radarrider
Posts: 9 +0
Have a HP laptop that I restored to factory original from second partition AFTER it was jacked. I installed updated virus scanners on a desktop and cleaned the laptop drive. Seemed to work, but had too many files damaged, so did HP factory recovery from D: partition. Installed Panda, Threatfire and AVG Internet Security. Still having same problems with very slow boots, security errors and lock ups. Will not create a restore point. The orinigal infection removed all the restore points. Seems to work in safe mode with networking okay.
UnHackMe finds control_RunDll and some other files tell it to delete. They aren't found on the reboot and UnHackMe usually locks up. If I cancel out of UnHackMe, PC will usually come on up.
Vista 32-bit, 4 GB.
Followed steps. Here are the logs:
MalwareBytes:
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org
Database version: 5937
Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.19019
3/2/2011 4:32:53 PM
mbam-log-2011-03-02 (16-32-53).txt
Scan type: Quick scan
Objects scanned: 158163
Time elapsed: 5 minute(s), 58 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
GMER log
GMER 1.0.15.15530 - http://www.gmer.net
Rootkit quick scan 2011-03-02 15:39:43
Windows 6.0.6002 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 ST950032 rev.0002
Running: 053xeihi.exe; Driver: C:\Users\Dave\AppData\Local\Temp\uxryipod.sys
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\Ntfs \Ntfs TfFsMon.sys (ThreatFire Filesystem Monitor/PC Tools)
AttachedDevice \FileSystem\Ntfs \Ntfs AVGIDSFilter.Sys (IDS Application Activity Monitor Filter Driver./AVG Technologies CZ, s.r.o. )
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\fastfat \Fat AVGIDSFilter.Sys (IDS Application Activity Monitor Filter Driver./AVG Technologies CZ, s.r.o. )
AttachedDevice \Driver\tdx \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\tdx \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\tdx \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\tdx \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (Kernel Mode Driver Framework Runtime/Microsoft Corporation)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys (Kernel Mode Driver Framework Runtime/Microsoft Corporation)
---- EOF - GMER 1.0.15 ----
Attach.txt:
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_10-12-12.02)
Microsoft® Windows Vista™ Home Premium
Boot Device: \Device\HarddiskVolume1
Install Date: 2/26/2011 1:00:56 PM
System Uptime: 3/2/2011 3:40:33 PM (3 hours ago)
Motherboard: Quanta | | 361B
Processor: Intel(R) Core(TM)2 Duo CPU P8600 @ 2.40GHz | CPU | 2401/1066mhz
==== Disk Partitions =========================
C: is FIXED (NTFS) - 457 GiB total, 338.537 GiB free.
D: is FIXED (NTFS) - 9 GiB total, 1.56 GiB free.
E: is CDROM ()
F: is Removable
==== Disabled Device Manager Items =============
==== System Restore Points ===================
No restore point in system.
==== Installed Programs ======================
7-Zip 4.65
Adobe Flash Player 10 Plugin
Adobe Flash Player ActiveX
Adobe Reader 8.1.2
Adobe Shockwave Player
AVG 2011
Cards_Calendar_OrderGift_DoMorePlugout
CyberLink DVD Suite
CyberLink YouCam
DigitalPersona Personal 4.11
doPDF 6.2 printer
ESU for Microsoft Vista
Hewlett-Packard Active Check for Health Check
Hewlett-Packard Asset Agent for Health Check
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
HP Active Support Library
HP Customer Experience Enhancements
HP Doc Viewer
HP Help and Support
HP Integrated Module with Bluetooth wireless technology 6.0.1.6204
HP MediaSmart DVD
HP MediaSmart Music/Photo/Video
HP MediaSmart SmartMenu
HP MediaSmart TV
HP Photosmart Essential 2.5
HP Photosmart Essential 3.0
HP Quick Launch Buttons 6.40 H2
HP Smart Web Printing
HP Total Care Advisor
HP Update
HP User Guides 0115
HP Wireless Assistant
HPNetworkAssistant
HPPhotoSmartPhotobookWebPack1
HPTCSSetup
IDT Audio
Intel® Matrix Storage Manager
Java Auto Updater
Java(TM) 6 Update 24
Java(TM) 6 Update 6
JMicron JMB38X Flash Media Controller
LabelPrint
Malwarebytes' Anti-Malware
Microsoft .NET Framework 3.5 SP1
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Mozilla Firefox (3.6.14)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
muvee autoProducer 6.1
NVIDIA Drivers
Panda Cloud Antivirus
Panda Identity Protect 3.0.44
Panda Security Toolbar
Panda Security URL Filtering
PhotoNow!
Power2Go
PowerDirector
ProtectSmart Hard Drive Protection
PSSWCORE
QuickPlay SlingPlayer 0.4.6
Realtek 8169 8168 8101E 8102E Ethernet Driver
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)
Slingbox Flash Tour
SlingPlayer
Synaptics Pointing Device Driver
ThreatFire
UnHackMe 5.99 release
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Validity Sensors software
VideoToolkit01
VLC media player 1.1.7
Windows Driver Package - ENE (enecir) HIDClass (04/29/2008 2.5.0.0)
Yahoo! Toolbar
==== Event Viewer Messages From Past Week ========
3/2/2011 3:36:31 PM, Error: disk [11] - The driver detected a controller error on \Device\Harddisk1\DR1.
3/2/2011 2:51:49 PM, Error: Service Control Manager [7000] - The Parallel port driver service failed to start due to the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
3/2/2011 2:50:34 PM, Error: EventLog [6008] - The previous system shutdown at 2:42:16 PM on 3/2/2011 was unexpected.
3/2/2011 2:50:09 PM, Error: volsnap [27] - The shadow copies of volume C: were aborted during detection because a critical control file could not be opened.
3/2/2011 2:46:38 PM, Error: volsnap [14] - The shadow copies of volume C: were aborted because of an IO failure on volume C:.
3/2/2011 2:40:25 PM, Error: Service Control Manager [7034] - The NVIDIA Display Driver Service service terminated unexpectedly. It has done this 1 time(s).
3/2/2011 12:39:26 PM, Error: EventLog [6008] - The previous system shutdown at 12:09:14 PM on 3/2/2011 was unexpected.
3/2/2011 12:04:35 PM, Error: EventLog [6008] - The previous system shutdown at 11:37:09 AM on 3/2/2011 was unexpected.
3/2/2011 11:21:12 AM, Error: EventLog [6008] - The previous system shutdown at 11:15:29 AM on 3/2/2011 was unexpected.
3/1/2011 9:36:41 AM, Error: EventLog [6008] - The previous system shutdown at 8:36:19 AM on 3/1/2011 was unexpected.
3/1/2011 8:50:39 PM, Error: EventLog [6008] - The previous system shutdown at 7:53:12 PM on 3/1/2011 was unexpected.
3/1/2011 7:51:15 PM, Error: Ntfs [55] - The file system structure on the disk is corrupt and unusable. Please run the chkdsk utility on the volume C:.
3/1/2011 7:51:15 PM, Error: Ntfs [55] - The file system structure on the disk is corrupt and unusable. Please run the chkdsk utility on the volume \Device\HarddiskVolume1.
3/1/2011 7:47:26 PM, Error: Service Control Manager [7031] - The Windows Search service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service.
3/1/2011 7:46:44 PM, Error: Service Control Manager [7024] - The Windows Search service terminated with service-specific error 2147749155 (0x80040D23).
3/1/2011 7:45:27 PM, Error: EventLog [6008] - The previous system shutdown at 10:23:28 AM on 3/1/2011 was unexpected.
3/1/2011 7:31:39 AM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Eventlog service.
3/1/2011 7:26:09 AM, Error: Service Control Manager [7034] - The Program Compatibility Assistant Service service terminated unexpectedly. It has done this 16 time(s).
3/1/2011 7:26:09 AM, Error: Service Control Manager [7034] - The Network Connections service terminated unexpectedly. It has done this 14 time(s).
3/1/2011 7:26:09 AM, Error: Service Control Manager [7031] - The WLAN AutoConfig service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
3/1/2011 7:26:09 AM, Error: Service Control Manager [7031] - The Windows Audio Endpoint Builder service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
3/1/2011 7:26:04 AM, Error: Service Control Manager [7034] - The KtmRm for Distributed Transaction Coordinator service terminated unexpectedly. It has done this 3 time(s).
3/1/2011 7:26:04 AM, Error: Service Control Manager [7034] - The DNS Client service terminated unexpectedly. It has done this 3 time(s).
3/1/2011 7:26:04 AM, Error: Service Control Manager [7034] - The Cryptographic Services service terminated unexpectedly. It has done this 6 time(s).
3/1/2011 7:22:54 AM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the PlugPlay service.
3/1/2011 10:07:33 AM, Error: EventLog [6008] - The previous system shutdown at 9:44:25 AM on 3/1/2011 was unexpected.
2/28/2011 11:58:32 PM, Error: Service Control Manager [7034] - The Windows Firewall service terminated unexpectedly. It has done this 3 time(s).
2/28/2011 11:58:32 PM, Error: Service Control Manager [7034] - The Diagnostic Policy Service service terminated unexpectedly. It has done this 3 time(s).
2/28/2011 11:58:32 PM, Error: Service Control Manager [7034] - The Base Filtering Engine service terminated unexpectedly. It has done this 3 time(s).
2/28/2011 11:57:48 PM, Error: Service Control Manager [7034] - The Program Compatibility Assistant Service service terminated unexpectedly. It has done this 15 time(s).
2/28/2011 11:57:48 PM, Error: Service Control Manager [7034] - The Network Connections service terminated unexpectedly. It has done this 13 time(s).
2/28/2011 11:57:48 PM, Error: Service Control Manager [7034] - The Diagnostic System Host service terminated unexpectedly. It has done this 7 time(s).
2/28/2011 11:56:35 PM, Error: Service Control Manager [7034] - The Program Compatibility Assistant Service service terminated unexpectedly. It has done this 14 time(s).
2/28/2011 11:56:35 PM, Error: Service Control Manager [7034] - The Network Connections service terminated unexpectedly. It has done this 12 time(s).
2/28/2011 11:56:14 PM, Error: Service Control Manager [7034] - The Program Compatibility Assistant Service service terminated unexpectedly. It has done this 13 time(s).
2/28/2011 11:54:55 PM, Error: Service Control Manager [7034] - The Program Compatibility Assistant Service service terminated unexpectedly. It has done this 12 time(s).
2/28/2011 11:54:55 PM, Error: Service Control Manager [7034] - The Network Connections service terminated unexpectedly. It has done this 11 time(s).
2/28/2011 11:54:55 PM, Error: Service Control Manager [7031] - The WLAN AutoConfig service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 300000 milliseconds: Restart the service.
2/28/2011 11:47:14 PM, Error: Service Control Manager [7034] - The Program Compatibility Assistant Service service terminated unexpectedly. It has done this 9 time(s).
2/28/2011 11:47:14 PM, Error: Service Control Manager [7034] - The Network Connections service terminated unexpectedly. It has done this 8 time(s).
2/28/2011 11:47:14 PM, Error: Service Control Manager [7034] - The Diagnostic System Host service terminated unexpectedly. It has done this 4 time(s).
2/28/2011 11:44:32 PM, Error: Service Control Manager [7034] - The Program Compatibility Assistant Service service terminated unexpectedly. It has done this 8 time(s).
2/28/2011 11:44:32 PM, Error: Service Control Manager [7034] - The Network Connections service terminated unexpectedly. It has done this 7 time(s).
2/28/2011 11:44:32 PM, Error: Service Control Manager [7034] - The Diagnostic System Host service terminated unexpectedly. It has done this 3 time(s).
2/28/2011 11:42:10 PM, Error: Service Control Manager [7034] - The Windows Driver Foundation - User-mode Driver Framework service terminated unexpectedly. It has done this 3 time(s).
2/28/2011 11:42:10 PM, Error: Service Control Manager [7034] - The Tablet PC Input Service service terminated unexpectedly. It has done this 3 time(s).
2/28/2011 11:42:10 PM, Error: Service Control Manager [7034] - The Program Compatibility Assistant Service service terminated unexpectedly. It has done this 7 time(s).
2/28/2011 11:42:10 PM, Error: Service Control Manager [7034] - The Portable Device Enumerator Service service terminated unexpectedly. It has done this 3 time(s).
2/28/2011 11:42:10 PM, Error: Service Control Manager [7034] - The Network Connections service terminated unexpectedly. It has done this 6 time(s).
2/28/2011 11:42:10 PM, Error: Service Control Manager [7034] - The Human Interface Device Access service terminated unexpectedly. It has done this 3 time(s).
2/28/2011 11:42:10 PM, Error: Service Control Manager [7034] - The Distributed Link Tracking Client service terminated unexpectedly. It has done this 3 time(s).
2/28/2011 11:42:10 PM, Error: Service Control Manager [7034] - The Diagnostic System Host service terminated unexpectedly. It has done this 2 time(s).
2/28/2011 11:42:10 PM, Error: Service Control Manager [7034] - The Desktop Window Manager Session Manager service terminated unexpectedly. It has done this 3 time(s).
2/28/2011 11:40:23 PM, Error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Telephony service, but this action failed with the following error: An instance of the service is already running.
2/28/2011 11:35:46 PM, Error: Service Control Manager [7034] - The Superfetch service terminated unexpectedly. It has done this 3 time(s).
2/28/2011 11:35:46 PM, Error: Service Control Manager [7034] - The ReadyBoost service terminated unexpectedly. It has done this 3 time(s).
2/28/2011 11:35:46 PM, Error: Service Control Manager [7034] - The Program Compatibility Assistant Service service terminated unexpectedly. It has done this 6 time(s).
2/28/2011 11:35:46 PM, Error: Service Control Manager [7034] - The Network Connections service terminated unexpectedly. It has done this 5 time(s).
2/28/2011 11:35:46 PM, Error: Service Control Manager [7034] - The Diagnostic System Host service terminated unexpectedly. It has done this 1 time(s).
2/28/2011 11:35:46 PM, Error: Service Control Manager [7031] - The Windows Driver Foundation - User-mode Driver Framework service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 300000 milliseconds: Restart the service.
2/28/2011 11:35:46 PM, Error: Service Control Manager [7031] - The Portable Device Enumerator Service service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 300000 milliseconds: Restart the service.
2/28/2011 11:35:46 PM, Error: Service Control Manager [7031] - The Human Interface Device Access service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 300000 milliseconds: Restart the service.
2/28/2011 11:35:46 PM, Error: Service Control Manager [7031] - The Distributed Link Tracking Client service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 300000 milliseconds: Restart the service.
2/28/2011 11:35:46 PM, Error: Service Control Manager [7031] - The Desktop Window Manager Session Manager service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 300000 milliseconds: Restart the service.
2/28/2011 11:35:32 PM, Error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Windows Audio Endpoint Builder service, but this action failed with the following error: An instance of the service is already running.
2/28/2011 11:35:26 PM, Error: Service Control Manager [7034] - The Windows Search service terminated unexpectedly. It has done this 3 time(s).
2/28/2011 11:35:26 PM, Error: Service Control Manager [7034] - The Cryptographic Services service terminated unexpectedly. It has done this 4 time(s).
2/28/2011 11:35:26 PM, Error: Service Control Manager [7031] - The Telephony service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 300000 milliseconds: Restart the service.
2/28/2011 11:35:26 PM, Error: Service Control Manager [7031] - The KtmRm for Distributed Transaction Coordinator service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 1000 milliseconds: Restart the service.
2/28/2011 11:35:01 PM, Error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Base Filtering Engine service, but this action failed with the following error: An instance of the service is already running.
2/28/2011 11:34:58 PM, Error: Service Control Manager [7034] - The Program Compatibility Assistant Service service terminated unexpectedly. It has done this 5 time(s).
2/28/2011 11:34:58 PM, Error: Service Control Manager [7034] - The Network Location Awareness service terminated unexpectedly. It has done this 3 time(s).
2/28/2011 11:34:58 PM, Error: Service Control Manager [7034] - The Network Connections service terminated unexpectedly. It has done this 4 time(s).
2/28/2011 11:34:58 PM, Error: Service Control Manager [7034] - The Cryptographic Services service terminated unexpectedly. It has done this 3 time(s).
2/28/2011 11:34:58 PM, Error: Service Control Manager [7031] - The Terminal Services service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
2/28/2011 11:34:32 PM, Error: Service Control Manager [7034] - The Program Compatibility Assistant Service service terminated unexpectedly. It has done this 4 time(s).
2/28/2011 11:34:32 PM, Error: Service Control Manager [7034] - The Network Connections service terminated unexpectedly. It has done this 3 time(s).
2/28/2011 11:34:32 PM, Error: Service Control Manager [7034] - The Cryptographic Services service terminated unexpectedly. It has done this 2 time(s).
2/28/2011 11:34:32 PM, Error: Service Control Manager [7031] - The Telephony service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
2/28/2011 11:34:32 PM, Error: Service Control Manager [7031] - The Tablet PC Input Service service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
2/28/2011 11:34:32 PM, Error: Service Control Manager [7031] - The Superfetch service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
2/28/2011 11:34:32 PM, Error: Service Control Manager [7031] - The ReadyBoost service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
2/28/2011 11:34:32 PM, Error: Service Control Manager [7031] - The Network Location Awareness service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 100 milliseconds: Restart the service.
2/28/2011 11:34:09 PM, Error: Service Control Manager [7034] - The Program Compatibility Assistant Service service terminated unexpectedly. It has done this 3 time(s).
2/28/2011 11:34:09 PM, Error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Network Connections service, but this action failed with the following error: An instance of the service is already running.
2/28/2011 11:34:09 PM, Error: Service Control Manager [7031] - The Windows Search service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service.
2/28/2011 11:34:09 PM, Error: Service Control Manager [7031] - The Network Connections service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 100 milliseconds: Restart the service.
2/28/2011 11:34:09 PM, Error: Service Control Manager [7001] - The Windows Audio service depends on the Windows Audio Endpoint Builder service which failed to start because of the following error: The operation completed successfully.
2/28/2011 11:32:15 PM, Error: Service Control Manager [7022] - The Panda Cloud Antivirus Service service hung on starting.
2/28/2011 11:32:14 PM, Error: Service Control Manager [7022] - The AVGIDSAgent service hung on starting.
2/28/2011 11:26:08 PM, Error: EventLog [6008] - The previous system shutdown at 11:16:52 PM on 2/28/2011 was unexpected.
2/28/2011 1:36:27 PM, Error: Service Control Manager [7030] - The Panda Cloud Antivirus Service service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.
2/27/2011 9:23:58 PM, Error: Microsoft-Windows-WindowsUpdateClient [20] - Installation Failure: Windows failed to install the following update with error 0x80240016: Synaptics - Input - Synaptics PS/2 Port TouchPad.
2/27/2011 6:27:32 PM, Error: Microsoft-Windows-Service Pack Installer [6] - The Service Pack cannot be installed when the computer is running on battery power.
