Welcome Guest
« Go to Spyware Terminator Homepage Search | Active Topics | Members | Log In | Register
help remove AVWA.dll logfile listed. Options · View
jroyal
Posted: Monday, September 14, 2009 6:00:57 PM

Rank: Rookie
Groups: Member

Joined: 9/14/2009
Posts: 1
Location: clinton nc

never lets me remove it.

Help please

Logfile of Spyware Terminator v2.5.7.140 (db:3.009.014.000)
Scan Time: 9/14/2009 6:38:24 PM  length: 277 s
Platform: WXP (5.1.0.2600)
User: Admin
Boot Mode: Normal
Scan type: Fast_Spyware_Scan
Scanned Objects: 47511 (Critical:2)
Filter: No System items, No Safe items, No Invalid items

Running Processes
wltrysvc.exe : C:\WINDOWS\system32\wltrysvc.exe
bcmwltry.exe [Dell Inc] : C:\WINDOWS\system32\bcmwltry.exe
LEXBCES.EXE [Lexmark International, Inc.] : C:\WINDOWS\system32\LEXBCES.EXE
LEXPPS.EXE [Lexmark International, Inc.] : C:\WINDOWS\system32\LEXPPS.EXE
acsd.exe [America Online, Inc.] : C:\Program Files\Common Files\AOL\ACS\acsd.exe
AppleMobileDeviceService.exe [Apple Inc.] : C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
HPZipm12.exe [HP] : C:\WINDOWS\system32\HPZipm12.exe
ViewpointService.exe [Viewpoint Corporation] : C:\Program Files\Viewpoint\Common\ViewpointService.exe
wanmpsvc.exe [America Online, Inc.] : C:\WINDOWS\wanmpsvc.exe
Apoint.exe [Alps Electric Co., Ltd.] : C:\Program Files\Apoint\Apoint.exe
lxczbmgr.exe [Lexmark International, Inc.] : C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe
WLTRAY.exe [Dell Inc] : C:\WINDOWS\system32\WLTRAY.exe
lxczbmon.exe [Lexmark International, Inc.] : C:\Program Files\Lexmark 1200 Series\lxczbmon.exe
Apntex.exe [Alps Electric Co., Ltd.] : C:\Program Files\Apoint\Apntex.exe
ymsgr_tray.exe [Yahoo! Inc.] : C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
iPodService.exe [Apple Inc.] : C:\Program Files\iPod\bin\iPodService.exe

Internet Settings
R - HKCU\Software\Microsoft\Internet Explorer\Main, Search Bar =
R - HKLM\Software\Microsoft\Internet Explorer\Main, Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R - HKLM\Software\Microsoft\Internet Explorer\Search, SearchAssistant =
R - HKLM\Software\Microsoft\Internet Explorer\Search, CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
R - HKLM\System\CurrentControlSet\Services\Tcpip\Parameters, Domain =
R - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Telephony, DomainName =

BHO
02 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} -  [Yahoo! Inc.] : C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
02 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -  [Adobe Systems Incorporated] : C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
02 - BHO:  - {8EFE0C47-A3A3-4555-A4D1-FFC8C28040EB} -  : C:\WINDOWS\system32\AVWA.dll
02 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} -  : C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll

Toolbars
03 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} -  [Yahoo! Inc.] : C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
03 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} -  : C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll

StartUps
04 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Apoint :  [Alps Electric Co., Ltd.] : C:\Program Files\Apoint\Apoint.exe
04 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, lxczbmgr.exe :  [Lexmark International, Inc.] : C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe
04 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, AppleSyncNotifier :  [Apple Inc.] : C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
04 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Dell Wireless Manager UI :  [Dell Inc] : C:\WINDOWS\system32\WLTRAY.exe

Shell Extensions
America Online - {955B7B84-5308-419c-8ED8-0B9CA3C56985} -  [America Online, Inc.] : C:\Program Files\Common Files\aolshare\shell\us\shellext.dll
Yahoo! Mail Shell Extension - {5464D816-CF16-4784-B9F3-75C0DB52B499} -  [Yahoo! Inc.] : C:\Program Files\Yahoo!\Common\YMMAPI.dll
FileTimeShlExt Class - {3FCEF010-09A4-11D4-8D3B-D12F9D3D8B02} -  [Texas Instruments Incorporated] : C:\Program Files\Common Files\TI Shared\TIConnect\TIShlExt.dll
iTunes - {B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF} -  [Apple Inc.] : C:\Program Files\iTunes\iTunesMiniPlayer.dll

