Hi, AVG tells me I'm infected with Trojan Horse Crypt.AQLW and does not seem able to remove the infection. Following the 5 steps here are the results. Thank you for any help.
Malwarebytes Anti-Malware (Trial) 1.60.1.1000
www.malwarebytes.org
Database version: v2012.02.29.02
Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 9.0.8112.16421
Ed :: ED-PC [administrator]
Protection: Enabled
29/02/2012 11:04:28
mbam-log-2012-02-29 (11-04-28).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 284139
Time elapsed: 53 minute(s), 46 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 1
C:\Recycle.Bin (Trojan.Spyeyes) -> Quarantined and deleted successfully.
Files Detected: 2
C:\Recycle.Bin\B6232F3AA59.exe (Trojan.Spyeyes) -> Quarantined and deleted successfully.
C:\Recycle.Bin\481D2A6DA7EAFE9 (Trojan.Spyeyes) -> Quarantined and deleted successfully.
(end)
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2012-02-29 16:33:48
Windows 6.1.7601 Service Pack 1 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 Maxtor_6Y120L0 rev.YAR41BW0
Running: p5vthjdp.exe; Driver: C:\Users\Ed\AppData\Local\Temp\pxldapoc.sys
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwSaveKey + 13D1 82C7C369 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 82CB5D52 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
? System32\drivers\jewk.sys The system cannot find the path specified. !
.text C:\Windows\System32\Drivers\dfsc.sys section is writeable [0x8E2C7000, 0x3C9C, 0xE8000020]
.text C:\Windows\system32\DRIVERS\atikmdag.sys section is writeable [0x8EE13000, 0x38CD55, 0xE8000020]
PAGE spsys.sys!?SPRevision@@3PADA + 4F90 A08D5000 290 Bytes [8B, FF, 55, 8B, EC, 33, C0, ...]
PAGE spsys.sys!?SPRevision@@3PADA + 50B3 A08D5123 629 Bytes [05, 8D, A0, FE, 05, 34, 05, ...]
PAGE spsys.sys!?SPRevision@@3PADA + 5329 A08D5399 101 Bytes [6A, 28, 59, A5, 5E, C6, 03, ...]
PAGE spsys.sys!?SPRevision@@3PADA + 538F A08D53FF 148 Bytes [18, 5D, C2, 14, 00, 8B, FF, ...]
PAGE spsys.sys!?SPRevision@@3PADA + 543B A08D54AB 2228 Bytes [8B, FF, 55, 8B, EC, FF, 75, ...]
PAGE ...
---- User code sections - GMER 1.0.15 ----
.text C:\Windows\system32\svchost.exe[1556] ntdll.dll!NtProtectVirtualMemory 77485F18 5 Bytes JMP 0052000A
.text C:\Windows\system32\svchost.exe[1556] ntdll.dll!NtWriteVirtualMemory 77486A98 5 Bytes JMP 0059000A
.text C:\Windows\system32\svchost.exe[1556] ntdll.dll!KiUserExceptionDispatcher 77486FE8 5 Bytes JMP 001B000A
.text C:\Windows\System32\ping.exe[4392] ntdll.dll!NtCreateProcess 77485698 5 Bytes JMP 0055000A
.text C:\Windows\System32\ping.exe[4392] ntdll.dll!NtCreateProcessEx 774856A8 5 Bytes JMP 0056000A
.text C:\Windows\System32\ping.exe[4392] ntdll.dll!NtCreateUserProcess 77485778 5 Bytes JMP 0057000A
.text C:\Windows\System32\ping.exe[4392] ntdll.dll!NtProtectVirtualMemory 77485F18 5 Bytes JMP 003E000A
.text C:\Windows\System32\ping.exe[4392] ntdll.dll!NtWriteVirtualMemory 77486A98 5 Bytes JMP 003F000A
.text C:\Windows\System32\ping.exe[4392] ntdll.dll!KiUserExceptionDispatcher 77486FE8 5 Bytes JMP 003D000A
.text C:\Windows\System32\ping.exe[4392] USER32.dll!GetCursorPos 7516A4B3 5 Bytes JMP 008F000A
.text C:\Windows\System32\ping.exe[4392] USER32.dll!GetForegroundWindow 7517335D 5 Bytes JMP 0091000A
.text C:\Windows\System32\ping.exe[4392] USER32.dll!WindowFromPoint 75196BE9 5 Bytes JMP 0090000A
.text C:\Windows\System32\ping.exe[4392] ole32.dll!CoCreateInstance 75BB9D0B 5 Bytes JMP 005D000A
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\Windows\TEMP\mtbuaj\setup.exe[2176] @ C:\Windows\system32\ADVAPI32.DLL [KERNEL32.dll!GetProcAddress] [74D0FFF6] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Windows\TEMP\mtbuaj\setup.exe[2176] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [74D0FFF6] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Windows\TEMP\mtbuaj\setup.exe[2176] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [74D0FFF6] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Windows\TEMP\mtbuaj\setup.exe[2176] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [74D0FFF6] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Windows\TEMP\mtbuaj\setup.exe[2176] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!GetProcAddress] [74D0FFF6] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[2552] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [74D0FFF6] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[2552] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [74D0FFF6] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[2552] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [74D0FFF6] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[2552] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!GetProcAddress] [74D0FFF6] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[2552] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [74D0FFF6] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
---- Devices - GMER 1.0.15 ----
Device \Driver\ACPI_HAL \Device\00000056 halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 tdrpman.sys (Acronis Try&Decide and Restore Points Volume Filter Driver/Acronis)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 snapman.sys (Acronis Snapshot API/Acronis)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 tdrpman.sys (Acronis Try&Decide and Restore Points Volume Filter Driver/Acronis)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 snapman.sys (Acronis Snapshot API/Acronis)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 tdrpman.sys (Acronis Try&Decide and Restore Points Volume Filter Driver/Acronis)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 snapman.sys (Acronis Snapshot API/Acronis)
---- Modules - GMER 1.0.15 ----
Module (noname) (*** hidden *** ) 8E2A3000-8E2C6000 (143360 bytes)
---- Processes - GMER 1.0.15 ----
Process C:\Windows\System32\ping.exe (*** hidden *** ) 4392
---- Files - GMER 1.0.15 ----
File C:\Windows\$NtUninstallKB9130$\1825098505 0 bytes
File C:\Windows\$NtUninstallKB9130$\2727051553 0 bytes
