I noticed my computer has been crashing a lot more often in the past couple days than before, including some blue screen errors, and I got concerned. I did an S&D search and several serious looking items came up, including Win32.VB.du, Win32.Banker.prx, Win32.Autorun.dso, and a mention that my browser was infected with Win32.agent.adb. I tried running Malwarebytes, but it would usually crash midway through the scan, although I did get it to work in Safe Mode once, where it didn't find much. I used the Chameleon settings to get it to scan out of safe mode, but it didn't find anything. Spybot tends to lock up on its scan three files from the end. I use Microsoft Security Essentials, but that's also been crashing without warning lately, including during scans, and it doesn't find anything either.
I try to remove things with Spybot, but it says the resources are in use, and asks if it can run when I restart. I tried it, but it bluescreened at the end of its scan. I tried to install another antivirus like Avast, but it bluescreened at the end of installation then refused to start the program when it restarted. I tried the Outpost Security Suite, but it locked up during its initial scan and some fonts disappeared, then when I tried to restart in safe mode, the program wouldn't load. Then the computer wouldn't boot at all, so I had to go back into safe mode and uninstall the security suite, then it booted alright.
I've tried a few times to get rid of these things with Spybot, but they keep coming back... I'm worried something's seriously wrong. Here are the logs.
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 10.7.2
Run by Zarla at 21:11:44 on 2012-09-30
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3199.1297 [GMT -7:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
c:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\WiFiConnector\NintendoWFCReg.exe
C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe
C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWare.exe
C:\Program Files\Last.fm\LastFMHelper.exe
C:\Program Files\Stickies\stickies.exe
svchost.exe
C:\Program Files\Java\jre7\bin\jqs.exe
C:\Program Files\CDBurnerXP\NMSAccessU.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\Wacom_Tablet.exe
C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe
C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe
C:\WINDOWS\system32\WTablet\Wacom_TabletUser.exe
C:\WINDOWS\system32\Wacom_Tablet.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\Program Files\Winamp5\winamp.exe
C:\Program Files\Last.fm\LastFM.exe
C:\Program Files\Taskbar Shuffle\taskbarshuffle.exe
C:\Program Files\Steam\Steam.exe
.
============== Pseudo HJT Report ===============
.
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre7\bin\ssv.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre7\bin\jp2ssv.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [PinnacleDriverCheck] c:\windows\system32\PSDrvCheck.exe -CheckReg
mRun: [PHIME2002ASync] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /SYNC
mRun: [PHIME2002A] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /IMEName
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [IMJPMIG8.1] "c:\windows\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
mRunOnce: [1] c:\program files\malwarebytes' anti-malware\chameleon\mbam-chameleon.exe /r /p
StartupFolder: c:\docume~1\zarla\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
StartupFolder: c:\docume~1\zarla\startm~1\programs\startup\lastfm~1.lnk - c:\program files\last.fm\LastFMHelper.exe
StartupFolder: c:\docume~1\zarla\startm~1\programs\startup\stickies.lnk - c:\program files\stickies\stickies.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\runnin~1.lnk - c:\program files\wificonnector\NintendoWFCReg.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\wddmst~1.lnk - c:\program files\western digital\wd smartware\wd drive manager\WDDMStatus.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\wdsmar~1.lnk - c:\program files\western digital\wd smartware\front parlor\WDSmartWare.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://windowsupdate.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1344119090125
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1344119235656
TCP: DhcpNameServer = 192.168.1.254
TCP: Interfaces\{3E885F99-6B75-4C9E-AFC6-346B05F06238} : DhcpNameServer = 192.168.1.254
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: AtiExtEvent - Ati2evxx.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\zarla\application data\mozilla\firefox\profiles\jf4tt3qn.transferringover\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com
FF - prefs.js: network.proxy.type - 4
FF - component: c:\documents and settings\zarla\application data\mozilla\firefox\profiles\jf4tt3qn.transferringover\extensions\{463f6ca5-ee3c-4be1-b7e6-7fee11953374}\platform\winnt\components\FoxyTunes.10.dll
FF - component: c:\documents and settings\zarla\application data\mozilla\firefox\profiles\jf4tt3qn.transferringover\extensions\{463f6ca5-ee3c-4be1-b7e6-7fee11953374}\platform\winnt\components\FoxyTunes.11.dll
FF - component: c:\documents and settings\zarla\application data\mozilla\firefox\profiles\jf4tt3qn.transferringover\extensions\{463f6ca5-ee3c-4be1-b7e6-7fee11953374}\platform\winnt\components\FoxyTunes.12.dll
FF - component: c:\documents and settings\zarla\application data\mozilla\firefox\profiles\jf4tt3qn.transferringover\extensions\{463f6ca5-ee3c-4be1-b7e6-7fee11953374}\platform\winnt\components\FoxyTunes.13.dll
FF - component: c:\documents and settings\zarla\application data\mozilla\firefox\profiles\jf4tt3qn.transferringover\extensions\{463f6ca5-ee3c-4be1-b7e6-7fee11953374}\platform\winnt\components\FoxyTunes.9.dll
FF - component: c:\documents and settings\zarla\application data\mozilla\firefox\profiles\jf4tt3qn.transferringover\extensions\{463f6ca5-ee3c-4be1-b7e6-7fee11953374}\platform\winnt\components\FoxyTunes.dll
FF - plugin: c:\documents and settings\zarla\application data\mozilla\firefox\profiles\jf4tt3qn.transferringover\extensions\openxmlviewer@codeplex.com\plugins\npDocX.dll
FF - plugin: c:\documents and settings\zarla\application data\mozilla\firefox\profiles\jf4tt3qn.transferringover\extensions\openxmlviewer@codeplex.com\plugins\npnul32.dll
FF - plugin: c:\program files\foxit software\foxit reader\plugins\npFoxitReaderPlugin.dll
FF - plugin: c:\program files\java\jre7\bin\npjpi170_07.dll
FF - plugin: c:\program files\java\jre7\bin\plugin2\npjp2.dll
FF - plugin: c:\windows\system32\npDeployJava1.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: BarTab: bartap@philikon.de - %profile%\extensions\bartap@philikon.de
FF - Ext: OpenXMLViewer: OpenXMLViewer@Codeplex.com - %profile%\extensions\OpenXMLViewer@Codeplex.com
FF - Ext: Rehost Image: rehostimage@engy.us - %profile%\extensions\rehostimage@engy.us
FF - Ext: SkipScreen: SkipScreen@SkipScreen - %profile%\extensions\SkipScreen@SkipScreen
FF - Ext: Screengrab: {02450954-cdd9-410f-b1da-db804e18c671} - %profile%\extensions\{02450954-cdd9-410f-b1da-db804e18c671}
FF - Ext: Resurrect Pages: {0c8fbd76-bdeb-4c52-9b24-d587ce7b9dc3} - %profile%\extensions\{0c8fbd76-bdeb-4c52-9b24-d587ce7b9dc3}
FF - Ext: Linkification: {35106bca-6c78-48c7-ac28-56df30b51d2a} - %profile%\extensions\{35106bca-6c78-48c7-ac28-56df30b51d2a}
FF - Ext: FoxyTunes: {463F6CA5-EE3C-4be1-B7E6-7FEE11953374} - %profile%\extensions\{463F6CA5-EE3C-4be1-B7E6-7FEE11953374}
FF - Ext: Stylish: {46551EC9-40F0-4e47-8E18-8E5CF550CFB8} - %profile%\extensions\{46551EC9-40F0-4e47-8E18-8E5CF550CFB8}
FF - Ext: Image Search Options: {4a313247-8330-4a81-948e-b79936516f78} - %profile%\extensions\{4a313247-8330-4a81-948e-b79936516f78}
FF - Ext: ScrapBook: {53A03D43-5363-4669-8190-99061B2DEBA5} - %profile%\extensions\{53A03D43-5363-4669-8190-99061B2DEBA5}
FF - Ext: Popup ALT Attribute: {61FD08D8-A2CB-46c0-B36D-3F531AC53C12} - %profile%\extensions\{61FD08D8-A2CB-46c0-B36D-3F531AC53C12}
FF - Ext: NoScript: {73a6fe31-595d-460b-a920-fcc0f8843232} - %profile%\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
FF - Ext: LJlogin: {ad4ee9e5-49c7-4589-acf3-db9fa76a95c9} - %profile%\extensions\{ad4ee9e5-49c7-4589-acf3-db9fa76a95c9}
FF - Ext: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - %profile%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
FF - Ext: Download Statusbar: {D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389} - %profile%\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}
FF - Ext: Greasemonkey: {e4a8a97b-f2ed-450b-b12d-ee082ba24781} - %profile%\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
FF - Ext: Firefox 2, the theme, reloaded: {fd2f951f-77ea-4938-9493-0c892c027a13} - %profile%\extensions\{fd2f951f-77ea-4938-9493-0c892c027a13}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\DotNetAssistantExtension
.
---- FIREFOX POLICIES ----
FF - user.js: network.protocol-handler.warn-external.dnupdate - false
============= SERVICES / DRIVERS ===============
.
R0 ahcix86;ahcix86;c:\windows\system32\drivers\ahcix86.sys [2010-3-9 188984]
R0 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2012-3-20 171064]
R1 MpKslbbfa0b08;MpKslbbfa0b08;c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{2f98086c-330e-4dae-b963-0f9dd12d87d3}\MpKslbbfa0b08.sys [2012-9-30 29904]
R2 TabletServiceWacom;TabletServiceWacom;c:\windows\system32\Wacom_Tablet.exe [2012-8-14 1373480]
R2 WDDMService;WD SmartWare Drive Manager;c:\program files\western digital\wd smartware\wd drive manager\WDDMService.exe [2010-1-21 110592]
R2 WDSmartWareBackgroundService;WD SmartWare Background Service;c:\program files\western digital\wd smartware\front parlor\WDSmartWareBackgroundService.exe [2009-6-16 20480]
R3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdXP3.sys [2012-5-13 99856]
R3 HCWBT8xx;Hauppauge WinTV 848/9 WDM Video Driver;c:\windows\system32\drivers\HCWBT8XX.sys [2012-8-18 472644]
R3 mbamchameleon;mbamchameleon;c:\windows\system32\drivers\mbamchameleon.sys [2012-9-30 35144]
R3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [2012-8-16 11520]
S2 SkypeUpdate;Skype Updater;c:\program files\skype\updater\Updater.exe [2012-7-13 160944]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [2012-8-4 1691480]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\mozilla maintenance service\maintenanceservice.exe [2012-9-30 114144]
.
=============== Created Last 30 ================
.
2012-10-01 03:12:59 35144 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2012-09-30 17:25:35 66520 ----a-w- c:\program files\mozilla firefox\plugins\npnul32.dll
2012-09-30 17:25:35 25048 ----a-w- c:\program files\mozilla firefox\components\browserdirprovider.dll
2012-09-30 17:25:35 140248 ----a-w- c:\program files\mozilla firefox\components\brwsrcmp.dll
2012-09-30 17:25:34 505816 ----a-w- c:\program files\mozilla firefox\sqlite3.dll
2012-09-30 17:25:33 719832 ----a-w- c:\program files\mozilla firefox\mozcrt19.dll
2012-09-30 17:25:33 719832 ----a-w- c:\program files\mozilla firefox\mozcpp19.dll
2012-09-30 17:25:33 1014744 ----a-w- c:\program files\mozilla firefox\js3250.dll
2012-09-30 16:58:19 -------- d-----w- c:\program files\Mozilla Maintenance Service
2012-09-30 16:42:56 29904 ----a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{2f98086c-330e-4dae-b963-0f9dd12d87d3}\MpKslbbfa0b08.sys
2012-09-30 15:33:05 6980552 ----a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{2f98086c-330e-4dae-b963-0f9dd12d87d3}\mpengine.dll
2012-09-30 07:03:45 -------- d-----w- c:\program files\AVAST Software
2012-09-30 07:03:45 -------- d-----w- c:\documents and settings\all users\application data\AVAST Software
2012-09-29 16:10:53 -------- d-----w- c:\documents and settings\zarla\local settings\application data\PCHealth
2012-09-29 13:26:04 6980552 ----a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\backup\mpengine.dll
2012-09-29 13:10:09 221184 ----a-w- c:\windows\system32\wmpns.dll
2012-09-29 07:55:17 -------- d-----w- c:\documents and settings\zarla\application data\Malwarebytes
2012-09-29 07:54:57 -------- d-----w- c:\documents and settings\all users\application data\Malwarebytes
2012-09-29 07:54:54 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-09-29 07:54:53 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-09-29 03:19:49 404400 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-09-25 11:42:36 1409 ----a-w- c:\windows\QTFont.for
2012-09-08 06:05:38 -------- d-----w- c:\documents and settings\zarla\local settings\application data\kiloHearts
2012-09-08 06:04:55 -------- d-----w- c:\documents and settings\zarla\application data\MSPS
2012-09-05 02:22:40 -------- d-----w- c:\documents and settings\zarla\local settings\application data\DOSBox
2012-09-05 01:40:21 -------- d-----w- c:\documents and settings\zarla\local settings\application data\Lazy 8 Studios
2012-09-05 01:40:16 1998168 ----a-w- c:\windows\system32\D3DX9_43.dll
2012-09-05 01:40:09 -------- d-----w- c:\windows\Logs
2012-09-01 21:08:06 143872 ----a-w- c:\windows\system32\javacpl.cpl
2012-09-01 21:07:48 93672 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
.
==================== Find3M ====================
.
2012-09-01 21:07:37 821736 ----a-w- c:\windows\system32\npDeployJava1.dll
2012-09-01 21:07:37 746984 ----a-w- c:\windows\system32\deployJava1.dll
2012-08-28 15:14:53 916992 ----a-w- c:\windows\system32\wininet.dll
2012-08-28 15:14:53 43520 ----a-w- c:\windows\system32\licmgr10.dll
2012-08-28 15:14:52 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2012-08-28 12:07:15 385024 ----a-w- c:\windows\system32\html.iec
2012-08-20 04:43:37 588 ----a-w- c:\windows\uninstallstickies.bat
2012-08-14 17:11:50 685816 ----a-w- c:\windows\system32\drivers\sptd.sys
2012-08-04 23:32:36 0 ----a-w- c:\windows\ativpsrm.bin
2012-07-20 18:00:00 112640 ----a-w- c:\windows\system32\ff_vfw.dll
2012-07-06 13:58:51 78336 ----a-w- c:\windows\system32\browser.dll
2012-07-04 14:05:18 139784 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2012-07-03 13:40:15 1866112 ----a-w- c:\windows\system32\win32k.sys
2006-05-03 09:06:54 163328 --sh--r- c:\windows\system32\flvDX.dll
2007-02-21 10:47:16 31232 --sh--r- c:\windows\system32\msfDX.dll
.
============= FINISH: 21:14:09.51 ===============
Aswmbr logs:
aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-09-30 21:24:17
-----------------------------
21:24:17.640 OS Version: Windows 5.1.2600 Service Pack 3
21:24:17.640 Number of processors: 4 586 0x102
21:24:17.640 ComputerName: CEDA-09E6FD4986 UserName: Zarla
21:24:18.703 Initialize success
21:27:40.734 AVAST engine defs: 12093001
21:28:03.578 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Scsi\ahcix861Port2Path0Target0Lun0
21:28:03.578 Disk 0 Vendor: Seagate_ 1AJ1 Size: 953869MB BusType: 1
21:28:03.593 Disk 1 \Device\Harddisk1\DR1 -> \Device\Scsi\ahcix861Port2Path0Target1Lun0
21:28:03.593 Disk 1 Vendor: Seagate_ 3.AA Size: 476940MB BusType: 1
21:28:03.593 Disk 0 MBR read successfully
21:28:03.593 Disk 0 MBR scan
21:28:03.625 Disk 0 Windows XP default MBR code
21:28:03.625 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 953859 MB offset 63
21:28:03.625 Disk 0 scanning sectors +1953504000
21:28:03.703 Disk 0 scanning C:\WINDOWS\system32\drivers
21:28:16.546 Service scanning
21:28:28.812 Service MpKsld4a42852 c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2F98086C-330E-4DAE-B963-0F9DD12D87D3}\MpKsld4a42852.sys **LOCKED** 32
21:28:33.125 Service sptd C:\WINDOWS\System32\Drivers\sptd.sys **LOCKED** 32
21:28:37.046 Modules scanning
21:28:40.625 Disk 0 trace - called modules:
21:28:40.640 ntkrnlpa.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x8ac061e8]<<
21:28:40.640 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8a288030]
21:28:40.656 3 CLASSPNP.SYS[f74c7fd7] -> nt!IofCallDriver -> \Device\Scsi\ahcix861Port2Path0Target0Lun0[0x8ab1b998]
21:28:40.656 \Driver\ahcix86[0x8aac8f38] -> IRP_MJ_CREATE -> 0x8ac061e8
21:28:41.812 AVAST engine scan C:\WINDOWS
21:28:53.015 AVAST engine scan C:\WINDOWS\system32
21:31:29.281 AVAST engine scan C:\WINDOWS\system32\drivers
21:31:52.609 AVAST engine scan C:\Documents and Settings\Zarla
21:52:01.171 AVAST engine scan C:\Documents and Settings\All Users
00:11:40.640 Scan finished successfully
00:18:13.718 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Zarla\My Documents\MBR.dat"
00:18:13.718 The log file has been saved successfully to "C:\Documents and Settings\Zarla\My Documents\aswMBR.txt"
And the Spybot log:
Win32.VB.du: [SBI $C471BC2C] Settings (Registry change, nothing done)
HKEY_USERS\S-1-5-21-436374069-1202660629-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\HideFileExt
Win32.VB.du: [SBI $5DDE6C15] Settings (Registry change, nothing done)
HKEY_USERS\S-1-5-21-436374069-1202660629-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowSuperHidden
Microsoft.Windows.InfectedHostfile: [SBI $50865E77] Data (File, nothing done)
C:\WINDOWS\system32\drivers\etc\hosts_infected
Win32.Banker.prx: [SBI $22E68569] User settings (Registry change, nothing done)
HKEY_USERS\S-1-5-21-436374069-1202660629-839522115-1003\Software\Microsoft\Internet Explorer\BrowserEmulation\TLDUpdates
Win32.Banker.prx: [SBI $25582D55] User settings (Registry change, nothing done)
HKEY_USERS\S-1-5-21-436374069-1202660629-839522115-1003\Software\Microsoft\Internet Explorer\IETld\StaleIETldCache
Win32.Agent.ws: [SBI $2BB30D89] Settings (Registry key, nothing done)
HKEY_USERS\.DEFAULT\Software\AMD
Win32.Agent.ws: [SBI $2BB30D89] Settings (Registry key, nothing done)
HKEY_USERS\.DEFAULT\Software\ATI
Win32.Agent.ws: [SBI $2BB30D89] Settings (Registry key, nothing done)
HKEY_USERS\.DEFAULT\Software\Microsoft
Win32.Agent.ws: [SBI $2BB30D89] Settings (Registry key, nothing done)
HKEY_USERS\.DEFAULT\Software\Policies
Win32.Agent.ws: [SBI $2BB30D89] Settings (Registry key, nothing done)
HKEY_USERS\S-1-5-19\Software\Mediamatics
Win32.Agent.ws: [SBI $2BB30D89] Settings (Registry key, nothing done)
HKEY_USERS\S-1-5-19\Software\Microsoft
Win32.Agent.ws: [SBI $2BB30D89] Settings (Registry key, nothing done)
HKEY_USERS\S-1-5-19\Software\Classes
Win32.Agent.ws: [SBI $2BB30D89] Settings (Registry key, nothing done)
HKEY_USERS\S-1-5-20\Software\Mediamatics
Win32.Agent.ws: [SBI $2BB30D89] Settings (Registry key, nothing done)
HKEY_USERS\S-1-5-20\Software\Microsoft
Win32.Agent.ws: [SBI $2BB30D89] Settings (Registry key, nothing done)
HKEY_USERS\S-1-5-20\Software\Policies
Win32.Agent.ws: [SBI $2BB30D89] Settings (Registry key, nothing done)
HKEY_USERS\S-1-5-20\Software\Classes
Win32.Agent.ws: [SBI $2BB30D89] Settings (Registry key, nothing done)
HKEY_USERS\S-1-5-21-436374069-1202660629-839522115-1003\Software\Adobe
Win32.Agent.ws: [SBI $2BB30D89] Settings (Registry key, nothing done)
HKEY_USERS\S-1-5-21-436374069-1202660629-839522115-1003\Software\ATI
Win32.Agent.ws: [SBI $2BB30D89] Settings (Registry key, nothing done)
HKEY_USERS\S-1-5-21-436374069-1202660629-839522115-1003\Software\AVAST Software
Win32.Agent.ws: [SBI $2BB30D89] Settings (Registry key, nothing done)
HKEY_USERS\S-1-5-21-436374069-1202660629-839522115-1003\Software\Clients
Win32.Agent.ws: [SBI $2BB30D89] Settings (Registry key, nothing done)
HKEY_USERS\S-1-5-21-436374069-1202660629-839522115-1003\Software\Gabest
Win32.Agent.ws: [SBI $2BB30D89] Settings (Registry key, nothing done)
HKEY_USERS\S-1-5-21-436374069-1202660629-839522115-1003\Software\Google
Win32.Agent.ws: [SBI $2BB30D89] Settings (Registry key, nothing done)
HKEY_USERS\S-1-5-21-436374069-1202660629-839522115-1003\Software\JavaSoft
Win32.Agent.ws: [SBI $2BB30D89] Settings (Registry key, nothing done)
HKEY_USERS\S-1-5-21-436374069-1202660629-839522115-1003\Software\Last.fm
Win32.Agent.ws: [SBI $2BB30D89] Settings (Registry key, nothing done)
HKEY_USERS\S-1-5-21-436374069-1202660629-839522115-1003\Software\Macromedia
Win32.Agent.ws: [SBI $2BB30D89] Settings (Registry key, nothing done)
HKEY_USERS\S-1-5-21-436374069-1202660629-839522115-1003\Software\Malwarebytes' Anti-Malware
Win32.Agent.ws: [SBI $2BB30D89] Settings (Registry key, nothing done)
HKEY_USERS\S-1-5-21-436374069-1202660629-839522115-1003\Software\Mediamatics
Win32.Agent.ws: [SBI $2BB30D89] Settings (Registry key, nothing done)
HKEY_USERS\S-1-5-21-436374069-1202660629-839522115-1003\Software\Memeo
Win32.Agent.ws: [SBI $2BB30D89] Settings (Registry key, nothing done)
HKEY_USERS\S-1-5-21-436374069-1202660629-839522115-1003\Software\Microsoft
Win32.Agent.ws: [SBI $2BB30D89] Settings (Registry key, nothing done)
HKEY_USERS\S-1-5-21-436374069-1202660629-839522115-1003\Software\Mozilla
Win32.Agent.ws: [SBI $2BB30D89] Settings (Registry key, nothing done)
HKEY_USERS\S-1-5-21-436374069-1202660629-839522115-1003\Software\MozillaPlugins
Win32.Agent.ws: [SBI $2BB30D89] Settings (Registry key, nothing done)
HKEY_USERS\S-1-5-21-436374069-1202660629-839522115-1003\Software\Netscape
Win32.Agent.ws: [SBI $2BB30D89] Settings (Registry key, nothing done)
HKEY_USERS\S-1-5-21-436374069-1202660629-839522115-1003\Software\Nintendo
Win32.Agent.ws: [SBI $2BB30D89] Settings (Registry key, nothing done)
HKEY_USERS\S-1-5-21-436374069-1202660629-839522115-1003\Software\Policies
Win32.Agent.ws: [SBI $2BB30D89] Settings (Registry key, nothing done)
HKEY_USERS\S-1-5-21-436374069-1202660629-839522115-1003\Software\Realtek
Win32.Agent.ws: [SBI $2BB30D89] Settings (Registry key, nothing done)
HKEY_USERS\S-1-5-21-436374069-1202660629-839522115-1003\Software\Safer Networking Limited
Win32.Agent.ws: [SBI $2BB30D89] Settings (Registry key, nothing done)
HKEY_USERS\S-1-5-21-436374069-1202660629-839522115-1003\Software\Trolltech
Win32.Agent.ws: [SBI $2BB30D89] Settings (Registry key, nothing done)
HKEY_USERS\S-1-5-21-436374069-1202660629-839522115-1003\Software\Valve
Win32.Agent.ws: [SBI $2BB30D89] Settings (Registry key, nothing done)
HKEY_USERS\S-1-5-21-436374069-1202660629-839522115-1003\Software\WinampAC3
Win32.Agent.ws: [SBI $2BB30D89] Settings (Registry key, nothing done)
HKEY_USERS\S-1-5-21-436374069-1202660629-839522115-1003\Software\WinRAR
Win32.Agent.ws: [SBI $2BB30D89] Settings (Registry key, nothing done)
HKEY_USERS\S-1-5-21-436374069-1202660629-839522115-1003\Software\Classes
Win32.Agent.ws: [SBI $2BB30D89] Settings (Registry key, nothing done)
HKEY_USERS\S-1-5-18\Software\AMD
Win32.Agent.ws: [SBI $2BB30D89] Settings (Registry key, nothing done)
HKEY_USERS\S-1-5-18\Software\ATI
Win32.Agent.ws: [SBI $2BB30D89] Settings (Registry key, nothing done)
HKEY_USERS\S-1-5-18\Software\Microsoft
Win32.Agent.ws: [SBI $2BB30D89] Settings (Registry key, nothing done)
HKEY_USERS\S-1-5-18\Software\Policies
Win32.Autorun.dc3: [SBI $3958106B] Settings (Registry key, nothing done)
HKEY_USERS\S-1-5-21-436374069-1202660629-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}
--- Spybot - Search & Destroy version: 1.5 (build: 20070830) ---
2007-08-31 blindman.exe (1.0.0.6)
2007-08-31 SDMain.exe (1.0.0.4)
2007-08-31 SDUpdate.exe (1.0.6.4)
2007-08-31 SDWinSec.exe (1.0.0.8)
2007-08-31 SpybotSD.exe (1.5.1.15)
2009-03-05 TeaTimer.exe (1.6.6.32)
2012-08-15 unins000.exe (51.46.0.0)
2007-08-31 Update.exe (1.4.0.5)
2009-11-04 advcheck.dll (1.6.5.20)
2007-04-02 aports.dll (2.1.0.0)
2007-04-02 DelZip179.dll (1.79.5.3)
2008-09-15 SDHelper.dll (1.6.2.14)
2008-10-22 Tools.dll (2.1.6.8)
2012-04-04 Includes\Adware.sbi (*)
2012-09-25 Includes\AdwareC.sbi (*)
2010-08-13 Includes\Cookies.sbi (*)
2010-12-14 Includes\Dialer.sbi (*)
2012-09-26 Includes\DialerC.sbi (*)
2012-01-31 Includes\HeavyDuty.sbi (*)
2012-06-18 Includes\Hijackers.sbi (*)
2012-09-25 Includes\HijackersC.sbi (*)
2010-09-15 Includes\iPhone.sbi (*)
2012-03-13 Includes\Keyloggers.sbi (*)
2012-03-13 Includes\KeyloggersC.sbi (*)
2004-11-29 Includes\LSP.sbi (*)
2012-08-28 Includes\Malware.sbi (*)
2012-09-25 Includes\MalwareC.sbi (*)
2011-02-24 Includes\PUPS.sbi (*)
2012-08-21 Includes\PUPSC.sbi (*)
2010-01-25 Includes\Revision.sbi (*)
2012-06-18 Includes\Security.sbi (*)
2011-12-13 Includes\SecurityC.sbi (*)
2008-06-03 Includes\Spybots.sbi (*)
2008-06-03 Includes\SpybotsC.sbi (*)
2012-09-05 Includes\Spyware.sbi (*)
2012-09-04 Includes\SpywareC.sbi (*)
2010-03-08 Includes\Tracks.uti
2011-09-27 Includes\Trojans.sbi (*)
2012-09-27 Includes\TrojansC-02.sbi (*)
2012-09-20 Includes\TrojansC-03.sbi (*)
2012-09-28 Includes\TrojansC-04.sbi (*)
2012-08-31 Includes\TrojansC-05.sbi (*)
2012-09-07 Includes\TrojansC.sbi (*)
2008-03-04 Plugins\Chai.dll
2008-03-05 Plugins\Fennel.dll
2008-02-26 Plugins\Mate.dll
2008-12-24 Plugins\TCPIPAddress.dll
I try to remove things with Spybot, but it says the resources are in use, and asks if it can run when I restart. I tried it, but it bluescreened at the end of its scan. I tried to install another antivirus like Avast, but it bluescreened at the end of installation then refused to start the program when it restarted. I tried the Outpost Security Suite, but it locked up during its initial scan and some fonts disappeared, then when I tried to restart in safe mode, the program wouldn't load. Then the computer wouldn't boot at all, so I had to go back into safe mode and uninstall the security suite, then it booted alright.
I've tried a few times to get rid of these things with Spybot, but they keep coming back... I'm worried something's seriously wrong. Here are the logs.
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 10.7.2
Run by Zarla at 21:11:44 on 2012-09-30
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3199.1297 [GMT -7:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
c:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\WiFiConnector\NintendoWFCReg.exe
C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe
C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWare.exe
C:\Program Files\Last.fm\LastFMHelper.exe
C:\Program Files\Stickies\stickies.exe
svchost.exe
C:\Program Files\Java\jre7\bin\jqs.exe
C:\Program Files\CDBurnerXP\NMSAccessU.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\Wacom_Tablet.exe
C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe
C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe
C:\WINDOWS\system32\WTablet\Wacom_TabletUser.exe
C:\WINDOWS\system32\Wacom_Tablet.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\Program Files\Winamp5\winamp.exe
C:\Program Files\Last.fm\LastFM.exe
C:\Program Files\Taskbar Shuffle\taskbarshuffle.exe
C:\Program Files\Steam\Steam.exe
.
============== Pseudo HJT Report ===============
.
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre7\bin\ssv.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre7\bin\jp2ssv.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [PinnacleDriverCheck] c:\windows\system32\PSDrvCheck.exe -CheckReg
mRun: [PHIME2002ASync] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /SYNC
mRun: [PHIME2002A] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /IMEName
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [IMJPMIG8.1] "c:\windows\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
mRunOnce: [1] c:\program files\malwarebytes' anti-malware\chameleon\mbam-chameleon.exe /r /p
StartupFolder: c:\docume~1\zarla\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
StartupFolder: c:\docume~1\zarla\startm~1\programs\startup\lastfm~1.lnk - c:\program files\last.fm\LastFMHelper.exe
StartupFolder: c:\docume~1\zarla\startm~1\programs\startup\stickies.lnk - c:\program files\stickies\stickies.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\runnin~1.lnk - c:\program files\wificonnector\NintendoWFCReg.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\wddmst~1.lnk - c:\program files\western digital\wd smartware\wd drive manager\WDDMStatus.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\wdsmar~1.lnk - c:\program files\western digital\wd smartware\front parlor\WDSmartWare.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://windowsupdate.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1344119090125
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1344119235656
TCP: DhcpNameServer = 192.168.1.254
TCP: Interfaces\{3E885F99-6B75-4C9E-AFC6-346B05F06238} : DhcpNameServer = 192.168.1.254
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: AtiExtEvent - Ati2evxx.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\zarla\application data\mozilla\firefox\profiles\jf4tt3qn.transferringover\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com
FF - prefs.js: network.proxy.type - 4
FF - component: c:\documents and settings\zarla\application data\mozilla\firefox\profiles\jf4tt3qn.transferringover\extensions\{463f6ca5-ee3c-4be1-b7e6-7fee11953374}\platform\winnt\components\FoxyTunes.10.dll
FF - component: c:\documents and settings\zarla\application data\mozilla\firefox\profiles\jf4tt3qn.transferringover\extensions\{463f6ca5-ee3c-4be1-b7e6-7fee11953374}\platform\winnt\components\FoxyTunes.11.dll
FF - component: c:\documents and settings\zarla\application data\mozilla\firefox\profiles\jf4tt3qn.transferringover\extensions\{463f6ca5-ee3c-4be1-b7e6-7fee11953374}\platform\winnt\components\FoxyTunes.12.dll
FF - component: c:\documents and settings\zarla\application data\mozilla\firefox\profiles\jf4tt3qn.transferringover\extensions\{463f6ca5-ee3c-4be1-b7e6-7fee11953374}\platform\winnt\components\FoxyTunes.13.dll
FF - component: c:\documents and settings\zarla\application data\mozilla\firefox\profiles\jf4tt3qn.transferringover\extensions\{463f6ca5-ee3c-4be1-b7e6-7fee11953374}\platform\winnt\components\FoxyTunes.9.dll
FF - component: c:\documents and settings\zarla\application data\mozilla\firefox\profiles\jf4tt3qn.transferringover\extensions\{463f6ca5-ee3c-4be1-b7e6-7fee11953374}\platform\winnt\components\FoxyTunes.dll
FF - plugin: c:\documents and settings\zarla\application data\mozilla\firefox\profiles\jf4tt3qn.transferringover\extensions\openxmlviewer@codeplex.com\plugins\npDocX.dll
FF - plugin: c:\documents and settings\zarla\application data\mozilla\firefox\profiles\jf4tt3qn.transferringover\extensions\openxmlviewer@codeplex.com\plugins\npnul32.dll
FF - plugin: c:\program files\foxit software\foxit reader\plugins\npFoxitReaderPlugin.dll
FF - plugin: c:\program files\java\jre7\bin\npjpi170_07.dll
FF - plugin: c:\program files\java\jre7\bin\plugin2\npjp2.dll
FF - plugin: c:\windows\system32\npDeployJava1.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: BarTab: bartap@philikon.de - %profile%\extensions\bartap@philikon.de
FF - Ext: OpenXMLViewer: OpenXMLViewer@Codeplex.com - %profile%\extensions\OpenXMLViewer@Codeplex.com
FF - Ext: Rehost Image: rehostimage@engy.us - %profile%\extensions\rehostimage@engy.us
FF - Ext: SkipScreen: SkipScreen@SkipScreen - %profile%\extensions\SkipScreen@SkipScreen
FF - Ext: Screengrab: {02450954-cdd9-410f-b1da-db804e18c671} - %profile%\extensions\{02450954-cdd9-410f-b1da-db804e18c671}
FF - Ext: Resurrect Pages: {0c8fbd76-bdeb-4c52-9b24-d587ce7b9dc3} - %profile%\extensions\{0c8fbd76-bdeb-4c52-9b24-d587ce7b9dc3}
FF - Ext: Linkification: {35106bca-6c78-48c7-ac28-56df30b51d2a} - %profile%\extensions\{35106bca-6c78-48c7-ac28-56df30b51d2a}
FF - Ext: FoxyTunes: {463F6CA5-EE3C-4be1-B7E6-7FEE11953374} - %profile%\extensions\{463F6CA5-EE3C-4be1-B7E6-7FEE11953374}
FF - Ext: Stylish: {46551EC9-40F0-4e47-8E18-8E5CF550CFB8} - %profile%\extensions\{46551EC9-40F0-4e47-8E18-8E5CF550CFB8}
FF - Ext: Image Search Options: {4a313247-8330-4a81-948e-b79936516f78} - %profile%\extensions\{4a313247-8330-4a81-948e-b79936516f78}
FF - Ext: ScrapBook: {53A03D43-5363-4669-8190-99061B2DEBA5} - %profile%\extensions\{53A03D43-5363-4669-8190-99061B2DEBA5}
FF - Ext: Popup ALT Attribute: {61FD08D8-A2CB-46c0-B36D-3F531AC53C12} - %profile%\extensions\{61FD08D8-A2CB-46c0-B36D-3F531AC53C12}
FF - Ext: NoScript: {73a6fe31-595d-460b-a920-fcc0f8843232} - %profile%\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
FF - Ext: LJlogin: {ad4ee9e5-49c7-4589-acf3-db9fa76a95c9} - %profile%\extensions\{ad4ee9e5-49c7-4589-acf3-db9fa76a95c9}
FF - Ext: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - %profile%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
FF - Ext: Download Statusbar: {D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389} - %profile%\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}
FF - Ext: Greasemonkey: {e4a8a97b-f2ed-450b-b12d-ee082ba24781} - %profile%\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
FF - Ext: Firefox 2, the theme, reloaded: {fd2f951f-77ea-4938-9493-0c892c027a13} - %profile%\extensions\{fd2f951f-77ea-4938-9493-0c892c027a13}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\DotNetAssistantExtension
.
---- FIREFOX POLICIES ----
FF - user.js: network.protocol-handler.warn-external.dnupdate - false
============= SERVICES / DRIVERS ===============
.
R0 ahcix86;ahcix86;c:\windows\system32\drivers\ahcix86.sys [2010-3-9 188984]
R0 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2012-3-20 171064]
R1 MpKslbbfa0b08;MpKslbbfa0b08;c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{2f98086c-330e-4dae-b963-0f9dd12d87d3}\MpKslbbfa0b08.sys [2012-9-30 29904]
R2 TabletServiceWacom;TabletServiceWacom;c:\windows\system32\Wacom_Tablet.exe [2012-8-14 1373480]
R2 WDDMService;WD SmartWare Drive Manager;c:\program files\western digital\wd smartware\wd drive manager\WDDMService.exe [2010-1-21 110592]
R2 WDSmartWareBackgroundService;WD SmartWare Background Service;c:\program files\western digital\wd smartware\front parlor\WDSmartWareBackgroundService.exe [2009-6-16 20480]
R3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdXP3.sys [2012-5-13 99856]
R3 HCWBT8xx;Hauppauge WinTV 848/9 WDM Video Driver;c:\windows\system32\drivers\HCWBT8XX.sys [2012-8-18 472644]
R3 mbamchameleon;mbamchameleon;c:\windows\system32\drivers\mbamchameleon.sys [2012-9-30 35144]
R3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [2012-8-16 11520]
S2 SkypeUpdate;Skype Updater;c:\program files\skype\updater\Updater.exe [2012-7-13 160944]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [2012-8-4 1691480]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\mozilla maintenance service\maintenanceservice.exe [2012-9-30 114144]
.
=============== Created Last 30 ================
.
2012-10-01 03:12:59 35144 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2012-09-30 17:25:35 66520 ----a-w- c:\program files\mozilla firefox\plugins\npnul32.dll
2012-09-30 17:25:35 25048 ----a-w- c:\program files\mozilla firefox\components\browserdirprovider.dll
2012-09-30 17:25:35 140248 ----a-w- c:\program files\mozilla firefox\components\brwsrcmp.dll
2012-09-30 17:25:34 505816 ----a-w- c:\program files\mozilla firefox\sqlite3.dll
2012-09-30 17:25:33 719832 ----a-w- c:\program files\mozilla firefox\mozcrt19.dll
2012-09-30 17:25:33 719832 ----a-w- c:\program files\mozilla firefox\mozcpp19.dll
2012-09-30 17:25:33 1014744 ----a-w- c:\program files\mozilla firefox\js3250.dll
2012-09-30 16:58:19 -------- d-----w- c:\program files\Mozilla Maintenance Service
2012-09-30 16:42:56 29904 ----a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{2f98086c-330e-4dae-b963-0f9dd12d87d3}\MpKslbbfa0b08.sys
2012-09-30 15:33:05 6980552 ----a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{2f98086c-330e-4dae-b963-0f9dd12d87d3}\mpengine.dll
2012-09-30 07:03:45 -------- d-----w- c:\program files\AVAST Software
2012-09-30 07:03:45 -------- d-----w- c:\documents and settings\all users\application data\AVAST Software
2012-09-29 16:10:53 -------- d-----w- c:\documents and settings\zarla\local settings\application data\PCHealth
2012-09-29 13:26:04 6980552 ----a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\backup\mpengine.dll
2012-09-29 13:10:09 221184 ----a-w- c:\windows\system32\wmpns.dll
2012-09-29 07:55:17 -------- d-----w- c:\documents and settings\zarla\application data\Malwarebytes
2012-09-29 07:54:57 -------- d-----w- c:\documents and settings\all users\application data\Malwarebytes
2012-09-29 07:54:54 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-09-29 07:54:53 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-09-29 03:19:49 404400 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-09-25 11:42:36 1409 ----a-w- c:\windows\QTFont.for
2012-09-08 06:05:38 -------- d-----w- c:\documents and settings\zarla\local settings\application data\kiloHearts
2012-09-08 06:04:55 -------- d-----w- c:\documents and settings\zarla\application data\MSPS
2012-09-05 02:22:40 -------- d-----w- c:\documents and settings\zarla\local settings\application data\DOSBox
2012-09-05 01:40:21 -------- d-----w- c:\documents and settings\zarla\local settings\application data\Lazy 8 Studios
2012-09-05 01:40:16 1998168 ----a-w- c:\windows\system32\D3DX9_43.dll
2012-09-05 01:40:09 -------- d-----w- c:\windows\Logs
2012-09-01 21:08:06 143872 ----a-w- c:\windows\system32\javacpl.cpl
2012-09-01 21:07:48 93672 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
.
==================== Find3M ====================
.
2012-09-01 21:07:37 821736 ----a-w- c:\windows\system32\npDeployJava1.dll
2012-09-01 21:07:37 746984 ----a-w- c:\windows\system32\deployJava1.dll
2012-08-28 15:14:53 916992 ----a-w- c:\windows\system32\wininet.dll
2012-08-28 15:14:53 43520 ----a-w- c:\windows\system32\licmgr10.dll
2012-08-28 15:14:52 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2012-08-28 12:07:15 385024 ----a-w- c:\windows\system32\html.iec
2012-08-20 04:43:37 588 ----a-w- c:\windows\uninstallstickies.bat
2012-08-14 17:11:50 685816 ----a-w- c:\windows\system32\drivers\sptd.sys
2012-08-04 23:32:36 0 ----a-w- c:\windows\ativpsrm.bin
2012-07-20 18:00:00 112640 ----a-w- c:\windows\system32\ff_vfw.dll
2012-07-06 13:58:51 78336 ----a-w- c:\windows\system32\browser.dll
2012-07-04 14:05:18 139784 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2012-07-03 13:40:15 1866112 ----a-w- c:\windows\system32\win32k.sys
2006-05-03 09:06:54 163328 --sh--r- c:\windows\system32\flvDX.dll
2007-02-21 10:47:16 31232 --sh--r- c:\windows\system32\msfDX.dll
.
============= FINISH: 21:14:09.51 ===============
Aswmbr logs:
aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-09-30 21:24:17
-----------------------------
21:24:17.640 OS Version: Windows 5.1.2600 Service Pack 3
21:24:17.640 Number of processors: 4 586 0x102
21:24:17.640 ComputerName: CEDA-09E6FD4986 UserName: Zarla
21:24:18.703 Initialize success
21:27:40.734 AVAST engine defs: 12093001
21:28:03.578 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Scsi\ahcix861Port2Path0Target0Lun0
21:28:03.578 Disk 0 Vendor: Seagate_ 1AJ1 Size: 953869MB BusType: 1
21:28:03.593 Disk 1 \Device\Harddisk1\DR1 -> \Device\Scsi\ahcix861Port2Path0Target1Lun0
21:28:03.593 Disk 1 Vendor: Seagate_ 3.AA Size: 476940MB BusType: 1
21:28:03.593 Disk 0 MBR read successfully
21:28:03.593 Disk 0 MBR scan
21:28:03.625 Disk 0 Windows XP default MBR code
21:28:03.625 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 953859 MB offset 63
21:28:03.625 Disk 0 scanning sectors +1953504000
21:28:03.703 Disk 0 scanning C:\WINDOWS\system32\drivers
21:28:16.546 Service scanning
21:28:28.812 Service MpKsld4a42852 c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2F98086C-330E-4DAE-B963-0F9DD12D87D3}\MpKsld4a42852.sys **LOCKED** 32
21:28:33.125 Service sptd C:\WINDOWS\System32\Drivers\sptd.sys **LOCKED** 32
21:28:37.046 Modules scanning
21:28:40.625 Disk 0 trace - called modules:
21:28:40.640 ntkrnlpa.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x8ac061e8]<<
21:28:40.640 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8a288030]
21:28:40.656 3 CLASSPNP.SYS[f74c7fd7] -> nt!IofCallDriver -> \Device\Scsi\ahcix861Port2Path0Target0Lun0[0x8ab1b998]
21:28:40.656 \Driver\ahcix86[0x8aac8f38] -> IRP_MJ_CREATE -> 0x8ac061e8
21:28:41.812 AVAST engine scan C:\WINDOWS
21:28:53.015 AVAST engine scan C:\WINDOWS\system32
21:31:29.281 AVAST engine scan C:\WINDOWS\system32\drivers
21:31:52.609 AVAST engine scan C:\Documents and Settings\Zarla
21:52:01.171 AVAST engine scan C:\Documents and Settings\All Users
00:11:40.640 Scan finished successfully
00:18:13.718 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Zarla\My Documents\MBR.dat"
00:18:13.718 The log file has been saved successfully to "C:\Documents and Settings\Zarla\My Documents\aswMBR.txt"
And the Spybot log:
Win32.VB.du: [SBI $C471BC2C] Settings (Registry change, nothing done)
HKEY_USERS\S-1-5-21-436374069-1202660629-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\HideFileExt
Win32.VB.du: [SBI $5DDE6C15] Settings (Registry change, nothing done)
HKEY_USERS\S-1-5-21-436374069-1202660629-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowSuperHidden
Microsoft.Windows.InfectedHostfile: [SBI $50865E77] Data (File, nothing done)
C:\WINDOWS\system32\drivers\etc\hosts_infected
Win32.Banker.prx: [SBI $22E68569] User settings (Registry change, nothing done)
HKEY_USERS\S-1-5-21-436374069-1202660629-839522115-1003\Software\Microsoft\Internet Explorer\BrowserEmulation\TLDUpdates
Win32.Banker.prx: [SBI $25582D55] User settings (Registry change, nothing done)
HKEY_USERS\S-1-5-21-436374069-1202660629-839522115-1003\Software\Microsoft\Internet Explorer\IETld\StaleIETldCache
Win32.Agent.ws: [SBI $2BB30D89] Settings (Registry key, nothing done)
HKEY_USERS\.DEFAULT\Software\AMD
Win32.Agent.ws: [SBI $2BB30D89] Settings (Registry key, nothing done)
HKEY_USERS\.DEFAULT\Software\ATI
Win32.Agent.ws: [SBI $2BB30D89] Settings (Registry key, nothing done)
HKEY_USERS\.DEFAULT\Software\Microsoft
Win32.Agent.ws: [SBI $2BB30D89] Settings (Registry key, nothing done)
HKEY_USERS\.DEFAULT\Software\Policies
Win32.Agent.ws: [SBI $2BB30D89] Settings (Registry key, nothing done)
HKEY_USERS\S-1-5-19\Software\Mediamatics
Win32.Agent.ws: [SBI $2BB30D89] Settings (Registry key, nothing done)
HKEY_USERS\S-1-5-19\Software\Microsoft
Win32.Agent.ws: [SBI $2BB30D89] Settings (Registry key, nothing done)
HKEY_USERS\S-1-5-19\Software\Classes
Win32.Agent.ws: [SBI $2BB30D89] Settings (Registry key, nothing done)
HKEY_USERS\S-1-5-20\Software\Mediamatics
Win32.Agent.ws: [SBI $2BB30D89] Settings (Registry key, nothing done)
HKEY_USERS\S-1-5-20\Software\Microsoft
Win32.Agent.ws: [SBI $2BB30D89] Settings (Registry key, nothing done)
HKEY_USERS\S-1-5-20\Software\Policies
Win32.Agent.ws: [SBI $2BB30D89] Settings (Registry key, nothing done)
HKEY_USERS\S-1-5-20\Software\Classes
Win32.Agent.ws: [SBI $2BB30D89] Settings (Registry key, nothing done)
HKEY_USERS\S-1-5-21-436374069-1202660629-839522115-1003\Software\Adobe
Win32.Agent.ws: [SBI $2BB30D89] Settings (Registry key, nothing done)
HKEY_USERS\S-1-5-21-436374069-1202660629-839522115-1003\Software\ATI
Win32.Agent.ws: [SBI $2BB30D89] Settings (Registry key, nothing done)
HKEY_USERS\S-1-5-21-436374069-1202660629-839522115-1003\Software\AVAST Software
Win32.Agent.ws: [SBI $2BB30D89] Settings (Registry key, nothing done)
HKEY_USERS\S-1-5-21-436374069-1202660629-839522115-1003\Software\Clients
Win32.Agent.ws: [SBI $2BB30D89] Settings (Registry key, nothing done)
HKEY_USERS\S-1-5-21-436374069-1202660629-839522115-1003\Software\Gabest
Win32.Agent.ws: [SBI $2BB30D89] Settings (Registry key, nothing done)
HKEY_USERS\S-1-5-21-436374069-1202660629-839522115-1003\Software\Google
Win32.Agent.ws: [SBI $2BB30D89] Settings (Registry key, nothing done)
HKEY_USERS\S-1-5-21-436374069-1202660629-839522115-1003\Software\JavaSoft
Win32.Agent.ws: [SBI $2BB30D89] Settings (Registry key, nothing done)
HKEY_USERS\S-1-5-21-436374069-1202660629-839522115-1003\Software\Last.fm
Win32.Agent.ws: [SBI $2BB30D89] Settings (Registry key, nothing done)
HKEY_USERS\S-1-5-21-436374069-1202660629-839522115-1003\Software\Macromedia
Win32.Agent.ws: [SBI $2BB30D89] Settings (Registry key, nothing done)
HKEY_USERS\S-1-5-21-436374069-1202660629-839522115-1003\Software\Malwarebytes' Anti-Malware
Win32.Agent.ws: [SBI $2BB30D89] Settings (Registry key, nothing done)
HKEY_USERS\S-1-5-21-436374069-1202660629-839522115-1003\Software\Mediamatics
Win32.Agent.ws: [SBI $2BB30D89] Settings (Registry key, nothing done)
HKEY_USERS\S-1-5-21-436374069-1202660629-839522115-1003\Software\Memeo
Win32.Agent.ws: [SBI $2BB30D89] Settings (Registry key, nothing done)
HKEY_USERS\S-1-5-21-436374069-1202660629-839522115-1003\Software\Microsoft
Win32.Agent.ws: [SBI $2BB30D89] Settings (Registry key, nothing done)
HKEY_USERS\S-1-5-21-436374069-1202660629-839522115-1003\Software\Mozilla
Win32.Agent.ws: [SBI $2BB30D89] Settings (Registry key, nothing done)
HKEY_USERS\S-1-5-21-436374069-1202660629-839522115-1003\Software\MozillaPlugins
Win32.Agent.ws: [SBI $2BB30D89] Settings (Registry key, nothing done)
HKEY_USERS\S-1-5-21-436374069-1202660629-839522115-1003\Software\Netscape
Win32.Agent.ws: [SBI $2BB30D89] Settings (Registry key, nothing done)
HKEY_USERS\S-1-5-21-436374069-1202660629-839522115-1003\Software\Nintendo
Win32.Agent.ws: [SBI $2BB30D89] Settings (Registry key, nothing done)
HKEY_USERS\S-1-5-21-436374069-1202660629-839522115-1003\Software\Policies
Win32.Agent.ws: [SBI $2BB30D89] Settings (Registry key, nothing done)
HKEY_USERS\S-1-5-21-436374069-1202660629-839522115-1003\Software\Realtek
Win32.Agent.ws: [SBI $2BB30D89] Settings (Registry key, nothing done)
HKEY_USERS\S-1-5-21-436374069-1202660629-839522115-1003\Software\Safer Networking Limited
Win32.Agent.ws: [SBI $2BB30D89] Settings (Registry key, nothing done)
HKEY_USERS\S-1-5-21-436374069-1202660629-839522115-1003\Software\Trolltech
Win32.Agent.ws: [SBI $2BB30D89] Settings (Registry key, nothing done)
HKEY_USERS\S-1-5-21-436374069-1202660629-839522115-1003\Software\Valve
Win32.Agent.ws: [SBI $2BB30D89] Settings (Registry key, nothing done)
HKEY_USERS\S-1-5-21-436374069-1202660629-839522115-1003\Software\WinampAC3
Win32.Agent.ws: [SBI $2BB30D89] Settings (Registry key, nothing done)
HKEY_USERS\S-1-5-21-436374069-1202660629-839522115-1003\Software\WinRAR
Win32.Agent.ws: [SBI $2BB30D89] Settings (Registry key, nothing done)
HKEY_USERS\S-1-5-21-436374069-1202660629-839522115-1003\Software\Classes
Win32.Agent.ws: [SBI $2BB30D89] Settings (Registry key, nothing done)
HKEY_USERS\S-1-5-18\Software\AMD
Win32.Agent.ws: [SBI $2BB30D89] Settings (Registry key, nothing done)
HKEY_USERS\S-1-5-18\Software\ATI
Win32.Agent.ws: [SBI $2BB30D89] Settings (Registry key, nothing done)
HKEY_USERS\S-1-5-18\Software\Microsoft
Win32.Agent.ws: [SBI $2BB30D89] Settings (Registry key, nothing done)
HKEY_USERS\S-1-5-18\Software\Policies
Win32.Autorun.dc3: [SBI $3958106B] Settings (Registry key, nothing done)
HKEY_USERS\S-1-5-21-436374069-1202660629-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}
--- Spybot - Search & Destroy version: 1.5 (build: 20070830) ---
2007-08-31 blindman.exe (1.0.0.6)
2007-08-31 SDMain.exe (1.0.0.4)
2007-08-31 SDUpdate.exe (1.0.6.4)
2007-08-31 SDWinSec.exe (1.0.0.8)
2007-08-31 SpybotSD.exe (1.5.1.15)
2009-03-05 TeaTimer.exe (1.6.6.32)
2012-08-15 unins000.exe (51.46.0.0)
2007-08-31 Update.exe (1.4.0.5)
2009-11-04 advcheck.dll (1.6.5.20)
2007-04-02 aports.dll (2.1.0.0)
2007-04-02 DelZip179.dll (1.79.5.3)
2008-09-15 SDHelper.dll (1.6.2.14)
2008-10-22 Tools.dll (2.1.6.8)
2012-04-04 Includes\Adware.sbi (*)
2012-09-25 Includes\AdwareC.sbi (*)
2010-08-13 Includes\Cookies.sbi (*)
2010-12-14 Includes\Dialer.sbi (*)
2012-09-26 Includes\DialerC.sbi (*)
2012-01-31 Includes\HeavyDuty.sbi (*)
2012-06-18 Includes\Hijackers.sbi (*)
2012-09-25 Includes\HijackersC.sbi (*)
2010-09-15 Includes\iPhone.sbi (*)
2012-03-13 Includes\Keyloggers.sbi (*)
2012-03-13 Includes\KeyloggersC.sbi (*)
2004-11-29 Includes\LSP.sbi (*)
2012-08-28 Includes\Malware.sbi (*)
2012-09-25 Includes\MalwareC.sbi (*)
2011-02-24 Includes\PUPS.sbi (*)
2012-08-21 Includes\PUPSC.sbi (*)
2010-01-25 Includes\Revision.sbi (*)
2012-06-18 Includes\Security.sbi (*)
2011-12-13 Includes\SecurityC.sbi (*)
2008-06-03 Includes\Spybots.sbi (*)
2008-06-03 Includes\SpybotsC.sbi (*)
2012-09-05 Includes\Spyware.sbi (*)
2012-09-04 Includes\SpywareC.sbi (*)
2010-03-08 Includes\Tracks.uti
2011-09-27 Includes\Trojans.sbi (*)
2012-09-27 Includes\TrojansC-02.sbi (*)
2012-09-20 Includes\TrojansC-03.sbi (*)
2012-09-28 Includes\TrojansC-04.sbi (*)
2012-08-31 Includes\TrojansC-05.sbi (*)
2012-09-07 Includes\TrojansC.sbi (*)
2008-03-04 Plugins\Chai.dll
2008-03-05 Plugins\Fennel.dll
2008-02-26 Plugins\Mate.dll
2008-12-24 Plugins\TCPIPAddress.dll