This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] I've got a trojan that won't let me install AVG

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I have a trojan that redirects me to different website links, won't allow me to install AVG nor Spybot, and makes my processes in Windows Task Manager run at a CPU of 00. Here is my HJT log:


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:03:49 PM, on 5/31/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Safe mode with network support

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\Vuze\Azureus.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\cleanmgr.exe
C:\Documents and Settings\Alana Guinn\Desktop\Fumble\Jack.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: HelperObject Class - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 8\SnagItBHO.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (file missing)
O2 - BHO: SpywareBlock Class - {0A87E45F-537A-40B4-B812-E2544C21A09F} - C:\Program Files\SpyCatcher 2006\SCActiveBlock.dll (file missing)
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (file missing)
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 8\SnagItIEAddin.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL (file missing)
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [EPSON Stylus Photo R200 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2H1.EXE /P30 "EPSON Stylus Photo R200 Series" /O6 "USB001" /M "Stylus Photo R200"
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKLM\..\Run: [realteks] "C:\Documents and Settings\Alana Guinn\Application Data\Google\uwxhn7924753.exe" 2
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [SVCHOST.EXE] C:\WINDOWS\system32\drivers\svchost.exe
O4 - HKCU\..\Run: [nah_Shell] C:\Documents and Settings\Alana Guinn\nah_wgwa.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HotSync Manager.lnk = C:\Program Files\palmOne\Hotsync.exe
O4 - Global Startup: HOTSYNCSHORTCUTNAME.lnk = C:\Program Files\palmOne\Hotsync.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1144386485265
O17 - HKLM\System\CCS\Services\Tcpip\..\{FF2EC62F-89CE-4ADE-AEEF-F6831EFC5678}: NameServer = 85.255.112.191,85.255.112.78
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.112.191,85.255.112.78
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.112.191,85.255.112.78
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.112.191,85.255.112.78
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (file missing)
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
O23 - Service: Iap - Dell Inc - C:\Program Files\Dell\OpenManage\Client\Iap.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\system32\Tablet.exe

–
End of file - 8262 bytes
Hi,

Please do the following:

  • Open HiJackThis
  • Click on Do a system scan only
  • Check the boxes next to ONLY the entries listed below (if still present):


O4 - HKLM\..\Run: [realteks] "C:\Documents and Settings\Alana Guinn\Application Data\Google\uwxhn7924753.exe" 2
O4 - HKCU\..\Run: [nah_Shell] C:\Documents and Settings\Alana Guinn\nah_wgwa.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{FF2EC62F-89CE-4ADE-AEEF-F6831EFC5678}: NameServer = 85.255.112.191,85.255.112.78
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.112.191,85.255.112.78
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.112.191,85.255.112.78
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.112.191,85.255.112.78

  • Close all windows except Hijackthis and click Fix Checked
  • Click Yes when prompted
  • Close HijackThis.


NEXT

Please download ComboFix from Here or Here to your Desktop.
**Note:  In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved and renamed following this process directly to your desktop**
  • If you are using Firefox, make sure that your download settings are as follows:
    • Tools->Options->Main tab
    • Set to "Always ask me where to Save the files".
  • During the download, rename Combofix to Combo-Fix as follows:

    [external image: Posted Image]

    [external image: Posted Image]
  • It is important you rename Combofix during the download, but not after.
  • Please do not rename Combofix to other names, but only to the one indicated.
  • Close any open browsers.
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

    ———————————————————–

    • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
    • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

      ———————————————————–

    • Close any open browsers.
    • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
    • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
    • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.

    ———————————————————–

  • Double click on combo-Fix.exe & follow the prompts.
  • When finished, it will produce a report for you.  
  • Please post the "C:\Combo-Fix.txt" for further review.
**Note: Do not mouseclick combo-fix's window while it's running. That may cause it to stall**
Hi CatByte,
Thank you for your thourough reply. I have followed your instructions and am now posting the Combo-Fix text doc below.

