Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: "your system is infected" virus and also 'windows cannot access specified..'  (Read 25551 times)

0 Members and 1 Guest are viewing this topic.

ryguy15

    Topic Starter


    Rookie

    • Computer: Specs
    • Experience: Beginner
    • OS: Windows Vista
    Hi, I just recently got a virus that turned my wallpaper to solid black and came up with this message in a black box saying in read writing "YOUR SYSTEM IS INFECTED - System has been stopped due to a serious malfunction. Spyware activity has been detected. It is recommended to use spyware removal tool to prevent data loss. Do not use the computer before all spyware removed." and then it started up a fake antivirus programme that started scanning. With the help of AVG (free trial) I managed to get rid of the box with that message and my wallpaper picture has returned, but now when I try and run programmes like Malwarebyte's Anti-Malware, and Spybot, it comes up with an error message saying "Windows cannot access the specified device, path, or file.  You may not have the appropriate permissions to access the item."

    And now I also can't scan with AVG because the scan button has gone grey and I can't click on it. I tried reinstalling Malewarebytes Anti-malware and got it to launch, but then seconds after it starts scanning the programme just closes and then if I try and open it that same error message comes up.

    So any help would be greatly appreciated. Let me know if I need to give more information that this too.

    thanks.

    ryguy15

      Topic Starter


      Rookie

      • Computer: Specs
      • Experience: Beginner
      • OS: Windows Vista
      Just thought I might add that now my computer has taken to suddenly turning itself off for no apparent reason.
      Thanks again in advance to whoever can offer some help.

      SuperDave

      • Malware Removal Specialist
      • Moderator


      • Genius
      • Thanked: 1020
      • Certifications: List
      • Experience: Expert
      • OS: Windows 10
      Hello and welcome to Computer Hope Forum. My name is Dave. I will be helping you out with your particular problem on your computer. I am working under the guidance of one of the specialist of this forum so it may take a bit longer to process your logs.

      1. I will be working on your Malware issues. This may or may not solve other issues you have with your machine.
      2. The fixes are specific to your problem and should only be used for this issue on this machine.
      3. If you don't know or understand something, please don't hesitate to ask.
      4. Please DO NOT run any other tools or scans while I am helping you.
      5. It is important that you reply to this thread. Do not start a new topic.
      6. Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe.
      7. Absence of symptoms does not mean that everything is clear.

      If you can't access the internet with your infected computer you will have to download and transfer any programs to the computer you're using now and transfer them to the infected computer with a CD-RW or a USB storage device. I prefer a CD because a storage device can get infected. If you use a storage device hold the shift key down while inserting the USB storage device for about 10 secs. You will also have to transfer the logs you receive back to the good computer using the same method until we can get the computer back on-line.

      Please download and run the below tool named Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run.
      Save Rkill to your desktop.

      There are 4 different versions. If one of them won't run then download and try to run the other one.
       
      Vista and Win7 users need to right click Rkill and choose Run as Administrator
       

      You only need to get one of these to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.

      * Rkill.exe
      * Rkill.com
      * Rkill.scr
      * Rkill.pif

      Once you've gotten one of them to run then try to immediately run the following.
      *******************************************
      SUPERAntiSpyware

      If you already have SUPERAntiSpyware be sure to check for updates before scanning!


      Download SuperAntispyware Free Edition (SAS)
      * Double-click the icon on your desktop to run the installer.
      * When asked to Update the program definitions, click Yes
      * If you encounter any problems while downloading the updates, manually download and unzip them from here
      * Next click the Preferences button.

      •Under Start-Up Options uncheck Start SUPERAntiSpyware when Windows starts
      * Click the Scanning Control tab.
      * Under Scanner Options make sure only the following are checked:

      •Close browsers before scanning
      •Scan for tracking cookies
      •Terminate memory threats before quarantining
      Please leave the others unchecked

      •Click the Close button to leave the control center screen.