Services
23 - [Agere Systems] : C:\WINDOWS\system32\DRIVERS\AGRSM.sys
23 - [America Online, Inc.] : C:\Program Files\Common Files\AOL\ACS\acsd.exe
23 - [Alps Electric Co., Ltd.] : C:\WINDOWS\system32\DRIVERS\Apfiltr.sys
23 - [Apple Inc.] : C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
23 - [Broadcom Corporation] : C:\WINDOWS\system32\DRIVERS\bcmwl5.sys
23 - [Sonic Solutions] : C:\WINDOWS\system32\drivers\drvmcdb.sys
23 - [Sonic Solutions] : C:\WINDOWS\system32\drivers\drvnddm.sys
23 - [GEAR Software Inc.] : C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys
23 - [Apple Inc.] : C:\Program Files\iPod\bin\iPodService.exe
23 - [B.H.A Co.,Ltd.] : C:\WINDOWS\system32\drivers\jfbiacqq.sys
23 - [Lexmark International, Inc.] : C:\WINDOWS\system32\LEXBCES.EXE
23 - [HP] : C:\WINDOWS\system32\HPZipm12.exe
23 - [Silicon Integrated Systems Corporation] : C:\WINDOWS\system32\DRIVERS\sisgrp.sys
23 - [Silicon Integrated Systems Corporation] : C:\WINDOWS\system32\DRIVERS\SISAGPX.sys
23 - [Silicon Integrated Systems Corporation] : C:\WINDOWS\system32\DRIVERS\srvkp.sys
23 - [SiS Corporation] : C:\WINDOWS\system32\DRIVERS\sisnic.sys
23 - [Analog Devices, Inc.] : C:\WINDOWS\system32\drivers\smwdm.sys
23 - [Crawler.com] : C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
23 - [Sonic Solutions] : C:\WINDOWS\system32\drivers\sscdbhk5.sys
23 - [Sonic Solutions] : C:\WINDOWS\system32\drivers\ssrtln.sys
23 - [Sonic Solutions] : C:\WINDOWS\system32\dla\tfsnboio.sys
23 - [Sonic Solutions] : C:\WINDOWS\system32\dla\tfsncofs.sys
23 - [Sonic Solutions] : C:\WINDOWS\system32\dla\tfsndrct.sys
23 - [Sonic Solutions] : C:\WINDOWS\system32\dla\tfsndres.sys
23 - [Sonic Solutions] : C:\WINDOWS\system32\dla\tfsnifs.sys
23 - [Sonic Solutions] : C:\WINDOWS\system32\dla\tfsnopio.sys
23 - [Sonic Solutions] : C:\WINDOWS\system32\dla\tfsnpool.sys
23 - [Sonic Solutions] : C:\WINDOWS\system32\dla\tfsnudf.sys
23 - [Sonic Solutions] : C:\WINDOWS\system32\dla\tfsnudfa.sys
23 - [Promise Technology, Inc.] : C:\WINDOWS\system32\DRIVERS\ultra.sys
23 - [Viewpoint Corporation] : C:\Program Files\Viewpoint\Common\ViewpointService.exe
23 - [America Online, Inc.] : C:\WINDOWS\system32\DRIVERS\wanatw4.sys
23 - [America Online, Inc.] : C:\WINDOWS\wanmpsvc.exe

IE URL Search Hooks
Yahoo! Toolbar - {{EF99BD32-C1FB-11D2-892F-0090271D4F88}} -  [Yahoo! Inc.] : C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
AVG Security Toolbar BHO - {{A3BC75A2-1F87-4686-AA43-5347D756017C}} -  : C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll

Threat Files
<AVWA.dll ( BHO )> (User Threat) : C:\WINDOWS\system32\AVWA.dll

Advanced Files Report
%SYSDIR%\BCMLogon.dll [Broadcom Corporation] [Wireless Network Logon Provider] MD5=FA603A4F945CB3EE00B2342EDCB605DF SIZE=172032
%SYSDIR%\wltrysvc.exe MD5=61490BFA6558C8DD3027E130D9A02D4B SIZE=65536
%SYSDIR%\bcmwltry.exe [Dell Inc] [Dell Wireless WLAN Card Wireless Network Controller] MD5=72D58BB02CD83E6B7B9A97E06B3F0F43 SIZE=872556
%SYSDIR%\AegisE5.dll [Meetinghouse Data Communications] [AEGIS Client API] MD5=82519DCB6F4F0C346F393911CF892E16 SIZE=1396831
%SYSDIR%\wltrynt.dll [Broadcom Corporation] [Wireless Notification Provider] MD5=2A5107B2F9D26192319C4515F57CEE19 SIZE=81920
%SYSDIR%\LEXBCES.EXE [Lexmark International, Inc.] [MarkVision for Windows (32 bit)] MD5=E19C8550B4C6C67FABFFD998EACF440A SIZE=311296
%SYSDIR%\lexp2p32.dll [Lexmark International, Inc.] [MarkVision for Windows (32 bit)] MD5=9F2FD42D010FE6408D202ED4139BCDCB SIZE=201216
%SYSDIR%\lex2kusb.dll [Lexmark International, Inc.] [MarkVision for Windows (32 bit)] MD5=F1E07F5BB22E4568B8E2C0159E74EFD5 SIZE=197120
%SYSDIR%\LEXPPS.EXE [Lexmark International, Inc.] [MarkVision for Windows (32 bit)] MD5=7A48C1D07A4445F622882833CAE9AB32 SIZE=174592
%SYSDIR%\LEXBCE.DLL [Lexmark International, Inc.] [MarkVision for Windows (32 bit)] MD5=2FCC7D083C925365C9D6414495F3FC01 SIZE=147456
%SYSDIR%\lxczlmpm.DLL [Printer Communication System] MD5=07B801F4067C1D33490305A7BB6E9F15 SIZE=585728
%SYSDIR%\LEXLMPM.DLL [Lexmark International, Inc.] [MarkVision for Windows (32 bit)] MD5=C2671D78109644694DEA04B845092727 SIZE=192512
%SYSDIR%\hpzlnt12.dll [HP] [HP DeskJet] MD5=52417880AC75AC4B7F4E5C3B54CA6621 SIZE=139345
%SYSDIR%\LXPRMON.DLL [Lexmark Fax Solutions Software] MD5=20F6678F35F9FDD10C4F10A3C675A3C9 SIZE=45056
%SYSDIR%\IMGMAN32.dll [Data Techniques, Inc.] [ImageMan Image Processing Toolkit] MD5=86C5AAC31EA7909121327701045F74BD SIZE=339968
%SYSDIR%\IM31IMG.DIL [Data Techniques, Inc.] [ImageMan Image Processing Toolkit] MD5=9F22E3CE1639917EB07DCC730CD0D410 SIZE=49152
%PROGRAMFILES%\Lexmark Fax Solutions\FxCtrStr.dll [Lexmark Fax Solutions Software] MD5=C5C39333DE3112A7BBCB72A9B36FFBE7 SIZE=12288
%PROGRAMFILES%\Lexmark Fax Solutions\ipcmt.dll [Lexmark Fax Solutions Software] MD5=80141D4DA3968530BCF8E9053F589D02 SIZE=32768
%SYSDIR%\LXPMONRC.DLL [Lexmark International, Inc.] [Lexmark Fax Solutions Software Print Monitor] MD5=036E0FC24621BC09DF288016BEEB1015 SIZE=12288
%SYSDIR%\spool\PRTPROCS\W32X86\DLBCPP5C.dll [Inkjet Printer] MD5=C213C40D8E9F2D1AFFBD1262CD23E026 SIZE=78336
%SYSDIR%\spool\PRTPROCS\W32X86\lxczpp5c.dll [Lexmark International Inc.] [Lexmark 1200 Series] MD5=377B06E4D94687D149084CFC592C17BB SIZE=102400
%SYSDIR%\DLBCpwr.dll [Dell Computer Corporation] [POR Monitor] MD5=BEE52E9D94C02FEFB222EFC93458EDE6 SIZE=73728
%COMMONFILES%\AOL\ACS\acsd.exe [America Online, Inc.] [AOL Connectivity Service] MD5=52E82740FDF434A625FE0AC5E119A51F SIZE=1434848
%COMMONFILES%\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [Apple Inc.] [Apple Mobile Device Service] MD5=557F35D1CA42AEA14A6690E21887A31F SIZE=144712
%SYSDIR%\HPZipm12.exe [HP] [HP PML] MD5=9D84376931440F3679BEEF2A414FA493 SIZE=69632
%PROGRAMFILES%\Viewpoint\Common\ViewpointService.exe [Viewpoint Corporation] [Viewpoint Manager] MD5=5F974FDE801C73952770736BECDE11E7 SIZE=24652
%WINDIR%\wanmpsvc.exe [America Online, Inc.] [America Online] MD5=909F2DC0DA7F57D229A05EE90647B2C3 SIZE=65536
%PROGRAMFILES%\AVG\AVG8\avgcclix.dll [AVG Technologies CZ, s.r.o.] [AVG Internet Security] MD5=DE3830402BA5644F2E5BFD0AE4D62F3F SIZE=418072
%SYSDIR%\VXDIF.DLL [Alps Electric Co., Ltd.] [Vxdif] MD5=E4435F1F2CE46C3BD5C440E2E628F2DD SIZE=87805
%PROGRAMFILES%\Apoint\Apoint.DLL [Alps Electric Co., Ltd.] [Alps Pointing-device Driver] MD5=B0A474E5A52FAD49B51F22E1C88EFADE SIZE=1110016
%PROGRAMFILES%\Apoint\EzAuto.dll [Alps Electric Co., Ltd.] [Alps Utility for Pointing device] MD5=14BB715BB0752CF6D7E0404D0C9E56CF SIZE=65536
%PROGRAMFILES%\Apoint\EzLaunch.DLL [Alps Electric Co., Ltd.] [AlpsPoint] MD5=97208E1EB657D34DFCB9097A829CF151 SIZE=204800
%SYSDIR%\SiSApCom.dll [Silicon Integrated Systems Corporation] [SiSApCom Dynamic Link Library] MD5=67A5D081506A59E3604F99D0C41F5B37 SIZE=176128
%SYSDIR%\SiSBase.dll [Silicon Integrated Systems Corporation] [SiS (R) Compatible Super VGA SiSBase Dynamic Link Library] MD5=7CEEDD60BCEFA8C984C836FC3782B7F5 SIZE=49152
%SYSDIR%\InstFunc.dll [Silicon Integrated Systems Corporation] [SiS (R) Compatible Super VGA InstFunc Dynamic Link Library] MD5=DD3E700D6EAF231CE18A6618596DB01C SIZE=6080
%SYSDIR%\SiSParse.dll [Silicon Integrated Systems Corporation] [SiS (R) Compatible Super VGA Script Parser Dynamic Link Library] MD5=3CD70BA81B2A7F18E1ED36D4C611258E SIZE=241664
%SYSDIR%\tfswapi.dll [Sonic Solutions] MD5=ED8EF5ACE62DB99ADCB3F94E11B757D4 SIZE=61492
%SYSDIR%\dla\tfswcres.dll [Sonic Solutions] MD5=269D489D49703EA3155FBEFEC1D15554 SIZE=241721
%SYSDIR%\PNCRT.dll [Real Networks, Inc] [RealPlayer/RealServer] MD5=B9807BDDD55D3D4DA93A0BF5F67E4144 SIZE=278528
%PROGRAMFILES%\Real\RealPlayer\rpap3260.dll [RealNetworks, Inc.] [RealPlayer (32-bit)] MD5=809544B4C2AF383F21EDA6A7F99E7873 SIZE=395264
%COMMONFILES%\Real\Common\pngu3266.dll [RealNetworks, Inc.] [RealPlayer (32-bit)] MD5=C569002A381628A7D563053B9C4A81BC SIZE=387072
%COMMONFILES%\Real\Common\pnrs3260.dll [RealNetworks, Inc.] [RealPlayer (32-bit)] MD5=5C6607197619A82CED0B2C1EAED0F38C SIZE=28672
%COMMONFILES%\Real\Common\rpcl3260.dll [RealNetworks, Inc.] [RealPlayer (32-bit)] MD5=2C76F63B90CE49A293625EF212DAC996 SIZE=247808
%COMMONFILES%\Real\Common\pnen3260.dll [RealNetworks, Inc.] [RealMedia® Client Core (32-bit)] MD5=FC035D73E2D57E09FB09DC6C917A6F2F SIZE=985600
%COMMONFILES%\Real\Plugins\pnxr3260.dll [RealNetworks, Inc.] [Cross Platform Resource Handler for RealMedia® (32-bit)] MD5=A794A935C65EBF3DDCD4592088D9369E SIZE=36864
%PROGRAMFILES%\Real\RealPlayer\rnms3260.dll [RealNetworks, Inc.] [RealPlayer (32-bit)] MD5=9265248E670255B8C1A792AF948099DB SIZE=146432
%COMMONFILES%\Real\Update\rnqu3260.dll [RealNetworks, Inc.] [RealPlayer (32-bit)] MD5=C8E241FB54432E49ADFDEE4C1ECCE999 SIZE=143360
%COMMONFILES%\Real\Update\rpup3260.dll [RealNetworks, Inc.] [RealPlayer (32-bit)] MD5=4DB36D0E0732C857FD66A07069A8396A SIZE=158720
%COMMONFILES%\Real\Update\upgr3260.dll [RealNetworks, Inc.] [Upgrade Support Library (32-bit)] MD5=7E99A54DB6C29A3921EFFF5D603CF9A5 SIZE=168960
%COMMONFILES%\Real\Update\setu3260.dll [RealNetworks, Inc.] [RealPlayer (32-bit)] MD5=4D9D7D974CC094069FE984E475612489 SIZE=189952
%PROGRAMFILES%\Viewpoint\Viewpoint Manager\ViewMgrCore.dll [Viewpoint Corporation] [Viewpoint Manager] MD5=9DB5F5E7DFBAA7CD9AE818EE2720E393 SIZE=407248
%PROGRAMFILES%\iTunes\iTunesHelper.Resources\en.lproj\iTunesHelperLocalized.DLL [Apple Inc.] [iTunes] MD5=1E010DA190AC46D595598BF1FD65CF69 SIZE=43520
%PROGRAMFILES%\iTunes\iTunesHelper.Resources\iTunesHelper.DLL [Apple Inc.] [iTunes] MD5=BA535069AEE17EFE727BB7CA98F821CB SIZE=42496
%PROGRAMFILES%\QuickTime\QTSystem\QuickTime.qts [Apple Inc.] [QuickTime] MD5=A84E7D2FC9648943D072C606F04FE1C4 SIZE=13234176
%COMMONFILES%\Apple\Mobile Device Support\bin\iTunesMobileDevice.dll [Apple Inc.] [iTunesMobileDevice] MD5=25C299F83029712BB2DC6CEA5DEC49D5 SIZE=1335296
%PROGRAMFILES%\Lexmark 1200 Series\lxczbmon.exe [Lexmark International, Inc.] [Button Monitor Executable] MD5=FCE51DFBA1E59E56D11C2D66EA3E2F13 SIZE=58288
%PROGRAMFILES%\Apoint\Apntex.exe [Alps Electric Co., Ltd.] [Alps Pointing-device Driver for Windows NT/2000/XP] MD5=CCA1B81492B40890E44B2B20A780EE1F SIZE=45056
%PROGRAMFILES%\Yahoo!\Messenger\ymsgr_tray.exe [Yahoo! Inc.] [Yahoo! Messenger] MD5=F9AB943EB3CF38867FFEC53E9FC39EB5 SIZE=103928
%PROGRAMFILES%\Yahoo!\Messenger\res_msgr.dll [Yahoo! Inc.] [Yahoo! Messenger] MD5=C3837B8F0655210E10D02552679D8EC2 SIZE=1437696
%PROGRAMFILES%\iPod\bin\iPodService.exe [Apple Inc.] [iTunes] MD5=E8E568EA584973DFD99AAC7D00A16287 SIZE=542496
%PROGRAMFILES%\iPod\bin\iPodService.Resources\en.lproj\iPodServiceLocalized.DLL [Apple Inc.] [iTunes] MD5=3BCDC77E7530B08F71B6E3A06CEC9FCA SIZE=43520
%PROGRAMFILES%\iPod\bin\iPodService.Resources\iPodService.DLL [Apple Inc.] [iTunes] MD5=1C02ABFD1DA3B220FD5CBE147F4A76AB SIZE=42496
%PROGRAMFILES%\AVG\AVG8\avglvex.dll [AVG Technologies CZ, s.r.o.] [AVG Internet Security] MD5=19A8B72D162E1F365889097D11B3CC8D SIZE=197912
%PROGRAMFILES%\Yahoo!\Companion\Installs\cpn0\yt.dll [Yahoo! Inc.] [Yahoo! Toolbar] MD5=839BC91F49F8ADA29F3E3B8366057016 SIZE=803864
%PROGRAMFILES%\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [Adobe Systems Incorporated] [AcroIEHelper Library] MD5=42729C3DE75A7A51FC6F9EF6546C9199 SIZE=63136
%COMMONFILES%\aolshare\shell\us\shellext.dll [America Online, Inc.] [America Online, Inc. AOLShell] MD5=ADCA4CB85E002DC5328A6BB8699BF491 SIZE=111824
%PROGRAMFILES%\Yahoo!\Common\YMMAPI.dll [Yahoo! Inc.] [Yahoo! Mail] MD5=1F5AB2484C761395EF6BCDBBA8E0ECE2 SIZE=201240
%COMMONFILES%\TI Shared\TIConnect\TIShlExt.dll [Texas Instruments Incorporated] [TI Connect] MD5=29F343094BC035B56F9711D9F088E00C SIZE=172032
%PROGRAMFILES%\iTunes\iTunesMiniPlayer.dll [Apple Inc.] [iTunes] MD5=5A5B242EA6904522F0023881C3847C7C SIZE=124200
ssqPfgdE.dll
%SYSDIR%\DRIVERS\AGRSM.sys [Agere Systems] [Agere SoftModem Driver] MD5=A7D5C71FF4A5B8FEE626FE65B39D71D0 SIZE=1205292
%SYSDIR%\DRIVERS\Apfiltr.sys [Alps Electric Co., Ltd.] [Alps Touch Pad Driver for Windows 2000/XP] MD5=42860BA463D5C9C58A91D1AD208169A9 SIZE=94600
%SYSDIR%\svchost.exe -k netsvcs
%SYSDIR%\DRIVERS\bcmwl5.sys [Broadcom Corporation] [Broadcom 802.11 Network Adapter wireless driver] MD5=C3AB2D6954C7B5103770832A3A6A591B SIZE=369024
%SYSDIR%\svchost -k DcomLaunch
%SYSDIR%\svchost.exe -k NetworkService
%SYSDIR%\drivers\drvmcdb.sys [Sonic Solutions] MD5=049177996E5E33B5FAF40CAD2B82098C SIZE=86160
%SYSDIR%\drivers\drvnddm.sys [Sonic Solutions] MD5=2F4134D073F972575C174E3D621F0107 SIZE=40480
%SYSDIR%\DRIVERS\GEARAspiWDM.sys [GEAR Software Inc.] [CD DVD Filter] MD5=F2F431D1573EE632975C524418655B84 SIZE=23400
%SYSDIR%\svchost.exe -k HTTPFilter
%SYSDIR%\drivers\jfbiacqq.sys [B.H.A Co.,Ltd.] [BSASPI32.SYS] MD5=CC878331B1E33A7F37836F2311071E78 SIZE=23424
%SYSDIR%\svchost.exe -k LocalService
%SYSDIR%\svchost -k rpcss
%SYSDIR%\DRIVERS\sisgrp.sys [Silicon Integrated Systems Corporation] [SiS (R) Compatible Super VGA Miniport Driver for Windows XP] MD5=CFF5E2A076286519A08CF32C6E8602A9 SIZE=216320
%SYSDIR%\DRIVERS\SISAGPX.sys [Silicon Integrated Systems Corporation] [SiS AGPv3.5 Filter for Windows XP] MD5=61CA562DEF09A782D26B3E7EDEC5369A SIZE=36992
%SYSDIR%\DRIVERS\srvkp.sys [Silicon Integrated Systems Corporation] [SiS (R) WindowsXP Display Manager] MD5=741F2C7C62B9F55526E30C61701A31AC SIZE=12160
%SYSDIR%\DRIVERS\sisnic.sys [SiS Corporation] [NDIS 5 NIC Driver] MD5=8204C49CDE112F7B9C2F15707FE2CC5A SIZE=32256
%SYSDIR%\drivers\smwdm.sys [Analog Devices, Inc.] [SoundMAX Digital Audio Driver] MD5=48A061AA55C6884547FE6C76D6D45790 SIZE=612352
%SYSDIR%\drivers\sp_rsdrv2.sys [Crawler.com] [Spyware Terminator] MD5=8831252BCF05FCFB5ABD116A22E552D8 SIZE=142592
%SYSDIR%\drivers\sscdbhk5.sys [Sonic Solutions] MD5=7C0C9BDCA2D351FF3B4F9B69F99AA995 SIZE=5621
%SYSDIR%\drivers\ssrtln.sys [Sonic Solutions] MD5=31726706D54894D5059F7471111A87BB SIZE=23219
%SYSDIR%\svchost.exe -k imgsvc
%SYSDIR%\dla\tfsnboio.sys [Sonic Solutions] MD5=B0D311F33C5B4A5858E4E6C965A79267 SIZE=25685
%SYSDIR%\dla\tfsncofs.sys [Sonic Solutions] MD5=250F74FCE5D1ECCB29AD9ABEB55F35D8 SIZE=34837
%SYSDIR%\dla\tfsndrct.sys [Sonic Solutions] MD5=E23291934C59E1741BA83582E7A209C0 SIZE=4117
%SYSDIR%\dla\tfsndres.sys [Sonic Solutions] MD5=0D863D020633025F1E4AD3E0E325D503 SIZE=2233
%SYSDIR%\dla\tfsnifs.sys [Sonic Solutions] MD5=E3E10696663E35062851A376299198BD SIZE=85972
%SYSDIR%\dla\tfsnopio.sys [Sonic Solutions] MD5=00CC366BDCBD8A9A1C95C1C59900DD9B SIZE=14229
%SYSDIR%\dla\tfsnpool.sys [Sonic Solutions] MD5=84A91D08F49831E8C24E4D25DDEFAE87 SIZE=6357
%SYSDIR%\dla\tfsnudf.sys [Sonic Solutions] MD5=55B761C6E2D4FCEDAC3B46B6C0724830 SIZE=98580
%SYSDIR%\dla\tfsnudfa.sys [Sonic Solutions] MD5=64C6E8C217E30EE595120C66F6E783BA SIZE=100597
%SYSDIR%\DRIVERS\ultra.sys [Promise Technology, Inc.] [Promise ultra66 Miniport Driver for WindowsNT] MD5=1B698A51CD528D8DA4FFAED66DFC51B9 SIZE=36736
%SYSDIR%\DRIVERS\wanatw4.sys [America Online, Inc.] [Wan Miniport (ATW)] MD5=0A716C08CB13C3A8F4F51E882DBF7416 SIZE=33588
%SYSDIR%\wltrysvc.exe C:\WINDOWS\System32\bcmwltry.exe

End of Report

 
     Quarantine Process:
 
  Preparing structures
  Creating System Restore Point
  Quarantine AVWA.dll ( BHO )
  Registry Moving Failed: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8EFE0C47-A3A3-4555-A4D1-FFC8C28040EB} 
  File Moving Failed (Failed) : C:\WINDOWS\SYSTEM32\AVWA.dll
  File Deletion Failed: C:\WINDOWS\SYSTEM32\AVWA.dll
  Closing System Restore Point
  Done

Brocke
Posted: Monday, September 14, 2009 9:19:57 PM

Rank: General
Groups: Beta, Member, Threat Analyzer

Joined: 8/30/2006
Posts: 1,033
Location: USA, IOWA
try in safe mode to and run a full scan.

Try my Program Cleanup! Its 100% coded in Batch/.VBS. Let me know what you think :)
MacPeter
Posted: Saturday, October 17, 2009 3:55:04 PM

Rank: General
Groups: Beta, Member, Translator

Joined: 10/8/2006
Posts: 627
Location: Switzerland
Hi,


A Hijacklog would help....

XP SP3 fully patched


WinPatrol 16.0.2009.6
Comodo firewall +Antivir
Process Tamer 2.11.01
Returnil 2010
Spyware Terminator 2.6.5.111
System Protect 1.0
HDtune v2.55

1536 MB RAM
Users browsing this topic
Guest

Forum Jump

Main Forum Rss Feed : RSS

Powered by Yet Another Forum.net version 1.0.0 - 2/22/2006
Copyright © 2010 Yet Another Forum.net. All rights reserved.
This page was generated in 0.562 seconds.