Vista Home Premium X64
I got a virus that seems to have messed up my OS pretty good. I clean my system regularly using MBAM and Super Anti Spy Ware, and was using Avast AV. But my system got a nasty virus. I currently can't explore my system files without having to open my downloads folder from firefox. When in Normal mode, system will eventually slow to a crawl, and give me a blue screen reboot. In safe mode, my start button disappeared, and can't run most things from my desktop. I have seen a "Whitesmoke Translater" icon pop up on my desktop. I've uninstalled it twice, but its probably still floating around somewhere on the system. Some things have been turned off such as system restore, add remove programs won't launch (although I can uninstall programs using CCleaner).
Anyways, here are the requested logs from the read me first thread, for some reason the GMER logs are blank, not sure why:
ATTACH:
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_10-12-12.02)
Microsoft® Windows Vista™ Home Premium
Boot Device: \Device\HarddiskVolume2
Install Date: 3/14/2009 9:40:40 AM
System Uptime: 12/19/2010 5:42:30 PM (1 hours ago)
Motherboard: ASUSTeK Computer INC. | | P5Q-PRO
Processor: Intel(R) Core(TM)2 Quad CPU Q8300 @ 2.50GHz | LGA 775 | 2499/333mhz
==== Disk Partitions =========================
C: is FIXED (NTFS) - 466 GiB total, 257.096 GiB free.
D: is CDROM ()
E: is FIXED (NTFS) - 932 GiB total, 356.582 GiB free.
F: is FIXED (FAT32) - 75 GiB total, 0.97 GiB free.
==== Disabled Device Manager Items =============
==== System Restore Points ===================
==== Installed Programs ======================
Acrobat.com
Add or Remove Adobe Premiere Pro CS5
Adobe Acrobat 9 Pro - English, Français, Deutsch
Adobe Acrobat 9.3.0 - CPSID_52073
Adobe After Effects CS4
Adobe After Effects CS4 Presets
Adobe After Effects CS4 Third Party Content
Adobe AIR
Adobe Anchor Service CS3
Adobe Anchor Service CS4
Adobe Asset Services CS3
Adobe Bridge CS3
Adobe Bridge CS4
Adobe Bridge Start Meeting
Adobe Camera Raw 4.0
Adobe CMaps CS4
Adobe Color - Photoshop Specific CS4
Adobe Color EU Extra Settings CS4
Adobe Color JA Extra Settings CS4
Adobe Color NA Recommended Settings CS4
Adobe Color Video Profiles AE CS4
Adobe Community Help
Adobe Contribute CS4
Adobe Creative Suite 4 Master Collection
Adobe CSI CS4
Adobe Default Language CS4
Adobe Device Central CS3
Adobe Dreamweaver CS3
Adobe Dreamweaver CS4
Adobe Dynamiclink Support
Adobe Encore CS4
Adobe Encore CS4 Codecs
Adobe ExtendScript Toolkit 2
Adobe ExtendScript Toolkit CS4
Adobe Extension Manager CS3
Adobe Extension Manager CS4
Adobe Fireworks CS4
Adobe Flash CS3
Adobe Flash CS3 Professional
Adobe Flash CS4
Adobe Flash CS4 Extension - Flash Lite STI en
Adobe Flash CS4 STI-en
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Flash Video Encoder
Adobe Fonts All
Adobe Help Viewer CS3
Adobe Illustrator CS4
Adobe InDesign CS4
Adobe InDesign CS4 Application Feature Set Files (Roman)
Adobe InDesign CS4 Common Base Files
Adobe InDesign CS4 Icon Handler
Adobe Linguistics CS3
Adobe Linguistics CS4
Adobe Media Encoder CS4
Adobe Media Encoder CS4 Additional Exporter
Adobe Media Encoder CS4 Exporter
Adobe Media Encoder CS4 Importer
Adobe Media Player
Adobe MotionPicture Color Files CS4
Adobe OnLocation CS4
Adobe Output Module
Adobe PDF Library Files CS4
Adobe Photoshop CS3
Adobe Reader 9.2
Adobe Search for Help
Adobe Service Manager Extension
Adobe Setup
Adobe SGM CS4
Adobe Shockwave Player 11.5
Adobe SING CS4
Adobe Soundbooth CS4
