This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Personal AntiVirus infection! Help!

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My grandfather's computer is the one infected with Personal AntiVirus, I'm trying to fix it for him.

He has AVG Pro, with an AVG firewall and somehow got Personal AntiVirus on his computer. I have tried the things I could find to get rid of it, but MalwareBytes only found 6 files, which I deleted and that didn't help at all.

So I haven't found a virus scan that finds the virus, but I know its there because it keeps popping up etc. I've stopped the process pv.exe but I couldn't find any others that were related.

I did an Erunt backup, and used the AFT Cleaner before doing the hijackthis log.

Hopefully this is enough information!


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:42:59 PM, on 18/07/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16850)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\PROGRA~1\AVG\AVG8\avgfws8.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\PROGRA~1\AVG\AVG8\avgam.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\WINDOWS\twain_32\DELL\MFP1125\Monitor\Stsmon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O2 - BHO: &Helper - {A77D3539-581D-450C-9E44-A84C415A6172} - C:\WINDOWS\system32\msxmlm.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -startup
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [PaperPort PTD] "C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe"
O4 - HKLM\..\Run: [IndexSearch] "C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe"
O4 - HKLM\..\Run: [MFPMonitor] C:\WINDOWS\twain_32\DELL\MFP1125\Monitor\Stsmon.exe
O4 - HKLM\..\Run: [PersonalAV] C:\Program Files\PersonalAV\pav.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: is-VOBME.lnk = C:\Documents and Settings\David\Desktop\Virus Removal Tool\is-VOBME\startup.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {94EB57FE-2720-496C-B33F-D9353C6E23F7} (F-Secure Online Scanner 2.1) - http://www.cogeco.ca/en/ols21/fscax.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secur…loadManager.ocx
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.popcap.com/webgames/popcaploader_v10.cab
O18 - Protocol: intu-qt2007 - {026BF40D-BA05-467B-9F1F-AD0D7A3F5F11} - C:\Program Files\QuickTax 2007\ic2007pp.dll
O18 - Protocol: intu-qt2008 - {05E53CE9-66C8-4A9E-A99F-FDB7A8E7B596} - C:\Program Files\QuickTax 2008\ic2008pp.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: AVG8 Firewall (avgfws8) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgfws8.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Desktop Manager 5.7.806.10245 (GoogleDesktopManager-061008-081103) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe

–
End of file - 9894 bytes
Hi,

Please do the following:

  • Open HiJackThis
  • Click on Do a system scan only
  • Check the boxes next to ONLY the entries listed below (if still present):


R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: &Helper - {A77D3539-581D-450C-9E44-A84C415A6172} - C:\WINDOWS\system32\msxmlm.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O4 - HKLM\..\Run: [PersonalAV] C:\Program Files\PersonalAV\pav.exe
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.popcap.com/webgames/popcaploader_v10.cab

  • Close all windows except Hijackthis and click Fix Checked
  • Click Yes when prompted
  • Close HijackThis.


NEXT

Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.pif to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.