File C:\Windows\$NtUninstallKB9130$\2727051553\@ 2048 bytes
File C:\Windows\$NtUninstallKB9130$\2727051553\cfg.ini 296 bytes
File C:\Windows\$NtUninstallKB9130$\2727051553\Desktop.ini 4608 bytes
File C:\Windows\$NtUninstallKB9130$\2727051553\L 0 bytes
File C:\Windows\$NtUninstallKB9130$\2727051553\L\xadqgnnk 78336 bytes
File C:\Windows\$NtUninstallKB9130$\2727051553\oemid 130 bytes
File C:\Windows\$NtUninstallKB9130$\2727051553\U 0 bytes
File C:\Windows\$NtUninstallKB9130$\2727051553\U\00000001.@ 2048 bytes
File C:\Windows\$NtUninstallKB9130$\2727051553\U\00000002.@ 224768 bytes
File C:\Windows\$NtUninstallKB9130$\2727051553\U\00000004.@ 1024 bytes
File C:\Windows\$NtUninstallKB9130$\2727051553\U\80000000.@ 66560 bytes
File C:\Windows\$NtUninstallKB9130$\2727051553\U\80000004.@ 12800 bytes
File C:\Windows\$NtUninstallKB9130$\2727051553\U\80000032.@ 73216 bytes
File C:\Windows\$NtUninstallKB9130$\2727051553\version 842 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\3U9BMHDI\background_gradient[2] 453 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\3U9BMHDI\bullet[2] 447 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8MN4SDEE\bullet[1] 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\E6M0OIET\httpErrorPagesScripts[1] 0 bytes
File C:\Windows\Temp\~DF6B742880D68DE119.TMP 0 bytes
File C:\Windows\Temp\~DFB66948AF3F29F320.TMP 0 bytes
---- EOF - GMER 1.0.15 ----
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_29
Run by Ed at 16:36:58 on 2012-02-29
.
============== Running Processes ===============
.
C:\PROGRA~1\AVG\AVG2012\avgrsx.exe
C:\Program Files\AVG\AVG2012\avgcsrvx.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\atiesrxx.exe
C:\Windows\system32\atieclxx.exe
C:\Windows\System32\spoolsv.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Windows\TEMP\mtbuaj\setup.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\AVG\AVG2012\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\REALTEK\11n USB Wireless LAN Utility\RtlService.exe
C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Windows\system32\sppsvc.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\REALTEK\11n USB Wireless LAN Utility\RtWlan.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe
C:\Program Files\AVG\AVG2012\avgtray.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Nokia\Nokia Suite\NokiaSuite.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclMSBTSrvEx.exe
C:\totalcmd\TOTALCMD.EXE
C:\Windows\system32\conhost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\WLANExt.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\W2ww4sH.com
C:\Windows\system32\W2WW4S~1.COM
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\W2ww4sH.com
C:\Program Files\AVG\AVG2012\avgui.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Users\Ed\Downloads\dds.scr
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\System32\svchost.exe -k WerSvcGroup
.
============== Pseudo HJT Report ===============
.
uInternet Settings,ProxyOverride = *.local
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~4\office14\GROOVEEX.DLL
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - c:\progra~1\micros~4\office14\URLREDIR.DLL
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
uRun: [<NO NAME>]
uRun: [NokiaSuite.exe] c:\program files\nokia\nokia suite\NokiaSuite.exe -tray
mRun: [IntelliPoint] "c:\program files\microsoft intellipoint\ipoint.exe"
mRun: [itype] "c:\program files\microsoft intellitype pro\itype.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [VirtualCloneDrive] "c:\program files\elaborate bytes\virtualclonedrive\VCDDaemon.exe" /s
mRun: [BCSSync] "c:\program files\microsoft office\office14\BCSSync.exe" /DelayServices
mRun: [TrueImageMonitor.exe] c:\program files\acronis\trueimagehome\TrueImageMonitor.exe
mRun: [AcronisTimounterMonitor] c:\program files\acronis\trueimagehome\TimounterMonitor.exe
mRun: [Acronis Scheduler2 Service] "c:\program files\common files\acronis\schedule2\schedhlp.exe"
mRun: [RIMBBLaunchAgent.exe] c:\program files\common files\research in motion\usb drivers\RIMBBLaunchAgent.exe
mRun: [AVG_TRAY] "c:\program files\avg\avg2012\avgtray.exe"
mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~1\micros~4\office14\ONBttnIE.dll/105
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files\microsoft office\office14\ONBttnIELinkedNotes.dll
LSP: mswsock.dll
Trusted Zone: alipay.com
Trusted Zone: alisoft.com
Trusted Zone: taobao.com
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
TCP: DhcpNameServer = 194.168.4.100 194.168.8.100
TCP: Interfaces\{21C6F387-FCEA-420A-86F4-973DBEC97120} : DhcpNameServer = 194.168.4.100 194.168.8.100
TCP: Interfaces\{238FBD14-0FEC-4186-932C-E1225B93772E} : DhcpNameServer = 194.168.4.100 194.168.8.100
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL
Notify: wemneka - c:\windows\system32\config\systemprofile\appdata\local\wemneka.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~4\office14\GROOVEEX.DLL
LSA: Authentication Packages = msv1_0 relog_ap
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\ed\appdata\roaming\mozilla\firefox\profiles\x7uoiu9s.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk
FF - plugin: c:\progra~1\micros~4\office14\NPAUTHZ.DLL
FF - plugin: c:\progra~1\micros~4\office14\NPSPWRAP.DLL
FF - plugin: c:\program files\common files\research in motion\bbwebsllauncher\NPWebSLLauncher.dll
FF - plugin: c:\program files\foxit software\foxit phantompdf\plugins\npFoxitPhantomPDFPlugin.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\update\1.3.21.99\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npwangwang.dll
FF - plugin: c:\program files\trademanager\npwangwang.dll
FF - plugin: c:\users\ed\appdata\roaming\mozilla\firefox\profiles\x7uoiu9s.default\extensions\{ab91efd4-6975-4081-8552-1b3922ed79e2}\plugins\npAclmPlugin.dll
FF - plugin: c:\users\ed\appdata\roaming\mozilla\firefox\profiles\x7uoiu9s.default\extensions\{ab91efd4-6975-4081-8552-1b3922ed79e2}\plugins\npProductDetectPlugin.dll
.
