5c3a78447c3d6d82b6155fe848) \Device\Harddisk0\DR0
19:48:58.0453 2216 \Device\Harddisk0\DR0 - ok
19:48:58.0453 2216 Boot (0x1200) (d4948ae690d09add0c4fb599cd0fd1ea) \Device\Harddisk0\DR0\Partition0
19:48:58.0453 2216 \Device\Harddisk0\DR0\Partition0 - ok
19:48:58.0500 2216 Boot (0x1200) (a5f8381eea9d1cab7f8b240fe41763be) \Device\Harddisk0\DR0\Partition1
19:48:58.0500 2216 \Device\Harddisk0\DR0\Partition1 - ok
19:48:58.0500 2216 ============================================================
19:48:58.0500 2216 Scan finished
19:48:58.0500 2216 ============================================================
19:48:58.0515 3144 Detected object count: 0
19:48:58.0515 3144 Actual detected object count: 0
19:49:09.0843 3232 Deinitialize success




ComboFix log



ComboFix 11-12-04.04 - Real 12/04/2011 20:07:47.1.1 - FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.502.262 [GMT -8:00]
Running from: d:\combofix\ComboFix.exe
AV: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\TEMP
c:\documents and settings\All Users\Application Data\TEMP\0888F409.TMP
c:\documents and settings\All Users\Application Data\TEMP\5C321E34.TMP
c:\documents and settings\All Users\Application Data\TEMP\66633281.TMP
c:\documents and settings\Real\Application Data\AdwareAlert
c:\documents and settings\Real\Application Data\AdwareAlert\Log\2007 Dec 27 - 10_13_57 AM_578.log
c:\documents and settings\Real\Application Data\AdwareAlert\Log\2007 Dec 27 - 10_16_12 AM_484.log
c:\documents and settings\Real\Application Data\AdwareAlert\Log\2007 Dec 27 - 12_24_42 PM_093.log
c:\documents and settings\Real\Application Data\AdwareAlert\rs.dat
c:\documents and settings\Real\Application Data\inst.exe
c:\documents and settings\Real\Application Data\vso_ts_preview.xml
c:\documents and settings\Real\ResErrors.log
c:\documents and settings\Real\WINDOWS
c:\program files\ComPlus Applications\wuoryro.html
c:\program files\WinPCap
c:\program files\WinPCap\daemon_mgm.exe
c:\program files\WinPCap\npf_mgm.exe
c:\program files\WinPCap\rpcapd.exe
c:\temp\1cb
c:\temp\1cb\syscheck.log
c:\temp\bkR11
c:\temp\bkR11\ftCa.log
c:\windows\iun6002.exe
c:\windows\system32\Cache
c:\windows\system32\Cache\272512937d9e61a4.fb
c:\windows\system32\Cache\287204568329e189.fb
c:\windows\system32\Cache\28bc8f716fd76a47.fb
c:\windows\system32\Cache\2c53092c95605355.fb
c:\windows\system32\Cache\3917078cb68ec657.fb
c:\windows\system32\Cache\590ba23ce359fd0c.fb
c:\windows\system32\Cache\610289e025a3ee9a.fb
c:\windows\system32\Cache\651c5d3cdbfb8bd1.fb
c:\windows\system32\Cache\6c59ac5e7e7a3ad0.fb
c:\windows\system32\Cache\ad10a52aff5e038d.fb
c:\windows\system32\Cache\c4d28dca2e7648be.fb
c:\windows\system32\Cache\d1d5fb616f03ae83.fb
c:\windows\system32\Cache\d201ef9910cd39de.fb
c:\windows\system32\Cache\d2e94710a5708128.fb
c:\windows\system32\Cache\d79b9dfe81484ec4.fb
c:\windows\system32\Cache\e0de16f883bea794.fb
c:\windows\system32\drivers\npf.sys
c:\windows\system32\jmllm.ini
c:\windows\system32\jmllm.ini2
c:\windows\system32\pac.txt
c:\windows\system32\Packet.dll
c:\windows\system32\pthreadVC.dll
c:\windows\system32\ssembl~1
c:\windows\system32\WanPacket.dll
c:\windows\system32\wpcap.dll
c:\windows\WindowsXP-KB822603-x86.exe
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
——-\Legacy_DHLP
——-\Service_NPF
.
.
((((((((((((((((((((((((( Files Created from 2011-11-05 to 2011-12-05 )))))))))))))))))))))))))))))))
.
.
2011-11-30 19:03 . 2011-11-30 19:03 ——– d—–w- c:\documents and settings\Real\Application Data\AVG Secure Search
2011-11-30 18:50 . 2011-11-30 18:50 ——– d—–w- c:\documents and settings\All Users\Application Data\AVG Secure Search
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-16 06:17 . 2011-05-20 03:28 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-10-10 14:22 . 2004-08-04 13:00 692736 —-a-w- c:\windows\system32\inetcomm.dll
2011-10-07 14:23 . 2010-09-07 11:48 230608 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2011-10-04 14:21 . 2010-08-20 05:42 16720 —-a-w- c:\windows\system32\drivers\AVGIDSShim.sys
2011-09-28 07:06 . 2004-08-04 13:00 599040 —-a-w- c:\windows\system32\crypt32.dll
2011-09-26 19:41 . 2011-09-26 19:41 611328 ——w- c:\windows\system32\uiautomationcore.dll
2011-09-26 19:41 . 2004-08-04 13:00 220160 —-a-w- c:\windows\system32\oleacc.dll
2011-09-26 19:41 . 2004-08-04 13:00 20480 —-a-w- c:\windows\system32\oleaccrc.dll
2011-09-13 14:30 . 2010-09-07 11:48 32592 —-a-w- c:\windows\system32\drivers\avgrkx86.sys
2011-09-06 14:20 . 2004-08-04 13:00 1858944 —-a-w- c:\windows\system32\win32k.sys
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}]
2011-11-30 18:49 1547104 —-a-w- c:\program files\AVG Secure Search\9.0.0.18\AVG Secure Search_toolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{95B7759C-8C7F-4BF1-B163-73684A933233}"= "c:\program files\AVG Secure Search\9.0.0.18\AVG Secure Search_toolbar.dll" [2011-11-30 1547104]
.
[HKEY_CLASSES_ROOT\clsid\{95b7759c-8c7f-4bf1-b163-73684a933233}]
[HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj.1]
[HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="d:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 2097488]
"WeatherEye"="d:\documents and settings\Real\Local Settings\Application Data\TheWeatherNetwork\WeatherEye\WeatherEye.exe" [2010-09-22 309104]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"preload"="c:\windows\RUNXMLPL.exe" [2005-05-20 32768]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-04 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-08-24 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-08-24 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-08-24 114688]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-02-04 708698]
"SoundMan"="SOUNDMAN.EXE" [2005-04-15 77824]
"LaunchAp"="c:\program files\Launch Manager\LaunchAp.exe" [2005-07-25 32768]
"LManager"="c:\program files\Launch Manager\HotkeyApp.exe" [2006-04-20 69632]
"CtrlVol"="c:\program files\Launch Manager\CtrlVol.exe" [2003-09-16 20480]
"LMgrOSD"="c:\program files\Launch Manager\OSDCtrl.exe" [2005-07-25 241664]
"Wbutton"="c:\program files\Launch Manager\Wbutton.exe" [2006-04-20 86016]
