Hello guys
I wrote another thread some time ago but it didn't appear :S If it appears later, sorry for posting 2nd.
My problem is a trojan which AVG is white-listing as Trojan Horse Agent3.WJV in WINDOWS/system32/drivers/acpi.sys. My PC runs Windows XP. Those are the preliminaries required:
Malwarebyte:
Malwarebytes Anti-Malware 1.60.1.1000
www.malwarebytes.org
Database version: v2012.03.07.01
Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
Administrator :: 1674-DF9D5B4F95 [administrator]
07.3.2012 г. 14:02:39
mbam-log-2012-03-07 (14-02-39).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 169503
Time elapsed: 7 minute(s), 53 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 2
HKLM\SOFTWARE\Microsoft\Security Center|AntiVirusDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and repaired successfully.
HKLM\SOFTWARE\Microsoft\Security Center|UpdatesDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and repaired successfully.
Folders Detected: 0
(No malicious items detected)
Files Detected: 2
C:\Documents and Settings\Administrator\Local Settings\Temp\253.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Local Settings\Temp\jar_cache8744490021329884550.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully.
(end)
gmer:
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit quick scan 2012-03-07 14:35:32
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 ST3250820A rev.3.AAE
Running: u83rvlzx.exe; Driver: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\afayrfow.sys
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\Ntfs \Ntfs AVGIDSFilter.Sys (IDS Application Activity Monitor Filter Driver./AVG Technologies CZ, s.r.o. )
AttachedDevice \FileSystem\Fastfat \Fat fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat AVGIDSFilter.Sys (IDS Application Activity Monitor Filter Driver./AVG Technologies CZ, s.r.o. )
---- Threads - GMER 1.0.15 ----
Thread System [4:140] 822C739F
Thread System [4:664] 81D330F4
---- EOF - GMER 1.0.15 ----
dds:
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.6001.18702
Run by Administrator at 14:40:00 on 2012-03-07
Microsoft Windows XP Professional 5.1.2600.3.1251.359.1033.18.511.152 [GMT 2:00]
.
AV: AVG Anti-Virus Free Edition 2012 *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
============== Running Processes ===============
.
C:\PROGRA~1\AVG\AVG2012\avgrsx.exe
C:\Program Files\AVG\AVG2012\avgcsrvx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AVG\AVG2012\avgtray.exe
C:\Program Files\Ask.com\Updater\Updater.exe
C:\WINDOWS\system32\ctfmon.exe
svchost.exe
C:\Program Files\AVG\AVG2012\avgwdsvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = about:blank
uURLSearchHooks: uTorrentControl2 Toolbar: {687578b9-7132-4a7a-80e4-30ee31099e03} - c:\program files\utorrentcontrol2\prxtbuTor.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: uTorrentControl2 Toolbar: {687578b9-7132-4a7a-80e4-30ee31099e03} - c:\program files\utorrentcontrol2\prxtbuTor.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
BHO: Skype Plug-In: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
BHO: Ask Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: uTorrentControl2 Toolbar: {687578b9-7132-4a7a-80e4-30ee31099e03} - c:\program files\utorrentcontrol2\prxtbuTor.dll
TB: Ask Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [AVG_TRAY] "c:\program files\avg\avg2012\avgtray.exe"
mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
mRun: [<NO NAME>]
mRun: [ApnUpdater] "c:\program files\ask.com\updater\Updater.exe"
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
TCP: DhcpNameServer = 78.128.36.1 193.24.240.25
TCP: Interfaces\{2F3FA8D9-E659-4470-9AB5-6BA72DD094EF} : DhcpNameServer = 78.128.36.1 193.24.240.25
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\administrator\application data\mozilla\firefox\profiles\0z0654fc.default\
FF - plugin: c:\documents and settings\administrator\local settings\application data\google\update\1.3.21.99\npGoogleUpdate3.dll
FF - plugin: c:\program files\microsoft silverlight\2.0.40115.0\npctrlui.dll
.
============= SERVICES / DRIVERS ===============
.
R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [2011-7-11 23120]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2011-9-13 32592]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2011-10-7 230608]
R1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2011-8-8 40016]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\drivers\dtsoftbus01.sys [2012-2-17 232512]
R2 5606;5606;c:\docume~1\admini~1\locals~1\temp\5606.sys [2012-3-7 145408]
R2 AVGIDSAgent;AVGIDSAgent;c:\program files\avg\avg2012\AVGIDSAgent.exe [2011-10-12 4433248]
R2 avgwd;AVG WatchDog;c:\program files\avg\avg2012\avgwdsvc.exe [2011-8-2 192776]
R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [2011-7-11 134608]
R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [2011-7-11 24272]
R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [2011-10-4 16720]
.
=============== Created Last 30 ================
.
.
==================== Find3M ====================
.
2012-02-17 17:40:17 232512 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2012-02-17 17:09:23 73728 ----a-w- c:\windows\system32\javacpl.cpl
2012-02-17 17:09:23 410984 ----a-w- c:\windows\system32\deploytk.dll
.
============= FINISH: 14:41:08,59 ===============
attach:
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 17.2.2012 г. 19:12:43
System Uptime: 07.3.2012 г. 14:19:36 (0 hours ago)
.
Motherboard: | | VT8367-8233
Processor: AMD Athlon(tm) processor | Socket A | 2000/133mhz
.
==== Disk Partitions =========================
.
A: is Removable
C: is FIXED (NTFS) - 78 GiB total, 22,91 GiB free.
D: is FIXED (NTFS) - 155 GiB total, 23,937 GiB free.
E: is CDROM ()
G: is CDROM ()
.
==== Disabled Device Manager Items =============
.
Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: Realtek RTL8139/810x Family Fast Ethernet NIC
Device ID: PCI\VEN_10EC&DEV_8139&SUBSYS_813910EC&REV_10\3&61AAA01&0&60
Manufacturer: Realtek Semiconductor Corp.
Name: Realtek RTL8139/810x Family Fast Ethernet NIC
PNP Device ID: PCI\VEN_10EC&DEV_8139&SUBSYS_813910EC&REV_10\3&61AAA01&0&60
Service: RTL8023xp
.
==== System Restore Points ===================
.
RP1: 17.2.2012 г. 19:15:58 - System Checkpoint
RP2: 17.2.2012 г. 19:38:44 - Installed Adobe Reader 9.4.0 - Bulgarian.
RP3: 17.2.2012 г. 19:42:50 - Installed Microsoft Office Enterprise 2007
RP4: 17.2.2012 г. 19:51:54 - Printer Driver Send To Microsoft OneNote Driver Installed
RP5: 17.2.2012 г. 19:58:04 - Printer Driver Send To Microsoft OneNote Driver Installed
RP6: 17.2.2012 г. 20:00:03 - Installed SA Dictionary 2008 Beta 4.
RP7: 17.2.2012 г. 20:09:04 - Инсталиран REALTEK GbE & FE Ethernet PCI NIC Driver
RP8: 17.2.2012 г. 20:11:00 - Installed AVG 2012
RP9: 17.2.2012 г. 20:11:18 - Installed AVG 2012
RP10: 17.2.2012 г. 20:14:45 - Installed Platform
RP11: 19.2.2012 г. 00:45:49 - System Checkpoint
RP12: 20.2.2012 г. 10:14:55 - System Checkpoint
RP13: 21.2.2012 г. 12:34:17 - System Checkpoint
RP14: 22.2.2012 г. 19:46:16 - System Checkpoint
RP15: 23.2.2012 г. 19:47:00 - System Checkpoint
RP16: 24.2.2012 г. 20:46:17 - System Checkpoint
RP17: 25.2.2012 г. 20:51:48 - System Checkpoint
RP18: 26.2.2012 г. 21:50:14 - System Checkpoint
RP19: 27.2.2012 г. 22:30:53 - System Checkpoint
RP20: 28.2.2012 г. 22:51:48 - System Checkpoint
RP21: 29.2.2012 г. 23:51:49 - System Checkpoint
RP22: 02.3.2012 г. 00:52:17 - System Checkpoint
RP23: 03.3.2012 г. 01:50:56 - System Checkpoint
RP24: 04.3.2012 г. 02:50:57 - System Checkpoint
RP25: 05.3.2012 г. 03:50:57 - System Checkpoint
RP26: 06.3.2012 г. 04:50:57 - System Checkpoint
RP27: 07.3.2012 г. 07:11:25 - System Checkpoint
.
==== Installed Programs ======================
.
.
%WS4_ARP_DISPLAY%
Архиватор WinRAR
µTorrent
2007 Microsoft Office Suite Service Pack 2 (SP2)
Adobe Flash Player 10 Plugin
Adobe Reader 9.4.0 - Bulgarian
Ashampoo Burning Studio 6 FREE v.6.80
AVG 2012
Bulgarian Keyboards XP by G. Atanasov
CCleaner
DAEMON Tools Lite
Favorite-Games 5.15
Google Chrome
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows XP (KB954550-v5)
Java(TM) 6 Update 13
K-Lite Mega Codec Pack 7.1.0
Malwarebytes Anti-Malware version 1.60.1.1000
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Enterprise 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office Groove MUI (English) 2007
Microsoft Office Groove Setup Metadata MUI (English) 2007
Microsoft Office InfoPath MUI (English) 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Silverlight
Microsoft Software Update for Web Folders (English) 12
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Mozilla Firefox 4.0.1 (x86 bg)
MSXML 4.0 SP3 Parser
PandoraTV Toolbar
PandoraTV Toolbar Updater
Platform
REALTEK GbE & FE Ethernet PCI NIC Driver
SA Dictionary 2008 Beta 4
Skype Toolbars
Skype™ 5.3
The KMPlayer (remove only)
uTorrentControl2 Toolbar
VIA Audio Driver Setup Program
VIA Platform Device Manager
WebFldrs XP
Winamp
Windows Rights Management Client Backwards Compatibility SP2
Windows Rights Management Client with Service Pack 2
.
==== Event Viewer Messages From Past Week ========
.
07.3.2012 г. 14:21:07, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: viaagp
07.3.2012 г. 14:20:52, error: sr [1] - The System Restore filter encountered the unexpected error '0xC0000001' while processing the file '' on the volume 'HarddiskVolume1'. It has stopped monitoring the volume.
.
==== End Of File ===========================
What is next step to go?
I wrote another thread some time ago but it didn't appear :S If it appears later, sorry for posting 2nd.
My problem is a trojan which AVG is white-listing as Trojan Horse Agent3.WJV in WINDOWS/system32/drivers/acpi.sys. My PC runs Windows XP. Those are the preliminaries required:
Malwarebyte:
Malwarebytes Anti-Malware 1.60.1.1000
www.malwarebytes.org
Database version: v2012.03.07.01
Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
Administrator :: 1674-DF9D5B4F95 [administrator]
07.3.2012 г. 14:02:39
mbam-log-2012-03-07 (14-02-39).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 169503
Time elapsed: 7 minute(s), 53 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 2
HKLM\SOFTWARE\Microsoft\Security Center|AntiVirusDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and repaired successfully.
HKLM\SOFTWARE\Microsoft\Security Center|UpdatesDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and repaired successfully.
Folders Detected: 0
(No malicious items detected)
Files Detected: 2
C:\Documents and Settings\Administrator\Local Settings\Temp\253.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Local Settings\Temp\jar_cache8744490021329884550.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully.
(end)
gmer:
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit quick scan 2012-03-07 14:35:32
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 ST3250820A rev.3.AAE
Running: u83rvlzx.exe; Driver: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\afayrfow.sys
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\Ntfs \Ntfs AVGIDSFilter.Sys (IDS Application Activity Monitor Filter Driver./AVG Technologies CZ, s.r.o. )
AttachedDevice \FileSystem\Fastfat \Fat fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat AVGIDSFilter.Sys (IDS Application Activity Monitor Filter Driver./AVG Technologies CZ, s.r.o. )
---- Threads - GMER 1.0.15 ----
Thread System [4:140] 822C739F
Thread System [4:664] 81D330F4
---- EOF - GMER 1.0.15 ----
dds:
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.6001.18702
Run by Administrator at 14:40:00 on 2012-03-07
Microsoft Windows XP Professional 5.1.2600.3.1251.359.1033.18.511.152 [GMT 2:00]
.
AV: AVG Anti-Virus Free Edition 2012 *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
============== Running Processes ===============
.
C:\PROGRA~1\AVG\AVG2012\avgrsx.exe
C:\Program Files\AVG\AVG2012\avgcsrvx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AVG\AVG2012\avgtray.exe
C:\Program Files\Ask.com\Updater\Updater.exe
C:\WINDOWS\system32\ctfmon.exe
svchost.exe
C:\Program Files\AVG\AVG2012\avgwdsvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = about:blank
uURLSearchHooks: uTorrentControl2 Toolbar: {687578b9-7132-4a7a-80e4-30ee31099e03} - c:\program files\utorrentcontrol2\prxtbuTor.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: uTorrentControl2 Toolbar: {687578b9-7132-4a7a-80e4-30ee31099e03} - c:\program files\utorrentcontrol2\prxtbuTor.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
BHO: Skype Plug-In: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
BHO: Ask Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: uTorrentControl2 Toolbar: {687578b9-7132-4a7a-80e4-30ee31099e03} - c:\program files\utorrentcontrol2\prxtbuTor.dll
TB: Ask Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [AVG_TRAY] "c:\program files\avg\avg2012\avgtray.exe"
mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
mRun: [<NO NAME>]
mRun: [ApnUpdater] "c:\program files\ask.com\updater\Updater.exe"
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
TCP: DhcpNameServer = 78.128.36.1 193.24.240.25
TCP: Interfaces\{2F3FA8D9-E659-4470-9AB5-6BA72DD094EF} : DhcpNameServer = 78.128.36.1 193.24.240.25
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\administrator\application data\mozilla\firefox\profiles\0z0654fc.default\
FF - plugin: c:\documents and settings\administrator\local settings\application data\google\update\1.3.21.99\npGoogleUpdate3.dll
FF - plugin: c:\program files\microsoft silverlight\2.0.40115.0\npctrlui.dll
.
============= SERVICES / DRIVERS ===============
.
R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [2011-7-11 23120]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2011-9-13 32592]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2011-10-7 230608]
R1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2011-8-8 40016]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\drivers\dtsoftbus01.sys [2012-2-17 232512]
R2 5606;5606;c:\docume~1\admini~1\locals~1\temp\5606.sys [2012-3-7 145408]
R2 AVGIDSAgent;AVGIDSAgent;c:\program files\avg\avg2012\AVGIDSAgent.exe [2011-10-12 4433248]
R2 avgwd;AVG WatchDog;c:\program files\avg\avg2012\avgwdsvc.exe [2011-8-2 192776]
R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [2011-7-11 134608]
R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [2011-7-11 24272]
R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [2011-10-4 16720]
.
=============== Created Last 30 ================
.
.
==================== Find3M ====================
.
2012-02-17 17:40:17 232512 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2012-02-17 17:09:23 73728 ----a-w- c:\windows\system32\javacpl.cpl
2012-02-17 17:09:23 410984 ----a-w- c:\windows\system32\deploytk.dll
.
============= FINISH: 14:41:08,59 ===============
attach:
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 17.2.2012 г. 19:12:43
System Uptime: 07.3.2012 г. 14:19:36 (0 hours ago)
.
Motherboard: | | VT8367-8233
Processor: AMD Athlon(tm) processor | Socket A | 2000/133mhz
.
==== Disk Partitions =========================
.
A: is Removable
C: is FIXED (NTFS) - 78 GiB total, 22,91 GiB free.
D: is FIXED (NTFS) - 155 GiB total, 23,937 GiB free.
E: is CDROM ()
G: is CDROM ()
.
==== Disabled Device Manager Items =============
.
Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: Realtek RTL8139/810x Family Fast Ethernet NIC
Device ID: PCI\VEN_10EC&DEV_8139&SUBSYS_813910EC&REV_10\3&61AAA01&0&60
Manufacturer: Realtek Semiconductor Corp.
Name: Realtek RTL8139/810x Family Fast Ethernet NIC
PNP Device ID: PCI\VEN_10EC&DEV_8139&SUBSYS_813910EC&REV_10\3&61AAA01&0&60
Service: RTL8023xp
.
==== System Restore Points ===================
.
RP1: 17.2.2012 г. 19:15:58 - System Checkpoint
RP2: 17.2.2012 г. 19:38:44 - Installed Adobe Reader 9.4.0 - Bulgarian.
RP3: 17.2.2012 г. 19:42:50 - Installed Microsoft Office Enterprise 2007
RP4: 17.2.2012 г. 19:51:54 - Printer Driver Send To Microsoft OneNote Driver Installed
RP5: 17.2.2012 г. 19:58:04 - Printer Driver Send To Microsoft OneNote Driver Installed
RP6: 17.2.2012 г. 20:00:03 - Installed SA Dictionary 2008 Beta 4.
RP7: 17.2.2012 г. 20:09:04 - Инсталиран REALTEK GbE & FE Ethernet PCI NIC Driver
RP8: 17.2.2012 г. 20:11:00 - Installed AVG 2012
RP9: 17.2.2012 г. 20:11:18 - Installed AVG 2012
RP10: 17.2.2012 г. 20:14:45 - Installed Platform
RP11: 19.2.2012 г. 00:45:49 - System Checkpoint
RP12: 20.2.2012 г. 10:14:55 - System Checkpoint
RP13: 21.2.2012 г. 12:34:17 - System Checkpoint
RP14: 22.2.2012 г. 19:46:16 - System Checkpoint
RP15: 23.2.2012 г. 19:47:00 - System Checkpoint
RP16: 24.2.2012 г. 20:46:17 - System Checkpoint
RP17: 25.2.2012 г. 20:51:48 - System Checkpoint
RP18: 26.2.2012 г. 21:50:14 - System Checkpoint
RP19: 27.2.2012 г. 22:30:53 - System Checkpoint
RP20: 28.2.2012 г. 22:51:48 - System Checkpoint
RP21: 29.2.2012 г. 23:51:49 - System Checkpoint
RP22: 02.3.2012 г. 00:52:17 - System Checkpoint
RP23: 03.3.2012 г. 01:50:56 - System Checkpoint
RP24: 04.3.2012 г. 02:50:57 - System Checkpoint
RP25: 05.3.2012 г. 03:50:57 - System Checkpoint
RP26: 06.3.2012 г. 04:50:57 - System Checkpoint
RP27: 07.3.2012 г. 07:11:25 - System Checkpoint
.
==== Installed Programs ======================
.
.
%WS4_ARP_DISPLAY%
Архиватор WinRAR
µTorrent
2007 Microsoft Office Suite Service Pack 2 (SP2)
Adobe Flash Player 10 Plugin
Adobe Reader 9.4.0 - Bulgarian
Ashampoo Burning Studio 6 FREE v.6.80
AVG 2012
Bulgarian Keyboards XP by G. Atanasov
CCleaner
DAEMON Tools Lite
Favorite-Games 5.15
Google Chrome
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows XP (KB954550-v5)
Java(TM) 6 Update 13
K-Lite Mega Codec Pack 7.1.0
Malwarebytes Anti-Malware version 1.60.1.1000
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Enterprise 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office Groove MUI (English) 2007
Microsoft Office Groove Setup Metadata MUI (English) 2007
Microsoft Office InfoPath MUI (English) 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Silverlight
Microsoft Software Update for Web Folders (English) 12
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Mozilla Firefox 4.0.1 (x86 bg)
MSXML 4.0 SP3 Parser
PandoraTV Toolbar
PandoraTV Toolbar Updater
Platform
REALTEK GbE & FE Ethernet PCI NIC Driver
SA Dictionary 2008 Beta 4
Skype Toolbars
Skype™ 5.3
The KMPlayer (remove only)
uTorrentControl2 Toolbar
VIA Audio Driver Setup Program
VIA Platform Device Manager
WebFldrs XP
Winamp
Windows Rights Management Client Backwards Compatibility SP2
Windows Rights Management Client with Service Pack 2
.
==== Event Viewer Messages From Past Week ========
.
07.3.2012 г. 14:21:07, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: viaagp
07.3.2012 г. 14:20:52, error: sr [1] - The System Restore filter encountered the unexpected error '0xC0000001' while processing the file '' on the volume 'HarddiskVolume1'. It has stopped monitoring the volume.
.
==== End Of File ===========================
What is next step to go?