Adobe Soundbooth CS4 Codecs
Adobe Stock Photos CS3
Adobe Type Support CS4
Adobe Update Manager CS3
Adobe Update Manager CS4
Adobe Version Cue CS3 Client
Adobe WinSoft Linguistics Plugin
Adobe XMP Panels CS3
Adobe XMP Panels CS4
AdobeColorCommonSetCMYK
AdobeColorCommonSetRGB
Apple Application Support
Apple Software Update
ArcSoft TotalMedia Theatre 3
Ashampoo ClipFinder HD 2.03
Atheros Communications Inc.(R) AR8121/AR8113/AR8114 Gigabit/Fast Ethernet Driver
Boris Continuum Complete AE 6
Camtasia Studio 7
Canon MP Navigator EX 2.0
Canon Utilities Easy-PhotoPrint EX
Canon Utilities My Printer
Carmageddon 2
Catalyst Control Center - Branding
Catalyst Control Center Core Implementation
Catalyst Control Center Graphics Full Existing
Catalyst Control Center Graphics Full New
Catalyst Control Center Graphics Light
Catalyst Control Center Graphics Previews Common
Catalyst Control Center Graphics Previews Vista
Catalyst Control Center HydraVision Full
Catalyst Control Center InstallProxy
ccc-core-static
CCC Help English
CCleaner (remove only)
Connect
Coupon Printer for Windows
CuteFTP 8 Professional
CyberLink PhotoNow
CyberLink PowerDirector
CyberLink PowerProducer
DirectX 9 Runtime
Disk Heal
Dragon Age: Origins
DVRMSToolbox
Facebook Plug-In
FairStars Audio Converter 1.46
GDR 4053 for SQL Server Database Services 2005 ENU (KB970892)
GDR 4053 for SQL Server Tools and Workstation Components 2005 ENU (KB970892)
Gigabyte Wireless LAN Card
Google Earth Plug-in
Google Gears
Google Update Helper
Halo 2 for Windows Vista
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Jaadu VNC Connect
Jasc Paint Shop Pro 9
Java(TM) 6 Update 17
K-Lite Mega Codec Pack 6.4.0
kuler
Last.fm 1.5.4.27091
Lifextender
Magic ISO Maker v5.3 (build 0221)
Malwarebytes' Anti-Malware
Microsoft Choice Guard
Microsoft Games for Windows - LIVE Redistributable
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office Professional Edition 2003
Microsoft Office Project 2007 Service Pack 2 (SP2)
Microsoft Office Project MUI (English) 2007
Microsoft Office Project Standard 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Silverlight
Microsoft SQL Server 2005
Microsoft SQL Server 2005 Express Edition (SQLEXPRESS)
Microsoft SQL Server 2005 Tools Express Edition
Microsoft SQL Server Setup Support Files (English)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft_VC80_ATL_x86
Microsoft_VC80_CRT_x86
Microsoft_VC80_MFC_x86
Microsoft_VC80_MFCLOC_x86
Microsoft_VC90_ATL_x86
Microsoft_VC90_CRT_x86
Microsoft_VC90_MFC_x86
Mozilla Firefox (3.6.13)
MSVCRT
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
Netflix in Windows Media Center
NVIDIA PhysX
Octoshape add-in for Adobe Flash Player
Orb
Orb Runtime libraries
PDF Settings CS4
Photoshop Camera Raw
Pixel Bender Toolkit
PocketControl
PowerISO
PxMergeModule
Quake 4(TM)
QuickTime
Realtek High Definition Audio Driver
Roxio Activation Module
Roxio BackOnTrack
Roxio CinePlayer
Roxio CinePlayer Decoder Pack
Roxio Creator 2009
Roxio File Backup
Roxio Update Manager
Safari
Security Update for 2007 Microsoft Office System (KB969559)
Security Update for 2007 Microsoft Office System (KB976321)
Security Update for 2007 Microsoft Office System (KB982312)
Security Update for Microsoft Office system 2007 (972581)
Security Update for Microsoft Office system 2007 (KB974234)
ShowAnalyzer
Skins
SmartSound Quicktracks Plugin
Spelling Dictionaries Support For Adobe Reader 9
Suite Shared Configuration CS4
SUPERAntiSpyware Free Edition
Total Recorder 7.1
Uninstall Mystical
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Vegas Movie Studio Platinum 9.0
Visual Studio 2008 x64 Redistributables
Winamp
Winamp Application Detect
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live Messenger
Windows Live Sign-in Assistant
Windows Live Upload Tool
Windows Media Player Firefox Plugin
World of Warcraft FREE Trial
Yahoo! Messenger
Yahoo! Software Update
==== End Of File ===========================
DDS:
DDS (Ver_10-12-12.02) - NTFS_AMD64 NETWORK
Run by Administrator at 18:35:21.28 on Sun 12/19/2010
Internet Explorer: 8.0.6001.18928 BrowserJavaVersion: 1.6.0_17
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.4094.3005 [GMT -5:00]
AV: avast! antivirus *Disabled/Updated* {C37D8F93-0602-E43C-40AA-47DAD597F308}
SP: avast! antivirus *Disabled/Updated* {781C6E77-2038-EBB2-7A1A-7CA8AE10B9B5}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\mike.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Windows\explorer.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Windows\system32\Taskmgr.exe
C:\Windows\system32\mmc.exe
C:\Users\Administrator\Desktop\dds.scr
C:\Windows\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
uInternet Settings,ProxyOverride = <local>;*.local
uInternet Settings,ProxyServer = http=127.0.0.1:5555
mURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - C:\Program Files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: {218042f9-fc69-f292-a8c8-d08a6c1fd09f} - C:\Windows\SysWow64\config\systemprofile\AppData\Local\asohediq.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
TB: Contribute Toolbar: {517bdde4-e3a7-4570-b21e-2b52b6139fc7} - C:\Program Files (x86)\Adobe\/Adobe Contribute CS4/contributeieplugin.dll
TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - C:\Program Files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll
uRun: [AdobeBridge]
uRun: [ehTray.exe] C:\Windows\ehome\ehTray.exe
mRun: [<NO NAME>]
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Java\jre6\bin\jusched.exe"
mRunServices: [exe1] C:\Users\ADMINI~1\AppData\Local\Temp\exe1.exe
mRunServices: [RoxWatch11FormatLoaderECDC8.0.0.47] c:\program files (x86)\common files\roxio shared\11.0\sharedcom\formatloadermdcroxshellviewbrowser.exe
mRunServices: [OrderPurchase] c:\program files (x86)\adobe\acrobat 9.0\designer 8.2\de\samples\forms\purchase order\images\orderpurchase.exe
mRunServices: [resourcesMicrosoft] "C:\Program Files (x86)\Microsoft Silverlight\4.0.50524.0\fr\mscorrcresources.exe"
mRunServices: [SUPERAntiSpywareUpdate1001040] c:\users\admini~1\appdata\local\temp\exe1.exe
mRunServices: [AdobeU3D8B4] "C:\Program Files (x86)\Adobe\Adobe After Effects CS4\Support Files\(AdobePSL plug-ins)\windows\fileformats\AdobeU3D8B.exe"
mRunServices: [PressCenter] c:\program files (x86)\adobe\adobe photoshop cs3\plug-ins\dreamsuite\effect presets\photopress\centerpress9848.exe
mRunServices: [InstallShieldobjectps] "C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\ObjectInstallShield.exe"
mRunServices: [Photoshop3DEnginePhotoshop3DEngine11.011.02008081320080813..44120080813020000] c:\program files (x86)\adobe\adobe after effects cs4\support files\(adobepsl plug-ins)\windows\fileformats\adobeu3d8b.exe
dRun: [MqmPiZ] C:\Windows\TEMP\ls5wpc.exe
dRun: [MqmPoc] C:\Windows\TEMP\debug.exe
dRun: [MqmPZP] C:\Windows\TEMP\gdi32.exe
dRun: [MqmPf] C:\Windows\TEMP\win.exe
dRun: [MqmPz9] C:\Windows\TEMP\nvsvc32.exe
dRun: [MqmPxb] C:\Windows\TEMP\sysedit.exe
dRun: [Mqsrc] C:\Windows\login.exe
dRun: [Mque] C:\Windows\user.exe
dRun: [Mqrtc] C:\Windows\hexdump.exe
