PDA

View Full Version : Possible infection



davikut
2010-12-13, 06:28
Hi, my system used to restart automatically after I switched it on. I was also not able to hear sound. I formatted my computer a week ago thinking that it had been infected. I re-installed Windows and some necessary softwares.
But I'm still not able to hear sound. I checked and found that all the sound card drivers had been installed properly. I'm not sure whether there is some problem in the sound card or not.
Also after the formatting and re-install, the computer still restarts by itself at times. I've installed AVG Free 10 Antivirus in my computer and it didnt show any infection when scanned. Is my computer infected or is it some hardware problem? Here r my system's DDS logs...Thanks


DDS (Ver_10-12-12.02) - NTFSx86
Run by xp2 at 10:51:36.90 on Mon 12/13/2010
Internet Explorer: 6.0.2900.2180
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.223.68 [GMT 5.5:30]

AV: AVG Anti-Virus Free Edition 2011 *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}

============== Running Processes ===============

C:\PROGRA~1\AVG\AVG10\avgchsvx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\system32\VTtrayp.exe
D:\blubster\Blubster.exe
D:\blubster\BGCheck.exe
C:\Program Files\AVG\AVG10\avgwdsvc.exe
C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
C:\Program Files\AVG\AVG10\avgnsx.exe
C:\Program Files\AVG\AVG10\avgemcx.exe
C:\PROGRA~1\AVG\AVG10\avgrsx.exe
C:\Program Files\AVG\AVG10\avgcsrvx.exe
C:\Documents and Settings\xp2\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\xp2\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\xp2\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Program Files\7-Zip\7zFM.exe
D:\Setup Files\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.com/
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
mDefault_Search_URL = hxxp://www.google.com/ie
uInternet Connection Wizard,ShellNext = hxxp://www.google.com/
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.google.com/ie
mURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg10\toolbar\IEToolbar.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg10\avgssie.dll
BHO: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg10\toolbar\IEToolbar.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.2.4204.1700\swg.dll
BHO: PandoraTV Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
TB: PandoraTV Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - c:\program files\avg\avg10\toolbar\IEToolbar.dll
mRun: [VTTimer] VTTimer.exe
mRun: [VTTrayp] VTtrayp.exe
mRun: [Blubster] d:\blubster\Blubster.exe SILENT
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - c:\program files\avg\avg10\toolbar\IEToolbar.dll
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg10\avgpp.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\xp2\applic~1\mozilla\firefox\profiles\825jadpz.default\
FF - component: c:\documents and settings\all users\application data\google\toolbar for firefox\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - component: c:\documents and settings\all users\application data\google\toolbar for firefox\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbarloader.dll
FF - component: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\firefox\ext\components\nprpffbrowserrecordext.dll
FF - component: c:\program files\avg\avg10\firefox\components\avgssff.dll
FF - component: c:\program files\avg\avg10\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\avg\avg10\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\avg\avg10\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\avg\avg10\toolbar\firefox\avg@igeared\components\xpavgtbapi.dll
FF - plugin: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\mozillaplugins\nprphtml5videoshim.dll
FF - plugin: c:\documents and settings\xp2\local settings\application data\google\update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\google updater\2.4.2166.3772\npCIDetect14.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Google Toolbar for Firefox: {3112ca9c-de6d-4884-a869-9855de68056c} - c:\documents and settings\all users\application data\google\toolbar for firefox\{3112ca9c-de6d-4884-a869-9855de68056c}
FF - Ext: AVG Safe Search: {3f963a5b-e555-4543-90e2-c3908898db71} - c:\program files\avg\avg10\Firefox
FF - Ext: AVG Security Toolbar em:version=6.010.006.004 em:displayname=AVG Security Toolbar em:iconURL=chrome://tavgp/skin/logo.ico em:creator=AVG Technologies em:description=AVG Security Toolbar em:homepageURL=http://www.avg.com >: avg@igeared - c:\program files\avg\avg10\toolbar\firefox\avg@igeared
FF - Ext: RealPlayer Browser Record Plugin: {ABDE892B-13A8-4d1b-88E6-365A6E755758} - c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\firefox\Ext

============= SERVICES / DRIVERS ===============

R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [2010-9-13 25680]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2010-9-7 26064]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2010-9-7 249424]
R1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2010-9-7 34384]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [2010-9-7 299984]
R2 AVGIDSAgent;AVGIDSAgent;c:\program files\avg\avg10\identity protection\agent\bin\AVGIDSAgent.exe [2010-11-10 6127184]
R2 avgwd;AVG WatchDog;c:\program files\avg\avg10\avgwdsvc.exe [2010-10-22 265400]
R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [2010-8-19 123472]
R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [2010-8-19 30288]
R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [2010-8-19 26192]
S3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files\avg\avg10\toolbar\ToolbarBroker.exe [2010-12-12 517448]

=============== Created Last 30 ================

2010-12-12 16:53:12 -------- d-----w- c:\windows\system32\Adobe
2010-12-12 16:51:02 -------- d-----w- c:\docume~1\xp2\locals~1\applic~1\Adobe
2010-12-12 16:35:41 -------- d-----w- c:\docume~1\xp2\applic~1\r2 Studios
2010-12-12 16:35:41 -------- d-----w- c:\docume~1\alluse~1\applic~1\r2 Studios
2010-12-12 16:35:21 -------- d-----w- c:\program files\r2 Studios
2010-12-12 16:33:31 388096 ----a-r- c:\docume~1\xp2\applic~1\microsoft\installer\{45a66726-69bc-466b-a7a4-12fcba4883d7}\HiJackThis.exe
2010-12-12 16:33:27 -------- d-----w- c:\program files\Trend Micro
2010-12-12 16:31:39 -------- d-----w- c:\program files\HiJack This 2.0.4
2010-12-12 15:11:16 -------- d-----w- c:\docume~1\xp2\locals~1\applic~1\AVG Security Toolbar
2010-12-12 04:50:40 8192 ----a-w- c:\program files\mozilla firefox\plugins\nprjplug.dll
2010-12-12 04:50:05 140864 ----a-w- c:\program files\mozilla firefox\plugins\nppl3260.dll
2010-12-12 04:49:58 98304 ----a-w- c:\program files\mozilla firefox\plugins\nprpjplug.dll
2010-12-12 04:49:36 -------- d-----w- c:\program files\common files\xing shared
2010-12-12 04:48:37 569397 ----a-w- c:\program files\internet explorer\plugins\richfx\player\nprfxins.dll
2010-12-12 04:48:32 499712 ----a-w- c:\windows\system32\msvcp71.dll
2010-12-12 04:48:32 348160 ----a-w- c:\windows\system32\msvcr71.dll
2010-12-12 04:48:28 -------- d-----w- c:\program files\common files\Real
2010-12-12 04:39:11 -------- d-----w- c:\program files\VideoLAN
2010-12-12 03:48:42 -------- d-----w- c:\docume~1\xp2\applic~1\AVG10
2010-12-12 03:46:27 -------- d--h--w- c:\docume~1\alluse~1\applic~1\Common Files
2010-12-12 03:46:14 -------- d-----w- c:\docume~1\alluse~1\applic~1\AVG Security Toolbar
2010-12-12 03:44:56 -------- d-----w- c:\windows\system32\drivers\AVG
2010-12-12 03:44:56 -------- d-----w- c:\docume~1\alluse~1\applic~1\AVG10
2010-12-12 03:44:16 -------- d-----w- c:\program files\AVG
2010-12-12 03:42:23 -------- d-----w- c:\docume~1\alluse~1\applic~1\MFAData
2010-12-10 17:43:18 106496 ----a-w- c:\windows\system32\TwnLib20.dll
2010-12-10 17:43:15 476320 ------w- c:\windows\system32\ImagXpr7.dll
2010-12-10 17:43:15 471040 ------w- c:\windows\system32\ImagXRA7.dll
2010-12-10 17:43:15 364544 ------w- c:\windows\system32\TwnLib4.dll
2010-12-10 17:43:15 262144 ------w- c:\windows\system32\ImagXR7.dll
2010-12-10 17:43:14 1568768 ------w- c:\windows\system32\ImagX7.dll
2010-12-10 17:43:13 38912 ------w- c:\windows\system32\picn20.dll
2010-12-10 17:43:11 155648 ----a-w- c:\windows\system32\NeroCheck.exe
2010-12-10 17:20:05 -------- d-----w- c:\docume~1\xp2\locals~1\applic~1\Temp
2010-12-10 17:20:00 -------- d-----w- c:\docume~1\xp2\locals~1\applic~1\Google
2010-12-08 16:54:53 -------- d-----w- c:\docume~1\xp2\locals~1\applic~1\Mozilla
2010-12-08 16:38:14 -------- d-----w- c:\docume~1\xp2\locals~1\applic~1\AskToolbar
2010-12-07 13:10:03 3072 ----a-w- c:\windows\system32\drivers\audstub.sys
2010-12-07 13:09:31 57472 ----a-w- c:\windows\system32\drivers\redbook.sys
2010-12-07 13:08:41 74240 ----a-w- c:\windows\system32\usbui.dll
2010-12-07 13:08:35 44672 ----a-w- c:\windows\system32\drivers\UAGP35.SYS
2010-12-07 13:08:30 20992 ----a-w- c:\windows\system32\drivers\RTL8139.sys
2010-12-07 13:06:54 -------- d-----r- c:\documents and settings\all users\Documents
2010-12-07 13:05:21 13753 ----a-r- c:\windows\SET8.tmp
2010-12-07 13:05:18 1086058 ----a-r- c:\windows\SET4.tmp
2010-12-07 13:05:17 1042903 ----a-r- c:\windows\SET3.tmp
2010-12-07 13:05:11 -------- d-----w- c:\windows\system32\CatRoot2
2010-12-07 13:05:11 -------- d-----w- c:\windows\system32\CatRoot
2010-12-07 13:04:41 -------- d-----w- C:\Documents and Settings

==================== Find3M ====================

2010-12-07 09:52:38 14922996 ----a-w- c:\windows\system32\kmp_1431.exe

============= FINISH: 10:52:40.15 ===============

tashi
2010-12-21, 20:34
Reminder. :)


If you have waited four days or longer for assistance, please start a topic in this sub-forum and post with a link back to your topic in the Malware forum, so that we know who you are and your topic is not archived.

The Waiting Room (http://forums.spybot.info/forumdisplay.php?f=37)

Blade81
2010-12-23, 06:55
Hi,

Please post fresh dds logs.

Blade81
2010-12-29, 06:31
Still needing help?

Blade81
2011-01-04, 07:01
Due to inactivity, this thread will now be closed.

Note:If it has been three days or more since your last post, and the helper assisting you posted a response to that post to which you did not reply, your topic will not be reopened. At that point, if you still require help, please start a new topic and include a fresh DDS log and a link to your previous thread. Please do not add any logs that might have been requested in the closed topic, you would be starting fresh.

If it has been less than three days since your last response and you need the thread re-opened, please send me or other MOD a private message (pm). A valid, working link to the closed topic is required.