ComboFix 09-05-31.06 - Alana Guinn 06/01/2009 17:50.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1603 [GMT -7:00]
Running from: c:\documents and settings\[removed]\Desktop\Combo-Fix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Autorun.inf
c:\documents and settings\Alana Guinn\Application Data\Google\Shell32.dll
c:\documents and settings\Alana Guinn\Application Data\Google\uwxhn7924753.exe
c:\documents and settings\Alana Guinn\nah_log.dat
c:\documents and settings\Alana Guinn\nah_wgwa.exe
c:\program files\security toolbar
c:\program files\security toolbar\Uninstall.bat
c:\windows\system32\drivers\gxvxcducfumltlesrtqskiqvnstymocnrwopp.sys
c:\windows\system32\drivers\gxvxciqxobodovdygwipjwvympulknklypduj.sys
c:\windows\system32\drivers\gxvxcxmeycpkqxvdboppjpwqbompxetqwvexj.sys
c:\windows\system32\gxvxccounter
c:\windows\system32\gxvxcnkryysltfqhrsgtyoqymrrfwaioqltki.dll
c:\windows\system32\gxvxctagkdbxtxosughxwabjuoqbeaoeaavbd.dll
c:\windows\Tasks\{5B57CF47-0BFA-43c6-ACF9-3B3653DCADBA}.job

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_GXVXCSERV.SYS


((((((((((((((((((((((((( Files Created from 2009-05-02 to 2009-06-02 )))))))))))))))))))))))))))))))
.

2009-05-31 21:44 . 2009-05-31 21:44 664 —-a-w- c:\windows\system32\d3d9caps.dat
2009-05-23 00:32 . 2009-05-23 00:32 552 —-a-w- c:\windows\system32\d3d8caps.dat
2009-05-22 20:21 . 2009-05-22 20:21 422 —-a-w- c:\documents and settings\Alana Guinn\Application Data\Apple Computer\socks1.exe
2009-05-22 20:21 . 2009-05-22 20:21 16141 —-a-w- c:\documents and settings\Alana Guinn\Application Data\AVGTOOLBAR\lego.exe
2009-05-22 20:21 . 2009-05-22 20:21 145131 —-a-w- c:\documents and settings\Alana Guinn\Application Data\Arcsoft\nomad.exe
2009-05-22 20:21 . 2009-05-22 20:21 13221 —-a-w- c:\documents and settings\Alana Guinn\Application Data\AdobeUM\rengo.dll
2009-05-22 20:21 . 2009-05-22 20:21 11410 —-a-w- c:\documents and settings\Alana Guinn\Application Data\Azureus\msgdi.dll
2009-05-22 20:21 . 2009-05-22 20:21 11232 —-a-w- c:\documents and settings\Alana Guinn\Application Data\Adobe\shalom.exe
2009-05-22 20:21 . 2009-05-22 20:21 10121 —-a-w- c:\documents and settings\Alana Guinn\Application Data\ColorCop\kern.dll
2009-05-22 19:43 . 2009-03-09 19:06 15688 —-a-w- c:\windows\system32\lsdelete.exe
2009-05-22 19:35 . 2009-05-22 19:35 ——– d—–w- c:\program files\Trend Micro
2009-05-22 18:52 . 2009-05-22 18:52 ——– d—–w- c:\documents and settings\LocalService\Application Data\Share-to-Web Upload Folder
2009-05-22 18:36 . 2009-03-09 19:06 64160 —-a-w- c:\windows\system32\drivers\Lbd.sys
2009-05-22 18:33 . 2009-05-22 18:33 ——– dc-h–w- c:\documents and settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
2009-05-22 18:33 . 2009-03-12 08:17 2902048 -c–a-w- c:\documents and settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}\Ad-AwareAE.exe
2009-05-22 18:33 . 2009-05-22 18:33 ——– d—–w- c:\documents and settings\All Users\Application Data\Lavasoft
2009-05-22 05:26 . 2009-05-22 05:26 ——– d—–w- c:\documents and settings\Alana Guinn\Application Data\AVGTOOLBAR
2009-05-22 05:26 . 2009-05-31 21:43 ——– d—–w- c:\documents and settings\All Users\Application Data\avg8
2009-05-22 05:17 . 2009-05-22 05:17 ——– d-s—w- c:\documents and settings\LocalService\UserData
2009-05-22 05:02 . 2009-05-22 05:03 ——– d—–w- c:\documents and settings\LocalService\Local Settings\Application Data\Adobe
2009-05-22 04:51 . 2009-05-22 04:51 ——– d—–w- c:\documents and settings\LocalService\Local Settings\Application Data\Google
2009-05-18 05:15 . 2009-05-18 05:14 410984 —-a-w- c:\windows\system32\deploytk.dll
2009-05-18 05:14 . 2009-05-18 05:14 152576 —-a-w- c:\documents and settings\Alana Guinn\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2009-05-18 05:09 . 2009-05-18 05:09 ——– d—–w- c:\documents and settings\All Users\Application Data\DAEMON Tools Lite
2009-05-18 05:09 . 2009-05-18 05:09 ——– d—–w- c:\program files\DAEMON Tools Toolbar
2009-05-18 05:09 . 2009-05-18 05:09 ——– d—–w- c:\program files\DAEMON Tools Lite
2009-05-18 05:06 . 2009-05-18 05:10 ——– d—–w- c:\documents and settings\Alana Guinn\Application Data\DAEMON Tools Lite
2009-05-18 03:49 . 2009-05-18 05:06 721904 —-a-w- c:\windows\system32\drivers\sptd.sys
2009-05-05 19:42 . 2009-05-05 19:42 ——– d—–w- c:\documents and settings\Alana Guinn\Application Data\Share-to-Web Upload Folder