dRun: [Mqutc] C:\Windows\sysedit.exe
dRun: [MqmPqg] C:\Windows\TEMP\hexdump.exe
dRun: [Mqqsc] C:\Windows\drweb.exe
dRun: [MqmPb] C:\Windows\TEMP\mdm.exe
dRun: [Mqrta] C:\Windows\install.exe
dRun: [MqmPxc] C:\Windows\TEMP\smss.exe
dRun: [Mqvpe] C:\Windows\winamp.exe
dRun: [MqrMc] C:\Windows\gdi32.exe
dRun: [MqmPY] C:\Windows\TEMP\cmd.exe
dRun: [MqmPsb] C:\Windows\TEMP\drweb.exe
dRun: [Mqvre] C:\Windows\wininst.exe
dRun: [Mquvc] C:\Windows\setup.exe
dRun: [Mqqoc] C:\Windows\debug.exe
dRun: [MqmPvZ] C:\Windows\TEMP\install.exe
dRun: [MqmPy19ows\TEMP\2801464912.exe] C:\Windows\TEMP\2801464912.exe
dRun: [MqmP12/ows\TEMP\2397748736.exe] C:\Windows\TEMP\2397748736.exe
dRun: [MqmPz1Aows\TEMP\4281299296.exe] C:\Windows\TEMP\4281299296.exe
dRun: [MqmP10/ows\TEMP\3299524848.exe] C:\Windows\TEMP\3299524848.exe
dRun: [MqmPrc] C:\Windows\TEMP\winamp.exe
dRun: [ehphihhq] C:\Windows\TEMP\roaamyqqq\kwtesnbaffm.exe
dRunOnce: [FlashPlayerUpdate] C:\Windows\SysWow64\Macromed\Flash\FlashUtil10c.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
dPolicies-system: DisableRegistryTools = 1 (0x1)
IE: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~1\OFFICE11\EXCEL.EXE/3000
IE: {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - {0B4350D1-055F-47A3-B112-5F2F2B0D6F08} - C:\Program Files (x86)\Google\Google Gears\Internet Explorer\0.5.36.0\gears.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~1\OFFICE11\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files (x86)\AVG\AVG10\Toolbar\IEToolbar.dll
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG10\avgpp.dll
Notify: !SASWinLogon - C:\Program Files (x86)\SUPERAntiSpyware\SASWINLO.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - C:\Program Files (x86)\SUPERAntiSpyware\SASSEH.DLL
BHO-X64: AVG Safe Search: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG10\avgssiea.dll
BHO-X64: WormRadar.com IESiteBlocker.NavFilter - No File
TB-X64: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File
mRun-x64: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun-x64: [RtHDVCpl] RAVCpl64.exe
================= FIREFOX ===================
FF - ProfilePath - C:\Users\ADMINI~1\AppData\Roaming\Mozilla\Firefox\Profiles\dhecvdft.default\
FF - prefs.js: browser.search.defaulturl - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&invocationType=tb50ffwinampie7&query=
FF - prefs.js: browser.search.selectedEngine - Winamp Search
FF - prefs.js: browser.startup.homepage - hxxp://google.com
FF - prefs.js: keyword.URL - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&invocationType=tb50ffwinampab&query=
FF - component: C:\Program Files (x86)\AVG\AVG10\Firefox\components\avgssff.dll
FF - component: C:\Program Files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: C:\Program Files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: C:\Program Files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: C:\Program Files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll
FF - component: C:\Program Files (x86)\Google\Google Gears\Firefox\lib\ff36\gears.dll
FF - plugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: C:\Program Files (x86)\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: C:\Program Files (x86)\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npCouponPrinter.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npMozCouponPrinter.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npwachk.dll
