Hello,
I got some infection that my Avast tried to block but not before it turned off my firewall. I turned it back on and I restarted in windows safe mode and ran spybot S&D but it came up clean. I then ran Malwarebytes and it quarantined the following:
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\574993874 (Trojan.FakeAlert) -> Value: 574993874 -> Quarantined and deleted successfully.
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
Folders Infected:
(No malicious items detected)
Files Infected:
c:\documents and settings\Daniel\local settings\temp\0.8985798632878567.exe (Exploit.Drop.2) -> Quarantined and deleted successfully.
c:\documents and settings\Daniel\local settings\application data\hfx.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
I then ran an avast scan that turned up clean, and a avast boot time scan that came up clean (I had to enter normal windows mode to run the boot time scan).
My problem is after the boot time scan, my firewall was turned off again. So I turned it back on and restarted, and so far it has stayed on. I ran all the scans again but they came up clean. I am afraid I may have some virus/part of virus left going undetected. I would appreciate any help.
Thanks.
DDS (Ver_2011-06-23.01) - NTFSx86
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_21
Run by Daniel at 15:13:57 on 2011-07-24
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1163 [GMT -4:00]
.
AV: avast! Antivirus *Enabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\WINDOWS\System32\basfipm.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Apoint\Apoint.exe
C:\WINDOWS\System32\DSentry.exe
C:\WINDOWS\kdx\KHost.exe
C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe
C:\Program Files\Apoint\Apntex.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Games\Spy\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Games\Firefox\firefox.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.bbc.co.uk/
uInternet Connection Wizard,ShellNext = iexplore
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: {4314F235-1E09-4193-AAAE-042D73E41824} - No File
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\games\spy\spybot~1\SDHelper.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: {A78FAF59-B270-4B28-A275-68A94333847F} - No File
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: {F9C48591-50FA-4A03-BB63-5F3B832C8D88} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [SpybotSD TeaTimer] c:\games\spy\spybot - search & destroy\TeaTimer.exe
mRun: [Apoint] c:\program files\apoint\Apoint.exe
mRun: [DVDSentry] c:\windows\system32\DSentry.exe
mRun: [kdx] c:\windows\kdx\KHost.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /installquiet
mRun: [avast5] c:\progra~1\alwils~1\avast5\avastUI.exe /nogui
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [QuickTime Task] "c:\games\quick\qttask.exe" -atboottime
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe
IE: E&xport to Microsoft Excel
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBC} - c:\program files\java\jre6\bin\ssv.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\games\spy\spybot~1\SDHelper.dll
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://www.apple.com/qtactivex/qtplugin.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {33564D57-0000-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1283659333532
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}
DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA}
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {F54C1137-5E34-4B95-95A5-BA56D4D8D743} - hxxp://www.gamespot.com/KDX/zd/kdx.cab
TCP: DhcpNameServer = 208.33.159.39 71.2.28.14
TCP: Interfaces\{804A7E99-F08A-4061-9A5D-4578AEA20F9C} : DhcpNameServer = 208.33.159.39 71.2.28.14
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
Hosts: 127.0.0.1 www.spywareinfo.com
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\daniel\application data\mozilla\firefox\profiles\tmsh95n6.default\
FF - plugin: c:\documents and settings\daniel\application data\move networks\plugins\npqmp071503000010.dll
FF - plugin: c:\documents and settings\daniel\application data\move networks\plugins\npqmp071701000002.dll
FF - plugin: c:\games\codec\divx\divx player\npDivxPlayerPlugin.dll
FF - plugin: c:\games\codec\divx\divx web player\npdivx32.dll
FF - plugin: c:\games\quick\plugins\npqtplugin.dll
FF - plugin: c:\games\quick\plugins\npqtplugin2.dll
FF - plugin: c:\games\quick\plugins\npqtplugin3.dll
FF - plugin: c:\games\quick\plugins\npqtplugin4.dll
FF - plugin: c:\games\quick\plugins\npqtplugin5.dll
FF - plugin: c:\games\quick\plugins\npqtplugin6.dll
FF - plugin: c:\games\quick\plugins\npqtplugin7.dll
FF - plugin: c:\program files\adobe\reader 9.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\games\firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} - c:\games\firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - c:\games\firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - c:\games\firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - c:\games\firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} - c:\games\firefox\extensions\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\games\firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\games\firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF - Ext: Java Quick Starter: jqs@sun.com - c:\program files\java\jre6\lib\deploy\jqs\ff
FF - Ext: Move Media Player: moveplayer@movenetworks.com - c:\documents and settings\daniel\application data\Move Networks
.
============= SERVICES / DRIVERS ===============
.
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2011-4-27 441176]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2009-1-6 309848]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-1-6 19544]
R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast5\AvastSvc.exe [2010-4-25 42184]
R2 gpib420;GPIB Analyzer;c:\windows\system32\drivers\gpib420.sys [2006-2-13 31334]
R2 GpibPrtK;Gpib Port;c:\windows\system32\drivers\GpibPrtK.sys [2006-2-13 199783]
R2 lvalarmk;lvalarmk;c:\windows\system32\drivers\lvalarmk.dll [2005-7-27 10829]
R2 niarbk;niarbk;c:\windows\system32\drivers\niarbk.dll [2006-7-4 37376]
R2 nibffrk;nibffrk;c:\windows\system32\drivers\nibffrk.dll [2006-7-4 21504]
R2 Nidaq32k;Nidaq32k;c:\windows\system32\drivers\nidaq32k.sys [2006-7-4 674304]
R2 nidimk;nidimk;c:\windows\system32\drivers\nidimk.dll [2006-7-13 159232]
R2 nidmmk;NI DMM and Data Logger Kernel Driver;c:\windows\system32\drivers\nidmmk.dll [2006-7-4 50688]
R2 nidmxfk;nidmxfk;c:\windows\system32\drivers\nidmxfk.dll [2006-7-20 200704]
R2 nidwgk;nidwgk;c:\windows\system32\drivers\nidwgk.dll [2006-7-10 979456]
R2 niemrk;niemrk;c:\windows\system32\drivers\niemrk.dll [2006-7-20 370176]
R2 nifslk;nifslk;c:\windows\system32\drivers\nifslk.dll [2006-7-16 81920]
R2 nigplk;nigplk;c:\windows\system32\drivers\nigplk.dll [2006-2-15 101376]
R2 nihsdrk;nihsdrk;c:\windows\system32\drivers\nihsdrk.dll [2006-7-10 815616]
R2 nimdsk;nimdsk;c:\windows\system32\drivers\nimdsk.dll [2006-7-4 30208]
R2 nimxpk;nimxpk;c:\windows\system32\drivers\nimxpk.dll [2006-7-16 20480]
R2 nipsdk;nipsdk;c:\windows\system32\drivers\nipsdk.dll [2006-7-10 246784]
R2 nipxirmk;nipxirmk;c:\windows\system32\drivers\nipxirmk.dll [2006-7-18 71680]
R2 nisldk;nisldk;c:\windows\system32\drivers\nisldk.dll [2006-7-10 395776]
R2 nisrcdk;nisrcdk;c:\windows\system32\drivers\nisrcdk.dll [2006-7-10 965632]
R2 nistck;nistck;c:\windows\system32\drivers\niSTCk.dll [2006-7-4 111616]
R2 niswdk;niswdk;c:\windows\system32\drivers\niswdk.dll [2006-7-16 496640]
R2 nixsrk;nixsrk;c:\windows\system32\drivers\nixsrk.dll [2006-7-20 1746432]
R2 usb6xxxk;usb6xxxk;c:\windows\system32\drivers\usb6xxxk.dll [2006-7-16 19968]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2007-1-10 24652]
R3 GTICARD;GTICARD;c:\windows\system32\drivers\gticard.sys [2003-2-14 59328]
R3 nicdrk;nicdrk;c:\windows\system32\drivers\nicdrk.dll [2006-7-16 171520]
R3 nimru2k;nimru2k;c:\windows\system32\drivers\nimru2k.dll [2006-7-13 248832]
R3 nimsdrk;nimsdrk;c:\windows\system32\drivers\nimsdrk.dll [2006-7-16 137728]
R3 nimstsk;nimstsk;c:\windows\system32\drivers\nimstsk.dll [2006-7-16 51712]
R3 niscdk;niscdk;c:\windows\system32\drivers\niscdk.dll [2006-7-16 506880]
R3 nisdigk;nisdigk;c:\windows\system32\drivers\nisdigk.dll [2006-7-16 240128]
R3 nitiork;nitiork;c:\windows\system32\drivers\nitiork.dll [2006-7-16 790528]
S3 nidsark;nidsark;c:\windows\system32\drivers\nidsark.dll [2006-7-20 648192]
S3 niesrk;niesrk;c:\windows\system32\drivers\niesrk.dll [2006-7-20 500224]
S3 nimslk;nimslk;c:\windows\system32\drivers\nimslk.dll [2006-6-5 14464]
S3 nimsrlk;nimsrlk;c:\windows\system32\drivers\nimsrlk.dll [2006-6-5 151683]
S3 nipalusb;NI-PAL USB Driver;c:\windows\system32\drivers\nipalusb.sys [2006-7-13 105472]
S3 nisftk;nisftk;c:\windows\system32\drivers\nisftk.dll [2006-7-16 164864]
S3 nismbusk;nismbusk;c:\windows\system32\drivers\nismbusk.sys [2006-7-18 51200]
S3 nispdk;nispdk;c:\windows\system32\drivers\nispdk.dll [2006-7-16 43008]
S3 nissrk;nissrk;c:\windows\system32\drivers\nissrk.dll [2006-7-20 1026560]
S3 nistc2k;nistc2k;c:\windows\system32\drivers\nistc2k.dll [2006-6-6 163328]
S3 nistcrk;nistcrk;c:\windows\system32\drivers\nistcrk.dll [2006-7-16 111616]
S3 NiViFWK;NI-VISA FireWire Driver;c:\windows\system32\drivers\NiViFWK.sys [2006-7-14 8704]
S3 NiViPciK;NI-VISA PCI Driver;c:\windows\system32\drivers\NiViPciK.sys [2006-7-14 48128]
S3 NiViPxiK;NI-VISA PXI Driver;c:\windows\system32\drivers\NiViPxiK.sys [2006-7-14 10752]
S3 niwfrk;niwfrk;c:\windows\system32\drivers\niwfrk.dll [2006-7-20 434688]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2007-11-6 34064]
S4 nidevldu;nidevldu;system32\nipalsm.exe --> system32\nipalsm.exe [?]
.
=============== File Associations ===============
.
.scr=AutoCADScriptFile
.
=============== Created Last 30 ================
.
2011-07-23 20:25:23 0 ----a-w- c:\documents and settings\daniel\local settings\application data\wame.exe
2011-07-23 20:25:23 0 ----a-w- c:\documents and settings\daniel\local settings\application data\jpqi.exe
2011-07-23 20:25:23 0 ----a-w- c:\documents and settings\daniel\local settings\application data\jaea.exe
2011-07-23 20:25:23 0 ----a-w- c:\documents and settings\daniel\local settings\application data\gdxo.exe
2011-07-23 20:25:23 0 ----a-w- c:\documents and settings\all users\application data\vqkh.exe
2011-07-23 20:25:23 0 ----a-w- c:\documents and settings\all users\application data\pvix.exe
2011-07-23 20:25:23 0 ----a-w- c:\documents and settings\all users\application data\pmgd.exe
2011-07-23 20:25:23 0 ----a-w- c:\documents and settings\all users\application data\nxle.exe
.
==================== Find3M ====================
.
2011-07-23 06:41:38 319 ----a-w- C:\drmHeader.bin
2011-07-06 23:52:42 41272 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-07-06 23:52:42 22712 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-07-04 11:43:53 40112 ----a-w- c:\windows\avastSS.scr
2011-07-04 11:36:43 441176 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-06-18 04:16:13 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-06-02 14:02:05 1858944 ----a-w- c:\windows\system32\win32k.sys
2011-05-02 15:31:52 692736 ----a-w- c:\windows\system32\inetcomm.dll
2011-04-29 17:25:27 151552 ----a-w- c:\windows\system32\schannel.dll
2011-04-29 16:19:43 456320 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-04-26 11:07:50 33280 ----a-w- c:\windows\system32\csrsrv.dll
2011-04-26 11:07:50 293376 ----a-w- c:\windows\system32\winsrv.dll
.
============= FINISH: 15:17:42.65 ===============
I got some infection that my Avast tried to block but not before it turned off my firewall. I turned it back on and I restarted in windows safe mode and ran spybot S&D but it came up clean. I then ran Malwarebytes and it quarantined the following:
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\574993874 (Trojan.FakeAlert) -> Value: 574993874 -> Quarantined and deleted successfully.
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
Folders Infected:
(No malicious items detected)
Files Infected:
c:\documents and settings\Daniel\local settings\temp\0.8985798632878567.exe (Exploit.Drop.2) -> Quarantined and deleted successfully.
c:\documents and settings\Daniel\local settings\application data\hfx.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
I then ran an avast scan that turned up clean, and a avast boot time scan that came up clean (I had to enter normal windows mode to run the boot time scan).
My problem is after the boot time scan, my firewall was turned off again. So I turned it back on and restarted, and so far it has stayed on. I ran all the scans again but they came up clean. I am afraid I may have some virus/part of virus left going undetected. I would appreciate any help.
Thanks.
DDS (Ver_2011-06-23.01) - NTFSx86
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_21
Run by Daniel at 15:13:57 on 2011-07-24
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1163 [GMT -4:00]
.
AV: avast! Antivirus *Enabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\WINDOWS\System32\basfipm.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Apoint\Apoint.exe
C:\WINDOWS\System32\DSentry.exe
C:\WINDOWS\kdx\KHost.exe
C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe
C:\Program Files\Apoint\Apntex.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Games\Spy\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Games\Firefox\firefox.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.bbc.co.uk/
uInternet Connection Wizard,ShellNext = iexplore
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: {4314F235-1E09-4193-AAAE-042D73E41824} - No File
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\games\spy\spybot~1\SDHelper.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: {A78FAF59-B270-4B28-A275-68A94333847F} - No File
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: {F9C48591-50FA-4A03-BB63-5F3B832C8D88} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [SpybotSD TeaTimer] c:\games\spy\spybot - search & destroy\TeaTimer.exe
mRun: [Apoint] c:\program files\apoint\Apoint.exe
mRun: [DVDSentry] c:\windows\system32\DSentry.exe
mRun: [kdx] c:\windows\kdx\KHost.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /installquiet
mRun: [avast5] c:\progra~1\alwils~1\avast5\avastUI.exe /nogui
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [QuickTime Task] "c:\games\quick\qttask.exe" -atboottime
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe
IE: E&xport to Microsoft Excel
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBC} - c:\program files\java\jre6\bin\ssv.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\games\spy\spybot~1\SDHelper.dll
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://www.apple.com/qtactivex/qtplugin.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {33564D57-0000-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1283659333532
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}
DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA}
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {F54C1137-5E34-4B95-95A5-BA56D4D8D743} - hxxp://www.gamespot.com/KDX/zd/kdx.cab
TCP: DhcpNameServer = 208.33.159.39 71.2.28.14
TCP: Interfaces\{804A7E99-F08A-4061-9A5D-4578AEA20F9C} : DhcpNameServer = 208.33.159.39 71.2.28.14
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
Hosts: 127.0.0.1 www.spywareinfo.com
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\daniel\application data\mozilla\firefox\profiles\tmsh95n6.default\
FF - plugin: c:\documents and settings\daniel\application data\move networks\plugins\npqmp071503000010.dll
FF - plugin: c:\documents and settings\daniel\application data\move networks\plugins\npqmp071701000002.dll
FF - plugin: c:\games\codec\divx\divx player\npDivxPlayerPlugin.dll
FF - plugin: c:\games\codec\divx\divx web player\npdivx32.dll
FF - plugin: c:\games\quick\plugins\npqtplugin.dll
FF - plugin: c:\games\quick\plugins\npqtplugin2.dll
FF - plugin: c:\games\quick\plugins\npqtplugin3.dll
FF - plugin: c:\games\quick\plugins\npqtplugin4.dll
FF - plugin: c:\games\quick\plugins\npqtplugin5.dll
FF - plugin: c:\games\quick\plugins\npqtplugin6.dll
FF - plugin: c:\games\quick\plugins\npqtplugin7.dll
FF - plugin: c:\program files\adobe\reader 9.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\games\firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} - c:\games\firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - c:\games\firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - c:\games\firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - c:\games\firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} - c:\games\firefox\extensions\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\games\firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\games\firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF - Ext: Java Quick Starter: jqs@sun.com - c:\program files\java\jre6\lib\deploy\jqs\ff
FF - Ext: Move Media Player: moveplayer@movenetworks.com - c:\documents and settings\daniel\application data\Move Networks
.
============= SERVICES / DRIVERS ===============
.
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2011-4-27 441176]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2009-1-6 309848]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-1-6 19544]
R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast5\AvastSvc.exe [2010-4-25 42184]
R2 gpib420;GPIB Analyzer;c:\windows\system32\drivers\gpib420.sys [2006-2-13 31334]
R2 GpibPrtK;Gpib Port;c:\windows\system32\drivers\GpibPrtK.sys [2006-2-13 199783]
R2 lvalarmk;lvalarmk;c:\windows\system32\drivers\lvalarmk.dll [2005-7-27 10829]
R2 niarbk;niarbk;c:\windows\system32\drivers\niarbk.dll [2006-7-4 37376]
R2 nibffrk;nibffrk;c:\windows\system32\drivers\nibffrk.dll [2006-7-4 21504]
R2 Nidaq32k;Nidaq32k;c:\windows\system32\drivers\nidaq32k.sys [2006-7-4 674304]
R2 nidimk;nidimk;c:\windows\system32\drivers\nidimk.dll [2006-7-13 159232]
R2 nidmmk;NI DMM and Data Logger Kernel Driver;c:\windows\system32\drivers\nidmmk.dll [2006-7-4 50688]
R2 nidmxfk;nidmxfk;c:\windows\system32\drivers\nidmxfk.dll [2006-7-20 200704]
R2 nidwgk;nidwgk;c:\windows\system32\drivers\nidwgk.dll [2006-7-10 979456]
R2 niemrk;niemrk;c:\windows\system32\drivers\niemrk.dll [2006-7-20 370176]
R2 nifslk;nifslk;c:\windows\system32\drivers\nifslk.dll [2006-7-16 81920]
R2 nigplk;nigplk;c:\windows\system32\drivers\nigplk.dll [2006-2-15 101376]
R2 nihsdrk;nihsdrk;c:\windows\system32\drivers\nihsdrk.dll [2006-7-10 815616]
R2 nimdsk;nimdsk;c:\windows\system32\drivers\nimdsk.dll [2006-7-4 30208]
R2 nimxpk;nimxpk;c:\windows\system32\drivers\nimxpk.dll [2006-7-16 20480]
R2 nipsdk;nipsdk;c:\windows\system32\drivers\nipsdk.dll [2006-7-10 246784]
R2 nipxirmk;nipxirmk;c:\windows\system32\drivers\nipxirmk.dll [2006-7-18 71680]
R2 nisldk;nisldk;c:\windows\system32\drivers\nisldk.dll [2006-7-10 395776]
R2 nisrcdk;nisrcdk;c:\windows\system32\drivers\nisrcdk.dll [2006-7-10 965632]
R2 nistck;nistck;c:\windows\system32\drivers\niSTCk.dll [2006-7-4 111616]
R2 niswdk;niswdk;c:\windows\system32\drivers\niswdk.dll [2006-7-16 496640]
R2 nixsrk;nixsrk;c:\windows\system32\drivers\nixsrk.dll [2006-7-20 1746432]
R2 usb6xxxk;usb6xxxk;c:\windows\system32\drivers\usb6xxxk.dll [2006-7-16 19968]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2007-1-10 24652]
R3 GTICARD;GTICARD;c:\windows\system32\drivers\gticard.sys [2003-2-14 59328]
R3 nicdrk;nicdrk;c:\windows\system32\drivers\nicdrk.dll [2006-7-16 171520]
R3 nimru2k;nimru2k;c:\windows\system32\drivers\nimru2k.dll [2006-7-13 248832]
R3 nimsdrk;nimsdrk;c:\windows\system32\drivers\nimsdrk.dll [2006-7-16 137728]
R3 nimstsk;nimstsk;c:\windows\system32\drivers\nimstsk.dll [2006-7-16 51712]
R3 niscdk;niscdk;c:\windows\system32\drivers\niscdk.dll [2006-7-16 506880]
R3 nisdigk;nisdigk;c:\windows\system32\drivers\nisdigk.dll [2006-7-16 240128]
R3 nitiork;nitiork;c:\windows\system32\drivers\nitiork.dll [2006-7-16 790528]
S3 nidsark;nidsark;c:\windows\system32\drivers\nidsark.dll [2006-7-20 648192]
S3 niesrk;niesrk;c:\windows\system32\drivers\niesrk.dll [2006-7-20 500224]
S3 nimslk;nimslk;c:\windows\system32\drivers\nimslk.dll [2006-6-5 14464]
S3 nimsrlk;nimsrlk;c:\windows\system32\drivers\nimsrlk.dll [2006-6-5 151683]
S3 nipalusb;NI-PAL USB Driver;c:\windows\system32\drivers\nipalusb.sys [2006-7-13 105472]
S3 nisftk;nisftk;c:\windows\system32\drivers\nisftk.dll [2006-7-16 164864]
S3 nismbusk;nismbusk;c:\windows\system32\drivers\nismbusk.sys [2006-7-18 51200]
S3 nispdk;nispdk;c:\windows\system32\drivers\nispdk.dll [2006-7-16 43008]
S3 nissrk;nissrk;c:\windows\system32\drivers\nissrk.dll [2006-7-20 1026560]
S3 nistc2k;nistc2k;c:\windows\system32\drivers\nistc2k.dll [2006-6-6 163328]
S3 nistcrk;nistcrk;c:\windows\system32\drivers\nistcrk.dll [2006-7-16 111616]
S3 NiViFWK;NI-VISA FireWire Driver;c:\windows\system32\drivers\NiViFWK.sys [2006-7-14 8704]
S3 NiViPciK;NI-VISA PCI Driver;c:\windows\system32\drivers\NiViPciK.sys [2006-7-14 48128]
S3 NiViPxiK;NI-VISA PXI Driver;c:\windows\system32\drivers\NiViPxiK.sys [2006-7-14 10752]
S3 niwfrk;niwfrk;c:\windows\system32\drivers\niwfrk.dll [2006-7-20 434688]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2007-11-6 34064]
S4 nidevldu;nidevldu;system32\nipalsm.exe --> system32\nipalsm.exe [?]
.
=============== File Associations ===============
.
.scr=AutoCADScriptFile
.
=============== Created Last 30 ================
.
2011-07-23 20:25:23 0 ----a-w- c:\documents and settings\daniel\local settings\application data\wame.exe
2011-07-23 20:25:23 0 ----a-w- c:\documents and settings\daniel\local settings\application data\jpqi.exe
2011-07-23 20:25:23 0 ----a-w- c:\documents and settings\daniel\local settings\application data\jaea.exe
2011-07-23 20:25:23 0 ----a-w- c:\documents and settings\daniel\local settings\application data\gdxo.exe
2011-07-23 20:25:23 0 ----a-w- c:\documents and settings\all users\application data\vqkh.exe
2011-07-23 20:25:23 0 ----a-w- c:\documents and settings\all users\application data\pvix.exe
2011-07-23 20:25:23 0 ----a-w- c:\documents and settings\all users\application data\pmgd.exe
2011-07-23 20:25:23 0 ----a-w- c:\documents and settings\all users\application data\nxle.exe
.
==================== Find3M ====================
.
2011-07-23 06:41:38 319 ----a-w- C:\drmHeader.bin
2011-07-06 23:52:42 41272 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-07-06 23:52:42 22712 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-07-04 11:43:53 40112 ----a-w- c:\windows\avastSS.scr
2011-07-04 11:36:43 441176 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-06-18 04:16:13 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-06-02 14:02:05 1858944 ----a-w- c:\windows\system32\win32k.sys
2011-05-02 15:31:52 692736 ----a-w- c:\windows\system32\inetcomm.dll
2011-04-29 17:25:27 151552 ----a-w- c:\windows\system32\schannel.dll
2011-04-29 16:19:43 456320 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-04-26 11:07:50 33280 ----a-w- c:\windows\system32\csrsrv.dll
2011-04-26 11:07:50 293376 ----a-w- c:\windows\system32\winsrv.dll
.
============= FINISH: 15:17:42.65 ===============