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-02 00:40 . 2008-06-12 22:10 ——– d—–w- c:\documents and settings\All Users\Application Data\Google Updater
2009-06-02 00:40 . 2006-02-26 00:01 322 —-a-w- c:\windows\system32\tablet.dat
2009-06-01 05:48 . 2006-11-26 22:55 ——– d—–w- c:\documents and settings\Alana Guinn\Application Data\Skype
2009-05-31 22:17 . 2008-06-21 05:55 ——– d—–w- c:\documents and settings\Alana Guinn\Application Data\Azureus
2009-05-30 17:03 . 2006-04-06 00:12 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-05-30 17:03 . 2006-04-06 00:12 ——– d—–w- c:\program files\Spybot - Search & Destroy
2009-05-24 04:30 . 2006-04-06 19:45 ——– d—–w- c:\program files\Lavasoft
2009-05-24 04:30 . 2006-04-02 20:53 ——– d—–w- c:\documents and settings\Alana Guinn\Application Data\Lavasoft
2009-05-22 04:53 . 2006-02-09 12:34 ——– d—–w- c:\program files\Google
2009-05-20 18:12 . 2008-05-16 17:00 ——– d—–w- c:\documents and settings\Alana Guinn\Application Data\skypePM
2009-05-18 05:14 . 2006-02-09 12:30 ——– d—–w- c:\program files\Java
2009-05-15 23:02 . 2008-06-09 19:21 ——– d—–w- c:\documents and settings\Alana Guinn\Application Data\Move Networks
2009-05-05 19:13 . 2008-06-21 05:55 ——– d—–w- c:\program files\Vuze
2009-04-18 00:41 . 2008-12-19 00:55 ——– d—–w- c:\program files\DivX
2009-04-18 00:40 . 2009-04-18 00:40 ——– d—–w- c:\program files\Common Files\DivX Shared
2009-04-17 19:54 . 2009-04-17 19:54 ——– d—–w- c:\program files\Common Files\Skype
2009-04-17 19:54 . 2008-05-16 17:00 ——– d—–r- c:\program files\Skype
2009-04-17 19:54 . 2008-05-16 16:58 ——– d—–w- c:\documents and settings\All Users\Application Data\Skype
2009-04-09 03:16 . 2006-02-25 20:40 53400 —-a-w- c:\documents and settings\Alana Guinn\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-08 00:14 . 2009-04-08 00:14 1 —-a-w- c:\documents and settings\Alana Guinn\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2009-04-08 00:13 . 2009-04-08 00:13 ——– d—–w- c:\documents and settings\Alana Guinn\Application Data\OpenOffice.org
2009-04-08 00:09 . 2009-04-08 00:09 ——– d—–w- c:\program files\JRE
2009-04-08 00:09 . 2009-04-08 00:09 ——– d—–w- c:\program files\OpenOffice.org 3
2009-04-02 20:58 . 2008-11-30 03:51 10684866 —-a-w- c:\documents and settings\Alana Guinn\Application Data\Azureus\plugins\azump\mplayer.exe
2009-03-13 04:18 . 2009-03-13 04:18 75048 —-a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 8.1.0.52\SetupAdmin.exe
2009-03-09 18:34 . 2009-04-03 18:56 971776 —-a-w- c:\documents and settings\Alana Guinn\Application Data\Mozilla\Firefox\Profiles\ew8i4m3b.default\extensions\[removed]\platform\WINNT_x86-msvc\plugins\npmnqmp071303000006.dll
2009-03-06 14:22 . 2004-08-11 23:00 284160 —-a-w- c:\windows\system32\pdh.dll
2009-03-06 06:59 . 2009-03-16 18:04 36864 —-a-w- c:\windows\system32\drivers\usbaapl.sys
2009-03-06 06:59 . 2009-03-16 18:04 1900544 —-a-w- c:\windows\system32\usbaaplrc.dll
2009-02-24 19:34 . 2009-02-24 19:34 1044480 —-a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-02-24 19:34 . 2009-02-24 19:34 200704 —-a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2009-04-23 691656]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-06-12 68856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"vptray"="c:\progra~1\SYMANT~1\SYMANT~1\vptray.exe" [2003-05-21 90112]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-18 148888]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2005-04-25 139264]
"EPSON Stylus Photo R200 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_S4I2H1.EXE" [2003-07-08 99840]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 53248]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-07-14 339968]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-03-13 342312]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-03-09 515416]
"SigmatelSysTrayApp"="stsystra.exe" - c:\windows\stsystra.exe [2005-03-23 339968]

c:\documents and settings\Alana Guinn\Start Menu\Programs\Startup\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2004-10-4 113664]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2004-10-4 113664]
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-4-23 29696]
HotSync Manager.lnk - c:\program files\palmOne\Hotsync.exe [2004-6-9 471040]
HOTSYNCSHORTCUTNAME.lnk - c:\program files\palmOne\Hotsync.exe [2004-6-9 471040]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2008-10-24 19:03 10536 —-a-w- c:\program files\Citrix\GoToAssist\514\g2awinlogon.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKLM\~\startupfolder\C:^Documents and Settings^Alana Guinn^Start Menu^Programs^Startup^palmOne Registration.lnk]
path=c:\documents and settings\Alana Guinn\Start Menu\Programs\Startup\palmOne Registration.lnk
backup=c:\windows\pss\palmOne Registration.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^TabUserW.exe.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\TabUserW.exe.lnk
backup=c:\windows\pss\TabUserW.exe.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\usmt\\migwiz.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\SAGENT4.EXE"=
"c:\\Program Files\\Vuze\\Azureus.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"%windir%\\system32\\drivers\\svchost.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [5/22/2009 11:36 AM 64160]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [3/9/2009 12:06 PM 951632]
S3 PLUsbbc2;High-Speed USB Bridge Cable Driver;c:\windows\system32\drivers\usbbc2.sys [2/25/2006 7:19 PM 8960]
.
Contents of the 'Scheduled Tasks' folder

2009-05-22 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 19:06]

2009-05-20 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 19:34]

2009-06-02 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-06-09 02:24]
.
- - - - ORPHANS REMOVED - - - -

SafeBoot-procexp90.Sys


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/ig/dell?hl=en
mStart Page = hxxp://www.dell.com
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
FF - ProfilePath - c:\documents and settings\Alana Guinn\Application Data\Mozilla\Firefox\Profiles\ew8i4m3b.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - component: c:\program files\Real\RealPlayer\browserrecord\components\nprpbrowserrecordplugin.dll
FF - plugin: c:\documents and settings\Alana Guinn\Application Data\Mozilla\Firefox\Profiles\ew8i4m3b.default\extensions\[removed]\platform\WINNT_x86-msvc\plugins\npmnqmp071303000006.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPAdbESD.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPUploader.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-01 17:56
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(708)
c:\program files\Citrix\GoToAssist\514\G2AWinLogon.dll
.
Completion time: 2009-06-02 17:59
ComboFix-quarantined-files.txt 2009-06-02 00:58

Pre-Run: 175,594,246,144 bytes free
Post-Run: 175,643,045,888 bytes free

190 — E O F — 2009-05-14 04:08
Hi,

Please do the following:

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

http://forums.whatthetech.com/I_ve_got_trojan_won_t_let_me_install_AVG_t103634.html&view=findpost&p=564181#entry564181

Collect::
c:\documents and settings\Alana Guinn\Application Data\Apple Computer\socks1.exe
c:\documents and settings\Alana Guinn\Application Data\AVGTOOLBAR\lego.exe
c:\documents and settings\Alana Guinn\Application Data\Arcsoft\nomad.exe
c:\documents and settings\Alana Guinn\Application Data\AdobeUM\rengo.dll
c:\documents and settings\Alana Guinn\Application Data\Azureus\msgdi.dll
c:\documents and settings\Alana Guinn\Application Data\Adobe\shalom.exe
c:\documents and settings\Alana Guinn\Application Data\ColorCop\kern.dll

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"


Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

NEXT


Please download GooredFix and save it to your Desktop.
  • Double-click GooredFix.exe on your Desktop to run it.
  • Select "2. Fix Goored" by typing 2 and pressing Enter.
  • Make sure all instances of Firefox are closed at this point.
  • Type y at the prompt and press Enter again.
  • A log will open, please post the contents of that log in your next reply (it can also be found on your desktop, called GooredLog.txt).
Note: If you receive a message saying that GooredFix needs your system to be restarted, please close all applications and reboot your system. Please also allow any registry changes that may be prompted by any of your security programs.


NEXT

Please download Malwarebytes' Anti-Malware
  • Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT


Run an on-line scan with Kaspersky

Please do a scan with Kaspersky Online Scanner. Please note: Kaspersky requires Java Runtime Environment (JRE) be installed before scanning for malware, as ActiveX is no longer being used.)

If you are using Windows Vista, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.


  • Now under the Scan section on the left:
    Select My Computer
  • The program will now start and scan your system. This will run for a while, be patient and let it finish.
  • Once the scan is complete, click on View scan report
  • Now, click on the Save Report as button.
  • Save the file to your desktop.
  • Copy and paste that information in your next post.
You can refer to this animation by sundavis.


In your next reply please include
  • ComboFix Log
  • GooredFix Log
  • MBAM Log
  • Kaspersky report
Hi CatByte,
Thanks again. Here is the latest HijackThis log:

ComboFix 09-05-31.06 - Alana Guinn 06/01/2009 19:14.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1452 [GMT -7:00]
Running from: c:\documents and settings\[removed]\Desktop\Combo-Fix.exe
Command switches used :: c:\documents and settings\Alana Guinn\Desktop\cfscript.txt