"EPM-DM"="c:\acer\Empowering Technology\ePower\epm-dm.exe" [2005-11-11 212992]
"Acer ePower Management"="c:\acer\Empowering Technology\ePower\Acer ePower Management.exe" [2005-11-09 3084288]
"eRecoveryService"="c:\acer\Empowering Technology\eRecovery\Monitor.exe" [2006-01-25 397312]
"ADMTray.exe"="c:\acer\Empowering Technology\admtray.exe" [2005-10-25 2462208]
"eDataSecurity Loader"="c:\acer\Empowering Technology\eDataSecurity\eDSloader.exe" [2005-12-27 69632]
"tsnp2std"="c:\windows\tsnp2std.exe" [2005-11-15 110592]
"snp2std"="c:\windows\vsnp2std.exe" [2005-11-17 344064]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"CMCService"="c:\program files\ATI\Catalyst Media Center\CMCService.exe" [2008-06-06 172032]
"Media Codec Update Service"="d:\program files\Essentials Codec Pack\update.exe" [2007-04-08 303104]
"BrStsWnd"="c:\program files\Brownie\BrstsWnd.exe" [2009-06-11 3618104]
"AVG_TRAY"="c:\program files\AVG\AVG2012\avgtray.exe" [2011-10-25 2415456]
"vProt"="c:\program files\AVG Secure Search\vprot.exe" [2011-11-30 827232]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
BDARemote.lnk - c:\program files\USB TV\EM28XX\BDARemote.exe [2008-12-7 81997]
REALTEK 11n USB Wireless LAN Utility.lnk - c:\program files\REALTEK\11n USB Wireless LAN Utility\RtWLan.exe [2010-4-26 897024]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~1\AVG\AVG2012\avgrsx.exe /sync /restart
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\WINDOWS\\System32\\fxsclnt.exe"=
"d:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Common Files\\SafeNet Sentinel\\Sentinel Protection Server\\WinNT\\spnsrvnt.exe"=
"c:\\Program Files\\REALTEK\\11n USB Wireless LAN Utility\\RtWLan.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgmfapx.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgnsx.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgdiagex.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgemcx.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1542:TCP"= 1542:TCP:Realtek WPS TCP Prot
"1542:UDP"= 1542:UDP:Realtek WPS UDP Prot
"53:UDP"= 53:UDP:Realtek AP UDP Prot
.
R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [9/13/2010 4:27 PM 23120]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [9/7/2010 3:48 AM 32592]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [9/7/2010 3:48 AM 230608]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [9/7/2010 3:49 AM 295248]
R2 avgwd;AVG WatchDog;c:\program files\AVG\AVG2012\avgwdsvc.exe [8/2/2011 5:09 AM 192776]
R2 vToolbarUpdater;vToolbarUpdater;c:\program files\Common Files\AVG Secure Search\vToolbarUpdater\9.0.1\ToolbarUpdater.exe [11/30/2011 10:50 AM 855904]
S1 mailKmd;mailKmd; [x]
S3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files\AVG\AVG10\Toolbar\ToolbarBroker.exe [4/14/2011 4:20 PM 1025352]
S3 AVGIDSAgent;AVGIDSAgent;c:\program files\AVG\AVG2012\AVGIDSAgent.exe [10/12/2011 6:25 AM 4433248]
S3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [8/19/2010 9:42 PM 134608]
S3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [8/19/2010 9:42 PM 24272]
S3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [8/19/2010 9:42 PM 16720]
S3 ewusbnet;HUAWEI USB-NDIS miniport;c:\windows\system32\drivers\ewusbnet.sys [2/10/2010 12:31 PM 113280]
S3 hwusbdev;Huawei DataCard USB PNP Device;c:\windows\system32\drivers\ewusbdev.sys [2/10/2010 12:31 PM 100736]
S3 pcouffin;VSO Software pcouffin;c:\windows\system32\drivers\pcouffin.sys [12/21/2008 12:51 PM 47360]
S3 Revoflt;Revoflt;c:\windows\system32\drivers\revoflt.sys [10/15/2011 12:11 PM 27064]
S3 RTL8192su;Realtek RTL8192SU Wireless LAN 802.11n USB 2.0 Network Adapter;c:\windows\system32\drivers\rtl8192su.sys [4/26/2010 12:06 AM 563840]
.
.
——- Supplementary Scan ——-
.
uStart Page = about:blank
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: DhcpNameServer = [removed] [removed] [removed]
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files\Common Files\AVG Secure Search\ViProtocolInstaller\9.0.1\ViProtocol.dll
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
.
.
——- File Associations ——-
.
.
- - - - ORPHANS REMOVED - - - -
.
URLSearchHooks-{A3BC75A2-1F87-4686-AA43-5347D756017C} - (no file)
BHO-{025C9902-B55C-4739-BD41-808BFBD23FF7} - (no file)
BHO-{A3A9F3A6-E5B7-4666-A0B9-7901988AF11F} - (no file)
BHO-{AFEB5E5A-1C21-40BD-BCBC-E50860DC4000} - (no file)
BHO-{FF64059D-4D2A-4D6B-AA0F-2EE4A2FE3856} - (no file)
Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - (no file)
Notify-byxxyyv - byxxyyv.dll
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-12-04 20:19
Windows 5.1.2600 Service Pack 3 FAT NTAPI
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-2287598070-2175021220-185858733-1005\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'explorer.exe'(3948)
c:\windows\system32\WININET.dll
c:\windows\system32\MSNChatHook.dll
c:\windows\system32\sysenv.dll
c:\windows\system32\MSVCR71.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\IEFRAME.dll
c:\progra~1\COMMON~1\MICROS~1\WEBCOM~1\10\OWC10.DLL
c:\progra~1\COMMON~1\MICROS~1\WEBCOM~1\11\OWC11.DLL
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\windows\IME\SPGRMR.DLL
c:\program files\Common Files\Microsoft Shared\INK\SKCHUI.DLL
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\AVG\AVG2012\AVGRSX.EXE
c:\program files\AVG\AVG2012\avgcsrvx.exe
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\windows\SOUNDMAN.EXE
c:\acer\Empowering Technology\admServ.exe
c:\program files\ATI\Catalyst Media Center\Kernel\TV\CLCapSvc.exe
c:\program files\ATI\Catalyst Media Center\Kernel\CLML_NTService\CLMLServer.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\AVG\AVG2012\avgnsx.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\program files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2011-12-04 20:21:35 - machine was rebooted
ComboFix-quarantined-files.txt 2011-12-05 04:21
.
Pre-Run: 6,396,248,064 bytes free
Post-Run: 6,822,936,576 bytes free
.
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect
.
- - End Of File - - 3AEA82D97B80224741CF1522EC2BC69B
Hi,

Please do the following:

Please download Malwarebytes' Anti-Malware
  • Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT


Go here to run an online scanner from ESET.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activeX control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • When the scan completes, press the LIST OF THREATS FOUND button
  • Press EXPORT TO TEXT FILE , name the file ESETSCAN and save it to your desktop
  • Include the contents of this report in your next reply.
  • Press the BACK button.
  • Press Finish
Hi again, Saw that mbam removed two viruses and that eset has found some threats. Wepviewer is a program I purposely installed to find a wepkey I had forgotten on my computer a long time ago. Not sure why that is flagged as a threat. Here are the logs. MBAM Malwarebytes' Anti-Malware 1.51.2.1300 www.malwarebytes.org Database version: 8323 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 12/6/2011 12:06:25 PM mbam-log-2011-12-06 (12-06-25).txt Scan type: Quick scan Objects scanned: 158163 Time elapsed: 3 minute(s), 18 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 2 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{FF64059D-4D2A-4D6B-AA0F-2EE4A2FE3856} (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FF64059D-4D2A-4D6B-AA0F-2EE4A2FE3856} (Trojan.Vundo) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) ESETSCAN C:\System Volume Information\_restore{64C55BAE-0167-4E29-A424-980E0BCA06F2}\RP978\A0147112.ini Win32/Adware.Virtumonde.NEO application C:\Qoobox\Quarantine\C\WINDOWS\system32\jmllm.ini.vir Win32/Adware.Virtumonde.NEO application C:\Qoobox\Quarantine\C\WINDOWS\system32\jmllm.ini2.vir Win32/Adware.Virtumonde.NEO application C:\Qoobox\Quarantine\C\WINDOWS\system32\pac.txt.vir probably a variant of Win32/TrojanDownloader.Agent.JXCMRQU trojan D:\wepviewer\wirelesskeyview.zip Win32/WirelessKeyView.A application D:\wepviewer\wirelesskeyview\WirelessKeyView.exe Win32/WirelessKeyView.A application
Hi,

ESET is just alerting on the type of program that it is, it's not a threat. The other items are in quarantine or old restore points which we will clean up shortly.

Please do the following:

Visit ADOBE and download the latest version of Acrobat Reader (version X)
Having the latest updates ensures there are no security vulnerabilities in your system.

NEXT

[external image: Posted Image] Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.
  • Download the latest version of Java Runtime Environment (JRE) 6 and Save it to your Desktop.
  • Scroll down to where it says Java SE 6 Update 29
  • Click the Download button under JRE to the right.
  • Read the License Agreement then select Accept License Agreement
  • Click on the link to download Windows x86 Offline and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel, double-click on Add or Remove Programs and remove all older versions of Java.
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE or Java™ 6) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u29-windows-i586.exe to install the newest version.
  • After the install is complete, go into the Control Panel (using Classic View) and double-click the Java Icon. (looks like a coffee cup)
    • On the General tab, under Temporary Internet Files, click the Settings button.
    • Next, click on the Delete Files button
    • There are two options in the window to clear the cache - Leave BOTH CheckedApplications and Applets
      Trace and Log Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Window
  • Click OK to leave the Java Control Panel.


NEXT


Please post a fresh DDS Log and advise how the computer is running now and if there are any outstanding issues.
Hello The avg message box blocking access to the k8l.info website hasn't appeared in four days or so, but the frequency of it's appearance was more sporadic since the first day I posted here, so I can't say with certainty yet that it has been undone. I'm not keen that AVG thinks my browser should go to it's search page when I open a new tab in my internet explorer, which started five or six days ago, they should have asked me first. However, I can live with that. The computer seems to be booting up a little quicker, and running smoothly. It was fun and interesting to read your replies and go thru your directions. Had some unforseen obstacles to fight thru. For example, I had to remove the old ADOBE reader program, before I could install the new one. Even after a fresh bootup, the installation program would tell me that a file from the old reader probram was running and therefore, it couldn't install the new one. Helps keep the mind sharp. Almost wish I had a new issue just to keep playing with this stuff. Always found it interesting. Thanks for your time and have a coffee on me. Here are the new DDS and Attach files. . DDS (Ver_2011-08-26.01) - FAT32x86 Internet Explorer: 8.0.6001.18702 Run by [removed] at 0:34:34 on 2011-12-09 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.502.214 [GMT -8:00] . AV: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF} . ============== Running Processes =============== . C:\Program Files\AVG\AVG2012\AVGRSX.EXE C:\Program Files\AVG\AVG2012\avgcsrvx.exe C:\WINDOWS\system32\svchost.exe -k DcomLaunch SVCHOST.EXE C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup C:\Program Files\Intel\Wireless\Bin\EvtEng.exe C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe SVCHOST.EXE SVCHOST.EXE C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe SVCHOST.EXE C:\Program Files\AVG\AVG2012\avgwdsvc.exe C:\Acer\Empowering Technology\admServ.exe C:\Program Files\ATI\Catalyst Media Center\Kernel\TV\CLCapSvc.exe C:\Program Files\AVG\AVG2012\avgnsx.exe C:\Program Files\ATI\Catalyst Media Center\Kernel\CLML_NTService\CLMLServer.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\9.0.1\ToolbarUpdater.exe C:\Program Files\ATI\Catalyst Media Center\Kernel\TV\CLSched.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\system32\igfxtray.exe C:\WINDOWS\system32\hkcmd.exe C:\WINDOWS\system32\igfxpers.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\WINDOWS\SOUNDMAN.EXE C:\Program Files\Launch Manager\LaunchAp.exe C:\Program Files\Launch Manager\HotkeyApp.exe C:\Program Files\Launch Manager\OSDCtrl.exe C:\Program Files\Launch Manager\Wbutton.exe C:\acer\Empowering Technology\ePower\epm-dm.exe C:\Acer\Empowering Technology\eRecovery\Monitor.exe C:\Acer\Empowering Technology\admtray.exe C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe C:\WINDOWS\tsnp2std.exe C:\WINDOWS\vsnp2std.exe C:\Program Files\ATI\Catalyst Media Center\CMCService.exe C:\Program Files\Brownie\BrstsWnd.exe C:\Program Files\AVG\AVG2012\avgtray.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\AVG Secure Search\vprot.exe C:\Program Files\Brownie\brpjp04a.exe D:\Program Files\Spybot - Search & Destroy\TeaTimer.exe D:\Documents and Settings\Real\Local Settings\Application Data\TheWeatherNetwork\WeatherEye\WeatherEye.exe C:\Program Files\USB TV\EM28XX\BDARemote.exe C:\Program Files\REALTEK\11n USB Wireless LAN Utility\RtWLan.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Java\jre6\bin\jqs.exe . ============== Pseudo HJT Report =============== . uStart Page = about:blank uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s mURLSearchHooks: H - No File BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File BHO: {025C9902-B55C-4739-BD41-808BFBD23FF7} - No File BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg2012\avgssie.dll BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - d:\progra~1\spybot~1\SDHelper.dll BHO: AVG Security Toolbar: {95b7759c-8c7f-4bf1-b163-73684a933233} - c:\program files\avg secure search\9.0.0.18\AVG Secure Search_toolbar.dll BHO: {A3A9F3A6-E5B7-4666-A0B9-7901988AF11F} - No File BHO: {AFEB5E5A-1C21-40BD-BCBC-E50860DC4000} - No File BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: Acer eDataSecurity Management: {5cbe3b7c-1e47-477e-a7dd-396db0476e29} - c:\windows\system32\eDStoolbar.dll TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File TB: AVG Security Toolbar: {95b7759c-8c7f-4bf1-b163-73684a933233} - c:\program files\avg secure search\9.0.0.18\AVG Secure Search_toolbar.dll TB: {C4069E3A-68F1-403E-B40E-20066696354B} - No File TB: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No File TB: {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No File uRun: [SpybotSD TeaTimer] d:\program files\spybot - search & destroy\TeaTimer.exe uRun: [WeatherEye] d:\documents and settings\real\local settings\application data\theweathernetwork\weathereye\WeatherEye.exe uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe mRun: [preload] c:\windows\RUNXMLPL.exe mRun: [IMJPMIG8.1] "c:\windows\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 mRun: [MSPY2002] c:\windows\system32\ime\pintlgnt\ImScInst.exe /SYNC mRun: [PHIME2002ASync] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /SYNC mRun: [PHIME2002A] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /IMEName mRun: [igfxtray] c:\windows\system32\igfxtray.exe mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe mRun: [igfxpers] c:\windows\system32\igfxpers.exe mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe mRun: [SoundMan] SOUNDMAN.EXE mRun: [LaunchAp] "c:\program files\launch manager\LaunchAp.exe" mRun: [LManager] "c:\program files\launch manager\HotkeyApp.exe" mRun: [CtrlVol] "c:\program files\launch manager\CtrlVol.exe" mRun: [LMgrOSD] "c:\program files\launch manager\OSDCtrl.exe" mRun: [Wbutton] "c:\program files\launch manager\Wbutton.exe" mRun: [EPM-DM] c:\acer\empowering technology\epower\epm-dm.exe mRun: [Acer ePower Management] c:\acer\empowering technology\epower\Acer ePower Management.exe boot mRun: [eRecoveryService] c:\acer\empowering technology\erecovery\Monitor.exe mRun: [ADMTray.exe] "c:\acer\empowering technology\admtray.exe" mRun: [eDataSecurity Loader] c:\acer\empowering technology\edatasecurity\eDSloader.exe mRun: [tsnp2std] c:\windows\tsnp2std.exe mRun: [snp2std] c:\windows\vsnp2std.exe mRun: [CMCService] "c:\program files\ati\catalyst media center\CMCService.exe" mRun: [Media Codec Update Service] d:\program files\essentials codec pack\update.exe -silent mRun: [BrStsWnd] c:\program files\brownie\BrstsWnd.exe Autorun mRun: [AVG_TRAY] "c:\program files\avg\avg2012\avgtray.exe" mRun: [vProt] "c:\program files\avg secure search\vprot.exe" mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\bdarem~1.lnk - c:\program files\usb tv\em28xx\BDARemote.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\realte~1.lnk - c:\program files\realtek\11n usb wireless lan utility\RtWLan.exe IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000 IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - d:\progra~1\spybot~1\SDHelper.dll DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab TCP: DhcpNameServer = [removed] [removed] [removed] TCP: Interfaces\{30DB7A15-16BF-4C1B-A0A4-22CB48FE40A5} : DhcpNameServer = [removed] [removed] [removed] TCP: Interfaces\{5E8EE570-E275-4CA1-B039-87478A0FBD12} : DhcpNameServer = 192.168.1.254 192.168.1.254 Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg2012\avgpp.dll Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files\common files\avg secure search\viprotocolinstaller\9.0.1\ViProtocol.dll Notify: igfxcui - igfxdev.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll . ============= SERVICES / DRIVERS =============== . R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [2010-9-13 23120] R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2010-9-7 32592] R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2010-9-7 230608] R1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2010-9-7 40016] R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [2010-9-7 295248] R2 avgwd;AVG WatchDog;c:\program files\avg\avg2012\avgwdsvc.exe [2011-8-2 192776] R2 AWService;AdminWorks Agent X6;c:\acer\empowering technology\admServ.exe [2005-10-24 1314816] R2 vToolbarUpdater;vToolbarUpdater;c:\program files\common files\avg secure search\vtoolbarupdater\9.0.1\ToolbarUpdater.exe [2011-11-30 855904] S1 mailKmd;mailKmd; [x] S3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files\avg\avg10\toolbar\ToolbarBroker.exe [2011-4-14 1025352] S3 AVGIDSAgent;AVGIDSAgent;c:\program files\avg\avg2012\AVGIDSAgent.exe [2011-10-12 4433248] S3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [2010-8-19 134608] S3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [2010-8-19 24272] S3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [2010-8-19 16720] S3 ewusbnet;HUAWEI USB-NDIS miniport;c:\windows\system32\drivers\ewusbnet.sys [2010-2-10 113280] S3 hwusbdev;Huawei DataCard USB PNP Device;c:\windows\system32\drivers\ewusbdev.sys [2010-2-10 100736] S3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\windows\system32\drivers\mbamswissarmy.sys –> c:\windows\system32\drivers\mbamswissarmy.sys [?] S3 Revoflt;Revoflt;c:\windows\system32\drivers\revoflt.sys [2011-10-15 27064] S3 RTL8192su;Realtek RTL8192SU Wireless LAN 802.11n USB 2.0 Network Adapter;c:\windows\system32\drivers\rtl8192su.sys [2010-4-26 563840] . =============== Created Last 30 ================ . 2011-12-09 08:19:07 73728 —-a-w- c:\windows\system32\javacpl.cpl 2011-12-08 20:50:38 ——– d—–w- c:\documents and settings\real\local settings\application data\Temp 2011-12-08 19:25:20 ——– d-sh–w- C:\Recycled 2011-12-06 20:17:36 ——– d—–w- c:\program files\ESET 2011-12-06 19:58:13 ——– d—–w- c:\documents and settings\real\application data\Malwarebytes 2011-12-06 19:57:55 ——– d—–w- c:\documents and settings\all users\application data\Malwarebytes 2011-12-06 19:57:51 22216 —-a-w- c:\windows\system32\drivers\mbam.sys 2011-12-05 04:06:39 ——– d-sha-r- C:\cmdcons 2011-12-05 04:04:54 98816 —-a-w- c:\windows\sed.exe 2011-12-05 04:04:54 518144 —-a-w- c:\windows\SWREG.exe 2011-12-05 04:04:54 256000 —-a-w- c:\windows\PEV.exe 2011-12-05 04:04:54 208896 —-a-w- c:\windows\MBR.exe 2011-11-30 19:03:08 ——– d—–w- c:\documents and settings\real\application data\AVG Secure Search 2011-11-30 18:50:48 ——– d—–w- c:\documents and settings\all users\application data\AVG Secure Search . ==================== Find3M ==================== . 2011-12-09 08:18:52 472808 —-a-w- c:\windows\system32\deployJava1.dll 2011-11-16 06:17:38 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2011-10-10 14:22:42 692736 —-a-w- c:\windows\system32\inetcomm.dll 2011-10-07 14:23:48 230608 —-a-w- c:\windows\system32\drivers\avgldx86.sys 2011-10-04 14:21:42 16720 —-a-w- c:\windows\system32\drivers\AVGIDSShim.sys 2011-09-28 07:06:50 599040 —-a-w- c:\windows\system32\crypt32.dll 2011-09-26 19:41:20 611328 ——w- c:\windows\system32\uiautomationcore.dll 2011-09-26 19:41:20 220160 —-a-w- c:\windows\system32\oleacc.dll 2011-09-26 19:41:14 20480 —-a-w- c:\windows\system32\oleaccrc.dll 2011-09-13 14:30:10 32592 —-a-w- c:\windows\system32\drivers\avgrkx86.sys . ============= FINISH: 0:35:25.60 =============== . UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_2011-08-26.01) . Microsoft Windows XP Home Edition Boot Device: \Device\HarddiskVolume2 Install Date: 12/26/2006 12:15:37 PM System Uptime: 12/9/2011 12:14:14 AM (0 hours ago) . Motherboard: Acer | | Garda-910 Processor: Intel® Pentium® M processor 1.73GHz | U1 | 1729/133mhz . ==== Disk Partitions ========================= . C: is FIXED (FAT32) - 26 GiB total, 6.046 GiB free. D: is FIXED (FAT32) - 26 GiB total, 6.444 GiB free. E: is CDROM () . ==== Disabled Device Manager Items ============= . ==== System Restore Points =================== . RP946: 10/17/2011 9:47:16 PM - System Checkpoint RP947: 10/19/2011 5:01:06 PM - System Checkpoint RP948: 10/20/2011 5:10:42 PM - System Checkpoint RP949: 10/21/2011 8:44:28 PM - System Checkpoint RP950: 10/22/2011 11:27:58 PM - System Checkpoint RP951: 10/24/2011 4:25:15 PM - System Checkpoint RP952: 10/25/2011 4:34:02 PM - System Checkpoint RP953: 10/26/2011 5:49:38 PM - System Checkpoint RP954: 10/27/2011 5:58:55 PM - System Checkpoint RP955: 10/27/2011 8:05:36 PM - Software Distribution Service 3.0 RP956: 10/27/2011 8:33:48 PM - Software Distribution Service 3.0 RP957: 10/30/2011 4:49:59 PM - System Checkpoint RP958: 11/1/2011 4:48:21 PM - System Checkpoint RP959: 11/2/2011 5:03:01 PM - System Checkpoint RP960: 11/4/2011 10:45:40 PM - System Checkpoint RP961: 11/7/2011 4:36:28 PM - System Checkpoint RP962: 11/8/2011 4:38:55 PM - System Checkpoint RP963: 11/8/2011 9:41:02 PM - Software Distribution Service 3.0 RP964: 11/10/2011 5:22:40 PM - System Checkpoint RP965: 11/10/2011 6:36:43 PM - Software Distribution Service 3.0 RP966: 11/12/2011 1:05:38 PM - System Checkpoint RP967: 11/13/2011 7:18:15 PM - System Checkpoint RP968: 11/15/2011 4:32:53 PM - System Checkpoint RP969: 11/17/2011 3:23:35 PM - System Checkpoint RP970: 11/19/2011 10:07:13 AM - System Checkpoint RP971: 11/21/2011 4:34:55 PM - System Checkpoint RP972: 11/23/2011 4:14:18 PM - System Checkpoint RP973: 11/25/2011 3:32:10 PM - System Checkpoint RP974: 11/27/2011 11:21:53 AM - System Checkpoint RP975: 11/29/2011 10:12:06 AM - System Checkpoint RP976: 11/30/2011 11:28:24 AM - System Checkpoint RP977: 12/2/2011 10:54:11 AM - System Checkpoint RP978: 12/3/2011 6:57:44 PM - System Checkpoint RP979: 12/6/2011 10:54:15 AM - System Checkpoint RP980: 12/8/2011 9:39:35 AM - System Checkpoint RP981: 12/8/2011 12:27:08 PM - Removed Adobe Reader 8.1.3 RP982: 12/8/2011 12:47:12 PM - Installed Adobe Reader X (10.1.1). RP983: 12/9/2011 12:10:04 AM - Removed Java™ 6 Update 12 RP984: 12/9/2011 12:18:33 AM - Installed Java™ 6 Update 29 . ==== Installed Programs ====================== . µTorrent Acer eDataSecurity Management Acer eDataSecurity Management 1.00.26 Acer eLock Management Acer Empowering Technology framework Acer eNet Management Acer ePerformance Management Acer ePower Management Acer ePresentation Management Acer eSettings Management Acer GridVista Adobe Flash Player 11 ActiveX Adobe Reader X (10.1.1) ATI - Software Uninstall Utility ATI AVIVO Codecs AVG 2012 Brother HL-2140 CASISuite60 Catalyst Media Center Catalyst Media Center DVD Authoring Module CCleaner Cisco Connect ConvertXtoDVD [removed] CoolTick Stock Ticker 8.62 ESET Online Scanner v3 Free NaturalReader getPlus®_ocx Hotfix for Windows Media Format 11 SDK (KB929399) Hotfix for Windows Media Player 11 (KB939683) Hotfix for Windows XP (KB2570791) Hotfix for Windows XP (KB952287) Hotfix for Windows XP (KB979306) Hotfix for Windows XP (KB981793) Intel® Graphics Media Accelerator Driver for Mobile Intel® PROSet/Wireless Software InterActual Player IrfanView (remove only) Java Auto Updater Java™ 6 Update 29 Launch Manager V1.1.0.1 Malwarebytes' Anti-Malware version 1.51.2.1300 mCore Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Security Update (KB2572067) Microsoft .NET Framework 1.1 Security Update (KB979906) Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Office Professional Edition 2003 Microsoft User-Mode Driver Framework Feature Pack 1.0 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 mMHouse Mobile Internet Key mPfMgr mProSafe MSXML 4.0 SP2 (KB936181) MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) mWlsSafe mXML NTI Backup NOW! 4 NTI CD & DVD-Maker OJOsoft Total Video Converter PowerDVD Realtek AC'97 Audio REALTEK Wireless LAN Driver and Utility Revo Uninstaller Pro 2.5.5 Security Update for Microsoft Windows (KB2564958) Security Update for Windows Internet Explorer 8 (KB2497640) Security Update for Windows Internet Explorer 8 (KB2510531) Security Update for Windows Internet Explorer 8 (KB2530548) Security Update for Windows Internet Explorer 8 (KB2544521) Security Update for Windows Internet Explorer 8 (KB2559049) Security Update for Windows Internet Explorer 8 (KB2586448) Security Update for Windows Internet Explorer 8 (KB971961) Security Update for Windows Internet Explorer 8 (KB972260) Security Update for Windows Internet Explorer 8 (KB981332) Security Update for Windows Internet Explorer 8 (KB982381) Security Update for Windows Media Player (KB2378111) Security Update for Windows Media Player (KB911564) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player (KB954155) Security Update for Windows Media Player (KB968816) Security Update for Windows Media Player (KB973540) Security Update for Windows Media Player (KB975558) Security Update for Windows Media Player (KB978695) Security Update for Windows Media Player 11 (KB936782) Security Update for Windows Media Player 11 (KB954154) Security Update for Windows Media Player 6.4 (KB925398) Security Update for Windows Media Player 9 (KB936782) Security Update for Windows XP (KB2079403) Security Update for Windows XP (KB2115168) Security Update for Windows XP (KB2121546) Security Update for Windows XP (KB2229593) Security Update for Windows XP (KB2296011) Security Update for Windows XP (KB2347290) Security Update for Windows XP (KB2360937) Security Update for Windows XP (KB2387149) Security Update for Windows XP (KB2393802) Security Update for Windows XP (KB2412687) Security Update for Windows XP (KB2419632) Security Update for Windows XP (KB2423089) Security Update for Windows XP (KB2440591) Security Update for Windows XP (KB2443105) Security Update for Windows XP (KB2476490) Security Update for Windows XP (KB2478960) Security Update for Windows XP (KB2478971) Security Update for Windows XP (KB2479943) Security Update for Windows XP (KB2481109) Security Update for Windows XP (KB2483185) Security Update for Windows XP (KB2485663) Security Update for Windows XP (KB2491683) Security Update for Windows XP (KB2506212) Security Update for Windows XP (KB2507618) Security Update for Windows XP (KB2507938) Security Update for Windows XP (KB2508272) Security Update for Windows XP (KB2508429) Security Update for Windows XP (KB2509553) Security Update for Windows XP (KB2535512) Security Update for Windows XP (KB2536276-v2) Security Update for Windows XP (KB2544893-v2) Security Update for Windows XP (KB2544893) Security Update for Windows XP (KB2562937) Security Update for Windows XP (KB2566454) Security Update for Windows XP (KB2567053) Security Update for Windows XP (KB2567680) Security Update for Windows XP (KB2570222) Security Update for Windows XP (KB2570947) Security Update for Windows XP (KB2592799) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB938464) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950759) Security Update for Windows XP (KB950760) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951066) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB954600) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956391) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956744) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB956844) Security Update for Windows XP (KB958215) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958869) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960225) Security Update for Windows XP (KB960714) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB960859) Security Update for Windows XP (KB961501) Security Update for Windows XP (KB963027) Security Update for Windows XP (KB969059) Security Update for Windows XP (KB969947) Security Update for Windows XP (KB970238) Security Update for Windows XP (KB970430) Security Update for Windows XP (KB971468) Security Update for Windows XP (KB971657) Security Update for Windows XP (KB972270) Security Update for Windows XP (KB973346) Security Update for Windows XP (KB973354) Security Update for Windows XP (KB973507) Security Update for Windows XP (KB973869) Security Update for Windows XP (KB973904) Security Update for Windows XP (KB974112) Security Update for Windows XP (KB974318) Security Update for Windows XP (KB974392) Security Update for Windows XP (KB974571) Security Update for Windows XP (KB975025) Security Update for Windows XP (KB975467) Security Update for Windows XP (KB975560) Security Update for Windows XP (KB975561) Security Update for Windows XP (KB975562) Security Update for Windows XP (KB975713) Security Update for Windows XP (KB977816) Security Update for Windows XP (KB977914) Security Update for Windows XP (KB978037) Security Update for Windows XP (KB978262) Security Update for Windows XP (KB978338) Security Update for Windows XP (KB978542) Security Update for Windows XP (KB978601) Security Update for Windows XP (KB978706) Security Update for Windows XP (KB979309) Security Update for Windows XP (KB979482) Security Update for Windows XP (KB979559) Security Update for Windows XP (KB979683) Security Update for Windows XP (KB979687) Security Update for Windows XP (KB980195) Security Update for Windows XP (KB980218) Security Update for Windows XP (KB980232) Security Update for Windows XP (KB980436) Security Update for Windows XP (KB981322) Security Update for Windows XP (KB981997) Security Update for Windows XP (KB982132) Security Update for Windows XP (KB982665) Send To Phone 2.1 Sentinel Protection Installer 7.1.0 Soft Data Fax Modem with SmartCP SoftV90 Data Fax Modem with SmartCP Spybot - Search & Destroy Spybot - Search & Destroy 1.5.2.20 SpywareBlaster 4.0 Synaptics Pointing Device Driver TickerTape 1.3 UDoTaxes2010 Ultra DVD Ripper 3.0.1203 Update for Windows Internet Explorer 8 (KB976662) Update for Windows Internet Explorer 8 (KB980182) Update for Windows XP (KB2345886) Update for Windows XP (KB2541763) Update for Windows XP (KB2616676-v2) Update for Windows XP (KB2641690) Update for Windows XP (KB951978) Update for Windows XP (KB955759) Update for Windows XP (KB967715) Update for Windows XP (KB968389) Update for Windows XP (KB971029) Update for Windows XP (KB971737) Update for Windows XP (KB973687) Update for Windows XP (KB973815) USB Video Driver USB2.0 PC Camera (SN9C201&202) VLC media player 0.9.8a WeatherEye WebFldrs XP WinAVI Video Converter Windows Driver Package - Advanced Micro Devices, Inc. (USB28xxBGA) Media (08/31/2007 5.7.0831.0) Windows Driver Package - eMPIA Technology Inc, (emAudio) MEDIA (08/31/2007 5.7.0831.0) Windows Essentials Media Codec Pack 1.0 Windows Internet Explorer 8 Windows Media Format 11 runtime Windows Media Player 11 Windows XP Service Pack 3 Yahoo! Install Manager Yahoo! Internet Mail Yahoo! Messenger . ==== Event Viewer Messages From Past Week ======== . 12/8/2011 12:20:25 PM, error: Service Control Manager [7023] - The Application Management service terminated with the following error: The specified module could not be found. 12/6/2011 10:42:55 PM, error: Dhcp [1002] - The IP address lease 192.168.1.101 for the Network Card with network address 00166FA1A2E4 has been denied by the DHCP server [removed] (The DHCP Server sent a DHCPNACK message). 12/6/2011 10:28:06 AM, error: Service Control Manager [7022] - The CyberLink Background Capture Service (CBCS) service hung on starting. 12/6/2011 10:28:06 AM, error: Service Control Manager [7001] - The CyberLink Task Scheduler (CTS) service depends on the CyberLink Background Capture Service (CBCS) service which failed to start because of the following error: After starting, the service hung in a start-pending state. 12/3/2011 6:18:25 PM, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751) . ==== End Of File ===========================
Hi

Follow the steps here to reset the new tab page to open to your home page (or wherever you want it to)
http://windows.microsoft.com/en-CA/windows…ternet-Explorer

we just have some housekeeping to do now, please do the following:


You can delete the TDSSKiller, DDS and aswMBR logs and programs from your desktop.


NEXT


Follow these steps to uninstall Combofix

  • Make sure your security programs are totally disabled.
  • Click START then RUN
  • Now copy/paste Combofix /uninstall into the runbox and click OK. Note the space between the ..X and the /U, it needs to be there.

[external image: Posted Image]


If there are any logs/tools remaining on your desktop > right click and delete them.


NEXT


Below I have included a number of recommendations for how to protect your computer against malware infections.

  • It is good security practice to change your passwords to all your online accounts on a fairly regular basis, this is especially true after an infection. Refer to this Microsoft article
    Strong passwords: How to create and use them
    Then consider a password keeper, to keep all your passwords safe. KeePass is a small utility that allows you to manage all your passwords.

  • Keep Windows updated by regularly checking their website at :
    http://windowsupdate.microsoft.com/
    This will ensure your computer has always the latest security updates available installed on your computer.

  • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.

  • Download TFC to your desktop
    • Close any open windows.
    • Double click the TFC icon to run the program
    • TFC will close all open programs itself in order to run,
    • Click the Start button to begin the process.
    • Allow TFC to run uninterrupted.
    • The program should not take long to finish it's job
    • Once its finished it should automatically reboot your machine,
    • if it doesn't, manually reboot to ensure a complete clean
    It's normal after running TFC cleaner that the PC will be slower to boot the first time.

  • WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
    • Green to go
    • Yellow for caution
    • Red to stop
    WOT has an addon available for both Firefox and IE

  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.

  • ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.

  • In light of your recent issue, I'm sure you'd like to avoid any future infections. Please take a look at this well written article:
    PC Safety and Security–What Do I Need?.


**Be very wary with any security software that is advertised in popups or in other ways. They are not only usually of no use, but often have malware in them.


Thank you for your patience, and performing all of the procedures requested.

Please respond one last time so we can consider the thread resolved and close it, thank-you.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI