I ran TFC,Malwarebytes Anti-Malware,SUPERAntiSpyware Free, and Eset Online Anti-virus Scanner as requested by quietman7 but the infections are still present and I still get the Virtual memory too low message. So he directed me towards this forum to request help.I followed the instructions he gave me on using defogger,DDS, and GMER.I was able to use defogger and DDS but I was unable to use GMER.When I attempted to use GMER I received these messages:
GMER
C:\WINDOWS\system32\config\system:
The process cannot access the file because it is being used by another process.
GMER
LoadDriver("C:\DOCUME~1\Sickness\LOCALS~1\Temp\ufloapow.sys")
error 0xC0000061:Access is denied.
GMER opens up with: Services,ADS,Registry,Files,C:\ all pre-selected but I am unable to select anything else.
I also received this message today:
avguard.exe-Application Error
The instruction at "0x00f6986c" referenced memory at "oxoof6986c".The memory could not be "read"
Here is the log I was able to complete:
DDS (Ver_10-03-17.01) - NTFSx86
Run by Sickness at 23:32:42.45 on Wed 09/22/2010
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.247.94 [GMT -5:00]
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: AntiVir Desktop *On-access scanning enabled* (Outdated) {AD166499-45F9-482A-A743-FDD3350758C7}
============== Running Processes ===============
svchost.exe
svchost.exe
svchost.exe
svchost.exe
svchost.exe
svchost.exe
C:\WINDOWS\Explorer.EXE
svchost.exe
svchost.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Lexmark 2500 Series\lxddmon.exe
C:\Program Files\Lexmark 2500 Series\lxddamon.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Documents and Settings\Sickness\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.com/
mWindow Title = Microsoft Internet Explorer presented by Comcast
uURLSearchHooks: H - No File
BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\tfswshx.dll
TB: {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - No File
TB: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File
TB: {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - No File
TB: {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - No File
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
uRun: [ISUSPM] "c:\program files\common files\installshield\updateservice\ISUSPM.exe" -scheduler
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [Dell QuickSet] c:\program files\dell\quickset\quickset.exe
mRun: [DVDLauncher] "c:\program files\cyberlink\powerdvd\DVDLauncher.exe"
mRun: [ISUSPM Startup] "c:\program files\common files\installshield\updateservice\ISUSPM.exe" -startup
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [DivXUpdate] "c:\program files\divx\divx update\DivXUpdate.exe" /CHECKNOW
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
mRun: [lxddmon.exe] "c:\program files\lexmark 2500 series\lxddmon.exe"
mRun: [lxddamon] "c:\program files\lexmark 2500 series\lxddamon.exe"
mRun: [FaxCenterServer] "c:\program files\lexmark fax solutions\fm3032.exe" /s
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe
IE: Crawler Search
IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office11\EXCEL.EXE/3000
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE}
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~4\office11\REFIEBAR.DLL
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://www.apple.com/qtactivex/qtplugin.cab
DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} - hxxps://support.microsoft.com/OAS/ActiveX/MSDcode.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {2AF5BD25-90C5-4EEC-88C5-B44DC2905D8B} - hxxp://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.0.5.cab
DPF: {33564D57-0000-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
DPF: {69EF49E5-FE46-4B92-B5FA-2193AB7A6B8A} - hxxp://www.acclaim.com/cabs/acclaim_v4.cab
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1190106732546
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-160-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {E856B973-45FD-4559-8F82-EAB539144667} - hxxp://pccheckup.dellfix.com/rel/41/install/gtdownde.cab
DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} - hxxp://download.mcafee.com/molbin/iss-loc/mcfscan/2,2,0,5131/mcfscan.cab
DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} - hxxp://by103fd.bay103.hotmail.msn.com/activex/HMAtchmt.ocx
Notify: avgrsstarter - avgrsstx.dll
Notify: igfxcui - igfxdev.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - No File
SecurityProviders: msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, ntoskrnl.dll
============= SERVICES / DRIVERS ===============
R1 avgio;avgio;c:\program files\avira\antivir desktop\avgio.sys [2010-9-1 11608]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2010-6-30 29584]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2010-6-30 242896]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\avira\antivir desktop\sched.exe [2010-9-1 135336]
R2 AntiVirService;Avira AntiVir Guard;c:\program files\avira\antivir desktop\avguard.exe [2010-9-1 267432]
R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2010-9-1 60936]
R2 lxdd_device;lxdd_device;c:\windows\system32\lxddcoms.exe -service --> c:\windows\system32\lxddcoms.exe -service [?]
S2 lxddCATSCustConnectService;lxddCATSCustConnectService;c:\windows\system32\spool\drivers\w32x86\3\lxddserv.exe [2010-9-17 99248]
S3 BEHRINGER_2902;usb-audio.de driver for BEHRINGER USB AUDIO;c:\windows\system32\drivers\BUSB2902.sys [2008-8-18 110272]
S3 dump_wmimmc;dump_wmimmc;c:\windows\system32\drivers\dump_wmimmc.sys [2007-3-16 155411]
S3 pgusbmme;usb-audio.de MME-Adapter;c:\windows\system32\drivers\pgusbmm3.sys --> c:\windows\system32\drivers\pgusbmm3.sys [?]
S3 pgusbwdm;usb-audio.de driver (commercial V2.6.1);c:\windows\system32\drivers\pgusbwdm.sys --> c:\windows\system32\drivers\pgusbwdm.sys [?]
=============== Created Last 30 ================
2010-09-23 04:18:29 0 ----a-w- c:\documents and settings\sickness\defogger_reenable
2010-09-17 09:44:11 40960 ----a-w- c:\windows\system32\lxddvs.dll
2010-09-17 09:43:55 344064 ----a-w- c:\windows\system32\lxddcoin.dll
2010-09-17 09:42:35 692224 ----a-w- c:\windows\system32\lxdddrs.dll
2010-09-17 09:42:35 65536 ----a-w- c:\windows\system32\lxddcaps.dll
2010-09-17 09:42:34 69632 ----a-w- c:\windows\system32\lxddcnv4.dll
2010-09-17 09:41:14 45056 ----a-w- c:\windows\system32\LXF3PMON.DLL
2010-09-17 09:41:14 32768 ----a-w- c:\windows\system32\LXF3FXPU.DLL
2010-09-17 09:40:54 36864 ----a-w- c:\windows\system32\lxf3oem.dll
2010-09-17 09:38:51 0 d-----w- c:\program files\Lexmark Fax Solutions
2010-09-17 09:38:17 44 ----a-w- c:\windows\system32\lxddrwrd.ini
2010-09-17 09:38:14 0 d-----w- c:\program files\Lexmark Toolbar
2010-09-17 09:36:58 0 d-----w- c:\program files\Abbyy FineReader 6.0 Sprint
2010-09-17 09:35:25 0 d-----w- c:\program files\Lexmark 2500 Series
2010-09-17 09:34:59 983107 ----a-w- c:\windows\system32\lxddgf.dll
2010-09-17 09:34:59 86016 ----a-w- c:\windows\system32\lxddcub.dll
2010-09-17 09:34:58 77824 ----a-w- c:\windows\system32\lxddcu.dll
2010-09-17 09:34:58 36864 ----a-w- c:\windows\system32\lxddcur.dll
2010-09-17 09:34:57 537520 ----a-w- c:\windows\system32\lxddcoms.exe
2010-09-17 09:34:56 425984 ----a-w- c:\windows\system32\lxddcomm.dll
2010-09-17 09:34:54 684032 ----a-w- c:\windows\system32\lxddcomc.dll
2010-09-17 09:34:51 394160 ----a-w- c:\windows\system32\lxddcfg.exe
2010-09-17 09:34:49 77906 ----a-w- c:\windows\system32\lxddcfg.dll
2010-09-17 09:34:49 1932 ----a-w- c:\windows\system32\lxdd.loc
2010-09-16 17:05:06 0 d-----w- c:\program files\common files\ODBC
2010-09-06 05:04:55 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-09-06 05:04:43 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-09-06 05:04:43 0 d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-09-05 07:14:54 0 d-----w- c:\program files\VideoLAN
2010-09-03 19:56:04 0 d-----w- C:\TEMP
2010-09-03 18:02:49 0 d-----w- c:\documents and settings\sickness\Program Files
2010-09-01 17:23:11 0 d-----w- c:\docume~1\sickness\applic~1\Avira
2010-09-01 17:04:29 60936 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2010-09-01 17:04:23 0 d-----w- c:\program files\Avira
2010-09-01 17:04:23 0 d-----w- c:\docume~1\alluse~1\applic~1\Avira
2010-09-01 04:01:34 0 d-----w- c:\docume~1\alluse~1\applic~1\SUPERAntiSpyware.com
2010-09-01 01:23:09 0 d-----w- c:\docume~1\sickness\applic~1\Malwarebytes
2010-09-01 01:20:10 0 d-----w- c:\docume~1\alluse~1\applic~1\Malwarebytes
2010-08-24 16:59:54 15360 ---ha-r- c:\windows\system32\drivers\NetMotCM.sys
==================== Find3M ====================
2010-09-01 18:25:10 423656 ----a-w- c:\windows\system32\deployJava1.dll
2010-08-17 13:17:06 58880 ----a-w- c:\windows\system32\spoolsv.exe
2010-07-22 15:49:15 590848 ----a-w- c:\windows\system32\rpcrt4.dll
2010-07-22 05:57:20 5120 ----a-w- c:\windows\system32\xpsp4res.dll
2010-06-30 12:31:35 149504 ----a-w- c:\windows\system32\schannel.dll
2010-06-30 07:26:21 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2007-08-22 05:56:32 104 --sh--r- c:\windows\system32\405CE41993.sys
2007-02-03 19:50:06 88 --sh--r- c:\windows\system32\9319E45C40.sys
============= FINISH: 23:33:52.42 ===============
Also I see that it says tha AVG is active on my computer but I uinstalled it months ago.
Attached Files
Edited by Orange Blossom, 24 September 2010 - 11:06 AM.



This topic is locked
Back to top








