By using firefox and only connecting when directly browsing, I've tried to minimize the chances of an infection, but today I was hit with "XP Home Security - Unregistered Version". Avast! Antivirus had always done the job very well, but it's not finding this one.
The DDS log:
DDS (Ver_11-05-19.01) - NTFSx86
Internet Explorer: 8.0.6001.18702
Run by toshiba a100 at 11:53:45 on 2011-05-23
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1279 [GMT -7:00]
.
AV: avast! antivirus 4.8.1368 [VPS 110523-1] *Enabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
svchost.exe
svchost.exe
C:\Alwil Software\Avast4\aswUpdSv.exe
C:\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe
C:\WINDOWS\system32\TDispVol.exe
C:\WINDOWS\system32\TPSMain.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\RTHDCPL.EXE
C:\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
C:\Program Files\Microsoft Office\Office\OSA.EXE
C:\WINDOWS\system32\TPSBattM.exe
svchost.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\slserv.exe
C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
C:\Alwil Software\Avast4\ashMaiSv.exe
C:\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe
C:\Documents and Settings\toshiba a100\Local Settings\Application Data\qgy.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Mozilla Firefox\firefox.exe
C:\Alwil Software\Avast4\ashSimp2.exe
F:\Other\Programs\dds.scr
C:\WINDOWS\system32\WSCRIPT.exe
.
============== Pseudo HJT Report ===============
.
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\DLASHX_W.DLL
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [TOSCDSPD] c:\program files\toshiba\toscdspd\toscdspd.exe
mRun: [ehTray] c:\windows\ehome\ehtray.exe
mRun: [TFncKy] TFncKy.exe
mRun: [TDispVol] TDispVol.exe
mRun: [TPSMain] TPSMain.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NVRotateSysTray] rundll32.exe c:\windows\system32\nvsysrot.dll,Enable
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [avast!] c:\alwils~1\avast4\ashDisp.exe
mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\office~1.lnk - c:\program files\microsoft office\office\OSA.EXE
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0015-0000-0004-ABCDEFFEDCBC} - c:\program files\java\jre1.5.0_04\bin\npjpi150_04.dll
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Notify: psfus - psqlpwd.dll
LSA: Notification Packages = scecli psqlpwd
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\toshiba a100\application data\mozilla\firefox\profiles\djk6u5v1.default\
FF - prefs.js: browser.startup.homepage - hxxps://login.yahoo.com/config/mail?.intl=us
FF - plugin: c:\program files\java\jre1.5.0_04\bin\NPJPI150_04.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
.
============= SERVICES / DRIVERS ===============
.
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2011-2-24 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2011-2-24 20560]
R2 avast! Antivirus;avast! Antivirus;c:\alwil software\avast4\ashServ.exe [2011-2-24 138680]
R2 FdRedir;FdRedir;c:\program files\common files\protector suite ql\drivers\FdRedir.sys [2005-12-21 13568]
R2 FileDisk2;FileDisk Protector Kernel Driver;c:\program files\common files\protector suite ql\drivers\filedisk.sys [2005-12-21 33024]
R2 smihlp;SMI helper driver;c:\program files\protector suite ql\smihlp.sys [2005-12-21 3456]
R3 avast! Mail Scanner;avast! Mail Scanner;c:\alwil software\avast4\ashMaiSv.exe [2011-2-24 254040]
R3 avast! Web Scanner;avast! Web Scanner;c:\alwil software\avast4\ashWebSv.exe [2011-2-24 352920]
R3 NETwLx32; Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows XP 32 Bit;c:\windows\system32\drivers\NETwLx32.sys [2010-11-23 6607744]
.
=============== Created Last 30 ================
.
2011-05-23 17:53:35 331776 --sha-w- c:\documents and settings\toshiba a100\local settings\application data\qgy.exe
2011-05-22 08:32:17 -------- d--h--w- c:\windows\system32\GroupPolicy
2011-05-19 08:01:31 -------- d-----w- c:\documents and settings\toshiba a100\local settings\application data\Gas Powered Games
2011-05-19 07:40:50 -------- d-----w- C:\temp
2011-05-19 04:58:00 81768 ----a-w- c:\windows\system32\xinput1_3.dll
2011-05-19 04:58:00 237848 ----a-w- c:\windows\system32\xactengine2_4.dll
2011-05-19 04:58:00 15128 ----a-w- c:\windows\system32\x3daudio1_1.dll
.
==================== Find3M ====================
.
2011-03-13 20:31:20 98304 ----a-w- c:\windows\system32\CmdLineExt.dll
.
============= FINISH: 11:54:08.92 ===============
Looking through the task manager, I saw a "qgy.exe" which I could terminate, and searching through the HDD found a "qgy.exe" under the directory "C:\Windows\Prefetch". However, deleting that has not solved the problem.
EDIT: Posts merged ~Budapest
Attached File(s)
-
attach.zip (3.18K)
Number of downloads: 0
This post has been edited by Budapest: 24 May 2011 - 05:53 PM

Help
This topic is locked

Back to top
button.









