Hello, I Use internet Explorer And When I Use google & other common search engines they redirect to other sites when i click the link. When i realized this started happening i scanned my computer with Spybot S&D And I Found A Couple Of Viruses. I removed all of the viruses and i continued to be redirected. So I scanned again. I Found A virus that i also found the first time which it had said that it had been removed, Its called (pornis.hlpr). I Deleted the virus with Spybot S&D and scanned again. And to my suprise, it was there AGAIN. I Repeated Scanning And Removing 3 times and the virus kept coming back and my browser is still being redirected. I Have Also Noticed Another Weird Thing Which i Dont know too much about, I Opened Ctrl+Alt+delete and looked at processes. I Found Over 15 Processes Named mshta.exe and about 7-10 processes named svchost.exe. If Someone Can Give Me Instructions To Fix The Browser Redirect, Stop the virus pornis.hlpr and explain what svchost.exe and mshta.exe are that would be amazing.
I Have Windows XP, Spybot Search and Destroy 1.6.2.46. I scanned with AVG and nothing came up and I Would Like The Instructions That You Give me to be Detailed And Very Easy To Follow.
I Followed The Instrictions on "Read before you Post" And Used ERUNT, I Also Have The DDS. Ill Attatch The "ATTATCH" Txt File in a Zip file and copy and paste the dds Here:
DDS (Ver_10-12-12.02) - NTFSx86
Run by Paul G at 22:21:12.06 on 28/12/2010
Internet Explorer: 7.0.5730.11
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2046.907 [GMT -5:00]
AV: AVG Internet Security *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: AVG Firewall *Enabled*
============== Running Processes ===============
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
svchost.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
svchost.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\AVG\AVG9\avgtray.exe
C:\Program Files\Windows Live\Messenger\msnmsgr .exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Steam\Steam.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\AVG\AVG9\Identity Protection\agent\bin\avgidsmonitor.exe
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\AVG\AVG9\avgfws9.exe
C:\WINDOWS\SYSTEM32\bgsvcgen.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\system32\crypserv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\MioNet\jvm\bin\MioNet.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\WINDOWS\System32\mshta.exe
C:\Documents and Settings\Paul G\Local Settings\Temporary Internet Files\Content.IE5\01AOORYI\dds[1].scr
C:\Program Files\Skype\Toolbars\Shared\SkypeNames2.exe
============== Pseudo HJT Report ===============
uLocal Page = hxxp://www.google.com/
uStart Page = hxxp://www.facebook.com/?ref=hp
uSearch Page = hxxp://www.google.com/
mDefault_Page_URL = hxxp://www.google.com/
mDefault_Search_URL = hxxp://www.google.com/
mSearch Page = hxxp://www.google.com
mStart Page = hxxp://www.google.com
mSearchAssistant = hxxp://www.google.com
mCustomizeSearch = hxxp://www.google.com/
uURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg9\toolbar\IEToolbar.dll
mURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg9\toolbar\IEToolbar.dll
uWinlogon: Shell=c:\documents and settings\paul g\application data\antispy.exe
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: Freecause Toolbar BHO: {6955fb38-7614-4a87-95c5-626ccea88df7} - c:\program files\webs credits\Toolbar.dll
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: Zynga Toolbar: {7b13ec3e-999a-4b70-b9cb-2617b8323822} - c:\program files\zynga\tbZyn0.dll
BHO: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg9\toolbar\IEToolbar.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Skype add-on for Internet Explorer: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.6.5805.1910\swg.dll
BHO: DCA BHO: {b49699fc-1665-4414-a1cb-c4a2a4a13eec} - c:\program files\common files\freecause\dca\dca-bho.dll__BHODemonDisabled
BHO: FrostWire Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll__BHODemonDisabled
BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\program files\yahoo!\companion\installs\cpn\YTSingleInstance.dll__BHODemonDisabled
TB: TextAloud: {f053c368-5458-45b2-9b4d-d8914bdddbff} - c:\progra~1\textal~1\TAForIE.dll
TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll
TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - c:\program files\avg\avg9\toolbar\IEToolbar.dll
TB: Webs Credits: {d09588aa-5560-4240-b2f2-774d78d7e917} - c:\program files\webs credits\Toolbar.dll
TB: Zynga Toolbar: {7b13ec3e-999a-4b70-b9cb-2617b8323822} - c:\program files\zynga\tbZyn0.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
TB: FrostWire Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
uRun: [DellSupport] "c:\program files\dellsupport\DSAgnt.exe" /startup
uRun: [OM2_Monitor] "c:\program files\olympus\olympus master 2\MMonitor .exe" -NoStart
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr .exe" /background
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [Steam] "c:\program files\steam\Steam.exe" -silent
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
mRun: [dla] c:\windows\system32\dla\tfswctrl.exe
mRun: [MAAgent] c:\program files\markany\contentsafer\MAAgent.exe
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [MioNet] c:\program files\mionet\MioNetLauncher.exe /p
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [download] "c:\documents and settings\marianneg\application data\download2\svcnost.exe"
mRun: [romxecswan.tmp] "c:\docume~1\marian~1\locals~1\temp\romxecswan.tmp"
mRun: [Ncine] rundll32.exe "c:\windows\akinotudokawas.dll",Startup
mRun: [AVG9_TRAY] c:\progra~1\avg\avg9\avgtray.exe
mExplorerRun: [lsjyn] c:\docume~1\marian~1\locals~1\temp\jl5n037.exe
StartupFolder: c:\docume~1\paulg~1\startm~1\programs\startup\Internet.lnk -
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\nkbmon~1.lnk - c:\program files\nikon\pictureproject\NkbMonitor.exe
IE: E&xport to Microsoft Excel - c:\progra~1\mi1933~1\office11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE}
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\mi1933~1\office11\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
DPF: {140E4DF8-9E14-4A34-9577-C77561ED7883} - hxxp://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_cyri_4.1.71.0.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/0/5/7/05796dde-b2ba-4eef-8da4-f99c7e0c9b92/LegitCheckControl.cab
DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} - hxxps://www-secure.symantec.com/techsupp/asa/LSSupCtl.cab
DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper200711281.dll
DPF: {3DCEC959-378A-4922-AD7E-FD5C925D927F} - hxxp://disney.go.com/pirates/online/testActiveX/built/signed/DisneyOnlineGames.cab
DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} - hxxp://www.costcophotocenter.com/CostcoActivia.cab
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} - hxxps://www-secure.symantec.com/techsupp/asa/ctrl/SymAData.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {D54160C3-DB7B-4534-9B65-190EE4A9C7F7} - hxxp://download.games.yahoo.com/games/web_games/gamehouse/frenzy/SproutLauncher.cab
DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} - hxxp://download.games.yahoo.com/games/web_games/tikgames/cinematycoon/cinematycoon.cab
DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - hxxp://download.games.yahoo.com/games/web_games/popcap/insaniquarium/popcaploader_v6.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {E6F480FC-BD44-4CBA-B74A-89AF7842937D} - hxxp://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_cyri_4.3.1.0.cab
DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} - hxxp://gfx2.hotmail.com/mail/w4/pr01/photouploadcontrol/MSNPUpld.cab
DPF: {F127B9BA-89EA-4B04-9C67-2074A9DF61FD} - hxxp://costco.pnimedia.com/upload/activex/v2_0_0_9/PCAXSetupv2.0.0.9.cab?
DPF: {F137B9BA-89EA-4B04-9C67-2074A9DF61FD} - hxxp://costco.pnimedia.com/upload/activex/v2_0_0_10/PCAXSetupv2.0.0.10.cab?
TCP: NameServer = 208.67.220.220,208.67.222.222
TCP: {FEA9C020-82EE-40A0-8A3F-B41E53C66A37} = 208.67.220.220,208.67.222.222
Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - c:\program files\avg\avg9\toolbar\IEToolbar.dll
Handler: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - c:\program files\hp\hpcoretech\comp\hpuiprot.dll
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: AtiExtEvent - Ati2evxx.dll
Notify: avgrsstarter - avgrsstx.dll
AppInit_DLLs: cru629.dat,
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\window~4\MpShHook.dll
SEH: ShellHook Class: {88485281-8b4b-4f8d-9ede-82e29a064277} - c:\progra~1\markany\conten~1\MACSMA~1.DLL
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll
LSA: Authentication Packages = msv1_0 vtursr.dll
Hosts: 127.0.0.1 www.spywareinfo.com
============= SERVICES / DRIVERS ===============
R0 AVGIDSErHrxpx;AVG9IDSErHr;c:\windows\system32\drivers\AVGIDSxx.sys [2010-12-12 25168]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-8-8 216400]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2006-12-28 29584]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2008-8-28 243024]
R2 avg9wd;AVG Free WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2010-12-27 308136]
R2 avgfws9;AVG Firewall;c:\program files\avg\avg9\avgfws9.exe [2010-12-27 2331544]
R2 AVGIDSAgent;AVG9IDSAgent;c:\program files\avg\avg9\identity protection\agent\bin\AVGIDSAgent.exe [2010-12-27 5897808]
R3 Avgfwdx;Avgfwdx;c:\windows\system32\drivers\avgfwdx.sys [2010-12-12 30104]
R3 AVGIDSDriverxpx;AVG9IDSDriver;c:\program files\avg\avg9\identity protection\agent\driver\platform_xp\AVGIDSDriver.sys [2010-12-12 122448]
R3 AVGIDSFilterxpx;AVG9IDSFilter;c:\program files\avg\avg9\identity protection\agent\driver\platform_xp\AVGIDSFilter.sys [2010-12-12 30288]
R3 AVGIDSShimxpx;AVG9IDSShim;c:\program files\avg\avg9\identity protection\agent\driver\platform_xp\AVGIDSShim.sys [2010-12-12 26192]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2009-12-18 135664]
S3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files\avg\avg9\toolbar\ToolbarBroker.exe [2010-10-26 517448]
S3 Avgfwfd;AVG network filter service;c:\windows\system32\drivers\avgfwdx.sys [2010-12-12 30104]
S3 cpuz132;cpuz132;\??\c:\docume~1\paul\locals~1\temp\cpuz132\cpuz132_x32.sys --> c:\docume~1\paul\locals~1\temp\cpuz132\cpuz132_x32.sys [?]
S3 jnv4_mib;jnv4_mib;\??\c:\docume~1\michael\locals~1\temp\jnv4_mib.sys --> c:\docume~1\michael\locals~1\temp\jnv4_mib.sys [?]
S3 PID_0920;Logitech QuickCam Express(PID_0920);c:\windows\system32\drivers\LV532AV.SYS [2007-2-14 152576]
S4 MioNet;MioNet;c:\program files\mionet\MioNetManager.exe [2008-6-10 139264]
S4 RogersSelfHelpService;Rogers SHS Service;c:\program files\rogers\selfhealing\RogersSelfHelpService.exe [2010-6-3 139264]
S4 RogersUpdateManager;Rogers Update Manager;c:\program files\rogers\update manager\RogersUpdateManager.exe [2010-6-3 163840]
S4 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592]
=============== Created Last 30 ================
2073-10-27 14:55:34 2404352 ----a-w- c:\program files\microsoft games\halo custom edition\haloce.exe
2073-10-27 14:55:34 1835008 ----a-w- c:\program files\microsoft games\halo custom edition\haloceded.exe
2073-10-27 14:55:34 1118208 ----a-w- c:\program files\microsoft games\halo custom edition\Strings.dll
2072-07-31 21:44:42 375808 ----a-w- c:\program files\microsoft games\halo\binkw32.dll
2010-12-27 16:27:12 -------- d-----w- c:\docume~1\paulg~1\applic~1\AVG9
2010-12-27 16:22:01 12536 ----a-w- c:\windows\system32\avgrsstx.dll
2010-12-25 20:00:16 -------- d-----w- c:\program files\Aiseesoft Studio
2010-12-23 19:26:38 116224 ----a-w- c:\windows\system32\dllcache\xrxwiadr.dll
2010-12-23 19:26:32 23040 ----a-w- c:\windows\system32\dllcache\xrxwbtmp.dll
2010-12-23 19:26:31 18944 ----a-w- c:\windows\system32\dllcache\xrxscnui.dll
2010-12-23 19:26:25 27648 ----a-w- c:\windows\system32\dllcache\xrxftplt.exe
2010-12-23 19:26:19 4608 ----a-w- c:\windows\system32\dllcache\xrxflnch.exe
2010-12-23 19:26:06 99865 ----a-w- c:\windows\system32\dllcache\xlog.exe
2010-12-23 19:25:50 16970 ----a-w- c:\windows\system32\dllcache\xem336n5.sys
2010-12-23 19:25:48 19455 ----a-w- c:\windows\system32\dllcache\wvchntxx.sys
2010-12-23 19:25:40 12063 ----a-w- c:\windows\system32\dllcache\wsiintxx.sys
2010-12-23 19:25:38 8192 ----a-w- c:\windows\system32\dllcache\wshirda.dll
2010-12-23 19:25:14 8832 ----a-w- c:\windows\system32\dllcache\wmiacpi.sys
2010-12-23 19:25:10 154624 ----a-w- c:\windows\system32\dllcache\wlluc48.sys
2010-12-23 19:25:04 34890 ----a-w- c:\windows\system32\dllcache\wlandrv2.sys
2010-12-23 19:23:58 19016 ----a-w- c:\windows\system32\dllcache\w926nd.sys
2010-12-23 19:23:53 19528 ----a-w- c:\windows\system32\dllcache\w840nd.sys
2010-12-23 19:23:52 48256 ----a-w- c:\windows\system32\dllcache\w32.dll
2010-12-23 19:23:47 64605 ----a-w- c:\windows\system32\dllcache\vvoice.sys
2010-12-23 19:23:41 397502 ----a-w- c:\windows\system32\dllcache\vpctcom.sys
2010-12-23 19:23:34 604253 ----a-w- c:\windows\system32\dllcache\vmodem.sys
2010-12-23 19:23:28 249402 ----a-w- c:\windows\system32\dllcache\vinwm.sys
2010-12-23 19:23:23 24576 ----a-w- c:\windows\system32\dllcache\viairda.sys
2010-12-23 19:23:15 687999 ----a-w- c:\windows\system32\dllcache\usrwdxjs.sys
2010-12-23 19:23:09 765884 ----a-w- c:\windows\system32\dllcache\usrti.sys
2010-12-23 19:23:04 113762 ----a-w- c:\windows\system32\dllcache\usrpda.sys
2010-12-23 19:21:57 22912 ----a-w- c:\windows\system32\dllcache\umaxpcls.sys
2010-12-23 19:21:51 50176 ----a-w- c:\windows\system32\dllcache\umaxp60.dll
2010-12-23 19:21:46 47616 ----a-w- c:\windows\system32\dllcache\umaxcam.dll
2010-12-23 19:21:41 211968 ----a-w- c:\windows\system32\dllcache\um54scan.dll
2010-12-23 19:21:36 216064 ----a-w- c:\windows\system32\dllcache\um34scan.dll
2010-12-23 19:21:30 11520 ----a-w- c:\windows\system32\dllcache\twotrack.sys
2010-12-23 19:21:29 14336 ----a-w- c:\windows\system32\dllcache\tsprof.exe
2010-12-23 19:21:21 166784 ----a-w- c:\windows\system32\dllcache\tridxpm.sys
2010-12-23 19:21:16 525568 ----a-w- c:\windows\system32\dllcache\tridxp.dll
2010-12-23 19:21:11 159232 ----a-w- c:\windows\system32\dllcache\tridkbm.sys
2010-12-23 19:19:56 81408 ----a-w- c:\windows\system32\dllcache\tgiul50.dll
2010-12-23 19:18:58 10240 ----a-w- c:\windows\system32\dllcache\swpidflt.dll
2010-12-23 19:18:53 10240 ----a-w- c:\windows\system32\dllcache\swpdflt2.dll
2010-12-23 19:18:48 53760 ----a-w- c:\windows\system32\dllcache\sw_wheel.dll
2010-12-23 19:18:43 41472 ----a-w- c:\windows\system32\dllcache\sw_effct.dll
2010-12-23 19:18:37 155648 ----a-w- c:\windows\system32\dllcache\stlnprop.dll
2010-12-23 19:18:32 53248 ----a-w- c:\windows\system32\dllcache\stlncoin.dll
2010-12-23 19:18:27 285760 ----a-w- c:\windows\system32\dllcache\stlnata.sys
2010-12-23 19:18:22 16896 ----a-w- c:\windows\system32\dllcache\stcusb.sys
2010-12-23 19:18:15 48736 ----a-w- c:\windows\system32\dllcache\srwlnd5.sys
2010-12-23 19:18:10 99328 ----a-w- c:\windows\system32\dllcache\srusd.dll
2010-12-23 19:18:09 101376 ----a-w- c:\windows\system32\dllcache\srusbusd.dll
2010-12-23 19:18:02 24660 ----a-w- c:\windows\system32\dllcache\spxupchk.dll
2010-12-23 19:16:59 25034 ----a-w- c:\windows\system32\dllcache\smcpwr2n.sys
2010-12-23 19:15:57 50432 ----a-w- c:\windows\system32\dllcache\sisv.sys
2010-12-23 19:14:55 6784 ----a-w- c:\windows\system32\dllcache\serscan.sys
2010-12-23 19:13:58 77824 ----a-w- c:\windows\system32\dllcache\s3sav4m.sys
2010-12-23 19:12:57 19017 ----a-w- c:\windows\system32\dllcache\rtl8029.sys
2010-12-23 19:12:52 30720 ----a-w- c:\windows\system32\dllcache\rthwcls.sys
2010-12-23 19:12:47 9216 ----a-w- c:\windows\system32\dllcache\rsmgrstr.dll
2010-12-23 19:12:41 3840 ----a-w- c:\windows\system32\dllcache\rpfun.sys
2010-12-23 19:12:38 79104 ----a-w- c:\windows\system32\dllcache\rocket.sys
2010-12-23 19:12:31 37563 ----a-w- c:\windows\system32\dllcache\rlnet5.sys
2010-12-23 19:12:26 86097 ----a-w- c:\windows\system32\dllcache\reslog32.dll
2010-12-23 19:12:24 23040 ----a-w- c:\windows\system32\dllcache\EXCH_regtrace.exe
2010-12-23 19:12:23 14848 ----a-w- c:\windows\system32\dllcache\register.exe
2010-12-23 19:12:10 19584 ----a-w- c:\windows\system32\dllcache\rasirda.sys
2010-12-23 19:12:04 714762 ----a-w- c:\windows\system32\dllcache\r2mdmkxx.sys
2010-12-23 19:12:00 899146 ----a-w- c:\windows\system32\dllcache\r2mdkxga.sys
2010-12-23 19:10:59 7168 ----a-w- c:\windows\system32\dllcache\pnrmc.sys
2010-12-23 19:09:58 30282 ----a-w- c:\windows\system32\dllcache\pcntn5hl.sys
2010-12-23 19:08:58 54186 ----a-w- c:\windows\system32\dllcache\otcsercb.sys
2010-12-23 19:07:56 32840 ----a-w- c:\windows\system32\dllcache\ngrpci.sys
2010-12-23 19:06:56 75520 ----a-w- c:\windows\system32\dllcache\mxport.sys
2010-12-23 19:06:52 7168 ----a-w- c:\windows\system32\dllcache\mxport.dll
2010-12-23 19:06:48 19968 ----a-w- c:\windows\system32\dllcache\mxnic.sys
2010-12-23 19:06:44 19968 ----a-w- c:\windows\system32\dllcache\mxicfg.dll
2010-12-23 19:06:40 21888 ----a-w- c:\windows\system32\dllcache\mxcard.sys
2010-12-23 19:06:35 103296 ----a-w- c:\windows\system32\dllcache\mtxvideo.sys
2010-12-23 19:06:26 49024 ----a-w- c:\windows\system32\dllcache\mstape.sys
2010-12-23 19:06:20 12416 ----a-w- c:\windows\system32\dllcache\msriffwv.sys
2010-12-23 19:06:13 2944 ----a-w- c:\windows\system32\dllcache\msmpu401.sys
2010-12-23 19:06:11 22016 ----a-w- c:\windows\system32\dllcache\msircomm.sys
2010-12-23 19:06:02 35200 ----a-w- c:\windows\system32\dllcache\msgame.sys
2010-12-23 19:04:59 48768 ----a-w- c:\windows\system32\dllcache\maestro.sys
2010-12-23 19:03:56 19016 ----a-w- c:\windows\system32\dllcache\ktc111.sys
2010-12-23 19:02:56 13056 ----a-w- c:\windows\system32\dllcache\inport.sys
2010-12-23 19:01:59 28700 ----a-w- c:\windows\system32\dllcache\ibmexmp.sys
2010-12-23 19:00:58 19456 ----a-w- c:\windows\system32\dllcache\hr1w.dll
2010-12-23 18:59:59 8576 ----a-w- c:\windows\system32\dllcache\hidgame.sys
2010-12-23 18:58:58 27165 ----a-w- c:\windows\system32\dllcache\fetnd5.sys
2010-12-23 18:57:59 51200 ----a-w- c:\windows\system32\dllcache\eqnlogr.exe
2010-12-23 18:57:57 53248 ----a-w- c:\windows\system32\dllcache\eqndiag.exe
2010-12-23 18:57:55 629952 ----a-w- c:\windows\system32\dllcache\eqn.sys
2010-12-23 18:57:53 114944 ----a-w- c:\windows\system32\dllcache\epstw2k.sys
2010-12-23 18:57:51 18503 ----a-w- c:\windows\system32\dllcache\epro4.sys
2010-12-23 18:57:49 144896 ----a-w- c:\windows\system32\dllcache\epcfw2k.sys
2010-12-23 18:57:47 6400 ----a-w- c:\windows\system32\dllcache\enum1394.sys
2010-12-23 18:57:46 283904 ----a-w- c:\windows\system32\dllcache\emu10k1m.sys
2010-12-23 18:57:40 19996 ----a-w- c:\windows\system32\dllcache\em556n4.sys
2010-12-23 18:57:39 25159 ----a-w- c:\windows\system32\dllcache\elnk3.sys
2010-12-23 18:57:37 7296 ----a-w- c:\windows\system32\dllcache\elmsmc.sys
2010-12-23 18:57:36 171520 ----a-w- c:\windows\system32\dllcache\el99xn51.sys
2010-12-23 18:57:34 70174 ----a-w- c:\windows\system32\dllcache\el98xn5.sys
2010-12-23 02:11:58 12928 ----a-w- c:\windows\system32\dllcache\dot4prt.sys
2010-12-23 02:10:58 24064 ----a-w- c:\windows\system32\dllcache\devldr32.exe
2010-12-23 02:09:59 60970 ----a-w- c:\windows\system32\dllcache\cpqtrnd5.sys
2010-12-23 02:08:43 13824 ----a-w- c:\windows\system32\dllcache\bulltlp3.sys
2010-12-23 02:07:58 23552 ----a-w- c:\windows\system32\dllcache\atixbar.sys
2010-12-23 02:06:40 66048 ----a-w- c:\windows\system32\dllcache\s3legacy.dll
2010-12-23 01:57:57 20 ----a-w- c:\windows\AKINOTUDOKAWAS.DLL
2010-12-19 22:48:52 -------- d-----w- c:\program files\NCH Software
2010-12-19 22:11:24 -------- d-----w- c:\docume~1\paulg~1\locals~1\applic~1\AskToolbar
2010-12-19 21:49:58 -------- d-----w- c:\docume~1\paulg~1\applic~1\FrostWire
2010-12-19 21:48:26 -------- d-----w- c:\program files\Ask.com
2010-12-19 21:48:16 -------- d-----w- c:\program files\FrostWire
2010-12-15 23:04:18 472808 ----a-w- c:\windows\system32\deployJava1.dll
2010-12-14 17:56:20 -------- d-----w- c:\program files\Steam
2010-12-12 19:39:21 25168 ----a-w- c:\windows\system32\drivers\AVGIDSxx.sys
2010-12-12 19:38:21 50968 ----a-w- c:\windows\system32\avgfwdx.dll
2010-12-12 19:38:21 30104 ----a-w- c:\windows\system32\drivers\avgfwdx.sys
2010-12-06 20:40:43 0 ----a-w- c:\windows\Kqomamo.bin
==================== Find3M ====================
2010-12-15 23:04:04 73728 ----a-w- c:\windows\system32\javacpl.cpl
2010-10-24 22:34:22 447752 ----a-w- c:\windows\system32\vp6vfw.dll
2009-07-31 19:01:39 10331 ----a-w- c:\program files\common files\wuwi.com
=================== ROOTKIT ====================
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 5.1.2600 Disk: ST3500418AS rev.CC34 -> Harddisk0\DR0 -> \Device\Ide\IdePort1 P1T0L0-e
device: opened successfully
user: MBR read successfully
Disk trace:
kernel: MBR read successfully
_asm { CLI ; MOV AX, 0x0; MOV SS, AX; MOV SP, 0x7c00; STI ; MOV DS, AX; CLD ; MOV CX, 0x80; MOV SI, SP; MOV DI, 0x600; MOV ES, AX; REP MOVSD ; JMP FAR 0x0:0x62f; }
detected disk devices:
\Device\Ide\IdeDeviceP1T0L0-e -> \??\IDE#DiskST3500418AS_____________________________CC34____#5&139d26ec&0&0.0.0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b} device not found
detected hooks:
\Driver\atapi DriverStartIo -> 0x8A8ABAEA
user & kernel MBR OK
sectors 976773166 (+255): user != kernel
============= FINISH: 22:30:44.82 ===============
Thanks! :thanks: :crowned:
I Have Windows XP, Spybot Search and Destroy 1.6.2.46. I scanned with AVG and nothing came up and I Would Like The Instructions That You Give me to be Detailed And Very Easy To Follow.
I Followed The Instrictions on "Read before you Post" And Used ERUNT, I Also Have The DDS. Ill Attatch The "ATTATCH" Txt File in a Zip file and copy and paste the dds Here:
DDS (Ver_10-12-12.02) - NTFSx86
Run by Paul G at 22:21:12.06 on 28/12/2010
Internet Explorer: 7.0.5730.11
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2046.907 [GMT -5:00]
AV: AVG Internet Security *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: AVG Firewall *Enabled*
============== Running Processes ===============
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
svchost.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
svchost.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\AVG\AVG9\avgtray.exe
C:\Program Files\Windows Live\Messenger\msnmsgr .exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Steam\Steam.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\AVG\AVG9\Identity Protection\agent\bin\avgidsmonitor.exe
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\AVG\AVG9\avgfws9.exe
C:\WINDOWS\SYSTEM32\bgsvcgen.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\system32\crypserv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\MioNet\jvm\bin\MioNet.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\WINDOWS\System32\mshta.exe
C:\Documents and Settings\Paul G\Local Settings\Temporary Internet Files\Content.IE5\01AOORYI\dds[1].scr
C:\Program Files\Skype\Toolbars\Shared\SkypeNames2.exe
============== Pseudo HJT Report ===============
uLocal Page = hxxp://www.google.com/
uStart Page = hxxp://www.facebook.com/?ref=hp
uSearch Page = hxxp://www.google.com/
mDefault_Page_URL = hxxp://www.google.com/
mDefault_Search_URL = hxxp://www.google.com/
mSearch Page = hxxp://www.google.com
mStart Page = hxxp://www.google.com
mSearchAssistant = hxxp://www.google.com
mCustomizeSearch = hxxp://www.google.com/
uURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg9\toolbar\IEToolbar.dll
mURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg9\toolbar\IEToolbar.dll
uWinlogon: Shell=c:\documents and settings\paul g\application data\antispy.exe
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: Freecause Toolbar BHO: {6955fb38-7614-4a87-95c5-626ccea88df7} - c:\program files\webs credits\Toolbar.dll
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: Zynga Toolbar: {7b13ec3e-999a-4b70-b9cb-2617b8323822} - c:\program files\zynga\tbZyn0.dll
BHO: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg9\toolbar\IEToolbar.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Skype add-on for Internet Explorer: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.6.5805.1910\swg.dll
BHO: DCA BHO: {b49699fc-1665-4414-a1cb-c4a2a4a13eec} - c:\program files\common files\freecause\dca\dca-bho.dll__BHODemonDisabled
BHO: FrostWire Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll__BHODemonDisabled
BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\program files\yahoo!\companion\installs\cpn\YTSingleInstance.dll__BHODemonDisabled
TB: TextAloud: {f053c368-5458-45b2-9b4d-d8914bdddbff} - c:\progra~1\textal~1\TAForIE.dll
TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll
TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - c:\program files\avg\avg9\toolbar\IEToolbar.dll
TB: Webs Credits: {d09588aa-5560-4240-b2f2-774d78d7e917} - c:\program files\webs credits\Toolbar.dll
TB: Zynga Toolbar: {7b13ec3e-999a-4b70-b9cb-2617b8323822} - c:\program files\zynga\tbZyn0.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
TB: FrostWire Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
uRun: [DellSupport] "c:\program files\dellsupport\DSAgnt.exe" /startup
uRun: [OM2_Monitor] "c:\program files\olympus\olympus master 2\MMonitor .exe" -NoStart
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr .exe" /background
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [Steam] "c:\program files\steam\Steam.exe" -silent
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
mRun: [dla] c:\windows\system32\dla\tfswctrl.exe
mRun: [MAAgent] c:\program files\markany\contentsafer\MAAgent.exe
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [MioNet] c:\program files\mionet\MioNetLauncher.exe /p
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [download] "c:\documents and settings\marianneg\application data\download2\svcnost.exe"
mRun: [romxecswan.tmp] "c:\docume~1\marian~1\locals~1\temp\romxecswan.tmp"
mRun: [Ncine] rundll32.exe "c:\windows\akinotudokawas.dll",Startup
mRun: [AVG9_TRAY] c:\progra~1\avg\avg9\avgtray.exe
mExplorerRun: [lsjyn] c:\docume~1\marian~1\locals~1\temp\jl5n037.exe
StartupFolder: c:\docume~1\paulg~1\startm~1\programs\startup\Internet.lnk -
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\nkbmon~1.lnk - c:\program files\nikon\pictureproject\NkbMonitor.exe
IE: E&xport to Microsoft Excel - c:\progra~1\mi1933~1\office11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE}
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\mi1933~1\office11\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
DPF: {140E4DF8-9E14-4A34-9577-C77561ED7883} - hxxp://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_cyri_4.1.71.0.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/0/5/7/05796dde-b2ba-4eef-8da4-f99c7e0c9b92/LegitCheckControl.cab
DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} - hxxps://www-secure.symantec.com/techsupp/asa/LSSupCtl.cab
DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper200711281.dll
DPF: {3DCEC959-378A-4922-AD7E-FD5C925D927F} - hxxp://disney.go.com/pirates/online/testActiveX/built/signed/DisneyOnlineGames.cab
DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} - hxxp://www.costcophotocenter.com/CostcoActivia.cab
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} - hxxps://www-secure.symantec.com/techsupp/asa/ctrl/SymAData.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {D54160C3-DB7B-4534-9B65-190EE4A9C7F7} - hxxp://download.games.yahoo.com/games/web_games/gamehouse/frenzy/SproutLauncher.cab
DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} - hxxp://download.games.yahoo.com/games/web_games/tikgames/cinematycoon/cinematycoon.cab
DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - hxxp://download.games.yahoo.com/games/web_games/popcap/insaniquarium/popcaploader_v6.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {E6F480FC-BD44-4CBA-B74A-89AF7842937D} - hxxp://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_cyri_4.3.1.0.cab
DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} - hxxp://gfx2.hotmail.com/mail/w4/pr01/photouploadcontrol/MSNPUpld.cab
DPF: {F127B9BA-89EA-4B04-9C67-2074A9DF61FD} - hxxp://costco.pnimedia.com/upload/activex/v2_0_0_9/PCAXSetupv2.0.0.9.cab?
DPF: {F137B9BA-89EA-4B04-9C67-2074A9DF61FD} - hxxp://costco.pnimedia.com/upload/activex/v2_0_0_10/PCAXSetupv2.0.0.10.cab?
TCP: NameServer = 208.67.220.220,208.67.222.222
TCP: {FEA9C020-82EE-40A0-8A3F-B41E53C66A37} = 208.67.220.220,208.67.222.222
Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - c:\program files\avg\avg9\toolbar\IEToolbar.dll
Handler: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - c:\program files\hp\hpcoretech\comp\hpuiprot.dll
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: AtiExtEvent - Ati2evxx.dll
Notify: avgrsstarter - avgrsstx.dll
AppInit_DLLs: cru629.dat,
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\window~4\MpShHook.dll
SEH: ShellHook Class: {88485281-8b4b-4f8d-9ede-82e29a064277} - c:\progra~1\markany\conten~1\MACSMA~1.DLL
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll
LSA: Authentication Packages = msv1_0 vtursr.dll
Hosts: 127.0.0.1 www.spywareinfo.com
============= SERVICES / DRIVERS ===============
R0 AVGIDSErHrxpx;AVG9IDSErHr;c:\windows\system32\drivers\AVGIDSxx.sys [2010-12-12 25168]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-8-8 216400]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2006-12-28 29584]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2008-8-28 243024]
R2 avg9wd;AVG Free WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2010-12-27 308136]
R2 avgfws9;AVG Firewall;c:\program files\avg\avg9\avgfws9.exe [2010-12-27 2331544]
R2 AVGIDSAgent;AVG9IDSAgent;c:\program files\avg\avg9\identity protection\agent\bin\AVGIDSAgent.exe [2010-12-27 5897808]
R3 Avgfwdx;Avgfwdx;c:\windows\system32\drivers\avgfwdx.sys [2010-12-12 30104]
R3 AVGIDSDriverxpx;AVG9IDSDriver;c:\program files\avg\avg9\identity protection\agent\driver\platform_xp\AVGIDSDriver.sys [2010-12-12 122448]
R3 AVGIDSFilterxpx;AVG9IDSFilter;c:\program files\avg\avg9\identity protection\agent\driver\platform_xp\AVGIDSFilter.sys [2010-12-12 30288]
R3 AVGIDSShimxpx;AVG9IDSShim;c:\program files\avg\avg9\identity protection\agent\driver\platform_xp\AVGIDSShim.sys [2010-12-12 26192]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2009-12-18 135664]
S3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files\avg\avg9\toolbar\ToolbarBroker.exe [2010-10-26 517448]
S3 Avgfwfd;AVG network filter service;c:\windows\system32\drivers\avgfwdx.sys [2010-12-12 30104]
S3 cpuz132;cpuz132;\??\c:\docume~1\paul\locals~1\temp\cpuz132\cpuz132_x32.sys --> c:\docume~1\paul\locals~1\temp\cpuz132\cpuz132_x32.sys [?]
S3 jnv4_mib;jnv4_mib;\??\c:\docume~1\michael\locals~1\temp\jnv4_mib.sys --> c:\docume~1\michael\locals~1\temp\jnv4_mib.sys [?]
S3 PID_0920;Logitech QuickCam Express(PID_0920);c:\windows\system32\drivers\LV532AV.SYS [2007-2-14 152576]
S4 MioNet;MioNet;c:\program files\mionet\MioNetManager.exe [2008-6-10 139264]
S4 RogersSelfHelpService;Rogers SHS Service;c:\program files\rogers\selfhealing\RogersSelfHelpService.exe [2010-6-3 139264]
S4 RogersUpdateManager;Rogers Update Manager;c:\program files\rogers\update manager\RogersUpdateManager.exe [2010-6-3 163840]
S4 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592]
=============== Created Last 30 ================
2073-10-27 14:55:34 2404352 ----a-w- c:\program files\microsoft games\halo custom edition\haloce.exe
2073-10-27 14:55:34 1835008 ----a-w- c:\program files\microsoft games\halo custom edition\haloceded.exe
2073-10-27 14:55:34 1118208 ----a-w- c:\program files\microsoft games\halo custom edition\Strings.dll
2072-07-31 21:44:42 375808 ----a-w- c:\program files\microsoft games\halo\binkw32.dll
2010-12-27 16:27:12 -------- d-----w- c:\docume~1\paulg~1\applic~1\AVG9
2010-12-27 16:22:01 12536 ----a-w- c:\windows\system32\avgrsstx.dll
2010-12-25 20:00:16 -------- d-----w- c:\program files\Aiseesoft Studio
2010-12-23 19:26:38 116224 ----a-w- c:\windows\system32\dllcache\xrxwiadr.dll
2010-12-23 19:26:32 23040 ----a-w- c:\windows\system32\dllcache\xrxwbtmp.dll
2010-12-23 19:26:31 18944 ----a-w- c:\windows\system32\dllcache\xrxscnui.dll
2010-12-23 19:26:25 27648 ----a-w- c:\windows\system32\dllcache\xrxftplt.exe
2010-12-23 19:26:19 4608 ----a-w- c:\windows\system32\dllcache\xrxflnch.exe
2010-12-23 19:26:06 99865 ----a-w- c:\windows\system32\dllcache\xlog.exe
2010-12-23 19:25:50 16970 ----a-w- c:\windows\system32\dllcache\xem336n5.sys
2010-12-23 19:25:48 19455 ----a-w- c:\windows\system32\dllcache\wvchntxx.sys
2010-12-23 19:25:40 12063 ----a-w- c:\windows\system32\dllcache\wsiintxx.sys
2010-12-23 19:25:38 8192 ----a-w- c:\windows\system32\dllcache\wshirda.dll
2010-12-23 19:25:14 8832 ----a-w- c:\windows\system32\dllcache\wmiacpi.sys
2010-12-23 19:25:10 154624 ----a-w- c:\windows\system32\dllcache\wlluc48.sys
2010-12-23 19:25:04 34890 ----a-w- c:\windows\system32\dllcache\wlandrv2.sys
2010-12-23 19:23:58 19016 ----a-w- c:\windows\system32\dllcache\w926nd.sys
2010-12-23 19:23:53 19528 ----a-w- c:\windows\system32\dllcache\w840nd.sys
2010-12-23 19:23:52 48256 ----a-w- c:\windows\system32\dllcache\w32.dll
2010-12-23 19:23:47 64605 ----a-w- c:\windows\system32\dllcache\vvoice.sys
2010-12-23 19:23:41 397502 ----a-w- c:\windows\system32\dllcache\vpctcom.sys
2010-12-23 19:23:34 604253 ----a-w- c:\windows\system32\dllcache\vmodem.sys
2010-12-23 19:23:28 249402 ----a-w- c:\windows\system32\dllcache\vinwm.sys
2010-12-23 19:23:23 24576 ----a-w- c:\windows\system32\dllcache\viairda.sys
2010-12-23 19:23:15 687999 ----a-w- c:\windows\system32\dllcache\usrwdxjs.sys
2010-12-23 19:23:09 765884 ----a-w- c:\windows\system32\dllcache\usrti.sys
2010-12-23 19:23:04 113762 ----a-w- c:\windows\system32\dllcache\usrpda.sys
2010-12-23 19:21:57 22912 ----a-w- c:\windows\system32\dllcache\umaxpcls.sys
2010-12-23 19:21:51 50176 ----a-w- c:\windows\system32\dllcache\umaxp60.dll
2010-12-23 19:21:46 47616 ----a-w- c:\windows\system32\dllcache\umaxcam.dll
2010-12-23 19:21:41 211968 ----a-w- c:\windows\system32\dllcache\um54scan.dll
2010-12-23 19:21:36 216064 ----a-w- c:\windows\system32\dllcache\um34scan.dll
2010-12-23 19:21:30 11520 ----a-w- c:\windows\system32\dllcache\twotrack.sys
2010-12-23 19:21:29 14336 ----a-w- c:\windows\system32\dllcache\tsprof.exe
2010-12-23 19:21:21 166784 ----a-w- c:\windows\system32\dllcache\tridxpm.sys
2010-12-23 19:21:16 525568 ----a-w- c:\windows\system32\dllcache\tridxp.dll
2010-12-23 19:21:11 159232 ----a-w- c:\windows\system32\dllcache\tridkbm.sys
2010-12-23 19:19:56 81408 ----a-w- c:\windows\system32\dllcache\tgiul50.dll
2010-12-23 19:18:58 10240 ----a-w- c:\windows\system32\dllcache\swpidflt.dll
2010-12-23 19:18:53 10240 ----a-w- c:\windows\system32\dllcache\swpdflt2.dll
2010-12-23 19:18:48 53760 ----a-w- c:\windows\system32\dllcache\sw_wheel.dll
2010-12-23 19:18:43 41472 ----a-w- c:\windows\system32\dllcache\sw_effct.dll
2010-12-23 19:18:37 155648 ----a-w- c:\windows\system32\dllcache\stlnprop.dll
2010-12-23 19:18:32 53248 ----a-w- c:\windows\system32\dllcache\stlncoin.dll
2010-12-23 19:18:27 285760 ----a-w- c:\windows\system32\dllcache\stlnata.sys
2010-12-23 19:18:22 16896 ----a-w- c:\windows\system32\dllcache\stcusb.sys
2010-12-23 19:18:15 48736 ----a-w- c:\windows\system32\dllcache\srwlnd5.sys
2010-12-23 19:18:10 99328 ----a-w- c:\windows\system32\dllcache\srusd.dll
2010-12-23 19:18:09 101376 ----a-w- c:\windows\system32\dllcache\srusbusd.dll
2010-12-23 19:18:02 24660 ----a-w- c:\windows\system32\dllcache\spxupchk.dll
2010-12-23 19:16:59 25034 ----a-w- c:\windows\system32\dllcache\smcpwr2n.sys
2010-12-23 19:15:57 50432 ----a-w- c:\windows\system32\dllcache\sisv.sys
2010-12-23 19:14:55 6784 ----a-w- c:\windows\system32\dllcache\serscan.sys
2010-12-23 19:13:58 77824 ----a-w- c:\windows\system32\dllcache\s3sav4m.sys
2010-12-23 19:12:57 19017 ----a-w- c:\windows\system32\dllcache\rtl8029.sys
2010-12-23 19:12:52 30720 ----a-w- c:\windows\system32\dllcache\rthwcls.sys
2010-12-23 19:12:47 9216 ----a-w- c:\windows\system32\dllcache\rsmgrstr.dll
2010-12-23 19:12:41 3840 ----a-w- c:\windows\system32\dllcache\rpfun.sys
2010-12-23 19:12:38 79104 ----a-w- c:\windows\system32\dllcache\rocket.sys
2010-12-23 19:12:31 37563 ----a-w- c:\windows\system32\dllcache\rlnet5.sys
2010-12-23 19:12:26 86097 ----a-w- c:\windows\system32\dllcache\reslog32.dll
2010-12-23 19:12:24 23040 ----a-w- c:\windows\system32\dllcache\EXCH_regtrace.exe
2010-12-23 19:12:23 14848 ----a-w- c:\windows\system32\dllcache\register.exe
2010-12-23 19:12:10 19584 ----a-w- c:\windows\system32\dllcache\rasirda.sys
2010-12-23 19:12:04 714762 ----a-w- c:\windows\system32\dllcache\r2mdmkxx.sys
2010-12-23 19:12:00 899146 ----a-w- c:\windows\system32\dllcache\r2mdkxga.sys
2010-12-23 19:10:59 7168 ----a-w- c:\windows\system32\dllcache\pnrmc.sys
2010-12-23 19:09:58 30282 ----a-w- c:\windows\system32\dllcache\pcntn5hl.sys
2010-12-23 19:08:58 54186 ----a-w- c:\windows\system32\dllcache\otcsercb.sys
2010-12-23 19:07:56 32840 ----a-w- c:\windows\system32\dllcache\ngrpci.sys
2010-12-23 19:06:56 75520 ----a-w- c:\windows\system32\dllcache\mxport.sys
2010-12-23 19:06:52 7168 ----a-w- c:\windows\system32\dllcache\mxport.dll
2010-12-23 19:06:48 19968 ----a-w- c:\windows\system32\dllcache\mxnic.sys
2010-12-23 19:06:44 19968 ----a-w- c:\windows\system32\dllcache\mxicfg.dll
2010-12-23 19:06:40 21888 ----a-w- c:\windows\system32\dllcache\mxcard.sys
2010-12-23 19:06:35 103296 ----a-w- c:\windows\system32\dllcache\mtxvideo.sys
2010-12-23 19:06:26 49024 ----a-w- c:\windows\system32\dllcache\mstape.sys
2010-12-23 19:06:20 12416 ----a-w- c:\windows\system32\dllcache\msriffwv.sys
2010-12-23 19:06:13 2944 ----a-w- c:\windows\system32\dllcache\msmpu401.sys
2010-12-23 19:06:11 22016 ----a-w- c:\windows\system32\dllcache\msircomm.sys
2010-12-23 19:06:02 35200 ----a-w- c:\windows\system32\dllcache\msgame.sys
2010-12-23 19:04:59 48768 ----a-w- c:\windows\system32\dllcache\maestro.sys
2010-12-23 19:03:56 19016 ----a-w- c:\windows\system32\dllcache\ktc111.sys
2010-12-23 19:02:56 13056 ----a-w- c:\windows\system32\dllcache\inport.sys
2010-12-23 19:01:59 28700 ----a-w- c:\windows\system32\dllcache\ibmexmp.sys
2010-12-23 19:00:58 19456 ----a-w- c:\windows\system32\dllcache\hr1w.dll
2010-12-23 18:59:59 8576 ----a-w- c:\windows\system32\dllcache\hidgame.sys
2010-12-23 18:58:58 27165 ----a-w- c:\windows\system32\dllcache\fetnd5.sys
2010-12-23 18:57:59 51200 ----a-w- c:\windows\system32\dllcache\eqnlogr.exe
2010-12-23 18:57:57 53248 ----a-w- c:\windows\system32\dllcache\eqndiag.exe
2010-12-23 18:57:55 629952 ----a-w- c:\windows\system32\dllcache\eqn.sys
2010-12-23 18:57:53 114944 ----a-w- c:\windows\system32\dllcache\epstw2k.sys
2010-12-23 18:57:51 18503 ----a-w- c:\windows\system32\dllcache\epro4.sys
2010-12-23 18:57:49 144896 ----a-w- c:\windows\system32\dllcache\epcfw2k.sys
2010-12-23 18:57:47 6400 ----a-w- c:\windows\system32\dllcache\enum1394.sys
2010-12-23 18:57:46 283904 ----a-w- c:\windows\system32\dllcache\emu10k1m.sys
2010-12-23 18:57:40 19996 ----a-w- c:\windows\system32\dllcache\em556n4.sys
2010-12-23 18:57:39 25159 ----a-w- c:\windows\system32\dllcache\elnk3.sys
2010-12-23 18:57:37 7296 ----a-w- c:\windows\system32\dllcache\elmsmc.sys
2010-12-23 18:57:36 171520 ----a-w- c:\windows\system32\dllcache\el99xn51.sys
2010-12-23 18:57:34 70174 ----a-w- c:\windows\system32\dllcache\el98xn5.sys
2010-12-23 02:11:58 12928 ----a-w- c:\windows\system32\dllcache\dot4prt.sys
2010-12-23 02:10:58 24064 ----a-w- c:\windows\system32\dllcache\devldr32.exe
2010-12-23 02:09:59 60970 ----a-w- c:\windows\system32\dllcache\cpqtrnd5.sys
2010-12-23 02:08:43 13824 ----a-w- c:\windows\system32\dllcache\bulltlp3.sys
2010-12-23 02:07:58 23552 ----a-w- c:\windows\system32\dllcache\atixbar.sys
2010-12-23 02:06:40 66048 ----a-w- c:\windows\system32\dllcache\s3legacy.dll
2010-12-23 01:57:57 20 ----a-w- c:\windows\AKINOTUDOKAWAS.DLL
2010-12-19 22:48:52 -------- d-----w- c:\program files\NCH Software
2010-12-19 22:11:24 -------- d-----w- c:\docume~1\paulg~1\locals~1\applic~1\AskToolbar
2010-12-19 21:49:58 -------- d-----w- c:\docume~1\paulg~1\applic~1\FrostWire
2010-12-19 21:48:26 -------- d-----w- c:\program files\Ask.com
2010-12-19 21:48:16 -------- d-----w- c:\program files\FrostWire
2010-12-15 23:04:18 472808 ----a-w- c:\windows\system32\deployJava1.dll
2010-12-14 17:56:20 -------- d-----w- c:\program files\Steam
2010-12-12 19:39:21 25168 ----a-w- c:\windows\system32\drivers\AVGIDSxx.sys
2010-12-12 19:38:21 50968 ----a-w- c:\windows\system32\avgfwdx.dll
2010-12-12 19:38:21 30104 ----a-w- c:\windows\system32\drivers\avgfwdx.sys
2010-12-06 20:40:43 0 ----a-w- c:\windows\Kqomamo.bin
==================== Find3M ====================
2010-12-15 23:04:04 73728 ----a-w- c:\windows\system32\javacpl.cpl
2010-10-24 22:34:22 447752 ----a-w- c:\windows\system32\vp6vfw.dll
2009-07-31 19:01:39 10331 ----a-w- c:\program files\common files\wuwi.com
=================== ROOTKIT ====================
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 5.1.2600 Disk: ST3500418AS rev.CC34 -> Harddisk0\DR0 -> \Device\Ide\IdePort1 P1T0L0-e
device: opened successfully
user: MBR read successfully
Disk trace:
kernel: MBR read successfully
_asm { CLI ; MOV AX, 0x0; MOV SS, AX; MOV SP, 0x7c00; STI ; MOV DS, AX; CLD ; MOV CX, 0x80; MOV SI, SP; MOV DI, 0x600; MOV ES, AX; REP MOVSD ; JMP FAR 0x0:0x62f; }
detected disk devices:
\Device\Ide\IdeDeviceP1T0L0-e -> \??\IDE#DiskST3500418AS_____________________________CC34____#5&139d26ec&0&0.0.0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b} device not found
detected hooks:
\Driver\atapi DriverStartIo -> 0x8A8ABAEA
user & kernel MBR OK
sectors 976773166 (+255): user != kernel
============= FINISH: 22:30:44.82 ===============
Thanks! :thanks: :crowned: