This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

PSW.Agent.ASTO Help [Solved]

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello Whatthetech! My father has found his laptop infected with PSW.Agent.ASTO per AVG. He has asked me to take a look. I haven't done much except scanning at this time. The laptop is experiencing very sluggish performance in general, constant redirects or no loading of websites at all over the wireless connection. Wired connection appears to be ok so far. I hope I'm writing in the correct forum if not please forgive me and direct me to the correct place. Below are the contents of the OTL.log and extras.log. Thanks for any help!

OTL logfile created on: 8/25/2012 10:34:54 PM - Run 2
OTL by OldTimer - Version 3.2.58.1 Folder = C:\Documents and Settings\Bill\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1023.39 Mb Total Physical Memory | 513.54 Mb Available Physical Memory | 50.18% Memory free
2.40 Gb Paging File | 1.82 Gb Available in Paging File | 75.64% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 232.88 Gb Total Space | 208.42 Gb Free Space | 89.50% Space Free | Partition Type: NTFS

Computer Name: BILLSLAPTOP | User Name: Bill | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Bill\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\11.2.0\ToolbarUpdater.exe ()
PRC - C:\Program Files\AVG Secure Search\vprot.exe ()
PRC - C:\Program Files\AVG\AVG2012\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2012\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2012\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2012\avgemcx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2012\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG PC Tuneup\BoostSpeed.exe (AVG)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc)
PRC - C:\Program Files\Dell\QuickSet\NicConfigSvc.exe (Dell Inc.)
PRC - C:\Program Files\Intel\Wireless\Bin\ZCfgSvc.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe (Intel® Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\iFrmewrk.exe (Intel Corporation)
PRC - C:\Program Files\Apoint\Apoint.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\Apoint\ApntEx.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\Apoint\hidfind.exe (Alps Electric Co., Ltd.)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\11.2.0\SiteSafety.dll ()
MOD - C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\11.2.0\ToolbarUpdater.exe ()
MOD - C:\Program Files\AVG Secure Search\vprot.exe ()
MOD - C:\Program Files\AVG\AVG PC Tuneup\madExcept_.bpl ()
MOD - C:\Program Files\AVG\AVG PC Tuneup\madBasic_.bpl ()
MOD - C:\Program Files\AVG\AVG PC Tuneup\madDisAsm_.bpl ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files\Dell\QuickSet\dadkeyb.dll ()
MOD - C:\Program Files\Intel\Wireless\Bin\iWMSProv.dll ()


========== Win32 Services (SafeList) ==========

SRV - (zBackupAssistService) – %systemroot%\system32\sfvfs02.dll File not found
SRV - (viairda) – %systemroot%\system32\A4S2600.dll File not found
SRV - (vhidmini) – %systemroot%\system32\blueletscoaudio.dll File not found
SRV - (vc5secs) – %systemroot%\system32\lusbaudio.dll File not found
SRV - (UimBus) – %systemroot%\system32\RimSerPort.dll File not found
SRV - (TPwSav) – %systemroot%\system32\SE26bus.dll File not found
SRV - (tga) – %systemroot%\system32\s7oppitx.dll File not found
SRV - (SunkFilt) – %systemroot%\system32\nipxirmu.dll File not found
SRV - (StillCam) – %systemroot%\system32\vulfntrs.dll File not found
SRV - (sscdserd) – %systemroot%\system32\plugplay.dll File not found
SRV - (slssvc) – %systemroot%\system32\ELacpi.dll File not found
SRV - (sfvfs02) – %systemroot%\system32\vc8secs.dll File not found
SRV - (SE2Cmdm) – %systemroot%\system32\dlpwd.dll File not found
SRV - (SE2Bmdfl) – %systemroot%\system32\vss.dll File not found
SRV - (rpaservice) – %systemroot%\system32\dmisrv.dll File not found
SRV - (ptbsync) – %systemroot%\system32\irsir.dll File not found
SRV - (pnrouter) – %systemroot%\system32\MobilityService.dll File not found
SRV - (p1110vid) – %systemroot%\system32\tdcmdpst.dll File not found
SRV - (opcenum) – %systemroot%\system32\mssql$pinnaclesys.dll File not found
SRV - (nocashio) – %systemroot%\system32\csctl50.dll File not found
SRV - (NEC Usb3) – C:\WINDOWS\system32\usbnaw32.dll File not found
SRV - (ibmpmsvc) – %systemroot%\system32\msftpsvc.dll File not found
SRV - (helpsvc) – %SystemRoot%\PCHealth\HelpCtr\Binaries\pchsvc.dlles\pchsvc.dll File not found
SRV - (FVXSCSI) – %systemroot%\system32\bt3cusb.dll File not found
SRV - (firesvc) – %systemroot%\system32\logonsvcid.dll File not found
SRV - (df5serv) – %systemroot%\system32\BCM43XV.dll File not found
SRV - (DcLps) – %systemroot%\system32\trayman.dll File not found
SRV - (ANC) – %systemroot%\system32\nimcdfxk.dll File not found
SRV - (a016bus) – %systemroot%\system32\w3svc.dll File not found
SRV - (vToolbarUpdater11.2.0) – C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\11.2.0\ToolbarUpdater.exe ()
SRV - (AVGIDSAgent) – C:\Program Files\AVG\AVG2012\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
SRV - (avgwd) – C:\Program Files\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (NICCONFIGSVC) – C:\Program Files\Dell\QuickSet\NicConfigSvc.exe (Dell Inc.)
SRV - (WLANKEEPER) – C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe (Intel® Corporation)


========== Driver Services (SafeList) ==========

DRV - (WDICA) – File not found
DRV - (UIUSys) – system32\drivers\UIUSys.sys File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (PCIDump) – File not found
DRV - (lbrtfdc) – File not found
DRV - (i2omgmt) – File not found
DRV - (Changer) – File not found
DRV - (NPF) – C:\WINDOWS\system32\drivers\npf.sys (CACE Technologies, Inc.)
DRV - (AVGIDSHX) – C:\WINDOWS\system32\drivers\avgidshx.sys (AVG Technologies CZ, s.r.o. )
DRV - (Avgtdix) – C:\WINDOWS\system32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgldx86) – C:\WINDOWS\system32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgrkx86) – C:\WINDOWS\system32\drivers\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgmfx86) – C:\WINDOWS\system32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSShim) – C:\WINDOWS\system32\drivers\avgidsshimx.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSFilter) – C:\WINDOWS\system32\drivers\avgidsfilterx.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSDriver) – C:\WINDOWS\system32\drivers\avgidsdriverx.sys (AVG Technologies CZ, s.r.o. )
DRV - (s24trans) – C:\WINDOWS\system32\drivers\s24trans.sys (Intel Corporation)
DRV - (w29n51) – C:\WINDOWS\system32\drivers\w29n51.sys (Intel® Corporation)
DRV - (GTIPCI21) – C:\WINDOWS\system32\drivers\gtipci21.sys (Texas Instruments)
DRV - (ApfiltrService) – C:\WINDOWS\system32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (APPDRV) – C:\WINDOWS\system32\drivers\APPDRV.SYS (Dell Inc)
DRV - (gv3) – C:\WINDOWS\system32\drivers\gv3.sys (Microsoft Corporation)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (HSF_DPV) – C:\WINDOWS\system32\drivers\HSF_DPV.SYS (Conexant Systems, Inc.)
DRV - (HSFHWICH) – C:\WINDOWS\system32\drivers\HSFHWICH.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (STAC97) – C:\WINDOWS\system32\drivers\STAC97.sys (SigmaTel, Inc.)
DRV - (b57w2k) – C:\WINDOWS\system32\drivers\b57xp32.sys (Broadcom Corporation)
DRV - (ATIXPGAA) – C:\DELL\drivers\R101342\ATIXPGAA.SYS (ATI Technologies Inc.)
DRV - (OMCI) – C:\WINDOWS\system32\drivers\omci.sys (Dell Computer Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.centurylink.net/
IE - HKCU\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
IE - HKCU\..\SearchScopes,DefaultScope = {B240DD26-4407-41C9-8AF2-9C9CF73A29D3}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…amp;Form=IE8SRC
IE - HKCU\..\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}: "URL" = http://websearch.ask.com/redirect?client=i…mp;locale=en_US
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE - HKCU\..\SearchScopes\{7C5D3DC9-6347-406C-9697-A210947166A7}: "URL" = http://spicesearch.net/search.php?src=tops…q={SearchTerms}
IE - HKCU\..\SearchScopes\{7D184F1B-A9FC-4227-9E7C-E193AA25FAEA}: "URL" = http://search.avg.com/?d=4d5dd405&i;=23…guage}&nt;=1
IE - HKCU\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = http://isearch.avg.com/search?cid={794AE34…mp;d=2012-07-21 13:27:51&v;=11.0.0.10&sap;=dsp&q;={searchTerms}
IE - HKCU\..\SearchScopes\{B240DD26-4407-41C9-8AF2-9C9CF73A29D3}: "URL" = http://www.google.com/search?q={searchTerm…;rlz=1I7GGLL_en
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local


========== FireFox ==========

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin: C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\11.2.0\\npsitesafety.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_33: C:\WINDOWS\system32\npdeployJava1.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player: C:\Documents and Settings\Bill\Application Data\Move Networks\plugins\npqmp071503000010.dll (Move Networks)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player: C:\Documents and Settings\Bill\Application Data\Move Networks\plugins\npqmp071503000010.dll (Move Networks)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{F53C93F1-07D5-430c-86D4-C9531B27DFAF}: C:\Program Files\AVG\AVG2012\Firefox\DoNotTrack\ [2012/07/21 13:26:24 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\avg@toolbar: C:\Documents and Settings\All Users\Application Data\AVG Secure Search\11.1.0.12\ [2012/08/01 16:47:46 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[removed]: C:\Documents and Settings\Bill\Application Data\Move Networks [2009/11/04 20:19:47 | 000,000,000 | —D | M]

[2009/02/04 20:23:18 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Bill\Application Data\Mozilla\Extensions
[2009/02/04 20:23:18 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Bill\Application Data\Mozilla\Extensions\[removed]

========== Chrome ==========

CHR - default_search_provider: Google ()
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}source
id=chrome&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?client=chrome&output;=chrome&hl;={language}&q;={searchTerms}
CHR - homepage: http://spicesearch.net/

Hosts file not found
O2 - BHO: (AVG Do Not Track) - {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files\AVG\AVG2012\avgdtiex.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\11.1.0.12\AVG Secure Search_toolbar.dll ()
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7227.1100\swg.dll (Google Inc.)
O2 - BHO: (MSN Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3.0.1125.0\msneshellx.dll (Microsoft Corp.)
O2 - BHO: (LimeWire Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O2 - BHO: (AdvancedBrowserShoppingTips) - {E98C0F9D-DB47-6499-7D2E-24C6240895C8} - C:\Program Files\AdvancedBrowserShoppingTips\AdvancedBrowserShoppingTips.dll File not found
O3 - HKLM\..\Toolbar: (MSN Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.1125.0\msneshellx.dll (Microsoft Corp.)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\11.1.0.12\AVG Secure Search_toolbar.dll ()
O3 - HKLM\..\Toolbar: (LimeWire Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O3 - HKCU\..\Toolbar\WebBrowser: (LimeWire Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O4 - HKLM..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc)
O4 - HKLM..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe (Intel Corporation)
O4 - HKLM..\Run: [IntelZeroConfig] C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe (Intel Corporation)
O4 - HKLM..\Run: [vProt] C:\Program Files\AVG Secure Search\vprot.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra Button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe (PokerStars)
O9 - Extra Button: AVG Do Not Track - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files\AVG\AVG2012\avgdtiex.dll (AVG Technologies CZ, s.r.o.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.microsoft.com/windowsupd…b?1233792581121 (WUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_33)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} http://floridakeysmedia.tv/axiscam/Codebas…sCamControl.ocx (CamImage Class)
O16 - DPF: {CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_33)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_33)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3A9AEE7E-CEBB-42D6-9F37-70FE30B28641}: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\11.2.0\ViProtocol.dll ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\Bill\Application Data\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Bill\Application Data\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O32 - Unable to open key or key not present!
O32 - AutoRun File - [2009/02/04 17:03:32 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG2012\avgrsx.exe /sync /restart)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: p1110vid - %systemroot%\system32\tdcmdpst.dll File not found
NetSvcs: df5serv - %systemroot%\system32\BCM43XV.dll File not found
NetSvcs: pnrouter - %systemroot%\system32\MobilityService.dll File not found
NetSvcs: firesvc - %systemroot%\system32\logonsvcid.dll File not found
NetSvcs: slssvc - %systemroot%\system32\ELacpi.dll File not found
NetSvcs: viairda - %systemroot%\system32\A4S2600.dll File not found
NetSvcs: ptbsync - %systemroot%\system32\irsir.dll File not found
NetSvcs: DcLps - %systemroot%\system32\trayman.dll File not found
NetSvcs: zBackupAssistService - %systemroot%\system32\sfvfs02.dll File not found
NetSvcs: a016bus - %systemroot%\system32\w3svc.dll File not found
NetSvcs: TPwSav - %systemroot%\system32\SE26bus.dll File not found
NetSvcs: sfvfs02 - %systemroot%\system32\vc8secs.dll File not found
NetSvcs: rpaservice - %systemroot%\system32\dmisrv.dll File not found
NetSvcs: nocashio - %systemroot%\system32\csctl50.dll File not found
NetSvcs: UimBus - %systemroot%\system32\RimSerPort.dll File not found
NetSvcs: sscdserd - %systemroot%\system32\plugplay.dll File not found
NetSvcs: SE2Bmdfl - %systemroot%\system32\vss.dll File not found
NetSvcs: vc5secs - %systemroot%\system32\lusbaudio.dll File not found
NetSvcs: vhidmini - %systemroot%\system32\blueletscoaudio.dll File not found
NetSvcs: ANC - %systemroot%\system32\nimcdfxk.dll File not found
NetSvcs: StillCam - %systemroot%\system32\vulfntrs.dll File not found
NetSvcs: opcenum - %systemroot%\system32\mssql$pinnaclesys.dll File not found
NetSvcs: FVXSCSI - %systemroot%\system32\bt3cusb.dll File not found
NetSvcs: ibmpmsvc - %systemroot%\system32\msftpsvc.dll File not found
NetSvcs: SE2Cmdm - %systemroot%\system32\dlpwd.dll File not found
NetSvcs: SunkFilt - %systemroot%\system32\nipxirmu.dll File not found
NetSvcs: tga - %systemroot%\system32\s7oppitx.dll File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: helpsvc - %SystemRoot%\PCHealth\HelpCtr\Binaries\pchsvc.dlles\pchsvc.dll File not found

Drivers32: msacm.iac2 - C:\WINDOWS\System32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/08/25 22:26:54 | 000,596,480 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Bill\Desktop\OTL.exe
[2012/08/25 22:00:32 | 000,000,000 | —D | C] – C:\WINDOWS\CSC
[2012/08/17 20:19:24 | 000,000,000 | -HSD | C] – C:\Config.Msi
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/08/25 22:27:03 | 000,596,480 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Bill\Desktop\OTL.exe
[2012/08/25 22:19:51 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2012/08/25 22:19:24 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/08/25 22:19:24 | 000,000,366 | —- | M] () – C:\WINDOWS\tasks\AVG PC Tuneup Integrator Start On Bill Logon.job
[2012/08/25 22:19:17 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012/08/25 21:14:00 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/08/25 18:20:23 | 104,889,247 | —- | M] () – C:\WINDOWS\System32\drivers\AVG\incavi.avm
[2012/08/25 18:03:14 | 000,000,420 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{7DB3CAAF-CC8A-4858-8CB9-DD39357FE1DB}.job
[2012/08/25 17:01:08 | 000,000,232 | —- | M] () – C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
[2012/08/25 13:22:54 | 104,853,765 | —- | M] () – C:\WINDOWS\System32\drivers\AVG\incavi.avm.old
[2012/08/22 19:16:49 | 000,054,269 | —- | M] () – C:\WINDOWS\System32\drivers\AVG\iavichjg.avm
[2012/08/17 21:09:43 | 000,095,072 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2012/08/17 20:31:05 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2012/08/17 20:13:54 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2012/08/14 08:55:32 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2012/08/10 16:55:00 | 000,027,520 | —- | M] () – C:\Documents and Settings\Bill\Local Settings\Application Data\dt.dat
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/08/10 16:55:00 | 000,027,520 | —- | C] () – C:\Documents and Settings\Bill\Local Settings\Application Data\dt.dat
[2012/02/17 16:53:22 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2010/10/30 05:55:43 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2009/02/13 20:14:00 | 000,005,632 | —- | C] () – C:\Documents and Settings\Bill\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

========== LOP Check ==========

[2012/05/06 16:16:53 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\529C50A800006F0F01169D2AD151FC4E
[2012/08/01 18:02:04 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG Secure Search
[2012/07/21 13:38:01 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG2012
[2011/02/17 21:04:29 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Common Files
[2009/03/27 17:18:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Graboid Inc
[2012/08/25 13:23:38 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MFAData
[2012/02/24 21:37:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\RNDDock
[2012/08/25 22:38:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Temp
[2011/08/23 18:52:24 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TNDDock
[2009/03/12 06:11:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
[2010/04/11 08:16:03 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/10/17 08:05:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/06/23 22:06:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2012/04/14 18:39:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Bill\Application Data\AVG
[2012/07/21 13:27:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Bill\Application Data\AVG Secure Search
[2012/07/21 13:29:44 | 000,000,000 | —D | M] – C:\Documents and Settings\Bill\Application Data\AVG2012
[2009/02/04 18:44:49 | 000,000,000 | —D | M] – C:\Documents and Settings\Bill\Application Data\Infineon
[2012/07/21 15:07:48 | 000,000,000 | —D | M] – C:\Documents and Settings\Bill\Application Data\LimeWire
[2012/08/25 22:19:24 | 000,000,366 | —- | M] () – C:\WINDOWS\Tasks\AVG PC Tuneup Integrator Start On Bill Logon.job
[2012/08/25 17:01:08 | 000,000,232 | —- | M] () – C:\WINDOWS\Tasks\Scheduled Update for Ask Toolbar.job
[2012/08/25 18:03:14 | 000,000,420 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{7DB3CAAF-CC8A-4858-8CB9-DD39357FE1DB}.job

========== Purity Check ==========



========== Custom Scans ==========

< %SYSTEMDRIVE%\*.* >
[2009/02/04 17:03:32 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2012/07/21 12:32:15 | 000,000,211 | RHS- | M] () – C:\boot.ini
[2009/02/04 17:03:32 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2009/02/04 17:03:32 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2009/02/04 17:03:32 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2009/02/04 19:43:44 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2009/02/06 05:12:19 | 000,250,048 | RHS- | M] () – C:\ntldr
[2012/08/25 22:19:13 | 1610,612,736 | -HS- | M] () – C:\pagefile.sys

< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/02/04 17:03:18 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 07:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2008/07/06 05:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2009/02/04 10:52:32 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2009/02/04 10:52:32 | 000,626,688 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2009/02/04 10:52:32 | 000,421,888 | —- | M] () – C:\WINDOWS\System32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2009/02/06 05:19:40 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009/02/04 19:57:51 | 000,000,177 | -HS- | M] () – C:\Documents and Settings\Bill\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2009/02/04 17:09:33 | 000,000,079 | —- | M] () – C:\Documents and Settings\Bill\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2012/08/25 22:27:03 | 000,596,480 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Bill\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2012-08-18 01:31:34

< >

========== Hard Links - Junction Points - Mount Points - Symbolic Links ==========
[C:\WINDOWS\$NtUninstallKB35810$] -> Error: Cannot create file handle -> Unknown point type

========== Alternate Data Streams ==========

@Alternate Data Stream - 181 bytes -> C:\Documents and Settings\All Users\Application Data\Temp:0B4227B4

< End of report >
Hi Dreadful,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

There apparently were no extras.

That's because you ran OTL twice. The Extra.txt is only created on the first run.

It looks like you have a couple things going on in there.

Download ComboFix:

http://download.bleepingcomputer.com/sUBs/ComboFix.exe

* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link –> http://forums.whatthetech.com/How_Disable_…ams_t96260.html

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.


Notes:

1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Here's the Combofix log. Things to note: Combofix advised that the recovery console was not installed, but said alternately there may be a version installed that is not up-to-date. I followed the prompt to download, but the download failed. ComboFix went ahead scanning and fixing anyways. ComboFix did hang while deleting C:\Windows\System32\Cache. I rebooted and ComboFix completed, producing the following log.
Thank you, Tomk for your help!

ComboFix 12-08-25.04 - Bill 08/27/2012 0:00.2.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1023.600 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\TEMP
c:\windows\$NtUninstallKB35810$\3622537572
.
—- Previous Run ——-
.
c:\documents and settings\All Users\Application Data\TEMP
c:\documents and settings\All Users\Application Data\TEMP\AVG\avgmfapx.exe
c:\documents and settings\All Users\Application Data\TEMP\AVG\avgmfarx.dll
c:\documents and settings\All Users\Application Data\TEMP\AVG\avgntdumpx.exe
c:\documents and settings\All Users\Application Data\TEMP\AVG\avgrunasx.exe
c:\documents and settings\All Users\Application Data\TEMP\AVG\avi7.avg
c:\documents and settings\All Users\Application Data\TEMP\AVG\htmlayout.dll
c:\documents and settings\All Users\Application Data\TEMP\AVG\incavi.avm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_cz.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_da.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_es.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_fr.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_ge.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_hu.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_id.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_in.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_it.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_jp.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_ko.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_ms.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_nl.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_pb.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_pl.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_pt.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_ru.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_sc.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_sk.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_sp.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_tr.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_us.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_zh.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_zt.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfaconf.txt
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfacz.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfada.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfaes.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfafr.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfage.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfahu.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfaid.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfain.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfait.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfajp.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfako.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfams.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfanl.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfapb.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfapl.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfapt.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfaru.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfasc.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfask.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfasp.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfatr.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfaus.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfavera.txt
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfaverx.txt
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfazh.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfazt.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\microavi.avg
c:\documents and settings\All Users\Application Data\TEMP\AVG\miniavi.avg
c:\documents and settings\All Users\Application Data\TEMP\AVG\setup.exe
c:\documents and settings\All Users\Application Data\TEMP\AVG\setup.ini
c:\documents and settings\Bill\Start Menu\Programs\PlayMP3z
c:\documents and settings\Bill\Start Menu\Programs\PlayMP3z\Run PlayMP3z.pif
c:\program files\AdvancedBrowserShoppingTips
c:\program files\PlayMP3z
c:\program files\PlayMP3z\PlayMP3.exe
c:\program files\PlayMP3z\uninstall.exe
c:\windows\$NtUninstallKB35810$
c:\windows\$NtUninstallKB35810$\1378933202\@
c:\windows\$NtUninstallKB35810$\1378933202\cfg.ini
c:\windows\$NtUninstallKB35810$\1378933202\Desktop.ini
c:\windows\$NtUninstallKB35810$\1378933202\L\ternebbn
c:\windows\system32\Cache
c:\windows\system32\Cache\186d19cf7e0ce877.fb
c:\windows\system32\Cache\272512937d9e61a4.fb
c:\windows\system32\Cache\287204568329e189.fb
c:\windows\system32\Cache\28bc8f716fd76a47.fb
c:\windows\system32\Cache\2c53092c95605355.fb
c:\windows\system32\Cache\31a0997e9a5b5eb3.fb
c:\windows\system32\Cache\32c84fe32bb74d60.fb
c:\windows\system32\Cache\3917078cb68ec657.fb
c:\windows\system32\Cache\56d715584879f439.fb
c:\windows\system32\Cache\590ba23ce359fd0c.fb
c:\windows\system32\Cache\610289e025a3ee9a.fb
c:\windows\system32\Cache\651c5d3cdbfb8bd1.fb
c:\windows\system32\Cache\6c59ac5e7e7a3ad0.fb
c:\windows\system32\Cache\6d03dad1035885d3.fb
c:\windows\system32\Cache\760dde9be8f5d18e.fb
c:\windows\system32\Cache\9c8068dea46d2e51.fb
c:\windows\system32\Cache\a8556537add6dfc5.fb
c:\windows\system32\Cache\ad10a52aff5e038d.fb
c:\windows\system32\Cache\c1fa887b03019701.fb
c:\windows\system32\Cache\c4d28dca2e7648be.fb
c:\windows\system32\Cache\d201ef9910cd39de.fb
c:\windows\system32\Cache\d2e94710a5708128.fb
c:\windows\system32\Cache\d79b9dfe81484ec4.fb
c:\windows\system32\Cache\dd809aff28969ecc.fb
c:\windows\system32\Cache\e0de16f883bea794.fb
c:\windows\system32\Cache\f998975c9cc711ee.fb
c:\windows\system32\dds_trash_log.cmd
c:\windows\system32\dllcache\dlimport.exe
c:\windows\system32\dllcache\wmpvis.dll
c:\windows\system32\drivers\npf.sys
c:\windows\system32\Packet.dll
c:\windows\system32\SETC3.tmp
c:\windows\system32\SETC7.tmp
c:\windows\system32\SETCF.tmp
c:\windows\system32\wpcap.dll
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
——-\Legacy_NPF
——-\Service_NPF
——-\Legacy_NPF
.
.
((((((((((((((((((((((((( Files Created from 2012-07-27 to 2012-08-27 )))))))))))))))))))))))))))))))
.
.
2012-08-26 03:00 . 2012-08-26 03:10 ——– d—–w- c:\documents and settings\Administrator
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-07-21 17:47 . 2012-07-21 17:48 73728 —-a-w- c:\windows\system32\javacpl.cpl
2012-07-21 17:47 . 2012-07-21 17:48 476976 —-a-w- c:\windows\system32\npdeployJava1.dll
2012-07-21 17:47 . 2010-10-16 13:18 472880 —-a-w- c:\windows\system32\deployJava1.dll
2012-07-06 13:58 . 2003-07-16 16:19 78336 —-a-w- c:\windows\system32\browser.dll
2012-07-04 14:05 . 2009-02-04 22:00 139784 —-a-w- c:\windows\system32\drivers\rdpwd.sys
2012-07-03 13:40 . 2003-07-16 16:45 1866112 —-a-w- c:\windows\system32\win32k.sys
2012-07-02 17:49 . 2003-07-16 16:45 916992 —-a-w- c:\windows\system32\wininet.dll
2012-07-02 17:49 . 2003-07-16 16:26 43520 —-a-w- c:\windows\system32\licmgr10.dll
2012-07-02 17:49 . 2003-07-16 16:24 1469440 ——w- c:\windows\system32\inetcpl.cpl
2012-07-02 12:05 . 2004-08-04 05:59 385024 —-a-w- c:\windows\system32\html.iec
2012-06-05 15:50 . 2008-08-30 02:06 1372672 —-a-w- c:\windows\system32\msxml6.dll
2012-06-05 15:50 . 2003-07-16 16:31 1172480 —-a-w- c:\windows\system32\msxml3.dll
2012-06-04 04:32 . 2003-07-16 16:37 152576 —-a-w- c:\windows\system32\schannel.dll
2012-06-02 20:19 . 2009-02-05 00:10 22040 —-a-w- c:\windows\system32\wucltui.dll.mui
2012-06-02 20:19 . 2009-02-05 00:10 329240 —-a-w- c:\windows\system32\wucltui.dll
2012-06-02 20:19 . 2009-02-05 00:10 219160 —-a-w- c:\windows\system32\wuaucpl.cpl
2012-06-02 20:19 . 2009-02-05 00:10 15384 —-a-w- c:\windows\system32\wuaucpl.cpl.mui
2012-06-02 20:19 . 2008-10-16 20:12 210968 —-a-w- c:\windows\system32\wuweb.dll
2012-06-02 20:19 . 2009-02-05 00:10 45080 —-a-w- c:\windows\system32\wups2.dll
2012-06-02 20:19 . 2009-02-05 00:10 35864 —-a-w- c:\windows\system32\wups.dll
2012-06-02 20:19 . 2009-02-05 00:10 15384 —-a-w- c:\windows\system32\wuapi.dll.mui
2012-06-02 20:19 . 2009-02-04 22:00 53784 —-a-w- c:\windows\system32\wuauclt.exe
2012-06-02 20:19 . 2003-07-16 16:19 97304 —-a-w- c:\windows\system32\cdm.dll
2012-06-02 20:19 . 2009-02-05 00:10 17944 —-a-w- c:\windows\system32\wuaueng.dll.mui
2012-06-02 20:19 . 2009-02-05 00:10 577048 —-a-w- c:\windows\system32\wuapi.dll
2012-06-02 20:19 . 2009-02-04 22:00 1933848 —-a-w- c:\windows\system32\wuaueng.dll
2012-05-31 13:22 . 2003-03-20 22:18 599040 —-a-w- c:\windows\system32\crypt32.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{00000000-6E41-4FD3-8538-502F5495E5FC}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-03-28 1196936]
.
[HKEY_CLASSES_ROOT\clsid\{00000000-6e41-4fd3-8538-502f5495e5fc}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}]
2012-08-01 21:47 2074208 —-a-w- c:\program files\AVG Secure Search\11.1.0.12\AVG Secure Search_toolbar.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2010-03-28 17:11 1196936 —-a-w- c:\program files\Ask.com\GenericAskToolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-03-28 1196936]
"{95B7759C-8C7F-4BF1-B163-73684A933233}"= "c:\program files\AVG Secure Search\11.1.0.12\AVG Secure Search_toolbar.dll" [2012-08-01 2074208]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_CLASSES_ROOT\clsid\{95b7759c-8c7f-4bf1-b163-73684a933233}]
[HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj.1]
[HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-03-28 1196936]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-02-13 68856]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-07-07 344064]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2007-02-21 819200]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2007-02-21 970752]
"Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2007-05-14 1191936]
"Apoint"="c:\program files\Apoint\Apoint.exe" [2005-10-07 176128]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2011-10-06 59240]
"Microsoft Default Manager"="c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-02-03 233304]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-27 919008]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-21 59240]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2012-04-19 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2012-03-27 421736]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]
"AVG_TRAY"="c:\program files\AVG\AVG2012\avgtray.exe" [2012-04-05 2587008]
"vProt"="c:\program files\AVG Secure Search\vprot.exe" [2012-08-01 1107552]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 39264]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~1\AVG\AVG2012\avgrsx.exe /sync /restart
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgnsx.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgdiagex.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgmfapx.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgemcx.exe"=
.
R0 AVGIDSHX;AVGIDSHX;c:\windows\system32\drivers\avgidshx.sys [4/19/2012 4:50 AM 24896]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [1/31/2012 4:46 AM 31952]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2/22/2012 5:25 AM 235216]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [3/19/2012 5:17 AM 301248]
R2 AVGIDSAgent;AVGIDSAgent;c:\program files\AVG\AVG2012\avgidsagent.exe [7/4/2012 5:25 PM 5160568]
R2 avgwd;AVG WatchDog;c:\program files\AVG\AVG2012\avgwdsvc.exe [2/14/2012 4:53 AM 193288]
R2 vToolbarUpdater11.2.0;vToolbarUpdater11.2.0;c:\program files\Common Files\AVG Secure Search\vToolbarUpdater\11.2.0\ToolbarUpdater.exe [8/1/2012 4:47 PM 935008]
R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\avgidsdriverx.sys [12/23/2011 1:32 PM 139856]
R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\avgidsfilterx.sys [12/23/2011 1:32 PM 24144]
R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\avgidsshimx.sys [12/23/2011 1:32 PM 17232]
R3 GTIPCI21;GTIPCI21;c:\windows\system32\drivers\gtipci21.sys [2/4/2009 6:48 PM 88192]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2/3/2010 10:10 PM 135664]
S2 NEC Usb3;NEC USB3 Service;c:\windows\System32\svchost.exe -k NECUsb3s [7/16/2003 11:41 AM 14336]
S3 ATIXPGAA;ATIXPGAA;c:\dell\drivers\R101342\ATIXPGAA.SYS [2/4/2009 6:55 PM 12032]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2/3/2010 10:10 PM 135664]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
NECUsb3s REG_MULTI_SZ NEC Usb3
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
p1110vid
df5serv
pnrouter
firesvc
slssvc
viairda
ptbsync
DcLps
zBackupAssistService
a016bus
TPwSav
sfvfs02
rpaservice
nocashio
UimBus
sscdserd
SE2Bmdfl
vc5secs
vhidmini
ANC
StillCam
opcenum
FVXSCSI
ibmpmsvc
SE2Cmdm
SunkFilt
tga
.
Contents of the 'Scheduled Tasks' folder
.
2012-08-14 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 22:57]
.
2012-08-27 c:\windows\Tasks\AVG PC Tuneup Integrator Start On Bill Logon.job
- c:\program files\AVG\AVG PC Tuneup\BoostSpeed.exe [2012-04-14 22:20]
.
2012-08-27 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-04 03:10]
.
2012-08-26 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-04 03:10]
.
2012-08-26 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
- c:\program files\Ask.com\UpdateTask.exe [2010-03-28 17:11]
.
2012-08-27 c:\windows\Tasks\User_Feed_Synchronization-{7DB3CAAF-CC8A-4858-8CB9-DD39357FE1DB}.job
- c:\windows\system32\msfeedssync.exe [2007-08-14 09:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.centurylink.net/
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
TCP: DhcpNameServer = [removed] [removed]
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files\Common Files\AVG Secure Search\ViProtocolInstaller\11.2.0\ViProtocol.dll
.
- - - - ORPHANS REMOVED - - - -
.
WebBrowser-{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - (no file)
MSConfigStartUp-atmde - c:\docume~1\Bill\LOCALS~1\Temp\atmde.dll
MSConfigStartUp-cradwi - c:\docume~1\Bill\LOCALS~1\Temp\cradwi.dll
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-08-27 00:07
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,fd,2c,af,10,a9,24,f3,45,ba,d3,85,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,fd,2c,af,10,a9,24,f3,45,ba,d3,85,\
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(1056)
c:\windows\system32\Ati2evxx.dll
.
- - - - - - - > 'explorer.exe'(1168)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\progra~1\AVG\AVG2012\avgrsx.exe
c:\program files\AVG\AVG2012\avgcsrvx.exe
c:\windows\System32\Ati2evxx.exe
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\program files\Intel\Wireless\Bin\WLKeeper.exe
c:\windows\System32\SCardSvr.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\AVG\AVG2012\avgnsx.exe
c:\program files\AVG\AVG2012\avgemcx.exe
c:\program files\Dell\QuickSet\NICCONFIGSVC.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files\Apoint\HidFind.exe
c:\program files\Apoint\Apntex.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Intel\Wireless\Bin\Dot1XCfg.exe
.
**************************************************************************
.
Completion time: 2012-08-27 00:12:27 - machine was rebooted
ComboFix-quarantined-files.txt 2012-08-27 05:12
.
Pre-Run: 224,414,375,936 bytes free
Post-Run: 224,368,226,304 bytes free
.
- - End Of File - - 3071EFBA2DDD3B8620D0AC44ED0A8B58
Sorry. I forgot to warn you that Microsofts recovery console link is down.

Please download Farbar Service Scanner and run it on the computer with the issue.
  • Make sure "Include All Files" option remains checked.
  • Press "Scan".
  • It will create a log (FSS.txt) in the same directory the tool is run.
  • Please copy and paste the log to your reply.
Farbar Service Scanner Version: 06-08-2012 Ran by [removed] (administrator) on 27-08-2012 at 10:29:55 Running from "C:\Documents and Settings\Bill\Desktop" Microsoft Windows XP Professional Service Pack 3 (X86) Boot Mode: Normal **************************************************************** Internet Services: ============ Connection Status: ============== Localhost is accessible. LAN connected. Google IP is accessible. Google.com is accessible. Yahoo IP is accessible. Yahoo.com is accessible. Windows Firewall: ============= Firewall Disabled Policy: ================== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall"=DWORD:0 System Restore: ============ System Restore Disabled Policy: ======================== Security Center: ============ Windows Update: ============ Windows Autoupdate Disabled Policy: ============================ File Check: ======== C:\WINDOWS\system32\dhcpcsvc.dll => MD5 is legit C:\WINDOWS\system32\Drivers\afd.sys => MD5 is legit C:\WINDOWS\system32\Drivers\netbt.sys => MD5 is legit C:\WINDOWS\system32\Drivers\tcpip.sys => MD5 is legit C:\WINDOWS\system32\Drivers\ipsec.sys => MD5 is legit C:\WINDOWS\system32\dnsrslvr.dll => MD5 is legit C:\WINDOWS\system32\ipnathlp.dll => MD5 is legit C:\WINDOWS\system32\netman.dll => MD5 is legit C:\WINDOWS\system32\wbem\WMIsvc.dll => MD5 is legit C:\WINDOWS\system32\srsvc.dll => MD5 is legit C:\WINDOWS\system32\Drivers\sr.sys => MD5 is legit C:\WINDOWS\system32\wscsvc.dll => MD5 is legit C:\WINDOWS\system32\wbem\WMIsvc.dll => MD5 is legit C:\WINDOWS\system32\wuauserv.dll => MD5 is legit C:\WINDOWS\system32\qmgr.dll => MD5 is legit C:\WINDOWS\system32\es.dll => MD5 is legit C:\WINDOWS\system32\cryptsvc.dll => MD5 is legit C:\WINDOWS\system32\svchost.exe => MD5 is legit C:\WINDOWS\system32\rpcss.dll => MD5 is legit C:\WINDOWS\system32\services.exe => MD5 is legit Extra List: ======= AegisP(9) Avgtdix(11) Gpc(3) IPSec(5) NetBT(6) PSched(7) s24trans(8) Tcpip(4) 0x0B00000005000000010000000200000003000000040000000A0000000B00000006000000070000 000800000009000000 IpSec Tag value is correct. **** End of log ****
Good. Let's get an online scan. This will take hours probably.

Go here to run an online scanner from ESET.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activeX control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • When the scan completes, press the LIST OF THREATS FOUND button
  • Press EXPORT TO TEXT FILE , name the file ESETSCAN and save it to your desktop
  • Include the contents of this report in your next reply.
  • Press the BACK button.
  • Press Finish
Looks like the majority are in mp3's from Limewire. C:\Documents and Settings\Bill\Application Data\AVG\Rescue\PC Tuneup 2011\120414183929328.rsc multiple threats C:\Documents and Settings\Bill\Application Data\AVG\Rescue\PC Tuneup 2011\120506172257421.rsc multiple threats C:\Documents and Settings\Bill\Application Data\AVG\Rescue\PC Tuneup 2011\120721140315250.rsc multiple threats C:\Documents and Settings\Bill\My Documents\LimeWire\Saved\adult amateur wife voyeur sex euro teen camp celebrity sex tapes eve full sex film.mpe a variant of WMA/TrojanDownloader.GetCodec.gen trojan C:\Documents and Settings\Bill\My Documents\LimeWire\Saved\baptism of jesse taylor tanya - greatest hits.mp3 a variant of WMA/TrojanDownloader.GetCodec.gen trojan C:\Documents and Settings\Bill\My Documents\LimeWire\Saved\Clint Black - A good run of bad Luck.mp3 a variant of WMA/TrojanDownloader.GetCodec.gen trojan C:\Documents and Settings\Bill\My Documents\LimeWire\Saved\country - Conway Twitty - Hello Darlin.mp3 a variant of WMA/TrojanDownloader.GetCodec.gen trojan C:\Documents and Settings\Bill\My Documents\LimeWire\Saved\craig morgan - high quality.mp3 a variant of WMA/TrojanDownloader.GetCodec.gen trojan C:\Documents and Settings\Bill\My Documents\LimeWire\Saved\crime of passion [cd rip].mp3 a variant of WMA/TrojanDownloader.GetCodec.gen trojan C:\Documents and Settings\Bill\My Documents\LimeWire\Saved\david loggins [extended concert version].mp3 a variant of WMA/TrojanDownloader.GetCodec.gen trojan C:\Documents and Settings\Bill\My Documents\LimeWire\Saved\Dr. Hook and The Medicine Show - Sylvia's mother.mp3 a variant of WMA/TrojanDownloader.GetCodec.gen trojan C:\Documents and Settings\Bill\My Documents\LimeWire\Saved\Elvis Presley - Good time Charlie's Got The Blues - Undubbed (1973-12-13).mp3 a variant of WMA/TrojanDownloader.GetCodec.gen trojan C:\Documents and Settings\Bill\My Documents\LimeWire\Saved\good time charlie [cd rip].mp3 a variant of WMA/TrojanDownloader.GetCodec.gen trojan C:\Documents and Settings\Bill\My Documents\LimeWire\Saved\how could i love her so much - greatest hits.mp3 a variant of WMA/TrojanDownloader.GetCodec.gen trojan C:\Documents and Settings\Bill\My Documents\LimeWire\Saved\Hoyt Axton - Light this Candle.mp3 a variant of WMA/TrojanDownloader.GetCodec.gen trojan C:\Documents and Settings\Bill\My Documents\LimeWire\Saved\i love her john wayne - best track ever.mp3 a variant of WMA/TrojanDownloader.GetCodec.gen trojan C:\Documents and Settings\Bill\My Documents\LimeWire\Saved\jackie don tucker - greatest hits.mp3 a variant of WMA/TrojanDownloader.GetCodec.gen trojan C:\Documents and Settings\Bill\My Documents\LimeWire\Saved\jackie don tucker [cd rip].mp3 a variant of WMA/TrojanDownloader.GetCodec.gen trojan C:\Documents and Settings\Bill\My Documents\LimeWire\Saved\keep your hands to yourself - high quality.mp3 a variant of WMA/TrojanDownloader.GetCodec.gen trojan C:\Documents and Settings\Bill\My Documents\LimeWire\Saved\let it rock georgia satellites (256k 44800).mp3 a variant of WMA/TrojanDownloader.GetCodec.gen trojan C:\Documents and Settings\Bill\My Documents\LimeWire\Saved\Merle Haggard - Merle Haggard - Big city.mp3 a variant of WMA/TrojanDownloader.GetCodec.gen trojan C:\Documents and Settings\Bill\My Documents\LimeWire\Saved\rodeo or mexico garth brooks - greatest hits.mp3 a variant of WMA/TrojanDownloader.GetCodec.gen trojan C:\Documents and Settings\Bill\My Documents\LimeWire\Saved\seven bridges road alan george - high quality.mp3 a variant of WMA/TrojanDownloader.GetCodec.gen trojan C:\Documents and Settings\Bill\My Documents\LimeWire\Saved\Under this Old Hat - Chris LeDoux.mp3 a variant of WMA/TrojanDownloader.GetCodec.gen trojan C:\Documents and Settings\Bill\My Documents\LimeWire\Saved\watermelon crawl tim mcgraw.snd a variant of WMA/TrojanDownloader.GetCodec.gen trojan C:\Documents and Settings\Bill\My Documents\LimeWire\Saved\wolfman jack (256k 44800).mp3 a variant of WMA/TrojanDownloader.GetCodec.gen trojan C:\Qoobox\Quarantine\C\WINDOWS\system32\Drivers\cdrom.sys.vir Win32/Sirefef.DA trojan C:\System Volume Information\_restore{3568FDFF-3AE5-4BA7-BDD0-3C7E0DC116B4}\RP444\A0109318.sys Win32/Sirefef.DA trojan C:\System Volume Information\_restore{3568FDFF-3AE5-4BA7-BDD0-3C7E0DC116B4}\RP444\A0109359.sys Win32/Sirefef.DA trojan C:\System Volume Information\_restore{3568FDFF-3AE5-4BA7-BDD0-3C7E0DC116B4}\RP444\A0109375.sys Win32/Sirefef.DA trojan C:\System Volume Information\_restore{3568FDFF-3AE5-4BA7-BDD0-3C7E0DC116B4}\RP444\A0109395.sys Win32/Sirefef.DA trojan C:\System Volume Information\_restore{3568FDFF-3AE5-4BA7-BDD0-3C7E0DC116B4}\RP446\A0115675.sys Win32/Sirefef.DA trojan C:\System Volume Information\_restore{3568FDFF-3AE5-4BA7-BDD0-3C7E0DC116B4}\RP447\A0117720.sys Win32/Sirefef.DA trojan C:\System Volume Information\_restore{3568FDFF-3AE5-4BA7-BDD0-3C7E0DC116B4}\RP450\A0127808.sys Win32/Sirefef.DA trojan C:\System Volume Information\_restore{3568FDFF-3AE5-4BA7-BDD0-3C7E0DC116B4}\RP474\A0139126.sys Win32/Sirefef.DA trojan
Yep… porn and pirated programs are a guaranteed way to get infected. It's not a question of will you get infected… it's only how bad the infection is going to be.

COMBOFIX-Script

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    File::
    C:\Documents and Settings\Bill\My Documents\LimeWire\Saved\adult amateur wife voyeur sex euro teen camp celebrity sex tapes eve full sex film.mpe 
    C:\Documents and Settings\Bill\My Documents\LimeWire\Saved\baptism of jesse taylor tanya - greatest hits.mp3 
    C:\Documents and Settings\Bill\My Documents\LimeWire\Saved\Clint Black - A good run of bad Luck.mp3 
    C:\Documents and Settings\Bill\My Documents\LimeWire\Saved\country - Conway Twitty - Hello Darlin.mp3 
    C:\Documents and Settings\Bill\My Documents\LimeWire\Saved\craig morgan - high quality.mp3 
    C:\Documents and Settings\Bill\My Documents\LimeWire\Saved\crime of passion [cd rip].mp3 
    C:\Documents and Settings\Bill\My Documents\LimeWire\Saved\david loggins [extended concert version].mp3 
    C:\Documents and Settings\Bill\My Documents\LimeWire\Saved\Dr. Hook and The Medicine Show - Sylvia's mother.mp3 
    C:\Documents and Settings\Bill\My Documents\LimeWire\Saved\Elvis Presley - Good time Charlie's Got The Blues - Undubbed (1973-12-13).mp3 
    C:\Documents and Settings\Bill\My Documents\LimeWire\Saved\good time charlie [cd rip].mp3 
    C:\Documents and Settings\Bill\My Documents\LimeWire\Saved\how could i love her so much - greatest hits.mp3 
    C:\Documents and Settings\Bill\My Documents\LimeWire\Saved\Hoyt Axton - Light this Candle.mp3 
    C:\Documents and Settings\Bill\My Documents\LimeWire\Saved\i love her john wayne - best track ever.mp3 
    C:\Documents and Settings\Bill\My Documents\LimeWire\Saved\jackie don tucker - greatest hits.mp3 
    C:\Documents and Settings\Bill\My Documents\LimeWire\Saved\jackie don tucker [cd rip].mp3 
    C:\Documents and Settings\Bill\My Documents\LimeWire\Saved\keep your hands to yourself - high quality.mp3 
    C:\Documents and Settings\Bill\My Documents\LimeWire\Saved\let it rock georgia satellites (256k 44800).mp3 
    C:\Documents and Settings\Bill\My Documents\LimeWire\Saved\Merle Haggard - Merle Haggard - Big city.mp3 
    C:\Documents and Settings\Bill\My Documents\LimeWire\Saved\rodeo or mexico garth brooks - greatest hits.mp3 
    C:\Documents and Settings\Bill\My Documents\LimeWire\Saved\seven bridges road alan george - high quality.mp3 
    C:\Documents and Settings\Bill\My Documents\LimeWire\Saved\Under this Old Hat - Chris LeDoux.mp3 
    C:\Documents and Settings\Bill\My Documents\LimeWire\Saved\watermelon crawl tim mcgraw.snd 
    C:\Documents and Settings\Bill\My Documents\LimeWire\Saved\wolfman jack (256k 44800).mp3 
    C:\Documents and Settings\Bill\Application Data\AVG\Rescue\PC Tuneup 2011\120414183929328.rsc 
    C:\Documents and Settings\Bill\Application Data\AVG\Rescue\PC Tuneup 2011\120506172257421.rsc 
    C:\Documents and Settings\Bill\Application Data\AVG\Rescue\PC Tuneup 2011\120721140315250.rsc
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
ComboFix 12-08-25.04 - Bill 08/28/2012 2:03.3.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1023.423 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Bill\Desktop\CFScript.txt
AV: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
* Created a new restore point
.
FILE ::
"c:\documents and settings\Bill\Application Data\AVG\Rescue\PC Tuneup 2011\120414183929328.rsc"
"c:\documents and settings\Bill\Application Data\AVG\Rescue\PC Tuneup 2011\120506172257421.rsc"
"c:\documents and settings\Bill\Application Data\AVG\Rescue\PC Tuneup 2011\120721140315250.rsc"
"c:\documents and settings\Bill\My Documents\LimeWire\Saved\adult amateur wife voyeur sex euro teen camp celebrity sex tapes eve full sex film.mpe"
"c:\documents and settings\Bill\My Documents\LimeWire\Saved\baptism of jesse taylor tanya - greatest hits.mp3"
"c:\documents and settings\Bill\My Documents\LimeWire\Saved\Clint Black - A good run of bad Luck.mp3"
"c:\documents and settings\Bill\My Documents\LimeWire\Saved\country - Conway Twitty - Hello Darlin.mp3"
"c:\documents and settings\Bill\My Documents\LimeWire\Saved\craig morgan - high quality.mp3"
"c:\documents and settings\Bill\My Documents\LimeWire\Saved\crime of passion [cd rip].mp3"
"c:\documents and settings\Bill\My Documents\LimeWire\Saved\david loggins [extended concert version].mp3"
"c:\documents and settings\Bill\My Documents\LimeWire\Saved\Dr. Hook and The Medicine Show - Sylvia's mother.mp3"
"c:\documents and settings\Bill\My Documents\LimeWire\Saved\Elvis Presley - Good time Charlie's Got The Blues - Undubbed (1973-12-13).mp3"
"c:\documents and settings\Bill\My Documents\LimeWire\Saved\good time charlie [cd rip].mp3"
"c:\documents and settings\Bill\My Documents\LimeWire\Saved\how could i love her so much - greatest hits.mp3"
"c:\documents and settings\Bill\My Documents\LimeWire\Saved\Hoyt Axton - Light this Candle.mp3"
"c:\documents and settings\Bill\My Documents\LimeWire\Saved\i love her john wayne - best track ever.mp3"
"c:\documents and settings\Bill\My Documents\LimeWire\Saved\jackie don tucker - greatest hits.mp3"
"c:\documents and settings\Bill\My Documents\LimeWire\Saved\jackie don tucker [cd rip].mp3"
"c:\documents and settings\Bill\My Documents\LimeWire\Saved\keep your hands to yourself - high quality.mp3"
"c:\documents and settings\Bill\My Documents\LimeWire\Saved\let it rock georgia satellites (256k 44800).mp3"
"c:\documents and settings\Bill\My Documents\LimeWire\Saved\Merle Haggard - Merle Haggard - Big city.mp3"
"c:\documents and settings\Bill\My Documents\LimeWire\Saved\rodeo or mexico garth brooks - greatest hits.mp3"
"c:\documents and settings\Bill\My Documents\LimeWire\Saved\seven bridges road alan george - high quality.mp3"
"c:\documents and settings\Bill\My Documents\LimeWire\Saved\Under this Old Hat - Chris LeDoux.mp3"
"c:\documents and settings\Bill\My Documents\LimeWire\Saved\watermelon crawl tim mcgraw.snd"
"c:\documents and settings\Bill\My Documents\LimeWire\Saved\wolfman jack (256k 44800).mp3"
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Bill\Application Data\AVG\Rescue\PC Tuneup 2011\120414183929328.rsc
c:\documents and settings\Bill\Application Data\AVG\Rescue\PC Tuneup 2011\120506172257421.rsc
c:\documents and settings\Bill\Application Data\AVG\Rescue\PC Tuneup 2011\120721140315250.rsc
c:\documents and settings\Bill\My Documents\LimeWire\Saved\adult amateur wife voyeur sex euro teen camp celebrity sex tapes eve full sex film.mpe
c:\documents and settings\Bill\My Documents\LimeWire\Saved\baptism of jesse taylor tanya - greatest hits.mp3
c:\documents and settings\Bill\My Documents\LimeWire\Saved\Clint Black - A good run of bad Luck.mp3
c:\documents and settings\Bill\My Documents\LimeWire\Saved\country - Conway Twitty - Hello Darlin.mp3
c:\documents and settings\Bill\My Documents\LimeWire\Saved\craig morgan - high quality.mp3
c:\documents and settings\Bill\My Documents\LimeWire\Saved\crime of passion [cd rip].mp3
c:\documents and settings\Bill\My Documents\LimeWire\Saved\david loggins [extended concert version].mp3
c:\documents and settings\Bill\My Documents\LimeWire\Saved\Dr. Hook and The Medicine Show - Sylvia's mother.mp3
c:\documents and settings\Bill\My Documents\LimeWire\Saved\Elvis Presley - Good time Charlie's Got The Blues - Undubbed (1973-12-13).mp3
c:\documents and settings\Bill\My Documents\LimeWire\Saved\good time charlie [cd rip].mp3
c:\documents and settings\Bill\My Documents\LimeWire\Saved\how could i love her so much - greatest hits.mp3
c:\documents and settings\Bill\My Documents\LimeWire\Saved\Hoyt Axton - Light this Candle.mp3
c:\documents and settings\Bill\My Documents\LimeWire\Saved\i love her john wayne - best track ever.mp3
c:\documents and settings\Bill\My Documents\LimeWire\Saved\jackie don tucker - greatest hits.mp3
c:\documents and settings\Bill\My Documents\LimeWire\Saved\jackie don tucker [cd rip].mp3
c:\documents and settings\Bill\My Documents\LimeWire\Saved\keep your hands to yourself - high quality.mp3
c:\documents and settings\Bill\My Documents\LimeWire\Saved\let it rock georgia satellites (256k 44800).mp3
c:\documents and settings\Bill\My Documents\LimeWire\Saved\Merle Haggard - Merle Haggard - Big city.mp3
c:\documents and settings\Bill\My Documents\LimeWire\Saved\rodeo or mexico garth brooks - greatest hits.mp3
c:\documents and settings\Bill\My Documents\LimeWire\Saved\seven bridges road alan george - high quality.mp3
c:\documents and settings\Bill\My Documents\LimeWire\Saved\Under this Old Hat - Chris LeDoux.mp3
c:\documents and settings\Bill\My Documents\LimeWire\Saved\watermelon crawl tim mcgraw.snd
c:\documents and settings\Bill\My Documents\LimeWire\Saved\wolfman jack (256k 44800).mp3
.
.
((((((((((((((((((((((((( Files Created from 2012-07-28 to 2012-08-28 )))))))))))))))))))))))))))))))
.
.
2012-08-27 16:23 . 2012-08-27 16:23 ——– d—–w- c:\program files\ESET
2012-08-26 03:00 . 2012-08-26 03:10 ——– d—–w- c:\documents and settings\Administrator
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-07-21 17:47 . 2012-07-21 17:48 73728 —-a-w- c:\windows\system32\javacpl.cpl
2012-07-21 17:47 . 2012-07-21 17:48 476976 —-a-w- c:\windows\system32\npdeployJava1.dll
2012-07-21 17:47 . 2010-10-16 13:18 472880 —-a-w- c:\windows\system32\deployJava1.dll
2012-07-06 13:58 . 2003-07-16 16:19 78336 —-a-w- c:\windows\system32\browser.dll
2012-07-04 14:05 . 2009-02-04 22:00 139784 —-a-w- c:\windows\system32\drivers\rdpwd.sys
2012-07-03 13:40 . 2003-07-16 16:45 1866112 —-a-w- c:\windows\system32\win32k.sys
2012-07-02 17:49 . 2003-07-16 16:45 916992 —-a-w- c:\windows\system32\wininet.dll
2012-07-02 17:49 . 2003-07-16 16:26 43520 —-a-w- c:\windows\system32\licmgr10.dll
2012-07-02 17:49 . 2003-07-16 16:24 1469440 ——w- c:\windows\system32\inetcpl.cpl
2012-07-02 12:05 . 2004-08-04 05:59 385024 —-a-w- c:\windows\system32\html.iec
2012-06-05 15:50 . 2008-08-30 02:06 1372672 —-a-w- c:\windows\system32\msxml6.dll
2012-06-05 15:50 . 2003-07-16 16:31 1172480 —-a-w- c:\windows\system32\msxml3.dll
2012-06-04 04:32 . 2003-07-16 16:37 152576 —-a-w- c:\windows\system32\schannel.dll
2012-06-02 20:19 . 2009-02-05 00:10 22040 —-a-w- c:\windows\system32\wucltui.dll.mui
2012-06-02 20:19 . 2009-02-05 00:10 329240 —-a-w- c:\windows\system32\wucltui.dll
2012-06-02 20:19 . 2009-02-05 00:10 219160 —-a-w- c:\windows\system32\wuaucpl.cpl
2012-06-02 20:19 . 2009-02-05 00:10 15384 —-a-w- c:\windows\system32\wuaucpl.cpl.mui
2012-06-02 20:19 . 2008-10-16 20:12 210968 —-a-w- c:\windows\system32\wuweb.dll
2012-06-02 20:19 . 2009-02-05 00:10 45080 —-a-w- c:\windows\system32\wups2.dll
2012-06-02 20:19 . 2009-02-05 00:10 35864 —-a-w- c:\windows\system32\wups.dll
2012-06-02 20:19 . 2009-02-05 00:10 15384 —-a-w- c:\windows\system32\wuapi.dll.mui
2012-06-02 20:19 . 2009-02-04 22:00 53784 —-a-w- c:\windows\system32\wuauclt.exe
2012-06-02 20:19 . 2003-07-16 16:19 97304 —-a-w- c:\windows\system32\cdm.dll
2012-06-02 20:19 . 2009-02-05 00:10 17944 —-a-w- c:\windows\system32\wuaueng.dll.mui
2012-06-02 20:19 . 2009-02-05 00:10 577048 —-a-w- c:\windows\system32\wuapi.dll
2012-06-02 20:19 . 2009-02-04 22:00 1933848 —-a-w- c:\windows\system32\wuaueng.dll
2012-05-31 13:22 . 2003-03-20 22:18 599040 —-a-w- c:\windows\system32\crypt32.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2012-08-27_05.06.45 )))))))))))))))))))))))))))))))))))))))))
.
+ 2012-08-27 15:23 . 2012-08-27 15:23 16384 c:\windows\Temp\Perflib_Perfdata_844.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{00000000-6E41-4FD3-8538-502F5495E5FC}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-03-28 1196936]
.
[HKEY_CLASSES_ROOT\clsid\{00000000-6e41-4fd3-8538-502f5495e5fc}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}]
2012-08-01 21:47 2074208 —-a-w- c:\program files\AVG Secure Search\11.1.0.12\AVG Secure Search_toolbar.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2010-03-28 17:11 1196936 —-a-w- c:\program files\Ask.com\GenericAskToolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-03-28 1196936]
"{95B7759C-8C7F-4BF1-B163-73684A933233}"= "c:\program files\AVG Secure Search\11.1.0.12\AVG Secure Search_toolbar.dll" [2012-08-01 2074208]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_CLASSES_ROOT\clsid\{95b7759c-8c7f-4bf1-b163-73684a933233}]
[HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj.1]
[HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-03-28 1196936]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-02-13 68856]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-07-07 344064]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2007-02-21 819200]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2007-02-21 970752]
"Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2007-05-14 1191936]
"Apoint"="c:\program files\Apoint\Apoint.exe" [2005-10-07 176128]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2011-10-06 59240]
"Microsoft Default Manager"="c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-02-03 233304]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-07-27 919008]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-21 59240]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2012-04-19 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2012-03-27 421736]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]
"AVG_TRAY"="c:\program files\AVG\AVG2012\avgtray.exe" [2012-04-05 2587008]
"vProt"="c:\program files\AVG Secure Search\vprot.exe" [2012-08-01 1107552]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 39264]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~1\AVG\AVG2012\avgrsx.exe /sync /restart
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgnsx.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgdiagex.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgmfapx.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgemcx.exe"=
.
R0 AVGIDSHX;AVGIDSHX;c:\windows\system32\drivers\avgidshx.sys [4/19/2012 4:50 AM 24896]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [1/31/2012 4:46 AM 31952]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2/22/2012 5:25 AM 235216]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [3/19/2012 5:17 AM 301248]
R2 avgwd;AVG WatchDog;c:\program files\AVG\AVG2012\avgwdsvc.exe [2/14/2012 4:53 AM 193288]
R2 vToolbarUpdater11.2.0;vToolbarUpdater11.2.0;c:\program files\Common Files\AVG Secure Search\vToolbarUpdater\11.2.0\ToolbarUpdater.exe [8/1/2012 4:47 PM 935008]
R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\avgidsdriverx.sys [12/23/2011 1:32 PM 139856]
R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\avgidsfilterx.sys [12/23/2011 1:32 PM 24144]
R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\avgidsshimx.sys [12/23/2011 1:32 PM 17232]
R3 GTIPCI21;GTIPCI21;c:\windows\system32\drivers\gtipci21.sys [2/4/2009 6:48 PM 88192]
S2 AVGIDSAgent;AVGIDSAgent;c:\program files\AVG\AVG2012\avgidsagent.exe [7/4/2012 5:25 PM 5160568]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2/3/2010 10:10 PM 135664]
S2 NEC Usb3;NEC USB3 Service;c:\windows\System32\svchost.exe -k NECUsb3s [7/16/2003 11:41 AM 14336]
S3 ATIXPGAA;ATIXPGAA;c:\dell\drivers\R101342\ATIXPGAA.SYS [2/4/2009 6:55 PM 12032]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2/3/2010 10:10 PM 135664]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
NECUsb3s REG_MULTI_SZ NEC Usb3
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
p1110vid
df5serv
pnrouter
firesvc
slssvc
viairda
ptbsync
DcLps
zBackupAssistService
a016bus
TPwSav
sfvfs02
rpaservice
nocashio
UimBus
sscdserd
SE2Bmdfl
vc5secs
vhidmini
ANC
StillCam
opcenum
FVXSCSI
ibmpmsvc
SE2Cmdm
SunkFilt
tga
.
Contents of the 'Scheduled Tasks' folder
.
2012-08-14 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 22:57]
.
2012-08-27 c:\windows\Tasks\AVG PC Tuneup Integrator Start On Bill Logon.job
- c:\program files\AVG\AVG PC Tuneup\BoostSpeed.exe [2012-04-14 22:20]
.
2012-08-27 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-04 03:10]
.
2012-08-27 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-04 03:10]
.
2012-08-28 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
- c:\program files\Ask.com\UpdateTask.exe [2010-03-28 17:11]
.
2012-08-28 c:\windows\Tasks\User_Feed_Synchronization-{7DB3CAAF-CC8A-4858-8CB9-DD39357FE1DB}.job
- c:\windows\system32\msfeedssync.exe [2007-08-14 09:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.centurylink.net/
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
TCP: DhcpNameServer = [removed] [removed]
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files\Common Files\AVG Secure Search\ViProtocolInstaller\11.2.0\ViProtocol.dll
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-08-28 02:08
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,fd,2c,af,10,a9,24,f3,45,ba,d3,85,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,fd,2c,af,10,a9,24,f3,45,ba,d3,85,\
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(1048)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2012-08-28 02:09:44
ComboFix-quarantined-files.txt 2012-08-28 07:09
ComboFix2.txt 2012-08-27 05:12
.
Pre-Run: 224,184,991,744 bytes free
Post-Run: 224,176,181,248 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn
.
- - End Of File - - A95EF7FE559A52350CB7EA910309A336
I'd like you to run one more scan for me…

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot (shut down your computer then restart it).

Also please let me know of any issues that the computer is still having.
Malwarebytes Anti-Malware 1.62.0.1300 www.malwarebytes.org Database version: v2012.08.28.05 Windows XP Service Pack 3 x86 NTFS Internet Explorer 8.0.6001.18702 Bill :: BILLSLAPTOP [administrator] 8/28/2012 10:07:37 AM mbam-log-2012-08-28 (10-07-37).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 204156 Time elapsed: 5 minute(s), 13 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 1 HKCR\AppID\{418D86BE-7386-4F1A-83E0-53604ADBDA74} (Trojan.BHO) -> Quarantined and deleted successfully. Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end)
After the MalwareBytes post I disconnected the LAN cable and rebooted the laptop. Once booted I began using the internet with the wireless connection. All seems to be running correctly. Performance speed has increased back to where it was prior to the infections. It looks like you have everything working perfect. Thanks so much!!
I may have spoke too soon. Now when I open IE, it tries to load my homepage but appears to hang. In the task manager IE is utilizing 99% of the CPU. I'm not seeing this problem with any other program.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI