I am not sure what happened, however it started with a "Generic Host Process for WIN32 has encountered a problem" message. AVG and Malware Bytes have not picked anything up but I started getting constant misdirects when opening home page and now AVG has picked up all locked file can not test while scanning and the email sscanner componet is not active and the button to turn it on is gone?
I can not get online at all and am using my laptop while running the AVG scan on the desktop. Please advise and let me know what I need to provide. I tried starting in Safe Mode and installing MS Security Essentials, can not get it to open, update and run. Now getting error message svchost.exe " instruction at "0x001a2ae7" refernced memory at "0x000000000". The memory could not be "read". Click to terminate or cancel to debug program
EDIT: Moved from XP to Am I Infected forum ~ Hamluis.Here is the AVG and MalwareBytes scan results that I did from Safe Mode. What is going on, everything states no infection but getting constant misdirects? Could it be router?
AVG 9.0 Anti-Virus command line scanner
Copyright © 1992 - 2010 AVG Technologies
Program version 9.0.782, engine 9.0.828
Virus Database: Version 271.1.1/2979 2010-07-03
C:\0a55d7da5d5a228795b207\$shtdwn$.req Locked file. Not tested.
C:\0a55d7da5d5a228795b207\MPSigStub.exe Locked file. Not tested.
C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Locked file. Not tested.
C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Locked file. Not tested.
C:\Documents and Settings\Administrator\ntuser.dat Locked file. Not tested.
C:\Documents and Settings\Administrator\ntuser.dat.LOG Locked file. Not tested.
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8597adc434fa28b3815532689ba1a844_50e417e0-e461-474b-96e2-077b80325612 Locked file. Not tested.
C:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\user.dmp Locked file. Not tested.
C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\IMpServiceBCF43643-A118-4432-AEDE-D861FCBCFCDE.lock Locked file. Not tested.
C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\MpScanCache-0.bin Locked file. Not tested.
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Locked file. Not tested.
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Locked file. Not tested.
C:\Documents and Settings\LocalService\NTUSER.DAT Locked file. Not tested.
C:\Documents and Settings\LocalService\ntuser.dat.LOG Locked file. Not tested.
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Locked file. Not tested.
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Locked file. Not tested.
C:\Documents and Settings\NetworkService\NTUSER.DAT Locked file. Not tested.
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Locked file. Not tested.
C:\pagefile.sys Locked file. Not tested.
C:\System Volume Information\ Locked file. Not tested.
C:\WINDOWS\system32\config\DEFAULT Locked file. Not tested.
C:\WINDOWS\system32\config\default.LOG Locked file. Not tested.
C:\WINDOWS\system32\config\SAM Locked file. Not tested.
C:\WINDOWS\system32\config\SAM.LOG Locked file. Not tested.
C:\WINDOWS\system32\config\SECURITY Locked file. Not tested.
C:\WINDOWS\system32\config\SECURITY.LOG Locked file. Not tested.
C:\WINDOWS\system32\config\SOFTWARE Locked file. Not tested.
C:\WINDOWS\system32\config\software.LOG Locked file. Not tested.
C:\WINDOWS\system32\config\SYSTEM Locked file. Not tested.
C:\WINDOWS\system32\config\system.LOG Locked file. Not tested.
------------------------------------------------------------
Objects scanned : 399101
Found infections : 0
Found PUPs : 0
Healed infections : 0
Healed PUPs : 0
Warnings : 0
------------------------------------------------------------
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Database version: 4187
Windows 5.1.2600 Service Pack 3 (Safe Mode)
Internet Explorer 8.0.6001.18702
7/6/2010 2:06:04 PM
mbam-log-2010-07-06 (14-06-04).txt
Scan type: Full scan (C:\|)
Objects scanned: 223345
Time elapsed: 57 minute(s), 12 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
here is SAS scan log
SUPERAntiSpyware Scan Log
http://www.superantispyware.comGenerated 07/06/2010 at 04:20 PM
Application Version : 4.40.1002
Core Rules Database Version : 5162
Trace Rules Database Version: 2974
Scan type : Complete Scan
Total Scan Time : 00:57:20
Memory items scanned : 309
Memory threats detected : 0
Registry items scanned : 7002
Registry threats detected : 0
File items scanned : 73928
File threats detected : 122
Adware.Tracking Cookie
C:\Documents and Settings\LJC\Cookies\ljc@bridge1.admarketplace[1].txt
C:\Documents and Settings\LJC\Cookies\ljc@richmedia.yahoo[2].txt
C:\Documents and Settings\LJC\Cookies\ljc@myaccountsmsg.navyfcu[1].txt
C:\Documents and Settings\LJC\Cookies\ljc@myaccounts.navyfcu[1].txt
C:\Documents and Settings\LJC\Cookies\ljc@collective-media[2].txt
C:\Documents and Settings\LJC\Cookies\ljc@epilot.hamptonroads[1].txt
C:\Documents and Settings\LJC\Cookies\ljc@myaccountsaws.navyfcu[1].txt
C:\Documents and Settings\LJC\Cookies\ljc@ad.wsod[2].txt
C:\Documents and Settings\LJC\Cookies\ljc@insightexpressai[1].txt
C:\Documents and Settings\LJC\Cookies\ljc@ads.bleepingcomputer[2].txt
C:\Documents and Settings\LJC\Cookies\ljc@ads.gmodules[1].txt
C:\Documents and Settings\LJC\Cookies\ljc@bizzclick[1].txt
C:\Documents and Settings\LJC\Cookies\ljc@findlaw[1].txt
C:\Documents and Settings\LJC\Cookies\ljc@ads.as4x.tmcs.ticketmaster[1].txt
C:\Documents and Settings\LJC\Cookies\ljc@ads.monster[2].txt
C:\Documents and Settings\LJC\Cookies\ljc@admarketplace[1].txt
C:\Documents and Settings\LJC\Cookies\ljc@invitemedia[1].txt
cdn4.specificclick.net [ C:\Documents and Settings\Guest\Application Data\Macromedia\Flash Player\#SharedObjects\77ZHGR25 ]
udn.specificclick.net [ C:\Documents and Settings\Guest\Application Data\Macromedia\Flash Player\#SharedObjects\77ZHGR25 ]
adimages.scrippsnetworks.com [ C:\Documents and Settings\LJC\Application Data\Macromedia\Flash Player\#SharedObjects\LTBE23KF ]
broadcast.piximedia.fr [ C:\Documents and Settings\LJC\Application Data\Macromedia\Flash Player\#SharedObjects\LTBE23KF ]
cdn4.specificclick.net [ C:\Documents and Settings\LJC\Application Data\Macromedia\Flash Player\#SharedObjects\LTBE23KF ]
convoad.technoratimedia.com [ C:\Documents and Settings\LJC\Application Data\Macromedia\Flash Player\#SharedObjects\LTBE23KF ]
core.insightexpressai.com [ C:\Documents and Settings\LJC\Application Data\Macromedia\Flash Player\#SharedObjects\LTBE23KF ]
cp.media.cfsm1.cedarfair.com [ C:\Documents and Settings\LJC\Application Data\Macromedia\Flash Player\#SharedObjects\LTBE23KF ]
crackle.com [ C:\Documents and Settings\LJC\Application Data\Macromedia\Flash Player\#SharedObjects\LTBE23KF ]
googleads.g.doubleclick.net [ C:\Documents and Settings\LJC\Application Data\Macromedia\Flash Player\#SharedObjects\LTBE23KF ]
imagec05.247realmedia.com [ C:\Documents and Settings\LJC\Application Data\Macromedia\Flash Player\#SharedObjects\LTBE23KF ]
interclick.com [ C:\Documents and Settings\LJC\Application Data\Macromedia\Flash Player\#SharedObjects\LTBE23KF ]
m1.2mdn.net [ C:\Documents and Settings\LJC\Application Data\Macromedia\Flash Player\#SharedObjects\LTBE23KF ]
macromedia.com [ C:\Documents and Settings\LJC\Application Data\Macromedia\Flash Player\#SharedObjects\LTBE23KF ]
media.cnbc.com [ C:\Documents and Settings\LJC\Application Data\Macromedia\Flash Player\#SharedObjects\LTBE23KF ]
media.hamptonroads.com [ C:\Documents and Settings\LJC\Application Data\Macromedia\Flash Player\#SharedObjects\LTBE23KF ]
media.jambocast.com [ C:\Documents and Settings\LJC\Application Data\Macromedia\Flash Player\#SharedObjects\LTBE23KF ]
media.monster.com [ C:\Documents and Settings\LJC\Application Data\Macromedia\Flash Player\#SharedObjects\LTBE23KF ]
media.mtvnservices.com [ C:\Documents and Settings\LJC\Application Data\Macromedia\Flash Player\#SharedObjects\LTBE23KF ]
media.oprah.com [ C:\Documents and Settings\LJC\Application Data\Macromedia\Flash Player\#SharedObjects\LTBE23KF ]
media.scanscout.com [ C:\Documents and Settings\LJC\Application Data\Macromedia\Flash Player\#SharedObjects\LTBE23KF ]
media.tattomedia.com [ C:\Documents and Settings\LJC\Application Data\Macromedia\Flash Player\#SharedObjects\LTBE23KF ]
media.thewb.com [ C:\Documents and Settings\LJC\Application Data\Macromedia\Flash Player\#SharedObjects\LTBE23KF ]
media.wvec.com [ C:\Documents and Settings\LJC\Application Data\Macromedia\Flash Player\#SharedObjects\LTBE23KF ]
media1.break.com [ C:\Documents and Settings\LJC\Application Data\Macromedia\Flash Player\#SharedObjects\LTBE23KF ]
media10.washingtonpost.com [ C:\Documents and Settings\LJC\Application Data\Macromedia\Flash Player\#SharedObjects\LTBE23KF ]
mediaforgews.com [ C:\Documents and Settings\LJC\Application Data\Macromedia\Flash Player\#SharedObjects\LTBE23KF ]
msnbcmedia.msn.com [ C:\Documents and Settings\LJC\Application Data\Macromedia\Flash Player\#SharedObjects\LTBE23KF ]
msntest.serving-sys.com [ C:\Documents and Settings\LJC\Application Data\Macromedia\Flash Player\#SharedObjects\LTBE23KF ]
objects.tremormedia.com [ C:\Documents and Settings\LJC\Application Data\Macromedia\Flash Player\#SharedObjects\LTBE23KF ]
oddcast.com [ C:\Documents and Settings\LJC\Application Data\Macromedia\Flash Player\#SharedObjects\LTBE23KF ]
s0.2mdn.net [ C:\Documents and Settings\LJC\Application Data\Macromedia\Flash Player\#SharedObjects\LTBE23KF ]
secure-us.imrworldwide.com [ C:\Documents and Settings\LJC\Application Data\Macromedia\Flash Player\#SharedObjects\LTBE23KF ]
serving-sys.com [ C:\Documents and Settings\LJC\Application Data\Macromedia\Flash Player\#SharedObjects\LTBE23KF ]
spe.atdmt.com [ C:\Documents and Settings\LJC\Application Data\Macromedia\Flash Player\#SharedObjects\LTBE23KF ]
speed.pointroll.com [ C:\Documents and Settings\LJC\Application Data\Macromedia\Flash Player\#SharedObjects\LTBE23KF ]
tags.mediaforge.com [ C:\Documents and Settings\LJC\Application Data\Macromedia\Flash Player\#SharedObjects\LTBE23KF ]
udn.specificclick.net [ C:\Documents and Settings\LJC\Application Data\Macromedia\Flash Player\#SharedObjects\LTBE23KF ]
vitamine.networldmedia.net [ C:\Documents and Settings\LJC\Application Data\Macromedia\Flash Player\#SharedObjects\LTBE23KF ]
www.countryinns.com [ C:\Documents and Settings\LJC\Application Data\Macromedia\Flash Player\#SharedObjects\LTBE23KF ]
C:\Documents and Settings\LJC\Cookies\ljc@adinterax[2].txt
C:\Documents and Settings\LJC\Cookies\ljc@bs.serving-sys[1].txt
C:\Documents and Settings\LJC\Cookies\ljc@kontera[1].txt
C:\Documents and Settings\LJC\Cookies\ljc@overture[2].txt
C:\Documents and Settings\LJC\Cookies\ljc@pointroll[1].txt
C:\Documents and Settings\LJC\Cookies\ljc@serving-sys[1].txt
C:\Documents and Settings\LJC\Cookies\ljc@smartadserver[1].txt
core.insightexpressai.com [ C:\Documents and Settings\LocalService\Application Data\Macromedia\Flash Player\#SharedObjects\BDRLUU9Q ]
objects.tremormedia.com [ C:\Documents and Settings\LocalService\Application Data\Macromedia\Flash Player\#SharedObjects\BDRLUU9Q ]
C:\Documents and Settings\LocalService\Cookies\system@ads.pointroll[2].txt
C:\Documents and Settings\LocalService\Cookies\system@adserver.adtechus[1].txt
C:\Documents and Settings\LocalService\Cookies\system@advertise[1].txt
C:\Documents and Settings\LocalService\Cookies\system@collective-media[2].txt
C:\Documents and Settings\LocalService\Cookies\system@dc.tremormedia[2].txt
C:\Documents and Settings\LocalService\Cookies\system@insightexpressai[1].txt
C:\Documents and Settings\LocalService\Cookies\system@invitemedia[1].txt
C:\Documents and Settings\LocalService\Cookies\system@network.realmedia[1].txt
C:\Documents and Settings\LocalService\Cookies\system@pointroll[2].txt
C:\Documents and Settings\LocalService\Cookies\system@questionmarket[2].txt
C:\Documents and Settings\LocalService\Cookies\system@realmedia[2].txt
C:\Documents and Settings\LocalService\Cookies\system@revsci[1].txt
C:\Documents and Settings\LocalService\Cookies\system@t.pointroll[1].txt
media.mtvnservices.com [ C:\Documents and Settings\NetworkService\Application Data\Macromedia\Flash Player\#SharedObjects\6JT9CTV4 ]
media.onsugar.com [ C:\Documents and Settings\NetworkService\Application Data\Macromedia\Flash Player\#SharedObjects\6JT9CTV4 ]
media.scanscout.com [ C:\Documents and Settings\NetworkService\Application Data\Macromedia\Flash Player\#SharedObjects\6JT9CTV4 ]
objects.tremormedia.com [ C:\Documents and Settings\NetworkService\Application Data\Macromedia\Flash Player\#SharedObjects\6JT9CTV4 ]
secure-us.imrworldwide.com [ C:\Documents and Settings\NetworkService\Application Data\Macromedia\Flash Player\#SharedObjects\6JT9CTV4 ]
C:\Documents and Settings\NetworkService\Cookies\system@ads.gossipcenter[2].txt
C:\Documents and Settings\NetworkService\Cookies\system@advertise[1].txt
C:\Documents and Settings\NetworkService\Cookies\system@advertise[2].txt
C:\Documents and Settings\NetworkService\Cookies\system@bizzclick[1].txt
C:\Documents and Settings\NetworkService\Cookies\system@cdn.jemamedia[2].txt
C:\Documents and Settings\NetworkService\Cookies\system@clickpayz2.91462.blueseek[1].txt
C:\Documents and Settings\NetworkService\Cookies\system@content.yieldmanager[2].txt
C:\Documents and Settings\NetworkService\Cookies\system@content.yieldmanager[3].txt
C:\Documents and Settings\NetworkService\Cookies\system@media6degrees[2].txt
C:\Documents and Settings\NetworkService\Cookies\system@questionmarket[2].txt
C:\Documents and Settings\NetworkService\Cookies\system@revsci[2].txt
C:\Documents and Settings\NetworkService\Cookies\system@videoegg.adbureau[2].txt
Adware.Flash Tracking Cookie
C:\Documents and Settings\LJC\Application Data\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\LTBE23KF\MSNTEST.SERVING-SYS.COM
C:\Documents and Settings\LJC\Application Data\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\LTBE23KF\SERVING-SYS.COM
C:\Documents and Settings\LJC\Application Data\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\LTBE23KF\WWW.COUNTRYINNS.COM
C:\Documents and Settings\LJC\Application Data\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\LTBE23KF\BROADCAST.PIXIMEDIA.FR
C:\Documents and Settings\LJC\Application Data\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\LTBE23KF\CONVOAD.TECHNORATIMEDIA.COM
C:\Documents and Settings\LJC\Application Data\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\LTBE23KF\MEDIA.CNBC.COM
C:\Documents and Settings\LJC\Application Data\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\LTBE23KF\MEDIA.MTVNSERVICES.COM
C:\Documents and Settings\LJC\Application Data\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\LTBE23KF\MEDIA.OPRAH.COM
C:\Documents and Settings\LJC\Application Data\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\LTBE23KF\MEDIA.SCANSCOUT.COM
C:\Documents and Settings\LJC\Application Data\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\LTBE23KF\MEDIA.TATTOMEDIA.COM
C:\Documents and Settings\LJC\Application Data\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\LTBE23KF\MEDIA.WVEC.COM
C:\Documents and Settings\LJC\Application Data\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\LTBE23KF\MEDIA1.BREAK.COM
C:\Documents and Settings\LJC\Application Data\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\LTBE23KF\MEDIAFORGEWS.COM
C:\Documents and Settings\LJC\Application Data\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\LTBE23KF\MSNBCMEDIA.MSN.COM
C:\Documents and Settings\LJC\Application Data\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\LTBE23KF\OBJECTS.TREMORMEDIA.COM
C:\Documents and Settings\LJC\Application Data\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\LTBE23KF\TAGS.MEDIAFORGE.COM
C:\Documents and Settings\LJC\Application Data\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\LTBE23KF\VITAMINE.NETWORLDMEDIA.NET
C:\Documents and Settings\LJC\Application Data\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\LTBE23KF\INTERCLICK.COM
C:\Documents and Settings\LJC\Application Data\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\LTBE23KF\UDN.SPECIFICCLICK.NET
C:\Documents and Settings\LJC\Application Data\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\LTBE23KF\CRACKLE.COM
C:\Documents and Settings\LJC\Application Data\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\LTBE23KF\ADIMAGES.SCRIPPSNETWORKS.COM
C:\Documents and Settings\LJC\Application Data\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\LTBE23KF\SPEED.POINTROLL.COM
C:\Documents and Settings\LJC\Application Data\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\LTBE23KF\M1.2MDN.NET
C:\Documents and Settings\LJC\Application Data\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\LTBE23KF\SECURE-US.IMRWORLDWIDE.COM
C:\Documents and Settings\LJC\Application Data\MACROMEDIA\FLASH PLAYER\#SHAREDOBJECTS\LTBE23KF\ODDCAST.COM
Trojan.Dropper/Win-NV
C:\WINDOWS\SYSTEM32\WIN32S\MSVIDEO.DLL