laurag98107
Posts: 6 +0
My two home computers have a virus that I really do not know how to deal with - the virus disables the automatic updates, turns off system restore (by "group policy", which I don't know how to change), and removes all of the anti-virus components (avast on one and avg on the other). When I re-install the anti-virus, it acts like it's installing ok, but won't execute. I followed the 8 steps on one of them. I finally got avira to install and run on it. It found 14 viruses, which it quarantined. Malwarebytes installs but won't run, so I don't have that log to include, but I have posted/attached the other three files.
The second computer wasn't as badly infected (I thought) - I had gotten avast to re-install and execute on it, although I could never get Malwarebytes to run. That was about a week ago. Last night I discovered avast was completely disabled (displayed "unsecured"), so I followed avast's tech support's instructions. Step 2 is to make sure the avast program is enabled in the windows services - it's not listed at all. I copied the services screen, the 3 event logs,but that's as far as I got with that one.
What can I do to protect my computers from a virus that disables my antivirus programs??? Both were running fully functional, current antivirus programs when this happened.
Here are the 3 files I got for the first computer:
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-07-03 11:18:59
Windows 5.1.2600 Service Pack 2
Running: fdnncu31.exe; Driver: C:\DOCUME~1\lg\LOCALS~1\Temp\pxtdapoc.sys
---- System - GMER 1.0.15 ----
SSDT BA7EE64E ZwCreateKey
SSDT BA7EE644 ZwCreateThread
SSDT BA7EE653 ZwDeleteKey
SSDT BA7EE65D ZwDeleteValueKey
SSDT BA7EE662 ZwLoadKey
SSDT BA7EE630 ZwOpenProcess
SSDT BA7EE635 ZwOpenThread
SSDT BA7EE66C ZwReplaceKey
SSDT BA7EE667 ZwRestoreKey
SSDT BA7EE658 ZwSetValueKey
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\Fastfat \Fat fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
---- EOF - GMER 1.0.15 ----
DDS (Ver_10-03-17.01) - NTFSx86
Run by lg at 18:37:39.76 on Mon 07/05/2010
Internet Explorer: 6.0.2900.2180 BrowserJavaVersion: 1.6.0_11
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2005.1625 [GMT -7:00]
AV: AntiVir Desktop *On-access scanning enabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
svchost.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\CyberLink DVD Solution\Multimedia Launcher\PowerBar.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\lg\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
mWinlogon: Taskman=c:\recycler\s-1-5-21-0243556031-888888379-781863308-1451\games.exe
uWinlogon: Shell=explorer.exe,c:\recycler\s-1-5-21-0243556031-888888379-781863308-1451\games.exe
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File
uRun: [PowerBar] "c:\program files\cyberlink dvd solution\multimedia launcher\PowerBar.exe" /AtBootTime
uRun: [games] c:\recycler\s-1-5-21-0243556031-888888379-781863308-1451\games.exe
mRun: [conime.exe] conime.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [SoundMAXPnP] c:\program files\analog devices\core\smax4pnp.exe
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
dRun: [games] c:\recycler\s-1-5-21-0243556031-888888379-781863308-1451\games.exe
dRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
IE: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZKfox000
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\micros~3\INetRepl.dll
IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\micros~3\INetRepl.dll
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL
Notify: igfxcui - igfxdev.dll
IFEO: a2guard.exe - ntsd -d
IFEO: a2service.exe - ntsd -d
IFEO: a2start.exe - ntsd -d
IFEO: Ad-Aware.exe - ntsd -d
IFEO: Ad-AwareAdmin.exe - ntsd -d
Note: multiple IFEO entries found. Please refer to Attach.txt
Hosts: 156.250.52.182 msnfix.changelog.fr
Hosts: 156.250.52.182 www.incodesolutions.com
Hosts: 156.250.52.182 virusinfo.prevx.com
Hosts: 156.250.52.182 download.bleepingcomputer.com
Hosts: 156.250.52.182 www.dazhizhu.cn
Note: multiple HOSTS entries found. Please refer to Attach.txt
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\lg\applic~1\mozilla\firefox\profiles\qakz3kum.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/firefox?client=firefox-a&rls=org.mozilla:en-US
fficial
FF - plugin: c:\progra~1\palm\packag~1\NPInstal.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
============= SERVICES / DRIVERS ===============
R1 avgio;avgio;c:\program files\avira\antivir desktop\avgio.sys [2010-7-2 11608]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\avira\antivir desktop\sched.exe [2010-7-2 135336]
R2 AntiVirService;Avira AntiVir Guard;c:\program files\avira\antivir desktop\avguard.exe [2010-7-2 267432]
R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2010-7-2 60936]
R2 FreeAgentGoNext Service;Seagate Service;c:\program files\seagate\seagatemanager\sync\FreeAgentService.exe [2008-10-28 156968]
R3 ngrpci;NETGEAR FA310TX Fast Ethernet Adapter Driver;c:\windows\system32\drivers\Ngrpci.sys [2010-6-29 32840]
S3 AIDA32Driver;AIDA32Driver;c:\program files\aida32\aida32.sys [2004-2-23 3584]
=============== Created Last 30 ================
2010-07-03 13:00:40 0 d-----w- c:\program files\MSXML 4.0
2010-07-03 07:43:26 0 d-----w- c:\windows\system32\CatRoot_bak
2010-07-03 07:35:56 272128 -c----w- c:\windows\system32\dllcache\bthport.sys
2010-07-03 07:35:56 272128 ------w- c:\windows\system32\drivers\bthport.sys
2010-07-03 07:31:16 454016 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2010-07-03 07:24:35 0 dc-h--w- c:\docume~1\alluse~1\applic~1\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}
2010-07-03 07:24:24 0 d-----w- c:\program files\Lavasoft
2010-07-03 07:17:36 2186880 -c----w- c:\windows\system32\dllcache\ntoskrnl.exe
2010-07-03 07:17:36 2143744 -c----w- c:\windows\system32\dllcache\ntkrnlmp.exe
2010-07-03 07:17:35 2063744 -c----w- c:\windows\system32\dllcache\ntkrnlpa.exe
2010-07-03 07:17:35 2021888 -c----w- c:\windows\system32\dllcache\ntkrpamp.exe
2010-07-03 07:13:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-07-03 07:13:53 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-07-03 07:13:53 0 d-----w- c:\docume~1\alluse~1\applic~1\Malwarebytes
2010-07-03 07:13:52 0 d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-07-03 07:06:44 0 d-----w- c:\windows\system32\PreInstall
2010-07-03 05:39:44 0 d-----w- c:\windows\system32\NtmsData
2010-07-03 05:39:30 0 d-----w- c:\docume~1\lg\applic~1\Avira
2010-07-03 05:33:52 0 d-----w- c:\windows\system32\SoftwareDistribution
2010-07-03 05:29:13 60936 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2010-07-03 05:29:12 0 d-----w- c:\program files\Avira
2010-07-03 05:29:12 0 d-----w- c:\docume~1\alluse~1\applic~1\Avira
2010-07-01 04:02:57 0 d-----w- c:\program files\SpywareBlaster
2010-06-30 05:44:59 94720 -c--a-w- c:\windows\system32\dllcache\imekr61.ime
2010-06-30 05:42:53 488 ---ha-r- c:\windows\system32\logonui.exe.manifest
2010-06-30 05:42:49 749 ---ha-r- c:\windows\WindowsShell.Manifest
2010-06-30 05:42:49 749 ---ha-r- c:\windows\system32\wuaucpl.cpl.manifest
2010-06-30 05:42:49 749 ---ha-r- c:\windows\system32\sapi.cpl.manifest
2010-06-30 05:42:49 749 ---ha-r- c:\windows\system32\nwc.cpl.manifest
2010-06-30 05:42:49 749 ---ha-r- c:\windows\system32\ncpa.cpl.manifest
2010-06-30 05:38:33 32840 ----a-w- c:\windows\system32\drivers\Ngrpci.sys
2010-06-25 01:37:13 0 d-----w- c:\docume~1\lg\applic~1\AVG8
2010-06-21 23:06:59 0 d-----w- c:\docume~1\alluse~1\applic~1\Alwil Software
2010-06-21 02:50:05 0 d--h--w- c:\windows\system32\GroupPolicy
2010-06-11 02:06:50 100800 ----a-w- c:\docume~1\lg\applic~1\GDIPFONTCACHEV1.DAT
2010-06-08 04:29:16 0 d-----w- c:\docume~1\lg\applic~1\GlarySoft
==================== Find3M ====================
2010-06-30 05:42:06 22720 ----a-w- c:\windows\system32\emptyregdb.dat
2010-05-02 05:56:34 1850880 ----a-w- c:\windows\system32\win32k.sys
2010-04-20 05:51:20 285696 ----a-w- c:\windows\system32\atmfd.dll
2010-04-16 15:36:49 662016 ----a-w- c:\windows\system32\wininet.dll
2010-04-16 15:36:45 81920 ----a-w- c:\windows\system32\ieencode.dll
2004-03-11 20:27:22 40960 ----a-w- c:\program files\Uninstall_CDS.exe
============= FINISH: 18:37:59.26 ===============
Thank you for your help,
Laura
The second computer wasn't as badly infected (I thought) - I had gotten avast to re-install and execute on it, although I could never get Malwarebytes to run. That was about a week ago. Last night I discovered avast was completely disabled (displayed "unsecured"), so I followed avast's tech support's instructions. Step 2 is to make sure the avast program is enabled in the windows services - it's not listed at all. I copied the services screen, the 3 event logs,but that's as far as I got with that one.
What can I do to protect my computers from a virus that disables my antivirus programs??? Both were running fully functional, current antivirus programs when this happened.
Here are the 3 files I got for the first computer:
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-07-03 11:18:59
Windows 5.1.2600 Service Pack 2
Running: fdnncu31.exe; Driver: C:\DOCUME~1\lg\LOCALS~1\Temp\pxtdapoc.sys
---- System - GMER 1.0.15 ----
SSDT BA7EE64E ZwCreateKey
SSDT BA7EE644 ZwCreateThread
SSDT BA7EE653 ZwDeleteKey
SSDT BA7EE65D ZwDeleteValueKey
SSDT BA7EE662 ZwLoadKey
SSDT BA7EE630 ZwOpenProcess
SSDT BA7EE635 ZwOpenThread
SSDT BA7EE66C ZwReplaceKey
SSDT BA7EE667 ZwRestoreKey
SSDT BA7EE658 ZwSetValueKey
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\Fastfat \Fat fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
---- EOF - GMER 1.0.15 ----
DDS (Ver_10-03-17.01) - NTFSx86
Run by lg at 18:37:39.76 on Mon 07/05/2010
Internet Explorer: 6.0.2900.2180 BrowserJavaVersion: 1.6.0_11
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2005.1625 [GMT -7:00]
AV: AntiVir Desktop *On-access scanning enabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
svchost.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\CyberLink DVD Solution\Multimedia Launcher\PowerBar.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\lg\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
mWinlogon: Taskman=c:\recycler\s-1-5-21-0243556031-888888379-781863308-1451\games.exe
uWinlogon: Shell=explorer.exe,c:\recycler\s-1-5-21-0243556031-888888379-781863308-1451\games.exe
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File
uRun: [PowerBar] "c:\program files\cyberlink dvd solution\multimedia launcher\PowerBar.exe" /AtBootTime
uRun: [games] c:\recycler\s-1-5-21-0243556031-888888379-781863308-1451\games.exe
mRun: [conime.exe] conime.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [SoundMAXPnP] c:\program files\analog devices\core\smax4pnp.exe
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
dRun: [games] c:\recycler\s-1-5-21-0243556031-888888379-781863308-1451\games.exe
dRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
IE: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZKfox000
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\micros~3\INetRepl.dll
IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\micros~3\INetRepl.dll
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL
Notify: igfxcui - igfxdev.dll
IFEO: a2guard.exe - ntsd -d
IFEO: a2service.exe - ntsd -d
IFEO: a2start.exe - ntsd -d
IFEO: Ad-Aware.exe - ntsd -d
IFEO: Ad-AwareAdmin.exe - ntsd -d
Note: multiple IFEO entries found. Please refer to Attach.txt
Hosts: 156.250.52.182 msnfix.changelog.fr
Hosts: 156.250.52.182 www.incodesolutions.com
Hosts: 156.250.52.182 virusinfo.prevx.com
Hosts: 156.250.52.182 download.bleepingcomputer.com
Hosts: 156.250.52.182 www.dazhizhu.cn
Note: multiple HOSTS entries found. Please refer to Attach.txt
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\lg\applic~1\mozilla\firefox\profiles\qakz3kum.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/firefox?client=firefox-a&rls=org.mozilla:en-US
FF - plugin: c:\progra~1\palm\packag~1\NPInstal.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
============= SERVICES / DRIVERS ===============
R1 avgio;avgio;c:\program files\avira\antivir desktop\avgio.sys [2010-7-2 11608]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\avira\antivir desktop\sched.exe [2010-7-2 135336]
R2 AntiVirService;Avira AntiVir Guard;c:\program files\avira\antivir desktop\avguard.exe [2010-7-2 267432]
R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2010-7-2 60936]
R2 FreeAgentGoNext Service;Seagate Service;c:\program files\seagate\seagatemanager\sync\FreeAgentService.exe [2008-10-28 156968]
R3 ngrpci;NETGEAR FA310TX Fast Ethernet Adapter Driver;c:\windows\system32\drivers\Ngrpci.sys [2010-6-29 32840]
S3 AIDA32Driver;AIDA32Driver;c:\program files\aida32\aida32.sys [2004-2-23 3584]
=============== Created Last 30 ================
2010-07-03 13:00:40 0 d-----w- c:\program files\MSXML 4.0
2010-07-03 07:43:26 0 d-----w- c:\windows\system32\CatRoot_bak
2010-07-03 07:35:56 272128 -c----w- c:\windows\system32\dllcache\bthport.sys
2010-07-03 07:35:56 272128 ------w- c:\windows\system32\drivers\bthport.sys
2010-07-03 07:31:16 454016 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2010-07-03 07:24:35 0 dc-h--w- c:\docume~1\alluse~1\applic~1\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}
2010-07-03 07:24:24 0 d-----w- c:\program files\Lavasoft
2010-07-03 07:17:36 2186880 -c----w- c:\windows\system32\dllcache\ntoskrnl.exe
2010-07-03 07:17:36 2143744 -c----w- c:\windows\system32\dllcache\ntkrnlmp.exe
2010-07-03 07:17:35 2063744 -c----w- c:\windows\system32\dllcache\ntkrnlpa.exe
2010-07-03 07:17:35 2021888 -c----w- c:\windows\system32\dllcache\ntkrpamp.exe
2010-07-03 07:13:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-07-03 07:13:53 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-07-03 07:13:53 0 d-----w- c:\docume~1\alluse~1\applic~1\Malwarebytes
2010-07-03 07:13:52 0 d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-07-03 07:06:44 0 d-----w- c:\windows\system32\PreInstall
2010-07-03 05:39:44 0 d-----w- c:\windows\system32\NtmsData
2010-07-03 05:39:30 0 d-----w- c:\docume~1\lg\applic~1\Avira
2010-07-03 05:33:52 0 d-----w- c:\windows\system32\SoftwareDistribution
2010-07-03 05:29:13 60936 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2010-07-03 05:29:12 0 d-----w- c:\program files\Avira
2010-07-03 05:29:12 0 d-----w- c:\docume~1\alluse~1\applic~1\Avira
2010-07-01 04:02:57 0 d-----w- c:\program files\SpywareBlaster
2010-06-30 05:44:59 94720 -c--a-w- c:\windows\system32\dllcache\imekr61.ime
2010-06-30 05:42:53 488 ---ha-r- c:\windows\system32\logonui.exe.manifest
2010-06-30 05:42:49 749 ---ha-r- c:\windows\WindowsShell.Manifest
2010-06-30 05:42:49 749 ---ha-r- c:\windows\system32\wuaucpl.cpl.manifest
2010-06-30 05:42:49 749 ---ha-r- c:\windows\system32\sapi.cpl.manifest
2010-06-30 05:42:49 749 ---ha-r- c:\windows\system32\nwc.cpl.manifest
2010-06-30 05:42:49 749 ---ha-r- c:\windows\system32\ncpa.cpl.manifest
2010-06-30 05:38:33 32840 ----a-w- c:\windows\system32\drivers\Ngrpci.sys
2010-06-25 01:37:13 0 d-----w- c:\docume~1\lg\applic~1\AVG8
2010-06-21 23:06:59 0 d-----w- c:\docume~1\alluse~1\applic~1\Alwil Software
2010-06-21 02:50:05 0 d--h--w- c:\windows\system32\GroupPolicy
2010-06-11 02:06:50 100800 ----a-w- c:\docume~1\lg\applic~1\GDIPFONTCACHEV1.DAT
2010-06-08 04:29:16 0 d-----w- c:\docume~1\lg\applic~1\GlarySoft
==================== Find3M ====================
2010-06-30 05:42:06 22720 ----a-w- c:\windows\system32\emptyregdb.dat
2010-05-02 05:56:34 1850880 ----a-w- c:\windows\system32\win32k.sys
2010-04-20 05:51:20 285696 ----a-w- c:\windows\system32\atmfd.dll
2010-04-16 15:36:49 662016 ----a-w- c:\windows\system32\wininet.dll
2010-04-16 15:36:45 81920 ----a-w- c:\windows\system32\ieencode.dll
2004-03-11 20:27:22 40960 ----a-w- c:\program files\Uninstall_CDS.exe
============= FINISH: 18:37:59.26 ===============
Thank you for your help,
Laura