============= SERVICES / DRIVERS ===============
.
2 AMService;AMService
R? avgtdi;EUSBMSD
R? b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0
R? clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86
R? gupdate;Google Update Service (gupdate)
R? gupdatem;Google Update Service (gupdatem)
R? mcafeeframework;Tpkmpsvc
R? Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service
R? osppsvc;Office Software Protection Platform
R? PEVSystemStart;Avpnnic
R? RdpVideoMiniport;Remote Desktop Video Miniport Driver
R? Synth3dVsc;Synth3dVsc
R? TsUsbFlt;TsUsbFlt
R? tsusbhub;tsusbhub
R? umpusbvista;Texas Instruments USB Serial Driver
R? vet-filt;Wdmaud
R? VGPU;VGPU
R? WatAdminSvc;Windows Activation Technologies Service
S? AMD External Events Utility;AMD External Events Utility
S? amdkmdag;amdkmdag
S? amdkmdap;amdkmdap
S? AVGIDSEH;AVGIDSEH
S? Avgldx86;AVG AVI Loader Driver
S? Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield
S? Avgrkx86;AVG Anti-Rootkit Driver
S? avgwd;AVG WatchDog
S? MBAMProtector;MBAMProtector
S? MBAMService;MBAMService
S? Realtek11nCU;Realtek11nCU
S? RTL8167;Realtek 8167 NT Driver
S? RTL8192cu;Realtek RTL8192CU Wireless LAN 802.11n USB 2.0 Network Adapter
S? vwififlt;Virtual WiFi Filter Driver
.
=============== Created Last 30 ================
.
2012-02-29 11:02:24 -------- d-----w- c:\users\ed\appdata\roaming\Malwarebytes
2012-02-29 11:02:05 -------- d-----w- c:\programdata\Malwarebytes
2012-02-29 11:02:04 20464 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-02-29 11:02:03 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-02-29 05:34:02 83456 ----a-w- c:\windows\system32\W2ww4sH.com
2012-02-29 02:03:52 83456 ----a-w- c:\windows\system32\W2ww4sH.com_
2012-02-28 22:32:21 -------- d--h--w- C:\$AVG
2012-02-28 22:31:21 0 --sha-w- c:\windows\system32\dds_trash_log.cmd
2012-02-28 20:21:00 -------- d-----w- c:\users\ed\appdata\local\ReliefJet Essentials
2012-02-28 19:47:03 -------- d--h--w- c:\programdata\Common Files
2012-02-28 19:46:59 -------- d-----w- c:\users\ed\appdata\roaming\AVG2012
2012-02-28 19:45:13 -------- d-----w- c:\windows\system32\drivers\AVG
2012-02-28 19:45:13 -------- d-----w- c:\programdata\AVG2012
2012-02-28 19:43:53 -------- d-----w- c:\program files\AVG
2012-02-28 19:36:43 -------- d-----w- c:\programdata\MFAData
2012-02-28 10:23:19 -------- d-----w- c:\users\ed\appdata\local\{928C28D1-CF31-40B0-80C6-40ED46AAD963}
2012-02-28 10:23:07 -------- d-----w- c:\users\ed\appdata\local\{59D9C12F-AE5C-45A0-B534-62DAC15E1F5E}
2012-02-27 16:49:36 -------- d-----w- c:\users\ed\appdata\local\{306C849C-CB13-48A1-863E-C353BF9A5A5C}
2012-02-27 16:49:24 -------- d-----w- c:\users\ed\appdata\local\{1EEB30EC-52DA-4E18-A50C-AF2326DB4178}
2012-02-27 16:49:12 -------- d-----w- c:\users\ed\appdata\roaming\Windows Live Writer
2012-02-27 16:49:12 -------- d-----w- c:\users\ed\appdata\local\Windows Live Writer
2012-02-27 16:38:08 -------- d-----w- c:\users\ed\appdata\local\Windows Live
2012-02-27 16:38:00 -------- d-----w- c:\program files\common files\Windows Live
2012-02-26 15:30:20 -------- d-----w- C:\Jan
2012-02-26 13:51:56 -------- d-----w- c:\program files\MSXML 4.0
2012-02-24 23:01:36 -------- d-----w- c:\users\ed\appdata\roaming\Nokia Suite
2012-02-24 22:59:00 -------- d-----w- c:\users\ed\appdata\local\NokiaAccount
2012-02-24 22:50:02 -------- d-----w- c:\users\ed\appdata\local\Nokia
2012-02-24 22:49:00 -------- d-----w- c:\programdata\Nokia
2012-02-24 22:49:00 -------- d-----w- c:\program files\common files\Nokia
2012-02-24 22:48:01 18816 ----a-w- c:\windows\system32\drivers\pccsmcfd.sys
2012-02-24 22:47:40 -------- d-----w- c:\program files\PC Connectivity Solution
2012-02-24 22:47:20 75264 ----a-w- c:\windows\system32\nmwcdcls.dll
2012-02-24 22:46:44 -------- d-----w- c:\programdata\NokiaInstallerCache
2012-02-24 22:46:44 -------- d-----w- c:\program files\Nokia
2012-02-24 22:17:10 -------- d-----w- c:\users\ed\appdata\roaming\Blackberry Desktop
2012-02-24 22:05:47 -------- d-----w- c:\users\ed\appdata\local\Research In Motion
2012-02-24 22:05:46 -------- d-----w- c:\users\ed\appdata\roaming\Research In Motion
2012-02-24 22:04:04 35328 ----a-w- c:\windows\system32\drivers\RimSerial.sys
2012-02-24 22:03:33 -------- d-----w- c:\programdata\Research In Motion
2012-02-24 22:03:20 -------- d-----w- c:\program files\Research In Motion
2012-02-24 22:03:20 -------- d-----w- c:\program files\common files\Research In Motion
2012-02-24 17:20:47 -------- d-----w- c:\windows\system32\aliedit
2012-02-24 17:20:39 -------- d-----w- c:\program files\Trademanager
2012-02-24 17:17:47 -------- d-----w- c:\users\ed\appdata\local\Alibaba
2012-02-18 11:19:03 -------- d-----w- c:\users\ed\appdata\roaming\Scooter Software
2012-02-18 11:18:56 -------- d-----w- c:\program files\Beyond Compare 3
2012-02-18 03:10:38 6557240 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{c968969d-d305-4e77-a2be-728079485787}\mpengine.dll
2012-02-17 17:57:03 -------- d-----w- c:\program files\IMAPSize
2012-02-17 17:09:45 -------- d-----w- c:\users\ed\appdata\roaming\Helios
2012-02-17 17:09:11 49152 ----a-r- c:\users\ed\appdata\roaming\microsoft\installer\{b6ec7388-e277-4a5b-8c8f-71067a41ba64}\NewShortcut1.exe
2012-02-17 17:09:11 49152 ----a-r- c:\users\ed\appdata\roaming\microsoft\installer\{b6ec7388-e277-4a5b-8c8f-71067a41ba64}\ARPPRODUCTICON.exe
2012-02-17 17:09:08 -------- d-----w- c:\program files\TextPad 5
2012-02-15 17:24:18 89600 ----a-w- c:\windows\system32\spool\prtprocs\w32x86\HPZPPLHN.DLL
2012-02-15 17:21:11 -------- d-----w- c:\users\ed\appdata\local\ElevatedDiagnostics
2012-02-15 17:02:07 -------- d-----w- c:\program files\HP
2012-02-15 15:18:35 690688 ----a-w- c:\windows\system32\msvcrt.dll
2012-02-15 15:16:33 2343424 ----a-w- c:\windows\system32\win32k.sys
2012-02-04 12:59:55 44384 ----a-w- c:\windows\system32\drivers\tifsfilt.sys
2012-02-04 12:59:55 441760 ----a-w- c:\windows\system32\drivers\timntr.sys
2012-02-04 12:59:19 129248 ----a-w- c:\windows\system32\drivers\snapman.sys
2012-02-04 12:59:01 368544 ----a-w- c:\windows\system32\drivers\tdrpman.sys
2012-02-01 22:42:55 -------- d-----w- c:\users\ed\appdata\roaming\River Past G2
2012-01-31 21:54:25 -------- d-----w- c:\users\ed\appdata\local\Adobe
2012-01-31 21:53:37 -------- d-----w- c:\users\ed\appdata\roaming\MrSmooth.1F1C2CE6230412E7752D206B573506D8446D8E6A.1
2012-01-31 21:53:25 -------- d-----w- c:\program files\MrSmooth
2012-01-31 21:52:29 -------- d-----w- c:\program files\Mr Smooth
.
==================== Find3M ====================
.
2012-02-17 19:51:03 286720 ------w- c:\windows\Setup1.exe
2012-02-17 19:50:59 73216 ----a-w- c:\windows\ST6UNST.EXE
2012-01-28 19:37:18 87608 ----a-w- c:\users\ed\appdata\roaming\inst.exe
2012-01-28 19:37:18 47360 ----a-w- c:\windows\system32\drivers\pcouffin.sys
2012-01-28 19:37:18 47360 ----a-w- c:\users\ed\appdata\roaming\pcouffin.sys
2012-01-27 00:21:24 237072 ------w- c:\windows\system32\MpSigStub.exe
2012-01-17 22:58:10 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-01-08 13:27:31 472808 ----a-w- c:\windows\system32\deployJava1.dll
2012-01-07 17:23:59 231376 ----a-w- c:\windows\system32\drivers\truecrypt.sys
2012-01-07 15:11:00 152576 ----a-w- c:\windows\system32\msclmd.dll
2012-01-07 10:01:56 0 ----a-w- c:\windows\ativpsrm.bin
2012-01-06 08:00:00 545 ----a-w- c:\windows\UC.PIF
2012-01-06 08:00:00 545 ----a-w- c:\windows\RAR.PIF
2012-01-06 08:00:00 545 ----a-w- c:\windows\PKZIP.PIF
2012-01-06 08:00:00 545 ----a-w- c:\windows\PKUNZIP.PIF
2012-01-06 08:00:00 545 ----a-w- c:\windows\LHA.PIF
2012-01-06 08:00:00 545 ----a-w- c:\windows\ARJ.PIF
2011-12-29 18:00:00 79360 ----a-w- c:\windows\system32\ff_vfw.dll
2011-12-21 18:14:02 151552 ----a-w- c:\windows\system32\ac3acm.acm
2011-12-19 14:12:00 104752 ----a-w- c:\windows\system32\drivers\VBoxNetAdp.sys
2011-12-19 14:11:58 91440 ----a-w- c:\windows\system32\drivers\VBoxUSBMon.sys
2011-12-19 14:11:58 158512 ----a-w- c:\windows\system32\drivers\VBoxDrv.sys
2011-12-19 14:11:58 116016 ----a-w- c:\windows\system32\drivers\VBoxNetFlt.sys
2011-12-19 14:11:56 135472 ----a-w- c:\windows\system32\VBoxNetFltNobj.dll
2011-12-14 03:04:54 1798656 ----a-w- c:\windows\system32\jscript9.dll
2011-12-14 02:57:18 1127424 ----a-w- c:\windows\system32\wininet.dll
2011-12-14 02:56:58 1427456 ----a-w- c:\windows\system32\inetcpl.cpl
2011-12-14 02:50:04 2382848 ----a-w- c:\windows\system32\mshtml.tlb
.
============= FINISH: 16:45:35.16 ===============
Malwarebytes Anti-Malware (Trial) 1.60.1.1000
www.malwarebytes.org
Database version: v2012.02.29.02
Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 9.0.8112.16421
Ed :: ED-PC [administrator]
Protection: Enabled
29/02/2012 11:04:28
mbam-log-2012-02-29 (11-04-28).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 284139
Time elapsed: 53 minute(s), 46 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 1
C:\Recycle.Bin (Trojan.Spyeyes) -> Quarantined and deleted successfully.
Files Detected: 2
C:\Recycle.Bin\B6232F3AA59.exe (Trojan.Spyeyes) -> Quarantined and deleted successfully.
C:\Recycle.Bin\481D2A6DA7EAFE9 (Trojan.Spyeyes) -> Quarantined and deleted successfully.
(end)
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2012-02-29 16:33:48
Windows 6.1.7601 Service Pack 1 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 Maxtor_6Y120L0 rev.YAR41BW0
Running: p5vthjdp.exe; Driver: C:\Users\Ed\AppData\Local\Temp\pxldapoc.sys
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwSaveKey + 13D1 82C7C369 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 82CB5D52 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
? System32\drivers\jewk.sys The system cannot find the path specified. !
.text C:\Windows\System32\Drivers\dfsc.sys section is writeable [0x8E2C7000, 0x3C9C, 0xE8000020]
.text C:\Windows\system32\DRIVERS\atikmdag.sys section is writeable [0x8EE13000, 0x38CD55, 0xE8000020]
PAGE spsys.sys!?SPRevision@@3PADA + 4F90 A08D5000 290 Bytes [8B, FF, 55, 8B, EC, 33, C0, ...]
PAGE spsys.sys!?SPRevision@@3PADA + 50B3 A08D5123 629 Bytes [05, 8D, A0, FE, 05, 34, 05, ...]
PAGE spsys.sys!?SPRevision@@3PADA + 5329 A08D5399 101 Bytes [6A, 28, 59, A5, 5E, C6, 03, ...]
PAGE spsys.sys!?SPRevision@@3PADA + 538F A08D53FF 148 Bytes [18, 5D, C2, 14, 00, 8B, FF, ...]
PAGE spsys.sys!?SPRevision@@3PADA + 543B A08D54AB 2228 Bytes [8B, FF, 55, 8B, EC, FF, 75, ...]
PAGE ...
---- User code sections - GMER 1.0.15 ----
.text C:\Windows\system32\svchost.exe[1556] ntdll.dll!NtProtectVirtualMemory 77485F18 5 Bytes JMP 0052000A
.text C:\Windows\system32\svchost.exe[1556] ntdll.dll!NtWriteVirtualMemory 77486A98 5 Bytes JMP 0059000A
.text C:\Windows\system32\svchost.exe[1556] ntdll.dll!KiUserExceptionDispatcher 77486FE8 5 Bytes JMP 001B000A
.text C:\Windows\System32\ping.exe[4392] ntdll.dll!NtCreateProcess 77485698 5 Bytes JMP 0055000A
.text C:\Windows\System32\ping.exe[4392] ntdll.dll!NtCreateProcessEx 774856A8 5 Bytes JMP 0056000A
.text C:\Windows\System32\ping.exe[4392] ntdll.dll!NtCreateUserProcess 77485778 5 Bytes JMP 0057000A
.text C:\Windows\System32\ping.exe[4392] ntdll.dll!NtProtectVirtualMemory 77485F18 5 Bytes JMP 003E000A
.text C:\Windows\System32\ping.exe[4392] ntdll.dll!NtWriteVirtualMemory 77486A98 5 Bytes JMP 003F000A
.text C:\Windows\System32\ping.exe[4392] ntdll.dll!KiUserExceptionDispatcher 77486FE8 5 Bytes JMP 003D000A
.text C:\Windows\System32\ping.exe[4392] USER32.dll!GetCursorPos 7516A4B3 5 Bytes JMP 008F000A
.text C:\Windows\System32\ping.exe[4392] USER32.dll!GetForegroundWindow 7517335D 5 Bytes JMP 0091000A
.text C:\Windows\System32\ping.exe[4392] USER32.dll!WindowFromPoint 75196BE9 5 Bytes JMP 0090000A
.text C:\Windows\System32\ping.exe[4392] ole32.dll!CoCreateInstance 75BB9D0B 5 Bytes JMP 005D000A
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\Windows\TEMP\mtbuaj\setup.exe[2176] @ C:\Windows\system32\ADVAPI32.DLL [KERNEL32.dll!GetProcAddress] [74D0FFF6] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Windows\TEMP\mtbuaj\setup.exe[2176] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [74D0FFF6] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Windows\TEMP\mtbuaj\setup.exe[2176] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [74D0FFF6] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Windows\TEMP\mtbuaj\setup.exe[2176] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [74D0FFF6] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Windows\TEMP\mtbuaj\setup.exe[2176] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!GetProcAddress] [74D0FFF6] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[2552] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [74D0FFF6] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[2552] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [74D0FFF6] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[2552] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [74D0FFF6] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[2552] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!GetProcAddress] [74D0FFF6] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[2552] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [74D0FFF6] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
---- Devices - GMER 1.0.15 ----
Device \Driver\ACPI_HAL \Device\00000056 halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 tdrpman.sys (Acronis Try&Decide and Restore Points Volume Filter Driver/Acronis)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 snapman.sys (Acronis Snapshot API/Acronis)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 tdrpman.sys (Acronis Try&Decide and Restore Points Volume Filter Driver/Acronis)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 snapman.sys (Acronis Snapshot API/Acronis)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 tdrpman.sys (Acronis Try&Decide and Restore Points Volume Filter Driver/Acronis)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 snapman.sys (Acronis Snapshot API/Acronis)
---- Modules - GMER 1.0.15 ----
Module (noname) (*** hidden *** ) 8E2A3000-8E2C6000 (143360 bytes)
---- Processes - GMER 1.0.15 ----
Process C:\Windows\System32\ping.exe (*** hidden *** ) 4392
---- Files - GMER 1.0.15 ----
File C:\Windows\$NtUninstallKB9130$\1825098505 0 bytes
File C:\Windows\$NtUninstallKB9130$\2727051553 0 bytes
File C:\Windows\$NtUninstallKB9130$\2727051553\@ 2048 bytes
File C:\Windows\$NtUninstallKB9130$\2727051553\cfg.ini 296 bytes
File C:\Windows\$NtUninstallKB9130$\2727051553\Desktop.ini 4608 bytes
File C:\Windows\$NtUninstallKB9130$\2727051553\L 0 bytes
File C:\Windows\$NtUninstallKB9130$\2727051553\L\xadqgnnk 78336 bytes
File C:\Windows\$NtUninstallKB9130$\2727051553\oemid 130 bytes
File C:\Windows\$NtUninstallKB9130$\2727051553\U 0 bytes
File C:\Windows\$NtUninstallKB9130$\2727051553\U\00000001.@ 2048 bytes
File C:\Windows\$NtUninstallKB9130$\2727051553\U\00000002.@ 224768 bytes
File C:\Windows\$NtUninstallKB9130$\2727051553\U\00000004.@ 1024 bytes
File C:\Windows\$NtUninstallKB9130$\2727051553\U\80000000.@ 66560 bytes
File C:\Windows\$NtUninstallKB9130$\2727051553\U\80000004.@ 12800 bytes
File C:\Windows\$NtUninstallKB9130$\2727051553\U\80000032.@ 73216 bytes
File C:\Windows\$NtUninstallKB9130$\2727051553\version 842 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\3U9BMHDI\background_gradient[2] 453 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\3U9BMHDI\bullet[2] 447 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8MN4SDEE\bullet[1] 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\E6M0OIET\httpErrorPagesScripts[1] 0 bytes
File C:\Windows\Temp\~DF6B742880D68DE119.TMP 0 bytes
File C:\Windows\Temp\~DFB66948AF3F29F320.TMP 0 bytes
---- EOF - GMER 1.0.15 ----
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_29
Run by Ed at 16:36:58 on 2012-02-29
.
============== Running Processes ===============
.
C:\PROGRA~1\AVG\AVG2012\avgrsx.exe
C:\Program Files\AVG\AVG2012\avgcsrvx.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\atiesrxx.exe
C:\Windows\system32\atieclxx.exe
C:\Windows\System32\spoolsv.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Windows\TEMP\mtbuaj\setup.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\AVG\AVG2012\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\REALTEK\11n USB Wireless LAN Utility\RtlService.exe
C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Windows\system32\sppsvc.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\REALTEK\11n USB Wireless LAN Utility\RtWlan.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe
C:\Program Files\AVG\AVG2012\avgtray.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Nokia\Nokia Suite\NokiaSuite.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclMSBTSrvEx.exe
C:\totalcmd\TOTALCMD.EXE
C:\Windows\system32\conhost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\WLANExt.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\W2ww4sH.com
C:\Windows\system32\W2WW4S~1.COM
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\W2ww4sH.com
C:\Program Files\AVG\AVG2012\avgui.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Users\Ed\Downloads\dds.scr
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\System32\svchost.exe -k WerSvcGroup
.
============== Pseudo HJT Report ===============
.
uInternet Settings,ProxyOverride = *.local
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~4\office14\GROOVEEX.DLL
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - c:\progra~1\micros~4\office14\URLREDIR.DLL
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
uRun: [<NO NAME>]
uRun: [NokiaSuite.exe] c:\program files\nokia\nokia suite\NokiaSuite.exe -tray
mRun: [IntelliPoint] "c:\program files\microsoft intellipoint\ipoint.exe"
mRun: [itype] "c:\program files\microsoft intellitype pro\itype.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [VirtualCloneDrive] "c:\program files\elaborate bytes\virtualclonedrive\VCDDaemon.exe" /s
mRun: [BCSSync] "c:\program files\microsoft office\office14\BCSSync.exe" /DelayServices
mRun: [TrueImageMonitor.exe] c:\program files\acronis\trueimagehome\TrueImageMonitor.exe
mRun: [AcronisTimounterMonitor] c:\program files\acronis\trueimagehome\TimounterMonitor.exe
mRun: [Acronis Scheduler2 Service] "c:\program files\common files\acronis\schedule2\schedhlp.exe"
mRun: [RIMBBLaunchAgent.exe] c:\program files\common files\research in motion\usb drivers\RIMBBLaunchAgent.exe
mRun: [AVG_TRAY] "c:\program files\avg\avg2012\avgtray.exe"
mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~1\micros~4\office14\ONBttnIE.dll/105
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files\microsoft office\office14\ONBttnIELinkedNotes.dll
LSP: mswsock.dll
Trusted Zone: alipay.com
Trusted Zone: alisoft.com
Trusted Zone: taobao.com
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
TCP: DhcpNameServer = 194.168.4.100 194.168.8.100
TCP: Interfaces\{21C6F387-FCEA-420A-86F4-973DBEC97120} : DhcpNameServer = 194.168.4.100 194.168.8.100
TCP: Interfaces\{238FBD14-0FEC-4186-932C-E1225B93772E} : DhcpNameServer = 194.168.4.100 194.168.8.100
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL
Notify: wemneka - c:\windows\system32\config\systemprofile\appdata\local\wemneka.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~4\office14\GROOVEEX.DLL
LSA: Authentication Packages = msv1_0 relog_ap
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\ed\appdata\roaming\mozilla\firefox\profiles\x7uoiu9s.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk
FF - plugin: c:\progra~1\micros~4\office14\NPAUTHZ.DLL
FF - plugin: c:\progra~1\micros~4\office14\NPSPWRAP.DLL
FF - plugin: c:\program files\common files\research in motion\bbwebsllauncher\NPWebSLLauncher.dll
FF - plugin: c:\program files\foxit software\foxit phantompdf\plugins\npFoxitPhantomPDFPlugin.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\update\1.3.21.99\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npwangwang.dll
FF - plugin: c:\program files\trademanager\npwangwang.dll
FF - plugin: c:\users\ed\appdata\roaming\mozilla\firefox\profiles\x7uoiu9s.default\extensions\{ab91efd4-6975-4081-8552-1b3922ed79e2}\plugins\npAclmPlugin.dll
FF - plugin: c:\users\ed\appdata\roaming\mozilla\firefox\profiles\x7uoiu9s.default\extensions\{ab91efd4-6975-4081-8552-1b3922ed79e2}\plugins\npProductDetectPlugin.dll
.
============= SERVICES / DRIVERS ===============
.
2 AMService;AMService
R? avgtdi;EUSBMSD
R? b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0
R? clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86
R? gupdate;Google Update Service (gupdate)
R? gupdatem;Google Update Service (gupdatem)
R? mcafeeframework;Tpkmpsvc
R? Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service
R? osppsvc;Office Software Protection Platform
R? PEVSystemStart;Avpnnic
R? RdpVideoMiniport;Remote Desktop Video Miniport Driver
R? Synth3dVsc;Synth3dVsc
R? TsUsbFlt;TsUsbFlt
R? tsusbhub;tsusbhub
R? umpusbvista;Texas Instruments USB Serial Driver
R? vet-filt;Wdmaud
R? VGPU;VGPU
R? WatAdminSvc;Windows Activation Technologies Service
S? AMD External Events Utility;AMD External Events Utility
S? amdkmdag;amdkmdag
S? amdkmdap;amdkmdap
S? AVGIDSEH;AVGIDSEH
S? Avgldx86;AVG AVI Loader Driver
S? Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield
S? Avgrkx86;AVG Anti-Rootkit Driver
S? avgwd;AVG WatchDog
S? MBAMProtector;MBAMProtector
S? MBAMService;MBAMService
S? Realtek11nCU;Realtek11nCU
S? RTL8167;Realtek 8167 NT Driver
S? RTL8192cu;Realtek RTL8192CU Wireless LAN 802.11n USB 2.0 Network Adapter
S? vwififlt;Virtual WiFi Filter Driver
.
=============== Created Last 30 ================
.
2012-02-29 11:02:24 -------- d-----w- c:\users\ed\appdata\roaming\Malwarebytes
2012-02-29 11:02:05 -------- d-----w- c:\programdata\Malwarebytes
2012-02-29 11:02:04 20464 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-02-29 11:02:03 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-02-29 05:34:02 83456 ----a-w- c:\windows\system32\W2ww4sH.com
2012-02-29 02:03:52 83456 ----a-w- c:\windows\system32\W2ww4sH.com_
2012-02-28 22:32:21 -------- d--h--w- C:\$AVG
2012-02-28 22:31:21 0 --sha-w- c:\windows\system32\dds_trash_log.cmd
2012-02-28 20:21:00 -------- d-----w- c:\users\ed\appdata\local\ReliefJet Essentials
2012-02-28 19:47:03 -------- d--h--w- c:\programdata\Common Files
2012-02-28 19:46:59 -------- d-----w- c:\users\ed\appdata\roaming\AVG2012
2012-02-28 19:45:13 -------- d-----w- c:\windows\system32\drivers\AVG
2012-02-28 19:45:13 -------- d-----w- c:\programdata\AVG2012
2012-02-28 19:43:53 -------- d-----w- c:\program files\AVG
2012-02-28 19:36:43 -------- d-----w- c:\programdata\MFAData
2012-02-28 10:23:19 -------- d-----w- c:\users\ed\appdata\local\{928C28D1-CF31-40B0-80C6-40ED46AAD963}
2012-02-28 10:23:07 -------- d-----w- c:\users\ed\appdata\local\{59D9C12F-AE5C-45A0-B534-62DAC15E1F5E}
2012-02-27 16:49:36 -------- d-----w- c:\users\ed\appdata\local\{306C849C-CB13-48A1-863E-C353BF9A5A5C}
2012-02-27 16:49:24 -------- d-----w- c:\users\ed\appdata\local\{1EEB30EC-52DA-4E18-A50C-AF2326DB4178}
2012-02-27 16:49:12 -------- d-----w- c:\users\ed\appdata\roaming\Windows Live Writer
2012-02-27 16:49:12 -------- d-----w- c:\users\ed\appdata\local\Windows Live Writer
2012-02-27 16:38:08 -------- d-----w- c:\users\ed\appdata\local\Windows Live
2012-02-27 16:38:00 -------- d-----w- c:\program files\common files\Windows Live
2012-02-26 15:30:20 -------- d-----w- C:\Jan
2012-02-26 13:51:56 -------- d-----w- c:\program files\MSXML 4.0
2012-02-24 23:01:36 -------- d-----w- c:\users\ed\appdata\roaming\Nokia Suite
2012-02-24 22:59:00 -------- d-----w- c:\users\ed\appdata\local\NokiaAccount
2012-02-24 22:50:02 -------- d-----w- c:\users\ed\appdata\local\Nokia
2012-02-24 22:49:00 -------- d-----w- c:\programdata\Nokia
2012-02-24 22:49:00 -------- d-----w- c:\program files\common files\Nokia
2012-02-24 22:48:01 18816 ----a-w- c:\windows\system32\drivers\pccsmcfd.sys
2012-02-24 22:47:40 -------- d-----w- c:\program files\PC Connectivity Solution
2012-02-24 22:47:20 75264 ----a-w- c:\windows\system32\nmwcdcls.dll
2012-02-24 22:46:44 -------- d-----w- c:\programdata\NokiaInstallerCache
2012-02-24 22:46:44 -------- d-----w- c:\program files\Nokia
2012-02-24 22:17:10 -------- d-----w- c:\users\ed\appdata\roaming\Blackberry Desktop
2012-02-24 22:05:47 -------- d-----w- c:\users\ed\appdata\local\Research In Motion
2012-02-24 22:05:46 -------- d-----w- c:\users\ed\appdata\roaming\Research In Motion
2012-02-24 22:04:04 35328 ----a-w- c:\windows\system32\drivers\RimSerial.sys
2012-02-24 22:03:33 -------- d-----w- c:\programdata\Research In Motion
2012-02-24 22:03:20 -------- d-----w- c:\program files\Research In Motion
2012-02-24 22:03:20 -------- d-----w- c:\program files\common files\Research In Motion
2012-02-24 17:20:47 -------- d-----w- c:\windows\system32\aliedit
2012-02-24 17:20:39 -------- d-----w- c:\program files\Trademanager
2012-02-24 17:17:47 -------- d-----w- c:\users\ed\appdata\local\Alibaba
2012-02-18 11:19:03 -------- d-----w- c:\users\ed\appdata\roaming\Scooter Software
2012-02-18 11:18:56 -------- d-----w- c:\program files\Beyond Compare 3
2012-02-18 03:10:38 6557240 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{c968969d-d305-4e77-a2be-728079485787}\mpengine.dll
2012-02-17 17:57:03 -------- d-----w- c:\program files\IMAPSize
2012-02-17 17:09:45 -------- d-----w- c:\users\ed\appdata\roaming\Helios
2012-02-17 17:09:11 49152 ----a-r- c:\users\ed\appdata\roaming\microsoft\installer\{b6ec7388-e277-4a5b-8c8f-71067a41ba64}\NewShortcut1.exe
2012-02-17 17:09:11 49152 ----a-r- c:\users\ed\appdata\roaming\microsoft\installer\{b6ec7388-e277-4a5b-8c8f-71067a41ba64}\ARPPRODUCTICON.exe
2012-02-17 17:09:08 -------- d-----w- c:\program files\TextPad 5
2012-02-15 17:24:18 89600 ----a-w- c:\windows\system32\spool\prtprocs\w32x86\HPZPPLHN.DLL
2012-02-15 17:21:11 -------- d-----w- c:\users\ed\appdata\local\ElevatedDiagnostics
2012-02-15 17:02:07 -------- d-----w- c:\program files\HP
2012-02-15 15:18:35 690688 ----a-w- c:\windows\system32\msvcrt.dll
2012-02-15 15:16:33 2343424 ----a-w- c:\windows\system32\win32k.sys
2012-02-04 12:59:55 44384 ----a-w- c:\windows\system32\drivers\tifsfilt.sys
2012-02-04 12:59:55 441760 ----a-w- c:\windows\system32\drivers\timntr.sys
2012-02-04 12:59:19 129248 ----a-w- c:\windows\system32\drivers\snapman.sys
2012-02-04 12:59:01 368544 ----a-w- c:\windows\system32\drivers\tdrpman.sys
2012-02-01 22:42:55 -------- d-----w- c:\users\ed\appdata\roaming\River Past G2
2012-01-31 21:54:25 -------- d-----w- c:\users\ed\appdata\local\Adobe
2012-01-31 21:53:37 -------- d-----w- c:\users\ed\appdata\roaming\MrSmooth.1F1C2CE6230412E7752D206B573506D8446D8E6A.1
2012-01-31 21:53:25 -------- d-----w- c:\program files\MrSmooth
2012-01-31 21:52:29 -------- d-----w- c:\program files\Mr Smooth
.
==================== Find3M ====================
.
2012-02-17 19:51:03 286720 ------w- c:\windows\Setup1.exe
2012-02-17 19:50:59 73216 ----a-w- c:\windows\ST6UNST.EXE
2012-01-28 19:37:18 87608 ----a-w- c:\users\ed\appdata\roaming\inst.exe
2012-01-28 19:37:18 47360 ----a-w- c:\windows\system32\drivers\pcouffin.sys
2012-01-28 19:37:18 47360 ----a-w- c:\users\ed\appdata\roaming\pcouffin.sys
2012-01-27 00:21:24 237072 ------w- c:\windows\system32\MpSigStub.exe
2012-01-17 22:58:10 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-01-08 13:27:31 472808 ----a-w- c:\windows\system32\deployJava1.dll
2012-01-07 17:23:59 231376 ----a-w- c:\windows\system32\drivers\truecrypt.sys
2012-01-07 15:11:00 152576 ----a-w- c:\windows\system32\msclmd.dll
2012-01-07 10:01:56 0 ----a-w- c:\windows\ativpsrm.bin
2012-01-06 08:00:00 545 ----a-w- c:\windows\UC.PIF
2012-01-06 08:00:00 545 ----a-w- c:\windows\RAR.PIF
2012-01-06 08:00:00 545 ----a-w- c:\windows\PKZIP.PIF
2012-01-06 08:00:00 545 ----a-w- c:\windows\PKUNZIP.PIF
2012-01-06 08:00:00 545 ----a-w- c:\windows\LHA.PIF
2012-01-06 08:00:00 545 ----a-w- c:\windows\ARJ.PIF
2011-12-29 18:00:00 79360 ----a-w- c:\windows\system32\ff_vfw.dll
2011-12-21 18:14:02 151552 ----a-w- c:\windows\system32\ac3acm.acm
2011-12-19 14:12:00 104752 ----a-w- c:\windows\system32\drivers\VBoxNetAdp.sys
2011-12-19 14:11:58 91440 ----a-w- c:\windows\system32\drivers\VBoxUSBMon.sys
2011-12-19 14:11:58 158512 ----a-w- c:\windows\system32\drivers\VBoxDrv.sys
2011-12-19 14:11:58 116016 ----a-w- c:\windows\system32\drivers\VBoxNetFlt.sys
2011-12-19 14:11:56 135472 ----a-w- c:\windows\system32\VBoxNetFltNobj.dll
2011-12-14 03:04:54 1798656 ----a-w- c:\windows\system32\jscript9.dll
2011-12-14 02:57:18 1127424 ----a-w- c:\windows\system32\wininet.dll
2011-12-14 02:56:58 1427456 ----a-w- c:\windows\system32\inetcpl.cpl
2011-12-14 02:50:04 2382848 ----a-w- c:\windows\system32\mshtml.tlb
.
============= FINISH: 16:45:35.16 ===============