      * On the main screen click Scan your computer
      * On the left check the box for the drive you are scanning.
      * On the right choose Perform Complete Scan
      * Click Next to start the scan. Please be patient while it scans your computer.
      * After the scan is complete a summary box will appear. Click OK
      * Make sure everything in the white box has a check next to it, then click Next
      * It will quarantine what it found and if it asks if you want to reboot, click Yes

      •To retrieve the removal information please do the following:
      •After reboot, double-click the SUPERAntiSpyware icon on your desktop.
      •Click Preferences. Click the Statistics/Logs tab.

      •Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.

      •It will open in your default text editor (preferably Notepad).
      •Save the notepad file to your desktop by clicking (in notepad) File > Save As...

      * Save the log somewhere you can easily find it. (normally the desktop)
      * Click close and close again to exit the program.
      *Copy and Paste the log in your post.
      ****************************************
      Please download Malwarebytes Anti-Malware from here.

      Double Click mbam-setup.exe to install the application.
      • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes Anti-Malware, then click Finish.
      • If an update is found, it will download and install the latest version.
      • Once the program has loaded, select "Perform Full Scan", then click Scan.
      • The scan may take some time to finish,so please be patient.
      • When the scan is complete, click OK, then Show Results to view the results.
      • Make sure that everything is checked, and click Remove Selected.
      • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
      • Please save the log to a location you will remember.
      • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
      • Copy and paste the entire report in your next reply.
      Extra Note:

      If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.
      ************************************
      Please download: HiJackThis to your Desktop.
      • Double Click the HijackThis icon, located on your Desktop.
      • By Default, it will install to: C:\Program Files\Trend Micro\HijackThis
      • Accept the license agreement.
      • Click the Open the Misc Tools section button.
      • Place a checkmark beside Calculate MD5 of files if possible. Then, click Back.
      • Click Do a System Scan and Save a Logfile. Or, if you see a white screen, click Scan.
      • Please post the log in your next reply.
      Windows 8 and Windows 10 dual boot with two SSD's

      ryguy15

        Topic Starter


        Rookie

        • Computer: Specs
        • Experience: Beginner
        • OS: Windows Vista
        Hey SuperDave, first of all thank you for offering your help!
        Well, I've tried to do all those things that you said in your post, but unfortunately the only one that worked was the rkill.exe.
        I downloaded SUPERAntiSpyware and installed it and checked and unchecked all the boxes you said to, but then about 2mins into the scan it just closed itself and then when I tried to open it again I got the "Windows cannot access the specified device, path, or file.  You may not have the appropriate permissions to access the item." again. The same thing happened with Malwarebytes and also HiJackThis. So unfortunately I can't post any logs here yet :(

        I only downloaded the first rkill programme, should I try using the other ones as well? Or I could post the logs from the rkill.exe saying which programmes it terminated?

        Thanks again for you help.


        SuperDave

        • Malware Removal Specialist
        • Moderator


        • Genius
        • Thanked: 1020
        • Certifications: List
        • Experience: Expert
        • OS: Windows 10
        Boot in Safe Mode and try to run MBAM. If that works well, reboot in Normal mode and run SAS. Post the logs, if you can.
        Windows 8 and Windows 10 dual boot with two SSD's

        ryguy15

          Topic Starter


          Rookie

          • Computer: Specs
          • Experience: Beginner
          • OS: Windows Vista
          Even in safe mode the same thing happens. Malwarebytes just closes after I run the scan and  then I get that error message when I try to open it again. Each time I try to run malwarebytes or any of those other programmes I have to reinstall them.
          I don't know if this will be any help but this is the process that gets terminated by rkill:


          \\.\globalroot\Device\svchost.exe\svchost.exe


          SuperDave

          • Malware Removal Specialist
          • Moderator


          • Genius
          • Thanked: 1020
          • Certifications: List
          • Experience: Expert
          • OS: Windows 10
          We are going to be using a Windows Recovery Environment to help disinfect the system so it may boot again.

          Download the OTLPE Standard REATOGO Windows Recovery Environment.
            Place a blank CD-R disc in to your CD burning drive.Download
          OTLPEStd.exe and double-click on it to burn to a CD using the ISO Burner.Reboot your system using the boot CD you just created.

          Note : If you do not know how to set your computer to boot from CD follow the steps here
          Your system should now display a REATOGO-X-PE desktop.
          Double-click on the OTLPE icon.
          When asked "Do you wish to load the remote registry", select Yes
          When asked "Do you wish to load remote user profile(s) for scanning", select Yes
          Ensure the box "Automatically Load All Remaining Users" is checked and press OK
          OTL should now start. Change the following settings
          • Change Drivers to Non-Microsoft
            Press Run Scan to start the scan.
            When finished, the file will be saved  in drive C:\_OTL\MovedFiles
            Copy this file to your USB drive if you do not have internet connection on this system
            Please post the contents of the OTL.txt file in your reply.
          [/list]
          Windows 8 and Windows 10 dual boot with two SSD's

          MelyBoon

          • Guest
          Your comment has been removed. Please do not post malware advice, or post here in the malware forum, unless you need help.
          « Last Edit: October 16, 2010, 01:03:39 PM by SuperDave »

          ryguy15

            Topic Starter


            Rookie

            • Computer: Specs
            • Experience: Beginner
            • OS: Windows Vista
            Ok when I reboot the computer with the cd and get to the REATOGO-X-PE desktop, I double click on the OTLPE icon and it brings up some folder selection thing. The folders to choose from are:
            My Computer
            -RAMDisk(B:)
            -Local Disk (C:)
            -PRESARIO_RP(D:)
            -ReatogoPE (X:)
            -Shared Documents

            If i click on 'my computer' and click ok, it brings up a message saying "  No windows installations found"
            If I click on any of the others and click ok it says "Target is not windows 2000 or later"
            :\

            I also now have this stupid 'anitvirus 2010' programme reappearing, which I thought I had managed to originally get rid of.


            What should I do now?
            and again, thank you for helping me with this.

            ryguy15

              Topic Starter


              Rookie

              • Computer: Specs
              • Experience: Beginner
              • OS: Windows Vista
              I also can't get Task Manager to run.

              SuperDave

              • Malware Removal Specialist
              • Moderator


              • Genius
              • Thanked: 1020
              • Certifications: List
              • Experience: Expert
              • OS: Windows 10
              Ok. Let's try this. Click Start, My Computer, double-click on your C: drive and double-click on MalWareBytes-Antimalware. Right-click on mbam.exe and change the name to something gidget.exe. Now see if it will run. Please post the log if you can get it to run.
              Windows 8 and Windows 10 dual boot with two SSD's

              ryguy15

                Topic Starter


                Rookie

                • Computer: Specs
                • Experience: Beginner
                • OS: Windows Vista
                Ok I tried renaming mbam.exe but still no luck. About 2 seconds into the scan and the program just closes. And then it says I no longer have access to it when I try to open it again. Interestingly though, AVG appears to be working again (its still scanning and its been going for about 12 minutes now), although it hasn't found anything yet.

                SuperDave

                • Malware Removal Specialist
                • Moderator


                • Genius
                • Thanked: 1020
                • Certifications: List
                • Experience: Expert
                • OS: Windows 10
                  Please download
                ComboFix from BleepingComputer.com

                Alternate link: GeeksToGo.com

                Rename ComboFix.exe to commy.exe before you save it to your Desktop
                Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools A guide to do this can be found here
                Click Start>Run then copy paste the following command into the Run box & click OK "%userprofile%\desktop\commy.exe" /stepdel
                As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
                Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console[/list]

                Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

                Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:


                Click on Yes, to continue scanning for malware.
                When finished, it shall produce a log for you.  Please include the contents of C:\ComboFix.txt in your next reply.

                If you have problems with ComboFix usage, see How to use ComboFix

                Windows 8 and Windows 10 dual boot with two SSD's

                autotech



                  Starter
                • "Mongo just pawn in game of life."
                  • Experience: Familiar
                  • OS: Windows XP
                  Super Dave, I have been following this thread as a friend of mine got his Dell laptop with XP home hit also. Everything he stated has happen to me also, ie shutdown after 2 min, path not found, etc. When I went to rename mbam.exe I found it had been renamed
                  mbam. exe the space being the difference. when I went to rename it it was denied as the infection  has blocked anyone from renaming files other than it. Hope this helps. I am just waiting to see where this goes next to see if I can help my friend. Big Dave

                  ryguy15

                    Topic Starter


                    Rookie

                    • Computer: Specs
                    • Experience: Beginner
                    • OS: Windows Vista
                    Here is the log that Combofix produced:

                    ComboFix 10-10-21.05 - Ryan 22/10/2010  23:58:51.3.2 - x86
                    Microsoft® Windows Vista™ Home Premium   6.0.6002.2.1252.64.1033.18.1982.1121 [GMT 13:00]
                    Running from: c:\users\Ryan\Desktop\commy.exe
                    AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
                    SP: AVG Anti-Virus Free *enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
                    SP: Spybot - Search and Destroy *disabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
                    SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
                    .

                    (((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
                    .

                    c:\programdata.\documents\settings
                    c:\programdata\.wtav
                    c:\users\Ryan\AppData\Roaming\avdrn.dat
                    c:\users\Ryan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AnVi
                    c:\users\Ryan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AnVi\About.lnk
                    c:\users\Ryan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AnVi\Activate.lnk
                    c:\users\Ryan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AnVi\Antivirus Support.lnk
                    c:\users\Ryan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AnVi\Antivirus.lnk
                    c:\users\Ryan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AnVi\Buy.lnk
                    c:\users\Ryan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AnVi\Scan.lnk
                    c:\users\Ryan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AnVi\Settings.lnk
                    c:\users\Ryan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AnVi\Update.lnk
                    c:\users\Ryan\oashdihasidhasuidhiasdhiashdiuasdhasd
                    c:\windows\PRAGMAyrtxnwrcjt
                    c:\windows\PRAGMAyrtxnwrcjt\PRAGMAc.dll
                    c:\windows\PRAGMAyrtxnwrcjt\PRAGMAcfg.ini
                    c:\windows\PRAGMAyrtxnwrcjt\PRAGMAsrcr.dat

                    Infected copy of c:\windows\system32\drivers\AGP440.sys was found and disinfected
                    Restored copy from - c:\windows\system32\drivers\agp440.sys.bak

                    .
                    (((((((((((((((((((((((((((((((((((((((   Drivers/Services   )))))))))))))))))))))))))))))))))))))))))))))))))
                    .

                    -------\Service_userinit


                    (((((((((((((((((((((((((   Files Created from 2010-09-22 to 2010-10-22  )))))))))))))))))))))))))))))))
                    .

                    2010-10-22 11:20 . 2010-10-22 11:27   --------   d-----w-   c:\users\Ryan\AppData\Local\temp
                    2010-10-22 11:20 . 2010-10-22 11:20   --------   d-----w-   c:\users\Public\AppData\Local\temp
                    2010-10-22 11:20 . 2010-10-22 11:20   --------   d-----w-   c:\users\Guest\AppData\Local\temp
                    2010-10-22 11:20 . 2010-10-22 11:20   --------   d-----w-   c:\users\Guest(56)\AppData\Local\temp
                    2010-10-22 11:20 . 2010-10-22 11:20   --------   d-----w-   c:\users\Default\AppData\Local\temp
                    2010-10-22 08:08 . 2010-10-07 23:21   6146896   ----a-w-   c:\programdata\Microsoft\Windows Defender\Definition Updates\{A15205D0-8851-4AAD-B675-A6BFC9825264}\mpengine.dll
                    2010-10-18 02:01 . 2010-04-29 02:39   38224   ----a-w-   c:\windows\system32\drivers\mbamswissarmy.sys
                    2010-10-18 02:01 . 2010-04-29 02:39   20952   ----a-w-   c:\windows\system32\drivers\mbam.sys
                    2010-10-17 08:31 . 2010-10-17 08:41   11952   ----a-w-   c:\windows\system32\avgrsstx.dll
                    2010-10-17 08:31 . 2010-10-17 08:41   335240   ----a-w-   c:\windows\system32\drivers\avgldx86.sys
                    2010-10-17 08:30 . 2010-10-17 08:41   27784   ----a-w-   c:\windows\system32\drivers\avgmfx86.sys
                    2010-10-17 08:30 . 2010-10-17 08:43   --------   d-----w-   c:\windows\system32\drivers\Avg
                    2010-10-15 09:47 . 2010-09-13 13:56   168960   ----a-w-   c:\program files\Windows Media Player\wmplayer.exe
                    2010-10-15 09:47 . 2010-09-13 13:56   8147456   ----a-w-   c:\windows\system32\wmploc.DLL
                    2010-10-15 09:47 . 2010-09-06 16:20   125952   ----a-w-   c:\windows\system32\srvsvc.dll
                    2010-10-15 09:47 . 2010-09-06 13:45   304128   ----a-w-   c:\windows\system32\drivers\srv.sys
                    2010-10-15 09:47 . 2010-09-06 13:45   145408   ----a-w-   c:\windows\system32\drivers\srv2.sys
                    2010-10-15 09:47 . 2010-09-06 13:45   102400   ----a-w-   c:\windows\system32\drivers\srvnet.sys
                    2010-10-15 09:47 . 2010-09-06 16:19   17920   ----a-w-   c:\windows\system32\netevent.dll
                    2010-10-14 10:29 . 2010-10-14 10:29   --------   d-----w-   c:\program files\Trend Micro
                    2010-10-10 02:38 . 2010-10-10 02:38   --------   d-----w-   c:\program files\Giant Crocodile
                    2010-10-08 08:58 . 2010-10-08 08:58   --------   dc----w-   C:\$AVG
                    2010-10-08 06:08 . 2010-10-08 06:08   --------   dc----w-   C:\AVG10
                    2010-10-08 06:06 . 2010-10-08 06:06   --------   d--h--w-   c:\programdata\Common Files
                    2010-10-08 06:03 . 2010-10-14 08:43   --------   d-----w-   c:\programdata\AVG10
                    2010-10-08 05:51 . 2010-10-08 06:01   --------   d-----w-   c:\programdata\MFAData
                    2010-10-08 05:39 . 2010-10-18 19:05   --------   d-----w-   c:\program files\Malwarebytes' Anti-Malware
                    2010-09-30 08:28 . 2010-09-30 08:28   --------   d-----w-   c:\windows\Profiles
                    2010-09-29 07:54 . 2010-06-22 13:30   2048   ----a-w-   c:\windows\system32\tzres.dll
                    2010-09-28 11:31 . 2010-09-28 11:31   --------   d-----w-   c:\program files\iPod
                    2010-09-28 11:24 . 2010-09-28 11:24   --------   d-----w-   c:\program files\Bonjour

                    .
                    ((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
                    .
                    2010-10-18 22:41 . 2010-02-11 13:33   222080   ------w-   c:\windows\system32\MpSigStub.exe
                    2010-09-13 03:27 . 2010-09-13 03:27   25680   ----a-w-   c:\windows\system32\drivers\AVGIDSEH.sys
                    2010-09-07 22:17 . 2010-09-07 22:17   94208   ----a-w-   c:\windows\system32\QuickTimeVR.qtx
                    2010-09-07 22:17 . 2010-09-07 22:17   69632   ----a-w-   c:\windows\system32\QuickTime.qts
                    2010-08-17 14:11 . 2010-09-16 08:10   128000   ----a-w-   c:\windows\system32\spoolsv.exe
                    2010-07-27 05:44 . 2010-07-27 05:44   91424   ----a-w-   c:\windows\system32\dnssd.dll
                    2010-07-27 05:44 . 2010-07-27 05:44   107808   ----a-w-   c:\windows\system32\dns-sd.exe
                    2009-01-27 01:34 . 2009-01-27 01:34   1044480   ----a-w-   c:\program files\mozilla firefox\plugins\libdivx.dll
                    2009-01-27 01:34 . 2009-01-27 01:34   200704   ----a-w-   c:\program files\mozilla firefox\plugins\ssldivx.dll
                    2007-08-25 01:52 . 2008-06-05 11:59   300400   ----a-w-   c:\program files\mozilla firefox\components\coFFPlgn.dll
                    .