2/27/2011 5:03:17 PM, Error: Service Control Manager [7030] - The ThreatFire service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.
==== End Of File ===========================
DDS.txt in next post
UnHackMe finds control_RunDll and some other files tell it to delete. They aren't found on the reboot and UnHackMe usually locks up. If I cancel out of UnHackMe, PC will usually come on up.
Vista 32-bit, 4 GB.
Followed steps. Here are the logs:
MalwareBytes:
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org
Database version: 5937
Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.19019
3/2/2011 4:32:53 PM
mbam-log-2011-03-02 (16-32-53).txt
Scan type: Quick scan
Objects scanned: 158163
Time elapsed: 5 minute(s), 58 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
GMER log
GMER 1.0.15.15530 - http://www.gmer.net
Rootkit quick scan 2011-03-02 15:39:43
Windows 6.0.6002 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 ST950032 rev.0002
Running: 053xeihi.exe; Driver: C:\Users\Dave\AppData\Local\Temp\uxryipod.sys
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\Ntfs \Ntfs TfFsMon.sys (ThreatFire Filesystem Monitor/PC Tools)
AttachedDevice \FileSystem\Ntfs \Ntfs AVGIDSFilter.Sys (IDS Application Activity Monitor Filter Driver./AVG Technologies CZ, s.r.o. )
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\fastfat \Fat AVGIDSFilter.Sys (IDS Application Activity Monitor Filter Driver./AVG Technologies CZ, s.r.o. )
AttachedDevice \Driver\tdx \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\tdx \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\tdx \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\tdx \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (Kernel Mode Driver Framework Runtime/Microsoft Corporation)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys (Kernel Mode Driver Framework Runtime/Microsoft Corporation)
---- EOF - GMER 1.0.15 ----
Attach.txt:
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_10-12-12.02)
Microsoft® Windows Vista™ Home Premium
Boot Device: \Device\HarddiskVolume1
Install Date: 2/26/2011 1:00:56 PM
System Uptime: 3/2/2011 3:40:33 PM (3 hours ago)
Motherboard: Quanta | | 361B
Processor: Intel(R) Core(TM)2 Duo CPU P8600 @ 2.40GHz | CPU | 2401/1066mhz
==== Disk Partitions =========================
C: is FIXED (NTFS) - 457 GiB total, 338.537 GiB free.
D: is FIXED (NTFS) - 9 GiB total, 1.56 GiB free.
E: is CDROM ()
F: is Removable
==== Disabled Device Manager Items =============
==== System Restore Points ===================
No restore point in system.
==== Installed Programs ======================
7-Zip 4.65
Adobe Flash Player 10 Plugin
Adobe Flash Player ActiveX
Adobe Reader 8.1.2
Adobe Shockwave Player
AVG 2011
Cards_Calendar_OrderGift_DoMorePlugout
CyberLink DVD Suite
CyberLink YouCam
DigitalPersona Personal 4.11
doPDF 6.2 printer
ESU for Microsoft Vista
Hewlett-Packard Active Check for Health Check
Hewlett-Packard Asset Agent for Health Check
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
HP Active Support Library
HP Customer Experience Enhancements
HP Doc Viewer
HP Help and Support
HP Integrated Module with Bluetooth wireless technology 6.0.1.6204
HP MediaSmart DVD
HP MediaSmart Music/Photo/Video
HP MediaSmart SmartMenu
HP MediaSmart TV
HP Photosmart Essential 2.5
HP Photosmart Essential 3.0
HP Quick Launch Buttons 6.40 H2
HP Smart Web Printing
HP Total Care Advisor
HP Update
HP User Guides 0115
HP Wireless Assistant
HPNetworkAssistant
HPPhotoSmartPhotobookWebPack1
HPTCSSetup
IDT Audio
Intel® Matrix Storage Manager
Java Auto Updater
Java(TM) 6 Update 24
Java(TM) 6 Update 6
JMicron JMB38X Flash Media Controller
LabelPrint
Malwarebytes' Anti-Malware
Microsoft .NET Framework 3.5 SP1
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Mozilla Firefox (3.6.14)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
muvee autoProducer 6.1
NVIDIA Drivers
Panda Cloud Antivirus
Panda Identity Protect 3.0.44
Panda Security Toolbar
Panda Security URL Filtering
PhotoNow!
Power2Go
PowerDirector
ProtectSmart Hard Drive Protection
PSSWCORE
QuickPlay SlingPlayer 0.4.6
Realtek 8169 8168 8101E 8102E Ethernet Driver
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)
Slingbox Flash Tour
SlingPlayer
Synaptics Pointing Device Driver
ThreatFire
UnHackMe 5.99 release
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Validity Sensors software
VideoToolkit01
VLC media player 1.1.7
Windows Driver Package - ENE (enecir) HIDClass (04/29/2008 2.5.0.0)
Yahoo! Toolbar
==== Event Viewer Messages From Past Week ========
3/2/2011 3:36:31 PM, Error: disk [11] - The driver detected a controller error on \Device\Harddisk1\DR1.
3/2/2011 2:51:49 PM, Error: Service Control Manager [7000] - The Parallel port driver service failed to start due to the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
3/2/2011 2:50:34 PM, Error: EventLog [6008] - The previous system shutdown at 2:42:16 PM on 3/2/2011 was unexpected.
3/2/2011 2:50:09 PM, Error: volsnap [27] - The shadow copies of volume C: were aborted during detection because a critical control file could not be opened.
3/2/2011 2:46:38 PM, Error: volsnap [14] - The shadow copies of volume C: were aborted because of an IO failure on volume C:.
3/2/2011 2:40:25 PM, Error: Service Control Manager [7034] - The NVIDIA Display Driver Service service terminated unexpectedly. It has done this 1 time(s).
3/2/2011 12:39:26 PM, Error: EventLog [6008] - The previous system shutdown at 12:09:14 PM on 3/2/2011 was unexpected.
3/2/2011 12:04:35 PM, Error: EventLog [6008] - The previous system shutdown at 11:37:09 AM on 3/2/2011 was unexpected.
3/2/2011 11:21:12 AM, Error: EventLog [6008] - The previous system shutdown at 11:15:29 AM on 3/2/2011 was unexpected.
3/1/2011 9:36:41 AM, Error: EventLog [6008] - The previous system shutdown at 8:36:19 AM on 3/1/2011 was unexpected.
3/1/2011 8:50:39 PM, Error: EventLog [6008] - The previous system shutdown at 7:53:12 PM on 3/1/2011 was unexpected.
3/1/2011 7:51:15 PM, Error: Ntfs [55] - The file system structure on the disk is corrupt and unusable. Please run the chkdsk utility on the volume C:.
3/1/2011 7:51:15 PM, Error: Ntfs [55] - The file system structure on the disk is corrupt and unusable. Please run the chkdsk utility on the volume \Device\HarddiskVolume1.
3/1/2011 7:47:26 PM, Error: Service Control Manager [7031] - The Windows Search service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service.
3/1/2011 7:46:44 PM, Error: Service Control Manager [7024] - The Windows Search service terminated with service-specific error 2147749155 (0x80040D23).
3/1/2011 7:45:27 PM, Error: EventLog [6008] - The previous system shutdown at 10:23:28 AM on 3/1/2011 was unexpected.
3/1/2011 7:31:39 AM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Eventlog service.
3/1/2011 7:26:09 AM, Error: Service Control Manager [7034] - The Program Compatibility Assistant Service service terminated unexpectedly. It has done this 16 time(s).
3/1/2011 7:26:09 AM, Error: Service Control Manager [7034] - The Network Connections service terminated unexpectedly. It has done this 14 time(s).
3/1/2011 7:26:09 AM, Error: Service Control Manager [7031] - The WLAN AutoConfig service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
3/1/2011 7:26:09 AM, Error: Service Control Manager [7031] - The Windows Audio Endpoint Builder service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
3/1/2011 7:26:04 AM, Error: Service Control Manager [7034] - The KtmRm for Distributed Transaction Coordinator service terminated unexpectedly. It has done this 3 time(s).
3/1/2011 7:26:04 AM, Error: Service Control Manager [7034] - The DNS Client service terminated unexpectedly. It has done this 3 time(s).
3/1/2011 7:26:04 AM, Error: Service Control Manager [7034] - The Cryptographic Services service terminated unexpectedly. It has done this 6 time(s).
3/1/2011 7:22:54 AM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the PlugPlay service.
3/1/2011 10:07:33 AM, Error: EventLog [6008] - The previous system shutdown at 9:44:25 AM on 3/1/2011 was unexpected.
2/28/2011 11:58:32 PM, Error: Service Control Manager [7034] - The Windows Firewall service terminated unexpectedly. It has done this 3 time(s).
2/28/2011 11:58:32 PM, Error: Service Control Manager [7034] - The Diagnostic Policy Service service terminated unexpectedly. It has done this 3 time(s).
2/28/2011 11:58:32 PM, Error: Service Control Manager [7034] - The Base Filtering Engine service terminated unexpectedly. It has done this 3 time(s).
2/28/2011 11:57:48 PM, Error: Service Control Manager [7034] - The Program Compatibility Assistant Service service terminated unexpectedly. It has done this 15 time(s).
2/28/2011 11:57:48 PM, Error: Service Control Manager [7034] - The Network Connections service terminated unexpectedly. It has done this 13 time(s).
2/28/2011 11:57:48 PM, Error: Service Control Manager [7034] - The Diagnostic System Host service terminated unexpectedly. It has done this 7 time(s).
2/28/2011 11:56:35 PM, Error: Service Control Manager [7034] - The Program Compatibility Assistant Service service terminated unexpectedly. It has done this 14 time(s).
2/28/2011 11:56:35 PM, Error: Service Control Manager [7034] - The Network Connections service terminated unexpectedly. It has done this 12 time(s).
2/28/2011 11:56:14 PM, Error: Service Control Manager [7034] - The Program Compatibility Assistant Service service terminated unexpectedly. It has done this 13 time(s).
2/28/2011 11:54:55 PM, Error: Service Control Manager [7034] - The Program Compatibility Assistant Service service terminated unexpectedly. It has done this 12 time(s).
2/28/2011 11:54:55 PM, Error: Service Control Manager [7034] - The Network Connections service terminated unexpectedly. It has done this 11 time(s).
2/28/2011 11:54:55 PM, Error: Service Control Manager [7031] - The WLAN AutoConfig service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 300000 milliseconds: Restart the service.
2/28/2011 11:47:14 PM, Error: Service Control Manager [7034] - The Program Compatibility Assistant Service service terminated unexpectedly. It has done this 9 time(s).
2/28/2011 11:47:14 PM, Error: Service Control Manager [7034] - The Network Connections service terminated unexpectedly. It has done this 8 time(s).
2/28/2011 11:47:14 PM, Error: Service Control Manager [7034] - The Diagnostic System Host service terminated unexpectedly. It has done this 4 time(s).
2/28/2011 11:44:32 PM, Error: Service Control Manager [7034] - The Program Compatibility Assistant Service service terminated unexpectedly. It has done this 8 time(s).
2/28/2011 11:44:32 PM, Error: Service Control Manager [7034] - The Network Connections service terminated unexpectedly. It has done this 7 time(s).
2/28/2011 11:44:32 PM, Error: Service Control Manager [7034] - The Diagnostic System Host service terminated unexpectedly. It has done this 3 time(s).
2/28/2011 11:42:10 PM, Error: Service Control Manager [7034] - The Windows Driver Foundation - User-mode Driver Framework service terminated unexpectedly. It has done this 3 time(s).
2/28/2011 11:42:10 PM, Error: Service Control Manager [7034] - The Tablet PC Input Service service terminated unexpectedly. It has done this 3 time(s).
2/28/2011 11:42:10 PM, Error: Service Control Manager [7034] - The Program Compatibility Assistant Service service terminated unexpectedly. It has done this 7 time(s).
2/28/2011 11:42:10 PM, Error: Service Control Manager [7034] - The Portable Device Enumerator Service service terminated unexpectedly. It has done this 3 time(s).
2/28/2011 11:42:10 PM, Error: Service Control Manager [7034] - The Network Connections service terminated unexpectedly. It has done this 6 time(s).
2/28/2011 11:42:10 PM, Error: Service Control Manager [7034] - The Human Interface Device Access service terminated unexpectedly. It has done this 3 time(s).
2/28/2011 11:42:10 PM, Error: Service Control Manager [7034] - The Distributed Link Tracking Client service terminated unexpectedly. It has done this 3 time(s).
2/28/2011 11:42:10 PM, Error: Service Control Manager [7034] - The Diagnostic System Host service terminated unexpectedly. It has done this 2 time(s).
2/28/2011 11:42:10 PM, Error: Service Control Manager [7034] - The Desktop Window Manager Session Manager service terminated unexpectedly. It has done this 3 time(s).
2/28/2011 11:40:23 PM, Error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Telephony service, but this action failed with the following error: An instance of the service is already running.
2/28/2011 11:35:46 PM, Error: Service Control Manager [7034] - The Superfetch service terminated unexpectedly. It has done this 3 time(s).
2/28/2011 11:35:46 PM, Error: Service Control Manager [7034] - The ReadyBoost service terminated unexpectedly. It has done this 3 time(s).
2/28/2011 11:35:46 PM, Error: Service Control Manager [7034] - The Program Compatibility Assistant Service service terminated unexpectedly. It has done this 6 time(s).
2/28/2011 11:35:46 PM, Error: Service Control Manager [7034] - The Network Connections service terminated unexpectedly. It has done this 5 time(s).
2/28/2011 11:35:46 PM, Error: Service Control Manager [7034] - The Diagnostic System Host service terminated unexpectedly. It has done this 1 time(s).
2/28/2011 11:35:46 PM, Error: Service Control Manager [7031] - The Windows Driver Foundation - User-mode Driver Framework service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 300000 milliseconds: Restart the service.
2/28/2011 11:35:46 PM, Error: Service Control Manager [7031] - The Portable Device Enumerator Service service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 300000 milliseconds: Restart the service.
2/28/2011 11:35:46 PM, Error: Service Control Manager [7031] - The Human Interface Device Access service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 300000 milliseconds: Restart the service.
2/28/2011 11:35:46 PM, Error: Service Control Manager [7031] - The Distributed Link Tracking Client service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 300000 milliseconds: Restart the service.
2/28/2011 11:35:46 PM, Error: Service Control Manager [7031] - The Desktop Window Manager Session Manager service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 300000 milliseconds: Restart the service.
2/28/2011 11:35:32 PM, Error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Windows Audio Endpoint Builder service, but this action failed with the following error: An instance of the service is already running.
2/28/2011 11:35:26 PM, Error: Service Control Manager [7034] - The Windows Search service terminated unexpectedly. It has done this 3 time(s).
2/28/2011 11:35:26 PM, Error: Service Control Manager [7034] - The Cryptographic Services service terminated unexpectedly. It has done this 4 time(s).
2/28/2011 11:35:26 PM, Error: Service Control Manager [7031] - The Telephony service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 300000 milliseconds: Restart the service.
2/28/2011 11:35:26 PM, Error: Service Control Manager [7031] - The KtmRm for Distributed Transaction Coordinator service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 1000 milliseconds: Restart the service.
2/28/2011 11:35:01 PM, Error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Base Filtering Engine service, but this action failed with the following error: An instance of the service is already running.
2/28/2011 11:34:58 PM, Error: Service Control Manager [7034] - The Program Compatibility Assistant Service service terminated unexpectedly. It has done this 5 time(s).
2/28/2011 11:34:58 PM, Error: Service Control Manager [7034] - The Network Location Awareness service terminated unexpectedly. It has done this 3 time(s).
2/28/2011 11:34:58 PM, Error: Service Control Manager [7034] - The Network Connections service terminated unexpectedly. It has done this 4 time(s).
2/28/2011 11:34:58 PM, Error: Service Control Manager [7034] - The Cryptographic Services service terminated unexpectedly. It has done this 3 time(s).
2/28/2011 11:34:58 PM, Error: Service Control Manager [7031] - The Terminal Services service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
2/28/2011 11:34:32 PM, Error: Service Control Manager [7034] - The Program Compatibility Assistant Service service terminated unexpectedly. It has done this 4 time(s).
2/28/2011 11:34:32 PM, Error: Service Control Manager [7034] - The Network Connections service terminated unexpectedly. It has done this 3 time(s).
2/28/2011 11:34:32 PM, Error: Service Control Manager [7034] - The Cryptographic Services service terminated unexpectedly. It has done this 2 time(s).
2/28/2011 11:34:32 PM, Error: Service Control Manager [7031] - The Telephony service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
2/28/2011 11:34:32 PM, Error: Service Control Manager [7031] - The Tablet PC Input Service service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
2/28/2011 11:34:32 PM, Error: Service Control Manager [7031] - The Superfetch service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
2/28/2011 11:34:32 PM, Error: Service Control Manager [7031] - The ReadyBoost service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
2/28/2011 11:34:32 PM, Error: Service Control Manager [7031] - The Network Location Awareness service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 100 milliseconds: Restart the service.
2/28/2011 11:34:09 PM, Error: Service Control Manager [7034] - The Program Compatibility Assistant Service service terminated unexpectedly. It has done this 3 time(s).
2/28/2011 11:34:09 PM, Error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Network Connections service, but this action failed with the following error: An instance of the service is already running.
2/28/2011 11:34:09 PM, Error: Service Control Manager [7031] - The Windows Search service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service.
2/28/2011 11:34:09 PM, Error: Service Control Manager [7031] - The Network Connections service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 100 milliseconds: Restart the service.
2/28/2011 11:34:09 PM, Error: Service Control Manager [7001] - The Windows Audio service depends on the Windows Audio Endpoint Builder service which failed to start because of the following error: The operation completed successfully.
2/28/2011 11:32:15 PM, Error: Service Control Manager [7022] - The Panda Cloud Antivirus Service service hung on starting.
2/28/2011 11:32:14 PM, Error: Service Control Manager [7022] - The AVGIDSAgent service hung on starting.
2/28/2011 11:26:08 PM, Error: EventLog [6008] - The previous system shutdown at 11:16:52 PM on 2/28/2011 was unexpected.
2/28/2011 1:36:27 PM, Error: Service Control Manager [7030] - The Panda Cloud Antivirus Service service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.
2/27/2011 9:23:58 PM, Error: Microsoft-Windows-WindowsUpdateClient [20] - Installation Failure: Windows failed to install the following update with error 0x80240016: Synaptics - Input - Synaptics PS/2 Port TouchPad.
2/27/2011 6:27:32 PM, Error: Microsoft-Windows-Service Pack Installer [6] - The Service Pack cannot be installed when the computer is running on battery power.
2/27/2011 5:03:17 PM, Error: Service Control Manager [7030] - The ThreatFire service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.
==== End Of File ===========================
DDS.txt in next post