FF - plugin: C:\Users\Administrator\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - C:\Program Files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: XULRunner: {F5B5829B-74DA-489F-834F-B010DDDFC2C8} - C:\Users\Administrator\AppData\Local\{F5B5829B-74DA-489F-834F-B010DDDFC2C8}
FF - Ext: AVG Safe Search: {3f963a5b-e555-4543-90e2-c3908898db71} - C:\Program Files (x86)\AVG\AVG10\Firefox
FF - Ext: AVG Security Toolbar em:version=6.010.023.001 em:displayname=AVG Security Toolbar em:iconURL=chrome://tavgp/skin/logo.ico em:creator=AVG Technologies em:description=AVG Security Toolbar em:homepageURL=http://www.avg.com >: avg@igeared - C:\Program Files (x86)\AVG\AVG10\Toolbar\Firefox\avg@igeared
FF - Ext: XULRunner: {B62A3DC8-8C77-46B8-BDAE-CD9440DCEE4B} - C:\Windows\system32\config\systemprofile\AppData\Local\{B62A3DC8-8C77-46B8-BDAE-CD9440DCEE4B}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: <?xmlversion=1.0?><RDF xmlns=http://www.w3.org/1999/02/22-rdf-syntax-ns# xmlns:em=http://www.mozilla.org/2004/em-rdf#><Description about=urn:mozilla:install-manifest><em:id>{43c35458-c907-439b-bcfd-07d373834689}: {43c35458-c907-439b-bcfd-07d373834689} - %profile%\extensions\{43c35458-c907-439b-bcfd-07d373834689}
FF - Ext: DownloadHelper: {b9db16a4-6edc-47ec-a1f4-b86292ed211d} - %profile%\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
---- FIREFOX POLICIES ----
FF - user.js: browser.sessionstore.resume_from_crash - false
FF - user.js: yahoo.homepage.dontask - true
============= SERVICES / DRIVERS ===============
R0 AVGIDSEH;AVGIDSEH;C:\Windows\System32\drivers\AVGIDSEH.sys [2010-9-13 27216]
R0 Avgrkx64;AVG Anti-Rootkit Driver;C:\Windows\System32\drivers\avgrkx64.sys [2010-9-7 30288]
R0 PxHlpa64;PxHlpa64;C:\Windows\System32\drivers\PxHlpa64.sys [2009-3-27 55280]
R1 Avgfwfd;AVG network filter service;C:\Windows\System32\drivers\avgfwd6a.sys [2010-7-12 57696]
R1 Avgtdia;AVG TDI Driver;C:\Windows\System32\drivers\avgtdia.sys [2010-11-9 382032]
R3 rt61x64;Gigabyte RT61 Wireless Driver for Windows Vista;C:\Windows\System32\drivers\netr6164.sys [2009-6-10 393216]
S1 Avgldx64;AVG AVI Loader Driver;C:\Windows\System32\drivers\avgldx64.sys [2010-9-7 305232]
S1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;C:\Windows\System32\drivers\avgmfx64.sys [2010-9-7 41040]
S1 SASDIFSV;SASDIFSV;C:\Program Files (x86)\SUPERAntiSpyware\sasdifsv.sys [2010-2-17 12872]
S1 SASKUTIL;SASKUTIL;C:\Program Files (x86)\SUPERAntiSpyware\SASKUTIL.SYS [2010-5-6 67656]
S2 avgfws;AVG Firewall;C:\Program Files (x86)\AVG\AVG10\avgfws.exe [2010-11-9 3229728]
S2 AVGIDSAgent;AVGIDSAgent;C:\Program Files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe [2010-11-10 6127184]
S2 avgwd;AVG WatchDog;C:\Program Files (x86)\AVG\AVG10\avgwdsvc.exe [2010-10-22 265400]
S2 ftpsvc;Microsoft FTP Service;C:\Windows\system32\svchost.exe -k ftpsvc [2008-1-20 27648]
S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2009-9-29 133104]
S2 Roxio Upnp Server 11;Roxio Upnp Server 11;C:\Program Files (x86)\Roxio Creator 2009\Digital Home 11\RoxioUpnpService11.exe [2008-8-13 367088]
S2 RoxLiveShare11;LiveShare P2P Server 11;C:\Program Files (x86)\Common Files\Roxio Shared\11.0\SharedCOM\RoxLiveShare11.exe [2008-8-13 309744]
S2 RoxWatch11;Roxio Hard Drive Watcher 11;C:\Program Files (x86)\Common Files\Roxio Shared\11.0\SharedCOM\RoxWatch11.exe [2008-8-13 170480]
S2 SensticPocketService;Senstic Pocket Service;C:\Program Files (x86)\Senstic\PocketControl\SensticPocketServiceWin.exe [2010-3-3 61560]
S2 ServiceAceSpy;SCfortify;C:\Windows\SysWOW64\SCForte.exe --> C:\Windows\SysWOW64\SCForte.exe [?]