                    (((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
                    .
                    .
                    *Note* empty entries & legit default entries are not shown
                    REGEDIT4

                    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                    "msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
                    "SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]

                    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                    "Apoint"="c:\program files\Apoint2K\Apoint.exe" [2007-07-09 159744]
                    "QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2007-10-01 181544]
                    "QlbCtrl"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2007-09-19 202032]
                    "OnScreenDisplay"="c:\program files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe" [2007-09-04 554320]
                    "UCam_Menu"="c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" [2007-08-17 218408]
                    "Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
                    "HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2006-12-10 49152]
                    "hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-09-13 480560]
                    "WAWifiMessage"="c:\program files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe" [2007-01-08 311296]
                    "IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2007-02-05 849280]
                    "WinampAgent"="c:\program files\Winamp\winampa.exe" [2008-08-03 36352]
                    "AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-03-16 47392]
                    "VirtualCloneDrive"="c:\program files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2009-01-29 52392]
                    "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-06-23 13601312]
                    "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-06-23 92704]
                    "Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 57344]
                    "TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2010-03-24 202256]
                    "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]
                    "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
                    "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-17 248040]
                    "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-09-07 421888]
                    "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-09-23 421160]
                    "Malwarebytes Anti-Malware (rootkit-scan)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-04-29 1090952]

                    c:\users\Ryan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
                    OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]

                    c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
                    HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-1-2 210520]

                    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
                    "EnableLUA"= 0 (0x0)
                    "EnableUIADesktopToggle"= 0 (0x0)

                    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
                    "AppInit_DLLs"=c:\windows\System32\avgrsstx.dll

                    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
                    "aux"=wdmaud.drv

                    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
                    @="Driver"

                    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
                    @="Service"

                    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
                    "DisableMonitoring"=dword:00000001

                    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
                    "DisableMonitoring"=dword:00000001

                    R0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys

                    R0 TfSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys

                    R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe

                    R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
                    R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2009-08-10 133104]
                    R2 Nakido;Nakido;c:\program files\Nakido\nakido.exe

                    R3 ASPI;Advanced SCSI Programming Interface Driver;c:\windows\System32\DRIVERS\ASPI32.sys [2002-07-17 84832]
                    R3 cxru92a1;Virtual Bus for Microsoft ACPI-Compliant System;

                    R3 DFBCFDBA;DFBCFDBA;

                    R3 iscFlash;iscFlash;c:\swsetup\sp42533\iscflash.sys [2008-08-05 11520]
                    R3 TfNetMon;TfNetMon;c:\windows\system32\drivers\TfNetMon.sys

                    R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
                    R4 sptd;sptd;c:\windows\system32\Drivers\sptd.sys [2008-04-29 717296]
                    S0 AVGIDSEH;AVGIDSEH;c:\windows\system32\DRIVERS\AVGIDSEH.Sys [2010-09-13 25680]
                    S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\Drivers\avgldx86.sys [2010-10-17 335240]
                    S2 Application Updater;Application Updater;c:\program files\Application Updater\ApplicationUpdater.exe [2009-12-16 375296]
                    S2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]


                    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
                    HPZ12   REG_MULTI_SZ      Pml Driver HPZ12 Net Driver HPZ12
                    HPService   REG_MULTI_SZ      HPSLPSVC
                    hpdevmgmt   REG_MULTI_SZ      hpqcxs08 hpqddsvc
                    LocalServiceAndNoImpersonation   REG_MULTI_SZ      FontCache
                    .
                    Contents of the 'Scheduled Tasks' folder

                    2010-10-22 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
                    - c:\program files\Google\Update\GoogleUpdate.exe [2009-08-10 23:39]

                    2010-10-22 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
                    - c:\program files\Google\Update\GoogleUpdate.exe [2009-08-10 23:39]

                    2010-10-20 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-753018427-1233051673-1299658189-1003Core.job
                    - c:\users\Ryan\AppData\Local\Google\Update\GoogleUpdate.exe [2010-04-10 04:59]

