Stopped the avcare program starting itself on boot-up by deleting its program files folder. But there seems to be other (or associated) malware. Every so often an IE window (or 2) will open spontaneously, always displaying some kind of spam ad (gambling, pharmaceuticals, etc). Sometimes when I use google I get re-directs to something like 'windowsclick.com...'.
I've read how Malwarebytes' Anti-Malware is the thing to try, but I can't get it to install. First I have to re-name it to even be allowed to begin the installation process, and at the point where you choose 'Finish' and it's supposed to auto-launch, it doesn't (waited on it for over 3 hours).
I tried to do an AVG scan, but something caused the computer to re-start before it was finished.
When I did a search on files created at the time this began, I also noticed msa.exe which I googled and found to be more malware, though doing the same search again now (a day later) I'm not seeing it.
And the last problem I can identify is b.exe which is always a running process when I start up now.
I wouldn't be too bothered at having to re-format if I could back up some files, but the final symptom I've encounterd is that I can't burn a CD any more as when I tried to Nero presented me with an option I've never encounted before about burning rights and will now not let me burn without downloading them - and I read of other people having this problem who've said downloading them won't fix it anyway.
I've had occasional virus/malware problems in the past but always managed to fix things just by reading up and using suggested programs. But this has me beat. Much thanks in advance for any help you can give.
Here are the logs:
DDS (Ver_09-07-30.01) - NTFSx86
Run by Dave at 3:27:02.54 on 31/07/2009
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Home Edition 5.1.2600.3.1252.44.1033.18.511.118 [GMT 1:00]
AV: AVG 7.5.557 *On-access scanning enabled* (Outdated) {41564737-3200-1071-989B-0000E87B4FB1}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
svchost.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\Creative\Shared Files\CTDevSrv.exe
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\WINDOWS\SOINTGR.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Common Files\Logitech\QCDriver2\LVCOMS.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Creative\Creative Media Lite\CTZDetec.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Microsoft Office\Office\OSA.EXE
C:\Program Files\blueyonder IST\bin\mpbtn.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\Iexplore.exe
C:\Program Files\Internet Explorer\Iexplore.exe
C:\Documents and Settings\Dave\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.blueyonder.co.uk/blueyonder/index.jsp
uWindow Title = Microsoft Internet Explorer provided by blueyonder
uURLSearchHooks: {c12b4ec1-1f65-11d3-91ca-00104b9c4765} - c:\program files\copernic 2000 pro\CopernicFind.dll
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 5.0\reader\activex\AcroIEHelper.ocx
BHO: XML Class: {500bca15-57a7-4eaf-8143-8c619470b13d} - c:\windows\system32\msxml71.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~2\SDHelper.dll
BHO: EWPBrowseObject Class: {68f9551e-0411-48e4-9aaf-4bc42a6a46be} - c:\program files\canon\easy-webprint\EWPBrowseLoader.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.5.0_06\bin\ssv.dll
TB: Easy-WebPrint: {327c2873-e90d-4c37-aa9d-10ac9baba46c} - c:\program files\canon\easy-webprint\Toolband.dll
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [RealPlayer] "c:\program files\real\realone player\realplay.exe" /RunUPGToolCommandReBoot
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [ntuser] c:\windows\system32\drivers\spools.exe
uRun: [autoload] c:\documents and settings\dave\cftmon.exe
uRun: [Uniblue RegistryBooster 2] c:\program files\uniblue\registrybooster 2\RegistryBooster.exe /S
uRun: [CTZDetec.exe] c:\program files\creative\creative media lite\CTZDetec.exe
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [Monopod] c:\docume~1\dave\locals~1\temp\b.exe
mRun: [NeroCheck] c:\windows\system32\\NeroCheck.exe
mRun: [SO5 Integrator Pass Two] c:\windows\SOINTGR.EXE
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [AVG7_CC] c:\progra~1\grisoft\avg7\avgcc.exe /STARTUP
mRun: [LVCOMS] c:\program files\common files\logitech\qcdriver2\LVCOMS.EXE
mRun: [REGSHAVE] c:\program files\regshave\REGSHAVE.EXE /AUTORUN
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [SunJavaUpdateSched] c:\program files\java\jre1.5.0_06\bin\jusched.exe
mRun: [SSBkgdUpdate] "c:\program files\common files\scansoft shared\ssbkgdupdate\SSBkgdupdate.exe" -Embedding -boot
mRun: [OpwareSE4] "c:\program files\scansoft\omnipagese4.0\OpwareSE4.exe"
mRun: [ntuser] c:\windows\system32\drivers\spools.exe
mRun: [autoload] c:\documents and settings\dave\cftmon.exe
mRun: [net] "c:\windows\system32\net.net"
mRun: [MSxmlHpr] RUNDLL32.EXE c:\windows\system32\msxm192z.dll,w
mRunOnce: [Malwarebytes' Anti-Malware] c:\program files\malwarebytes' anti-malware\mbamgui.exe /install /silent
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
dRun: [AVG7_Run] c:\progra~1\grisoft\avg7\avgw.exe /RUNONCE
StartupFolder: c:\docume~1\dave\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office\FINDFAST.EXE
StartupFolder: c:\docume~1\dave\startm~1\programs\startup\office~1.lnk - c:\program files\microsoft office\office\OSA.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\blueyo~1.lnk - c:\program files\blueyonder ist\bin\matcli.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office10\EXCEL.EXE/3000
IE: Easy-WebPrint Add To Print List - c:\program files\canon\easy-webprint\Toolband.dll/RC_AddToList.html
IE: Easy-WebPrint High Speed Print - c:\program files\canon\easy-webprint\Toolband.dll/RC_HSPrint.html
IE: Easy-WebPrint Preview - c:\program files\canon\easy-webprint\Toolband.dll/RC_Preview.html
IE: Easy-WebPrint Print - c:\program files\canon\easy-webprint\Toolband.dll/RC_Print.html
IE: Search Using Copernic - file://c:\program files\copernic 2000 pro\Search Extension.htm
IE: {2A465934-E5F0-11D2-91B5-00104B9C4765} - c:\program files\copernic 2000 pro\Copernic.exe
IE: {2A465936-E5F0-11D2-91B5-00104B9C4765} - c:\program files\copernic 2000 pro\Copernic.exe
IE: {99EFB53C-C965-43CF-9F45-52242D134187} - c:\program files\copernic 2000 pro\Translate.htm
IE: {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - c:\program files\aim\aim.exe
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE}
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBC} - c:\program files\java\jre1.5.0_06\bin\ssv.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~2\SDHelper.dll
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Notify: f3dsl - lsd_f3.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\dave\applic~1\mozilla\firefox\profiles\6vriaue5.default\
FF - component: c:\program files\mozilla firefox\extensions\talkback@mozilla.org\components\qfaservices.dll
============= SERVICES / DRIVERS ===============
R?2 msncache;msncache;c:\windows\system32\svchost.exe -k netsvcs [2002-5-19 14336]
R1 Avg7Core;AVG7 Kernel;c:\windows\system32\drivers\avg7core.sys [2006-9-29 821856]
R1 Avg7RsW;AVG7 Wrap Driver;c:\windows\system32\drivers\avg7rsw.sys [2005-11-3 4224]
R1 Avg7RsXP;AVG7 Rezident Driver;c:\windows\system32\drivers\avg7rsxp.sys [2006-4-24 27776]
R1 AvgClean;AVG7 Clean Driver;c:\windows\system32\drivers\avgclean.sys [2007-2-17 10760]
R2 Avg7Alrt;AVG7 Alert Manager Server;c:\progra~1\grisoft\avg7\avgamsvr.exe [2007-2-17 418816]
R2 Avg7UpdSvc;AVG7 Update Service;c:\progra~1\grisoft\avg7\avgupsvc.exe [2007-2-17 49664]
R2 AVGEMS;AVG E-mail Scanner;c:\progra~1\grisoft\avg7\avgemc.exe [2007-2-17 406528]
R2 AvgTdi;AVG Network Redirector;c:\windows\system32\drivers\avgtdi.sys [2005-6-30 4960]
R3 ham50;Creatix V.92 HAM Data Fax Modem;c:\windows\system32\drivers\CTXH51.sys [2002-4-22 471407]
S1 iesprt;KeIE;\??\c:\windows\system32\iesprt.sys --> c:\windows\system32\iesprt.sys [?]
S3 PID_0920;Logitech QuickCam Express(PID_0920);c:\windows\system32\drivers\LV532AV.SYS [2005-1-13 152576]
S3 Z302Mic;Vimicro Z302 Mic Audio Filter Driver;c:\windows\system32\drivers\UsbMicfilt.sys [2004-3-7 22571]
S3 ZSMC302;PCL-W310;c:\windows\system32\drivers\usbVM302.sys [2004-3-7 93962]
=============== Created Last 30 ================
2009-07-30 04:16 <DIR> --d----- c:\docume~1\dave\applic~1\Malwarebytes
2009-07-30 04:01 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-07-30 03:22 <DIR> --d----- c:\docume~1\alluse~1\applic~1\18048904
2009-07-30 03:21 142,852 a------- c:\windows\system32\msxml71.dll
2009-07-30 03:20 37,148 a------- c:\windows\system32\net.net
2009-07-02 05:35 <DIR> --dsh--- c:\documents and settings\dave\IECompatCache
2009-07-01 09:04 <DIR> --dsh--- c:\documents and settings\dave\PrivacIE
2009-07-01 08:52 <DIR> --dsh--- c:\documents and settings\dave\IETldCache
2009-07-01 08:48 102,912 -c------ c:\windows\system32\dllcache\iecompat.dll
2009-07-01 08:47 <DIR> --d----- c:\windows\ie8updates
2009-07-01 08:45 12,800 -c------ c:\windows\system32\dllcache\xpshims.dll
2009-07-01 08:45 246,272 -c------ c:\windows\system32\dllcache\ieproxy.dll
2009-07-01 08:41 <DIR> -cd-h--- c:\windows\ie8
==================== Find3M ====================
2009-07-03 18:09 915,456 a------- c:\windows\system32\wininet.dll
2009-06-16 15:36 119,808 a------- c:\windows\system32\t2embed.dll
2009-06-16 15:36 81,920 a------- c:\windows\system32\fontsub.dll
2009-06-03 20:09 1,291,264 a------- c:\windows\system32\quartz.dll
2009-05-07 16:32 345,600 a------- c:\windows\system32\localspl.dll
2009-03-04 21:55 16,320,472 a------- c:\program files\vlc-0.9.8a-win32.exe
2009-02-03 20:58 763 a------- c:\program files\dizzy.ini
2008-05-14 23:55 498 a------- c:\documents and settings\dave\mpr2.dat
2008-05-14 23:55 498 a------- c:\documents and settings\dave\mpr.dat
2008-04-26 06:14 148,992 a------- c:\program files\ms_setup.exe
2007-11-17 10:43 389,784 a------- c:\program files\switchsetup.exe
2007-06-23 22:44 6,820,528 a------- c:\program files\FirefoxGoogleToolbarSetup.exe
2007-04-22 08:16 788,153 a------- c:\program files\pdf_image_extraction_wizard_11_setup.exe
2007-03-17 15:05 1,898 a------- c:\program files\dizzyreadme.txt
2007-03-17 14:59 532,480 a------- c:\program files\setup.exe
2007-03-17 14:55 947,083 a------- c:\program files\dizzy.pak
2007-03-08 11:38 7,223 a------- c:\program files\Lost.3x11.(HDTV-NoTV)[VTV].torrent
2007-02-17 02:13 19,170,000 a------- c:\program files\avg75free_441a944.exe
2006-10-17 22:14 1,097,783 a------- c:\program files\dizzy.exe
2006-08-23 08:29 1,969 a------- c:\program files\NESten.INI
2006-08-12 19:59 7,206 a------- c:\program files\the[1].shield.507.dsr-loki.[VTV].=mininova.org=.torrent
2006-07-20 20:44 648,594 a------- c:\program files\NESten061B1.exe
2006-06-09 18:20 1,033,987 a------- c:\program files\wrar36b4.exe
2005-06-11 07:04 3,899,239 a------- c:\program files\BitTorrent-4.1.2-Beta.exe
2005-05-24 00:12 3,597,968 a------- c:\program files\aimUK55.exe
2004-06-11 01:53 47,503 a------- c:\program files\KillBox.zip
2004-06-07 02:46 31,232 a--sh--- c:\program files\Thumbs.db
2004-05-31 17:11 402,564 a------- c:\program files\bhblastersetup.exe
2004-05-29 17:50 79 a------- c:\program files\adios.reg
2004-05-07 16:21 3,684,032 a------- c:\program files\spybotsd12.exe
2003-01-15 18:08 8,365,240 a------- c:\program files\RealOnePlayerV2GOLD.exe
2008-02-02 08:09 10,856 a--sh--- c:\windows\system32\KGyGaAvL.sys
2008-09-09 11:51 32,768 a--sh--- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008090920080910\index.dat
============= FINISH: 3:29:08.90 ===============