I completed everything in the preparation guide except for the GMER log as it froze my PC everytime I tried to run it. I posted a new topic to this effect and was directed by Orange Blossom to disregard the GMER log for now, and to post a new topic here...
Don't worry about the GMER log. Please create a NEW TOPIC and post it ==>HERE<== Please include a description of your computer issues and what you have done to try to resolve them and the DDS logs. Let them know what happened when you tried to run GMER.
Orange Blossom
My problem has been varied and never very constant. It started a few weeks ago with some hinky IE behavior, none of it all that horrible, but hardly convinient; aggressive redirects and frozen pages. Then that went away and I noticed that it took almost 15 seconds for any IE window to close after mashing the close button. Then that went away (mostly) and now IE is doing two new weird things: Any attempt to return to the Google search results from a visited website produces a redirect toward what ever page I'm trying to navigate from. I have to leapfrog the redirect by way of the "back/forward" drop-down menu. But it only does this when navigating from the 1st page of Google hits/results, if I go to the second page of Google results and navigate to any website, hitting the back button takes me right back to the results page 2 like it should. Or sometimes if I hit the back button to go back to the Google returns page it'll completely jump over the results and take me all the way back to the blank google prompt page. It's a pain. Other that IE problems, I'm having a lot of problems with basic stuff: Programs freezing that have never done so before, icons disappearing from my desktop, etc.
Next, when I attempted to update my Vista OS it failed several times to install KB979683, returning an error code of FFFFFFF. When I went to MS and tracked this code down I was told that updater will not DL/install this update because it detected Alureon Rootkit and to install might cause an unbootable PC. It also said that it was up to me to get rid of it.
I DL'd TDSSKiller and ran it as per your (BleepingComputer...) instructions. It ran once, for a few seconds, appeared to have immediately identified several files, then my PC locked up. I reran it after unclencing my 'puter, but every attempt since has come back with a suspiciously clean bill of health. I think I'm still infected as the hinkiness continues.
Lastly, I DL's the latest v. of Windows Malicious Software Removal Tool and ran it. It took hours and when done it would not show me what it'd found )is anything)
The bottom line is that my PC is acting very weird lately, and sometimes completely freezes up.
Any help appreciated. ~ G
My 'puter:
OS Name Microsoft® Windows Vista™ Home Premium
Version 6.0.6001 Service Pack 1 Build 6001
Other OS Description Not Available
OS Manufacturer Microsoft Corporation
System Name PRIMUS
System Manufacturer Gateway
System Model GT5670
System Type X86-based PC
Processor AMD Phenom 8400 Triple-Core Processor, 2100 Mhz, 3 Core(s), 3 Logical Processor(s)
BIOS Version/Date Phoenix Technologies, LTD 6.00 PG, 1/18/2008
SMBIOS Version 2.4
Windows Directory C:\Windows
System Directory C:\Windows\system32
Boot Device \Device\HarddiskVolume2
Locale United States
Hardware Abstraction Layer Version = "6.0.6001.18000"
User Name Primus\Gregg
Time Zone Pacific Daylight Time
Installed Physical Memory (RAM) 3.00 GB
Total Physical Memory 2.87 GB
Available Physical Memory 1.42 GB
Total Virtual Memory 5.96 GB
Available Virtual Memory 4.23 GB
Page File Space 3.17 GB
Page File C:\pagefile.sys
_________________________________________________________________________
My DDS.txt:
DDS (Ver_10-03-17.01) - NTFSx86
Run by Gregg at 3:16:08.09 on Sat 05/29/2010
Internet Explorer: 8.0.6001.18904
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.2942.1431 [GMT -7:00]
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: AVG Anti-Virus Free *enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: AVG Anti-Spyware *disabled* (Outdated) {48F2E28D-ED66-4646-9C11-B3055B0AF604}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\LEXBCES.EXE
C:\Windows\System32\LEXPPS.EXE
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Program Files\Cobian Backup 10\cbVSCService.exe
C:\Windows\system32\lxbvcoms.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\Windows\System32\tcpsvcs.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\PROGRA~1\SPEEDB~2\VideoAcceleratorService.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\AVG\AVG9\avgemc.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\taskeng.exe
C:\PROGRA~1\SPEEDB~2\VideoAcceleratorEngine.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Windows\RtHDVCpl.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Windows\System32\wpcumi.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\AVG\AVG9\avgtray.exe
C:\Program Files\DAP\DAP.exe
C:\Program Files\Eraser\Eraser.exe
C:\Program Files\Uniblue\ProcessQuickLink 2\ProcessQuickLink2.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Windows Mail\WinMail.exe
C:\Program Files\Windows Live\Mail\wlmail.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\Gregg\Desktop\dds.scr
C:\Windows\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
uSearch Page =
uStart Page = hxxp://www.google.com/
uDefault_Page_URL = hxxp://www.gateway.com/g/startpage.html?Ch=Retail&SubCH=nofound&Br=GTW&Loc=ENG_US&Sys=DTP&M=GT5670
uSearch Bar =
mStart Page = hxxp://www.gateway.com/g/startpage.html?Ch=Retail&SubCH=nofound&Br=GTW&Loc=ENG_US&Sys=DTP&M=GT5670
mDefault_Page_URL = hxxp://www.gateway.com/g/startpage.html?Ch=Retail&SubCH=nofound&Br=GTW&Loc=ENG_US&Sys=DTP&M=GT5670
uInternet Settings,ProxyOverride = *.local
mSearchAssistant =
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: SBCONVERT Class: {31b27f2d-6bc6-451b-b3d2-4eab36b2fc3b} - c:\program files\speedbit video downloader\toolbar\tbcore3.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: DAPIELoader Class: {ff6c3cf0-4b15-11d1-abed-709549c10000} - c:\progra~1\dap\DAPIEL~1.DLL
BHO: GrabberObj Class: {ff7c3cf0-4b15-11d1-abed-709549c10000} - c:\progra~1\speedb~1\toolbar\grabber.dll
TB: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
TB: SpeedBit Video Downloader: {0329e7d6-6f54-462d-93f6-f5c3118badf2} - c:\program files\speedbit video downloader\toolbar\tbcore3.dll
TB: {8B79EE88-E62D-4AA8-B530-CC357BA112B7} - No File
TB: {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - No File
TB: {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
uRun: [DownloadAccelerator] "c:\program files\dap\DAP.EXE" /STARTUP
uRun: [Eraser] c:\program files\eraser\Eraser.exe -hide
uRun: [DU Meter] c:\program files\du meter\DUMeter.exe
uRun: [Uniblue ProcessQuickLink 2] "c:\program files\uniblue\processquicklink 2\ProcessQuickLink2.exe" /autostart
mRun: [RtHDVCpl] RtHDVCpl.exe
mRun: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [WPCUMI] c:\windows\system32\WpcUmi.exe
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [AVG9_TRAY] c:\progra~1\avg\avg9\avgtray.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\logite~1.lnk - c:\program files\logitech\setpoint\SetPoint.exe
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: &Clean Traces - c:\program files\dap\privacy package\dapcleanerie.htm
IE: &Download with &DAP - c:\program files\dap\dapextie.htm
IE: &ieSpell Options - c:\program files\iespell\iespell.dll/SPELLOPTION.HTM
IE: Check &Spelling - c:\program files\iespell\iespell.dll/SPELLCHECK.HTM
IE: Download &all with DAP - c:\program files\dap\dapextie2.htm
IE: Download &Flash Movies - c:\program files\flash2x\flash hunter\save.htm
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office10\EXCEL.EXE/3000
IE: Lookup on Merriam Webster - file://c:\program files\iespell\Merriam Webster.HTM
IE: Lookup on Wikipedia - file://c:\program files\iespell\wikipedia.HTM
IE: {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - res://c:\program files\iespell\iespell.dll/SPELLCHECK.HTM
IE: {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - res://c:\program files\iespell\iespell.dll/SPELLOPTION.HTM
IE: {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - c:\program files\bodog poker\BPGame.exe
LSP: c:\windows\system32\wpclsp.dll
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/FacebookPhotoUploader5.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {2042B57E-6336-459E-B7CE-2A0F6C9E6AF8} - file:///E:/win/setup/iaieplay.dll
DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} - hxxp://photos.walmart.com/WalmartActivia.cab
DPF: {48DD0448-9209-4F81-9F6D-D83562940134} - hxxp://lads.myspace.com/upload/MySpaceUploader1006.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {C52439A0-2693-4E40-B141-9F9AD5257241} - hxxps://ediagnostics.lexmark.com/serval.cab
DPF: {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_04-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll
AppInit_DLLs: avgrsstx.dll
============= SERVICES / DRIVERS ===============
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-1-2 216200]
R1 AvgMfx86;AVG Minifilter x86 Resident Driver;c:\windows\system32\drivers\avgmfx86.sys [2008-4-14 29512]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2010-3-22 242896]
R2 avg9emc;AVG Free E-mail Scanner;c:\program files\avg\avg9\avgemc.exe [2010-3-22 916760]
R2 avg9wd;AVG Free WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2010-3-22 308064]
R2 cbVSCService;Cobian Backup 10 Volume Shadow Copy service;c:\program files\cobian backup 10\cbVSCService.exe [2010-5-25 67584]
R2 lxbv_device;lxbv_device;c:\windows\system32\lxbvcoms.exe -service --> c:\windows\system32\lxbvcoms.exe -service [?]
R2 VideoAcceleratorService;VideoAcceleratorService;c:\progra~1\speedb~2\videoacceleratorservice.exe -start -scm --> c:\progra~1\speedb~2\VideoAcceleratorService.exe -start -scm [?]
R3 SaiH075C;SaiH075C;c:\windows\system32\drivers\SaiH075C.sys [2008-4-3 176640]
S2 AdobeActiveFileMonitor;Adobe Active File Monitor;c:\program files\adobe\photoshop elements 3.0\photoshopelementsfileagent.exe --> c:\program files\adobe\photoshop elements 3.0\PhotoshopElementsFileAgent.exe [?]
S2 gupdate1c996687543bade;Google Update Service (gupdate1c996687543bade);c:\program files\google\update\GoogleUpdate.exe [2009-2-24 133104]
S2 PhotoshopElementsDeviceConnect;Photoshop Elements Device Connect;c:\program files\adobe\photoshop elements 3.0\photoshopelementsdeviceconnect.exe --> c:\program files\adobe\photoshop elements 3.0\PhotoshopElementsDeviceConnect.exe [?]
S3 CoachVid;CoachVid;c:\windows\system32\drivers\CoachVid.sys [2009-6-19 45344]
S3 NETw2v32;Intel® PRO/Wireless 2200BG Network Connection Driver for Windows Vista;c:\windows\system32\drivers\NETw2v32.sys [2006-11-2 2589184]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\gamemon.des -service --> c:\windows\system32\GameMon.des -service [?]
=============== Created Last 30 ================
2010-05-26 07:26:04 20 ----a-w- c:\users\gregg\defogger_reenable
2010-05-26 06:54:07 0 d-----w- c:\program files\Cobian Backup 10
2010-05-26 05:40:46 2048 ----a-w- c:\windows\system32\tzres.dll
2010-05-22 09:57:02 0 d-----w- c:\windows\system32\MpEngineStore
2010-05-17 23:00:43 176 ----a-w- c:\windows\system32\MRT.INI
2010-05-17 22:51:27 24064 ----a-w- c:\windows\system32\nshhttp.dll
2010-05-17 22:51:26 411136 ----a-w- c:\windows\system32\drivers\http.sys
2010-05-17 22:51:25 31232 ----a-w- c:\windows\system32\httpapi.dll
2010-05-17 22:43:12 523776 ----a-w- c:\windows\system32\RMActivate_isv.exe
2010-05-17 22:43:12 511488 ----a-w- c:\windows\system32\RMActivate.exe
2010-05-17 22:43:10 347136 ----a-w- c:\windows\system32\RMActivate_ssp.exe
2010-05-17 22:43:09 472576 ----a-w- c:\windows\system32\secproc_isv.dll
2010-05-17 22:43:09 472064 ----a-w- c:\windows\system32\secproc.dll
2010-05-17 22:43:09 346624 ----a-w- c:\windows\system32\RMActivate_ssp_isv.exe
2010-05-17 22:43:09 329216 ----a-w- c:\windows\system32\msdrm.dll
2010-05-17 22:43:09 151040 ----a-w- c:\windows\system32\secproc_ssp_isv.dll
2010-05-17 22:43:09 151040 ----a-w- c:\windows\system32\secproc_ssp.dll
2010-05-17 22:41:23 898952 ----a-w- c:\windows\system32\drivers\tcpip.sys
2010-05-17 22:41:23 25088 ----a-w- c:\windows\system32\drivers\tunnel.sys
2010-05-17 22:41:23 190464 ----a-w- c:\windows\system32\iphlpsvc.dll
2010-05-17 22:40:56 62464 ----a-w- c:\windows\system32\l3codeca.acm
2010-05-17 22:40:54 3598216 ----a-w- c:\windows\system32\ntkrnlpa.exe
2010-05-17 22:40:53 3545992 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-05-17 22:40:49 738304 ----a-w- c:\windows\system32\inetcomm.dll
2010-05-17 22:40:48 78848 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2010-05-17 22:40:47 212992 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2010-05-17 22:40:47 105984 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-05-17 22:40:46 420352 ----a-w- c:\windows\system32\vbscript.dll
2010-05-17 22:40:45 98304 ----a-w- c:\windows\system32\cabview.dll
2010-05-17 22:40:42 171520 ----a-w- c:\windows\system32\wintrust.dll
2010-05-14 23:49:24 0 d-----w- c:\users\gregg\appdata\roaming\Tibia
2010-05-05 08:24:16 0 ----a-w- c:\users\gregg\appdata\roaming\wklnhst.dat
==================== Find3M ====================
2010-05-26 08:13:28 2484 ----a-w- c:\windows\bthservsdp.dat
2010-05-23 04:42:17 140832 ----a-w- c:\windows\system32\drivers\nvstor32.sys
2010-04-20 16:52:36 242896 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-03-22 16:24:41 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2010-03-22 16:24:41 12464 ----a-w- c:\windows\system32\avgrsstx(8558).dll
2010-02-11 06:31:30 51200 ----a-w- c:\windows\inf\infpub.dat
2010-02-11 06:31:29 143360 ----a-w- c:\windows\inf\infstrng.dat
2010-02-11 06:31:28 86016 ----a-w- c:\windows\inf\infstor.dat
2009-01-20 14:38:49 145 --sha-w- c:\program files\desktop.ini
2008-06-14 15:59:28 665600 ----a-w- c:\windows\inf\drvindex.dat
2006-11-02 12:42:02 30674 ----a-w- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 12:42:02 30674 ----a-w- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 12:42:02 287440 ----a-w- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 12:42:02 287440 ----a-w- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfc.dat
2009-10-24 02:56:06 245760 --sha-w- c:\windows\serviceprofiles\localservice\appdata\roaming\microsoft\windows\ietldcache\index.dat
2010-02-11 01:08:40 245760 --sha-w- c:\windows\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\ietldcache\index.dat
============= FINISH: 3:17:53.19 ===============
