Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Virus? deadly slow computer


  • Please log in to reply

#1
Keman

Keman

    Member

  • Member
  • PipPip
  • 36 posts
well a few days ago, I think it was friday AVG blocked a file of some sort and quarentend it or whatever it does. Ever since then the computer has been deadly slow, (well it starts out ok but given a few mins it will begin to creep to the point I have been tring to get teh OTL file and get this posted most of the morning =\)


I'm sure a slow computer may not sound like much, but it becomes unusable to where you have to just restart it after a while and this all just started friday. Before hand it ran very fast and just fine. Any help is greatly appreciated and here are the OTL logs from the scan






OTL logfile created on: 9/6/2011 12:24:32 PM - Run 3
OTL by OldTimer - Version 3.2.27.0 Folder = C:\Documents and Settings\Dustin\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

894.48 Mb Total Physical Memory | 362.49 Mb Available Physical Memory | 40.53% Memory free
2.12 Gb Paging File | 1.67 Gb Available in Paging File | 78.78% Paging File free
Paging file location(s): C:\pagefile.sys 1344 2688 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS.1 | %ProgramFiles% = C:\Program Files
Drive C: | 144.74 Gb Total Space | 104.13 Gb Free Space | 71.94% Space Free | Partition Type: NTFS
Drive D: | 4.30 Gb Total Space | 1.49 Gb Free Space | 34.76% Space Free | Partition Type: FAT32
Drive Z: | 74.52 Gb Total Space | 51.03 Gb Free Space | 68.48% Space Free | Partition Type: NTFS

Computer Name: DUSTINS | User Name: Dustin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/09/06 11:17:55 | 000,581,120 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Dustin\Desktop\OTL.exe
PRC - [2011/04/18 17:40:08 | 002,334,560 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgtray.exe
PRC - [2011/04/18 17:39:42 | 007,398,752 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
PRC - [2011/04/14 05:36:42 | 001,080,672 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgnsx.exe
PRC - [2011/03/16 16:05:20 | 001,025,888 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgemcx.exe
PRC - [2011/03/16 16:05:14 | 000,656,736 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgchsvx.exe
PRC - [2011/02/10 07:55:18 | 001,148,256 | ---- | M] () -- C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSMonitor.exe
PRC - [2011/02/08 05:33:42 | 000,269,520 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgwdsvc.exe
PRC - [2011/02/08 05:33:20 | 000,658,784 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgrsx.exe
PRC - [2011/01/30 08:45:14 | 000,035,736 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Adobe\Reader 10.0\Reader\reader_sl.exe
PRC - [2008/11/09 13:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
PRC - [2007/06/13 03:23:07 | 001,033,216 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS.1\explorer.exe


========== Modules (No Company Name) ==========

MOD - [2011/02/10 07:55:18 | 001,148,256 | ---- | M] () -- C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSMonitor.exe
MOD - [2010/06/01 10:17:46 | 000,929,792 | ---- | M] () -- C:\Program Files\Yahoo!\Messenger\yui.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [Disabled | Stopped] -- -- (HidServ)
SRV - [2011/04/18 17:39:42 | 007,398,752 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe -- (AVGIDSAgent)
SRV - [2011/02/08 05:33:42 | 000,269,520 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG10\avgwdsvc.exe -- (avgwd)
SRV - [2010/02/19 13:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard)
SRV - [2008/11/09 13:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) [Auto | Running] -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe -- (YahooAUService)
SRV - [2008/04/13 17:12:11 | 000,006,656 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\system32\wuauserv.dll -- (wuauserv)


========== Driver Services (SafeList) ==========

DRV - [2011/07/06 19:52:42 | 000,041,272 | ---- | M] (Malwarebytes Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS.1\system32\drivers\mbamswissarmy.sys -- (MBAMSwissArmy)
DRV - [2011/04/14 21:28:42 | 000,134,480 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\WINDOWS.1\system32\drivers\AVGIDSDriver.sys -- (AVGIDSDriver)
DRV - [2011/04/05 00:59:56 | 000,297,168 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS.1\system32\drivers\avgtdix.sys -- (Avgtdix)
DRV - [2011/03/16 16:03:20 | 000,032,592 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\WINDOWS.1\system32\DRIVERS\avgrkx86.sys -- (Avgrkx86)
DRV - [2011/03/01 14:25:18 | 000,034,896 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\WINDOWS.1\system32\drivers\avgmfx86.sys -- (Avgmfx86)
DRV - [2011/02/22 08:13:02 | 000,022,992 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | Boot | Running] -- C:\WINDOWS.1\system32\DRIVERS\AVGIDSEH.Sys -- (AVGIDSEH)
DRV - [2011/02/10 07:53:54 | 000,027,216 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\WINDOWS.1\system32\drivers\AVGIDSShim.sys -- (AVGIDSShim)
DRV - [2011/02/10 07:53:52 | 000,024,144 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\WINDOWS.1\system32\drivers\AVGIDSFilter.sys -- (AVGIDSFilter)
DRV - [2011/01/07 06:41:46 | 000,248,656 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS.1\system32\drivers\avgldx86.sys -- (Avgldx86)
DRV - [2008/01/14 03:06:32 | 000,021,632 | ---- | M] (ManyCam LLC.) [Kernel | On_Demand | Running] -- C:\WINDOWS.1\system32\drivers\ManyCam.sys -- (ManyCam)
DRV - [2005/12/19 11:37:42 | 004,127,232 | R--- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS.1\system32\drivers\RtkHDAud.Sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2005/10/29 05:12:32 | 001,391,104 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS.1\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2004/04/13 16:14:12 | 000,070,144 | R--- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\WINDOWS.1\system32\drivers\Rtlnicxp.sys -- (RTL8023xp)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS.1\system32\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS.1\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS.1\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS.1\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\3.0.40818.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS.1\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@virtools.com/3DviaPlayer: C:\Program Files\Virtools\3D Life Player\npvirtools.dll (Dassault Systèmes)
FF - HKCU\Software\MozillaPlugins\@octoshape.com/Octoshape Streaming Services,version=1.0: C:\Documents and Settings\Dustin\Application Data\Octoshape\Octoshape Streaming Services\sua-1002170-0-npoctoshape.dll (Octoshape ApS)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG10\Firefox4\ [2011/08/09 09:32:49 | 000,000,000 | ---D | M]

[2009/04/09 09:24:53 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Dustin\Application Data\Mozilla\Extensions
[2009/04/09 09:24:53 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Dustin\Application Data\Mozilla\Extensions\[email protected]

O1 HOSTS File: ([2011/09/02 10:33:36 | 000,000,027 | ---- | M]) - C:\WINDOWS.1\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll (AVG Technologies CZ, s.r.o.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found.
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS5.5ServiceManager] File not found
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKCU..\Run: [Messenger (Yahoo!)] C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{1525843B-0C9C-4653-B128-A454543986FE}: DhcpNameServer = 192.168.1.254 192.168.1.254
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS.1\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS.1\system32\userinit.exe) - C:\WINDOWS.1\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS.1\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\Dustin\My Documents\My Pictures\Background\BG.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Dustin\My Documents\My Pictures\Background\BG.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/05/31 20:32:15 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgchsvx.exe /sync) - C:\Program Files\AVG\AVG10\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgrsx.exe /sync /restart) - C:\Program Files\AVG\AVG10\avgrsx.exe (AVG Technologies CZ, s.r.o.)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/09/06 11:17:55 | 000,581,120 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Dustin\Desktop\OTL.exe
[2011/09/06 10:27:06 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2011/09/06 10:26:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS.1\Start Menu\Programs\Miro
[2011/09/02 10:49:47 | 000,000,000 | -HSD | C] -- C:\RECYCLER(2)
[2011/08/25 10:02:22 | 000,000,000 | ---D | C] -- C:\WINDOWS.1\System32\appmgmt
[2011/08/18 10:14:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS.1\Application Data\regid.1986-12.com.adobe
[2011/08/18 10:01:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dustin\Application Data\PCF-VLC
[2011/08/18 08:48:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dustin\Application Data\gtk-2.0
[2011/08/17 11:35:00 | 000,000,000 | ---D | C] -- C:\Program Files\GetMiro Toolbar
[2011/08/17 11:34:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dustin\Application Data\Participatory Culture Foundation
[2011/08/17 11:33:56 | 000,000,000 | ---D | C] -- C:\Program Files\Participatory Culture Foundation
[2009/04/15 12:26:30 | 000,018,944 | ---- | C] ( ) -- C:\WINDOWS.1\System32\Implode.dll

========== Files - Modified Within 30 Days ==========

[2011/09/06 12:31:13 | 000,000,664 | ---- | M] () -- C:\WINDOWS.1\System32\d3d9caps.dat
[2011/09/06 12:24:05 | 000,002,206 | ---- | M] () -- C:\WINDOWS.1\System32\wpa.dbl
[2011/09/06 12:23:22 | 000,002,048 | --S- | M] () -- C:\WINDOWS.1\bootstat.dat
[2011/09/06 11:17:55 | 000,581,120 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Dustin\Desktop\OTL.exe
[2011/09/06 09:14:14 | 131,240,018 | ---- | M] () -- C:\WINDOWS.1\System32\drivers\AVG\incavi.avm
[2011/09/02 10:33:36 | 000,000,027 | ---- | M] () -- C:\WINDOWS.1\System32\drivers\etc\hosts
[2011/08/30 11:57:03 | 000,000,132 | ---- | M] () -- C:\Documents and Settings\Dustin\Application Data\Adobe PNG Format CS5 Prefs
[2011/08/25 11:11:01 | 000,000,344 | ---- | M] () -- C:\WINDOWS.1\tasks\AdobeAAMUpdater-1.0-DUSTINS-Dustin.job
[2011/08/25 10:30:44 | 000,055,808 | ---- | M] () -- C:\Documents and Settings\Dustin\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/08/25 09:53:40 | 000,000,288 | ---- | M] () -- C:\Documents and Settings\Dustin\Application Data\.backup.dm
[2011/08/19 08:33:55 | 003,513,816 | ---- | M] () -- C:\WINDOWS.1\System32\FNTCACHE.DAT
[2011/08/18 10:01:28 | 000,000,218 | ---- | M] () -- C:\Documents and Settings\Dustin\.recently-used.xbel

========== Files Created - No Company Name ==========

[2011/08/30 11:55:54 | 000,000,132 | ---- | C] () -- C:\Documents and Settings\Dustin\Application Data\Adobe PNG Format CS5 Prefs
[2011/08/25 11:11:01 | 000,000,344 | ---- | C] () -- C:\WINDOWS.1\tasks\AdobeAAMUpdater-1.0-DUSTINS-Dustin.job
[2011/08/25 09:51:58 | 000,000,288 | ---- | C] () -- C:\Documents and Settings\Dustin\Application Data\.backup.dm
[2011/08/18 10:08:46 | 000,000,870 | ---- | C] () -- C:\Documents and Settings\All Users.WINDOWS.1\Start Menu\Programs\Adobe Photoshop CS5.1.lnk
[2011/08/18 10:07:11 | 000,000,832 | ---- | C] () -- C:\Documents and Settings\All Users.WINDOWS.1\Start Menu\Programs\Adobe Bridge CS5.1.lnk
[2011/08/18 10:06:43 | 000,000,925 | ---- | C] () -- C:\Documents and Settings\All Users.WINDOWS.1\Start Menu\Programs\Adobe Device Central CS5.5.lnk
[2011/08/18 10:05:27 | 000,001,026 | ---- | C] () -- C:\Documents and Settings\All Users.WINDOWS.1\Start Menu\Programs\Adobe Extension Manager CS5.5.lnk
[2011/08/18 10:05:17 | 000,001,176 | ---- | C] () -- C:\Documents and Settings\All Users.WINDOWS.1\Start Menu\Programs\Adobe ExtendScript Toolkit CS5.5.lnk
[2011/08/18 10:04:36 | 000,000,728 | ---- | C] () -- C:\Documents and Settings\All Users.WINDOWS.1\Start Menu\Programs\Adobe Help.lnk
[2011/08/18 10:01:28 | 000,000,218 | ---- | C] () -- C:\Documents and Settings\Dustin\.recently-used.xbel
[2011/07/28 13:40:10 | 000,256,000 | ---- | C] () -- C:\WINDOWS.1\PEV.exe
[2011/07/28 13:40:10 | 000,208,896 | ---- | C] () -- C:\WINDOWS.1\MBR.exe
[2011/07/28 13:40:10 | 000,098,816 | ---- | C] () -- C:\WINDOWS.1\sed.exe
[2011/07/28 13:40:10 | 000,080,412 | ---- | C] () -- C:\WINDOWS.1\grep.exe
[2011/07/28 13:40:10 | 000,068,096 | ---- | C] () -- C:\WINDOWS.1\zip.exe
[2011/06/17 17:26:17 | 000,003,416 | ---- | C] () -- C:\Documents and Settings\Dustin\Application Data\StuntCrazy_thePodge_so_tgi.sol
[2011/06/17 17:26:17 | 000,000,040 | ---- | C] () -- C:\Documents and Settings\Dustin\Application Data\swfstats.sol
[2011/02/04 16:51:36 | 000,000,664 | ---- | C] () -- C:\WINDOWS.1\System32\d3d9caps.dat
[2011/01/21 12:20:42 | 000,000,056 | -H-- | C] () -- C:\WINDOWS.1\System32\ezsidmv.dat
[2010/01/13 12:02:26 | 000,000,277 | ---- | C] () -- C:\WINDOWS.1\System32\MRT.INI
[2009/11/24 09:31:05 | 000,000,000 | ---- | C] () -- C:\WINDOWS.1\USERSWAP.INI
[2009/11/24 09:16:05 | 000,032,768 | ---- | C] () -- C:\WINDOWS.1\System32\Hlinkprx.dll
[2009/07/19 13:49:10 | 000,000,256 | ---- | C] () -- C:\WINDOWS.1\System32\pool.bin
[2009/04/15 12:27:54 | 000,011,776 | ---- | C] () -- C:\WINDOWS.1\System32\Proph32.dll
[2009/04/15 12:27:45 | 000,077,824 | ---- | C] () -- C:\WINDOWS.1\System32\ProphSMTP.dll
[2009/04/15 12:27:11 | 000,001,292 | ---- | C] () -- C:\WINDOWS.1\ODBC.INI
[2009/04/15 12:26:32 | 000,000,661 | ---- | C] () -- C:\WINDOWS.1\Proph2.ini
[2009/04/15 12:26:29 | 000,748,160 | ---- | C] () -- C:\WINDOWS.1\System32\co2c40en.dll
[2009/04/15 12:26:29 | 000,153,761 | ---- | C] () -- C:\WINDOWS.1\System32\u2frtf.dll
[2009/04/15 12:26:29 | 000,124,256 | ---- | C] () -- C:\WINDOWS.1\System32\u2dmapi.dll
[2009/04/15 12:26:29 | 000,109,568 | ---- | C] () -- C:\WINDOWS.1\System32\u2fhtml.dll
[2009/04/15 12:26:29 | 000,097,489 | ---- | C] () -- C:\WINDOWS.1\System32\u2fcr.dll
[2009/04/15 12:26:29 | 000,069,632 | ---- | C] () -- C:\WINDOWS.1\System32\u2fxls.dll
[2009/04/15 12:26:29 | 000,069,632 | ---- | C] () -- C:\WINDOWS.1\System32\u2fwordw.dll
[2009/04/15 12:26:29 | 000,054,272 | ---- | C] () -- C:\WINDOWS.1\System32\p2irdao.dll
[2009/04/15 12:26:29 | 000,053,248 | ---- | C] () -- C:\WINDOWS.1\System32\u2fwks.dll
[2009/04/15 12:26:29 | 000,053,248 | ---- | C] () -- C:\WINDOWS.1\System32\u2ftext.dll
[2009/04/15 12:26:29 | 000,053,248 | ---- | C] () -- C:\WINDOWS.1\System32\u2fsepv.dll
[2009/04/15 12:26:29 | 000,050,176 | ---- | C] () -- C:\WINDOWS.1\System32\p2ctdao.dll
[2009/04/15 12:26:29 | 000,049,152 | ---- | C] () -- C:\WINDOWS.1\System32\u2frec.dll
[2009/04/15 12:26:29 | 000,049,152 | ---- | C] () -- C:\WINDOWS.1\System32\u2fdif.dll
[2009/04/15 12:26:29 | 000,045,056 | ---- | C] () -- C:\WINDOWS.1\System32\u2ddisk.dll
[2009/04/15 12:26:29 | 000,036,352 | ---- | C] () -- C:\WINDOWS.1\System32\p2bbnd.dll
[2009/04/08 16:46:08 | 000,110,293 | R--- | C] () -- C:\WINDOWS.1\System32\atiicdxx.dat
[2009/04/08 16:45:20 | 000,135,168 | R--- | C] () -- C:\WINDOWS.1\System32\RtlCPAPI.dll
[2009/04/08 16:45:20 | 000,040,960 | ---- | C] () -- C:\WINDOWS.1\System32\ChCfg.exe
[2009/04/07 18:06:48 | 000,055,808 | ---- | C] () -- C:\Documents and Settings\Dustin\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/04/03 16:04:18 | 000,000,335 | ---- | C] () -- C:\WINDOWS.1\TRPMAKER.INI
[2009/04/01 15:29:31 | 000,002,048 | --S- | C] () -- C:\WINDOWS.1\bootstat.dat
[2009/04/01 15:22:58 | 000,021,640 | ---- | C] () -- C:\WINDOWS.1\System32\emptyregdb.dat
[2009/04/01 07:16:44 | 000,004,249 | ---- | C] () -- C:\WINDOWS.1\ODBCINST.INI
[2009/04/01 06:45:12 | 003,513,816 | ---- | C] () -- C:\WINDOWS.1\System32\FNTCACHE.DAT
[2004/08/03 22:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS.1\System32\mlang.dat
[2004/08/03 22:00:00 | 000,432,686 | ---- | C] () -- C:\WINDOWS.1\System32\perfh009.dat
[2004/08/03 22:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS.1\System32\perfi009.dat
[2004/08/03 22:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS.1\System32\dssec.dat
[2004/08/03 22:00:00 | 000,067,516 | ---- | C] () -- C:\WINDOWS.1\System32\perfc009.dat
[2004/08/03 22:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS.1\System32\mib.bin
[2004/08/03 22:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS.1\System32\perfd009.dat
[2004/08/03 22:00:00 | 000,004,569 | ---- | C] () -- C:\WINDOWS.1\System32\secupd.dat
[2004/08/03 22:00:00 | 000,001,788 | ---- | C] () -- C:\WINDOWS.1\System32\Dcache.bin
[2004/08/03 22:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS.1\System32\noise.dat
[2004/07/29 15:49:10 | 013,107,200 | ---- | C] () -- C:\WINDOWS.1\System32\oembios.bin
[2004/07/29 15:48:26 | 000,005,151 | ---- | C] () -- C:\WINDOWS.1\System32\oembios.dat
[2003/01/07 15:05:08 | 000,002,695 | ---- | C] () -- C:\WINDOWS.1\System32\OUTLPERF.INI

< End of report >
  • 0

Advertisements


#2
RKinner

RKinner

    Malware Expert

  • Expert
  • 20,031 posts
  • MVP
Malwarebytes' Anti-Malware
:!: If you have a previous version of MalwareBytes', remove it via Add or Remove Programs and download a fresh copy. :!:

http://www.malwarebytes.org/mbam.php

SAVE Malwarebytes' Anti-Malware to your desktop.

* Double-click mbam-setup.exe and follow the prompts to install the program.
* At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
* If an update is found, it will download and install the latest version.
* Once the program has loaded, select Perform quick scan, then click Scan.
* When the scan is complete, click OK, then Show Results to view the results.

* Be sure that everything is checked, and click Remove Selected.

* When completed, a log will open in Notepad. Please save it to a convenient location.
* The log can also be found here:
C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt
* Post that log back here.



ComboFix
:!: If you have a previous version of Combofix.exe, delete it and download a fresh copy. :!:

:!: It must be saved to your desktop, do not run it :!:

:!: Disable your Antivirus software when downloading or running Combofix. If it has Script Blocking features, please disable these as well. See: http://www.bleepingc...opic114351.html


Download and Save this file -- to your Desktop -- from either of these two sources:
http://download.blee...Bs/ComboFix.exe
http://subs.geekstogo.com/ComboFix.exe

Doubleclick on ComboFix to start the program.



* :!: Important: Have no other programs running. Your Task Bar should be clear of any program entries including your Browser.


* A window may open with a series of Disclaimers. Accept the Disclaimers to start the fix. Allow it to install the Recovery Console then Continue. When the scan completes Notepad will open with with your results log open. Do a File, Exit and answer 'Yes' to save changes.


A caution - Do not run Combofix more than once. Do not touch your mouse/keyboard until the scan has completed, as this may cause the process to stall or your computer to lock. The scan will temporarily disable your desktop, and if interrupted may leave your desktop disabled. If this occurs, please reboot to restore the desktop. Even when ComboFix appears to be doing nothing, look at your Drive light. If it is flashing, Combofix is still at work.

A file will be created at => C:\Combofix.txt. I'll need to see that in your reply.

Download TDSSKiller:
http://support.kaspe.../tdsskiller.exe
Save it to your desktop then run it.
Double click on TDSSKiller.exe
If TDSSKiller alerts you that the system needs to reboot, please consent.
When done, a log file should be created on your C: drive named "TDSSKiller.txt" please copy and paste the contents in your next reply.

Download aswMBR.exe ( 511KB ) to your desktop.

Double click the aswMBR.exe to run it

change the a-v scan to None.
uncheck trace disk IO calls
Click the "Scan" button to start scan


On completion of the scan (Note if the Fix button is enabled (Not the FixMBR button) and tell me) click save log, save it to your desktop and post in your next reply

Get Process Explorer

http://live.sysinter...com/procexp.exe

Save it to your desktop then run it (Vista or Win7 - right click and Run As Administrator). Click once or twice on the CPU column header to sort things by CPU usage with the big hitters at the top. Wait qa minute for things to settle down then File, Save As, Save. Open the file Procexp.txt on your desktop and copy and paste the text to a reply.


Ron
  • 0

#3
Keman

Keman

    Member

  • Topic Starter
  • Member
  • PipPip
  • 36 posts
ok first off sorry for the slow reply, this a work comp so I only have access to it mon-fri till 5"ish" and it took forever to get all those logs with the computer running as it was, but after doing all that it does seem to be running better so thats good. here are the logs you ask for.

OTL

OTL logfile created on: 9/6/2011 12:24:32 PM - Run 3
OTL by OldTimer - Version 3.2.27.0 Folder = C:\Documents and Settings\Dustin\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

894.48 Mb Total Physical Memory | 362.49 Mb Available Physical Memory | 40.53% Memory free
2.12 Gb Paging File | 1.67 Gb Available in Paging File | 78.78% Paging File free
Paging file location(s): C:\pagefile.sys 1344 2688 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS.1 | %ProgramFiles% = C:\Program Files
Drive C: | 144.74 Gb Total Space | 104.13 Gb Free Space | 71.94% Space Free | Partition Type: NTFS
Drive D: | 4.30 Gb Total Space | 1.49 Gb Free Space | 34.76% Space Free | Partition Type: FAT32
Drive Z: | 74.52 Gb Total Space | 51.03 Gb Free Space | 68.48% Space Free | Partition Type: NTFS

Computer Name: DUSTINS | User Name: Dustin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/09/06 11:17:55 | 000,581,120 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Dustin\Desktop\OTL.exe
PRC - [2011/04/18 17:40:08 | 002,334,560 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgtray.exe
PRC - [2011/04/18 17:39:42 | 007,398,752 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
PRC - [2011/04/14 05:36:42 | 001,080,672 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgnsx.exe
PRC - [2011/03/16 16:05:20 | 001,025,888 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgemcx.exe
PRC - [2011/03/16 16:05:14 | 000,656,736 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgchsvx.exe
PRC - [2011/02/10 07:55:18 | 001,148,256 | ---- | M] () -- C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSMonitor.exe
PRC - [2011/02/08 05:33:42 | 000,269,520 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgwdsvc.exe
PRC - [2011/02/08 05:33:20 | 000,658,784 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgrsx.exe
PRC - [2011/01/30 08:45:14 | 000,035,736 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Adobe\Reader 10.0\Reader\reader_sl.exe
PRC - [2008/11/09 13:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
PRC - [2007/06/13 03:23:07 | 001,033,216 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS.1\explorer.exe


========== Modules (No Company Name) ==========

MOD - [2011/02/10 07:55:18 | 001,148,256 | ---- | M] () -- C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSMonitor.exe
MOD - [2010/06/01 10:17:46 | 000,929,792 | ---- | M] () -- C:\Program Files\Yahoo!\Messenger\yui.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [Disabled | Stopped] -- -- (HidServ)
SRV - [2011/04/18 17:39:42 | 007,398,752 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe -- (AVGIDSAgent)
SRV - [2011/02/08 05:33:42 | 000,269,520 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG10\avgwdsvc.exe -- (avgwd)
SRV - [2010/02/19 13:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard)
SRV - [2008/11/09 13:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) [Auto | Running] -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe -- (YahooAUService)
SRV - [2008/04/13 17:12:11 | 000,006,656 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\system32\wuauserv.dll -- (wuauserv)


========== Driver Services (SafeList) ==========

DRV - [2011/07/06 19:52:42 | 000,041,272 | ---- | M] (Malwarebytes Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS.1\system32\drivers\mbamswissarmy.sys -- (MBAMSwissArmy)
DRV - [2011/04/14 21:28:42 | 000,134,480 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\WINDOWS.1\system32\drivers\AVGIDSDriver.sys -- (AVGIDSDriver)
DRV - [2011/04/05 00:59:56 | 000,297,168 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS.1\system32\drivers\avgtdix.sys -- (Avgtdix)
DRV - [2011/03/16 16:03:20 | 000,032,592 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\WINDOWS.1\system32\DRIVERS\avgrkx86.sys -- (Avgrkx86)
DRV - [2011/03/01 14:25:18 | 000,034,896 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\WINDOWS.1\system32\drivers\avgmfx86.sys -- (Avgmfx86)
DRV - [2011/02/22 08:13:02 | 000,022,992 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | Boot | Running] -- C:\WINDOWS.1\system32\DRIVERS\AVGIDSEH.Sys -- (AVGIDSEH)
DRV - [2011/02/10 07:53:54 | 000,027,216 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\WINDOWS.1\system32\drivers\AVGIDSShim.sys -- (AVGIDSShim)
DRV - [2011/02/10 07:53:52 | 000,024,144 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\WINDOWS.1\system32\drivers\AVGIDSFilter.sys -- (AVGIDSFilter)
DRV - [2011/01/07 06:41:46 | 000,248,656 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS.1\system32\drivers\avgldx86.sys -- (Avgldx86)
DRV - [2008/01/14 03:06:32 | 000,021,632 | ---- | M] (ManyCam LLC.) [Kernel | On_Demand | Running] -- C:\WINDOWS.1\system32\drivers\ManyCam.sys -- (ManyCam)
DRV - [2005/12/19 11:37:42 | 004,127,232 | R--- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS.1\system32\drivers\RtkHDAud.Sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2005/10/29 05:12:32 | 001,391,104 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS.1\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2004/04/13 16:14:12 | 000,070,144 | R--- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\WINDOWS.1\system32\drivers\Rtlnicxp.sys -- (RTL8023xp)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS.1\system32\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS.1\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS.1\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS.1\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\3.0.40818.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS.1\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@virtools.com/3DviaPlayer: C:\Program Files\Virtools\3D Life Player\npvirtools.dll (Dassault Systèmes)
FF - HKCU\Software\MozillaPlugins\@octoshape.com/Octoshape Streaming Services,version=1.0: C:\Documents and Settings\Dustin\Application Data\Octoshape\Octoshape Streaming Services\sua-1002170-0-npoctoshape.dll (Octoshape ApS)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG10\Firefox4\ [2011/08/09 09:32:49 | 000,000,000 | ---D | M]

[2009/04/09 09:24:53 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Dustin\Application Data\Mozilla\Extensions
[2009/04/09 09:24:53 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Dustin\Application Data\Mozilla\Extensions\[email protected]

O1 HOSTS File: ([2011/09/02 10:33:36 | 000,000,027 | ---- | M]) - C:\WINDOWS.1\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll (AVG Technologies CZ, s.r.o.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found.
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS5.5ServiceManager] File not found
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKCU..\Run: [Messenger (Yahoo!)] C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{1525843B-0C9C-4653-B128-A454543986FE}: DhcpNameServer = 192.168.1.254 192.168.1.254
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS.1\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS.1\system32\userinit.exe) - C:\WINDOWS.1\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS.1\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\Dustin\My Documents\My Pictures\Background\BG.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Dustin\My Documents\My Pictures\Background\BG.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/05/31 20:32:15 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgchsvx.exe /sync) - C:\Program Files\AVG\AVG10\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgrsx.exe /sync /restart) - C:\Program Files\AVG\AVG10\avgrsx.exe (AVG Technologies CZ, s.r.o.)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/09/06 11:17:55 | 000,581,120 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Dustin\Desktop\OTL.exe
[2011/09/06 10:27:06 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2011/09/06 10:26:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS.1\Start Menu\Programs\Miro
[2011/09/02 10:49:47 | 000,000,000 | -HSD | C] -- C:\RECYCLER(2)
[2011/08/25 10:02:22 | 000,000,000 | ---D | C] -- C:\WINDOWS.1\System32\appmgmt
[2011/08/18 10:14:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS.1\Application Data\regid.1986-12.com.adobe
[2011/08/18 10:01:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dustin\Application Data\PCF-VLC
[2011/08/18 08:48:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dustin\Application Data\gtk-2.0
[2011/08/17 11:35:00 | 000,000,000 | ---D | C] -- C:\Program Files\GetMiro Toolbar
[2011/08/17 11:34:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dustin\Application Data\Participatory Culture Foundation
[2011/08/17 11:33:56 | 000,000,000 | ---D | C] -- C:\Program Files\Participatory Culture Foundation
[2009/04/15 12:26:30 | 000,018,944 | ---- | C] ( ) -- C:\WINDOWS.1\System32\Implode.dll

========== Files - Modified Within 30 Days ==========

[2011/09/06 12:31:13 | 000,000,664 | ---- | M] () -- C:\WINDOWS.1\System32\d3d9caps.dat
[2011/09/06 12:24:05 | 000,002,206 | ---- | M] () -- C:\WINDOWS.1\System32\wpa.dbl
[2011/09/06 12:23:22 | 000,002,048 | --S- | M] () -- C:\WINDOWS.1\bootstat.dat
[2011/09/06 11:17:55 | 000,581,120 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Dustin\Desktop\OTL.exe
[2011/09/06 09:14:14 | 131,240,018 | ---- | M] () -- C:\WINDOWS.1\System32\drivers\AVG\incavi.avm
[2011/09/02 10:33:36 | 000,000,027 | ---- | M] () -- C:\WINDOWS.1\System32\drivers\etc\hosts
[2011/08/30 11:57:03 | 000,000,132 | ---- | M] () -- C:\Documents and Settings\Dustin\Application Data\Adobe PNG Format CS5 Prefs
[2011/08/25 11:11:01 | 000,000,344 | ---- | M] () -- C:\WINDOWS.1\tasks\AdobeAAMUpdater-1.0-DUSTINS-Dustin.job
[2011/08/25 10:30:44 | 000,055,808 | ---- | M] () -- C:\Documents and Settings\Dustin\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/08/25 09:53:40 | 000,000,288 | ---- | M] () -- C:\Documents and Settings\Dustin\Application Data\.backup.dm
[2011/08/19 08:33:55 | 003,513,816 | ---- | M] () -- C:\WINDOWS.1\System32\FNTCACHE.DAT
[2011/08/18 10:01:28 | 000,000,218 | ---- | M] () -- C:\Documents and Settings\Dustin\.recently-used.xbel

========== Files Created - No Company Name ==========

[2011/08/30 11:55:54 | 000,000,132 | ---- | C] () -- C:\Documents and Settings\Dustin\Application Data\Adobe PNG Format CS5 Prefs
[2011/08/25 11:11:01 | 000,000,344 | ---- | C] () -- C:\WINDOWS.1\tasks\AdobeAAMUpdater-1.0-DUSTINS-Dustin.job
[2011/08/25 09:51:58 | 000,000,288 | ---- | C] () -- C:\Documents and Settings\Dustin\Application Data\.backup.dm
[2011/08/18 10:08:46 | 000,000,870 | ---- | C] () -- C:\Documents and Settings\All Users.WINDOWS.1\Start Menu\Programs\Adobe Photoshop CS5.1.lnk
[2011/08/18 10:07:11 | 000,000,832 | ---- | C] () -- C:\Documents and Settings\All Users.WINDOWS.1\Start Menu\Programs\Adobe Bridge CS5.1.lnk
[2011/08/18 10:06:43 | 000,000,925 | ---- | C] () -- C:\Documents and Settings\All Users.WINDOWS.1\Start Menu\Programs\Adobe Device Central CS5.5.lnk
[2011/08/18 10:05:27 | 000,001,026 | ---- | C] () -- C:\Documents and Settings\All Users.WINDOWS.1\Start Menu\Programs\Adobe Extension Manager CS5.5.lnk
[2011/08/18 10:05:17 | 000,001,176 | ---- | C] () -- C:\Documents and Settings\All Users.WINDOWS.1\Start Menu\Programs\Adobe ExtendScript Toolkit CS5.5.lnk
[2011/08/18 10:04:36 | 000,000,728 | ---- | C] () -- C:\Documents and Settings\All Users.WINDOWS.1\Start Menu\Programs\Adobe Help.lnk
[2011/08/18 10:01:28 | 000,000,218 | ---- | C] () -- C:\Documents and Settings\Dustin\.recently-used.xbel
[2011/07/28 13:40:10 | 000,256,000 | ---- | C] () -- C:\WINDOWS.1\PEV.exe
[2011/07/28 13:40:10 | 000,208,896 | ---- | C] () -- C:\WINDOWS.1\MBR.exe
[2011/07/28 13:40:10 | 000,098,816 | ---- | C] () -- C:\WINDOWS.1\sed.exe
[2011/07/28 13:40:10 | 000,080,412 | ---- | C] () -- C:\WINDOWS.1\grep.exe
[2011/07/28 13:40:10 | 000,068,096 | ---- | C] () -- C:\WINDOWS.1\zip.exe
[2011/06/17 17:26:17 | 000,003,416 | ---- | C] () -- C:\Documents and Settings\Dustin\Application Data\StuntCrazy_thePodge_so_tgi.sol
[2011/06/17 17:26:17 | 000,000,040 | ---- | C] () -- C:\Documents and Settings\Dustin\Application Data\swfstats.sol
[2011/02/04 16:51:36 | 000,000,664 | ---- | C] () -- C:\WINDOWS.1\System32\d3d9caps.dat
[2011/01/21 12:20:42 | 000,000,056 | -H-- | C] () -- C:\WINDOWS.1\System32\ezsidmv.dat
[2010/01/13 12:02:26 | 000,000,277 | ---- | C] () -- C:\WINDOWS.1\System32\MRT.INI
[2009/11/24 09:31:05 | 000,000,000 | ---- | C] () -- C:\WINDOWS.1\USERSWAP.INI
[2009/11/24 09:16:05 | 000,032,768 | ---- | C] () -- C:\WINDOWS.1\System32\Hlinkprx.dll
[2009/07/19 13:49:10 | 000,000,256 | ---- | C] () -- C:\WINDOWS.1\System32\pool.bin
[2009/04/15 12:27:54 | 000,011,776 | ---- | C] () -- C:\WINDOWS.1\System32\Proph32.dll
[2009/04/15 12:27:45 | 000,077,824 | ---- | C] () -- C:\WINDOWS.1\System32\ProphSMTP.dll
[2009/04/15 12:27:11 | 000,001,292 | ---- | C] () -- C:\WINDOWS.1\ODBC.INI
[2009/04/15 12:26:32 | 000,000,661 | ---- | C] () -- C:\WINDOWS.1\Proph2.ini
[2009/04/15 12:26:29 | 000,748,160 | ---- | C] () -- C:\WINDOWS.1\System32\co2c40en.dll
[2009/04/15 12:26:29 | 000,153,761 | ---- | C] () -- C:\WINDOWS.1\System32\u2frtf.dll
[2009/04/15 12:26:29 | 000,124,256 | ---- | C] () -- C:\WINDOWS.1\System32\u2dmapi.dll
[2009/04/15 12:26:29 | 000,109,568 | ---- | C] () -- C:\WINDOWS.1\System32\u2fhtml.dll
[2009/04/15 12:26:29 | 000,097,489 | ---- | C] () -- C:\WINDOWS.1\System32\u2fcr.dll
[2009/04/15 12:26:29 | 000,069,632 | ---- | C] () -- C:\WINDOWS.1\System32\u2fxls.dll
[2009/04/15 12:26:29 | 000,069,632 | ---- | C] () -- C:\WINDOWS.1\System32\u2fwordw.dll
[2009/04/15 12:26:29 | 000,054,272 | ---- | C] () -- C:\WINDOWS.1\System32\p2irdao.dll
[2009/04/15 12:26:29 | 000,053,248 | ---- | C] () -- C:\WINDOWS.1\System32\u2fwks.dll
[2009/04/15 12:26:29 | 000,053,248 | ---- | C] () -- C:\WINDOWS.1\System32\u2ftext.dll
[2009/04/15 12:26:29 | 000,053,248 | ---- | C] () -- C:\WINDOWS.1\System32\u2fsepv.dll
[2009/04/15 12:26:29 | 000,050,176 | ---- | C] () -- C:\WINDOWS.1\System32\p2ctdao.dll
[2009/04/15 12:26:29 | 000,049,152 | ---- | C] () -- C:\WINDOWS.1\System32\u2frec.dll
[2009/04/15 12:26:29 | 000,049,152 | ---- | C] () -- C:\WINDOWS.1\System32\u2fdif.dll
[2009/04/15 12:26:29 | 000,045,056 | ---- | C] () -- C:\WINDOWS.1\System32\u2ddisk.dll
[2009/04/15 12:26:29 | 000,036,352 | ---- | C] () -- C:\WINDOWS.1\System32\p2bbnd.dll
[2009/04/08 16:46:08 | 000,110,293 | R--- | C] () -- C:\WINDOWS.1\System32\atiicdxx.dat
[2009/04/08 16:45:20 | 000,135,168 | R--- | C] () -- C:\WINDOWS.1\System32\RtlCPAPI.dll
[2009/04/08 16:45:20 | 000,040,960 | ---- | C] () -- C:\WINDOWS.1\System32\ChCfg.exe
[2009/04/07 18:06:48 | 000,055,808 | ---- | C] () -- C:\Documents and Settings\Dustin\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/04/03 16:04:18 | 000,000,335 | ---- | C] () -- C:\WINDOWS.1\TRPMAKER.INI
[2009/04/01 15:29:31 | 000,002,048 | --S- | C] () -- C:\WINDOWS.1\bootstat.dat
[2009/04/01 15:22:58 | 000,021,640 | ---- | C] () -- C:\WINDOWS.1\System32\emptyregdb.dat
[2009/04/01 07:16:44 | 000,004,249 | ---- | C] () -- C:\WINDOWS.1\ODBCINST.INI
[2009/04/01 06:45:12 | 003,513,816 | ---- | C] () -- C:\WINDOWS.1\System32\FNTCACHE.DAT
[2004/08/03 22:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS.1\System32\mlang.dat
[2004/08/03 22:00:00 | 000,432,686 | ---- | C] () -- C:\WINDOWS.1\System32\perfh009.dat
[2004/08/03 22:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS.1\System32\perfi009.dat
[2004/08/03 22:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS.1\System32\dssec.dat
[2004/08/03 22:00:00 | 000,067,516 | ---- | C] () -- C:\WINDOWS.1\System32\perfc009.dat
[2004/08/03 22:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS.1\System32\mib.bin
[2004/08/03 22:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS.1\System32\perfd009.dat
[2004/08/03 22:00:00 | 000,004,569 | ---- | C] () -- C:\WINDOWS.1\System32\secupd.dat
[2004/08/03 22:00:00 | 000,001,788 | ---- | C] () -- C:\WINDOWS.1\System32\Dcache.bin
[2004/08/03 22:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS.1\System32\noise.dat
[2004/07/29 15:49:10 | 013,107,200 | ---- | C] () -- C:\WINDOWS.1\System32\oembios.bin
[2004/07/29 15:48:26 | 000,005,151 | ---- | C] () -- C:\WINDOWS.1\System32\oembios.dat
[2003/01/07 15:05:08 | 000,002,695 | ---- | C] () -- C:\WINDOWS.1\System32\OUTLPERF.INI

< End of report >





MBAM

Malwarebytes' Anti-Malware 1.51.1.1800
www.malwarebytes.org

Database version: 7684

Windows 5.1.2600 Service Pack 2
Internet Explorer 8.0.6001.18702

9/9/2011 10:43:44 AM
mbam-log-2011-09-09 (10-43-44).txt

Scan type: Quick scan
Objects scanned: 229999
Time elapsed: 12 minute(s), 20 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)



ComboFix

ComboFix 11-09-09.03 - Dustin 09/09/2011 12:16:21.3.2 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.894.239 [GMT -7:00]
Running from: c:\documents and settings\Dustin\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free Edition 2011 *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Administrator\Local Settings\Application Data\ApplicationHistory
c:\documents and settings\Administrator\Local Settings\Application Data\ApplicationHistory\ngen.exe.2c05686e.ini
c:\documents and settings\Administrator\Local Settings\Application Data\ApplicationHistory\SL30.tmp.47ef97a6.ini.inuse
c:\documents and settings\Administrator\Local Settings\Application Data\ApplicationHistory\SLC6.tmp.7cc0d7c.ini
c:\documents and settings\Administrator\Start Menu\Programs\System Recovery
c:\documents and settings\Administrator\Start Menu\Programs\System Recovery\Application & Driver Recovery.lnk
c:\documents and settings\Administrator\Start Menu\Programs\System Recovery\Create my Drivers-Applications CD(s).lnk
c:\documents and settings\Administrator\Start Menu\Programs\System Recovery\Recovery Media Creator.lnk
c:\documents and settings\Administrator\Start Menu\Programs\System Recovery\System Recovery.lnk
c:\windows.1\system32\comct332.ocx
.
c:\windows.1\system32\proquota.exe was missing
Restored copy from - c:\system volume information\_restore{78760705-30F8-4C87-8B25-BB34F8E3D247}\RP584\A0121371.exe
.
.
((((((((((((((((((((((((( Files Created from 2011-08-09 to 2011-09-09 )))))))))))))))))))))))))))))))
.
.
2011-09-09 19:30 . 2004-08-05 02:00 50176 -c--a-w- c:\windows.1\system32\dllcache\proquota.exe
2011-09-09 19:30 . 2004-08-05 02:00 50176 ----a-w- c:\windows.1\system32\proquota.exe
2011-09-09 14:37 . 2011-07-07 02:52 41272 ----a-w- c:\windows.1\system32\drivers\mbamswissarmy.sys
2011-09-09 14:37 . 2011-07-07 02:52 22712 ----a-w- c:\windows.1\system32\drivers\mbam.sys
2011-09-06 17:27 . 2011-09-06 17:27 -------- d-----w- c:\windows.1\system32\wbem\Repository
2011-09-02 17:49 . 2011-09-06 17:27 -------- d-----w- C:\RECYCLER(2)
2011-08-18 17:14 . 2011-08-26 18:03 -------- d-----w- c:\documents and settings\All Users.WINDOWS.1\Application Data\regid.1986-12.com.adobe
2011-08-18 17:01 . 2011-08-26 23:37 -------- d-----w- c:\documents and settings\Dustin\Application Data\PCF-VLC
2011-08-18 15:48 . 2011-08-22 18:25 -------- d-----w- c:\documents and settings\Dustin\Application Data\gtk-2.0
2011-08-17 18:35 . 2011-08-17 18:35 -------- d-----w- c:\program files\GetMiro Toolbar
2011-08-17 18:34 . 2011-08-17 18:34 -------- d-----w- c:\documents and settings\Dustin\Application Data\Participatory Culture Foundation
2011-08-17 18:33 . 2011-08-17 18:33 -------- d-----w- c:\program files\Participatory Culture Foundation
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-06-30 17:16 . 2010-12-03 14:16 32256 ----a-w- c:\windows.1\system32\Spool\prtprocs\w32x86\x5pp.dll
2011-06-30 17:16 . 2010-12-03 14:16 10752 ----a-w- c:\windows.1\system32\Spool\prtprocs\w32x86\x5print.dll
2011-06-23 16:41 . 2011-05-19 16:11 404640 ----a-w- c:\windows.1\system32\FlashPlayerCPLApp.cpl
2011-06-16 17:34 . 2011-06-16 17:34 73728 ----a-w- c:\windows.1\system32\javacpl.cpl
2011-06-16 17:34 . 2011-06-16 17:34 472808 ----a-w- c:\windows.1\system32\deployJava1.dll
.
.
((((((((((((((((((((((((((((( [email protected]_16.12.40 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-06-27 02:07 . 2009-06-27 02:07 59712 c:\windows.1\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4137_x-ww_15fb92d3\mfc90rus.dll
+ 2009-06-27 02:07 . 2009-06-27 02:07 42816 c:\windows.1\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4137_x-ww_15fb92d3\mfc90kor.dll
+ 2009-06-27 02:07 . 2009-06-27 02:07 43328 c:\windows.1\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4137_x-ww_15fb92d3\mfc90jpn.dll
+ 2009-06-27 02:07 . 2009-06-27 02:07 61248 c:\windows.1\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4137_x-ww_15fb92d3\mfc90ita.dll
+ 2009-06-27 02:07 . 2009-06-27 02:07 62784 c:\windows.1\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4137_x-ww_15fb92d3\mfc90fra.dll
+ 2009-06-27 02:07 . 2009-06-27 02:07 61760 c:\windows.1\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4137_x-ww_15fb92d3\mfc90esp.dll
+ 2009-06-27 02:07 . 2009-06-27 02:07 61760 c:\windows.1\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4137_x-ww_15fb92d3\mfc90esn.dll
+ 2009-06-27 02:07 . 2009-06-27 02:07 53568 c:\windows.1\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4137_x-ww_15fb92d3\mfc90enu.dll
+ 2009-06-27 02:07 . 2009-06-27 02:07 63296 c:\windows.1\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4137_x-ww_15fb92d3\mfc90deu.dll
+ 2009-06-27 02:07 . 2009-06-27 02:07 36672 c:\windows.1\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4137_x-ww_15fb92d3\mfc90cht.dll
+ 2009-06-27 02:07 . 2009-06-27 02:07 35648 c:\windows.1\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4137_x-ww_15fb92d3\mfc90chs.dll
+ 2009-06-27 02:10 . 2009-06-27 02:10 59904 c:\windows.1\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4137_x-ww_a57b1f13\mfcm90u.dll
+ 2009-06-27 02:10 . 2009-06-27 02:10 59904 c:\windows.1\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4137_x-ww_a57b1f13\mfcm90.dll
+ 2011-09-09 17:29 . 2011-09-09 17:29 16384 c:\windows.1\temp\Perflib_Perfdata_7e0.dat
+ 2011-08-18 17:04 . 2011-08-18 17:04 29184 c:\windows.1\Installer\4c5fc2.msi
+ 2011-08-18 17:01 . 2011-08-18 17:01 10134 c:\windows.1\Installer\{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}\ARPPRODUCTICON.exe
+ 2011-08-18 17:01 . 2011-08-18 17:01 10134 c:\windows.1\Installer\{D1A19B02-817E-4296-A45B-07853FD74D57}\ARPPRODUCTICON.exe
+ 2011-08-18 17:02 . 2011-08-18 17:02 10134 c:\windows.1\Installer\{B6D38690-755E-4F40-A35A-23F8BC2B86AC}\ARPPRODUCTICON.exe
+ 2011-08-18 17:01 . 2011-08-18 17:01 10134 c:\windows.1\Installer\{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}\ARPPRODUCTICON.exe
+ 2009-06-19 20:26 . 2011-08-25 18:06 23040 c:\windows.1\Installer\{91130409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
- 2009-06-19 20:26 . 2011-07-25 23:10 23040 c:\windows.1\Installer\{91130409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
+ 2009-06-19 20:26 . 2011-08-25 18:06 27136 c:\windows.1\Installer\{91130409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
- 2009-06-19 20:26 . 2011-07-25 23:10 27136 c:\windows.1\Installer\{91130409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
+ 2009-06-19 20:26 . 2011-08-25 18:06 11264 c:\windows.1\Installer\{91130409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
- 2009-06-19 20:26 . 2011-07-25 23:10 11264 c:\windows.1\Installer\{91130409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
- 2009-06-19 20:26 . 2011-07-25 23:10 12288 c:\windows.1\Installer\{91130409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
+ 2009-06-19 20:26 . 2011-08-25 18:06 12288 c:\windows.1\Installer\{91130409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
+ 2011-08-18 17:01 . 2011-08-18 17:01 10134 c:\windows.1\Installer\{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}\ARPPRODUCTICON.exe
+ 2011-08-18 17:05 . 2011-08-18 17:05 10134 c:\windows.1\Installer\{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}\ARPPRODUCTICON.exe
+ 2011-08-18 17:01 . 2011-08-18 17:01 10134 c:\windows.1\Installer\{08D2E121-7F6A-43EB-97FD-629B44903403}\ARPPRODUCTICON.exe
+ 2011-08-18 17:02 . 2011-08-18 17:02 10134 c:\windows.1\Installer\{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}\ARPPRODUCTICON.exe
+ 2009-06-19 20:26 . 2011-08-25 18:06 4096 c:\windows.1\Installer\{91130409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
- 2009-06-19 20:26 . 2011-07-25 23:10 4096 c:\windows.1\Installer\{91130409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
+ 2009-06-27 02:07 . 2009-06-27 02:07 653120 c:\windows.1\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4137_x-ww_d494ac0e\msvcr90.dll
+ 2009-06-27 02:07 . 2009-06-27 02:07 569664 c:\windows.1\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4137_x-ww_d494ac0e\msvcp90.dll
+ 2009-06-27 02:10 . 2009-06-27 02:10 225280 c:\windows.1\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4137_x-ww_d494ac0e\msvcm90.dll
+ 2009-06-27 02:07 . 2009-06-27 02:07 159032 c:\windows.1\WinSxS\x86_Microsoft.VC90.ATL_1fc8b3b9a1e18e3b_9.0.30729.4137_x-ww_35349982\atl90.dll
+ 2011-03-01 01:01 . 2011-03-01 01:01 947472 c:\windows.1\system32\msjava.dll
+ 2011-08-18 17:05 . 2011-08-18 17:05 356352 c:\windows.1\Installer\4c5fc8.msi
+ 2011-08-18 17:02 . 2011-08-18 17:02 319488 c:\windows.1\Installer\4c5fbc.msi
+ 2011-08-18 17:02 . 2011-08-18 17:02 315392 c:\windows.1\Installer\4c5fb6.msi
+ 2011-08-18 17:01 . 2011-08-18 17:01 316928 c:\windows.1\Installer\4c5fb0.msi
+ 2011-08-18 17:01 . 2011-08-18 17:01 356864 c:\windows.1\Installer\4c5faa.msi
+ 2011-08-18 17:01 . 2011-08-18 17:01 359424 c:\windows.1\Installer\4c5fa4.msi
+ 2011-08-18 17:01 . 2011-08-18 17:01 356352 c:\windows.1\Installer\4c5f9e.msi
+ 2011-08-18 17:00 . 2011-08-18 17:00 316416 c:\windows.1\Installer\4c5f98.msi
+ 2009-06-19 20:26 . 2011-08-25 18:06 409600 c:\windows.1\Installer\{91130409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
- 2009-06-19 20:26 . 2011-07-25 23:10 409600 c:\windows.1\Installer\{91130409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
- 2009-06-19 20:26 . 2011-07-25 23:10 286720 c:\windows.1\Installer\{91130409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
+ 2009-06-19 20:26 . 2011-08-25 18:06 286720 c:\windows.1\Installer\{91130409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
+ 2009-06-19 20:26 . 2011-08-25 18:06 794624 c:\windows.1\Installer\{91130409-6000-11D3-8CFE-0150048383C9}\outicon.exe
- 2009-06-19 20:26 . 2011-07-25 23:10 794624 c:\windows.1\Installer\{91130409-6000-11D3-8CFE-0150048383C9}\outicon.exe
- 2009-06-19 20:26 . 2011-07-25 23:10 135168 c:\windows.1\Installer\{91130409-6000-11D3-8CFE-0150048383C9}\misc.exe
+ 2009-06-19 20:26 . 2011-08-25 18:06 135168 c:\windows.1\Installer\{91130409-6000-11D3-8CFE-0150048383C9}\misc.exe
+ 2009-06-27 02:07 . 2009-06-27 02:07 3780416 c:\windows.1\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4137_x-ww_a57b1f13\mfc90u.dll
+ 2009-06-27 02:07 . 2009-06-27 02:07 3765048 c:\windows.1\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4137_x-ww_a57b1f13\mfc90.dll
+ 2009-12-03 17:54 . 2011-09-06 17:28 1186168 c:\windows.1\system32\Restore\rstrlog.dat
+ 2009-04-01 13:45 . 2011-08-19 15:33 3513816 c:\windows.1\system32\FNTCACHE.DAT
+ 2011-08-09 16:32 . 2011-08-09 16:32 3489280 c:\windows.1\Installer\77d62.msi
+ 2011-08-18 17:06 . 2011-08-18 17:06 2096128 c:\windows.1\Installer\4c5fce.msi
+ 2011-08-08 15:51 . 2011-08-08 15:51 1611776 c:\windows.1\Installer\4befe.msi
+ 2009-12-04 19:00 . 2011-08-11 18:00 52390856 c:\windows.1\system32\MRT.exe
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Messenger (Yahoo!)"="c:\progra~1\Yahoo!\MESSEN~1\YahooMessenger.exe" [2010-06-01 5252408]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2005-12-19 15797248]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696]
"AVG_TRAY"="c:\program files\AVG\AVG10\avgtray.exe" [2011-04-19 2334560]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2011-01-30 35736]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2011-03-16 499608]
"SwitchBoard"="c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"AdobeCS5.5ServiceManager"="c:\program files\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" [2011-01-12 1523360]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~1\AVG\AVG10\avgchsvx.exe /sync\0c:\progra~1\AVG\AVG10\avgrsx.exe /sync /restart
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"DisableNotifications"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Game Vindicator\\Game Vindicator\\GameVindicator.exe"=
"c:\\Program Files\\SecondLife\\SLVoice.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Documents and Settings\\Dustin\\Application Data\\Octoshape\\Octoshape Streaming Services\\OctoshapeClient.exe"=
"c:\\Program Files\\Prophesy\\Client\\Disp\\prodsp2.exe"=
"\\\\Rons\\Prophecy Host Folder\\Program Files\\Prophesy\\Disp\\DispShip.exe"=
"\\\\Rons\\Prophecy Host Folder\\Program Files\\Prophesy\\ProphFTP.exe"=
"c:\\Program Files\\AVG\\AVG10\\avgmfapx.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\SecondLifeViewer2\\SLVoice.exe"=
"c:\\Program Files\\SecondLifeViewer2\\slplugin.exe"=
"c:\\Program Files\\AVG\\AVG10\\avgdiagex.exe"=
"c:\\Program Files\\AVG\\AVG10\\avgnsx.exe"=
"c:\\Program Files\\AVG\\AVG10\\avgemcx.exe"=
.
R0 AVGIDSEH;AVGIDSEH;c:\windows.1\system32\drivers\AVGIDSEH.sys [9/13/2010 4:27 PM 22992]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows.1\system32\drivers\avgrkx86.sys [9/7/2010 3:48 AM 32592]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows.1\system32\drivers\avgldx86.sys [9/7/2010 3:48 AM 248656]
R1 Avgtdix;AVG TDI Driver;c:\windows.1\system32\drivers\avgtdix.sys [9/7/2010 3:49 AM 297168]
R2 AVGIDSAgent;AVGIDSAgent;c:\program files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe [4/18/2011 5:39 PM 7398752]
R2 avgwd;AVG WatchDog;c:\program files\AVG\AVG10\avgwdsvc.exe [2/8/2011 5:33 AM 269520]
R3 AVGIDSDriver;AVGIDSDriver;c:\windows.1\system32\drivers\AVGIDSDriver.sys [8/19/2010 9:42 PM 134480]
R3 AVGIDSFilter;AVGIDSFilter;c:\windows.1\system32\drivers\AVGIDSFilter.sys [8/19/2010 9:42 PM 24144]
R3 AVGIDSShim;AVGIDSShim;c:\windows.1\system32\drivers\AVGIDSShim.sys [8/19/2010 9:42 PM 27216]
R3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;c:\windows.1\system32\drivers\ManyCam.sys [1/14/2008 3:06 AM 21632]
S3 SwitchBoard;Adobe SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2/19/2010 1:37 PM 517096]
.
Contents of the 'Scheduled Tasks' folder
.
2011-08-25 c:\windows.1\Tasks\AdobeAAMUpdater-1.0-DUSTINS-Dustin.job
- c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe [2011-08-18 00:42]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.cnn.com/
TCP: DhcpNameServer = 192.168.1.254 192.168.1.254
.
- - - - ORPHANS REMOVED - - - -
.
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-09-09 12:35
Windows 5.1.2600 Service Pack 2 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 5.1.2600 Disk: ST3160812AS rev.3.AAE -> Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-7
.
device: opened successfully
user: MBR read successfully
error: Read A device attached to the system is not functioning.
kernel: MBR read successfully
detected disk devices:
detected hooks:
\Driver\atapi DriverStartIo -> 0x8481D2E0
user & kernel MBR OK
.
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(812)
c:\windows.1\system32\Ati2evxx.dll
.
Completion time: 2011-09-09 12:42:00
ComboFix-quarantined-files.txt 2011-09-09 19:41
ComboFix2.txt 2011-09-02 17:40
ComboFix3.txt 2011-08-02 23:29
ComboFix4.txt 2011-07-29 16:14
.
Pre-Run: 111,583,531,008 bytes free
Post-Run: 112,435,830,784 bytes free
.
- - End Of File - - BC89D14AA22C5AB8A9596370A29D0374





TDSSKiller

2011/09/12 06:37:29.0759 2540 TDSS rootkit removing tool 2.5.21.0 Sep 10 2011 21:07:05
2011/09/12 06:37:31.0040 2540 ================================================================================
2011/09/12 06:37:31.0040 2540 SystemInfo:
2011/09/12 06:37:31.0040 2540
2011/09/12 06:37:31.0040 2540 OS Version: 5.1.2600 ServicePack: 2.0
2011/09/12 06:37:31.0040 2540 Product type: Workstation
2011/09/12 06:37:31.0040 2540 ComputerName: DUSTINS
2011/09/12 06:37:31.0040 2540 UserName: Dustin
2011/09/12 06:37:31.0040 2540 Windows directory: C:\WINDOWS.1
2011/09/12 06:37:31.0040 2540 System windows directory: C:\WINDOWS.1
2011/09/12 06:37:31.0040 2540 Processor architecture: Intel x86
2011/09/12 06:37:31.0040 2540 Number of processors: 2
2011/09/12 06:37:31.0040 2540 Page size: 0x1000
2011/09/12 06:37:31.0040 2540 Boot type: Normal boot
2011/09/12 06:37:31.0040 2540 ================================================================================
2011/09/12 06:37:47.0164 2540 Initialize success
2011/09/12 06:37:59.0741 2008 ================================================================================
2011/09/12 06:37:59.0741 2008 Scan started
2011/09/12 06:37:59.0741 2008 Mode: Manual;
2011/09/12 06:37:59.0741 2008 ================================================================================
2011/09/12 06:38:06.0725 2008 ACPI (a10c7534f7223f4a73a948967d00e69b) C:\WINDOWS.1\system32\DRIVERS\ACPI.sys
2011/09/12 06:38:07.0663 2008 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS.1\system32\drivers\ACPIEC.sys
2011/09/12 06:38:10.0506 2008 aec (1ee7b434ba961ef845de136224c30fec) C:\WINDOWS.1\system32\drivers\aec.sys
2011/09/12 06:38:11.0506 2008 AFD (55e6e1c51b6d30e54335750955453702) C:\WINDOWS.1\System32\drivers\afd.sys
2011/09/12 06:38:16.0427 2008 AsyncMac (02000abf34af4c218c35d257024807d6) C:\WINDOWS.1\system32\DRIVERS\asyncmac.sys
2011/09/12 06:38:18.0099 2008 atapi (cdfe4411a69c224bd1d11b2da92dac51) C:\WINDOWS.1\system32\DRIVERS\atapi.sys
2011/09/12 06:38:20.0146 2008 ati2mtag (cd35697cb6c7e081effa98f46023e10b) C:\WINDOWS.1\system32\DRIVERS\ati2mtag.sys
2011/09/12 06:38:22.0708 2008 Atmarpc (ec88da854ab7d7752ec8be11a741bb7f) C:\WINDOWS.1\system32\DRIVERS\atmarpc.sys
2011/09/12 06:38:23.0568 2008 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS.1\system32\DRIVERS\audstub.sys
2011/09/12 06:38:24.0817 2008 AVGIDSDriver (c403e7f715bb0a851a9dfae16ec4ae42) C:\WINDOWS.1\system32\DRIVERS\AVGIDSDriver.Sys
2011/09/12 06:38:25.0239 2008 AVGIDSEH (1af676db3f3d4cc709cfab2571cf5fc3) C:\WINDOWS.1\system32\DRIVERS\AVGIDSEH.Sys
2011/09/12 06:38:26.0145 2008 AVGIDSFilter (4c51e233c87f9ec7598551de554bc99d) C:\WINDOWS.1\system32\DRIVERS\AVGIDSFilter.Sys
2011/09/12 06:38:26.0661 2008 AVGIDSShim (c3fc426e54f55c1cc3219e415b88e10c) C:\WINDOWS.1\system32\DRIVERS\AVGIDSShim.Sys
2011/09/12 06:38:27.0145 2008 Avgldx86 (4e796d3d2c3182b13b3e3b5a2ad4ef0a) C:\WINDOWS.1\system32\DRIVERS\avgldx86.sys
2011/09/12 06:38:27.0677 2008 Avgmfx86 (5639de66b37d02bd22df4cf3155fba60) C:\WINDOWS.1\system32\DRIVERS\avgmfx86.sys
2011/09/12 06:38:28.0583 2008 Avgrkx86 (d1baf652eda0ae70896276a1fb32c2d4) C:\WINDOWS.1\system32\DRIVERS\avgrkx86.sys
2011/09/12 06:38:29.0364 2008 Avgtdix (aaf0ebcad95f2164cffb544e00392498) C:\WINDOWS.1\system32\DRIVERS\avgtdix.sys
2011/09/12 06:38:30.0614 2008 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS.1\system32\drivers\Beep.sys
2011/09/12 06:38:32.0707 2008 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS.1\system32\drivers\cbidf2k.sys
2011/09/12 06:38:33.0551 2008 CCDECODE (6163ed60b684bab19d3352ab22fc48b2) C:\WINDOWS.1\system32\DRIVERS\CCDECODE.sys
2011/09/12 06:38:34.0551 2008 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS.1\system32\drivers\Cdaudio.sys
2011/09/12 06:38:35.0223 2008 Cdfs (cd7d5152df32b47f4e36f710b35aae02) C:\WINDOWS.1\system32\drivers\Cdfs.sys
2011/09/12 06:38:35.0582 2008 Cdrom (af9c19b3100fe010496b1a27181fbf72) C:\WINDOWS.1\system32\DRIVERS\cdrom.sys
2011/09/12 06:38:38.0457 2008 Disk (00ca44e4534865f8a3b64f7c0984bff0) C:\WINDOWS.1\system32\DRIVERS\disk.sys
2011/09/12 06:38:38.0957 2008 dmboot (c0fbb516e06e243f0cf31f597e7ebf7d) C:\WINDOWS.1\system32\drivers\dmboot.sys
2011/09/12 06:38:39.0301 2008 dmio (f5e7b358a732d09f4bcf2824b88b9e28) C:\WINDOWS.1\system32\drivers\dmio.sys
2011/09/12 06:38:39.0863 2008 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS.1\system32\drivers\dmload.sys
2011/09/12 06:38:40.0519 2008 DMusic (a6f881284ac1150e37d9ae47ff601267) C:\WINDOWS.1\system32\drivers\DMusic.sys
2011/09/12 06:38:41.0019 2008 drmkaud (1ed4dbbae9f5d558dbba4cc450e3eb2e) C:\WINDOWS.1\system32\drivers\drmkaud.sys
2011/09/12 06:38:41.0613 2008 Fastfat (3117f595e9615e04f05a54fc15a03b20) C:\WINDOWS.1\system32\drivers\Fastfat.sys
2011/09/12 06:38:42.0035 2008 Fdc (ced2e8396a8838e59d8fd529c680e02c) C:\WINDOWS.1\system32\DRIVERS\fdc.sys
2011/09/12 06:38:42.0441 2008 Fips (e153ab8a11de5452bcf5ac7652dbf3ed) C:\WINDOWS.1\system32\drivers\Fips.sys
2011/09/12 06:38:43.0035 2008 Flpydisk (0dd1de43115b93f4d85e889d7a86f548) C:\WINDOWS.1\system32\drivers\Flpydisk.sys
2011/09/12 06:38:43.0363 2008 FltMgr (3d234fb6d6ee875eb009864a299bea29) C:\WINDOWS.1\system32\DRIVERS\fltMgr.sys
2011/09/12 06:38:43.0691 2008 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS.1\system32\drivers\Fs_Rec.sys
2011/09/12 06:38:44.0066 2008 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS.1\system32\DRIVERS\ftdisk.sys
2011/09/12 06:38:44.0300 2008 Gpc (c0f1d4a21de5a415df8170616703debf) C:\WINDOWS.1\system32\DRIVERS\msgpc.sys
2011/09/12 06:38:44.0535 2008 HDAudBus (3fcc124b6e08ee0e9351f717dd136939) C:\WINDOWS.1\system32\DRIVERS\HDAudBus.sys
2011/09/12 06:38:44.0738 2008 HidUsb (1de6783b918f540149aa69943bdfeba8) C:\WINDOWS.1\system32\DRIVERS\hidusb.sys
2011/09/12 06:38:45.0144 2008 HTTP (9f8b0f4276f618964fd118be4289b7cd) C:\WINDOWS.1\system32\Drivers\HTTP.sys
2011/09/12 06:38:45.0503 2008 i8042prt (5502b58eef7486ee6f93f3f164dcb808) C:\WINDOWS.1\system32\DRIVERS\i8042prt.sys
2011/09/12 06:38:45.0800 2008 Imapi (f8aa320c6a0409c0380e5d8a99d76ec6) C:\WINDOWS.1\system32\DRIVERS\imapi.sys
2011/09/12 06:38:47.0003 2008 IntcAzAudAddService (0782317ca4b1c229a0854c998c4595fe) C:\WINDOWS.1\system32\drivers\RtkHDAud.sys
2011/09/12 06:38:48.0144 2008 intelppm (279fb78702454dff2bb445f238c048d2) C:\WINDOWS.1\system32\DRIVERS\intelppm.sys
2011/09/12 06:38:48.0488 2008 Ip6Fw (4448006b6bc60e6c027932cfc38d6855) C:\WINDOWS.1\system32\DRIVERS\Ip6Fw.sys
2011/09/12 06:38:48.0691 2008 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS.1\system32\DRIVERS\ipfltdrv.sys
2011/09/12 06:38:48.0894 2008 IpInIp (e1ec7f5da720b640cd8fb8424f1b14bb) C:\WINDOWS.1\system32\DRIVERS\ipinip.sys
2011/09/12 06:38:49.0191 2008 IpNat (e2168cbc7098ffe963c6f23f472a3593) C:\WINDOWS.1\system32\DRIVERS\ipnat.sys
2011/09/12 06:38:49.0441 2008 IPSec (64537aa5c003a6afeee1df819062d0d1) C:\WINDOWS.1\system32\DRIVERS\ipsec.sys
2011/09/12 06:38:49.0800 2008 IRENUM (50708daa1b1cbb7d6ac1cf8f56a24410) C:\WINDOWS.1\system32\DRIVERS\irenum.sys
2011/09/12 06:38:50.0316 2008 isapnp (e504f706ccb699c2596e9a3da1596e87) C:\WINDOWS.1\system32\DRIVERS\isapnp.sys
2011/09/12 06:38:50.0722 2008 Kbdclass (ebdee8a2ee5393890a1acee971c4c246) C:\WINDOWS.1\system32\DRIVERS\kbdclass.sys
2011/09/12 06:38:51.0253 2008 kmixer (ba5deda4d934e6288c2f66caf58d2562) C:\WINDOWS.1\system32\drivers\kmixer.sys
2011/09/12 06:38:51.0597 2008 KSecDD (674d3e5a593475915dc6643317192403) C:\WINDOWS.1\system32\drivers\KSecDD.sys
2011/09/12 06:38:52.0597 2008 ManyCam (c6d085c7045200143528136a43a65fde) C:\WINDOWS.1\system32\DRIVERS\ManyCam.sys
2011/09/12 06:38:53.0175 2008 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS.1\system32\drivers\mnmdd.sys
2011/09/12 06:38:53.0659 2008 Modem (6fc6f9d7acc36dca9b914565a3aeda05) C:\WINDOWS.1\system32\drivers\Modem.sys
2011/09/12 06:38:53.0987 2008 Mouclass (34e1f0031153e491910e12551400192c) C:\WINDOWS.1\system32\DRIVERS\mouclass.sys
2011/09/12 06:38:54.0471 2008 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS.1\system32\DRIVERS\mouhid.sys
2011/09/12 06:38:54.0893 2008 MountMgr (65653f3b4477f3c63e68a9659f85ee2e) C:\WINDOWS.1\system32\drivers\MountMgr.sys
2011/09/12 06:38:55.0221 2008 MRxDAV (29414447eb5bde2f8397dc965dbb3156) C:\WINDOWS.1\system32\DRIVERS\mrxdav.sys
2011/09/12 06:38:55.0424 2008 MRxSmb (fb6c89bb3ce282b08bdb1e3c179e1c39) C:\WINDOWS.1\system32\DRIVERS\mrxsmb.sys
2011/09/12 06:38:55.0612 2008 Msfs (561b3a4333ca2dbdba28b5b956822519) C:\WINDOWS.1\system32\drivers\Msfs.sys
2011/09/12 06:38:55.0878 2008 MSKSSRV (ae431a8dd3c1d0d0610cdbac16057ad0) C:\WINDOWS.1\system32\drivers\MSKSSRV.sys
2011/09/12 06:38:56.0065 2008 MSPCLOCK (13e75fef9dfeb08eeded9d0246e1f448) C:\WINDOWS.1\system32\drivers\MSPCLOCK.sys
2011/09/12 06:38:56.0190 2008 MSPQM (1988a33ff19242576c3d0ef9ce785da7) C:\WINDOWS.1\system32\drivers\MSPQM.sys
2011/09/12 06:38:56.0409 2008 mssmbios (469541f8bfd2b32659d5d463a6714bce) C:\WINDOWS.1\system32\DRIVERS\mssmbios.sys
2011/09/12 06:38:56.0503 2008 MSTEE (bf13612142995096ab084f2db7f40f77) C:\WINDOWS.1\system32\drivers\MSTEE.sys
2011/09/12 06:38:56.0737 2008 Mup (82035e0f41c2dd05ae41d27fe6cf7de1) C:\WINDOWS.1\system32\drivers\Mup.sys
2011/09/12 06:38:56.0987 2008 NABTSFEC (5c8dc6429c43dc6177c1fa5b76290d1a) C:\WINDOWS.1\system32\DRIVERS\NABTSFEC.sys
2011/09/12 06:38:57.0252 2008 NDIS (558635d3af1c7546d26067d5d9b6959e) C:\WINDOWS.1\system32\drivers\NDIS.sys
2011/09/12 06:38:57.0377 2008 NdisIP (520ce427a8b298f54112857bcf6bde15) C:\WINDOWS.1\system32\DRIVERS\NdisIP.sys
2011/09/12 06:38:57.0581 2008 NdisTapi (08d43bbdacdf23f34d79e44ed35c1b4c) C:\WINDOWS.1\system32\DRIVERS\ndistapi.sys
2011/09/12 06:38:57.0862 2008 Ndisuio (34d6cd56409da9a7ed573e1c90a308bf) C:\WINDOWS.1\system32\DRIVERS\ndisuio.sys
2011/09/12 06:38:57.0893 2008 NdisWan (0b90e255a9490166ab368cd55a529893) C:\WINDOWS.1\system32\DRIVERS\ndiswan.sys
2011/09/12 06:38:58.0096 2008 NDProxy (59fc3fb44d2669bc144fd87826bb571f) C:\WINDOWS.1\system32\drivers\NDProxy.sys
2011/09/12 06:38:58.0331 2008 NetBIOS (3a2aca8fc1d7786902ca434998d7ceb4) C:\WINDOWS.1\system32\DRIVERS\netbios.sys
2011/09/12 06:38:58.0487 2008 NetBT (0c80e410cd2f47134407ee7dd19cc86b) C:\WINDOWS.1\system32\DRIVERS\netbt.sys
2011/09/12 06:38:58.0799 2008 Npfs (4f601bcb8f64ea3ac0994f98fed03f8e) C:\WINDOWS.1\system32\drivers\Npfs.sys
2011/09/12 06:38:58.0924 2008 Ntfs (19a811ef5f1ed5c926a028ce107ff1af) C:\WINDOWS.1\system32\drivers\Ntfs.sys
2011/09/12 06:38:59.0049 2008 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS.1\system32\drivers\Null.sys
2011/09/12 06:38:59.0252 2008 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS.1\system32\DRIVERS\nwlnkflt.sys
2011/09/12 06:38:59.0487 2008 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS.1\system32\DRIVERS\nwlnkfwd.sys
2011/09/12 06:38:59.0705 2008 Parport (29744eb4ce659dfe3b4122deb45bc478) C:\WINDOWS.1\system32\DRIVERS\parport.sys
2011/09/12 06:39:00.0080 2008 PartMgr (3334430c29dc338092f79c38ef7b4cd0) C:\WINDOWS.1\system32\drivers\PartMgr.sys
2011/09/12 06:39:00.0283 2008 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS.1\system32\drivers\ParVdm.sys
2011/09/12 06:39:00.0424 2008 PCI (8086d9979234b603ad5bc2f5d890b234) C:\WINDOWS.1\system32\DRIVERS\pci.sys
2011/09/12 06:39:00.0658 2008 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS.1\system32\DRIVERS\pciide.sys
2011/09/12 06:39:00.0752 2008 Pcmcia (82a087207decec8456fbe8537947d579) C:\WINDOWS.1\system32\drivers\Pcmcia.sys
2011/09/12 06:39:01.0893 2008 PptpMiniport (1c5cc65aac0783c344f16353e60b72ac) C:\WINDOWS.1\system32\DRIVERS\raspptp.sys
2011/09/12 06:39:02.0143 2008 PSched (48671f327553dcf1d27f6197f622a668) C:\WINDOWS.1\system32\DRIVERS\psched.sys
2011/09/12 06:39:02.0330 2008 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS.1\system32\DRIVERS\ptilink.sys
2011/09/12 06:39:02.0440 2008 PxHelp20 (153d02480a0a2f45785522e814c634b6) C:\WINDOWS.1\system32\Drivers\PxHelp20.sys
2011/09/12 06:39:03.0049 2008 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS.1\system32\DRIVERS\rasacd.sys
2011/09/12 06:39:03.0377 2008 Rasl2tp (98faeb4a4dcf812ba1c6fca4aa3e115c) C:\WINDOWS.1\system32\DRIVERS\rasl2tp.sys
2011/09/12 06:39:03.0674 2008 RasPppoe (7306eeed8895454cbed4669be9f79faa) C:\WINDOWS.1\system32\DRIVERS\raspppoe.sys
2011/09/12 06:39:03.0939 2008 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS.1\system32\DRIVERS\raspti.sys
2011/09/12 06:39:04.0111 2008 Rdbss (03b965b1ca47f6ef60eb5e51cb50e0af) C:\WINDOWS.1\system32\DRIVERS\rdbss.sys
2011/09/12 06:39:04.0189 2008 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS.1\system32\DRIVERS\RDPCDD.sys
2011/09/12 06:39:04.0346 2008 rdpdr (a2cae2c60bc37e0751ef9dda7ceaf4ad) C:\WINDOWS.1\system32\DRIVERS\rdpdr.sys
2011/09/12 06:39:04.0627 2008 RDPWD (b54cd38a9ebfbf2b3561426e3fe26f62) C:\WINDOWS.1\system32\drivers\RDPWD.sys
2011/09/12 06:39:04.0814 2008 redbook (b31b4588e4086d8d84adbf9845c2402b) C:\WINDOWS.1\system32\DRIVERS\redbook.sys
2011/09/12 06:39:05.0174 2008 RimVSerPort (d9b34325ee5df78b8f28a3de9f577c7d) C:\WINDOWS.1\system32\DRIVERS\RimSerial.sys
2011/09/12 06:39:05.0502 2008 ROOTMODEM (d8b0b4ade32574b2d9c5cc34dc0dbbe7) C:\WINDOWS.1\system32\Drivers\RootMdm.sys
2011/09/12 06:39:05.0752 2008 RTL8023xp (e9877aa069dc11b03dbd1d33b8b2a3ca) C:\WINDOWS.1\system32\DRIVERS\Rtlnicxp.sys
2011/09/12 06:39:06.0002 2008 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS.1\system32\DRIVERS\secdrv.sys
2011/09/12 06:39:06.0189 2008 serenum (a2d868aeeff612e70e213c451a70cafb) C:\WINDOWS.1\system32\DRIVERS\serenum.sys
2011/09/12 06:39:06.0314 2008 Serial (cd9404d115a00d249f70a371b46d5a26) C:\WINDOWS.1\system32\DRIVERS\serial.sys
2011/09/12 06:39:06.0486 2008 Sfloppy (0d13b6df6e9e101013a7afb0ce629fe0) C:\WINDOWS.1\system32\drivers\Sfloppy.sys
2011/09/12 06:39:06.0845 2008 SLIP (5caeed86821fa2c6139e32e9e05ccdc9) C:\WINDOWS.1\system32\DRIVERS\SLIP.sys
2011/09/12 06:39:07.0345 2008 splitter (0ce218578fff5f4f7e4201539c45c78f) C:\WINDOWS.1\system32\drivers\splitter.sys
2011/09/12 06:39:07.0455 2008 sr (e41b6d037d6cd08461470af04500dc24) C:\WINDOWS.1\system32\DRIVERS\sr.sys
2011/09/12 06:39:07.0783 2008 Srv (7a4f147cc6b133f905f6e65e2f8669fb) C:\WINDOWS.1\system32\DRIVERS\srv.sys
2011/09/12 06:39:07.0986 2008 streamip (284c57df5dc7abca656bc2b96a667afb) C:\WINDOWS.1\system32\DRIVERS\StreamIP.sys
2011/09/12 06:39:08.0189 2008 swenum (03c1bae4766e2450219d20b993d6e046) C:\WINDOWS.1\system32\DRIVERS\swenum.sys
2011/09/12 06:39:08.0361 2008 swmidi (94abc808fc4b6d7d2bbf42b85e25bb4d) C:\WINDOWS.1\system32\drivers\swmidi.sys
2011/09/12 06:39:09.0002 2008 sysaudio (650ad082d46bac0e64c9c0e0928492fd) C:\WINDOWS.1\system32\drivers\sysaudio.sys
2011/09/12 06:39:09.0111 2008 Tcpip (2a5554fc5b1e04e131230e3ce035c3f9) C:\WINDOWS.1\system32\DRIVERS\tcpip.sys
2011/09/12 06:39:09.0330 2008 TDPIPE (38d437cf2d98965f239b0abcd66dcb0f) C:\WINDOWS.1\system32\drivers\TDPIPE.sys
2011/09/12 06:39:09.0705 2008 TDTCP (ed0580af02502d00ad8c4c066b156be9) C:\WINDOWS.1\system32\drivers\TDTCP.sys
2011/09/12 06:39:10.0017 2008 TermDD (a540a99c281d933f3d69d55e48727f47) C:\WINDOWS.1\system32\DRIVERS\termdd.sys
2011/09/12 06:39:10.0673 2008 Udfs (12f70256f140cd7d52c58c7048fde657) C:\WINDOWS.1\system32\drivers\Udfs.sys
2011/09/12 06:39:11.0033 2008 Update (ced744117e91bdc0beb810f7d8608183) C:\WINDOWS.1\system32\DRIVERS\update.sys
2011/09/12 06:39:11.0189 2008 usbccgp (bffd9f120cc63bcbaa3d840f3eef9f79) C:\WINDOWS.1\system32\DRIVERS\usbccgp.sys
2011/09/12 06:39:11.0376 2008 usbehci (15e993ba2f6946b2bfbbfcd30398621e) C:\WINDOWS.1\system32\DRIVERS\usbehci.sys
2011/09/12 06:39:11.0642 2008 usbhub (c72f40947f92cea56a8fb532edf025f1) C:\WINDOWS.1\system32\DRIVERS\usbhub.sys
2011/09/12 06:39:12.0033 2008 usbohci (bdfe799a8531bad8a5a985821fe78760) C:\WINDOWS.1\system32\DRIVERS\usbohci.sys
2011/09/12 06:39:12.0361 2008 usbscan (a6bc71402f4f7dd5b77fd7f4a8ddba85) C:\WINDOWS.1\system32\DRIVERS\usbscan.sys
2011/09/12 06:39:12.0736 2008 USBSTOR (6cd7b22193718f1d17a47a1cd6d37e75) C:\WINDOWS.1\system32\DRIVERS\USBSTOR.SYS
2011/09/12 06:39:12.0970 2008 VgaSave (8a60edd72b4ea5aea8202daf0e427925) C:\WINDOWS.1\System32\drivers\vga.sys
2011/09/12 06:39:13.0251 2008 VolSnap (ee4660083deba849ff6c485d944b379b) C:\WINDOWS.1\system32\drivers\VolSnap.sys
2011/09/12 06:39:13.0439 2008 Wanarp (984ef0b9788abf89974cfed4bfbaacbc) C:\WINDOWS.1\system32\DRIVERS\wanarp.sys
2011/09/12 06:39:13.0626 2008 wdmaud (efd235ca22b57c81118c1aeb4798f1c1) C:\WINDOWS.1\system32\drivers\wdmaud.sys
2011/09/12 06:39:14.0267 2008 WSTCODEC (d5842484f05e12121c511aa93f6439ec) C:\WINDOWS.1\system32\DRIVERS\WSTCODEC.SYS
2011/09/12 06:39:14.0626 2008 MBR (0x1B8) (cdac57608c39097805c8c958f1f73d97) \Device\Harddisk0\DR0
2011/09/12 06:39:14.0689 2008 \Device\Harddisk0\DR0 - detected Rootkit.Boot.Pihar.a (0)
2011/09/12 06:39:14.0798 2008 Boot (0x1200) (3d06d2bcaaff1b8afc4505f5233e9a6e) \Device\Harddisk0\DR0\Partition0
2011/09/12 06:39:14.0907 2008 Boot (0x1200) (3034b219128998b90e501cc22e82c5ff) \Device\Harddisk0\DR0\Partition1
2011/09/12 06:39:14.0954 2008 ================================================================================
2011/09/12 06:39:14.0954 2008 Scan finished
2011/09/12 06:39:14.0954 2008 ================================================================================
2011/09/12 06:39:15.0173 0348 Detected object count: 1
2011/09/12 06:39:15.0173 0348 Actual detected object count: 1
2011/09/12 07:15:45.0578 0348 \Device\Harddisk0\DR0 (Rootkit.Boot.Pihar.a) - will be cured after reboot
2011/09/12 07:15:45.0578 0348 \Device\Harddisk0\DR0 - ok
2011/09/12 07:15:45.0578 0348 Rootkit.Boot.Pihar.a(\Device\Harddisk0\DR0) - User select action: Cure
2011/09/12 07:16:01.0531 3984 Deinitialize success







ASWmbr

aswMBR version 0.9.8.986 Copyright© 2011 AVAST Software
Run date: 2011-09-12 08:14:09
-----------------------------
08:14:09.921 OS Version: Windows 5.1.2600 Service Pack 2
08:14:09.921 Number of processors: 2 586 0x605
08:14:09.921 ComputerName: DUSTINS UserName: Dustin
08:14:10.406 Initialize success
08:15:00.968 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-7
08:15:00.968 Disk 0 Vendor: ST3160812AS 3.AAE Size: 152627MB BusType: 3
08:15:02.984 Disk 0 MBR read successfully
08:15:02.984 Disk 0 MBR scan
08:15:02.984 Disk 0 Windows XP default MBR code
08:15:02.984 Disk 0 malicious Win32:MBRoot code @ sector 61 !
08:15:03.015 Disk 0 PE file @ sector 312560640 !
08:15:03.046 Disk 0 scanning C:\WINDOWS.1\system32\drivers
08:15:07.765 Service scanning
08:15:08.656 Modules scanning
08:15:12.250 Scan finished successfully
08:18:42.125 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Dustin\Desktop\MBR.dat"
08:18:42.125 The log file has been saved successfully to "C:\Documents and Settings\Dustin\Desktop\aswMBR.txt"







Procexp

Process PID CPU Private Bytes Working Set Description Company Name
System Idle Process 0 99.22 0 K 28 K
procexp.exe 2296 0.78 9,968 K 14,788 K Sysinternals Process Explorer Sysinternals - www.sysinternals.com
Interrupts n/a < 0.01 0 K 0 K Hardware Interrupts and DPCs
Ymsgr_tray.exe 1180 19,280 K 6,272 K Yahoo! Messenger Tray Yahoo! Inc.
YahooAUService.exe 1224 3,072 K 4,328 K AutoUpater Service Module Yahoo! Inc.
wmiprvse.exe 2484 2,920 K 4,860 K WMI Microsoft Corporation
winlogon.exe 808 6,816 K 4,040 K Windows NT Logon Application Microsoft Corporation
wdfmgr.exe 1028 1,528 K 1,780 K Windows User Mode Driver Manager Microsoft Corporation
System 4 0 K 150,728 K
svchost.exe 1240 17,512 K 26,920 K Generic Host Process for Win32 Services Microsoft Corporation
svchost.exe 1060 3,036 K 4,804 K Generic Host Process for Win32 Services Microsoft Corporation
svchost.exe 1144 1,792 K 4,196 K Generic Host Process for Win32 Services Microsoft Corporation
svchost.exe 1360 1,332 K 3,544 K Generic Host Process for Win32 Services Microsoft Corporation
svchost.exe 1436 1,560 K 4,008 K Generic Host Process for Win32 Services Microsoft Corporation
svchost.exe 1924 1,316 K 3,808 K Generic Host Process for Win32 Services Microsoft Corporation
svchost.exe 192 2,464 K 4,244 K Generic Host Process for Win32 Services Microsoft Corporation
spoolsv.exe 1648 3,440 K 5,500 K Spooler SubSystem App Microsoft Corporation
smss.exe 592 172 K 416 K Windows NT Session Manager Microsoft Corporation
services.exe 856 2,048 K 4,760 K Services and Controller app Microsoft Corporation
RTHDCPL.exe 1728 17,848 K 20,388 K Realtek HD Audio Control Panel Realtek Semiconductor Corp.
lsass.exe 868 3,852 K 1,020 K LSA Shell (Export Version) Microsoft Corporation
jusched.exe 2160 1,080 K 4,136 K Java™ Update Scheduler Sun Microsystems, Inc.
jucheck.exe 756 2,572 K 6,152 K Java™ Update Checker Sun Microsystems, Inc.
jqs.exe 1996 2,036 K 1,388 K Java™ Quick Starter Service Sun Microsystems, Inc.
iexplore.exe 2328 75,096 K 1,724 K Internet Explorer Microsoft Corporation
explorer.exe 540 17,460 K 26,380 K Windows Explorer Microsoft Corporation
ctfmon.exe 2324 940 K 3,672 K CTF Loader Microsoft Corporation
csrss.exe 776 1,688 K 3,784 K Client Server Runtime Process Microsoft Corporation
avgwdsvc.exe 1960 9,064 K 15,976 K AVG Watchdog Service AVG Technologies CZ, s.r.o.
avgtray.exe 2100 4,348 K 2,392 K AVG Tray Monitor AVG Technologies CZ, s.r.o.
avgrsx.exe 232 828 K 500 K AVG Resident Shield Service AVG Technologies CZ, s.r.o.
avgnsx.exe 1828 11,144 K 244 K AVG Online Shield Service AVG Technologies CZ, s.r.o.
AVGIDSMonitor.exe 2880 1,048 K 3,528 K
AVGIDSAgent.exe 1344 21,052 K 17,092 K AVG Identity Protection Service AVG Technologies CZ, s.r.o.
avgemcx.exe 1864 2,196 K 5,060 K AVG E-mail Scanner AVG Technologies CZ, s.r.o.
avgcsrvx.exe 2004 11,796 K 304 K AVG Scanning Core Module - Server Part AVG Technologies CZ, s.r.o.
avgchsvx.exe 624 19,128 K 196 K AVG Cache Server AVG Technologies CZ, s.r.o.
ati2evxx.exe 1044 616 K 2,512 K ATI External Event Utility EXE Module ATI Technologies Inc.
ati2evxx.exe 432 764 K 3,112 K ATI External Event Utility EXE Module ATI Technologies Inc.
alg.exe 3580 1,180 K 3,564 K Application Layer Gateway Service Microsoft Corporation
AdobeARM.exe 2136 4,208 K 7,856 K Adobe Reader and Acrobat Manager Adobe Systems Incorporated



Once again thanks alot for you time Ron, it is much appreciated.
  • 0

#4
RKinner

RKinner

    Malware Expert

  • Expert
  • 20,031 posts
  • MVP
You need to update to XP SP3. Running SP2 you will get a lot more of these infections.

If this is an AMD CPU then you need to get KB953356:
http://www.microsoft...ang=en&id=23751
and install it first.


You should be offered the SP3 update from MS Updates but if not you can get it from:

http://technet.micro...indows/bb794714

We need to clean up System Restore. Follow Jim's procedure here:
http://aumha.net/vie...581099691bf108f


You can uninstall or delete any tools we had you download and their logs.
To uninstall combofix, copy the next line:

"%userprofile%\Desktop\combofix.exe" /Uninstall

Start, Run, cmd, OK then right click, Paste, then hit Enter.

OTL has a cleanup tab so if you run it again and select cleanup it will remove itself and its backup files.

To hide hidden files again (If you do not run OTL cleanup):

XP

# Close all programs so that you are at your desktop.
# Double-click on the My Computer icon.
# Select the Tools menu and click Folder Options.
# After the new window appears select the View tab.
# Uncheck the checkbox labeled Display the contents of system folders.
# Under the Hidden files and folders section select the 'Hide protected operating system files (recommended)' option.
# Check the checkbox labeled Hide protected operating system files.
# Press the Apply button and then the OK button and shutdown My Computer.

You probably do not have the latest Java (Java™ 6 Update 27 or 7 update 0). Get the latest at:
http://www.java.com/en/

Save it to your PC then close all browsers and install it. Note on Java and Firefox. For some reason Java does not remove old consoles from Firefox. Any time you update Java you should do Firefox, Add-ons, Extensions and disable any old Java Consoles

They will look like: Java Console 6.xx. The xx corresponds to the update number. When they switch to 7 update 0 then it will be Java Console 7.

Multiple Java Consoles will slow down the Firefox boot. After any change to Firefox or its extension you should run Speedyfox. (Mentioned later.)


Also make sure you have the latest versions of any adobe.com products you use like Shockwave, Flash or Acrobat.

Whether you use adobe reader, acrobat or fox-it to read pdf files you need to disable Javascript in the program. There is an exploit out there now that can use it to get on your PC. For Adobe Reader: Start, All Programs, Adobe Reader, Edit, Preferences, Click on Javascript in the left column and uncheck Enable Acrobat Javascript. OK Close program. It's the same for Foxit reader except you uncheck Enable Javascript Actions.

To help keep your programs up-to-date you should download and run the UpdateChecker:
http://www.filehippo.../updatechecker/
(You don't need to download Betas and if there is a program you don't use you can just uninstall it rather than update it. You can right click on the updatechecker icon (looks like a downward green arrowhead) and select Settings and tell it no betas. If you don't use MSN Messenger I would not upgdate it. MS installs a bunch of stuff when you do. You can tell the program to not show you that update.)
If you use Firefox or Chome then get the AdBlock Plus Add-on. WOT (Web of Trust) is another you might want to try.
The equivalent to AdBlock Plus for IE is called Simple Adblock and you should install it too: Adhttp://simple-adblock.com/

If Firefox is slow loading make sure it only has the current Java add-on. Then download and run Speedy Fox.
http://www.crystalidea.com/speedyfox . Click on Speedup my Firefox. When it finishes click on Exit.

Be warned: If you use Limewire, utorrent or any of the other P2P programs you will almost certain be coming back to the Malware Removal forum. If you must use P2P then submit any files you get to http://virustotal.com before you open them.

If you have a router, log on to it today and change the default password! If using a Wireless router you really should be using encryption on the link. Use the strongest (newest) encryption method that your router and PC wireless adapter support especially if you own a business. See http://www.king5.com...-120637284.html and http://www.seattlepi...ted-1344185.php for why encryption is important. If you don't know how, visit the router maker's website. They all have detailed step by step instructions or a wizard you can download.

Ron
  • 0

#5
Keman

Keman

    Member

  • Topic Starter
  • Member
  • PipPip
  • 36 posts
Again thank you so much and not just to you ron, but to all the helpers at geekstogo. You all are amazing to say the least. I will take all the steps you stated above and put them to good use.



PS: Thanks for your contribution to the internet society, becuase of this you have been awarded 100 internets!

Edited by Keman, 13 September 2011 - 09:13 AM.

  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP