Hello!
I have AVG installed and I receive continuous threat alerts for the IDP.Trojan.1C8D1A13 & Crypt.AQLW viruses/malware. I have reviewed and followed the instructions given in the document "5-step Viruses/Spyware/Malware Preliminary Removal Instructions". Here are the logs that were generated:
Malwarebytes Anti-Malware (Trial) 1.61.0.1400
Database version: v2012.05.02.06
Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
Matthew :: MATTDESKTOP [administrator]
Protection: Enabled
5/2/2012 2:30:01 PM
mbam-log-2012-05-02 (14-30-01).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 206304
Time elapsed: 13 minute(s), 40 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 50
HKCR\AppID\{E5345AE2-094A-4ae3-9578-1787ECDA733A} (Adware.PeDev) -> Quarantined and deleted successfully.
HKCR\Typelib\{28252909-1BE7-4236-BD77-B59CFF2AE6C4} (Adware.PeDev) -> Quarantined and deleted successfully.
HKCR\Interface\{1E5DD896-FD9B-4D31-831A-2427216A0A02} (Adware.PeDev) -> Quarantined and deleted successfully.
HKCR\Typelib\{2A7DB8D1-43BE-4AD3-A81E-9BB8C9D00073} (Adware.Delphinmediaviewer) -> Quarantined and deleted successfully.
HKCR\Interface\{2BB15D36-43BE-4743-A3A0-3308F4B1A610} (Adware.Delphinmediaviewer) -> Quarantined and deleted successfully.
HKCR\Typelib\{58634367-D62B-4C2C-86BE-5AAC45CDB671} (Trojan.BHO) -> Quarantined and deleted successfully.
HKCR\Interface\{A36A5936-CFD9-4B41-86BD-319A1931887F} (Trojan.BHO) -> Quarantined and deleted successfully.
HKCR\Typelib\{67907B3C-A6EF-4A01-99AD-3FCD5F526429} (Adware.ISTBar) -> Quarantined and deleted successfully.
HKCR\Interface\{0985C112-2562-46F2-8DA6-92648BA4630F} (Adware.ISTBar) -> Quarantined and deleted successfully.
HKCR\Typelib\{D0288A41-9855-4A9B-8316-BABE243648DA} (Trojan.BHO) -> Quarantined and deleted successfully.
HKCR\Interface\{339D8AFF-0B42-4260-AD82-78CE605A9543} (Trojan.BHO) -> Quarantined and deleted successfully.
HKCR\Typelib\{E9A5B71C-093B-4F34-AF07-34FCA89BA0DF} (Adware.ISTBar) -> Quarantined and deleted successfully.
HKCR\Interface\{0E704BA4-C517-4BE7-A1CD-C3FFDA1E1FFE} (Adware.ISTBar) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{8CBA1B49-8144-4721-A7B1-64C578C9EED7} (Trojan.BHO) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00000010-6F7D-442C-93E3-4A4827C2E4C8} (Adware.NetOptimizer) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{00000010-6F7D-442C-93E3-4A4827C2E4C8} (Adware.NetOptimizer) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{531BE052-76FC-4B05-9CCD-AF6AA265113C} (Trojan.Banker) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{531BE052-76FC-4B05-9CCD-AF6AA265113C} (Trojan.Banker) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{549B5CA7-4A86-11D7-A4DF-000874180BB3} (Trojan.Agent) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{FAA356E4-D317-42A6-AB41-A3021C6E7D52} (Adware.ISTBar) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{F919FBD3-A96B-4679-AF26-F551439BB5FD} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKCR\fis.amo (Adware.SmartShopper) -> Quarantined and deleted successfully.
HKCR\fis.amo.1 (Adware.SmartShopper) -> Quarantined and deleted successfully.
HKCR\fis.momo (Adware.SmartShopper) -> Quarantined and deleted successfully.
HKCR\fis.momo.1 (Adware.SmartShopper) -> Quarantined and deleted successfully.
HKCR\fis.ohb (Adware.SmartShopper) -> Quarantined and deleted successfully.
HKCR\fis.ohb.1 (Adware.SmartShopper) -> Quarantined and deleted successfully.
HKCR\PAE_BHO.PEDEV_IEListener (Adware.PeDev) -> Quarantined and deleted successfully.
HKCR\PAE_BHO.PEDEV_IEListener.1 (Adware.PeDev) -> Quarantined and deleted successfully.
HKCR\PEDEV.PEDEVOptions (Adware.PeDev) -> Quarantined and deleted successfully.
HKCR\PEDEV.PEDEVOptions.1 (Adware.PeDev) -> Quarantined and deleted successfully.
HKCR\PEDEV.PEDEVPDM (Adware.PeDev) -> Quarantined and deleted successfully.
HKCR\PEDEV.PEDEVPDM.1 (Adware.PeDev) -> Quarantined and deleted successfully.
HKCR\PEDEV.PEDEVStatistic (Adware.PeDev) -> Quarantined and deleted successfully.
HKCR\PEDEV.PEDEVStatistic.1 (Adware.PeDev) -> Quarantined and deleted successfully.
HKCR\PEDEV.PEDEVUrlChecker (Adware.PeDev) -> Quarantined and deleted successfully.
HKCR\PEDEV.PEDEVUrlChecker.1 (Adware.PeDev) -> Quarantined and deleted successfully.
HKCR\PEDEV_BHO.PEDEV (Adware.PeDev) -> Quarantined and deleted successfully.
HKCR\PEDEV_BHO.PEDEV.1 (Adware.PeDev) -> Quarantined and deleted successfully.
HKCR\sp (TrojanProxy.Agent) -> Quarantined and deleted successfully.
HKCR\AppID\PEDEV.DLL (Adware.PeDev) -> Quarantined and deleted successfully.
HKCR\AppID\pedev.EXE (Adware.PeDev) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\884E079B2F78C10334A79B210E9EA2B7 (Adware.SearchTool) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\OTGV1DNWQQ (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\SmartShopper (Adware.SmartShopper) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\XBV6RD5SZF (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\AntiVirus 2010 (Rogue.AntiVirus2010) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\sp (TrojanProxy.Agent) -> Quarantined and deleted successfully.
HKLM\System\CurrentControlSet\Services\SPService (TrojanProxy.Agent) -> Quarantined and deleted successfully.
Registry Values Detected: 8
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar|{FAA356E4-D317-42A6-AB41-A3021C6E7D52} (Adware.ISTBar) -> Data: -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Internet Explorer\Extensions\CmdMapping\{10E42047-DEB9-4535-A118-B3F6EC39B807} (Adware.ISTBar) -> Data: -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Internet Explorer\Extensions\CmdMapping|{10E42047-DEB9-4535-A118-B3F6EC39B807} (Adware.ISTBar) -> Data: 8198 -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{FAA356E4-D317-42a6-AB41-A3021C6E7D52} (Adware.ISTBar) -> Data: -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{96AFBE69-C3B0-4b00-8578-D933D2896EE2} (TrojanProxy.Agent) -> Data: -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved|{96AFBE69-C3B0-4b00-8578-D933D2896EE2} (TrojanProxy.Agent) -> Data: sp -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost|netsvc (TrojanProxy.Agent) -> Data: SPService^w^ -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad|PSFactoryBuffer (Trojan.Agent) -> Data: {ffe8b3ec-23c7-4c2b-9adb-b70d4929f38c} -> Quarantined and deleted successfully.
Registry Data Items Detected: 1
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon|Userinit (Hijack.Userinit) -> Bad: (C:\WINDOWS\system32\userinit.exe,C:\Windows\System32\wsaupdater.exe,) Good: (Userinit.exe) -> Quarantined and repaired successfully.
Folders Detected: 5
C:\Documents and Settings\All Users\Application Data\WinAntiVirus Pro 2006 (Rogue.WinAntiVirus) -> Quarantined and deleted successfully.
C:\Documents and Settings\Matthew\Application Data\WinAntiVirus Pro 2006 (Rogue.WinAntiVirus) -> Quarantined and deleted successfully.
C:\Documents and Settings\Matthew\Application Data\WinAntiVirus Pro 2006\Logs (Rogue.WinAntiVirus) -> Quarantined and deleted successfully.
C:\Program Files\Common Files\WinAntiVirus Pro 2006 (Rogue.WinAntiVirus) -> Quarantined and deleted successfully.
C:\Program Files\WinAntiVirus Pro 2006 (Rogue.WinAntiVirus) -> Quarantined and deleted successfully.
Files Detected: 11
C:\WINDOWS\SYSTEM32\DRIVERS\cdrom.sys (Rootkit.0Access) -> Quarantined and deleted successfully.
C:\WINDOWS\Tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\Matthew\Application Data\WinAntiVirus Pro 2006\PGE.dat (Rogue.WinAntiVirus) -> Quarantined and deleted successfully.
C:\Documents and Settings\Matthew\Application Data\WinAntiVirus Pro 2006\Logs\update.log (Rogue.WinAntiVirus) -> Quarantined and deleted successfully.
C:\Documents and Settings\Matthew\Application Data\WinAntiVirus Pro 2006\Logs\wa6Support.log (Rogue.WinAntiVirus) -> Quarantined and deleted successfully.
C:\Documents and Settings\Matthew\Application Data\WinAntiVirus Pro 2006\Logs\winav.log (Rogue.WinAntiVirus) -> Quarantined and deleted successfully.
C:\Program Files\WinAntiVirus Pro 2006\msvcp71.dll (Rogue.WinAntiVirus) -> Quarantined and deleted successfully.
C:\Program Files\WinAntiVirus Pro 2006\msvcr71.dll (Rogue.WinAntiVirus) -> Quarantined and deleted successfully.
C:\WINDOWS\smdat32a.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\smdat32m.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
(end)
GMER 1.0.15.15641
Rootkit quick scan 2012-05-02 15:05:46
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 ST340014A rev.3.16
Running: cy0dl57e.exe; Driver: C:\DOCUME~1\Matthew\LOCALS~1\Temp\pwloipow.sys
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\Ntfs \Ntfs AVGIDSFilter.Sys (IDS Application Activity Monitor Filter Driver./AVG Technologies CZ, s.r.o. )
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat AVGIDSFilter.Sys (IDS Application Activity Monitor Filter Driver./AVG Technologies CZ, s.r.o. )
AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
---- EOF - GMER 1.0.15 ----
DDS txt and DDS attach in following thread.....
I have AVG installed and I receive continuous threat alerts for the IDP.Trojan.1C8D1A13 & Crypt.AQLW viruses/malware. I have reviewed and followed the instructions given in the document "5-step Viruses/Spyware/Malware Preliminary Removal Instructions". Here are the logs that were generated:
Malwarebytes Anti-Malware (Trial) 1.61.0.1400
Database version: v2012.05.02.06
Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
Matthew :: MATTDESKTOP [administrator]
Protection: Enabled
5/2/2012 2:30:01 PM
mbam-log-2012-05-02 (14-30-01).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 206304
Time elapsed: 13 minute(s), 40 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 50
HKCR\AppID\{E5345AE2-094A-4ae3-9578-1787ECDA733A} (Adware.PeDev) -> Quarantined and deleted successfully.
HKCR\Typelib\{28252909-1BE7-4236-BD77-B59CFF2AE6C4} (Adware.PeDev) -> Quarantined and deleted successfully.
HKCR\Interface\{1E5DD896-FD9B-4D31-831A-2427216A0A02} (Adware.PeDev) -> Quarantined and deleted successfully.
HKCR\Typelib\{2A7DB8D1-43BE-4AD3-A81E-9BB8C9D00073} (Adware.Delphinmediaviewer) -> Quarantined and deleted successfully.
HKCR\Interface\{2BB15D36-43BE-4743-A3A0-3308F4B1A610} (Adware.Delphinmediaviewer) -> Quarantined and deleted successfully.
HKCR\Typelib\{58634367-D62B-4C2C-86BE-5AAC45CDB671} (Trojan.BHO) -> Quarantined and deleted successfully.
HKCR\Interface\{A36A5936-CFD9-4B41-86BD-319A1931887F} (Trojan.BHO) -> Quarantined and deleted successfully.
HKCR\Typelib\{67907B3C-A6EF-4A01-99AD-3FCD5F526429} (Adware.ISTBar) -> Quarantined and deleted successfully.
HKCR\Interface\{0985C112-2562-46F2-8DA6-92648BA4630F} (Adware.ISTBar) -> Quarantined and deleted successfully.
HKCR\Typelib\{D0288A41-9855-4A9B-8316-BABE243648DA} (Trojan.BHO) -> Quarantined and deleted successfully.
HKCR\Interface\{339D8AFF-0B42-4260-AD82-78CE605A9543} (Trojan.BHO) -> Quarantined and deleted successfully.
HKCR\Typelib\{E9A5B71C-093B-4F34-AF07-34FCA89BA0DF} (Adware.ISTBar) -> Quarantined and deleted successfully.
HKCR\Interface\{0E704BA4-C517-4BE7-A1CD-C3FFDA1E1FFE} (Adware.ISTBar) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{8CBA1B49-8144-4721-A7B1-64C578C9EED7} (Trojan.BHO) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00000010-6F7D-442C-93E3-4A4827C2E4C8} (Adware.NetOptimizer) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{00000010-6F7D-442C-93E3-4A4827C2E4C8} (Adware.NetOptimizer) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{531BE052-76FC-4B05-9CCD-AF6AA265113C} (Trojan.Banker) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{531BE052-76FC-4B05-9CCD-AF6AA265113C} (Trojan.Banker) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{549B5CA7-4A86-11D7-A4DF-000874180BB3} (Trojan.Agent) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{FAA356E4-D317-42A6-AB41-A3021C6E7D52} (Adware.ISTBar) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{F919FBD3-A96B-4679-AF26-F551439BB5FD} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKCR\fis.amo (Adware.SmartShopper) -> Quarantined and deleted successfully.
HKCR\fis.amo.1 (Adware.SmartShopper) -> Quarantined and deleted successfully.
HKCR\fis.momo (Adware.SmartShopper) -> Quarantined and deleted successfully.
HKCR\fis.momo.1 (Adware.SmartShopper) -> Quarantined and deleted successfully.
HKCR\fis.ohb (Adware.SmartShopper) -> Quarantined and deleted successfully.
HKCR\fis.ohb.1 (Adware.SmartShopper) -> Quarantined and deleted successfully.
HKCR\PAE_BHO.PEDEV_IEListener (Adware.PeDev) -> Quarantined and deleted successfully.
HKCR\PAE_BHO.PEDEV_IEListener.1 (Adware.PeDev) -> Quarantined and deleted successfully.
HKCR\PEDEV.PEDEVOptions (Adware.PeDev) -> Quarantined and deleted successfully.
HKCR\PEDEV.PEDEVOptions.1 (Adware.PeDev) -> Quarantined and deleted successfully.
HKCR\PEDEV.PEDEVPDM (Adware.PeDev) -> Quarantined and deleted successfully.
HKCR\PEDEV.PEDEVPDM.1 (Adware.PeDev) -> Quarantined and deleted successfully.
HKCR\PEDEV.PEDEVStatistic (Adware.PeDev) -> Quarantined and deleted successfully.
HKCR\PEDEV.PEDEVStatistic.1 (Adware.PeDev) -> Quarantined and deleted successfully.
HKCR\PEDEV.PEDEVUrlChecker (Adware.PeDev) -> Quarantined and deleted successfully.
HKCR\PEDEV.PEDEVUrlChecker.1 (Adware.PeDev) -> Quarantined and deleted successfully.
HKCR\PEDEV_BHO.PEDEV (Adware.PeDev) -> Quarantined and deleted successfully.
HKCR\PEDEV_BHO.PEDEV.1 (Adware.PeDev) -> Quarantined and deleted successfully.
HKCR\sp (TrojanProxy.Agent) -> Quarantined and deleted successfully.
HKCR\AppID\PEDEV.DLL (Adware.PeDev) -> Quarantined and deleted successfully.
HKCR\AppID\pedev.EXE (Adware.PeDev) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\884E079B2F78C10334A79B210E9EA2B7 (Adware.SearchTool) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\OTGV1DNWQQ (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\SmartShopper (Adware.SmartShopper) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\XBV6RD5SZF (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\AntiVirus 2010 (Rogue.AntiVirus2010) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\sp (TrojanProxy.Agent) -> Quarantined and deleted successfully.
HKLM\System\CurrentControlSet\Services\SPService (TrojanProxy.Agent) -> Quarantined and deleted successfully.
Registry Values Detected: 8
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar|{FAA356E4-D317-42A6-AB41-A3021C6E7D52} (Adware.ISTBar) -> Data: -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Internet Explorer\Extensions\CmdMapping\{10E42047-DEB9-4535-A118-B3F6EC39B807} (Adware.ISTBar) -> Data: -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Internet Explorer\Extensions\CmdMapping|{10E42047-DEB9-4535-A118-B3F6EC39B807} (Adware.ISTBar) -> Data: 8198 -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{FAA356E4-D317-42a6-AB41-A3021C6E7D52} (Adware.ISTBar) -> Data: -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{96AFBE69-C3B0-4b00-8578-D933D2896EE2} (TrojanProxy.Agent) -> Data: -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved|{96AFBE69-C3B0-4b00-8578-D933D2896EE2} (TrojanProxy.Agent) -> Data: sp -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost|netsvc (TrojanProxy.Agent) -> Data: SPService^w^ -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad|PSFactoryBuffer (Trojan.Agent) -> Data: {ffe8b3ec-23c7-4c2b-9adb-b70d4929f38c} -> Quarantined and deleted successfully.
Registry Data Items Detected: 1
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon|Userinit (Hijack.Userinit) -> Bad: (C:\WINDOWS\system32\userinit.exe,C:\Windows\System32\wsaupdater.exe,) Good: (Userinit.exe) -> Quarantined and repaired successfully.
Folders Detected: 5
C:\Documents and Settings\All Users\Application Data\WinAntiVirus Pro 2006 (Rogue.WinAntiVirus) -> Quarantined and deleted successfully.
C:\Documents and Settings\Matthew\Application Data\WinAntiVirus Pro 2006 (Rogue.WinAntiVirus) -> Quarantined and deleted successfully.
C:\Documents and Settings\Matthew\Application Data\WinAntiVirus Pro 2006\Logs (Rogue.WinAntiVirus) -> Quarantined and deleted successfully.
C:\Program Files\Common Files\WinAntiVirus Pro 2006 (Rogue.WinAntiVirus) -> Quarantined and deleted successfully.
C:\Program Files\WinAntiVirus Pro 2006 (Rogue.WinAntiVirus) -> Quarantined and deleted successfully.
Files Detected: 11
C:\WINDOWS\SYSTEM32\DRIVERS\cdrom.sys (Rootkit.0Access) -> Quarantined and deleted successfully.
C:\WINDOWS\Tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\Matthew\Application Data\WinAntiVirus Pro 2006\PGE.dat (Rogue.WinAntiVirus) -> Quarantined and deleted successfully.
C:\Documents and Settings\Matthew\Application Data\WinAntiVirus Pro 2006\Logs\update.log (Rogue.WinAntiVirus) -> Quarantined and deleted successfully.
C:\Documents and Settings\Matthew\Application Data\WinAntiVirus Pro 2006\Logs\wa6Support.log (Rogue.WinAntiVirus) -> Quarantined and deleted successfully.
C:\Documents and Settings\Matthew\Application Data\WinAntiVirus Pro 2006\Logs\winav.log (Rogue.WinAntiVirus) -> Quarantined and deleted successfully.
C:\Program Files\WinAntiVirus Pro 2006\msvcp71.dll (Rogue.WinAntiVirus) -> Quarantined and deleted successfully.
C:\Program Files\WinAntiVirus Pro 2006\msvcr71.dll (Rogue.WinAntiVirus) -> Quarantined and deleted successfully.
C:\WINDOWS\smdat32a.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\smdat32m.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
(end)
GMER 1.0.15.15641
Rootkit quick scan 2012-05-02 15:05:46
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 ST340014A rev.3.16
Running: cy0dl57e.exe; Driver: C:\DOCUME~1\Matthew\LOCALS~1\Temp\pwloipow.sys
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\Ntfs \Ntfs AVGIDSFilter.Sys (IDS Application Activity Monitor Filter Driver./AVG Technologies CZ, s.r.o. )
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat AVGIDSFilter.Sys (IDS Application Activity Monitor Filter Driver./AVG Technologies CZ, s.r.o. )
AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
---- EOF - GMER 1.0.15 ----
DDS txt and DDS attach in following thread.....