View Single Post
Old 12-04-2008, 01:34 PM   #5 (permalink)
hsnmz
Registered User
 
Join Date: Dec 2008
Posts: 14
OS: Win XP Service Pack 3


Re: AVG 8 antivirus unable to update

After running the Flash Disinfector the internet speed became very slow.
kaspersky scan is not running, first it gave me an error "Starting java applet has failed! Please go online to use this program" with an OK button. After pressing OK nothing happened for next 30 minutes. I uninstalled and reinstalled the java update 11 but still Kaspersky gave same error. I followed all the steps as you instructed. Now the internet is very slow. Still combofix ran fine and I am attaching its log below

===================================

ComboFix 08-12-03.03 - Hassan Mirza 2008-12-04 23:30:22.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1600 [GMT 5:00]
Running from: c:\documents and settings\Hassan Mirza\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Hassan Mirza\Desktop\CFScript.txt
* Created a new restore point

FILE ::
c:\docume~1\HASSAN~1\LOCALS~1\Temp\cpuz.sys
c:\windows\system32\drivers\ndisprot.sys
I:\system.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\drivers\ndisprot.sys

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_CPUZ126
-------\Legacy_NDISPROT
-------\Service_cpuz126
-------\Service_Ndisprot


((((((((((((((((((((((((( Files Created from 2008-11-04 to 2008-12-04 )))))))))))))))))))))))))))))))
.

2008-12-04 23:15 . 2008-12-04 23:15 <DIR> d--h----- C:\$AVG8.VAULT$
2008-12-04 21:48 . 2008-12-04 21:48 <DIR> d--hs---- c:\documents and settings\Hassan Mirza\UserData
2008-12-02 23:22 . 2008-12-02 23:22 250 --a------ c:\windows\gmer.ini
2008-11-12 21:15 . 2008-09-04 22:15 1,106,944 -----c--- c:\windows\system32\dllcache\msxml3.dll
2008-11-12 21:15 . 2008-10-24 16:21 455,296 -----c--- c:\windows\system32\dllcache\mrxsmb.sys
2008-11-12 19:19 . 2008-11-12 19:19 <DIR> d-------- c:\windows\system32\Futuremark

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-19 02:22 --------- d-----w c:\documents and settings\Hassan Mirza\Application Data\BitTorrent
2008-11-18 17:13 107,888 ----a-w c:\windows\system32\CmdLineExt.dll
2008-11-18 17:06 --------- d--h--w c:\program files\InstallShield Installation Information
2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-19 09:10 22,328 ----a-w c:\windows\system32\drivers\PnkBstrK.sys
2008-10-19 09:10 103,736 ----a-w c:\windows\system32\PnkBstrB.exe
2008-10-16 09:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 09:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 09:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 09:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 09:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 09:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 09:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 09:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-09-30 11:43 1,286,152 ----a-w c:\windows\system32\msxml4.dll
2008-09-15 12:12 1,846,400 ----a-w c:\windows\system32\win32k.sys
2008-09-13 13:46 10,520 ----a-w c:\windows\system32\avgrsstx.dll
2008-09-10 01:14 1,307,648 ----a-w c:\windows\system32\msxml6.dll
2008-09-04 17:15 1,106,944 ----a-w c:\windows\system32\msxml3.dll
.

((((((((((((((((((((((((((((( snapshot@2008-12-03_23.47.00.39 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-12-04 18:33:30 16,384 ----atw c:\windows\Temp\Perflib_Perfdata_4d8.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NVIDIA nTune"="d:\program files\NVIDIA Corporation\nTune\nTuneCmd.exe" [2007-09-04 81920]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-10-07 13574144]
"Launch Ai Booster"="d:\program files\ASUS\AI Booster\OverClk.exe" [2006-07-13 3712512]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2006-05-18 843776]
"WinPatrol"="d:\program files\BillP Studios\WinPatrol\winpatrol.exe" [2008-01-27 316728]
"SunJavaUpdateSched"="d:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2008-12-04 1261336]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-04 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-10-07 86016]
"nwiz"="nwiz.exe" [2008-10-07 c:\windows\system32\nwiz.exe]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.ffds"= ffdshow.ax
"msacm.ac3filter"= ac3filter.acm

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"e:\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"d:\\Program Files\\DAP\\DAP.exe"=
"d:\\Program Files\\BitTorrent\\bittorrent.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"d:\\Program Files\\Sony Ericsson\\Update Service\\Update Service.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"e:\\Far Cry 2\\bin\\FarCry2.exe"=
"e:\\Far Cry 2\\bin\\FC2Launcher.exe"=
"e:\\Far Cry 2\\bin\\FC2Editor.exe"=

R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys [2008-09-13 97928]
R2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2008-09-13 875288]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2008-09-13 231704]
R2 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\Drivers\avgtdix.sys [2008-09-13 76040]
R2 SVKP;SVKP;\??\c:\windows\system32\SVKP.sys [2008-05-17 2368]
S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\DRIVERS\ggflt.sys [2008-06-21 13352]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [2008-05-18 138112]
S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [2008-05-18 8320]
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-04 23:32:36
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
d:\program files\NVIDIA Corporation\nTune\nTuneService.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\rundll32.exe
c:\progra~1\AVG\AVG8\avgupd.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\program files\AVG\AVG8\avgrsx.exe
.
**************************************************************************
.
Completion time: 2008-12-04 23:35:06 - machine was rebooted
ComboFix-quarantined-files.txt 2008-12-04 18:34:50
ComboFix2.txt 2008-12-03 18:47:56

Pre-Run: 1,963,597,824 bytes free
Post-Run: 1,974,329,344 bytes free

130 --- E O F --- 2008-11-12 18:55:39

Last edited by hsnmz; 12-04-2008 at 01:37 PM.
hsnmz is offline