                    2010-10-22 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-753018427-1233051673-1299658189-1003UA.job
                    - c:\users\Ryan\AppData\Local\Google\Update\GoogleUpdate.exe [2010-04-10 04:59]

                    2010-10-22 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-753018427-1233051673-1299658189-1003.job
                    - c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-24 09:09]

                    2010-10-22 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-753018427-1233051673-1299658189-1003.job
                    - c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-24 09:09]
                    .
                    .
                    ------- Supplementary Scan -------
                    .
                    uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_nz&c=81&bd=Presario&pf=laptop
                    mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_nz&c=81&bd=Presario&pf=laptop
                    uInternet Settings,ProxyServer = proxy.student.otago.ac.nz:3128
                    uInternet Settings,ProxyOverride = <local>
                    IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
                    DPF: {32C3FEAE-0877-4767-8C20-62A5829A0945} - hxxp://static.ak.facebook.com/fbplugin/win32/axfbootloader.cab
                    FF - ProfilePath - c:\users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\5isep8bi.default\
                    FF - component: c:\programdata\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext\components\nprpffbrowserrecordext.dll
                    FF - component: c:\users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\5isep8bi.default\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}\components\IBitCometExtension.dll
                    FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
                    FF - plugin: c:\program files\Google\Update\1.2.183.39\npGoogleOneClick8.dll
                    FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
                    FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
                    FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
                    FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
                    FF - plugin: c:\programdata\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
                    FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
                    .
                    - - - - ORPHANS REMOVED - - - -

                    BHO-{9DFE2FE9-CF99-4ADF-A28E-9B5ADB8DC74F} - (no file)
                    HKLM-Run-hpqSRMon - (no file)
                    HKLM-Run-AVG8_TRAY - c:\progra~1\AVG\AVG8\avgtray.exe
                    AddRemove-Antivirus - c:\program files\AnVi\Pklkvqdii+`}`
                    AddRemove-AVG8Uninstall - c:\program files\AVG\AVG8\setup.exe


                    .
                    --------------------- DLLs Loaded Under Running Processes ---------------------

                    - - - - - - - > 'Explorer.exe'(4816)
                    c:\program files\Nokia\Nokia PC Suite 6\phonebrowser.dll
                    c:\program files\Nokia\Nokia PC Suite 6\PCSCM.dll
                    c:\program files\Nokia\Nokia PC Suite 6\Lang\PhoneBrowser_eng-us.nlr
                    c:\program files\Nokia\Nokia PC Suite 6\Resource\PhoneBrowser_Nokia.ngr
                    .
                    ------------------------ Other Running Processes ------------------------
                    .
                    c:\windows\system32\nvvsvc.exe
                    c:\windows\system32\WLANExt.exe
                    c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
                    c:\program files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
                    c:\program files\Bonjour\mDNSResponder.exe
                    c:\program files\CyberLink\Shared Files\RichVideo.exe
                    c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
                    c:\program files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
                    c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
                    c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
                    c:\windows\system32\DRIVERS\xaudio.exe
                    c:\program files\Hewlett-Packard\Shared\hpqwmiex.exe
                    c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
                    c:\windows\system32\rundll32.exe
                    c:\windows\System32\rundll32.exe
                    c:\program files\Windows Media Player\wmpnscfg.exe
                    c:\program files\Windows Media Player\wmpnetwk.exe
                    c:\program files\Apoint2K\ApMsgFwd.exe
                    c:\program files\Apoint2K\Apntex.exe
                    c:\program files\Hewlett-Packard\Shared\HpqToaster.exe
                    c:\program files\iPod\bin\iPodService.exe
                    c:\program files\Hewlett-Packard\HP Health Check\hphc_service.exe
                    .
                    **************************************************************************
                    .
                    Completion time: 2010-10-23  00:35:43 - machine was rebooted
                    ComboFix-quarantined-files.txt  2010-10-22 11:35

                    Pre-Run: 6,880,415,744 bytes free
                    Post-Run: 7,537,274,880 bytes free

                    - - End Of File - - DA41FB2AD76064205DDCCAAABE2D398C