Hi, I'm having problems with an unknown infection. I think it's inagzlj.dll and appears to be blocking RegEdit and Task Manager (amongst other things). It has cleared out my System Restore points.
Here's my Pseudo HJT logfile:
DDS (Ver_09-05-14.01) - NTFSx86 MINIMAL
Run by Andy at 16:36:54.51 on 08/06/2009
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1628 [GMT 1:00]
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: ZoneAlarm Firewall *enabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\Explorer.EXE
C:\Program Files\AVG\AVG8\avgui.exe
C:\Program Files\AVG\AVG8\avgscanx.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
F:\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.co.uk/ig?hl=en&source=iglk
BHO: : {0013d1c2-6ff9-439f-91e4-2c9365928d1d} - c:\windows\system32\inagzlj.dll
BHO: MSN helper: {10c0b0c0-fc01-473b-8ebb-4376353f96e4} - bekbn.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - No File
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.3572\swg.dll
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
TB: {90B8B761-DF2B-48AC-BBE0-BCC03A819B3B} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [DAEMON Tools Lite] "c:\program files\daemon tools lite\daemon.exe" -autorun
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe
mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe
mRun: [Launch LgDevAgt] "c:\program files\logitech\gamepanel software\LgDevAgt.exe"
mRun: [Launch LCDMon] "c:\program files\logitech\gamepanel software\lcd manager\LCDMon.exe"
mRun: [Launch LGDCore] "c:\program files\logitech\gamepanel software\g-series software\LGDCore.exe" /SHOWHIDE
mRun: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [ISUSPM] "c:\program files\common files\installshield\updateservice\ISUSPM.exe" -scheduler
mRun: [ZoneAlarm Client] "c:\program files\zone labs\zonealarm\zlclient.exe"
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [RivaTunerStartupDaemon] "c:\program files\rivatuner v2.24\RivaTuner.exe" /S
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
StartupFolder: c:\docume~1\alluse~1.win\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
StartupFolder: c:\docume~1\alluse~1.win\startm~1\programs\startup\logite~1.lnk - c:\program files\logitech\setpoint\SetPoint.exe
uPolicies-system: DisableTaskMgr = 1 (0x1)
uPolicies-system: DisableRegistryTools = 1 (0x1)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/C/0/C/C0CBBA88-A6F2-48D9-9B0E-1719D1177202/LegitCheckControl.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
TCP: {194AD7D5-00DD-4FF0-A5AF-C777D5FFBE76} = 192.168.0.1
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
Notify: AtiExtEvent - Ati2evxx.dll
Notify: avgrsstarter - avgrsstx.dll
Notify: kzdlruev - inagzlj.dll
Notify: LBTWlgn - c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Directory Opus Shell Execute Hook: {3cf9ece0-1a9f-11d2-8c73-00c06c2005de} - c:\program files\gpsoftware\directory opus\dopuslib.dll
============= SERVICES / DRIVERS ===============
S1 atitray;atitray;c:\program files\ray adams\ati tray tools\atitray.sys [2007-5-22 18088]
S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-2-2 325896]
S1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2009-2-2 27784]
S1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-2-2 108552]
S1 vsdatant;vsdatant;c:\windows\system32\vsdatant.sys [2009-2-2 353672]
S2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\avg\avg8\avgemc.exe [2009-2-2 908568]
S2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2009-1-21 298776]
S2 gupdate1c99effaa0730a;Google Update Service (gupdate1c99effaa0730a);c:\program files\google\update\GoogleUpdate.exe [2009-3-7 133104]
S2 LBeepKE;LBeepKE;c:\windows\system32\drivers\LBeepKE.sys [2009-2-2 10384]
S2 vmmkovyd;Remote Access IP ARP Support;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336]
S2 vsmon;TrueVector Internet Monitor;c:\windows\system32\zonelabs\vsmon.exe -service --> c:\windows\system32\zonelabs\vsmon.exe -service [?]
S3 AtiHdmiService;ATI Function Driver for HDMI Service;c:\windows\system32\drivers\AtiHdmi.sys [2007-7-20 84992]
S3 BDA_Capture_225;USB Digital-TV receiver. Driver 3.0.1.18;c:\windows\system32\drivers\BDA_Capture_225.sys [2009-2-19 17152]
S3 BDA_Loader_225;USB Digital-TV Receiver. Firmware Loader 7.1.9.0;c:\windows\system32\drivers\BDA_Loader_225.sys [2009-2-19 18944]
S3 rxpvbus;Reality XP Avionics Bus Driver;c:\windows\system32\drivers\rxpvbus.sys [2005-11-4 44032]
S3 s115bus;Sony Ericsson Device 115 driver (WDM);c:\windows\system32\drivers\s115bus.sys [2007-4-23 83208]
S3 s115mdfl;Sony Ericsson Device 115 USB WMC Modem Filter;c:\windows\system32\drivers\s115mdfl.sys [2007-4-23 15112]
S3 s115mdm;Sony Ericsson Device 115 USB WMC Modem Driver;c:\windows\system32\drivers\s115mdm.sys [2007-4-23 108680]
S3 SWUSBFLT;Microsoft SideWinder VIA Filter Driver;c:\windows\system32\drivers\SWUSBFLT.SYS [2009-2-21 3968]
=============== Created Last 30 ================
2009-06-08 15:24 <DIR> --d----- c:\program files\BHODemon 2
2009-06-08 14:11 1 a------- c:\windows\system32\ck.dat
2009-06-07 05:09 <DIR> --d-h--- c:\program files\win32GI
2009-06-07 04:47 <DIR> --d----- c:\program files\Capcom
2009-06-07 04:28 669,184 a------- c:\windows\system32\pbsvc.exe
2009-06-07 03:45 <DIR> --d----- c:\docume~1\andy~1.big\applic~1\Ubisoft
2009-06-07 01:45 <DIR> --d----- c:\program files\Left 4 Dead
2009-06-03 23:57 48,640 a------- C:\Iexplore0987.exe
2009-06-03 07:38 <DIR> --d----- c:\docume~1\andy~1.big\applic~1\SPORE
2009-05-31 14:24 <DIR> --d----- c:\program files\AllToAVI
2009-05-31 09:32 <DIR> --dsh--- c:\documents and settings\andy.bigbox\IECompatCache
2009-05-22 16:52 805,400 a----r-- c:\windows\system32\tmpA3.tmp
2009-05-22 16:52 805,400 a----r-- c:\windows\system32\tmpA2.tmp
2009-05-22 12:32 4,096 a------- c:\windows\system32\crash
2009-05-22 08:51 <DIR> --dsh--- c:\documents and settings\andy.bigbox\PrivacIE
2009-05-22 08:50 <DIR> --dsh--- c:\documents and settings\andy.bigbox\IETldCache
2009-05-22 08:34 <DIR> --d----- c:\windows\ie8updates
2009-05-22 08:34 102,400 -c------ c:\windows\system32\dllcache\iecompat.dll
2009-05-22 08:32 <DIR> -cd-h--- c:\windows\ie8
2009-05-17 09:41 <DIR> --d----- c:\program files\PJP
2009-05-13 15:21 <DIR> --d----- c:\program files\RivaTuner v2.24
2009-05-12 20:42 <DIR> --d----- c:\program files\SpeedFan
2009-05-12 20:42 45 a------- c:\windows\system32\initdebug.nfo
2009-05-11 08:59 <DIR> --d----- c:\program files\SimBin
==================== Find3M ====================
2009-06-07 04:28 22,328 a------- c:\docume~1\andy~1.big\applic~1\PnkBstrK.sys
2009-05-22 16:52 444,952 a------- c:\windows\system32\wrap_oal.dll
2009-05-22 16:52 109,080 a------- c:\windows\system32\OpenAL32.dll
2009-05-14 00:36 24,944 a------- c:\windows\system32\drivers\GVTDrv.sys
2009-05-11 10:13 107,888 a------- c:\windows\system32\CmdLineExt.dll
2009-05-11 09:02 325,896 a------- c:\windows\system32\drivers\avgldx86.sys
2009-05-11 09:02 11,952 a------- c:\windows\system32\avgrsstx.dll
2009-05-11 09:02 108,552 a------- c:\windows\system32\drivers\avgtdix.sys
2009-05-03 09:34 724,992 a------- c:\windows\iun6002.exe
2009-04-19 10:43 279,712 a------- c:\windows\system32\drivers\atksgt.sys
2009-04-19 10:43 25,888 a------- c:\windows\system32\drivers\lirsgt.sys
2009-03-29 12:55 15,600 a------- c:\windows\gdrv.sys
2009-03-27 17:14 4,212 a---h--- c:\windows\system32\zllictbl.dat
2009-03-17 21:05 593,920 -------- c:\windows\system32\ati2sgag.exe
2009-03-16 21:27 442,368 a------- c:\windows\system32\ATIDEMGX.dll
2009-03-16 21:26 328,704 a------- c:\windows\system32\ati2dvag.dll
2009-03-16 21:17 307,200 a------- c:\windows\system32\atiiiexx.dll
2009-03-16 21:17 204,800 a------- c:\windows\system32\atipdlxx.dll
2009-03-16 21:16 155,648 a------- c:\windows\system32\Oemdspif.dll
2009-03-16 21:16 26,112 a------- c:\windows\system32\Ati2mdxx.exe
2009-03-16 21:16 43,520 a------- c:\windows\system32\ati2edxx.dll
2009-03-16 21:16 155,648 a------- c:\windows\system32\ati2evxx.dll
2009-03-16 21:15 602,112 a------- c:\windows\system32\ati2evxx.exe
2009-03-16 21:13 53,248 a------- c:\windows\system32\ATIDDC.DLL
2009-03-16 21:06 3,820,736 a------- c:\windows\system32\ati3duag.dll
2009-03-16 21:04 11,563,008 a------- c:\windows\system32\atioglxx.dll
2009-03-16 20:53 2,675,328 a------- c:\windows\system32\ativvaxx.dll
2009-03-16 20:40 49,664 a------- c:\windows\system32\atimpc32.dll
2009-03-16 20:40 49,664 a------- c:\windows\system32\amdpcom32.dll
2009-03-16 20:36 475,136 a------- c:\windows\system32\atikvmag.dll
2009-03-16 20:35 303,104 a------- c:\windows\system32\atiok3x2.dll
2009-03-16 20:35 131,072 a------- c:\windows\system32\atiadlxx.dll
2009-03-16 20:35 45,056 a------- c:\windows\system32\aticalrt.dll
2009-03-16 20:34 45,056 a------- c:\windows\system32\aticalcl.dll
2009-03-16 20:34 17,408 a------- c:\windows\system32\atitvo32.dll
2009-03-16 20:33 3,264,512 a------- c:\windows\system32\aticaldd.dll
2009-03-16 20:28 630,784 a------- c:\windows\system32\ati2cqag.dll
2009-03-09 14:20 87,608 a------- c:\docume~1\andy~1.big\applic~1\inst.exe
2009-03-09 14:20 47,360 a------- c:\docume~1\andy~1.big\applic~1\pcouffin.sys
2006-07-05 06:33 472,000 a------- c:\windows\inf\wg311t\WG311T13.sys
2006-04-25 18:30 35,232 a------- c:\windows\inf\wg311t\ME_INST.EXE
2006-04-25 18:30 26,112 a------- c:\windows\inf\wg311t\install.exe
2003-10-06 09:21 0 a---h--- c:\docume~1\alluse~1.win\applic~1\sdpsenv.dat
2009-02-21 12:37 90 ---sh--- c:\windows\cnerolf.bin
2009-02-10 13:26 90 ---sh--- c:\windows\cnerolf.dat
============= FINISH: 16:39:30.21 ===============
Currently running AVG in Safe Mode (command line) to see if that will clear it out, but would appreciate more advice. Thanks.
Jock in a Frock