S2 uvnc_service;uvnc_service;C:\Program Files\UltraVNC\winvnc.exe [2009-11-3 1772472]
S3 AVG Security Toolbar Service;AVG Security Toolbar Service;C:\Program Files (x86)\AVG\AVG10\Toolbar\ToolbarBroker.exe [2010-12-8 517448]
S3 AVGIDSDriver;AVGIDSDriver;C:\Windows\System32\drivers\AVGIDSDriver.sys [2010-8-19 133712]
S3 AVGIDSFilter;AVGIDSFilter;C:\Windows\System32\drivers\AVGIDSFilter.sys [2010-8-19 35920]
S3 avshws;Senstic PocketCam;C:\Windows\System32\drivers\camsource64.sys [2010-3-3 31304]
S3 clr_optimization_v2.0.50727_64;Microsoft .NET Framework NGEN v2.0.50727_X64;C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe [2010-1-7 89920]
S3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;C:\Program Files (x86)\Dragon Age\bin_ship\daupdatersvc.service.exe [2010-3-4 25832]
S3 ENTECH64;ENTECH64;C:\Windows\System32\drivers\Entech64.sys [2009-3-14 12744]
S3 Netaapl;Apple Mobile Device Ethernet Service;C:\Windows\System32\drivers\netaapl64.sys [2009-8-28 21504]
S3 NPF;NetGroup Packet Filter Driver;C:\Windows\System32\drivers\npf.sys [2009-11-22 40464]
S3 PerfHost;Performance Counter DLL Host;C:\Windows\SysWOW64\perfhost.exe [2008-1-20 19968]
S3 PocketAudio;Senstic PocketAudio (WDM);C:\Windows\System32\drivers\senaudio64.sys [2010-3-2 37192]
S3 Roxio UPnP Renderer 11;Roxio UPnP Renderer 11;C:\Program Files (x86)\Roxio Creator 2009\Digital Home 11\RoxioUPnPRenderer11.exe [2008-8-13 313840]
S3 RoxMediaDB11;RoxMediaDB11;C:\Program Files (x86)\Common Files\Roxio Shared\11.0\SharedCOM\RoxMediaDB11.exe [2009-3-3 1122304]
S3 SwitchBoard;Adobe SwitchBoard;C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-2-19 517096]
S3 TotRec7;Total Recorder WDM audio driver;C:\Windows\System32\drivers\TotRec7.sys [2008-10-27 178696]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2010-4-19 50688]
S3 WMSvc;Web Management Service;C:\Windows\System32\inetsrv\WMSvc.exe [2008-1-20 12288]
S4 DTBService;DTBService;C:\Program Files (x86)\DVRMSToolbox\DTBFWService.exe [2009-10-20 20480]
=============== File Associations ===============
JSEFile=%SystemRoot%\SysWow64\CScript.exe "%1" %*
VBEFile=%SystemRoot%\SysWow64\CScript.exe "%1" %*
VBSFile=%SystemRoot%\SysWow64\CScript.exe "%1" %*
=============== Created Last 30 ================
2010-12-18 23:03:48 -------- d-----w- C:\Users\ADMINI~1\AppData\Roaming\WhiteSmokeTranslator
2010-12-16 18:25:57 82434 ----a-w- C:\PROGRA~3\420O87fA.exe
2010-12-10 05:58:28 -------- d-----w- C:\Program Files (x86)\Disk Heal
2010-12-09 04:16:47 -------- d-----w- C:\Users\ADMINI~1\AppData\Local\AVG Security Toolbar
2010-12-09 03:01:49 749832 ----a-w- C:\PROGRA~3\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight-6\SpotlightResources.dll
2010-12-09 02:44:54 -------- d--h--w- C:\$AVG
2010-12-09 02:14:03 -------- d-----w- C:\Users\ADMINI~1\AppData\Roaming\AVG10
2010-12-09 02:12:55 -------- d--h--w- C:\PROGRA~3\Common Files
2010-12-09 02:12:36 -------- d-----w- C:\PROGRA~3\AVG Security Toolbar
2010-12-09 02:12:06 -------- d-----w- C:\Windows\SysWow64\drivers\AVG
2010-12-09 02:11:25 -------- d-----w- C:\Windows\System32\drivers\AVG
2010-12-09 02:11:25 -------- d-----w- C:\PROGRA~3\AVG10
2010-12-09 02:09:13 -------- d-----w- C:\Program Files (x86)\AVG
2010-12-08 23:59:50 -------- d-----w- C:\PROGRA~3\MFAData
2010-12-08 05:25:07 3079168 ----a-w- C:\Windows\mike.exe
2010-12-08 03:58:42 -------- d-----w- C:\PROGRA~3\Alwil Software
2010-12-04 06:01:37 416128 ----a-w- C:\PROGRA~3\Microsoft\eHome\Packages\NetTV\Browse-4\NetTVResources.dll