file zipped: c:\documents and settings\Alana Guinn\Application Data\Adobe\shalom.exe
file zipped: c:\documents and settings\Alana Guinn\Application Data\AdobeUM\rengo.dll
file zipped: c:\documents and settings\Alana Guinn\Application Data\Apple Computer\socks1.exe
file zipped: c:\documents and settings\Alana Guinn\Application Data\Arcsoft\nomad.exe
file zipped: c:\documents and settings\Alana Guinn\Application Data\AVGTOOLBAR\lego.exe
file zipped: c:\documents and settings\Alana Guinn\Application Data\Azureus\msgdi.dll
file zipped: c:\documents and settings\Alana Guinn\Application Data\ColorCop\kern.dll
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Alana Guinn\Application Data\Adobe\shalom.exe
c:\documents and settings\Alana Guinn\Application Data\AdobeUM\rengo.dll
c:\documents and settings\Alana Guinn\Application Data\Apple Computer\socks1.exe
c:\documents and settings\Alana Guinn\Application Data\Arcsoft\nomad.exe
c:\documents and settings\Alana Guinn\Application Data\AVGTOOLBAR\lego.exe
c:\documents and settings\Alana Guinn\Application Data\Azureus\msgdi.dll
c:\documents and settings\Alana Guinn\Application Data\ColorCop\kern.dll

.
((((((((((((((((((((((((( Files Created from 2009-05-02 to 2009-06-02 )))))))))))))))))))))))))))))))
.

2009-06-02 02:11 . 2009-06-02 02:11 ——– d-s—w- c:\windows\Cookies
2009-05-31 21:44 . 2009-05-31 21:44 664 —-a-w- c:\windows\system32\d3d9caps.dat
2009-05-23 00:32 . 2009-05-23 00:32 552 —-a-w- c:\windows\system32\d3d8caps.dat
2009-05-22 19:43 . 2009-03-09 19:06 15688 —-a-w- c:\windows\system32\lsdelete.exe
2009-05-22 19:35 . 2009-05-22 19:35 ——– d—–w- c:\program files\Trend Micro
2009-05-22 18:52 . 2009-05-22 18:52 ——– d—–w- c:\documents and settings\LocalService\Application Data\Share-to-Web Upload Folder
2009-05-22 18:36 . 2009-03-09 19:06 64160 —-a-w- c:\windows\system32\drivers\Lbd.sys
2009-05-22 18:33 . 2009-05-22 18:33 ——– dc-h–w- c:\documents and settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
2009-05-22 18:33 . 2009-03-12 08:17 2902048 -c–a-w- c:\documents and settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}\Ad-AwareAE.exe
2009-05-22 18:33 . 2009-05-22 18:33 ——– d—–w- c:\documents and settings\All Users\Application Data\Lavasoft
2009-05-22 05:26 . 2009-06-02 02:14 ——– d—–w- c:\documents and settings\Alana Guinn\Application Data\AVGTOOLBAR
2009-05-22 05:26 . 2009-05-31 21:43 ——– d—–w- c:\documents and settings\All Users\Application Data\avg8
2009-05-22 05:17 . 2009-05-22 05:17 ——– d-s—w- c:\documents and settings\LocalService\UserData
2009-05-22 05:02 . 2009-05-22 05:03 ——– d—–w- c:\documents and settings\LocalService\Local Settings\Application Data\Adobe
2009-05-22 04:51 . 2009-05-22 04:51 ——– d—–w- c:\documents and settings\LocalService\Local Settings\Application Data\Google
2009-05-18 05:15 . 2009-05-18 05:14 410984 —-a-w- c:\windows\system32\deploytk.dll
2009-05-18 05:14 . 2009-05-18 05:14 152576 —-a-w- c:\documents and settings\Alana Guinn\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2009-05-18 05:09 . 2009-05-18 05:09 ——– d—–w- c:\documents and settings\All Users\Application Data\DAEMON Tools Lite
2009-05-18 05:09 . 2009-05-18 05:09 ——– d—–w- c:\program files\DAEMON Tools Toolbar
2009-05-18 05:09 . 2009-05-18 05:09 ——– d—–w- c:\program files\DAEMON Tools Lite
2009-05-18 05:06 . 2009-05-18 05:10 ——– d—–w- c:\documents and settings\Alana Guinn\Application Data\DAEMON Tools Lite
2009-05-18 03:49 . 2009-05-18 05:06 721904 —-a-w- c:\windows\system32\drivers\sptd.sys
2009-05-05 19:42 . 2009-05-05 19:42 ——– d—–w- c:\documents and settings\Alana Guinn\Application Data\Share-to-Web Upload Folder

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-02 02:14 . 2008-09-17 00:15 ——– d—–w- c:\documents and settings\Alana Guinn\Application Data\ColorCop
2009-06-02 02:14 . 2008-06-21 05:55 ——– d—–w- c:\documents and settings\Alana Guinn\Application Data\Azureus
2009-06-02 02:14 . 2008-05-06 21:12 ——– d—–w- c:\documents and settings\Alana Guinn\Application Data\Arcsoft
2009-06-02 02:14 . 2006-04-08 02:48 ——– d—–w- c:\documents and settings\Alana Guinn\Application Data\AdobeUM
2009-06-02 02:14 . 2006-03-07 03:58 ——– d—–w- c:\documents and settings\Alana Guinn\Application Data\Apple Computer
2009-06-02 00:40 . 2008-06-12 22:10 ——– d—–w- c:\documents and settings\All Users\Application Data\Google Updater
2009-06-02 00:40 . 2006-02-26 00:01 322 —-a-w- c:\windows\system32\tablet.dat
2009-06-01 05:48 . 2006-11-26 22:55 ——– d—–w- c:\documents and settings\Alana Guinn\Application Data\Skype
2009-05-30 17:03 . 2006-04-06 00:12 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-05-30 17:03 . 2006-04-06 00:12 ——– d—–w- c:\program files\Spybot - Search & Destroy
2009-05-24 04:30 . 2006-04-06 19:45 ——– d—–w- c:\program files\Lavasoft
2009-05-24 04:30 . 2006-04-02 20:53 ——– d—–w- c:\documents and settings\Alana Guinn\Application Data\Lavasoft
2009-05-22 04:53 . 2006-02-09 12:34 ——– d—–w- c:\program files\Google
2009-05-20 18:12 . 2008-05-16 17:00 ——– d—–w- c:\documents and settings\Alana Guinn\Application Data\skypePM
2009-05-18 05:14 . 2006-02-09 12:30 ——– d—–w- c:\program files\Java
2009-05-15 23:02 . 2008-06-09 19:21 ——– d—–w- c:\documents and settings\Alana Guinn\Application Data\Move Networks
2009-05-05 19:13 . 2008-06-21 05:55 ——– d—–w- c:\program files\Vuze
2009-04-18 00:41 . 2008-12-19 00:55 ——– d—–w- c:\program files\DivX
2009-04-18 00:40 . 2009-04-18 00:40 ——– d—–w- c:\program files\Common Files\DivX Shared
2009-04-17 19:54 . 2009-04-17 19:54 ——– d—–w- c:\program files\Common Files\Skype
2009-04-17 19:54 . 2008-05-16 17:00 ——– d—–r- c:\program files\Skype
2009-04-17 19:54 . 2008-05-16 16:58 ——– d—–w- c:\documents and settings\All Users\Application Data\Skype
2009-04-09 03:16 . 2006-02-25 20:40 53400 —-a-w- c:\documents and settings\Alana Guinn\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-08 00:14 . 2009-04-08 00:14 1 —-a-w- c:\documents and settings\Alana Guinn\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2009-04-08 00:13 . 2009-04-08 00:13 ——– d—–w- c:\documents and settings\Alana Guinn\Application Data\OpenOffice.org
2009-04-08 00:09 . 2009-04-08 00:09 ——– d—–w- c:\program files\JRE
2009-04-08 00:09 . 2009-04-08 00:09 ——– d—–w- c:\program files\OpenOffice.org 3
2009-04-02 20:58 . 2008-11-30 03:51 10684866 —-a-w- c:\documents and settings\Alana Guinn\Application Data\Azureus\plugins\azump\mplayer.exe
2009-03-13 04:18 . 2009-03-13 04:18 75048 —-a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 8.1.0.52\SetupAdmin.exe
2009-03-09 18:34 . 2009-04-03 18:56 971776 —-a-w- c:\documents and settings\Alana Guinn\Application Data\Mozilla\Firefox\Profiles\ew8i4m3b.default\extensions\[removed]\platform\WINNT_x86-msvc\plugins\npmnqmp071303000006.dll
2009-03-06 14:22 . 2004-08-11 23:00 284160 —-a-w- c:\windows\system32\pdh.dll
2009-03-06 06:59 . 2009-03-16 18:04 36864 —-a-w- c:\windows\system32\drivers\usbaapl.sys
2009-03-06 06:59 . 2009-03-16 18:04 1900544 —-a-w- c:\windows\system32\usbaaplrc.dll
2009-02-24 19:34 . 2009-02-24 19:34 1044480 —-a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-02-24 19:34 . 2009-02-24 19:34 200704 —-a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.

((((((((((((((((((((((((((((( SnapShot@2009-06-02_00.56.09 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-06-02 02:11 . 2009-06-02 00:39 16384 c:\windows\Cookies\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2009-04-23 691656]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-06-12 68856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"vptray"="c:\progra~1\SYMANT~1\SYMANT~1\vptray.exe" [2003-05-21 90112]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-18 148888]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2005-04-25 139264]
"EPSON Stylus Photo R200 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_S4I2H1.EXE" [2003-07-08 99840]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 53248]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-07-14 339968]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-03-13 342312]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-03-09 515416]
"SigmatelSysTrayApp"="stsystra.exe" - c:\windows\stsystra.exe [2005-03-23 339968]

c:\documents and settings\Alana Guinn\Start Menu\Programs\Startup\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2004-10-4 113664]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2004-10-4 113664]
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-4-23 29696]
HotSync Manager.lnk - c:\program files\palmOne\Hotsync.exe [2004-6-9 471040]
HOTSYNCSHORTCUTNAME.lnk - c:\program files\palmOne\Hotsync.exe [2004-6-9 471040]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2008-10-24 19:03 10536 —-a-w- c:\program files\Citrix\GoToAssist\514\g2awinlogon.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKLM\~\startupfolder\C:^Documents and Settings^Alana Guinn^Start Menu^Programs^Startup^palmOne Registration.lnk]
path=c:\documents and settings\Alana Guinn\Start Menu\Programs\Startup\palmOne Registration.lnk
backup=c:\windows\pss\palmOne Registration.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^TabUserW.exe.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\TabUserW.exe.lnk
backup=c:\windows\pss\TabUserW.exe.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\usmt\\migwiz.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\SAGENT4.EXE"=
"c:\\Program Files\\Vuze\\Azureus.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"%windir%\\system32\\drivers\\svchost.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [5/22/2009 11:36 AM 64160]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [3/9/2009 12:06 PM 951632]
S3 PLUsbbc2;High-Speed USB Bridge Cable Driver;c:\windows\system32\drivers\usbbc2.sys [2/25/2006 7:19 PM 8960]
.
Contents of the 'Scheduled Tasks' folder

2009-05-22 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 19:06]

2009-05-20 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 19:34]

2009-06-02 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-06-09 02:24]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/ig/dell?hl=en
mStart Page = hxxp://www.dell.com
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
FF - ProfilePath - c:\documents and settings\Alana Guinn\Application Data\Mozilla\Firefox\Profiles\ew8i4m3b.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - component: c:\program files\Real\RealPlayer\browserrecord\components\nprpbrowserrecordplugin.dll
FF - plugin: c:\documents and settings\Alana Guinn\Application Data\Mozilla\Firefox\Profiles\ew8i4m3b.default\extensions\[removed]\platform\WINNT_x86-msvc\plugins\npmnqmp071303000006.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPAdbESD.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPUploader.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-01 19:16
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(708)
c:\program files\Citrix\GoToAssist\514\G2AWinLogon.dll
.
Completion time: 2009-06-02 19:18
ComboFix-quarantined-files.txt 2009-06-02 02:17
ComboFix2.txt 2009-06-02 00:59

Pre-Run: 175,648,423,936 bytes free
Post-Run: 175,633,506,304 bytes free

191 — E O F — 2009-05-14 04:08
Upload was successful

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI