I have AVG 9.0.920. I am running Windows 7.
AVG will give popups saying c:\windows\system32\svchost.exe is infected with Win32/DH.CAFF8202BE. The Resident Shield Alert will show many entries for svchost.exe, but it doesn't give specific information, other than Win32/DH.CAFF8202BE.
I have noticed that there are 4 instances of iexplore.exe running in my Task Manager, but if I kill them, they just come back. So I am sure there is some malware/spyware at work, but I don't know how to stop it and get rid of it.
I have tried running AVG scan, HiJackThis, TDSSKiller, Combofix, and most recently OTL.
Thank you very much for your help.
Here is my OTL log:
OTL logfile created on: 11/21/2011 7:36:33 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\NEW
Enterprise Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.31 Gb Available Physical Memory | 65.32% Memory free
4.50 Gb Paging File | 3.82 Gb Available in Paging File | 84.86% Paging File free
Paging file location(s): [Binary data over 100 bytes]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 698.64 Gb Total Space | 6.04 Gb Free Space | 0.86% Space Free | Partition Type: NTFS
Drive E: | 465.76 Gb Total Space | 285.33 Gb Free Space | 61.26% Space Free | Partition Type: NTFS
Drive F: | 465.76 Gb Total Space | 5.76 Gb Free Space | 1.24% Space Free | Partition Type: NTFS
Drive G: | 114.49 Gb Total Space | 33.12 Gb Free Space | 28.93% Space Free | Partition Type: NTFS
Drive H: | 698.63 Gb Total Space | 3.79 Gb Free Space | 0.54% Space Free | Partition Type: NTFS
Computer Name: MAGIC | User Name: oh | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011/11/21 19:26:12 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\NEW\OTL.exe
PRC - [2011/06/23 23:22:20 | 000,271,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conhost.exe
PRC - [2011/01/05 19:37:52 | 000,136,128 | ---- | M] (JP Software) -- C:\TCMD\tcc.exe
PRC - [2010/11/20 16:29:20 | 002,640,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
========== Modules (No Company Name) ==========
MOD - [2011/01/05 19:38:12 | 000,294,128 | ---- | M] () -- C:\TCMD\onig.dll
========== Win32 Services (SafeList) ==========
SRV - [2011/06/06 11:55:28 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) [Auto | Stopped] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2011/05/25 02:21:15 | 001,343,400 | ---- | M] (Microsoft Corporation) [Unknown | Stopped] -- C:\Windows\System32\Wat\WatAdminSvc.exe -- (WatAdminSvc)
SRV - [2011/05/24 20:18:45 | 000,308,136 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Stopped] -- C:\Program Files\AVG\AVG9\avgwdsvc.exe -- (avg9wd)
SRV - [2011/05/24 20:18:34 | 000,921,952 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Stopped] -- C:\Program Files\AVG\AVG9\avgemc.exe -- (avg9emc)
SRV - [2010/12/01 21:19:32 | 001,696,496 | ---- | M] (RealVNC Ltd) [Auto | Stopped] -- C:\Program Files\RealVNC\VNC4\WinVNC4.exe -- (WinVNC4)
SRV - [2009/07/13 20:16:15 | 000,016,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\StorSvc.dll -- (StorSvc)
SRV - [2009/07/13 20:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009/07/13 20:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc)
SRV - [2009/07/13 20:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2007/11/15 09:09:42 | 000,121,360 | ---- | M] (Logitech, Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe -- (LBTServ)
========== Driver Services (SafeList) ==========
DRV - [2011/09/13 07:02:55 | 000,029,712 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Stopped] -- C:\Windows\System32\Drivers\avgmfx86.sys -- (AvgMfx86)
DRV - [2011/05/25 07:13:12 | 000,243,152 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\System32\Drivers\avgtdix.sys -- (AvgTdiX)
DRV - [2011/05/24 20:18:33 | 000,216,400 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Stopped] -- C:\Windows\System32\Drivers\avgldx86.sys -- (AvgLdx86)
DRV - [2011/05/24 20:18:28 | 000,052,872 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\System32\Drivers\avgrkx86.sys -- (AvgRkx86)
DRV - [2010/12/01 21:05:12 | 000,004,608 | ---- | M] (RealVNC Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vncmirror.sys -- (vncmirror)
DRV - [2010/11/20 16:29:34 | 000,015,872 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV - [2010/11/20 16:29:24 | 000,052,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV - [2010/11/20 16:29:03 | 000,175,360 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\vmbus.sys -- (vmbus)
DRV - [2010/11/20 16:29:03 | 000,112,640 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\tsusbhub.sys -- (tsusbhub)
DRV - [2010/11/20 16:29:03 | 000,077,184 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\Synth3dVsc.sys -- (Synth3dVsc)
DRV - [2010/11/20 16:29:03 | 000,062,464 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\dmvsc.sys -- (dmvsc)
DRV - [2010/11/20 16:29:03 | 000,040,704 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\drivers\vmstorfl.sys -- (storflt)
DRV - [2010/11/20 16:29:03 | 000,035,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WinUsb)
DRV - [2010/11/20 16:29:03 | 000,028,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\storvsc.sys -- (storvsc)
DRV - [2010/11/20 16:29:03 | 000,027,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV - [2010/11/20 16:29:03 | 000,025,600 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\terminpt.sys -- (terminpt)
DRV - [2010/11/20 16:29:03 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\VMBusHID.sys -- (VMBusHID)
DRV - [2010/11/20 16:29:03 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\vms3cap.sys -- (s3cap)
DRV - [2010/07/10 04:37:00 | 011,008,040 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2009/06/18 18:45:02 | 004,172,832 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\RTKVAC.SYS -- (ALCXWDM) Service for Realtek AC97 Audio (WDM)
DRV - [2008/08/20 10:27:36 | 000,019,240 | ---- | M] (Silicon Image, Inc) [Kernel | Boot | Running] -- C:\Windows\system32\drivers\SiWinAcc.sys -- (SiFilter)
DRV - [2008/08/20 10:27:26 | 000,015,400 | ---- | M] (Silicon Image, Inc) [Kernel | Boot | Running] -- C:\Windows\system32\drivers\SiRemFil.sys -- (SiRemFil)
DRV - [2008/08/20 10:27:08 | 000,074,280 | ---- | M] (Silicon Image, Inc) [Kernel | Boot | Running] -- C:\Windows\system32\drivers\SI3112.sys -- (SI3112)
DRV - [2008/07/22 06:42:58 | 000,051,200 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Rtnicxp.sys -- (RTL8023xp)
DRV - [2007/09/21 02:10:54 | 000,078,992 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\LMouKE.Sys -- (LMouKE)
DRV - [2007/09/21 02:10:46 | 000,036,240 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\LMouFilt.Sys -- (LMouFilt)
DRV - [2007/09/21 02:10:40 | 000,035,088 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\LHidFilt.Sys -- (LHidFilt)
DRV - [2007/09/21 02:10:26 | 000,063,120 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\L8042mou.Sys -- (L8042mou)
DRV - [2007/09/21 02:10:20 | 000,020,240 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\L8042Kbd.sys -- (L8042Kbd)
DRV - [2006/11/11 09:58:00 | 000,049,952 | ---- | M] (HighPoint Technologies, Inc.) [Kernel | Boot | Running] -- C:\Windows\system32\drivers\hpt3xx.sys -- (hpt3xx)
DRV - [2004/04/10 08:42:36 | 000,002,944 | ---- | M] ([email protected]) [Kernel | System | Stopped] -- C:\Windows\System32\mbmiodrvr.sys -- (mbmiodrvr)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\URLSearchHook: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - No CLSID value found
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.condui...&ctid=CT2786678
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-US
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = F6 61 E6 78 47 31 CC 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.update: false
FF - prefs.js..browser.startup.homepage: "http://www.google.com"
FF - prefs.js..extensions.enabledItems: {b01bf10c-302a-11da-b67b-000d60ca027b}:2.6.1
FF - prefs.js..flock.keyword.provider: "Google"
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@idsoftware.com/QuakeLive: C:\ProgramData\id Software\QuakeLive\npquakezero.dll (id Software Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=1.1.9: C:\Program Files\VideoLAN\VLC\npvlc.dll (the VideoLAN Team)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Users\oh\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Users\oh\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\oh\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\oh\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG9\Firefox [2011/09/13 07:04:25 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Flock 2.6.1\extensions\\Components: C:\Program Files\Flock\components [2011/05/25 03:27:51 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Flock 2.6.1\extensions\\Plugins: C:\Program Files\Flock\plugins [2011/11/13 22:02:01 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox 4.0 Beta 4\components [2011/10/01 13:56:39 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox 4.0 Beta 4\plugins
[2011/05/25 03:27:54 | 000,000,000 | ---D | M] (No name found) -- C:\Users\oh\AppData\Roaming\Mozilla\Extensions
[2011/05/25 03:27:54 | 000,000,000 | ---D | M] (No name found) -- C:\Users\oh\AppData\Roaming\Mozilla\Extensions\{a463f10c-3994-11da-9945-000d60ca027b}
[2011/11/13 15:38:11 | 000,000,000 | ---D | M] (No name found) -- C:\Users\oh\AppData\Roaming\Mozilla\Firefox\Profiles\p1vepw30.default\extensions
[2011/11/12 14:21:08 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\oh\AppData\Roaming\Mozilla\Firefox\Profiles\p1vepw30.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2011/11/09 18:18:12 | 000,000,000 | ---D | M] (uTorrentBar Community Toolbar) -- C:\Users\oh\AppData\Roaming\Mozilla\Firefox\Profiles\p1vepw30.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}
[2011/11/12 14:21:10 | 000,000,000 | ---D | M] (Greasemonkey) -- C:\Users\oh\AppData\Roaming\Mozilla\Firefox\Profiles\p1vepw30.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2011/06/28 19:03:51 | 000,000,000 | ---D | M] (Conduit Engine) -- C:\Users\oh\AppData\Roaming\Mozilla\Firefox\Profiles\p1vepw30.default\extensions\[email protected]
[2011/05/25 01:28:54 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2011/05/25 01:28:54 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2011/06/30 04:41:12 | 000,142,296 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2010/01/01 03:00:00 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\oh\AppData\Local\Google\Chrome\Application\15.0.874.121\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Java Deployment Toolkit 6.0.240.7 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java Platform SE 6 U24 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\oh\AppData\Local\Google\Chrome\Application\15.0.874.121\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\oh\AppData\Local\Google\Chrome\Application\15.0.874.121\pdf.dll
CHR - plugin: Google Talk Plugin (Enabled) = C:\Users\oh\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
CHR - plugin: Google Talk Plugin Video Accelerator (Enabled) = C:\Users\oh\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll
CHR - plugin: VLC Multimedia Plug-in (Enabled) = C:\Program Files\VideoLAN\VLC\npvlc.dll
CHR - plugin: QUAKE LIVE (Enabled) = C:\ProgramData\id Software\QuakeLive\npquakezero.dll
CHR - plugin: Google Update (Enabled) = C:\Users\oh\AppData\Local\Google\Update\1.3.21.69\npGoogleUpdate3.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: uTorrentBar = C:\Users\oh\AppData\Local\Google\Chrome\User Data\Default\Extensions\bejbohlohkkgompgecdcbbglkpjfjgdj\2.3.0.15_0\
CHR - Extension: Adblock Plus for Google Chrome\u2122 (Beta) = C:\Users\oh\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.1.4_0\
CHR - Extension: Social Fixer = C:\Users\oh\AppData\Local\Google\Chrome\User Data\Default\Extensions\ipjaijdkhejnbfpodmofannadgfokfnm\6.201_0\
O1 HOSTS File: ([2011/05/24 19:31:51 | 000,030,237 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 68.167.161.182 Hades
O1 - Hosts: 68.167.161.178 [bleep]
O1 - Hosts: 68.167.161.179 Magic
O1 - Hosts: 68.167.161.180 Mist
O1 - Hosts: 68.167.161.181 Fire
O1 - Hosts: 68.167.161.182 www.doubleclick.net
O1 - Hosts: 68.167.161.182 ad.preferances.com
O1 - Hosts: 68.167.161.182 ad.doubleclick.com
O1 - Hosts: 68.167.161.182 ads.web.aol.com
O1 - Hosts: 68.167.161.182 ad.preferences.com
O1 - Hosts: 68.167.161.182 ad.washingtonpost.com
O1 - Hosts: 68.167.161.182 adpick.switchboard.com
O1 - Hosts: 68.167.161.182 ads.doubleclick.com
O1 - Hosts: 68.167.161.182 ads.infospace.com
O1 - Hosts: 68.167.161.182 ads.msn.com
O1 - Hosts: 68.167.161.182 ads.switchboard.com
O1 - Hosts: 68.167.161.182 ads.enliven.com
O1 - Hosts: 68.167.161.182 oz.valueclick.com
O1 - Hosts: 68.167.161.182 ads.doubleclick.net
O1 - Hosts: 68.167.161.182 ad2.doubleclick.net
O1 - Hosts: 68.167.161.182 ad3.doubleclick.net
O1 - Hosts: 68.167.161.182 ad4.doubleclick.net
O1 - Hosts: 68.167.161.182 ad5.doubleclick.net
O1 - Hosts: 68.167.161.182 ad6.doubleclick.net
O1 - Hosts: 68.167.161.182 ad7.doubleclick.net
O1 - Hosts: 752 more lines...
O4 - HKLM..\Run: [AVG9_TRAY] C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [Kernel and Hardware Abstraction Layer] C:\Windows\KHALMNPR.Exe (Logitech, Inc.)
O4 - HKLM..\Run: [Logitech Hardware Abstraction Layer] C:\Windows\KHALMNPR.Exe (Logitech, Inc.)
O4 - HKLM..\Run: [SoundMan] C:\Windows\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
O4 - HKCU..\Run: [uTorrent] C:\Program Files\uTorrent\uTorrent.exe (BitTorrent, Inc.)
O4 - Startup: C:\Users\oh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Launch TightVNC Server.lnk = File not found
O4 - Startup: C:\Users\oh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\tcmd.exe + autoexec.btm - Shortcut.lnk = C:\TCMD\tcmd.exe (JP Software)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_29)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{06981283-E60C-4913-856A-AC3852073764}: NameServer = 64.105.199.75,208.67.220.220
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - AppInit_DLLs: (C:\Windows\System32\avgrsstx.dll) -C:\Windows\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) -C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - Winlogon\Notify\LBTWlgn: DllName - (c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll) - c:\Program Files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O20 - Winlogon\Notify\WgaLogon: DllName - (Reg Error: Value error.) - Reg Error: Value error. File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 16:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2011/05/09 13:53:54 | 000,000,000 | ---- | M] () - F:\autorun.ini -- [ NTFS ]
O32 - AutoRun File - [2003/12/31 19:02:05 | 000,000,000 | ---- | M] () - G:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2010/11/15 15:22:15 | 000,000,098 | ---- | M] () - G:\autorun.ini -- [ NTFS ]
O32 - AutoRun File - [2011/05/24 13:40:55 | 000,000,000 | ---- | M] () - H:\autorun.ini -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/11/21 19:09:52 | 000,000,000 | ---D | C] -- C:\virus2011
[2011/11/21 18:05:40 | 000,000,000 | ---D | C] -- C:\Windows\Minidump
[2011/11/21 17:38:31 | 000,000,000 | --SD | C] -- C:\ComboFix
[2011/11/20 19:02:19 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java
[2011/11/20 18:51:48 | 000,000,000 | ---D | C] -- C:\Users\oh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HiJackThis
[2011/11/20 18:51:46 | 000,000,000 | ---D | C] -- C:\Program Files\HiJackThis
[2011/11/20 17:10:05 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2011/11/20 17:10:05 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2011/11/20 17:10:05 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2011/11/20 17:09:52 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2011/11/20 17:09:26 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011/11/20 16:59:20 | 004,303,424 | R--- | C] (Swearware) -- C:\Users\oh\Desktop\ComboFix.exe
[2011/11/20 16:38:23 | 000,000,000 | ---D | C] -- C:\Windows\Sun
[2011/11/16 18:37:46 | 000,000,000 | ---D | C] -- C:\testing
[2011/10/28 17:34:08 | 000,000,000 | ---D | C] -- C:\Users\oh\AppData\Roaming\dvdcss
[2011/10/28 16:57:15 | 000,000,000 | ---D | C] -- C:\Users\oh\Documents\DVDFab
[2011/10/28 16:49:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDFab HD Decrypter
[2011/10/28 16:49:30 | 000,000,000 | ---D | C] -- C:\Program Files\DVDFab HD Decrypter 4
[2011/10/25 19:53:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\id Software
[2011/10/25 19:53:26 | 000,000,000 | ---D | C] -- C:\ProgramData\id Software
[2 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
[11 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[11 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/11/21 19:35:33 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011/11/21 19:35:27 | 1610,256,384 | -HS- | M] () -- C:\hiberfil.sys
[2011/11/21 19:33:58 | 000,019,712 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/11/21 19:33:58 | 000,019,712 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/11/21 19:19:54 | 000,615,122 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2011/11/21 19:19:54 | 000,103,496 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2011/11/21 18:52:06 | 000,000,896 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-814184897-3768303927-2348027941-1001UA.job
[2011/11/21 18:10:29 | 089,416,955 | ---- | M] () -- C:\Windows\System32\drivers\Avg\incavi.avm
[2011/11/21 17:34:50 | 004,303,424 | R--- | M] (Swearware) -- C:\Users\oh\Desktop\ComboFix.exe
[2011/11/20 22:52:03 | 000,000,844 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-814184897-3768303927-2348027941-1001Core.job
[2011/11/20 19:16:20 | 000,266,864 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2011/11/20 18:51:49 | 000,002,971 | ---- | M] () -- C:\Users\oh\Desktop\HiJackThis.lnk
[2011/11/18 17:54:32 | 000,002,403 | ---- | M] () -- C:\Users\oh\Desktop\Google Chrome.lnk
[2011/11/03 20:03:17 | 000,093,780 | ---- | M] () -- C:\Letter of Recommendation - Suzanne - noname.eml
[2011/11/02 20:13:20 | 000,002,166 | ---- | M] () -- C:\Users\oh\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox 4.0 Beta 4.lnk
[2011/10/28 16:49:33 | 000,001,112 | ---- | M] () -- C:\Users\oh\Application Data\Microsoft\Internet Explorer\Quick Launch\DVDFab HD Decrypter 4.lnk
[2011/10/28 16:49:33 | 000,001,088 | ---- | M] () -- C:\Users\oh\Desktop\DVDFab HD Decrypter 4.lnk
[2 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
[11 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[11 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/11/20 18:51:49 | 000,002,971 | ---- | C] () -- C:\Users\oh\Desktop\HiJackThis.lnk
[2011/11/20 17:10:05 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2011/11/20 17:10:05 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2011/11/20 17:10:05 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2011/11/20 17:10:05 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2011/11/20 17:10:05 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2011/11/03 20:02:24 | 000,093,780 | ---- | C] () -- C:\Letter of Recommendation - Suzanne - noname.eml
[2011/10/28 16:49:33 | 000,001,112 | ---- | C] () -- C:\Users\oh\Application Data\Microsoft\Internet Explorer\Quick Launch\DVDFab HD Decrypter 4.lnk
[2011/10/28 16:49:33 | 000,001,088 | ---- | C] () -- C:\Users\oh\Desktop\DVDFab HD Decrypter 4.lnk
[2011/09/21 06:27:35 | 000,921,600 | ---- | C] () -- C:\Windows\System32\vorbisenc.dll
[2011/09/21 06:27:35 | 000,237,568 | ---- | C] () -- C:\Windows\System32\OggDS.dll
[2011/09/21 06:27:35 | 000,188,416 | ---- | C] () -- C:\Windows\System32\vorbis.dll
[2011/09/21 06:27:35 | 000,045,056 | ---- | C] () -- C:\Windows\System32\ogg.dll
[2011/07/26 16:03:34 | 000,000,083 | ---- | C] () -- C:\Users\oh\AppData\Roaming\sversion.ini
[2011/07/26 16:01:52 | 000,069,632 | ---- | C] () -- C:\Windows\uinst001.exe
[2011/07/07 20:17:17 | 000,026,112 | ---- | C] () -- C:\Windows\System32\VNCpm.dll
[2011/06/10 13:19:51 | 001,481,728 | ---- | C] () -- C:\Windows\System32\LegitCheckControl.dll
[2011/06/06 08:27:20 | 000,667,136 | ---- | C] () -- C:\Windows\System32\OGACheckControl.dll
[2011/06/06 08:27:18 | 000,414,208 | ---- | C] () -- C:\Windows\System32\WgaTray.exe
[2011/06/06 08:27:18 | 000,190,976 | ---- | C] () -- C:\Windows\System32\WgaLogon.dll
[2011/05/31 21:25:28 | 000,650,752 | ---- | C] () -- C:\Windows\System32\xvidcore.dll
[2011/05/31 21:25:28 | 000,240,640 | ---- | C] () -- C:\Windows\System32\xvidvfw.dll
[2011/05/25 03:27:55 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat
[2011/05/24 18:28:56 | 000,049,152 | ---- | C] () -- C:\Windows\System32\ChCfg.exe
[2011/05/24 18:28:03 | 000,000,164 | ---- | C] () -- C:\Windows\avrack.ini
[2010/11/20 16:29:34 | 000,080,896 | ---- | C] () -- C:\Windows\System32\RDVGHelper.exe
[2010/11/20 16:29:26 | 000,066,048 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe
[2010/11/20 16:29:20 | 002,616,320 | ---- | C] () -- C:\Windows\expl.dat
[2010/11/20 16:29:20 | 000,286,720 | ---- | C] () -- C:\Windows\System32\winl.dat
[2010/11/20 16:29:20 | 000,020,992 | ---- | C] () -- C:\Windows\System32\svch.dat
[2009/07/13 23:57:37 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009/07/13 23:33:53 | 000,266,864 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2009/07/13 21:05:48 | 000,615,122 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2009/07/13 21:05:48 | 000,291,294 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2009/07/13 21:05:48 | 000,103,496 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2009/07/13 21:05:48 | 000,031,548 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2009/07/13 21:05:05 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2009/07/13 21:04:11 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2009/07/13 18:55:01 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009/07/13 18:51:43 | 000,073,728 | ---- | C] () -- C:\Windows\System32\BthpanContextHandler.dll
[2009/07/13 18:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\System32\BWContextHandler.dll
[2009/06/10 16:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
[2009/04/14 06:43:32 | 000,154,144 | ---- | C] () -- C:\Windows\System32\RTLCPAPI.dll
[2005/09/27 11:15:46 | 000,235,144 | ---- | C] () -- C:\Windows\System32\SetAid.dll
[2001/01/23 22:31:18 | 000,151,552 | ---- | C] () -- C:\Windows\System32\prntfix.exe
[2000/04/14 15:50:02 | 000,343,040 | ---- | C] () -- C:\Windows\System32\Lffpx7.dll
[1998/06/11 12:08:06 | 000,095,232 | ---- | C] () -- C:\Windows\System32\Lfkodak.dll
========== LOP Check ==========
[2011/11/02 19:31:23 | 000,000,000 | ---D | M] -- C:\Users\oh\AppData\Roaming\BSW
[2011/07/09 18:16:43 | 000,000,000 | ---D | M] -- C:\Users\oh\AppData\Roaming\EAC
[2011/11/20 18:13:45 | 000,000,000 | ---D | M] -- C:\Users\oh\AppData\Roaming\EditPlus 3
[2011/05/25 03:27:40 | 000,000,000 | ---D | M] -- C:\Users\oh\AppData\Roaming\Flock
[2011/05/24 20:12:03 | 000,000,000 | ---D | M] -- C:\Users\oh\AppData\Roaming\LockHunter
[2011/11/21 19:33:45 | 000,000,000 | ---D | M] -- C:\Users\oh\AppData\Roaming\uTorrent
[2009/07/13 23:53:46 | 000,010,144 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
< End of report >