Just found this Tech Support site after the event, but hope you can help.
Just over 2 weeks ago, I was browsing the net, when all of sudden my PC is "locked-down" and I'm informed I have to pay 100 big ones to get it unlocked
I managed to get into safe mode using F8 and was able to remove a exe file in the roming/ temp folder, and revert to an earlyier store-point, re-booted, got back to Windows Vista ok and ran a full virus scan and installed malwarebytes (which said no infection found). Then 2 days ago, I was browsing the net and guess what!! same thing again, PC is "locked-down" and I'm informed I have to pay 100 big ones to get it unlocked. "Will I never learn!! or figure I should change my browsing habits!! This time F8 didn't work, and my Avira anti-virus had been disabled/killed so I had to use the Alienware backup DVD to revert to an earlyier store-point, then re-install Avira and ran malwarebyte to get back to normal Windows Vista.
It was only then that I found your great web site https://www.techspot.com/community/forums/virus-and-malware-removal.28/ and have tried to follow your UPDATED 5-step Viruses/Spyware/Malware Preliminary Removal Instructions. I've also installed Avira "web protection" to improve my browsing habits
So I need your expert help, is my PC clean now?
Step 1: Antivirus scanning
Avira Free Antivirus 2012 Realtime protection running, Web protection Active (Last update 20/07/2012).
--------------------------------------------
Step 2: Malwarebytes Anti-Malware
Downloaded, updated Performed Full scan.
log pasted:
---
Malwarebytes Anti-Malware 1.62.0.1300
www.malwarebytes.org
Database version: v2012.07.20.06
Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 8.0.6001.19272
zaphod :: ALX [administrator]
20/07/2012 17:11:01
mbam-log-2012-07-20 (17-11-01).txt
Scan type: Full scan (C:\|)
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 482206
Time elapsed: 3 hour(s), 57 minute(s), 41 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
(end)
--------------------------------------------
Step 3: GMER
Downloaded, disconnected ethernet cable from PC, closed all running progs, tempoarily disabled Avira Free 2012 Realtime protection and ran GMER.exe.
gmer.exe has stopped working,
Problem signature:
Problem Event Name: APPCRASH
Application Name: gmer.exe
Application Version: 1.0.15.15641
Application Timestamp: 4e21f2b1
Fault Module Name: gmer.exe
Fault Module Version: 1.0.15.15641
Fault Module Timestamp: 4e21f2b1
Exception Code: c0000005
Exception Offset: 0000c676
OS Version: 6.0.6002.2.2.0.256.1
Locale ID: 2057
Additional Information 1: 4254
Additional Information 2: fe2c75f8e1cb8e4ac132f386ef457bf0
Additional Information 3: ee4d
Additional Information 4: 3ecfdc723e6b34047eef7acd3cf23e4f
closed prog.
GMER refuses to run, tried again, UN-checked "Devices" in right pane.
Left running over night.
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2012-07-21 06:33:39
Windows 6.0.6002 Service Pack 2 Harddisk0\DR0 -> \Device\0000005e NVIDIA__ rev.
Running: gmer.exe; Driver: C:\Users\zaphod\AppData\Local\Temp\pxldrpow.sys
---- System - GMER 1.0.15 ----
SSDT 8C5FB766 ZwCreateSection
SSDT 8C5FB770 ZwRequestWaitReplyPort
SSDT 8C5FB76B ZwSetContextThread
SSDT 8C5FB775 ZwSetSecurityObject
SSDT 8C5FB77A ZwSystemDebugControl
SSDT 8C5FB707 ZwTerminateProcess
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!KeSetEvent + 215 81EB68D8 4 Bytes [66, B7, 5F, 8C]
.text ntkrnlpa.exe!KeSetEvent + 539 81EB6BFC 4 Bytes [70, B7, 5F, 8C]
.text ntkrnlpa.exe!KeSetEvent + 56D 81EB6C30 4 Bytes [6B, B7, 5F, 8C]
.text ntkrnlpa.exe!KeSetEvent + 5D1 81EB6C94 4 Bytes [75, B7, 5F, 8C]
.text ntkrnlpa.exe!KeSetEvent + 619 81EB6CDC 4 Bytes [7A, B7, 5F, 8C]
.text ...
? C:\Users\zaphod\AppData\Local\Temp\ALSysIO.sys The system cannot find the file specified. !
? C:\Users\zaphod\AppData\Local\Temp\aswMBR.sys The system cannot find the file specified. !
---- EOF - GMER 1.0.15 ----
-------------------------
Step 4: DDS
Ran dds.scr, logs pasted below.
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.6001.19272 BrowserJavaVersion: 10.4.1
Run by zaphod at 7:19:09 on 2012-07-21
Microsoft® Windows Vista™ Ultimate 6.0.6002.2.1252.44.1033.18.3070.1749 [GMT 1:00]
.
AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\taskeng.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\WUDFHost.exe
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
C:\Windows\system32\werfault.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Notepad++\notepad++.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uSearch Bar = Preserve
uStart Page = about:blank
uURLSearchHooks: UrlSearchHook Class: {00000000-6e41-4fd3-8538-502f5495e5fc} - c:\program files\ask.com\GenericAskToolbar.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\oracle\javafx 2.1 runtime\bin\ssv.dll
BHO: FDMIECookiesBHO Class: {cc59e0f9-7e43-44fa-9faa-8377850bf205} - c:\program files\free download manager\iefdm2.dll
BHO: Avira SearchFree Toolbar plus Web Protection: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\oracle\javafx 2.1 runtime\bin\jp2ssv.dll
TB: Avira SearchFree Toolbar plus Web Protection: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
uRun: [Radio Downloader] "c:\program files\radio downloader\Radio Downloader.exe" /hidemainwindow
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
mRun: [<NO NAME>]
StartupFolder: c:\users\zaphod\appdata\roaming\micros~1\windows\startm~1\programs\startup\gpsgate.lnk - c:\program files\franson\gpsgate 2.0\GpsGateXP.exe
StartupFolder: c:\users\zaphod\appdata\roaming\micros~1\windows\startm~1\programs\startup\mozill~1.lnk - c:\program files\mozilla thunderbird\thunderbird.exe
StartupFolder: c:\users\zaphod\appdata\roaming\micros~1\windows\startm~1\programs\startup\router~1.lnk - c:\routerstatslite\RouterStatsLite.exe
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
LSP: c:\program files\avira\antivir desktop\avsda.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_04-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
TCP: DhcpNameServer = 212.139.132.6 212.74.112.67
TCP: Interfaces\{26783D5D-28E4-4D4E-BB12-5AD4317EA9FF} : DhcpNameServer = 212.139.132.6 212.74.112.67
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\zaphod\appdata\roaming\mozilla\firefox\profiles\vt926wag.default\
FF - prefs.js: browser.search.selectedEngine - Ask.com
FF - prefs.js: browser.startup.homepage - hxxp://search.avira.com/?l=dis&o=APN10401&gct=hp&dc=EU&locale=en_GB
FF - prefs.js: keyword.URL - hxxp://websearch.ask.com/redirect?client=ff&src=kw&tb=AVR-3&o=APN10401&locale=en_GB&apn_uid=a300e5d3-68b2-4618-a3b0-fb5435561f7c&apn_ptnrs=^ABZ&apn_sauid=5A09183C-8FBE-4BA6-9BE8-1AE89B6F5AD2&apn_dtid=^YYYYYY^YY^GB&&q=
FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\update\1.3.21.115\npGoogleUpdate3.dll
FF - plugin: c:\program files\joystick plugin\npjoystick.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npjoystick.dll
FF - plugin: c:\program files\nvidia corporation\3d vision\npnv3dv.dll
FF - plugin: c:\program files\nvidia corporation\3d vision\npnv3dvstreaming.dll
FF - plugin: c:\program files\oracle\javafx 2.1 runtime\bin\dtplugin\npdeployJava1.dll
FF - plugin: c:\program files\oracle\javafx 2.1 runtime\bin\plugin2\npjp2.dll
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_3_300_262.dll
.
============= SERVICES / DRIVERS ===============
.
R1 avkmgr;avkmgr;c:\windows\system32\drivers\avkmgr.sys [2012-3-17 36000]
R1 bizVSerial;Franson VSerial;c:\windows\system32\drivers\bizVSerialNT.sys [2006-4-3 14949]
R1 VBoxDrv;VirtualBox Service;c:\windows\system32\drivers\VBoxDrv.sys [2012-4-27 158512]
R1 VBoxUSBMon;VirtualBox USB Monitor Driver;c:\windows\system32\drivers\VBoxUSBMon.sys [2012-4-27 91952]
R2 AntiVirSchedulerService;Avira Scheduler;c:\program files\avira\antivir desktop\sched.exe [2012-3-17 86224]
R2 AntiVirService;Avira Realtime Protection;c:\program files\avira\antivir desktop\avguard.exe [2012-3-17 110032]
R2 AntiVirWebService;Avira Web Protection;c:\program files\avira\antivir desktop\avwebgrd.exe [2012-3-17 465360]
R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2012-3-17 83392]
R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\nvidia corporation\nvidia update core\daemonu.exe [2012-5-19 2348352]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\nvidia corporation\3d vision\nvSCPAPISvr.exe [2012-2-29 382272]
R3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\drivers\VBoxNetAdp.sys [2012-4-12 104752]
R3 VBoxNetFlt;VirtualBox Bridged Networking Service;c:\windows\system32\drivers\VBoxNetFlt.sys [2012-4-12 116016]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2011-9-24 136176]
S3 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\common files\adobe\arm\1.0\armsvc.exe [2011-6-6 64952]
S3 FGYB;FGYB;c:\users\zaphod\appdata\local\temp\fgyb.exe --> c:\users\zaphod\appdata\local\temp\FGYB.exe [?]
S3 Franson GpsGate 2.0;Franson GpsGate 2.0;c:\program files\franson\gpsgate 2.0\GpsGateService.exe [2008-9-12 258048]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2011-9-24 136176]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\mozilla maintenance service\maintenanceservice.exe [2012-6-23 113120]
S3 TfBulk;TfBulk;c:\windows\system32\drivers\TfBulk.SYS [2007-5-31 13312]
S3 TrojanKillerDriver;GridinSoft Trojan Killer Driver;c:\windows\system32\drivers\gtkdrv.sys [2012-1-4 16128]
S3 VBoxUSB;VirtualBox USB;c:\windows\system32\drivers\VBoxUSB.sys [2012-4-12 82736]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
.
=============== Created Last 30 ================
.
2012-07-20 17:13:25 -------- d-----w- c:\program files\ESET
2012-07-20 00:32:32 14664 ----a-w- c:\windows\stinger.sys
2012-07-20 00:31:54 -------- d-----w- c:\program files\stinger
2012-07-19 22:58:43 -------- d-----w- c:\program files\Ask.com
2012-07-19 22:58:37 -------- d-----w- c:\users\zaphod\appdata\local\APN
2012-07-19 22:42:24 -------- d-----w- c:\program files\GridinSoft Trojan Killer
2012-07-11 18:21:17 2047488 ----a-w- c:\windows\system32\win32k.sys
2012-07-11 18:19:02 984064 ----a-w- c:\windows\system32\crypt32.dll
2012-07-11 18:19:02 98304 ----a-w- c:\windows\system32\cryptnet.dll
2012-07-11 18:19:02 133120 ----a-w- c:\windows\system32\cryptsvc.dll
2012-07-11 18:19:00 1401856 ----a-w- c:\windows\system32\msxml6.dll
2012-07-11 18:19:00 1248768 ----a-w- c:\windows\system32\msxml3.dll
2012-07-11 18:18:59 708608 ----a-w- c:\program files\common files\system\ado\msado15.dll
2012-07-11 18:18:58 440704 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2012-07-11 18:18:58 278528 ----a-w- c:\windows\system32\schannel.dll
2012-07-11 18:18:58 204288 ----a-w- c:\windows\system32\ncrypt.dll
2012-07-08 20:41:04 -------- d-----w- C:\maps
2012-07-07 07:05:40 22344 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-07-07 07:05:40 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-07-03 20:50:20 -------- d-----w- c:\users\zaphod\appdata\roaming\Malwarebytes
2012-07-03 20:50:19 -------- d-----w- c:\programdata\Malwarebytes
2012-06-25 08:36:33 -------- d-----w- c:\users\zaphod\appdata\local\Macromedia
2012-06-23 11:16:06 -------- d-----w- c:\program files\Mozilla Maintenance Service
2012-06-23 11:16:04 157608 ----a-w- c:\program files\mozilla firefox\maintenanceservice_installer.exe
2012-06-23 11:16:04 113120 ----a-w- c:\program files\mozilla firefox\maintenanceservice.exe
2012-06-23 11:16:03 770384 ----a-w- c:\program files\mozilla firefox\msvcr100.dll
2012-06-23 11:16:03 421200 ----a-w- c:\program files\mozilla firefox\msvcp100.dll
2012-06-21 15:57:52 2422272 ----a-w- c:\windows\system32\wucltux.dll
2012-06-21 15:57:39 88576 ----a-w- c:\windows\system32\wudriver.dll
2012-06-21 15:57:36 33792 ----a-w- c:\windows\system32\wuapp.exe
2012-06-21 15:57:36 171904 ----a-w- c:\windows\system32\wuwebv.dll
.
==================== Find3M ====================
.
2012-06-25 06:37:46 70344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-06-25 06:37:46 426184 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-05-19 15:42:29 772552 ----a-w- c:\windows\system32\npDeployJava1.dll
2012-05-18 21:35:06 73216 ----a-w- c:\windows\ST6UNST.EXE
2012-05-18 21:35:06 249856 ------w- c:\windows\Setup1.exe
2012-05-15 06:37:49 916992 ----a-w- c:\windows\system32\wininet.dll
2012-05-15 06:32:25 43520 ----a-w- c:\windows\system32\licmgr10.dll
2012-05-15 06:32:00 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2012-05-15 06:31:44 109056 ----a-w- c:\windows\system32\iesysprep.dll
2012-05-15 06:31:43 71680 ----a-w- c:\windows\system32\iesetup.dll
2012-05-15 05:01:56 385024 ----a-w- c:\windows\system32\html.iec
2012-05-15 03:26:05 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2012-05-15 03:23:41 1638912 ----a-w- c:\windows\system32\mshtml.tlb
2012-05-08 16:37:03 83392 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2012-05-01 14:03:49 180736 ----a-w- c:\windows\system32\drivers\rdpwd.sys
.
============= FINISH: 7:19:31.35 ===============
---------------
Attach.txt pasted:
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft® Windows Vista™ Ultimate
Boot Device: \Device\HarddiskVolume1
Install Date: 03/03/2011 22:47:44
System Uptime: 20/07/2012 17:07:35 (14 hours ago)
.
Motherboard: ELITEGROUP COMPUTER SYSTEM CO.,LTD. | | NFORCE6M-A
Processor: AMD Athlon(tm) 64 X2 Dual Core Processor 6000+ | Socket AM2 | 3000/201mhz
.
==== Disk Partitions =========================
.
A: is Removable
C: is FIXED (NTFS) - 924 GiB total, 488.452 GiB free.
D: is CDROM ()
E: is Removable
F: is Removable
G: is Removable
H: is Removable
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
.
==== Installed Programs ======================
.
Adobe Flash Player 11 Plugin
Adobe Reader X (10.1.0)
Amazon Kindle
Ask Toolbar
Aspell English Dictionary-0.50-2
Audacity 1.3.13 (Unicode)
Avira Free Antivirus
Avira SearchFree Toolbar plus Web Protection Updater
CCleaner
Core Temp version 0.99.8
Data Parse
EasyNavs version 3.02
ESET Online Scanner v3
Franson GpsGate 2.6
Free Download Manager 3.0
Garmin GTN Trainer Lite
Global Mapper 13
GNS400W-500W Trainer
GNU Aspell 0.50-3
Google Chrome
Google Earth
Google Earth Plug-in
Google Update Helper
HNavDBEditor version 3.02
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
ImgBurn
Java Auto Updater
Java(TM) 6 Update 31
Java(TM) 7 Update 4
JavaFX 2.1.0
Joystick Plug-in
JRollon Planes CRJ-200 version 1.4.0
K-Lite Mega Codec Pack 7.7.8
Kml Builder
Log Parser 2.2
Log Parser Lizard
Malwarebytes Anti-Malware version 1.62.0.1300
Media Player Classic - Home Cinema v1.5.2.3456
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 4 Client Profile
Microsoft .NET Framework 4 Extended
Microsoft Application Error Reporting
Microsoft Flight Simulator SimConnect Client v10.0.61259.0
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
Movica
Mozilla Firefox 13.0.1 (x86 en-GB)
Mozilla Maintenance Service
Mozilla Thunderbird 13.0.1 (x86 en-GB)
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
My MP4Box GUI 0.5.5.4
Navigraph nDAC 3
Notepad++
NVIDIA 3D Vision Controller Driver 296.10
NVIDIA 3D Vision Driver 296.10
NVIDIA Control Panel 296.10
NVIDIA Graphics Driver 296.10
NVIDIA Install Application
NVIDIA PhysX
NVIDIA PhysX System Software 9.12.0213
NVIDIA Stereoscopic 3D Driver
NVIDIA Update 1.7.11
NVIDIA Update Components
OpenMG Limited Patch 4.7-07-14-05-01
OpenMG Secure Module 4.7.00
Oracle VM VirtualBox 4.1.14
Plan-G
PROCIO
Python 2.7.2
Radio Downloader
RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2604111)
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2657424)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)
Security Update for Microsoft .NET Framework 4 Extended (KB2487367)
Security Update for Microsoft .NET Framework 4 Extended (KB2656351)
SimConnect Config Tool
SkyView2
SonicStage 4.3
Topfield Tools
Trojan Killer
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
VLC media player 2.0.2
Windows Grep 2.3
WinHTTrack Website Copier 3.44-1
WinRAR 4.01 (32-bit)
XPS Annotator 1.22
.
==== Event Viewer Messages From Past Week ========
.
20/07/2012 17:07:54, Error: Microsoft-Windows-Dhcp-Client [1002] - The IP address lease 192.168.0.2 for the Network Card with network address 0019212F521E has been denied by the DHCP server 192.168.0.1 (The DHCP Server sent a DHCPNACK message).
20/07/2012 01:57:42, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: avipbb avkmgr bizVSerial spldr ssmdrv VBoxDrv VBoxUSBMon Wanarpv6
20/07/2012 01:57:42, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
20/07/2012 01:56:39, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
20/07/2012 01:56:31, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "" in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC}
19/07/2012 23:30:40, Error: Service Control Manager [7024] - The Avira Realtime Protection service terminated with service-specific error 306 (0x132).
17/07/2012 18:30:50, Error: Server [2505] - The server could not bind to the transport \Device\NetBT_Tcpip_{26783D5D-28E4-4D4E-BB12-5AD4317EA9FF} because another computer on the network has the same name. The server could not start.
14/07/2012 08:52:36, Error: Service Control Manager [7022] - The Windows Update service hung on starting.
.
==== End Of File ===========================
Re-enabled Anti-virus and re-connected to internet.
-----------------
Step 5: Log Handling.
Posting logs as requested.
Thanks for any help, I'm just disappointed I didn't find your site first, two weeks ago.
cessna729.
Just over 2 weeks ago, I was browsing the net, when all of sudden my PC is "locked-down" and I'm informed I have to pay 100 big ones to get it unlocked
It was only then that I found your great web site https://www.techspot.com/community/forums/virus-and-malware-removal.28/ and have tried to follow your UPDATED 5-step Viruses/Spyware/Malware Preliminary Removal Instructions. I've also installed Avira "web protection" to improve my browsing habits
So I need your expert help, is my PC clean now?
Step 1: Antivirus scanning
Avira Free Antivirus 2012 Realtime protection running, Web protection Active (Last update 20/07/2012).
--------------------------------------------
Step 2: Malwarebytes Anti-Malware
Downloaded, updated Performed Full scan.
log pasted:
---
Malwarebytes Anti-Malware 1.62.0.1300
www.malwarebytes.org
Database version: v2012.07.20.06
Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 8.0.6001.19272
zaphod :: ALX [administrator]
20/07/2012 17:11:01
mbam-log-2012-07-20 (17-11-01).txt
Scan type: Full scan (C:\|)
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 482206
Time elapsed: 3 hour(s), 57 minute(s), 41 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
(end)
--------------------------------------------
Step 3: GMER
Downloaded, disconnected ethernet cable from PC, closed all running progs, tempoarily disabled Avira Free 2012 Realtime protection and ran GMER.exe.
gmer.exe has stopped working,
Problem signature:
Problem Event Name: APPCRASH
Application Name: gmer.exe
Application Version: 1.0.15.15641
Application Timestamp: 4e21f2b1
Fault Module Name: gmer.exe
Fault Module Version: 1.0.15.15641
Fault Module Timestamp: 4e21f2b1
Exception Code: c0000005
Exception Offset: 0000c676
OS Version: 6.0.6002.2.2.0.256.1
Locale ID: 2057
Additional Information 1: 4254
Additional Information 2: fe2c75f8e1cb8e4ac132f386ef457bf0
Additional Information 3: ee4d
Additional Information 4: 3ecfdc723e6b34047eef7acd3cf23e4f
closed prog.
GMER refuses to run, tried again, UN-checked "Devices" in right pane.
Left running over night.
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2012-07-21 06:33:39
Windows 6.0.6002 Service Pack 2 Harddisk0\DR0 -> \Device\0000005e NVIDIA__ rev.
Running: gmer.exe; Driver: C:\Users\zaphod\AppData\Local\Temp\pxldrpow.sys
---- System - GMER 1.0.15 ----
SSDT 8C5FB766 ZwCreateSection
SSDT 8C5FB770 ZwRequestWaitReplyPort
SSDT 8C5FB76B ZwSetContextThread
SSDT 8C5FB775 ZwSetSecurityObject
SSDT 8C5FB77A ZwSystemDebugControl
SSDT 8C5FB707 ZwTerminateProcess
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!KeSetEvent + 215 81EB68D8 4 Bytes [66, B7, 5F, 8C]
.text ntkrnlpa.exe!KeSetEvent + 539 81EB6BFC 4 Bytes [70, B7, 5F, 8C]
.text ntkrnlpa.exe!KeSetEvent + 56D 81EB6C30 4 Bytes [6B, B7, 5F, 8C]
.text ntkrnlpa.exe!KeSetEvent + 5D1 81EB6C94 4 Bytes [75, B7, 5F, 8C]
.text ntkrnlpa.exe!KeSetEvent + 619 81EB6CDC 4 Bytes [7A, B7, 5F, 8C]
.text ...
? C:\Users\zaphod\AppData\Local\Temp\ALSysIO.sys The system cannot find the file specified. !
? C:\Users\zaphod\AppData\Local\Temp\aswMBR.sys The system cannot find the file specified. !
---- EOF - GMER 1.0.15 ----
-------------------------
Step 4: DDS
Ran dds.scr, logs pasted below.
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.6001.19272 BrowserJavaVersion: 10.4.1
Run by zaphod at 7:19:09 on 2012-07-21
Microsoft® Windows Vista™ Ultimate 6.0.6002.2.1252.44.1033.18.3070.1749 [GMT 1:00]
.
AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\taskeng.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\WUDFHost.exe
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
C:\Windows\system32\werfault.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Notepad++\notepad++.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uSearch Bar = Preserve
uStart Page = about:blank
uURLSearchHooks: UrlSearchHook Class: {00000000-6e41-4fd3-8538-502f5495e5fc} - c:\program files\ask.com\GenericAskToolbar.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\oracle\javafx 2.1 runtime\bin\ssv.dll
BHO: FDMIECookiesBHO Class: {cc59e0f9-7e43-44fa-9faa-8377850bf205} - c:\program files\free download manager\iefdm2.dll
BHO: Avira SearchFree Toolbar plus Web Protection: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\oracle\javafx 2.1 runtime\bin\jp2ssv.dll
TB: Avira SearchFree Toolbar plus Web Protection: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
uRun: [Radio Downloader] "c:\program files\radio downloader\Radio Downloader.exe" /hidemainwindow
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
mRun: [<NO NAME>]
StartupFolder: c:\users\zaphod\appdata\roaming\micros~1\windows\startm~1\programs\startup\gpsgate.lnk - c:\program files\franson\gpsgate 2.0\GpsGateXP.exe
StartupFolder: c:\users\zaphod\appdata\roaming\micros~1\windows\startm~1\programs\startup\mozill~1.lnk - c:\program files\mozilla thunderbird\thunderbird.exe
StartupFolder: c:\users\zaphod\appdata\roaming\micros~1\windows\startm~1\programs\startup\router~1.lnk - c:\routerstatslite\RouterStatsLite.exe
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
LSP: c:\program files\avira\antivir desktop\avsda.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_04-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
TCP: DhcpNameServer = 212.139.132.6 212.74.112.67
TCP: Interfaces\{26783D5D-28E4-4D4E-BB12-5AD4317EA9FF} : DhcpNameServer = 212.139.132.6 212.74.112.67
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\zaphod\appdata\roaming\mozilla\firefox\profiles\vt926wag.default\
FF - prefs.js: browser.search.selectedEngine - Ask.com
FF - prefs.js: browser.startup.homepage - hxxp://search.avira.com/?l=dis&o=APN10401&gct=hp&dc=EU&locale=en_GB
FF - prefs.js: keyword.URL - hxxp://websearch.ask.com/redirect?client=ff&src=kw&tb=AVR-3&o=APN10401&locale=en_GB&apn_uid=a300e5d3-68b2-4618-a3b0-fb5435561f7c&apn_ptnrs=^ABZ&apn_sauid=5A09183C-8FBE-4BA6-9BE8-1AE89B6F5AD2&apn_dtid=^YYYYYY^YY^GB&&q=
FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\update\1.3.21.115\npGoogleUpdate3.dll
FF - plugin: c:\program files\joystick plugin\npjoystick.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npjoystick.dll
FF - plugin: c:\program files\nvidia corporation\3d vision\npnv3dv.dll
FF - plugin: c:\program files\nvidia corporation\3d vision\npnv3dvstreaming.dll
FF - plugin: c:\program files\oracle\javafx 2.1 runtime\bin\dtplugin\npdeployJava1.dll
FF - plugin: c:\program files\oracle\javafx 2.1 runtime\bin\plugin2\npjp2.dll
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_3_300_262.dll
.
============= SERVICES / DRIVERS ===============
.
R1 avkmgr;avkmgr;c:\windows\system32\drivers\avkmgr.sys [2012-3-17 36000]
R1 bizVSerial;Franson VSerial;c:\windows\system32\drivers\bizVSerialNT.sys [2006-4-3 14949]
R1 VBoxDrv;VirtualBox Service;c:\windows\system32\drivers\VBoxDrv.sys [2012-4-27 158512]
R1 VBoxUSBMon;VirtualBox USB Monitor Driver;c:\windows\system32\drivers\VBoxUSBMon.sys [2012-4-27 91952]
R2 AntiVirSchedulerService;Avira Scheduler;c:\program files\avira\antivir desktop\sched.exe [2012-3-17 86224]
R2 AntiVirService;Avira Realtime Protection;c:\program files\avira\antivir desktop\avguard.exe [2012-3-17 110032]
R2 AntiVirWebService;Avira Web Protection;c:\program files\avira\antivir desktop\avwebgrd.exe [2012-3-17 465360]
R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2012-3-17 83392]
R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\nvidia corporation\nvidia update core\daemonu.exe [2012-5-19 2348352]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\nvidia corporation\3d vision\nvSCPAPISvr.exe [2012-2-29 382272]
R3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\drivers\VBoxNetAdp.sys [2012-4-12 104752]
R3 VBoxNetFlt;VirtualBox Bridged Networking Service;c:\windows\system32\drivers\VBoxNetFlt.sys [2012-4-12 116016]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2011-9-24 136176]
S3 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\common files\adobe\arm\1.0\armsvc.exe [2011-6-6 64952]
S3 FGYB;FGYB;c:\users\zaphod\appdata\local\temp\fgyb.exe --> c:\users\zaphod\appdata\local\temp\FGYB.exe [?]
S3 Franson GpsGate 2.0;Franson GpsGate 2.0;c:\program files\franson\gpsgate 2.0\GpsGateService.exe [2008-9-12 258048]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2011-9-24 136176]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\mozilla maintenance service\maintenanceservice.exe [2012-6-23 113120]
S3 TfBulk;TfBulk;c:\windows\system32\drivers\TfBulk.SYS [2007-5-31 13312]
S3 TrojanKillerDriver;GridinSoft Trojan Killer Driver;c:\windows\system32\drivers\gtkdrv.sys [2012-1-4 16128]
S3 VBoxUSB;VirtualBox USB;c:\windows\system32\drivers\VBoxUSB.sys [2012-4-12 82736]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
.
=============== Created Last 30 ================
.
2012-07-20 17:13:25 -------- d-----w- c:\program files\ESET
2012-07-20 00:32:32 14664 ----a-w- c:\windows\stinger.sys
2012-07-20 00:31:54 -------- d-----w- c:\program files\stinger
2012-07-19 22:58:43 -------- d-----w- c:\program files\Ask.com
2012-07-19 22:58:37 -------- d-----w- c:\users\zaphod\appdata\local\APN
2012-07-19 22:42:24 -------- d-----w- c:\program files\GridinSoft Trojan Killer
2012-07-11 18:21:17 2047488 ----a-w- c:\windows\system32\win32k.sys
2012-07-11 18:19:02 984064 ----a-w- c:\windows\system32\crypt32.dll
2012-07-11 18:19:02 98304 ----a-w- c:\windows\system32\cryptnet.dll
2012-07-11 18:19:02 133120 ----a-w- c:\windows\system32\cryptsvc.dll
2012-07-11 18:19:00 1401856 ----a-w- c:\windows\system32\msxml6.dll
2012-07-11 18:19:00 1248768 ----a-w- c:\windows\system32\msxml3.dll
2012-07-11 18:18:59 708608 ----a-w- c:\program files\common files\system\ado\msado15.dll
2012-07-11 18:18:58 440704 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2012-07-11 18:18:58 278528 ----a-w- c:\windows\system32\schannel.dll
2012-07-11 18:18:58 204288 ----a-w- c:\windows\system32\ncrypt.dll
2012-07-08 20:41:04 -------- d-----w- C:\maps
2012-07-07 07:05:40 22344 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-07-07 07:05:40 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-07-03 20:50:20 -------- d-----w- c:\users\zaphod\appdata\roaming\Malwarebytes
2012-07-03 20:50:19 -------- d-----w- c:\programdata\Malwarebytes
2012-06-25 08:36:33 -------- d-----w- c:\users\zaphod\appdata\local\Macromedia
2012-06-23 11:16:06 -------- d-----w- c:\program files\Mozilla Maintenance Service
2012-06-23 11:16:04 157608 ----a-w- c:\program files\mozilla firefox\maintenanceservice_installer.exe
2012-06-23 11:16:04 113120 ----a-w- c:\program files\mozilla firefox\maintenanceservice.exe
2012-06-23 11:16:03 770384 ----a-w- c:\program files\mozilla firefox\msvcr100.dll
2012-06-23 11:16:03 421200 ----a-w- c:\program files\mozilla firefox\msvcp100.dll
2012-06-21 15:57:52 2422272 ----a-w- c:\windows\system32\wucltux.dll
2012-06-21 15:57:39 88576 ----a-w- c:\windows\system32\wudriver.dll
2012-06-21 15:57:36 33792 ----a-w- c:\windows\system32\wuapp.exe
2012-06-21 15:57:36 171904 ----a-w- c:\windows\system32\wuwebv.dll
.
==================== Find3M ====================
.
2012-06-25 06:37:46 70344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-06-25 06:37:46 426184 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-05-19 15:42:29 772552 ----a-w- c:\windows\system32\npDeployJava1.dll
2012-05-18 21:35:06 73216 ----a-w- c:\windows\ST6UNST.EXE
2012-05-18 21:35:06 249856 ------w- c:\windows\Setup1.exe
2012-05-15 06:37:49 916992 ----a-w- c:\windows\system32\wininet.dll
2012-05-15 06:32:25 43520 ----a-w- c:\windows\system32\licmgr10.dll
2012-05-15 06:32:00 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2012-05-15 06:31:44 109056 ----a-w- c:\windows\system32\iesysprep.dll
2012-05-15 06:31:43 71680 ----a-w- c:\windows\system32\iesetup.dll
2012-05-15 05:01:56 385024 ----a-w- c:\windows\system32\html.iec
2012-05-15 03:26:05 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2012-05-15 03:23:41 1638912 ----a-w- c:\windows\system32\mshtml.tlb
2012-05-08 16:37:03 83392 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2012-05-01 14:03:49 180736 ----a-w- c:\windows\system32\drivers\rdpwd.sys
.
============= FINISH: 7:19:31.35 ===============
---------------
Attach.txt pasted:
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft® Windows Vista™ Ultimate
Boot Device: \Device\HarddiskVolume1
Install Date: 03/03/2011 22:47:44
System Uptime: 20/07/2012 17:07:35 (14 hours ago)
.
Motherboard: ELITEGROUP COMPUTER SYSTEM CO.,LTD. | | NFORCE6M-A
Processor: AMD Athlon(tm) 64 X2 Dual Core Processor 6000+ | Socket AM2 | 3000/201mhz
.
==== Disk Partitions =========================
.
A: is Removable
C: is FIXED (NTFS) - 924 GiB total, 488.452 GiB free.
D: is CDROM ()
E: is Removable
F: is Removable
G: is Removable
H: is Removable
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
.
==== Installed Programs ======================
.
Adobe Flash Player 11 Plugin
Adobe Reader X (10.1.0)
Amazon Kindle
Ask Toolbar
Aspell English Dictionary-0.50-2
Audacity 1.3.13 (Unicode)
Avira Free Antivirus
Avira SearchFree Toolbar plus Web Protection Updater
CCleaner
Core Temp version 0.99.8
Data Parse
EasyNavs version 3.02
ESET Online Scanner v3
Franson GpsGate 2.6
Free Download Manager 3.0
Garmin GTN Trainer Lite
Global Mapper 13
GNS400W-500W Trainer
GNU Aspell 0.50-3
Google Chrome
Google Earth
Google Earth Plug-in
Google Update Helper
HNavDBEditor version 3.02
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
ImgBurn
Java Auto Updater
Java(TM) 6 Update 31
Java(TM) 7 Update 4
JavaFX 2.1.0
Joystick Plug-in
JRollon Planes CRJ-200 version 1.4.0
K-Lite Mega Codec Pack 7.7.8
Kml Builder
Log Parser 2.2
Log Parser Lizard
Malwarebytes Anti-Malware version 1.62.0.1300
Media Player Classic - Home Cinema v1.5.2.3456
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 4 Client Profile
Microsoft .NET Framework 4 Extended
Microsoft Application Error Reporting
Microsoft Flight Simulator SimConnect Client v10.0.61259.0
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
Movica
Mozilla Firefox 13.0.1 (x86 en-GB)
Mozilla Maintenance Service
Mozilla Thunderbird 13.0.1 (x86 en-GB)
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
My MP4Box GUI 0.5.5.4
Navigraph nDAC 3
Notepad++
NVIDIA 3D Vision Controller Driver 296.10
NVIDIA 3D Vision Driver 296.10
NVIDIA Control Panel 296.10
NVIDIA Graphics Driver 296.10
NVIDIA Install Application
NVIDIA PhysX
NVIDIA PhysX System Software 9.12.0213
NVIDIA Stereoscopic 3D Driver
NVIDIA Update 1.7.11
NVIDIA Update Components
OpenMG Limited Patch 4.7-07-14-05-01
OpenMG Secure Module 4.7.00
Oracle VM VirtualBox 4.1.14
Plan-G
PROCIO
Python 2.7.2
Radio Downloader
RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2604111)
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2657424)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)
Security Update for Microsoft .NET Framework 4 Extended (KB2487367)
Security Update for Microsoft .NET Framework 4 Extended (KB2656351)
SimConnect Config Tool
SkyView2
SonicStage 4.3
Topfield Tools
Trojan Killer
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
VLC media player 2.0.2
Windows Grep 2.3
WinHTTrack Website Copier 3.44-1
WinRAR 4.01 (32-bit)
XPS Annotator 1.22
.
==== Event Viewer Messages From Past Week ========
.
20/07/2012 17:07:54, Error: Microsoft-Windows-Dhcp-Client [1002] - The IP address lease 192.168.0.2 for the Network Card with network address 0019212F521E has been denied by the DHCP server 192.168.0.1 (The DHCP Server sent a DHCPNACK message).
20/07/2012 01:57:42, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: avipbb avkmgr bizVSerial spldr ssmdrv VBoxDrv VBoxUSBMon Wanarpv6
20/07/2012 01:57:42, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
20/07/2012 01:56:39, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
20/07/2012 01:56:31, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "" in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC}
19/07/2012 23:30:40, Error: Service Control Manager [7024] - The Avira Realtime Protection service terminated with service-specific error 306 (0x132).
17/07/2012 18:30:50, Error: Server [2505] - The server could not bind to the transport \Device\NetBT_Tcpip_{26783D5D-28E4-4D4E-BB12-5AD4317EA9FF} because another computer on the network has the same name. The server could not start.
14/07/2012 08:52:36, Error: Service Control Manager [7022] - The Windows Update service hung on starting.
.
==== End Of File ===========================
Re-enabled Anti-virus and re-connected to internet.
-----------------
Step 5: Log Handling.
Posting logs as requested.
Thanks for any help, I'm just disappointed I didn't find your site first, two weeks ago.
cessna729.