2010-12-04 06:01:34 652296 ----a-w- C:\PROGRA~3\Microsoft\eHome\Packages\SportsTemplate\SportsTemplateCore-4\Microsoft.MediaCenter.Sports.UI.dll
2010-12-02 10:30:51 -------- d-----w- C:\Windows\SysWow64\AppLogs
2010-12-02 05:08:43 -------- d-----w- C:\Spiceworld Order_files
==================== Find3M ====================
2010-12-16 18:25:47 82434 ----a-w- C:\PROGRA~3\420O87fA.exe
2010-11-29 22:42:06 24152 ----a-w- C:\Windows\System32\drivers\mbam.sys
2010-11-12 07:00:08 0 ----a-w- C:\Windows\SysWow64\lsp3BE5.tmp
2010-11-10 03:20:56 382032 ----a-w- C:\Windows\System32\drivers\avgtdia.sys
2010-11-02 22:14:10 37628360 ----a-w- C:\Windows\System32\mrt.exe
2010-10-17 06:38:17 114 ----a-w- C:\24339.bat
2003-05-16 13:01:38 9705984 ----a-w- C:\Program Files (x86)\DS.exe
2003-05-01 18:59:32 1413120 ----a-w- C:\Program Files (x86)\DS_PlugIn.8bf
============= FINISH: 18:36:11.02 ===============
MBAM:
Malwarebytes' Anti-Malware 1.50
www.malwarebytes.org
Database version: 5309
Windows 6.0.6002 Service Pack 2 (Safe Mode)
Internet Explorer 8.0.6001.18928
12/19/2010 11:49:28 AM
mbam-log-2010-12-19 (11-49-28).txt
Scan type: Quick scan
Objects scanned: 171832
Time elapsed: 2 minute(s), 42 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 2
Registry Values Infected: 36
Registry Data Items Infected: 0
Folders Infected: 1
Files Infected: 22
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID\{B1B220C1-A503-59BD-F413-02B53A2C8954} (Trojan.ErtFor) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B1B220C1-A503-59BD-F413-02B53A2C8954} (Trojan.ErtFor) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Gwukuw (Trojan.Hiloti) -> Value: Gwukuw -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{B1B220C1-A503-59BD-F413-02B53A2C8954} (Trojan.ErtFor) -> Value: {B1B220C1-A503-59BD-F413-02B53A2C8954} -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{B1B220C1-A503-59BD-F413-02B53A2C8954} (Trojan.ErtFor) -> Value: {B1B220C1-A503-59BD-F413-02B53A2C8954} -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MqmPsd (Trojan.Downloader) -> Value: MqmPsd -> Quarantined and deleted successfully.
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MqmPsd (Trojan.Downloader) -> Value: MqmPsd -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MqmPgP (Trojan.Downloader) -> Value: MqmPgP -> Quarantined and deleted successfully.
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MqmPgP (Trojan.Downloader) -> Value: MqmPgP -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Mqpe (Trojan.Downloader) -> Value: Mqpe -> Quarantined and deleted successfully.
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Mqpe (Trojan.Downloader) -> Value: Mqpe -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MqpSc (Trojan.Downloader.Gen) -> Value: MqpSc -> Quarantined and deleted successfully.
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MqpSc (Trojan.Downloader.Gen) -> Value: MqpSc -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Mquse (Trojan.Agent) -> Value: Mquse -> Quarantined and deleted successfully.
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Mquse (Trojan.Agent) -> Value: Mquse -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MqmPtPQ (Trojan.Downloader.Gen) -> Value: MqmPtPQ -> Quarantined and deleted successfully.
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MqmPtPQ (Trojan.Downloader.Gen) -> Value: MqmPtPQ -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\uPc+kt0NbhdCxl (Trojan.Downloader.Gen) -> Value: uPc+kt0NbhdCxl -> Quarantined and deleted successfully.
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\uPc+kt0NbhdCxl (Trojan.Downloader.Gen) -> Value: uPc+kt0NbhdCxl -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MqvPc (Trojan.Downloader) -> Value: MqvPc -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MqvPcla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9) Gecko/2008052906 Firefox/3.0 (Trojan.Downloader) -> Value: MqvPcla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9) Gecko/2008052906 Firefox/3.0 -> Quarantined and deleted successfully.
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MqvPc (Trojan.Downloader) -> Value: MqvPc -> Quarantined and deleted successfully.
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MqvPcla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9) Gecko/2008052906 Firefox/3.0 (Trojan.Downloader) -> Value: MqvPcla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9) Gecko/2008052906 Firefox/3.0 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MqmPeP (Trojan.Downloader.Gen) -> Value: MqmPeP -> Quarantined and deleted successfully.
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MqmPeP (Trojan.Downloader.Gen) -> Value: MqmPeP -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MqmPqe (Trojan.Downloader.Gen) -> Value: MqmPqe -> Quarantined and deleted successfully.
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MqmPqe (Trojan.Downloader.Gen) -> Value: MqmPqe -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MqmPvc (Trojan.Downloader.Gen) -> Value: MqmPvc -> Quarantined and deleted successfully.
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MqmPvc (Trojan.Downloader.Gen) -> Value: MqmPvc -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MqmPwe (Trojan.Downloader.Gen) -> Value: MqmPwe -> Quarantined and deleted successfully.
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MqmPwe (Trojan.Downloader.Gen) -> Value: MqmPwe -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MqmPtg (Trojan.Downloader.Gen) -> Value: MqmPtg -> Quarantined and deleted successfully.
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MqmPtg (Trojan.Downloader.Gen) -> Value: MqmPtg -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MqsZ (Trojan.Downloader) -> Value: MqsZ -> Quarantined and deleted successfully.
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MqsZ (Trojan.Downloader) -> Value: MqsZ -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MqmPd (Trojan.Downloader.Gen) -> Value: MqmPd -> Quarantined and deleted successfully.
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MqmPd (Trojan.Downloader.Gen) -> Value: MqmPd -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Xbonehisuket (Trojan.Agent.U) -> Value: Xbonehisuket -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
c:\Users\administrator\AppData\Roaming\whitesmoketranslator (PUP.WhiteSmoke) -> Not selected for removal.
Files Infected:
c:\Users\administrator\AppData\Local\anacmtUR.dll (Trojan.Hiloti) -> Quarantined and deleted successfully.
c:\Windows\SysWOW64\dgl4orpym.dll (Trojan.ErtFor) -> Quarantined and deleted successfully.
c:\Windows\Temp\fcmepok.exe (Trojan.Hiloti) -> Quarantined and deleted successfully.
c:\Windows\Temp\iexplorer.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
c:\Windows\Temp\660354609.exe (Trojan.FakeAlert.Gen) -> Quarantined and deleted successfully.
c:\Windows\Temp\805278609.exe (Trojan.FakeAlert.Gen) -> Quarantined and deleted successfully.
c:\Windows\Temp\taskmgr.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\Windows\Temp\win32.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\Windows\avp.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\Windows\avp32.exe (Trojan.Downloader.Gen) -> Quarantined and deleted successfully.
c:\Windows\svchost.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Windows\Temp\bmuq44of6.exe (Trojan.Downloader.Gen) -> Quarantined and deleted successfully.
c:\Windows\System32\ev8lqr8x.dll (Trojan.Downloader.Gen) -> Quarantined and deleted successfully.
c:\Windows\win16.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\Windows\Temp\avp32.exe (Trojan.Downloader.Gen) -> Quarantined and deleted successfully.
c:\Windows\Temp\login.exe (Trojan.Downloader.Gen) -> Quarantined and deleted successfully.
c:\Windows\Temp\user.exe (Trojan.Downloader.Gen) -> Quarantined and deleted successfully.
c:\Windows\Temp\setup.exe (Trojan.Downloader.Gen) -> Quarantined and deleted successfully.
c:\Windows\Temp\wininst.exe (Trojan.Downloader.Gen) -> Quarantined and deleted successfully.
c:\Windows\mdm.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\Windows\Temp\avp.exe (Trojan.Downloader.Gen) -> Quarantined and deleted successfully.
c:\Windows\System32\config\systemprofile\AppData\Local\asohediq.dll (Trojan.Agent.U) -> Quarantined and deleted successfully.
Thanks Everyone for your help on this..