Solved What is ilhdxm.exe?

2016-04-18 06:16:05.887 Sophos Virus Removal Tool version 2.5.5
2016-04-18 06:16:05.887 Copyright (c) 2009-2014 Sophos Limited. All rights reserved.

2016-04-18 06:16:05.887 This tool will scan your computer for viruses and other threats. If it finds any, it will give you the option to remove them.

2016-04-18 06:16:05.887 Windows version 6.2 SP 0.0 build 9200 SM=0x300 PT=0x1 WOW64
2016-04-18 06:16:05.887 Checking for updates...
2016-04-18 06:16:05.895 Update progress: proxy server not available
2016-04-18 06:16:12.240 Option all = no
2016-04-18 06:16:12.240 Option recurse = yes
2016-04-18 06:16:12.240 Option archive = no
2016-04-18 06:16:12.240 Option service = yes
2016-04-18 06:16:12.240 Option confirm = yes
2016-04-18 06:16:12.240 Option sxl = yes
2016-04-18 06:16:12.241 Option max-data-age = 35
2016-04-18 06:16:12.241 Option EnableSafeClean = yes
2016-04-18 06:16:13.657 Option vdl-logging = yes
2016-04-18 06:16:13.659 Customer ID: 094260ca9b3af99f9d4a3909fc47a743
2016-04-18 06:16:13.659 Machine ID: fc7cd4e2ea454fcc8b2c9d5835b8d395
2016-04-18 06:16:13.659 Component SVRTcli.exe version 2.5.5
2016-04-18 06:16:13.660 Component control.dll version 2.5.5
2016-04-18 06:16:13.660 Component SVRTservice.exe version 2.5.5
2016-04-18 06:16:13.660 Component engine\osdp.dll version 1.44.1.2240
2016-04-18 06:16:13.660 Component engine\veex.dll version 3.64.0.2240
2016-04-18 06:16:13.660 Component engine\savi.dll version 9.0.0.2240
2016-04-18 06:16:13.661 Component rkdisk.dll version 1.5.30.0
2016-04-18 06:16:13.661 Version info: Product version 2.5.5
2016-04-18 06:16:13.661 Version info: Detection engine 3.64.0
2016-04-18 06:16:13.661 Version info: Detection data 5.25
2016-04-18 06:16:13.661 Version info: Build date 3/8/2016
2016-04-18 06:16:13.661 Version info: Data files added 360
2016-04-18 06:16:13.661 Version info: Last successful update (not yet updated)
2016-04-18 06:16:21.507 Downloading updates...
2016-04-18 06:16:21.509 Update progress: [I96736] Looking for package C1A903B2-E63E-483b-982D-04BB9C457C60 1.0
2016-04-18 06:16:21.509 Update progress: [I49502] Found supplement SAVIW32 LATEST
2016-04-18 06:16:21.509 Update progress: [I49502] Found supplement IDE526 LATEST
2016-04-18 06:16:21.509 Update progress: [I49502] Found supplement IDE527 LATEST
2016-04-18 06:16:21.509 Update progress: [I49502] Found supplement IDE528 LATEST
2016-04-18 06:16:21.509 Update progress: [I49502] Found supplement IDE529 LATEST
2016-04-18 06:16:21.509 Update progress: [I19463] Syncing product C1A903B2-E63E-483b-982D-04BB9C457C60 1
2016-04-18 06:16:21.509 Update progress: [I19463] Syncing product SAVIW32 68
2016-04-18 06:16:21.975 Update progress: [I19463] Syncing product IDE526 167
2016-04-18 06:16:22.377 Installing updates...
2016-04-18 06:16:22.980 Error level 1
2016-04-18 06:16:22.994 Update progress: [I19463] Syncing product IDE527 142
2016-04-18 06:16:22.994 Update progress: [I19463] Syncing product IDE528 54
2016-04-18 06:16:22.994 Update progress: [I19463] Syncing product IDE529 1
2016-04-18 06:16:26.616 Update successful
2016-04-18 06:16:33.077 Option all = no
2016-04-18 06:16:33.077 Option recurse = yes
2016-04-18 06:16:33.077 Option archive = no
2016-04-18 06:16:33.077 Option service = yes
2016-04-18 06:16:33.077 Option confirm = yes
2016-04-18 06:16:33.077 Option sxl = yes
2016-04-18 06:16:33.078 Option max-data-age = 35
2016-04-18 06:16:33.078 Option EnableSafeClean = yes
2016-04-18 06:16:33.474 Option vdl-logging = yes
2016-04-18 06:16:33.476 Customer ID: 094260ca9b3af99f9d4a3909fc47a743
2016-04-18 06:16:33.476 Machine ID: fc7cd4e2ea454fcc8b2c9d5835b8d395
2016-04-18 06:16:33.476 Component SVRTcli.exe version 2.5.5
2016-04-18 06:16:33.477 Component control.dll version 2.5.5
2016-04-18 06:16:33.477 Component SVRTservice.exe version 2.5.5
2016-04-18 06:16:33.477 Component engine\osdp.dll version 1.44.1.2240
2016-04-18 06:16:33.477 Component engine\veex.dll version 3.64.0.2240
2016-04-18 06:16:33.477 Component engine\savi.dll version 9.0.0.2240
2016-04-18 06:16:33.477 Component rkdisk.dll version 1.5.30.0
2016-04-18 06:16:33.478 Version info: Product version 2.5.5
2016-04-18 06:16:33.478 Version info: Detection engine 3.64.0
2016-04-18 06:16:33.478 Version info: Detection data 5.25
2016-04-18 06:16:33.478 Version info: Build date 3/8/2016
2016-04-18 06:16:33.478 Version info: Data files added 360
2016-04-18 06:16:33.478 Version info: Last successful update 4/18/2016 9:16:26 AM

2016-04-18 07:04:05.243 >>> Virus 'Mal/VMProtBad-A' found in file C:\Games\Hotline Miami 2 Wrong Number\steam_api.dll
2016-04-18 07:04:08.289 Could not open C:\hiberfil.sys
2016-04-18 07:08:35.065 Could not open C:\pagefile.sys
2016-04-18 07:43:29.305 Could not open C:\swapfile.sys
2016-04-18 07:43:29.352 Could not open C:\System Volume Information\{13244409-f6a5-11e5-82f4-000000005aad}{3808876b-c176-4e48-b7ae-04046e6cc752}
2016-04-18 07:43:29.352 Could not open C:\System Volume Information\{3808876b-c176-4e48-b7ae-04046e6cc752}
2016-04-18 07:43:29.352 Could not open C:\System Volume Information\{733d35eb-0077-11e6-82f6-000000005aad}{3808876b-c176-4e48-b7ae-04046e6cc752}
2016-04-18 07:43:29.352 Could not open C:\System Volume Information\{86c155d6-015b-11e6-82f7-000000005aad}{3808876b-c176-4e48-b7ae-04046e6cc752}
2016-04-18 07:43:29.353 Could not open C:\System Volume Information\{86eef92e-0315-11e6-82f7-000000005aad}{3808876b-c176-4e48-b7ae-04046e6cc752}
2016-04-18 07:43:29.353 Could not open C:\System Volume Information\{a87f03cd-f95b-11e5-82f5-000000005aad}{3808876b-c176-4e48-b7ae-04046e6cc752}
2016-04-18 07:48:13.275 Could not open C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Current Session
2016-04-18 07:48:13.276 Could not open C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Current Tabs
2016-04-18 07:48:13.439 Could not check C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\LOCK (virus scan failed)
2016-04-18 07:48:13.462 Could not check C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extension State\LOCK (virus scan failed)
2016-04-18 07:48:26.680 Could not check C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\File System\Origins\LOCK (virus scan failed)
2016-04-18 07:48:26.709 Could not check C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\GCM Store\LOCK (virus scan failed)
2016-04-18 07:48:26.843 Could not check C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\IndexedDB\https_docs.google.com_0.indexeddb.leveldb\LOCK (virus scan failed)
2016-04-18 07:48:27.596 Could not check C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local App Settings\bgkodfmeijboinjdegggmkbkjfiagaan\LOCK (virus scan failed)
2016-04-18 07:48:27.610 Could not check C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ghbmnnjooekpmoecnnnilnnbdlolhkhi\LOCK (virus scan failed)
2016-04-18 07:48:27.616 Could not check C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\nnckehldicaciogcbchegobnafnjkcne\LOCK (virus scan failed)
2016-04-18 07:48:35.050 Could not check C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Service Worker\Database\LOCK (virus scan failed)
2016-04-18 07:48:35.111 Could not check C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Session Storage\LOCK (virus scan failed)
2016-04-18 07:48:35.326 Could not check C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\bgkodfmeijboinjdegggmkbkjfiagaan\E597E9D0BAF6\File System\Origins\LOCK (virus scan failed)
2016-04-18 07:48:35.370 Could not check C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\bgkodfmeijboinjdegggmkbkjfiagaan\E597E9D0BAF6\IndexedDB\https_web.whatsapp.com_0.indexeddb.leveldb\LOCK (virus scan failed)
2016-04-18 07:48:35.479 Could not check C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\bgkodfmeijboinjdegggmkbkjfiagaan\E597E9D0BAF6\Service Worker\Database\LOCK (virus scan failed)
2016-04-18 07:48:35.536 Could not check C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\boadgeojelhgndaghljhdicfkmllpafd\LOCK (virus scan failed)
2016-04-18 07:48:35.542 Could not check C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\dliochdbjfkdbacpmhlcpmleaejidimm\LOCK (virus scan failed)
2016-04-18 07:48:35.546 Could not check C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\gmlllbghnfkpflemihljekbapjopfjik\LOCK (virus scan failed)
2016-04-18 07:48:35.582 Could not check C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\jlpkojjdgbllmedoapgfodplfhcbnbpn\LOCK (virus scan failed)
2016-04-18 07:48:35.606 Could not check C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\mdapmeleikeppmfgadilffngabfpibok\LOCK (virus scan failed)
2016-04-18 08:01:28.137 Could not open C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb
2016-04-18 08:01:28.139 Could not open C:\Windows\System32\catroot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb
2016-04-18 08:01:37.233 Could not open C:\Windows\System32\config\BBI
2016-04-18 08:01:37.284 Could not open C:\Windows\System32\config\RegBack\DEFAULT
2016-04-18 08:01:37.286 Could not open C:\Windows\System32\config\RegBack\SAM
2016-04-18 08:01:37.288 Could not open C:\Windows\System32\config\RegBack\SECURITY
2016-04-18 08:01:37.292 Could not open C:\Windows\System32\config\RegBack\SOFTWARE
2016-04-18 08:01:37.293 Could not open C:\Windows\System32\config\RegBack\SYSTEM
2016-04-18 09:35:11.475 >>> Virus 'Mal/Generic-S' found in file D:\Games\DiRT Rally\steamclient.dll
2016-04-18 09:35:11.475 >>> Virus 'Mal/Generic-S' found in file D:\Games\DiRT Rally\steamclient.dll
2016-04-18 09:35:11.475 >>> Virus 'Mal/Generic-S' found in file D:\Games\DiRT Rally\steamclient.dll
2016-04-18 09:35:11.475 >>> Virus 'Mal/Generic-S' found in file D:\Games\DiRT Rally\steamclient.dll
2016-04-18 09:35:11.475 >>> Virus 'Mal/Generic-S' found in file D:\Games\DiRT Rally\steamclient.dll
2016-04-18 09:35:11.475 >>> Virus 'Mal/Generic-S' found in file D:\Games\DiRT Rally\steamclient.dll
2016-04-18 09:35:55.061 >>> Virus 'Mal/Generic-S' found in file D:\Games\DiRT Rally\steam_apir.dll
2016-04-18 09:35:55.061 >>> Virus 'Mal/Generic-S' found in file D:\Games\DiRT Rally\steam_apir.dll
2016-04-18 09:35:55.061 >>> Virus 'Mal/Generic-S' found in file D:\Games\DiRT Rally\steam_apir.dll
2016-04-18 09:35:55.061 >>> Virus 'Mal/Generic-S' found in file D:\Games\DiRT Rally\steam_apir.dll
2016-04-18 09:35:55.062 >>> Virus 'Mal/Generic-S' found in file D:\Games\DiRT Rally\steam_apir.dll
2016-04-18 09:35:55.062 >>> Virus 'Mal/Generic-S' found in file D:\Games\DiRT Rally\steam_apir.dll
2016-04-18 09:40:53.342 >>> Virus 'Troj/Agent-ABWY' found in file D:\Games\The Elder Scrolls V - Skyrim - Legendary Edition\steam_api.dll
2016-04-18 10:43:39.989 The following items will be cleaned up:
2016-04-18 10:43:39.989 Mal/VMProtBad-A
2016-04-18 10:43:39.989 Mal/Generic-S
2016-04-18 10:43:39.989 Troj/Agent-ABWY
 
redtarget.gif
Update Adobe Flash Player: http://get.adobe.com/flashplayer/
Make sure you UN-check Yes, install McAfee Security Scan Plus

NOTE 1: Beginning with Adobe Flash Version 11.3, the universal installer includes the 32-bit and 64-bit versions of the Flash Player.
NOTE 2: While installing make sure you UN-check any extra garbage which wants to install alongside.

redtarget.gif
Update your Java version here: https://www.techspot.com/downloads/6463-java-se.html
Alternate download: http://www.java.com/en/download/manual.jsp

Note 1: UNCHECK any pre-checked toolbar and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update.
Note 2: If you're running 64-bit system make sure you install BOTH, 32-bit and 64-bit Java.

=================================

Your computer is clean

1. This step will remove all cleaning tools we used, it'll reset restore points (so you won't get reinfected by accidentally using some older restore point) and it'll make some other minor adjustments...
This is a very crucial step so make sure you don't skip it.
Download
51a5ce45263de-delfix.png
DelFix by Xplode to your desktop. Delfix will delete all the used tools and logfiles.

Double-click Delfix.exe to start the tool.
Make sure the following items are checked:
  • Activate UAC (optional; some users prefer to keep it off)
  • Remove disinfection tools
  • Create registry backup
  • Purge System Restore
  • Reset system settings
Now click "Run" and wait patiently.
Once finished a logfile will be created. You don't have to attach it to your next reply.

2. Make sure Windows Updates are current.

3. If any trojans, rootkits or bootkits were listed among your infection(s), make sure, you change all of your on-line important passwords (bank account(s), secured web sites, etc.) immediately!

4. Check if your browser plugins are up to date.
Firefox - https://www.mozilla.org/en-US/plugincheck/
other browsers: https://browsercheck.qualys.com/ (click on "Scan without installing plugin" and then on "Scan now")

5. Download, and install WOT (Web OF Trust): http://www.mywot.com/. It'll warn you (in most cases) about dangerous web sites.

6. Run Malwarebytes "Quick scan" once in a while to assure safety of your computer.

7. Run Temporary File Cleaner (TFC), AdwCleaner and Junkware Removal Tool (JRT) weekly (you need to redownload these tools since they were removed by DelFix).

8. Download and install Secunia Personal Software Inspector (PSI): https://www.techspot.com/downloads/4898-secunia-personal-software-inspector-psi.html. The Secunia PSI is a FREE security tool designed to detect vulnerable and out-dated programs and plug-ins which expose your PC to attacks. Run it weekly.

9. (optional) If you want to keep all your programs up to date, download and install FileHippo Update Checker.
The Update Checker will scan your computer for installed software, check the versions and then send this information to FileHippo.com to see if there are any newer releases.

10. When installing\updating ANY program, make sure you always select "Custom " installation, so you can UN-check any possible "drive-by-install" (foistware), like toolbars etc., which may try to install along with the legitimate program. Do NOT click "Next" button without looking at any given page.

11. Read:
How did I get infected?, With steps so it does not happen again!: http://www.bleepingcomputer.com/forums/topic2520.html
Simple and easy ways to keep your computer safe and secure on the Internet: http://www.bleepingcomputer.com/tutorials/keep-your-computer-safe-online/
About those Toolbars and Add-ons - Potentially Unwanted Programs (PUPs) which change your browser settings: http://www.bleepingcomputer.com/for...curity-questions-best-practices/#entry3187642

12. Please, let me know, how your computer is doing.
 
Back