NEXT


[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
Thank you very much! DDS (Ver_09-06-26.01) - NTFSx86 Run by [removed] at 10:49:56.17 on 19/07/2009 Internet Explorer: 7.0.5730.11 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1022.429 [GMT -4:00] AV: AVG Anti-Virus plus Firewall *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} FW: AVG Firewall *enabled* {8decf618-9569-4340-b34a-d78d28969b66} ============== Running Processes =============== C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe C:\PROGRA~1\AVG\AVG8\avgfws8.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\PROGRA~1\AVG\AVG8\avgam.exe C:\PROGRA~1\AVG\AVG8\avgemc.exe C:\PROGRA~1\AVG\AVG8\avgrsx.exe C:\PROGRA~1\AVG\AVG8\avgnsx.exe C:\WINDOWS\Explorer.EXE C:\Program Files\AVG\AVG8\avgcsrvx.exe C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe C:\PROGRA~1\AVG\AVG8\avgtray.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe C:\WINDOWS\twain_32\DELL\MFP1125\Monitor\Stsmon.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe C:\Documents and Settings\David\Desktop\gmer\gmer.exe C:\Documents and Settings\David\Desktop\dds.pif ============== Pseudo HJT Report =============== uStart Page = hxxp://www.google.ca/ uSearch Page = hxxp://www.google.com uSearch Bar = hxxp://www.google.com/ie uInternet Connection Wizard,ShellNext = iexplore uInternet Settings,ProxyOverride = *.local uSearchURL,(Default) = hxxp://www.google.com/keyword/%s mSearchAssistant = hxxp://www.google.com/ie uURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg8\toolbar\IEToolbar.dll mURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg8\toolbar\IEToolbar.dll BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll BHO: {53707962-6f74-2d53-2644-206d7942484f} - c:\program files\spybot - search & destroy\SDHelper.dll BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\tfswshx.dll BHO: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg8\toolbar\IEToolbar.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - c:\program files\avg\avg8\toolbar\IEToolbar.dll TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background mRun: [ISUSPM Startup] "c:\program files\common files\installshield\updateservice\ISUSPM.exe" -startup mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [SSBkgdUpdate] "c:\program files\common files\scansoft shared\ssbkgdupdate\SSBkgdupdate.exe" -Embedding -boot mRun: [PaperPort PTD] "c:\program files\scansoft\paperport\pptd40nt.exe" mRun: [IndexSearch] "c:\program files\scansoft\paperport\IndexSearch.exe" mRun: [MFPMonitor] c:\windows\twain_32\dell\mfp1125\monitor\Stsmon.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office\OSA9.EXE StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\quickb~1.lnk - c:\program files\common files\intuit\quickbooks\qbupdate\qbupdate.exe IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll Trusted Zone: musicmatch.com\online DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {94EB57FE-2720-496C-B33F-D9353C6E23F7} - hxxp://www.cogeco.ca/en/ols21/fscax.cab DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} - hxxps://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} - hxxp://messenger.msn.com/download/MsnMessengerSetupDownloader.cab DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab DPF: {CAFEEFAC-0015-0000-0008-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_08-windows-i586.cab DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_10-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab Handler: intu-qt2007 - {026BF40D-BA05-467b-9F1F-AD0D7A3F5F11} - c:\program files\quicktax 2007\ic2007pp.dll Handler: intu-qt2008 - {05E53CE9-66C8-4a9e-A99F-FDB7A8E7B596} - c:\program files\quicktax 2008\ic2008pp.dll Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll Notify: avgrsstarter - avgrsstx.dll AppInit_DLLs: c:\progra~1\google\google~2\GOEC62~1.DLL SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll ============= SERVICES / DRIVERS =============== R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [2009-5-12 12552] R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-7-17 64160] R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-5-12 335752] R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2009-4-16 27784] R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-5-12 108552] R2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\avg\avg8\avgemc.exe [2009-5-12 907032] R2 avg8wd;AVG8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2009-5-12 298776] R2 avgfws8;AVG8 Firewall;c:\progra~1\avg\avg8\avgfws8.exe [2009-5-12 1368952] R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-7-3 1029456] R3 Avgfwdx;Avgfwdx;c:\windows\system32\drivers\avgfwdx.sys [2009-5-12 29208] S3 Avgfwfd;AVG network filter service;c:\windows\system32\drivers\avgfwdx.sys [2009-5-12 29208] S3 GoogleDesktopManager-061008-081103;Google Desktop Manager 5.7.806.10245;c:\program files\google\google desktop search\GoogleDesktop.exe [2008-2-3 29744] =============== Created Last 30 ================ 2009-07-18 14:42 –d—– c:\program files\Trend Micro 2009-07-18 13:59 1,597,472 a–sh— c:\windows\system32\drivers\fidbox.dat 2009-07-18 13:59 19,796 a–sh— c:\windows\system32\drivers\fidbox.idx 2009-07-17 12:35 –d—– c:\program files\SpywareBlaster 2009-07-17 12:06 15,688 a——- c:\windows\system32\lsdelete.exe 2009-07-17 11:59 64,160 a——- c:\windows\system32\drivers\Lbd.sys 2009-07-17 11:58 -cd-h— c:\docume~1\alluse~1\applic~1\{EF63305C-BAD7-4144-9208-D65528260864} 2009-07-17 11:58 –d—– c:\program files\Lavasoft 2009-07-17 11:35 –d—– c:\docume~1\david\applic~1\Malwarebytes 2009-07-17 11:35 38,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-07-17 11:35 19,096 a——- c:\windows\system32\drivers\mbam.sys 2009-07-17 11:35 –d—– c:\program files\Malwarebytes' Anti-Malware 2009-07-17 11:35 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes 2009-07-17 10:23 –d—– c:\program files\common files\Uninstall 2009-07-17 10:22 –d—– c:\program files\PersonalAV 2009-07-15 20:37 –d—– c:\docume~1\david\applic~1\Monotype Imaging 2009-07-15 20:26 49,152 —-h— c:\windows\devcon.exe 2009-07-15 20:26 53,248 a——- c:\windows\system32\vdrde.dll 2009-07-15 20:23 45,056 a——- c:\windows\system32\vdrsetup.dll 2009-07-15 20:22 101,888 a——- c:\windows\system32\D1125WIA.dll 2009-07-15 20:16 31,567 a——- c:\windows\maxlink.ini 2009-07-15 20:16 –d—– c:\program files\ScanSoft 2009-07-15 20:14 2,418 —-h— c:\windows\DRUnins.ini 2009-07-15 20:14 2,292,176 a—-r– c:\windows\Uninstall.exe 2009-07-15 20:14 128,240 a—-r– c:\windows\Druni.exe 2009-07-15 20:14 26,096 a——- c:\windows\SFA.exe 2009-07-15 20:14 550 —-h— c:\windows\Uninstall.iss 2009-07-15 20:01 –d—– c:\program files\VS Revo Group 2009-07-15 19:56 –d—– c:\program files\iPod 2009-07-15 19:56 –d—– c:\program files\iTunes 2009-07-15 19:56 –d—– c:\docume~1\alluse~1\applic~1\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906} 2009-07-15 19:54 –d—– c:\program files\Bonjour 2009-07-15 18:01 –d—– c:\windows\system32\drivers\NSS 2009-07-15 18:01 –d—– c:\docume~1\alluse~1\applic~1\Norton 2009-07-15 18:00 –d—– c:\docume~1\alluse~1\applic~1\Symantec 2009-07-15 18:00 –d—– c:\docume~1\alluse~1\applic~1\NortonInstaller ==================== Find3M ==================== 2009-07-16 06:49 5,018 a–sh— c:\windows\system32\KGyGaAvL.sys 2009-07-07 09:28 335,752 a——- c:\windows\system32\drivers\avgldx86.sys 2009-06-16 10:36 119,808 a——- c:\windows\system32\t2embed.dll 2009-06-16 10:36 81,920 a——- c:\windows\system32\fontsub.dll 2009-06-16 10:36 119,808 ——– c:\windows\system32\dllcache\t2embed.dll 2009-06-16 10:36 81,920 ——– c:\windows\system32\dllcache\fontsub.dll 2009-06-03 15:09 1,291,264 a——- c:\windows\system32\quartz.dll 2009-06-03 15:09 1,291,264 ——– c:\windows\system32\dllcache\quartz.dll 2009-05-12 17:16 11,952 a——- c:\windows\system32\avgrsstx.dll 2009-05-12 17:15 50,968 a——- c:\windows\system32\avgfwdx.dll 2009-05-07 11:32 345,600 a——- c:\windows\system32\localspl.dll 2009-05-07 11:32 345,600 ——– c:\windows\system32\dllcache\localspl.dll 2009-04-29 00:56 827,392 a——- c:\windows\system32\wininet.dll 2009-04-29 00:56 827,392 a——- c:\windows\system32\dllcache\wininet.dll 2009-04-29 00:56 233,472 ——– c:\windows\system32\dllcache\webcheck.dll 2009-04-29 00:56 1,159,680 a——- c:\windows\system32\dllcache\urlmon.dll 2009-04-29 00:56 671,232 a——- c:\windows\system32\dllcache\mstime.dll 2009-04-29 00:56 44,544 a——- c:\windows\system32\dllcache\pngfilt.dll 2009-04-29 00:56 105,984 ——– c:\windows\system32\dllcache\url.dll 2009-04-29 00:56 102,912 ——– c:\windows\system32\dllcache\occache.dll 2009-04-29 00:56 3,596,288 a——- c:\windows\system32\dllcache\mshtml.dll 2009-04-29 00:56 477,696 a——- c:\windows\system32\dllcache\mshtmled.dll 2009-04-29 00:56 193,024 a——- c:\windows\system32\dllcache\msrating.dll 2009-04-28 05:05 70,656 ——– c:\windows\system32\dllcache\ie4uinit.exe 2009-04-28 05:05 13,824 ——– c:\windows\system32\dllcache\ieudinit.exe 2009-04-25 01:27 636,088 ——– c:\windows\system32\dllcache\iexplore.exe 2009-04-25 01:26 161,792 ——– c:\windows\system32\dllcache\ieakui.dll 2006-09-29 20:32 1 a——- c:\documents and settings\david\scrcfg.dat 2008-08-24 17:00 32,768 a–sh— c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008082420080825\index.dat ============= FINISH: 10:50:16.21 ===============
Hi,

Please do the following:


Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.


Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now
I don't have internet on the infected computer, I've brought their tower to my house and I can't get online with it here. Is there somewhere I can download the Microsoft Windows Recovery Console to transfer over and install it? Also, I could not get AVG to turn off or even the processes to end without completely uninstalling it. It is no longer running, the processes are gone, but ComboFix thinks its still there, is it safe to run the scan?
Thanks, got it to run. But it hasn't affected Personal Antivirus at all, its still there.



ComboFix 09-07-19.02 - David 19/07/2009 18:04.1.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1022.625 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: AVG Anti-Virus plus Firewall *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: AVG Firewall *disabled* {8decf618-9569-4340-b34a-d78d28969b66}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\windows\Installer\1947a.msi
c:\windows\Installer\1bdce7.msi
c:\windows\Installer\6d07.msi
c:\windows\Installer\6d0e.msi
c:\windows\Installer\6d15.msi
c:\windows\Installer\6d1c.msi
c:\windows\Installer\6d23.msi
c:\windows\Installer\6d3e.msi
c:\windows\Installer\a0e837.msi
c:\windows\Installer\ec70256.msi

—– BITS: Possible infected sites —–

hxxp://symlabssoftwareupdate.com
.
((((((((((((((((((((((((( Files Created from 2009-06-19 to 2009-07-19 )))))))))))))))))))))))))))))))
.

2009-07-18 18:42 . 2009-07-18 18:42 ——– d—–w- c:\program files\Trend Micro
2009-07-18 18:26 . 2009-07-18 18:26 ——– d—–w- c:\program files\ERUNT
2009-07-18 17:59 . 2009-07-19 02:00 1597472 –sha-w- c:\windows\system32\drivers\fidbox.dat
2009-07-17 16:35 . 2009-07-17 16:35 ——– d—–w- c:\documents and settings\All Users\Application Data\TEMP
2009-07-17 16:35 . 2009-07-17 16:35 ——– d—–w- c:\program files\SpywareBlaster
2009-07-17 16:06 . 2009-07-03 14:49 15688 —-a-w- c:\windows\system32\lsdelete.exe
2009-07-17 15:59 . 2009-07-03 14:49 64160 —-a-w- c:\windows\system32\drivers\Lbd.sys
2009-07-17 15:58 . 2009-07-17 15:59 ——– d—–w- c:\documents and settings\All Users\Application Data\Lavasoft
2009-07-17 15:58 . 2009-07-17 15:58 ——– d—–w- c:\program files\Lavasoft
2009-07-17 15:35 . 2009-07-17 15:35 ——– d—–w- c:\documents and settings\David\Application Data\Malwarebytes
2009-07-17 15:35 . 2009-06-17 15:27 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-17 15:35 . 2009-07-17 15:35 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-07-17 15:35 . 2009-07-17 15:35 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-07-17 15:35 . 2009-06-17 15:27 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-07-17 14:23 . 2009-07-17 14:23 ——– d—–w- c:\program files\Common Files\Uninstall
2009-07-17 14:22 . 2009-07-17 14:23 ——– d—–w- c:\program files\PersonalAV
2009-07-16 11:47 . 2009-07-16 11:47 ——– d—–w- c:\windows\system32\config\systemprofile\Application Data\Dell
2009-07-16 11:47 . 2009-07-16 11:47 ——– d—–w- c:\windows\system32\config\systemprofile\Application Data\Monotype Imaging
2009-07-16 00:37 . 2009-07-16 00:37 ——– d—–w- c:\documents and settings\David\Application Data\Monotype Imaging
2009-07-16 00:33 . 2009-07-16 00:33 ——– d—–w- c:\documents and settings\LocalService\Application Data\Dell
2009-07-16 00:33 . 2009-07-16 00:33 ——– d—–w- c:\documents and settings\LocalService\Application Data\Monotype Imaging
2009-07-16 00:26 . 2007-04-20 20:47 49152 —h–w- c:\windows\devcon.exe
2009-07-16 00:26 . 2007-11-07 05:59 53248 —-a-w- c:\windows\system32\vdrde.dll
2009-07-16 00:23 . 2007-11-07 06:00 45056 —-a-w- c:\windows\system32\vdrsetup.dll
2009-07-16 00:22 . 2007-11-07 05:59 101888 —-a-w- c:\windows\system32\D1125WIA.dll
2009-07-16 00:19 . 2009-07-16 00:19 ——– d—–w- c:\documents and settings\David\Local Settings\Application Data\Scansoft
2009-07-16 00:16 . 2009-07-16 00:16 ——– d—–w- c:\program files\ScanSoft
2009-07-16 00:14 . 2007-11-07 05:59 2292176 —-a-r- c:\windows\Uninstall.exe
2009-07-16 00:14 . 2007-11-07 05:59 128240 —-a-r- c:\windows\Druni.exe
2009-07-16 00:14 . 2007-05-18 15:20 26096 —-a-w- c:\windows\SFA.exe
2009-07-16 00:13 . 2009-07-16 00:13 ——– d—–w- c:\documents and settings\David\Application Data\InstallShield
2009-07-16 00:01 . 2009-07-16 00:01 ——– d—–w- c:\program files\VS Revo Group
2009-07-15 23:58 . 2009-07-15 23:58 ——– d—–w- c:\program files\Apple Software Update
2009-07-15 23:56 . 2009-07-15 23:56 ——– d—–w- c:\program files\iPod
2009-07-15 23:56 . 2009-07-15 23:57 ——– d—–w- c:\program files\iTunes
2009-07-15 23:56 . 2009-07-15 23:57 ——– d—–w- c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-07-15 23:54 . 2009-07-15 23:54 ——– d—–w- c:\program files\Bonjour
2009-07-15 23:52 . 2009-07-16 00:04 ——– d—–w- c:\program files\QuickTime
2009-07-15 23:46 . 2009-07-15 23:46 75040 —-a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 8.2.1.6\SetupAdmin.exe
2009-07-15 22:01 . 2009-07-15 22:01 ——– d—–w- c:\documents and settings\All Users\Application Data\Norton
2009-07-15 22:01 . 2009-07-15 22:01 ——– d—–w- c:\windows\system32\drivers\NSS
2009-07-15 22:00 . 2009-07-15 22:00 ——– d—–w- c:\documents and settings\All Users\Application Data\Symantec
2009-07-15 22:00 . 2009-07-15 22:00 ——– d—–w- c:\documents and settings\All Users\Application Data\NortonInstaller

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-19 20:34 . 2009-05-12 21:15 ——– d—–w- c:\documents and settings\All Users\Application Data\avg8
2009-07-19 03:20 . 2005-12-02 03:07 ——– d—–w- c:\program files\Sonic
2009-07-19 03:13 . 2007-02-08 19:26 ——– d—–w- c:\program files\HP
2009-07-19 03:13 . 2006-06-10 16:12 ——– d—–w- c:\program files\Hewlett-Packard
2009-07-19 03:00 . 2007-01-22 15:39 ——– d—–w- c:\program files\Google
2009-07-19 02:59 . 2005-12-02 03:13 ——– d—–w- c:\program files\Corel
2009-07-19 02:00 . 2009-07-18 17:59 19796 –sha-w- c:\windows\system32\drivers\fidbox.idx
2009-07-16 10:49 . 2005-12-21 23:40 5018 –sha-w- c:\windows\system32\KGyGaAvL.sys
2009-07-16 10:49 . 2006-12-08 19:06 88 –sh–r- c:\windows\system32\05CE6C3B71.sys
2009-07-16 00:22 . 2005-12-02 03:12 ——– d—–w- c:\program files\Dell
2009-07-16 00:20 . 2006-01-15 19:24 56384 —-a-w- c:\documents and settings\David\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-16 00:16 . 2005-12-18 20:45 ——– d—–w- c:\documents and settings\All Users\Application Data\ScanSoft
2009-07-16 00:16 . 2005-12-18 20:46 ——– d—–w- c:\program files\Common Files\ScanSoft Shared
2009-07-16 00:09 . 2008-12-28 18:52 ——– d—–w- c:\program files\Common Files\Symantec Shared
2009-07-16 00:04 . 2005-12-02 03:08 ——– d—–w- c:\program files\WordPerfect Office 12
2009-07-16 00:04 . 2005-12-02 03:03 ——– d—–w- c:\program files\Modem Helper
2009-07-16 00:04 . 2005-12-02 03:04 ——– d—–w- c:\program files\Common Files\AOL
2009-07-15 23:56 . 2007-12-25 16:43 ——– d—–w- c:\program files\Common Files\Apple
2009-07-14 17:17 . 2008-01-31 15:32 4286 —-a-w- c:\documents and settings\All Users\Application Data\Intuit\QuickBooks 2008\qbbackup.sys
2009-07-07 13:28 . 2009-05-12 21:16 335752 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2009-06-16 14:36 . 2004-08-10 18:51 119808 —-a-w- c:\windows\system32\t2embed.dll
2009-06-16 14:36 . 2004-08-10 18:51 81920 —-a-w- c:\windows\system32\fontsub.dll
2009-06-16 12:50 . 2009-04-16 17:04 27784 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-06-11 17:02 . 2009-06-11 13:04 ——– d—–w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2009-06-11 13:03 . 2009-06-11 13:03 ——– d—–w- c:\documents and settings\LocalService\Application Data\AVGTOOLBAR
2009-06-03 19:09 . 2004-08-10 18:51 1291264 —-a-w- c:\windows\system32\quartz.dll
2009-06-02 17:38 . 2009-06-11 17:02 1004800 —-a-w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar\IEToolbar.dll
2009-05-26 00:50 . 2009-05-12 21:16 ——– d—–w- c:\documents and settings\David\Application Data\AVGTOOLBAR
2009-05-19 17:39 . 2009-05-19 17:39 152576 —-a-w- c:\documents and settings\David\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2009-05-12 21:16 . 2009-05-12 21:16 11952 —-a-w- c:\windows\system32\avgrsstx.dll
2009-05-12 21:16 . 2009-05-12 21:16 12552 —-a-w- c:\windows\system32\drivers\avgrkx86.sys
2009-05-12 21:16 . 2009-05-12 21:16 108552 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2009-05-12 21:15 . 2009-05-12 21:15 50968 —-a-w- c:\windows\system32\avgfwdx.dll
2009-05-12 21:15 . 2009-05-12 21:15 29208 —-a-w- c:\windows\system32\drivers\avgfwdx.sys
2009-05-07 15:32 . 2004-08-10 18:51 345600 —-a-w- c:\windows\system32\localspl.dll
2009-04-29 04:56 . 2004-08-10 18:51 827392 —-a-w- c:\windows\system32\wininet.dll
2009-04-29 04:55 . 2004-08-10 18:51 78336 —-a-w- c:\windows\system32\ieencode.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2005-06-10 249856]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-10-06 29744]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-26 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-07-13 292128]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472]
"PaperPort PTD"="c:\program files\ScanSoft\PaperPort\pptd40nt.exe" [2007-05-16 30248]
"IndexSearch"="c:\program files\ScanSoft\PaperPort\IndexSearch.exe" [2007-05-16 46632]
"MFPMonitor"="c:\windows\twain_32\DELL\MFP1125\Monitor\Stsmon.exe" [2007-08-08 2002944]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-4-23 29696]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-2-17 65588]
QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2009-3-4 967960]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-05-12 21:16 11952 —-a-w- c:\windows\system32\avgrsstx.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\StubInstaller.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Intuit\\QuickBooks 2008\\QBDBMgrN.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [12/05/2009 5:16 PM 12552]
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [17/07/2009 11:59 AM 64160]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [12/05/2009 5:16 PM 335752]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [12/05/2009 5:16 PM 108552]
R3 Avgfwdx;Avgfwdx;c:\windows\system32\drivers\avgfwdx.sys [12/05/2009 5:15 PM 29208]
S3 Avgfwfd;AVG network filter service;c:\windows\system32\drivers\avgfwdx.sys [12/05/2009 5:15 PM 29208]
S3 GoogleDesktopManager-061008-081103;Google Desktop Manager 5.7.806.10245;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [03/02/2008 1:38 PM 29744]
.
Contents of the 'Scheduled Tasks' folder

2009-07-15 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]

2005-12-10 c:\windows\Tasks\ISP signup reminder 1.job
- c:\windows\system32\OOBE\oobebaln.exe [2004-08-10 00:12]
.
- - - - ORPHANS REMOVED - - - -

URLSearchHooks-{A3BC75A2-1F87-4686-AA43-5347D756017C} - (no file)
Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
SafeBoot-Lavasoft Ad-Aware Service


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.ca/
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
Trusted Zone: musicmatch.com\online
Handler: intu-qt2007 - {026BF40D-BA05-467b-9F1F-AD0D7A3F5F11} - c:\program files\QuickTax 2007\ic2007pp.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-19 18:09
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(2404)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\ati2evxx.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-07-19 18:13 - machine was rebooted
ComboFix-quarantined-files.txt 2009-07-19 22:13

Pre-Run: 130,293,682,176 bytes free
Post-Run: 130,187,591,680 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

216 — E O F — 2009-07-16 02:11
Hi,

Please do the following:

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

Folder::
c:\program files\PersonalAV

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"


Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.


NEXT


Please download Malwarebytes' Anti-Malware
  • Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT

Run an on-line scan with Kaspersky

Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take several minutes.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.

    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply


In your next reply please include
  • ComboFix Log
  • MBAM Log
  • Kaspersky report
My mistake sorry, I asked you to do an online scan and it's just registered in my head, that you explained you couldn't get online with this machine :smack: Please disregard that part.

My mistake sorry, I asked you to do an online scan and it's just registered in my head, that you explained you couldn't get online with this machine :smack:

Please disregard that part.


It's okay, I actually rearranged everything and managed to get online with it so I could get that recovery thing through the program, because it wasn't working right. I'm just waiting for the Online Scanner to download everything and update. I'll post all 3 reports as soon as the online scanner is done :)

scan (sorry to shock you LOL)


I just didn't expect it to take so long lol. But they do have alot of things on their C drive. I'll leave it overnight and post the logs in the morning, thanks :)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI