Hello
My laptop has been getting warnings about expiro.x infections. Appear to have lost windows media player and audicity.
Here are my logsMalwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org
Database version: 8152
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
11/13/2011 8:37:30 AM
mbam-log-2011-11-13 (08-37-30).txt
Scan type: Quick scan
Objects scanned: 179418
Time elapsed: 6 minute(s), 49 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 10
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 14
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RpcLocator (Virus.Expiro) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{97AEFDD8-2F60-11D3-8A39-00C04F72D8E3} (Virus.Expiro) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS (Virus.Expiro) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MSDTC (Virus.Expiro) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MSIServer (Virus.Expiro) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Microsoft .NET Framework 1.1 (1033) (Virus.Expiro) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WmiApSrv (Virus.Expiro) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{9C757116-4367-4DA9-AC0E-6C6577AD5560} (Virus.Expiro) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{A0B2DD9A-7F53-4E65-8547-851952EC8C96} (Virus.Expiro) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{80D45A3E-3CD8-4FF4-9E99-43A2109049D6} (Virus.Expiro) -> Quarantined and deleted successfully.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
c:\WINDOWS\system32\locator.exe (Virus.Expiro) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\vssvc.exe (Virus.Expiro) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\msdtc.exe (Virus.Expiro) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\msiexec.exe (Virus.Expiro) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\wbem\wmiapsrv.exe (Virus.Expiro) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\mstsc.exe (Virus.Expiro) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\utilman.exe (Trojan.FakeMS) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\cleanmgr.exe (Virus.Expiro) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\mspaint.exe (Virus.Expiro) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\odbcad32.exe (Virus.Expiro) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\wiaacmgr.exe (Virus.Expiro) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\calc.exe (Virus.Expiro) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\charmap.exe (Virus.Expiro) -> Quarantined and deleted successfully.
c:\documents and settings\Willy\local settings\Temp\wpbt0.dll (Exploit.Drop) -> Quarantined and deleted successfully.
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2011-11-13 10:13:23
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-e TOSHIBA_MK5056GSYF rev.LJ001D
Running: g5wc9831.exe; Driver: C:\DOCUME~1\Willy\LOCALS~1\Temp\fxtdipow.sys
---- System - GMER 1.0.15 ----
SSDT \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwOpenProcess [0xB2207F3C]
SSDT \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwTerminateProcess [0xB2207FE4]
SSDT \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwTerminateThread [0xB2208080]
SSDT \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwWriteVirtualMemory [0xB220811C]
---- Kernel code sections - GMER 1.0.15 ----
? edoygsx.sys The system cannot find the file specified. !
.text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xB956F360, 0x3061D7, 0xE8000020]
? C:\DOCUME~1\Willy\LOCALS~1\Temp\fxtdipob.sys The system cannot find the file specified. !
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\Ntfs \Ntfs AVGIDSFilter.Sys (IDS Application Activity Monitor Filter Driver./AVG Technologies CZ, s.r.o. )
AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume1 snapman.sys (Apricorn Snapshot API/Apricorn)
AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume2 snapman.sys (Apricorn Snapshot API/Apricorn)
AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume3 snapman.sys (Apricorn Snapshot API/Apricorn)
AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume4 snapman.sys (Apricorn Snapshot API/Apricorn)
AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
Device \FileSystem\Fastfat \Fat B03F9D20
Device \FileSystem\Fastfat \Fat B04008C1
AttachedDevice \FileSystem\Fastfat \Fat fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat AVGIDSFilter.Sys (IDS Application Activity Monitor Filter Driver./AVG Technologies CZ, s.r.o. )
---- EOF - GMER 1.0.15 ----
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.6001.18702
Run by Willy at 10:17:33 on 2011-11-13
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3070.2232 [GMT -5:00]
.
AV: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
svchost.exe
C:\Program Files\Common Files\Apricorn\Schedule2\schedul2.exe
C:\Program Files\AVG\AVG2012\avgwdsvc.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files\AVG\AVG2012\avgnsx.exe
C:\Program Files\AVG\AVG2012\avgemcx.exe
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
C:\WINDOWS\system32\STacSV.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\OEM02Mon.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Common Files\Logitech\LCD Manager\LCDMon.exe
C:\WINDOWS\system32\KADxMain.exe
C:\Program Files\Common Files\Logitech\LCD Manager\Applets\LCDClock.exe
C:\Program Files\Dell\MediaDirect\PCMService.exe
C:\Program Files\Common Files\Logitech\LCD Manager\Applets\LCDPOP3.exe
C:\Program Files\Common Files\Logitech\LCD Manager\Applets\LCDMedia.exe
C:\Program Files\Apricorn\EZ Gig II\EZGigMonitor.exe
C:\Program Files\Apricorn\EZ Gig II\TimounterMonitor.exe
C:\Program Files\Common Files\Apricorn\Schedule2\schedhlp.exe
C:\Program Files\AVG\AVG2012\avgtray.exe
C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe
C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Documents and Settings\Willy\Application Data\SanDisk\Sansa Updater\SansaDispatch.exe
C:\Program Files\Common Files\SupportSoft\bin\bcont.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Program Files\AVG\AVG2012\avgui.exe
C:\Program Files\AVG\AVG2012\avgrsx.exe
C:\Program Files\AVG\AVG2012\avgcsrvx.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wscntfy.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg2012\avgssie.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
uRun: [SansaDispatch] c:\documents and settings\willy\application data\sandisk\sansa updater\SansaDispatch.exe
uRun: [Desktop Software] "c:\program files\common files\supportsoft\bin\bcont.exe" /ini "c:\program files\comcastui\desktop software\uinstaller.ini" /fromrun /starthidden
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /installquiet
mRun: [NVHotkey] rundll32.exe nvHotkey.dll,Start
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [OEM02Mon.exe] c:\windows\OEM02Mon.exe
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [IntelZeroConfig] "c:\program files\intel\wireless\bin\ZCfgSvc.exe"
mRun: [IntelWireless] "c:\program files\intel\wireless\bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
mRun: [Dell QuickSet] c:\program files\dell\quickset\quickset.exe
mRun: [Launch LCDMon] "c:\program files\common files\logitech\lcd manager\LCDMon.exe"
mRun: [KADxMain] c:\windows\system32\KADxMain.exe
mRun: [PCMService] "c:\program files\dell\mediadirect\PCMService.exe"
mRun: [EZGigMonitor.exe] c:\program files\apricorn\ez gig ii\EZGigMonitor.exe
mRun: [AcronisTimounterMonitor] c:\program files\apricorn\ez gig ii\TimounterMonitor.exe
mRun: [Apricorn Scheduler Service] "c:\program files\common files\apricorn\schedule2\schedhlp.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [AVG_TRAY] "c:\program files\avg\avg2012\avgtray.exe"
mRun: [ddoctorv2] "c:\program files\comcast\desktop doctor\bin\sprtcmd.exe" /P ddoctorv2
mRun: [<NO NAME>]
mRun: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\stsystra.exe
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray
StartupFolder: c:\documents and settings\willy\start menu\programs\startup\desktop.ini~NFDCDVNA
StartupFolder: c:\docume~1\willy\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office\office12\ONENOTEM.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\blueto~1.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe
StartupFolder: c:\documents and settings\all users\start menu\programs\startup\desktop.ini~QAQP9CP6
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\nkbmon~1.lnk - c:\program files\nikon\pictureproject\NkbMonitor.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\window~2.lnk - c:\program files\windows desktop search\WindowsSearch.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444552440000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg2012\avgpp.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
LSA: Authentication Packages = msv1_0 relog_ap
Hosts: 127.0.0.1 www.spywareinfo.com
.
============= SERVICES / DRIVERS ===============
.
R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [2011-11-12 23120]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2011-11-12 32592]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2011-11-12 230608]
R1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2011-11-12 40016]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [2011-11-12 295248]
R2 AVGIDSAgent;AVGIDSAgent;c:\program files\avg\avg2012\AVGIDSAgent.exe [2011-10-12 4433248]
R2 avgwd;AVG WatchDog;c:\program files\avg\avg2012\avgwdsvc.exe [2011-8-2 192776]
R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2011-11-13 366152]
R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [2011-11-12 134608]
R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [2011-11-12 24272]
R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [2011-11-12 16720]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-11-13 22216]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [2008-4-25 14336]
.
=============== File Associations ===============
.
inffile=%windir%\NOTEPAD.EXE %1
txtfile=%windir%\NOTEPAD.EXE %1
.
=============== Created Last 30 ================
.
2011-11-13 13:45:46 4033376 ----a-w- c:\windows\system32\avgr41e.nt
2011-11-13 13:28:28 -------- d-----w- c:\documents and settings\willy\application data\Malwarebytes
2011-11-13 13:28:21 -------- d-----w- c:\documents and settings\all users\application data\Malwarebytes
2011-11-13 13:28:17 22216 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-11-13 13:28:16 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-11-13 01:48:26 24272 ----a-w- c:\windows\system32\drivers\AVGIDSFilter.sys
2011-11-13 01:48:26 23120 ----a-w- c:\windows\system32\drivers\AVGIDSEH.sys
2011-11-13 01:48:26 134608 ----a-w- c:\windows\system32\drivers\AVGIDSDriver.sys
2011-11-13 01:48:25 16720 ----a-w- c:\windows\system32\drivers\AVGIDSShim.sys
2011-11-13 01:48:24 295248 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2011-11-13 01:48:20 32592 ----a-w- c:\windows\system32\drivers\avgrkx86.sys
2011-11-13 01:48:20 230608 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2011-11-13 01:38:33 -------- d-----w- c:\program files\CCleaner
2011-11-13 01:02:02 18727 ----a-w- c:\documents and settings\willy\local settings\application data\dfl20z32.dll
2011-11-13 00:59:07 134 ----a-w- c:\documents and settings\willy\local settings\application data\wsr20zt32.dll
.
==================== Find3M ====================
.
2011-11-13 00:59:04 536576 ----a-w- c:\windows\system32\cmd.exe
2011-11-13 00:59:04 216576 ----a-w- c:\windows\system32\notepad.exe
2011-11-13 00:59:03 363008 ----a-w- c:\windows\system32\osk.exe
2011-11-13 00:59:03 220160 ----a-w- c:\windows\system32\magnify.exe
2011-10-18 23:04:03 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-10-10 14:22:41 692736 ----a-w- c:\windows\system32\inetcomm.dll
2011-09-28 07:06:50 599040 ----a-w- c:\windows\system32\crypt32.dll
2011-09-26 15:41:20 611328 ----a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 15:41:20 220160 ----a-w- c:\windows\system32\oleacc.dll
2011-09-26 15:41:14 20480 ----a-w- c:\windows\system32\oleaccrc.dll
2011-09-06 13:25:11 1867904 ----a-w- c:\windows\system32\win32k.sys
2011-08-22 23:48:55 916480 ----a-w- c:\windows\system32\wininet.dll
2011-08-22 23:48:54 43520 ----a-w- c:\windows\system32\licmgr10.dll
2011-08-22 23:48:54 1469440 ------w- c:\windows\system32\inetcpl.cpl
2011-08-22 11:56:39 385024 ----a-w- c:\windows\system32\html.iec
2011-08-17 13:49:54 138496 ----a-w- c:\windows\system32\drivers\afd.sys
.
============= FINISH: 10:18:03.68 ===============
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume2
Install Date: 5/4/2010 6:44:21 PM
System Uptime: 11/13/2011 8:38:34 AM (2 hours ago)
.
Motherboard: Dell Inc. | |
Processor: Intel(R) Core(TM)2 Duo CPU T9300 @ 2.50GHz | Microprocessor | 2468/200mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 453 GiB total, 314.183 GiB free.
D: is CDROM ()
.
==== Disabled Device Manager Items =============
.
Class GUID:
Description:
Device ID: ROOT\APRICORNDEVICES\SOFTWARE
Manufacturer:
Name:
PNP Device ID: ROOT\APRICORNDEVICES\SOFTWARE
Service:
.
==== System Restore Points ===================
.
RP274: 8/13/2011 8:59:00 PM - System Checkpoint
RP275: 8/15/2011 8:04:01 AM - System Checkpoint
RP276: 8/15/2011 7:17:38 PM - Configured Microsoft Office Home and Student 2007
RP277: 8/17/2011 7:48:00 PM - System Checkpoint
RP278: 8/18/2011 1:38:09 PM - Installed HiJackThis
RP279: 8/18/2011 1:40:18 PM - Configured Microsoft Office Home and Student 2007
RP280: 8/19/2011 6:47:19 PM - System Checkpoint
RP281: 8/21/2011 10:57:21 AM - System Checkpoint
RP282: 8/21/2011 8:07:53 PM - Configured Microsoft Office Home and Student 2007
RP283: 8/21/2011 8:09:14 PM - Configured Microsoft Office Home and Student 2007
RP284: 8/22/2011 10:35:27 PM - System Checkpoint
RP285: 8/27/2011 5:51:15 PM - Software Distribution Service 3.0
RP286: 9/1/2011 3:24:23 PM - System Checkpoint
RP287: 9/3/2011 7:56:11 PM - System Checkpoint
RP288: 9/5/2011 1:35:08 AM - System Checkpoint
RP289: 9/5/2011 12:56:31 PM - Configured Microsoft Office Home and Student 2007
RP290: 9/8/2011 7:18:13 AM - System Checkpoint
RP291: 9/8/2011 8:16:36 PM - Software Distribution Service 3.0
RP292: 9/27/2011 11:59:46 PM - Installed Java(TM) 6 Update 26
RP293: 9/29/2011 11:05:10 AM - System Checkpoint
RP294: 10/1/2011 9:59:22 AM - Installed AVG 2012
RP295: 10/1/2011 9:59:46 AM - Removed AVG 2011
RP296: 10/1/2011 10:00:16 AM - Installed AVG 2012
RP297: 10/1/2011 10:05:15 AM - Removed AVG 2011
RP298: 10/3/2011 8:06:53 PM - System Checkpoint
RP299: 10/4/2011 8:20:50 PM - System Checkpoint
RP300: 10/9/2011 1:33:21 AM - System Checkpoint
RP301: 10/9/2011 2:21:08 PM - Configured Microsoft Office Home and Student 2007
RP302: 10/10/2011 8:04:04 PM - System Checkpoint
RP303: 10/11/2011 7:13:14 PM - Software Distribution Service 3.0
RP304: 10/13/2011 8:13:58 PM - System Checkpoint
RP305: 10/14/2011 5:23:40 AM - Installed Java(TM) 6 Update 26
RP306: 10/15/2011 8:23:14 AM - System Checkpoint
RP307: 10/16/2011 7:17:45 PM - Configured Microsoft Office Home and Student 2007
RP308: 10/19/2011 9:39:19 PM - System Checkpoint
RP309: 10/21/2011 7:23:15 AM - System Checkpoint
RP310: 10/22/2011 11:14:46 AM - System Checkpoint
RP311: 10/23/2011 1:14:25 PM - System Checkpoint
RP312: 10/26/2011 7:48:05 PM - System Checkpoint
RP313: 10/28/2011 1:04:51 PM - System Checkpoint
RP314: 10/29/2011 2:02:49 PM - System Checkpoint
RP315: 11/1/2011 6:56:12 PM - System Checkpoint
RP316: 11/2/2011 11:29:57 PM - System Checkpoint
RP317: 11/7/2011 9:14:59 AM - System Checkpoint
RP318: 11/8/2011 5:49:12 PM - Software Distribution Service 3.0
RP319: 11/11/2011 8:02:34 AM - Software Distribution Service 3.0
RP320: 11/12/2011 7:59:20 PM - AVG restore point before healing of system file
RP321: 11/12/2011 8:00:30 PM - AVG restore point before healing of system file
RP322: 11/12/2011 8:02:45 PM - AVG restore point before healing of system file
RP323: 11/12/2011 8:03:24 PM - AVG restore point before healing of system file
RP324: 11/12/2011 8:14:23 PM - AVG restore point before healing of system file
RP325: 11/12/2011 8:20:01 PM - Software Distribution Service 3.0
RP326: 11/12/2011 8:28:50 PM - AVG restore point before healing of system file
RP327: 11/12/2011 8:30:24 PM - AVG restore point before healing of system file
RP328: 11/12/2011 8:34:56 PM - AVG restore point before healing of system file
RP329: 11/12/2011 8:42:32 PM - AVG restore point before healing of system file
RP330: 11/12/2011 8:46:00 PM - AVG restore point before healing of system file
RP331: 11/12/2011 8:46:49 PM - AVG restore point before healing of system file
RP332: 11/12/2011 8:47:13 PM - AVG restore point before healing of system file
RP333: 11/12/2011 8:47:53 PM - AVG restore point before healing of system file
RP334: 11/12/2011 8:53:45 PM - AVG restore point before healing of system file
RP335: 11/12/2011 8:58:52 PM - Restore Operation
RP336: 11/12/2011 8:59:56 PM - AVG restore point before healing of system file
RP337: 11/12/2011 9:05:23 PM - Restore Operation
RP338: 11/12/2011 9:06:27 PM - AVG restore point before healing of system file
RP339: 11/13/2011 6:55:57 AM - AVG restore point before healing of system file
RP340: 11/13/2011 6:56:07 AM - AVG restore point before healing of system file
RP341: 11/13/2011 7:00:57 AM - AVG restore point before healing of system file
RP342: 11/13/2011 7:06:55 AM - AVG restore point before healing of system file
My laptop has been getting warnings about expiro.x infections. Appear to have lost windows media player and audicity.
Here are my logsMalwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org
Database version: 8152
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
11/13/2011 8:37:30 AM
mbam-log-2011-11-13 (08-37-30).txt
Scan type: Quick scan
Objects scanned: 179418
Time elapsed: 6 minute(s), 49 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 10
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 14
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RpcLocator (Virus.Expiro) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{97AEFDD8-2F60-11D3-8A39-00C04F72D8E3} (Virus.Expiro) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS (Virus.Expiro) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MSDTC (Virus.Expiro) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MSIServer (Virus.Expiro) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Microsoft .NET Framework 1.1 (1033) (Virus.Expiro) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WmiApSrv (Virus.Expiro) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{9C757116-4367-4DA9-AC0E-6C6577AD5560} (Virus.Expiro) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{A0B2DD9A-7F53-4E65-8547-851952EC8C96} (Virus.Expiro) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{80D45A3E-3CD8-4FF4-9E99-43A2109049D6} (Virus.Expiro) -> Quarantined and deleted successfully.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
c:\WINDOWS\system32\locator.exe (Virus.Expiro) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\vssvc.exe (Virus.Expiro) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\msdtc.exe (Virus.Expiro) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\msiexec.exe (Virus.Expiro) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\wbem\wmiapsrv.exe (Virus.Expiro) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\mstsc.exe (Virus.Expiro) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\utilman.exe (Trojan.FakeMS) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\cleanmgr.exe (Virus.Expiro) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\mspaint.exe (Virus.Expiro) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\odbcad32.exe (Virus.Expiro) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\wiaacmgr.exe (Virus.Expiro) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\calc.exe (Virus.Expiro) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\charmap.exe (Virus.Expiro) -> Quarantined and deleted successfully.
c:\documents and settings\Willy\local settings\Temp\wpbt0.dll (Exploit.Drop) -> Quarantined and deleted successfully.
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2011-11-13 10:13:23
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-e TOSHIBA_MK5056GSYF rev.LJ001D
Running: g5wc9831.exe; Driver: C:\DOCUME~1\Willy\LOCALS~1\Temp\fxtdipow.sys
---- System - GMER 1.0.15 ----
SSDT \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwOpenProcess [0xB2207F3C]
SSDT \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwTerminateProcess [0xB2207FE4]
SSDT \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwTerminateThread [0xB2208080]
SSDT \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwWriteVirtualMemory [0xB220811C]
---- Kernel code sections - GMER 1.0.15 ----
? edoygsx.sys The system cannot find the file specified. !
.text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xB956F360, 0x3061D7, 0xE8000020]
? C:\DOCUME~1\Willy\LOCALS~1\Temp\fxtdipob.sys The system cannot find the file specified. !
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\Ntfs \Ntfs AVGIDSFilter.Sys (IDS Application Activity Monitor Filter Driver./AVG Technologies CZ, s.r.o. )
AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume1 snapman.sys (Apricorn Snapshot API/Apricorn)
AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume2 snapman.sys (Apricorn Snapshot API/Apricorn)
AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume3 snapman.sys (Apricorn Snapshot API/Apricorn)
AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume4 snapman.sys (Apricorn Snapshot API/Apricorn)
AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
Device \FileSystem\Fastfat \Fat B03F9D20
Device \FileSystem\Fastfat \Fat B04008C1
AttachedDevice \FileSystem\Fastfat \Fat fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat AVGIDSFilter.Sys (IDS Application Activity Monitor Filter Driver./AVG Technologies CZ, s.r.o. )
---- EOF - GMER 1.0.15 ----
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.6001.18702
Run by Willy at 10:17:33 on 2011-11-13
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3070.2232 [GMT -5:00]
.
AV: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
svchost.exe
C:\Program Files\Common Files\Apricorn\Schedule2\schedul2.exe
C:\Program Files\AVG\AVG2012\avgwdsvc.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files\AVG\AVG2012\avgnsx.exe
C:\Program Files\AVG\AVG2012\avgemcx.exe
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
C:\WINDOWS\system32\STacSV.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\OEM02Mon.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Common Files\Logitech\LCD Manager\LCDMon.exe
C:\WINDOWS\system32\KADxMain.exe
C:\Program Files\Common Files\Logitech\LCD Manager\Applets\LCDClock.exe
C:\Program Files\Dell\MediaDirect\PCMService.exe
C:\Program Files\Common Files\Logitech\LCD Manager\Applets\LCDPOP3.exe
C:\Program Files\Common Files\Logitech\LCD Manager\Applets\LCDMedia.exe
C:\Program Files\Apricorn\EZ Gig II\EZGigMonitor.exe
C:\Program Files\Apricorn\EZ Gig II\TimounterMonitor.exe
C:\Program Files\Common Files\Apricorn\Schedule2\schedhlp.exe
C:\Program Files\AVG\AVG2012\avgtray.exe
C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe
C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Documents and Settings\Willy\Application Data\SanDisk\Sansa Updater\SansaDispatch.exe
C:\Program Files\Common Files\SupportSoft\bin\bcont.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Program Files\AVG\AVG2012\avgui.exe
C:\Program Files\AVG\AVG2012\avgrsx.exe
C:\Program Files\AVG\AVG2012\avgcsrvx.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wscntfy.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg2012\avgssie.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
uRun: [SansaDispatch] c:\documents and settings\willy\application data\sandisk\sansa updater\SansaDispatch.exe
uRun: [Desktop Software] "c:\program files\common files\supportsoft\bin\bcont.exe" /ini "c:\program files\comcastui\desktop software\uinstaller.ini" /fromrun /starthidden
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /installquiet
mRun: [NVHotkey] rundll32.exe nvHotkey.dll,Start
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [OEM02Mon.exe] c:\windows\OEM02Mon.exe
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [IntelZeroConfig] "c:\program files\intel\wireless\bin\ZCfgSvc.exe"
mRun: [IntelWireless] "c:\program files\intel\wireless\bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
mRun: [Dell QuickSet] c:\program files\dell\quickset\quickset.exe
mRun: [Launch LCDMon] "c:\program files\common files\logitech\lcd manager\LCDMon.exe"
mRun: [KADxMain] c:\windows\system32\KADxMain.exe
mRun: [PCMService] "c:\program files\dell\mediadirect\PCMService.exe"
mRun: [EZGigMonitor.exe] c:\program files\apricorn\ez gig ii\EZGigMonitor.exe
mRun: [AcronisTimounterMonitor] c:\program files\apricorn\ez gig ii\TimounterMonitor.exe
mRun: [Apricorn Scheduler Service] "c:\program files\common files\apricorn\schedule2\schedhlp.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [AVG_TRAY] "c:\program files\avg\avg2012\avgtray.exe"
mRun: [ddoctorv2] "c:\program files\comcast\desktop doctor\bin\sprtcmd.exe" /P ddoctorv2
mRun: [<NO NAME>]
mRun: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\stsystra.exe
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray
StartupFolder: c:\documents and settings\willy\start menu\programs\startup\desktop.ini~NFDCDVNA
StartupFolder: c:\docume~1\willy\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office\office12\ONENOTEM.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\blueto~1.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe
StartupFolder: c:\documents and settings\all users\start menu\programs\startup\desktop.ini~QAQP9CP6
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\nkbmon~1.lnk - c:\program files\nikon\pictureproject\NkbMonitor.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\window~2.lnk - c:\program files\windows desktop search\WindowsSearch.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444552440000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg2012\avgpp.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
LSA: Authentication Packages = msv1_0 relog_ap
Hosts: 127.0.0.1 www.spywareinfo.com
.
============= SERVICES / DRIVERS ===============
.
R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [2011-11-12 23120]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2011-11-12 32592]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2011-11-12 230608]
R1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2011-11-12 40016]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [2011-11-12 295248]
R2 AVGIDSAgent;AVGIDSAgent;c:\program files\avg\avg2012\AVGIDSAgent.exe [2011-10-12 4433248]
R2 avgwd;AVG WatchDog;c:\program files\avg\avg2012\avgwdsvc.exe [2011-8-2 192776]
R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2011-11-13 366152]
R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [2011-11-12 134608]
R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [2011-11-12 24272]
R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [2011-11-12 16720]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-11-13 22216]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [2008-4-25 14336]
.
=============== File Associations ===============
.
inffile=%windir%\NOTEPAD.EXE %1
txtfile=%windir%\NOTEPAD.EXE %1
.
=============== Created Last 30 ================
.
2011-11-13 13:45:46 4033376 ----a-w- c:\windows\system32\avgr41e.nt
2011-11-13 13:28:28 -------- d-----w- c:\documents and settings\willy\application data\Malwarebytes
2011-11-13 13:28:21 -------- d-----w- c:\documents and settings\all users\application data\Malwarebytes
2011-11-13 13:28:17 22216 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-11-13 13:28:16 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-11-13 01:48:26 24272 ----a-w- c:\windows\system32\drivers\AVGIDSFilter.sys
2011-11-13 01:48:26 23120 ----a-w- c:\windows\system32\drivers\AVGIDSEH.sys
2011-11-13 01:48:26 134608 ----a-w- c:\windows\system32\drivers\AVGIDSDriver.sys
2011-11-13 01:48:25 16720 ----a-w- c:\windows\system32\drivers\AVGIDSShim.sys
2011-11-13 01:48:24 295248 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2011-11-13 01:48:20 32592 ----a-w- c:\windows\system32\drivers\avgrkx86.sys
2011-11-13 01:48:20 230608 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2011-11-13 01:38:33 -------- d-----w- c:\program files\CCleaner
2011-11-13 01:02:02 18727 ----a-w- c:\documents and settings\willy\local settings\application data\dfl20z32.dll
2011-11-13 00:59:07 134 ----a-w- c:\documents and settings\willy\local settings\application data\wsr20zt32.dll
.
==================== Find3M ====================
.
2011-11-13 00:59:04 536576 ----a-w- c:\windows\system32\cmd.exe
2011-11-13 00:59:04 216576 ----a-w- c:\windows\system32\notepad.exe
2011-11-13 00:59:03 363008 ----a-w- c:\windows\system32\osk.exe
2011-11-13 00:59:03 220160 ----a-w- c:\windows\system32\magnify.exe
2011-10-18 23:04:03 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-10-10 14:22:41 692736 ----a-w- c:\windows\system32\inetcomm.dll
2011-09-28 07:06:50 599040 ----a-w- c:\windows\system32\crypt32.dll
2011-09-26 15:41:20 611328 ----a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 15:41:20 220160 ----a-w- c:\windows\system32\oleacc.dll
2011-09-26 15:41:14 20480 ----a-w- c:\windows\system32\oleaccrc.dll
2011-09-06 13:25:11 1867904 ----a-w- c:\windows\system32\win32k.sys
2011-08-22 23:48:55 916480 ----a-w- c:\windows\system32\wininet.dll
2011-08-22 23:48:54 43520 ----a-w- c:\windows\system32\licmgr10.dll
2011-08-22 23:48:54 1469440 ------w- c:\windows\system32\inetcpl.cpl
2011-08-22 11:56:39 385024 ----a-w- c:\windows\system32\html.iec
2011-08-17 13:49:54 138496 ----a-w- c:\windows\system32\drivers\afd.sys
.
============= FINISH: 10:18:03.68 ===============
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume2
Install Date: 5/4/2010 6:44:21 PM
System Uptime: 11/13/2011 8:38:34 AM (2 hours ago)
.
Motherboard: Dell Inc. | |
Processor: Intel(R) Core(TM)2 Duo CPU T9300 @ 2.50GHz | Microprocessor | 2468/200mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 453 GiB total, 314.183 GiB free.
D: is CDROM ()
.
==== Disabled Device Manager Items =============
.
Class GUID:
Description:
Device ID: ROOT\APRICORNDEVICES\SOFTWARE
Manufacturer:
Name:
PNP Device ID: ROOT\APRICORNDEVICES\SOFTWARE
Service:
.
==== System Restore Points ===================
.
RP274: 8/13/2011 8:59:00 PM - System Checkpoint
RP275: 8/15/2011 8:04:01 AM - System Checkpoint
RP276: 8/15/2011 7:17:38 PM - Configured Microsoft Office Home and Student 2007
RP277: 8/17/2011 7:48:00 PM - System Checkpoint
RP278: 8/18/2011 1:38:09 PM - Installed HiJackThis
RP279: 8/18/2011 1:40:18 PM - Configured Microsoft Office Home and Student 2007
RP280: 8/19/2011 6:47:19 PM - System Checkpoint
RP281: 8/21/2011 10:57:21 AM - System Checkpoint
RP282: 8/21/2011 8:07:53 PM - Configured Microsoft Office Home and Student 2007
RP283: 8/21/2011 8:09:14 PM - Configured Microsoft Office Home and Student 2007
RP284: 8/22/2011 10:35:27 PM - System Checkpoint
RP285: 8/27/2011 5:51:15 PM - Software Distribution Service 3.0
RP286: 9/1/2011 3:24:23 PM - System Checkpoint
RP287: 9/3/2011 7:56:11 PM - System Checkpoint
RP288: 9/5/2011 1:35:08 AM - System Checkpoint
RP289: 9/5/2011 12:56:31 PM - Configured Microsoft Office Home and Student 2007
RP290: 9/8/2011 7:18:13 AM - System Checkpoint
RP291: 9/8/2011 8:16:36 PM - Software Distribution Service 3.0
RP292: 9/27/2011 11:59:46 PM - Installed Java(TM) 6 Update 26
RP293: 9/29/2011 11:05:10 AM - System Checkpoint
RP294: 10/1/2011 9:59:22 AM - Installed AVG 2012
RP295: 10/1/2011 9:59:46 AM - Removed AVG 2011
RP296: 10/1/2011 10:00:16 AM - Installed AVG 2012
RP297: 10/1/2011 10:05:15 AM - Removed AVG 2011
RP298: 10/3/2011 8:06:53 PM - System Checkpoint
RP299: 10/4/2011 8:20:50 PM - System Checkpoint
RP300: 10/9/2011 1:33:21 AM - System Checkpoint
RP301: 10/9/2011 2:21:08 PM - Configured Microsoft Office Home and Student 2007
RP302: 10/10/2011 8:04:04 PM - System Checkpoint
RP303: 10/11/2011 7:13:14 PM - Software Distribution Service 3.0
RP304: 10/13/2011 8:13:58 PM - System Checkpoint
RP305: 10/14/2011 5:23:40 AM - Installed Java(TM) 6 Update 26
RP306: 10/15/2011 8:23:14 AM - System Checkpoint
RP307: 10/16/2011 7:17:45 PM - Configured Microsoft Office Home and Student 2007
RP308: 10/19/2011 9:39:19 PM - System Checkpoint
RP309: 10/21/2011 7:23:15 AM - System Checkpoint
RP310: 10/22/2011 11:14:46 AM - System Checkpoint
RP311: 10/23/2011 1:14:25 PM - System Checkpoint
RP312: 10/26/2011 7:48:05 PM - System Checkpoint
RP313: 10/28/2011 1:04:51 PM - System Checkpoint
RP314: 10/29/2011 2:02:49 PM - System Checkpoint
RP315: 11/1/2011 6:56:12 PM - System Checkpoint
RP316: 11/2/2011 11:29:57 PM - System Checkpoint
RP317: 11/7/2011 9:14:59 AM - System Checkpoint
RP318: 11/8/2011 5:49:12 PM - Software Distribution Service 3.0
RP319: 11/11/2011 8:02:34 AM - Software Distribution Service 3.0
RP320: 11/12/2011 7:59:20 PM - AVG restore point before healing of system file
RP321: 11/12/2011 8:00:30 PM - AVG restore point before healing of system file
RP322: 11/12/2011 8:02:45 PM - AVG restore point before healing of system file
RP323: 11/12/2011 8:03:24 PM - AVG restore point before healing of system file
RP324: 11/12/2011 8:14:23 PM - AVG restore point before healing of system file
RP325: 11/12/2011 8:20:01 PM - Software Distribution Service 3.0
RP326: 11/12/2011 8:28:50 PM - AVG restore point before healing of system file
RP327: 11/12/2011 8:30:24 PM - AVG restore point before healing of system file
RP328: 11/12/2011 8:34:56 PM - AVG restore point before healing of system file
RP329: 11/12/2011 8:42:32 PM - AVG restore point before healing of system file
RP330: 11/12/2011 8:46:00 PM - AVG restore point before healing of system file
RP331: 11/12/2011 8:46:49 PM - AVG restore point before healing of system file
RP332: 11/12/2011 8:47:13 PM - AVG restore point before healing of system file
RP333: 11/12/2011 8:47:53 PM - AVG restore point before healing of system file
RP334: 11/12/2011 8:53:45 PM - AVG restore point before healing of system file
RP335: 11/12/2011 8:58:52 PM - Restore Operation
RP336: 11/12/2011 8:59:56 PM - AVG restore point before healing of system file
RP337: 11/12/2011 9:05:23 PM - Restore Operation
RP338: 11/12/2011 9:06:27 PM - AVG restore point before healing of system file
RP339: 11/13/2011 6:55:57 AM - AVG restore point before healing of system file
RP340: 11/13/2011 6:56:07 AM - AVG restore point before healing of system file
RP341: 11/13/2011 7:00:57 AM - AVG restore point before healing of system file
RP342: 11/13/2011 7:06:55 AM - AVG restore point before healing of system file