___________________________________________________________________
Attach.txt
DDS (Ver_10-03-17.01) - NTFSx86
Run by Gregg at 3:16:08.09 on Sat 05/29/2010
Internet Explorer: 8.0.6001.18904
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.2942.1431 [GMT -7:00]
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: AVG Anti-Virus Free *enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: AVG Anti-Spyware *disabled* (Outdated) {48F2E28D-ED66-4646-9C11-B3055B0AF604}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\LEXBCES.EXE
C:\Windows\System32\LEXPPS.EXE
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Program Files\Cobian Backup 10\cbVSCService.exe
C:\Windows\system32\lxbvcoms.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\Windows\System32\tcpsvcs.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\PROGRA~1\SPEEDB~2\VideoAcceleratorService.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\AVG\AVG9\avgemc.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\taskeng.exe
C:\PROGRA~1\SPEEDB~2\VideoAcceleratorEngine.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Windows\RtHDVCpl.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Windows\System32\wpcumi.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\AVG\AVG9\avgtray.exe
C:\Program Files\DAP\DAP.exe
C:\Program Files\Eraser\Eraser.exe
C:\Program Files\Uniblue\ProcessQuickLink 2\ProcessQuickLink2.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Windows Mail\WinMail.exe
C:\Program Files\Windows Live\Mail\wlmail.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\Gregg\Desktop\dds.scr
C:\Windows\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
uSearch Page =
uStart Page = hxxp://www.google.com/
uDefault_Page_URL = hxxp://www.gateway.com/g/startpage.html?Ch=Retail&SubCH=nofound&Br=GTW&Loc=ENG_US&Sys=DTP&M=GT5670
uSearch Bar =
mStart Page = hxxp://www.gateway.com/g/startpage.html?Ch=Retail&SubCH=nofound&Br=GTW&Loc=ENG_US&Sys=DTP&M=GT5670
mDefault_Page_URL = hxxp://www.gateway.com/g/startpage.html?Ch=Retail&SubCH=nofound&Br=GTW&Loc=ENG_US&Sys=DTP&M=GT5670
uInternet Settings,ProxyOverride = *.local
mSearchAssistant =
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: SBCONVERT Class: {31b27f2d-6bc6-451b-b3d2-4eab36b2fc3b} - c:\program files\speedbit video downloader\toolbar\tbcore3.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: DAPIELoader Class: {ff6c3cf0-4b15-11d1-abed-709549c10000} - c:\progra~1\dap\DAPIEL~1.DLL
BHO: GrabberObj Class: {ff7c3cf0-4b15-11d1-abed-709549c10000} - c:\progra~1\speedb~1\toolbar\grabber.dll
TB: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
TB: SpeedBit Video Downloader: {0329e7d6-6f54-462d-93f6-f5c3118badf2} - c:\program files\speedbit video downloader\toolbar\tbcore3.dll
TB: {8B79EE88-E62D-4AA8-B530-CC357BA112B7} - No File
TB: {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - No File
TB: {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
uRun: [DownloadAccelerator] "c:\program files\dap\DAP.EXE" /STARTUP
uRun: [Eraser] c:\program files\eraser\Eraser.exe -hide
uRun: [DU Meter] c:\program files\du meter\DUMeter.exe
uRun: [Uniblue ProcessQuickLink 2] "c:\program files\uniblue\processquicklink 2\ProcessQuickLink2.exe" /autostart
mRun: [RtHDVCpl] RtHDVCpl.exe
mRun: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [WPCUMI] c:\windows\system32\WpcUmi.exe
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [AVG9_TRAY] c:\progra~1\avg\avg9\avgtray.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\logite~1.lnk - c:\program files\logitech\setpoint\SetPoint.exe
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: &Clean Traces - c:\program files\dap\privacy package\dapcleanerie.htm
IE: &Download with &DAP - c:\program files\dap\dapextie.htm
IE: &ieSpell Options - c:\program files\iespell\iespell.dll/SPELLOPTION.HTM
IE: Check &Spelling - c:\program files\iespell\iespell.dll/SPELLCHECK.HTM
IE: Download &all with DAP - c:\program files\dap\dapextie2.htm
IE: Download &Flash Movies - c:\program files\flash2x\flash hunter\save.htm
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office10\EXCEL.EXE/3000
IE: Lookup on Merriam Webster - file://c:\program files\iespell\Merriam Webster.HTM
IE: Lookup on Wikipedia - file://c:\program files\iespell\wikipedia.HTM
IE: {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - res://c:\program files\iespell\iespell.dll/SPELLCHECK.HTM
IE: {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - res://c:\program files\iespell\iespell.dll/SPELLOPTION.HTM
IE: {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - c:\program files\bodog poker\BPGame.exe
LSP: c:\windows\system32\wpclsp.dll
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/FacebookPhotoUploader5.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {2042B57E-6336-459E-B7CE-2A0F6C9E6AF8} - file:///E:/win/setup/iaieplay.dll
DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} - hxxp://photos.walmart.com/WalmartActivia.cab
DPF: {48DD0448-9209-4F81-9F6D-D83562940134} - hxxp://lads.myspace.com/upload/MySpaceUploader1006.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {C52439A0-2693-4E40-B141-9F9AD5257241} - hxxps://ediagnostics.lexmark.com/serval.cab
DPF: {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_04-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll
AppInit_DLLs: avgrsstx.dll
============= SERVICES / DRIVERS ===============
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-1-2 216200]
R1 AvgMfx86;AVG Minifilter x86 Resident Driver;c:\windows\system32\drivers\avgmfx86.sys [2008-4-14 29512]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2010-3-22 242896]
R2 avg9emc;AVG Free E-mail Scanner;c:\program files\avg\avg9\avgemc.exe [2010-3-22 916760]
R2 avg9wd;AVG Free WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2010-3-22 308064]
R2 cbVSCService;Cobian Backup 10 Volume Shadow Copy service;c:\program files\cobian backup 10\cbVSCService.exe [2010-5-25 67584]
R2 lxbv_device;lxbv_device;c:\windows\system32\lxbvcoms.exe -service --> c:\windows\system32\lxbvcoms.exe -service [?]
R2 VideoAcceleratorService;VideoAcceleratorService;c:\progra~1\speedb~2\videoacceleratorservice.exe -start -scm --> c:\progra~1\speedb~2\VideoAcceleratorService.exe -start -scm [?]
R3 SaiH075C;SaiH075C;c:\windows\system32\drivers\SaiH075C.sys [2008-4-3 176640]
S2 AdobeActiveFileMonitor;Adobe Active File Monitor;c:\program files\adobe\photoshop elements 3.0\photoshopelementsfileagent.exe --> c:\program files\adobe\photoshop elements 3.0\PhotoshopElementsFileAgent.exe [?]
S2 gupdate1c996687543bade;Google Update Service (gupdate1c996687543bade);c:\program files\google\update\GoogleUpdate.exe [2009-2-24 133104]
S2 PhotoshopElementsDeviceConnect;Photoshop Elements Device Connect;c:\program files\adobe\photoshop elements 3.0\photoshopelementsdeviceconnect.exe --> c:\program files\adobe\photoshop elements 3.0\PhotoshopElementsDeviceConnect.exe [?]
S3 CoachVid;CoachVid;c:\windows\system32\drivers\CoachVid.sys [2009-6-19 45344]
S3 NETw2v32;Intel® PRO/Wireless 2200BG Network Connection Driver for Windows Vista;c:\windows\system32\drivers\NETw2v32.sys [2006-11-2 2589184]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\gamemon.des -service --> c:\windows\system32\GameMon.des -service [?]
=============== Created Last 30 ================
2010-05-26 07:26:04 20 ----a-w- c:\users\gregg\defogger_reenable
2010-05-26 06:54:07 0 d-----w- c:\program files\Cobian Backup 10
2010-05-26 05:40:46 2048 ----a-w- c:\windows\system32\tzres.dll
2010-05-22 09:57:02 0 d-----w- c:\windows\system32\MpEngineStore
2010-05-17 23:00:43 176 ----a-w- c:\windows\system32\MRT.INI
2010-05-17 22:51:27 24064 ----a-w- c:\windows\system32\nshhttp.dll
2010-05-17 22:51:26 411136 ----a-w- c:\windows\system32\drivers\http.sys
2010-05-17 22:51:25 31232 ----a-w- c:\windows\system32\httpapi.dll
2010-05-17 22:43:12 523776 ----a-w- c:\windows\system32\RMActivate_isv.exe
2010-05-17 22:43:12 511488 ----a-w- c:\windows\system32\RMActivate.exe
2010-05-17 22:43:10 347136 ----a-w- c:\windows\system32\RMActivate_ssp.exe
2010-05-17 22:43:09 472576 ----a-w- c:\windows\system32\secproc_isv.dll
2010-05-17 22:43:09 472064 ----a-w- c:\windows\system32\secproc.dll
2010-05-17 22:43:09 346624 ----a-w- c:\windows\system32\RMActivate_ssp_isv.exe
2010-05-17 22:43:09 329216 ----a-w- c:\windows\system32\msdrm.dll
2010-05-17 22:43:09 151040 ----a-w- c:\windows\system32\secproc_ssp_isv.dll
2010-05-17 22:43:09 151040 ----a-w- c:\windows\system32\secproc_ssp.dll
2010-05-17 22:41:23 898952 ----a-w- c:\windows\system32\drivers\tcpip.sys
2010-05-17 22:41:23 25088 ----a-w- c:\windows\system32\drivers\tunnel.sys
2010-05-17 22:41:23 190464 ----a-w- c:\windows\system32\iphlpsvc.dll
2010-05-17 22:40:56 62464 ----a-w- c:\windows\system32\l3codeca.acm
2010-05-17 22:40:54 3598216 ----a-w- c:\windows\system32\ntkrnlpa.exe
2010-05-17 22:40:53 3545992 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-05-17 22:40:49 738304 ----a-w- c:\windows\system32\inetcomm.dll
2010-05-17 22:40:48 78848 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2010-05-17 22:40:47 212992 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2010-05-17 22:40:47 105984 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-05-17 22:40:46 420352 ----a-w- c:\windows\system32\vbscript.dll
2010-05-17 22:40:45 98304 ----a-w- c:\windows\system32\cabview.dll
2010-05-17 22:40:42 171520 ----a-w- c:\windows\system32\wintrust.dll
2010-05-14 23:49:24 0 d-----w- c:\users\gregg\appdata\roaming\Tibia
2010-05-05 08:24:16 0 ----a-w- c:\users\gregg\appdata\roaming\wklnhst.dat
==================== Find3M ====================
2010-05-26 08:13:28 2484 ----a-w- c:\windows\bthservsdp.dat
2010-05-23 04:42:17 140832 ----a-w- c:\windows\system32\drivers\nvstor32.sys
2010-04-20 16:52:36 242896 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-03-22 16:24:41 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2010-03-22 16:24:41 12464 ----a-w- c:\windows\system32\avgrsstx(8558).dll
2010-02-11 06:31:30 51200 ----a-w- c:\windows\inf\infpub.dat
2010-02-11 06:31:29 143360 ----a-w- c:\windows\inf\infstrng.dat
2010-02-11 06:31:28 86016 ----a-w- c:\windows\inf\infstor.dat
2009-01-20 14:38:49 145 --sha-w- c:\program files\desktop.ini
2008-06-14 15:59:28 665600 ----a-w- c:\windows\inf\drvindex.dat
2006-11-02 12:42:02 30674 ----a-w- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 12:42:02 30674 ----a-w- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 12:42:02 287440 ----a-w- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 12:42:02 287440 ----a-w- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfc.dat
2009-10-24 02:56:06 245760 --sha-w- c:\windows\serviceprofiles\localservice\appdata\roaming\microsoft\windows\ietldcache\index.dat
2010-02-11 01:08:40 245760 --sha-w- c:\windows\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\ietldcache\index.dat
============= FINISH: 3:17:53.19 ===============