This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] What's left after Super Anit Spyware?

18 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Helping a friend to clean up her PC running XP Home, following removal (I hope) of Super Anti Spyware. Running very slowly, and will not shut down. Thanks in advance! ***GMER site is not allowing downloads**** Restore point created. ERUNT completed. 📎Attach.txt DDS: DDS (Ver_10-03-17.01) - NTFSx86 Run by [removed] at 11:41:37.48 on Tue 04/06/2010 Internet Explorer: 6.0.2900.5512 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.510.77 [GMT -5:00] AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} ============== Running Processes =============== C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Analog Devices\Core\smax4pnp.exe C:\Program Files\Dell Photo AIO Printer 942\dlbubmgr.exe C:\Program Files\Dell Photo AIO Printer 942\memcard.exe C:\Program Files\Dell Photo AIO Printer 942\dlbubmon.exe C:\PROGRA~1\AVG\AVG8\avgtray.exe C:\Program Files\iTunes\iTunesHelper.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe svchost.exe C:\Program Files\Citrix\Secure Access Client\nsload.exe C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\APC\APC PowerChute Personal Edition\apcsystray.exe C:\PROGRA~1\AVG\AVG8\avgrsx.exe C:\PROGRA~1\AVG\AVG8\avgnsx.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\Program Files\Citrix\Secure Access Client\nsverctl.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\PROGRA~1\AVG\AVG8\avgemc.exe C:\Program Files\AVG\AVG8\avgcsrvx.exe C:\Program Files\iPod\bin\iPodService.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Documents and Settings\Yelena\Desktop\Malware\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://www.google.com/ uSearch Page = hxxp://www.google.com uSearch Bar = hxxp://www.google.com/ie mDefault_Search_URL = hxxp://www.google.com/ie uInternet Settings,ProxyServer = http=127.0.0.1:5555 uInternet Settings,ProxyOverride = uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s mSearchAssistant = hxxp://www.google.com/ie uURLSearchHooks: H - No File uURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg8\toolbar\IEToolbar.dll mURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg8\toolbar\IEToolbar.dll BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.5.0_11\bin\ssv.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.5.4723.1820\swg.dll TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - c:\program files\avg\avg8\toolbar\IEToolbar.dll TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe" uRun: [mcovnsfx] c:\documents and settings\yelena\local settings\application data\hueegh\diiosftav.exe mRun: [SoundMAXPnP] c:\program files\analog devices\core\smax4pnp.exe mRun: [UIUCU] c:\docume~1\yelena\locals~1\temp\UIUCU.EXE -CLEAN_UP -S mRun: [ATIPTA] "c:\program files\ati technologies\ati control panel\atiptaxx.exe" mRun: [Dell Photo AIO Printer 942] "c:\program files\dell photo aio printer 942\dlbubmgr.exe" mRun: [DellMCM] "c:\program files\dell photo aio printer 942\memcard.exe" mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe mRun: [21098746521098765] c:\documents and settings\all users\application data\gav\gav.exe mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [mcovnsfx] c:\documents and settings\yelena\local settings\application data\hueegh\diiosftav.exe mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k dRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\apcups~1.lnk - c:\program files\apc\apc powerchute personal edition\Display.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\citrix~1.lnk - c:\program files\citrix\secure access client\nsload.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\mcafee~1.lnk - c:\program files\mcafee security scan\1.0.150\SSScheduler.exe IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000 IE: Google Sidewiki… - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBC} - c:\program files\java\jre1.5.0_11\bin\ssv.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL LSP: c:\program files\common files\pc tools\lsp\PCTLsp.dll DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxps://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll Notify: avgrsstarter - avgrsstx.dll Hosts: 208.43.47.212 a1.review.zdnet.com Hosts: 208.43.47.212 reviews.riverstreams.co.uk Hosts: [removed] d1.reviews.cnet.com Hosts: [removed] review.2009softwarereviews.com Hosts: 208.43.47.212 reviews.download.com Note: multiple HOSTS entries found. Please refer to Attach.txt ============= SERVICES / DRIVERS =============== R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-5-29 335240] R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2007-4-6 27784] R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-5-29 108552] R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\avg\avg8\avgemc.exe [2009-5-29 908056] R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2009-5-29 297752] R2 cag;Citrix cag plugin for Access Gateway;c:\program files\common files\deterministic networks\common files\cag.sys [2009-10-22 80920] R2 nsverctl;Citrix Secure Access Client Service;c:\program files\citrix\secure access client\nsverctl.exe [2010-1-19 154264] R3 ctxva51;Citrix Virtual Adapter;c:\windows\system32\drivers\ctxva51.sys [2010-1-19 41624] S2 Browser Defender Update Service;Browser Defender Update Service;c:\program files\spyware doctor\bdt\BDTUpdateService.exe [2010-3-22 112592] S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-2-4 135664] S3 Net6IM;Net6;c:\windows\system32\drivers\net6im51.sys –> c:\windows\system32\drivers\net6im51.sys [?] S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\spyware doctor\pctsAuxs.exe [2010-3-22 366840] S3 sdCoreService;PC Tools Security Service;c:\program files\spyware doctor\pctsSvc.exe [2010-3-22 1142224] =============== Created Last 30 ================ 2010-03-23 04:23:55 216520 —-a-w- c:\windows\system32\drivers\PCTCore.sys 2010-03-23 04:23:50 7383 —-a-w- c:\windows\system32\drivers\pctcore.cat 2010-03-23 04:23:49 88040 —-a-w- c:\windows\system32\drivers\PCTAppEvent.sys 2010-03-23 04:23:47 7412 —-a-w- c:\windows\system32\drivers\PCTAppEvent.cat 2010-03-23 03:41:35 767952 —-a-w- c:\windows\BDTSupport.dll 2010-03-23 03:41:34 882 —-a-w- c:\windows\RegSDImport.xml 2010-03-23 03:41:34 879 —-a-w- c:\windows\RegISSImport.xml 2010-03-23 03:41:34 165840 —-a-w- c:\windows\PCTBDRes.dll 2010-03-23 03:41:34 1652688 —-a-w- c:\windows\PCTBDCore.dll 2010-03-23 03:41:34 149456 —-a-w- c:\windows\SGDetectionTool.dll 2010-03-23 03:41:34 131 —-a-w- c:\windows\IDB.zip 2010-03-23 03:41:34 1152444 —-a-w- c:\windows\UDB.zip 2010-03-23 03:40:15 7387 —-a-w- c:\windows\system32\drivers\pctgntdi.cat 2010-03-23 03:40:15 233136 —-a-w- c:\windows\system32\drivers\pctgntdi.sys 2010-03-23 03:40:09 7383 —-a-w- c:\windows\system32\drivers\pctplsg.cat 2010-03-23 03:40:09 70408 —-a-w- c:\windows\system32\drivers\pctplsg.sys 2010-03-23 03:40:01 0 d—–w- c:\program files\Spyware Doctor 2010-03-23 03:40:01 0 d—–w- c:\program files\common files\PC Tools 2010-03-23 03:40:01 0 d—–w- c:\docume~1\yelena\applic~1\PC Tools 2010-03-23 03:40:01 0 d—–w- c:\docume~1\alluse~1\applic~1\PC Tools 2010-03-19 03:40:51 232 —-a-w- c:\windows\reimage.ini 2010-03-19 03:40:20 0 d—–w- c:\program files\Reimage 2010-03-11 02:57:10 3558912 -c—-w- c:\windows\system32\dllcache\moviemk.exe ==================== Find3M ==================== 2010-01-27 01:01:09 60744 —-a-w- c:\documents and settings\yelena\g2mdlhlpx.exe ============= FINISH: 11:42:11.01 ===============
Hello neuro and :welcome:

My name is JonTom.

  • Malware Logs can sometimes take a lot of time to research and interpret.
  • Please be patient while I try to assist with your problem. If at any time you do not understand what is required, please ask for further explanation.
  • Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to get your system clean.
  • Read every reply you receive carefully and thoroughly before carrying out the instructions. You may also find it helpful to print out the instructions you receive, as in some instances you may have to disconnect your computer from the Internet.
  • PLEASE NOTE: If you do not reply after 5 days your thread will be closed.

  • Please be aware that I am still in training, and all of my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advice.
  • This may cause a delay in response time, but I will do my best to keep it as short as possible.
  • I will reply back shortly with instructions.
GMER website download page is now available; ran GMER twice, crashing both times. The second bsd listed "PAGE_FAULT_IN_NONPAGED_AREA" for file kwlyqfog.sys. This file did not turn up in a file search (including system and hidden files). Not sure if I should try running GMER again in safe mode or otherwise. It seemed to make it all the way through "temproary internet files", which appear to never have been deleted on this PC! I'll await your initial analysis and further instructions.
Hello neuro

Thank you for the log.

Please work your way through the following steps. Take your time. If you are unsure about anything come back and ask - it is what I am here for.

  • Please download OTM


    • Please download OTM by OldTimer by clicking here.
    • Save the file (called OTM.exe) to your desktop.
    • Double click on the OTM.exe icon to run the program. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
    • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):


    :Processes 
    explorer.exe
    
    :Files
    c:\documents and settings\yelena\local settings\application data\hueegh\diiosftav.exe
    c:\documents and settings\all users\application data\gav\gav.exe
    c:\documents and settings\yelena\local settings\application data\hueegh
    c:\documents and settings\all users\application data\gav
    
    :Reg
    [HKEY_CURRENT_USER\Sofware\Microsoft\Windows\CurrentVersion\Internet Settings]
    "ProxyServer"=-
    "ProxyOverride"=-
    
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks]
    "{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"=""
    
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "mcovnsfx"=-
    
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "mcovnsfx"=-
    
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "21098746521098765"=-
    
    :Commands
    [Resethosts]
    [Purity]
    [EmptyTemp]
    [Start Explorer]
    [Reboot]




    • Return to OTM, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
    • Click the Moveit! button.
    • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
    • Close OTM.
    • Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File -> Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.
  • Please perform the following scan:


    • Please download MalwareBytes AntiMalware by clicking here and save the file (called mbam-setup.exe) to your desktop.
    • Double click on the mbam-setup.exe icon to install the program.
    • Follow the prompts during installation and have the Installation Wizzard create a desktop icon.
    • Once installed, double click on the MalwareBytes AntiMalware icon to launch the program.
    • A screen will appear. It will look like this:

    [external image: Posted Image]


    • Click on the "Update" tab and then on "Check for Updates".
    • The program will now install the latest Malware definition files.
    • Once complete, click on the "Scanner" tab, select "Perform full scan"and then click on "Scan".
    • Once the program has scanned your computer, a log file will be created in Notepad.
    • Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log.


    • If the scan detects any Malware-related objects, make sure that everything is checked, and click "Remove Selected" <– Very Important.
    • When disinfection is completed, a log will open in Notepad and you may be prompted to restart your computer.
    • The log is automatically saved by MBAM and can be viewed by clicking the "Logs" tab.
    • Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process. If asked to restart your computer, please do so immediately.
    • Come back here to this thread and Paste the log in your next reply.

  • Please make all files and folders VISIBLE:


    • Click "Start" Go to My Computer-> Tools-> Folder Options-> View tab:
    • Choose to "Show hidden files and folders."
    • Uncheck the "Hide protected operating system files" and the "Hide extensions for know file types" boxes.
    • Close the window with "OK".

  • Please scan the following files

    Please visit Virus Total by clicking here.
    You will be taken to a web page that looks like this:
    [external image: Posted Image]

    • Click the Browse button and search for the following file: c:\documents and settings\yelena\g2mdlhlpx.exe
    • Click Open.
    • Then click Send File.
    • Please be patient while the file is scanned.
    • If Virus Total tells you that the file has already been scanned, click "reanalyse now".
    • Note: If you are unable to find the file please let me know.
    • Please provide the results from the scan in your next reply.

  • Rootkit Scan:


    • Please try to download and run GMER again.
    • If you are still having problems getting GMER to download, try the following scan instead:

  • RootRepeal


    • Please download RootRepeal to your desktop
    • Physically disconnect your machine from the internet as your system will be unprotected.
    • Unzip it to it's own folder, close all other programs especially your security programs (anti-spyware, anti-virus, and firewall) and run RootRepeal.exe
    • Click the Report tab at the bottom and then the Scan button.
    • A box will pop up, check the boxes beside Drivers, Files, Processes SSDT and click OK.
    • Another box will open, check the boxes beside all the drives, eg : C:\, then click OK.
    • The scan will take a little while to run, so let it go unhindered.
    • Once it is done, click the "Save Report" button, call it RepealScan and save the log to your desktop.
    • Reconnect to the internet.
    • Post the log here in your reply.

    In your next reply, please provide the OTM and MBAM logs, the VirusTotal Scan log and the Rootkit scan log.
    Note: You may need more than one reply to make sure all of the log information is included.
OTM log: All processes killed ========== PROCESSES ========== No active process named explorer.exe was found! ========== FILES ========== File/Folder c:\documents and settings\yelena\local settings\application data\hueegh\diiosftav.exe not found. File/Folder c:\documents and settings\all users\application data\gav\gav.exe not found. c:\documents and settings\yelena\local settings\application data\hueegh folder moved successfully. c:\documents and settings\all users\application data\gav folder moved successfully. ========== REGISTRY ========== Registry key HKEY_CURRENT_USER\Sofware\Microsoft\Windows\CurrentVersion\Internet Settings not found. Registry key HKEY_CURRENT_USER\Sofware\Microsoft\Windows\CurrentVersion\Internet Settings not found. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"|"" /E : value set successfully! Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\mcovnsfx deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\mcovnsfx deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\21098746521098765 deleted successfully. ========== COMMANDS ========== C:\WINDOWS\System32\drivers\etc\Hosts moved successfully. HOSTS file reset successfully [EMPTYTEMP] User: All Users User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: HelpAssistant ->Temp folder emptied: 31218447 bytes ->Temporary Internet Files folder emptied: 233445516 bytes ->Java cache emptied: 4020264 bytes ->Flash cache emptied: 541781 bytes User: LocalService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 19288173 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 109814128 bytes User: Yelena ->Temp folder emptied: 187509002 bytes ->Temporary Internet Files folder emptied: 53595740 bytes ->Java cache emptied: 17884933 bytes ->Flash cache emptied: 541781 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 2195181 bytes %systemroot%\System32 .tmp files removed: 2577 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 8202987 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes RecycleBin emptied: 361225231 bytes Total Files Cleaned = 982.00 mb OTM by OldTimer - Version 3.1.10.1 log created on 04062010_175046 Files moved on Reboot… C:\Documents and Settings\Yelena\Local Settings\Temp\Google Toolbar\GoogleToolbarWelcome.log moved successfully. C:\WINDOWS\temp\$$$dq3e moved successfully. C:\WINDOWS\temp\$67we.$ moved successfully. Registry entries deleted on Reboot…
MBAM Log: Malwarebytes' Anti-Malware 1.45 www.malwarebytes.org Database version: 3961 Windows 5.1.2600 Service Pack 3 Internet Explorer 6.0.2900.5512 4/6/2010 6:44:51 PM mbam-log-2010-04-06 (18-44-51).txt Scan type: Full scan (C:\|) Objects scanned: 155983 Time elapsed: 35 minute(s), 15 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 6 Registry Values Infected: 0 Registry Data Items Infected: 1 Folders Infected: 0 Files Infected: 1 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CLASSES_ROOT\AppID\{29256442-2c14-48ca-b756-3ee0f8bdc774} (Rogue.AntiVirus1) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\avsoft (Trojan.Fraudpack) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\AppID\QWProtect.dll (Rogue.AntiVirus1) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\qwprotect.qwprotectbho (Rogue.AntiVirus1) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\qwprotect.qwprotectbho.1 (Rogue.AntiVirus1) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\Software\avsoft (Trojan.Fraudpack) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. Folders Infected: (No malicious items detected) Files Infected: C:\_OTM\MovedFiles\04062010_175046\c_documents and settings\all users\application data\gav\wsdt05.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully. ________________________________________________________________________________ _________________________________________ VIrusTotal Scan appears to be clean: File g2mdlhlpx.exe received on 2010.04.05 06:26:24 (UTC) Current status: finished Result: 0/39 (0.00%)
Root Repeal log below. I will await your next instructions…. ROOTREPEAL © AD, 2007-2009 ================================================== Scan Start Time: 2010/04/06 19:27 Program Version: Version 1.3.5.0 Windows Version: Windows XP SP3 ================================================== Drivers ——————- Name: dump_atapi.sys Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys Address: 0xEF60C000 Size: 98304 File Visible: No Signed: - Status: - Name: dump_WMILIB.SYS Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS Address: 0xF8B5B000 Size: 8192 File Visible: No Signed: - Status: - Name: iufx.sys Image Path: iufx.sys Address: 0xF8627000 Size: 54016 File Visible: No Signed: - Status: - Name: rootrepeal.sys Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys Address: 0xED2C4000 Size: 49152 File Visible: No Signed: - Status: - Hidden/Locked Files ——————- Path: Volume C:\ Status: MBR Rootkit Detected! Path: C:\hiberfil.sys Status: Locked to the Windows API! ==EOF==
Hello neuro

Thank you for the logs.

  • Combofix


    • Download ComboFix from one of the following locations:

      Link 1
      Link 2

    • VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

    • IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here .
    • Double click on ComboFix.exe & follow the prompts.

    • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
    • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
    • Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

    [external image: Posted Image]

    • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

    [external image: Posted Image]

    • Click on Yes, to continue scanning for malware.
    • When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
    • Notes: Do not mouse-click Combofix's window while it is running. That may cause it to stall.
    • Do not "re-run" Combofix. If you have a problem, reply back for further instructions.

  • GMER


    • I would like you to try GMER again, but this time do the following:
    • Open GMER and allow it to complete its initial scan.
    • If possible rootkit activity is found, you will be asked if you would like to perform a full scan.
    • Click on "NO".
    • In the right panel, you will see a number of boxes that have check marks placed next to them.
    • Please make sure that "Sections", "IAT/EAT", "Drives/Partition other than Systemdrive (typically C:\)", "Show All", "system" and "files" are UN-checked.
    • Now click the "Scan" button.
    • Once the scan is complete, you may receive another notice about rootkit activity. This is normal.
    • Click on "OK".
    • GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "GMER.txt".
    • Save the file where you can easily find it, such as your desktop.

    Please provide the ComboFix log and the GMER log in your next reply. If GMER fails to complete please let me know.
I am following the above instructions. Does Combofix will take care of the MBR rootkit, or will we be relying on GMER for that? I will try GMER with the AV disabled (don't think I did that before and perhaps that's why it kept crashing). Thanks.
Combofix & GMER (downloaded a "new" version which seemed to run fine… now) logs below. Next steps?

ComboFix 10-04-08.01 - Yelena 04/08/2010 20:49:55.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.510.184 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\Malware\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

((((((((((((((((((((((((( Files Created from 2010-03-09 to 2010-04-09 )))))))))))))))))))))))))))))))
.

2010-04-07 00:12 . 2010-04-07 00:12 0 —-a-w- c:\documents and settings\Yelena\settings.dat
2010-04-06 23:06 . 2010-04-06 23:06 ——– d—–w- c:\documents and settings\Yelena\Application Data\Malwarebytes
2010-04-06 23:06 . 2010-03-30 05:46 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-06 23:06 . 2010-04-06 23:06 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-04-06 23:06 . 2010-03-30 05:45 20824 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-04-06 23:06 . 2010-04-06 23:06 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-04-06 22:50 . 2010-04-06 22:50 ——– d—–w- C:\_OTM
2010-04-06 16:39 . 2010-04-06 16:40 ——– d—–w- c:\program files\ERUNT
2010-03-23 04:23 . 2010-03-23 04:23 216520 —-a-w- c:\windows\system32\drivers\PCTCore.sys
2010-03-23 04:23 . 2010-03-23 04:23 88040 —-a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2010-03-23 03:41 . 2010-01-22 14:55 767952 —-a-w- c:\windows\BDTSupport.dll
2010-03-23 03:41 . 2010-01-22 14:56 149456 —-a-w- c:\windows\SGDetectionTool.dll
2010-03-23 03:41 . 2010-01-22 14:56 165840 —-a-w- c:\windows\PCTBDRes.dll
2010-03-23 03:41 . 2010-01-22 14:56 1652688 —-a-w- c:\windows\PCTBDCore.dll
2010-03-23 03:41 . 2009-10-28 06:36 1152444 —-a-w- c:\windows\UDB.zip
2010-03-23 03:41 . 2008-11-26 17:08 131 —-a-w- c:\windows\IDB.zip
2010-03-23 03:40 . 2010-02-05 14:17 233136 —-a-w- c:\windows\system32\drivers\pctgntdi.sys
2010-03-23 03:40 . 2010-02-05 14:25 70408 —-a-w- c:\windows\system32\drivers\pctplsg.sys
2010-03-23 03:40 . 2010-03-28 16:56 ——– d—–w- c:\program files\Spyware Doctor
2010-03-23 03:40 . 2010-03-23 03:42 ——– d—–w- c:\program files\Common Files\PC Tools
2010-03-23 03:40 . 2010-03-23 03:40 ——– d—–w- c:\documents and settings\Yelena\Application Data\PC Tools
2010-03-23 03:40 . 2010-03-23 03:40 ——– d—–w- c:\documents and settings\All Users\Application Data\PC Tools
2010-03-23 03:39 . 2010-04-09 01:56 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-03-20 18:48 . 2010-03-20 18:48 ——– d—–w- c:\documents and settings\HelpAssistant\UserData
2010-03-20 18:39 . 2010-01-27 01:01 60744 —-a-w- c:\documents and settings\HelpAssistant\g2mdlhlpx.exe
2010-03-19 03:40 . 2010-03-28 17:06 ——– d—–w- c:\program files\Reimage
2010-03-11 02:57 . 2009-10-23 15:28 3558912 -c—-w- c:\windows\system32\dllcache\moviemk.exe
2010-03-10 04:33 . 2010-03-10 04:33 1025024 -c—-w- c:\windows\system32\dllcache\browseui.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-23 04:23 . 2010-03-23 04:23 7383 —-a-w- c:\windows\system32\drivers\pctcore.cat
2010-03-23 04:23 . 2010-03-23 04:23 7412 —-a-w- c:\windows\system32\drivers\PCTAppEvent.cat
2010-02-26 05:43 . 2006-03-04 03:33 667136 —-a-w- c:\windows\system32\wininet.dll
2010-02-26 05:43 . 2004-08-04 10:00 81920 —-a-w- c:\windows\system32\ieencode.dll
2010-02-20 16:08 . 2010-02-20 16:08 ——– d—–w- c:\program files\Common Files\Deterministic Networks
2010-01-27 01:01 . 2010-01-27 01:01 60744 —-a-w- c:\documents and settings\Yelena\g2mdlhlpx.exe
2010-01-22 18:24 . 2010-01-22 18:24 79144 —-a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.2.25\SetupAdmin.exe
2010-01-19 11:58 . 2010-01-19 11:58 133784 —-a-w- c:\windows\system32\config\systemprofile\Application Data\Mozilla\Plugins\npagee.dll
2010-01-19 11:58 . 2010-01-19 11:58 41624 —-a-w- c:\windows\system32\drivers\ctxva51.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-11-25 1230080]

[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-11-25 1230080]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-11-25 1230080]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-08-11 68856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2004-10-14 1404928]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2006-02-10 344064]
"Dell Photo AIO Printer 942"="c:\program files\Dell Photo AIO Printer 942\dlbubmgr.exe" [2004-08-31 294912]
"DellMCM"="c:\program files\Dell Photo AIO Printer 942\memcard.exe" [2004-07-27 262144]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2010-03-19 2046816]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-11-11 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-11-12 141600]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-08-11 68856]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
APC UPS Status.lnk - c:\program files\APC\APC PowerChute Personal Edition\Display.exe [2007-4-14 221247]
Citrix Access Gateway.lnk - c:\program files\Citrix\Secure Access Client\nsload.exe [2010-1-19 1483928]
McAfee Security Scan.lnk - c:\program files\McAfee Security Scan\1.0.150\SSScheduler.exe [2009-7-27 199184]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-08-16 15:56 11952 —-a-w- c:\windows\system32\avgrsstx.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Citrix\\Secure Access Client\\nsepa.exe"=
"c:\\Program Files\\Citrix\\Secure Access Client\\nsload.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"65533:TCP"= 65533:TCP:Services
"52344:TCP"= 52344:TCP:Services
"2479:TCP"= 2479:TCP:Services
"3246:TCP"= 3246:TCP:Services
"3389:TCP"= 3389:TCP:Remote Desktop
"7981:TCP"= 7981:TCP:Services
"7982:TCP"= 7982:TCP:Services
"8824:TCP"= 8824:TCP:Services
"5162:TCP"= 5162:TCP:Services

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [5/29/2009 4:29 PM 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [5/29/2009 4:29 PM 108552]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [5/29/2009 4:29 PM 908056]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [5/29/2009 4:29 PM 297752]
R2 cag;Citrix cag plugin for Access Gateway;c:\program files\Common Files\Deterministic Networks\Common Files\cag.sys [10/22/2009 4:34 PM 80920]
R2 nsverctl;Citrix Secure Access Client Service;c:\program files\Citrix\Secure Access Client\nsverctl.exe [1/19/2010 6:56 AM 154264]
R3 ctxva51;Citrix Virtual Adapter;c:\windows\system32\drivers\ctxva51.sys [1/19/2010 6:58 AM 41624]
S2 Browser Defender Update Service;Browser Defender Update Service;c:\program files\Spyware Doctor\BDT\BDTUpdateService.exe [3/22/2010 10:41 PM 112592]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2/4/2010 8:26 PM 135664]
S3 Net6IM;Net6;c:\windows\system32\DRIVERS\net6im51.sys –> c:\windows\system32\DRIVERS\net6im51.sys [?]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [3/22/2010 10:40 PM 366840]
.
Contents of the 'Scheduled Tasks' folder

2010-03-26 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 18:34]

2010-04-09 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-05 01:26]

2010-04-09 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-05 01:26]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
mDefault_Search_URL = hxxp://www.google.com/ie
uInternet Settings,ProxyServer = http=127.0.0.1:5555
uInternet Settings,ProxyOverride =
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.google.com/ie
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
LSP: c:\program files\Common Files\PC Tools\Lsp\PCTLsp.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-04-08 20:56
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(1860)
c:\program files\Malwarebytes' Anti-Malware\mbamext.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\Ati2evxx.exe
c:\program files\APC\APC PowerChute Personal Edition\mainserv.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\progra~1\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\wscntfy.exe
c:\program files\AVG\AVG8\avgcsrvx.exe
c:\program files\Dell Photo AIO Printer 942\dlbubmon.exe
c:\program files\APC\APC PowerChute Personal Edition\apcsystray.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2010-04-08 21:00:07 - machine was rebooted
ComboFix-quarantined-files.txt 2010-04-09 02:00

Pre-Run: 69,829,423,104 bytes free
Post-Run: 69,802,643,456 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

- - End Of File - - D179840236B6F6DD06A374A308DC5444
________________________________________________________________________________
_____________________________________________________

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-04-09 01:54:43
Windows 5.1.2600 Service Pack 3
Running: ju73vw56.exe; Driver: C:\DOCUME~1\Yelena\LOCALS~1\Temp\kwlyqfog.sys


—- Devices - GMER 1.0.15 —-

AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

—- EOF - GMER 1.0.15 —-
Hello neuro

Thank you for the logs.

Does Combofix will take care of the MBR rootkit, or will we be relying on GMER for that?


The GMER scan came back clean and ComboFix has not detected an MBR infection. I think RootRepeal may be reporting a false positive.


  • Please work through the following steps


    • Open Notepad (Click on "Start", then on "Run" and type "notepad" (without quotations) in the Open field, then click on "OK").
    • NOTE: Do not Use Wordpad or any other text editor except Notepad or the script will fail.
    • Copy and Paste the text in the quotebox below into the open Notepad window:

      DDS::
      uInternet Settings,ProxyServer = http=127.0.0.1:5555
      uInternet Settings,ProxyOverride =

    • Save this as "CFScript.txt" (including the quotation marks), change the "Save as type" to "All Files" and save it to your desktop.
    • Close any open browsers.
    • Disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
    • Refering to the picture below, drag CFScript.txt into ComboFix.exe

      [external image: Posted Image]
    • When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.
    • Once the log is produced, re-engage your resident anti virus.


    Next, I would like to take a closer look at some files on your system.

  • Please scan the following files


    • Please use the instructions in post number 4 of this thread to scan the following files in Bold:

    c:\windows\system32\config\systemprofile\Application Data\Mozilla\Plugins\npagee.dll

    c:\windows\system32\drivers\ctxva51.sys

    c:\program files\Common Files\Deterministic Networks\Common Files\cag.sys


    Please post the full logs from each scan in your next reply.

Please provide the ComboFix log and the VT scan logs in your next reply.
Thanks for the response about the rootkit. Here are the logs you have requested: ComboFix 10-04-08.01 - Yelena 04/10/2010 14:15:39.2.2 - x86 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.510.115 [GMT -5:00] Running from: c:\documents and settings\[removed]\Desktop\Malware\ComboFix.exe Command switches used :: c:\documents and settings\Yelena\Desktop\Malware\CFScript.txt AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} . ((((((((((((((((((((((((( Files Created from 2010-03-10 to 2010-04-10 ))))))))))))))))))))))))))))))) . 2010-04-07 00:12 . 2010-04-07 00:12 0 —-a-w- c:\documents and settings\Yelena\settings.dat 2010-04-06 23:06 . 2010-04-06 23:06 ——– d—–w- c:\documents and settings\Yelena\Application Data\Malwarebytes 2010-04-06 23:06 . 2010-03-30 05:46 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2010-04-06 23:06 . 2010-04-06 23:06 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes 2010-04-06 23:06 . 2010-03-30 05:45 20824 —-a-w- c:\windows\system32\drivers\mbam.sys 2010-04-06 23:06 . 2010-04-06 23:06 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware 2010-04-06 22:50 . 2010-04-06 22:50 ——– d—–w- C:\_OTM 2010-04-06 16:39 . 2010-04-06 16:40 ——– d—–w- c:\program files\ERUNT 2010-03-23 04:23 . 2010-03-23 04:23 216520 —-a-w- c:\windows\system32\drivers\PCTCore.sys 2010-03-23 04:23 . 2010-03-23 04:23 88040 —-a-w- c:\windows\system32\drivers\PCTAppEvent.sys 2010-03-23 03:41 . 2010-01-22 14:55 767952 —-a-w- c:\windows\BDTSupport.dll 2010-03-23 03:41 . 2010-01-22 14:56 149456 —-a-w- c:\windows\SGDetectionTool.dll 2010-03-23 03:41 . 2010-01-22 14:56 165840 —-a-w- c:\windows\PCTBDRes.dll 2010-03-23 03:41 . 2010-01-22 14:56 1652688 —-a-w- c:\windows\PCTBDCore.dll 2010-03-23 03:41 . 2009-10-28 06:36 1152444 —-a-w- c:\windows\UDB.zip 2010-03-23 03:41 . 2008-11-26 17:08 131 —-a-w- c:\windows\IDB.zip 2010-03-23 03:40 . 2010-02-05 14:17 233136 —-a-w- c:\windows\system32\drivers\pctgntdi.sys 2010-03-23 03:40 . 2010-02-05 14:25 70408 —-a-w- c:\windows\system32\drivers\pctplsg.sys 2010-03-23 03:40 . 2010-03-28 16:56 ——– d—–w- c:\program files\Spyware Doctor 2010-03-23 03:40 . 2010-03-23 03:42 ——– d—–w- c:\program files\Common Files\PC Tools 2010-03-23 03:40 . 2010-03-23 03:40 ——– d—–w- c:\documents and settings\Yelena\Application Data\PC Tools 2010-03-23 03:40 . 2010-03-23 03:40 ——– d—–w- c:\documents and settings\All Users\Application Data\PC Tools 2010-03-23 03:39 . 2010-04-09 07:19 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP 2010-03-20 18:48 . 2010-03-20 18:48 ——– d—–w- c:\documents and settings\HelpAssistant\UserData 2010-03-20 18:39 . 2010-01-27 01:01 60744 —-a-w- c:\documents and settings\HelpAssistant\g2mdlhlpx.exe 2010-03-19 03:40 . 2010-03-28 17:06 ——– d—–w- c:\program files\Reimage . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-03-23 04:23 . 2010-03-23 04:23 7383 —-a-w- c:\windows\system32\drivers\pctcore.cat 2010-03-23 04:23 . 2010-03-23 04:23 7412 —-a-w- c:\windows\system32\drivers\PCTAppEvent.cat 2010-02-26 05:43 . 2006-03-04 03:33 667136 ——w- c:\windows\system32\wininet.dll 2010-02-26 05:43 . 2004-08-04 10:00 81920 —-a-w- c:\windows\system32\ieencode.dll 2010-02-20 16:08 . 2010-02-20 16:08 ——– d—–w- c:\program files\Common Files\Deterministic Networks 2010-01-27 01:01 . 2010-01-27 01:01 60744 —-a-w- c:\documents and settings\Yelena\g2mdlhlpx.exe 2010-01-22 18:24 . 2010-01-22 18:24 79144 —-a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.2.25\SetupAdmin.exe 2010-01-19 11:58 . 2010-01-19 11:58 133784 —-a-w- c:\windows\system32\config\systemprofile\Application Data\Mozilla\Plugins\npagee.dll 2010-01-19 11:58 . 2010-01-19 11:58 41624 —-a-w- c:\windows\system32\drivers\ctxva51.sys . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks] "{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-11-25 1230080] [HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-11-25 1230080] [HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}] [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser] "{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-11-25 1230080] [HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-08-11 68856] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2004-10-14 1404928] "ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2006-02-10 344064] "Dell Photo AIO Printer 942"="c:\program files\Dell Photo AIO Printer 942\dlbubmgr.exe" [2004-08-31 294912] "DellMCM"="c:\program files\Dell Photo AIO Printer 942\memcard.exe" [2004-07-27 262144] "AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2010-03-19 2046816] "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-11-11 417792] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-11-12 141600] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-08-11 68856] c:\documents and settings\All Users\Start Menu\Programs\Startup\ APC UPS Status.lnk - c:\program files\APC\APC PowerChute Personal Edition\Display.exe [2007-4-14 221247] Citrix Access Gateway.lnk - c:\program files\Citrix\Secure Access Client\nsload.exe [2010-1-19 1483928] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter] 2009-08-16 15:56 11952 —-a-w- c:\windows\system32\avgrsstx.dll [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\AVG\\AVG8\\avgemc.exe"= "c:\\Program Files\\AVG\\AVG8\\avgupd.exe"= "c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"= "c:\\Program Files\\Bonjour\\mDNSResponder.exe"= "c:\\Program Files\\iTunes\\iTunes.exe"= "c:\\Program Files\\Citrix\\Secure Access Client\\nsepa.exe"= "c:\\Program Files\\Citrix\\Secure Access Client\\nsload.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "65533:TCP"= 65533:TCP:Services "52344:TCP"= 52344:TCP:Services "2479:TCP"= 2479:TCP:Services "3246:TCP"= 3246:TCP:Services "3389:TCP"= 3389:TCP:Remote Desktop "7981:TCP"= 7981:TCP:Services "7982:TCP"= 7982:TCP:Services "8824:TCP"= 8824:TCP:Services "5162:TCP"= 5162:TCP:Services R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [5/29/2009 4:29 PM 335240] R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [5/29/2009 4:29 PM 108552] R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [5/29/2009 4:29 PM 908056] R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [5/29/2009 4:29 PM 297752] R2 cag;Citrix cag plugin for Access Gateway;c:\program files\Common Files\Deterministic Networks\Common Files\cag.sys [10/22/2009 4:34 PM 80920] R2 nsverctl;Citrix Secure Access Client Service;c:\program files\Citrix\Secure Access Client\nsverctl.exe [1/19/2010 6:56 AM 154264] R3 ctxva51;Citrix Virtual Adapter;c:\windows\system32\drivers\ctxva51.sys [1/19/2010 6:58 AM 41624] S2 Browser Defender Update Service;Browser Defender Update Service;c:\program files\Spyware Doctor\BDT\BDTUpdateService.exe [3/22/2010 10:41 PM 112592] S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2/4/2010 8:26 PM 135664] S3 Net6IM;Net6;c:\windows\system32\DRIVERS\net6im51.sys –> c:\windows\system32\DRIVERS\net6im51.sys [?] S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [3/22/2010 10:40 PM 366840] . Contents of the 'Scheduled Tasks' folder 2010-03-26 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 18:34] 2010-04-09 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2010-02-05 01:26] 2010-04-09 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2010-02-05 01:26] . . ——- Supplementary Scan ——- . uStart Page = hxxp://www.google.com/ uSearch Page = hxxp://www.google.com uSearch Bar = hxxp://www.google.com/ie uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html LSP: c:\program files\Common Files\PC Tools\Lsp\PCTLsp.dll . ************************************************************************** scanning hidden processes … scanning hidden autostart entries … scanning hidden files … scan completed successfully hidden files: ************************************************************************** . Completion time: 2010-04-10 14:22:48 ComboFix-quarantined-files.txt 2010-04-10 19:22 ComboFix2.txt 2010-04-09 02:00 Pre-Run: 69,799,337,984 bytes free Post-Run: 69,771,206,656 bytes free - - End Of File - - 7DFA12023CB89F2E897E15CE6876988B File npagee.dll received on 2010.04.10 19:34:02 (UTC) Current status: Loading … queued waiting scanning finished NOT FOUND STOPPED Result: 0/39 (0%) Loading server information… Your file is queued in position: 1. Estimated start time is between 38 and 55 seconds. Do not close the window until scan is complete. The scanner that was processing your file is stopped at this moment, we are going to wait a few seconds to try to recover your result. If you are waiting for more than five minutes you have to resend your file. Your file is being scanned by VirusTotal in this moment, results will be shown as they're generated. Compact Print results Your file has expired or does not exists. Service is stopped in this moments, your file is waiting to be scanned (position: ) for an undefined time. You can wait for web response (automatic reload) or type your email in the form below and click "request" so the system sends you a notification when the scan is finished. Email: Antivirus Version Last Update Result a-squared 4.5.0.50 2010.04.10 - AhnLab-V3 5.0.0.2 2010.04.10 - AntiVir 7.10.6.55 2010.04.09 - Antiy-AVL 2.0.3.7 2010.04.09 - Authentium 5.2.0.5 2010.04.10 - Avast 4.8.1351.0 2010.04.10 - Avast5 5.0.332.0 2010.04.10 - AVG 9.0.0.787 2010.04.10 - BitDefender 7.2 2010.04.10 - CAT-QuickHeal 10.00 2010.04.10 - ClamAV 0.96.0.3-git 2010.04.10 - Comodo 4558 2010.04.10 - DrWeb 5.0.2.03300 2010.04.10 - eSafe 7.0.17.0 2010.04.08 - eTrust-Vet 35.2.7418 2010.04.09 - F-Prot 4.5.1.85 2010.04.10 - F-Secure 9.0.15370.0 2010.04.10 - Fortinet 4.0.14.0 2010.04.10 - GData 19 2010.04.10 - Ikarus T3.1.1.80.0 2010.04.10 - Jiangmin 13.0.900 2010.04.10 - Kaspersky 7.0.0.125 2010.04.10 - McAfee-GW-Edition 6.8.5 2010.04.09 - Microsoft 1.5605 2010.04.10 - NOD32 5016 2010.04.10 - Norman 6.04.11 2010.04.10 - nProtect 2009.1.8.0 2010.04.06 - Panda 10.0.2.2 2010.04.10 - PCTools 7.0.3.5 2010.04.10 - Prevx 3.0 2010.04.10 - Rising 22.42.04.03 2010.04.09 - Sophos 4.52.0 2010.04.10 - Sunbelt 6161 2010.04.10 - Symantec 20091.2.0.41 2010.04.10 - TheHacker 6.5.2.0.259 2010.04.10 - TrendMicro 9.120.0.1004 2010.04.10 - VBA32 3.12.12.4 2010.04.09 - ViRobot 2010.4.10.2270 2010.04.10 - VirusBuster 5.0.27.0 2010.04.10 - Additional information File size: 133784 bytes MD5…: 54cc6d87bbc801549ec3cf68633df0a1 SHA1..: e98df3f6167adf9cbb30881377896573d4de7247 SHA256: e40bada35226da51d312f016b10add455cb61dc8595f70f4e23d04083663167c ssdeep: 1536:AuHY6H4dqGrK8qCqxp+RFtakjps+N5QO2ErxEpLK28Kc2p59+by:AuHY6Yd diCqX0IBKv2R1p59++ PEiD..: - PEInfo: PE Structure information ( base data ) entrypointaddress.: 0x6a82 timedatestamp…..: 0x4b54fcb6 (Tue Jan 19 00:28:38 2010) machinetype…….: 0x14c (I386) ( 5 sections ) name viradd virsiz rawdsiz ntrpy md5 .text 0x1000 0x1686f 0x16a00 6.63 631c9f616ac3f7c9515c1bd847fe0b6c .rdata 0x18000 0x49e7 0x4a00 5.55 f4112791e345f96da1c2243e006918ca .data 0x1d000 0x33f8 0x1600 3.35 d7ae860bac5e39321c2091733d1c7b50 .rsrc 0x21000 0x648 0x800 4.42 27f8a273037b3fbbac9b60984724c6d9 .reloc 0x22000 0x2146 0x2200 4.45 b696d872c2cd6e29c81510c7b2686c36 ( 7 imports ) > WININET.dll: InternetGetCookieA > KERNEL32.dll: GetVersionExA, OutputDebugStringA, lstrlenW, Sleep, GetTempPathA, GetLocaleInfoA, GetCurrentProcess, GetModuleHandleA, CloseHandle, SetFilePointer, LocalFree, GetSystemDirectoryA, GetLocalTime, InterlockedDecrement, FormatMessageA, GetProcessHeap, HeapAlloc, GetModuleFileNameA, lstrlenA, MultiByteToWideChar, GetLastError, WideCharToMultiByte, FindResourceExA, FindResourceA, LoadResource, LockResource, SizeofResource, LoadLibraryA, GetProcAddress, FreeLibrary, GetTickCount, ReadFile, GetStringTypeW, GetStringTypeA, LCMapStringW, LCMapStringA, SetEndOfFile, FlushFileBuffers, GetConsoleMode, GetConsoleCP, WriteFile, CreateFileA, SetStdHandle, GetSystemTimeAsFileTime, WriteConsoleW, GetConsoleOutputCP, WriteConsoleA, InitializeCriticalSectionAndSpinCount, GetCurrentProcessId, QueryPerformanceCounter, GetEnvironmentStringsW, FreeEnvironmentStringsW, RaiseException, EnterCriticalSection, LeaveCriticalSection, InitializeCriticalSection, DeleteCriticalSection, HeapDestroy, HeapFree, HeapReAlloc, HeapSize, RtlUnwind, GetCurrentThreadId, GetCommandLineA, CreateDirectoryA, TerminateProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, GetModuleHandleW, TlsGetValue, TlsAlloc, TlsSetValue, TlsFree, InterlockedIncrement, SetLastError, GetCPInfo, GetACP, GetOEMCP, IsValidCodePage, HeapCreate, VirtualFree, VirtualAlloc, ExitProcess, SetHandleCount, GetStdHandle, GetFileType, GetStartupInfoA, FreeEnvironmentStringsA, GetEnvironmentStrings > USER32.dll: GetDesktopWindow > ADVAPI32.dll: RegOpenKeyExA, RegQueryValueExA, RegCloseKey > ole32.dll: CoTaskMemFree, CLSIDFromString, CLSIDFromProgID, OleRun, StringFromGUID2, CoGetObject, CoCreateInstance, CoUninitialize, CoInitializeEx, CoGetClassObject, CoInitialize > OLEAUT32.dll: -, -, -, - > msi.dll: -, -, -, -, - ( 5 exports ) NP_GetEntryPoints, NP_Initialize, NP_Shutdown, ns_MSI_InstallEpa, ns_MSI_UninstallEpa RDS…: NSRL Reference Data Set - pdfid.: - trid..: Win64 Executable Generic (59.6%) Win32 Executable MS Visual C++ (generic) (26.2%) Win32 Executable Generic (5.9%) Win32 Dynamic Link Library (generic) (5.2%) Generic Win/DOS Executable (1.3%) sigcheck: publisher….: Citrix Systems, Inc. copyright….: Copyright 2003-09 Citrix Systems, Inc. product……: Citrix Access Gateway description..: Citrix Access Gateway original name: npagee.dll internal name: npagee.dll file version.: 9, 1, 101, 5 comments…..: n/a signers……: Citrix Systems, Inc. Thawte Code Signing CA Thawte Premium Server CA signing date.: 2:28 AM 1/19/2010 verified…..: - File ctxva51.sys received on 2010.04.10 19:37:38 (UTC) Current status: Loading … queued waiting scanning finished NOT FOUND STOPPED Result: 0/39 (0%) Loading server information… Your file is queued in position: 1. Estimated start time is between 38 and 55 seconds. Do not close the window until scan is complete. The scanner that was processing your file is stopped at this moment, we are going to wait a few seconds to try to recover your result. If you are waiting for more than five minutes you have to resend your file. Your file is being scanned by VirusTotal in this moment, results will be shown as they're generated. Compact Print results Your file has expired or does not exists. Service is stopped in this moments, your file is waiting to be scanned (position: ) for an undefined time. You can wait for web response (automatic reload) or type your email in the form below and click "request" so the system sends you a notification when the scan is finished. Email: Antivirus Version Last Update Result a-squared 4.5.0.50 2010.04.10 - AhnLab-V3 5.0.0.2 2010.04.10 - AntiVir 7.10.6.55 2010.04.09 - Antiy-AVL 2.0.3.7 2010.04.09 - Authentium 5.2.0.5 2010.04.10 - Avast 4.8.1351.0 2010.04.10 - Avast5 5.0.332.0 2010.04.10 - AVG 9.0.0.787 2010.04.10 - BitDefender 7.2 2010.04.10 - CAT-QuickHeal 10.00 2010.04.10 - ClamAV 0.96.0.3-git 2010.04.10 - Comodo 4558 2010.04.10 - DrWeb 5.0.2.03300 2010.04.10 - eSafe 7.0.17.0 2010.04.08 - eTrust-Vet 35.2.7418 2010.04.09 - F-Prot 4.5.1.85 2010.04.10 - F-Secure 9.0.15370.0 2010.04.10 - Fortinet 4.0.14.0 2010.04.10 - GData 19 2010.04.10 - Ikarus T3.1.1.80.0 2010.04.10 - Jiangmin 13.0.900 2010.04.10 - Kaspersky 7.0.0.125 2010.04.10 - McAfee-GW-Edition 6.8.5 2010.04.09 - Microsoft 1.5605 2010.04.10 - NOD32 5016 2010.04.10 - Norman 6.04.11 2010.04.10 - nProtect 2009.1.8.0 2010.04.06 - Panda 10.0.2.2 2010.04.10 - PCTools 7.0.3.5 2010.04.10 - Prevx 3.0 2010.04.10 - Rising 22.42.04.03 2010.04.09 - Sophos 4.52.0 2010.04.10 - Sunbelt 6161 2010.04.10 - Symantec 20091.2.0.41 2010.04.10 - TheHacker 6.5.2.0.259 2010.04.10 - TrendMicro 9.120.0.1004 2010.04.10 - VBA32 3.12.12.4 2010.04.09 - ViRobot 2010.4.10.2270 2010.04.10 - VirusBuster 5.0.27.0 2010.04.10 - Additional information File size: 41624 bytes MD5…: 1207e2a67f5b11df34fb3dd9f0ec607f SHA1..: 3848bbf88d608e4070c605fddb035e7877351f02 SHA256: cc2d4b5487c3c6579c4888ba8c5c3a3cef8a83e9b2ef674354e73463b5a8562b ssdeep: 768:+ptZoFXUGdhdZFImkuTeYDfuDCj06JNQS/cR+kvFTyL4r:+9oFXldhdZ2mku qY7uDyJNQvv5yUr PEiD..: - PEInfo: PE Structure information ( base data ) entrypointaddress.: 0x73e2 timedatestamp…..: 0x4b06d781 (Fri Nov 20 17:53:05 2009) machinetype…….: 0x14c (I386) ( 7 sections ) name viradd virsiz rawdsiz ntrpy md5 .text 0x600 0x4856 0x4a00 6.53 337c3fee7e93070184dbfec4bb82212f .rdata 0x5000 0x15c 0x200 3.27 32ae9a79e3adf7790f8e7795be658211 .data 0x5200 0x360 0x400 1.29 d86d1684d6c8495fd57d2c582f98f0f1 PAGE 0x5600 0x1bfc 0x1c00 6.52 39d866a97da424fcfdabef2a747086a6 INIT 0x7200 0x820 0xa00 5.08 8c15327be3921d300336d5b93adc8ac6 .rsrc 0x7c00 0x848 0xa00 3.03 68eb94a1fe894d2c0487ab0a8a79972f .reloc 0x8600 0x924 0xa00 5.69 c6dd8fa25e19016112993cc48faa2bf7 ( 3 imports ) > ntoskrnl.exe: KeBugCheckEx, KeTickCount, RtlInitUnicodeString, IofCompleteRequest, MmMapLockedPagesSpecifyCache, InterlockedPushEntrySList, InterlockedPopEntrySList, memcpy, ExfInterlockedRemoveHeadList, IoFreeMdl, ExDeleteNPagedLookasideList, ExInitializeNPagedLookasideList, ExfInterlockedInsertTailList, memset, DbgPrint, RtlAssert > HAL.dll: KfReleaseSpinLock, KeGetCurrentIrql, KfAcquireSpinLock > NDIS.SYS: NdisMIndicateStatusComplete, NdisMQueryAdapterResources, NdisOpenConfiguration, NdisReadNetworkAddress, NdisCloseConfiguration, NdisFreeBufferPool, NdisMIndicateStatus, NdisFreePacket, NdisFreePacketPool, NdisAllocateMemoryWithTag, NdisAllocatePacketPool, NdisAllocatePacket, NdisAllocateBufferPool, NdisMDeregisterDevice, NdisMRegisterDevice, NdisFreeMemory, NdisInitializeEvent, NdisSetTimer, NdisSetEvent, NdisInitializeTimer, NdisMSetAttributesEx, NdisMGetDeviceProperty, NdisMSleep, NdisWaitEvent, NdisCancelTimer, NdisMRegisterUnloadHandler, NdisTerminateWrapper, NdisMRegisterMiniport, NdisInitializeWrapper, NdisAllocateBuffer ( 0 exports ) RDS…: NSRL Reference Data Set - pdfid.: - trid..: Win32 Executable Generic (58.4%) Clipper DOS Executable (13.8%) Generic Win/DOS Executable (13.7%) DOS Executable Generic (13.7%) VXD Driver (0.2%) sigcheck: publisher….: Citrix Systems, Inc. copyright….: © 2009 Citrix Systems, Inc. All Rights Reserved. product……: Citrix description..: Citrix Secure Access Driver original name: ctxva51.SYS internal name: ctxva51.SYS file version.: 1.0.0.2 built by: WinDDK comments…..: n/a signers……: Citrix Systems, Inc. Thawte Code Signing CA Thawte Premium Server CA signing date.: 2:28 AM 1/19/2010 verified…..: - File cag.sys received on 2010.04.10 19:39:45 (UTC) Current status: Loading … queued waiting scanning finished NOT FOUND STOPPED Result: 0/39 (0%) Loading server information… Your file is queued in position: 2. Estimated start time is between 46 and 66 seconds. Do not close the window until scan is complete. The scanner that was processing your file is stopped at this moment, we are going to wait a few seconds to try to recover your result. If you are waiting for more than five minutes you have to resend your file. Your file is being scanned by VirusTotal in this moment, results will be shown as they're generated. Compact Print results Your file has expired or does not exists. Service is stopped in this moments, your file is waiting to be scanned (position: ) for an undefined time. You can wait for web response (automatic reload) or type your email in the form below and click "request" so the system sends you a notification when the scan is finished. Email: Antivirus Version Last Update Result a-squared 4.5.0.50 2010.04.10 - AhnLab-V3 5.0.0.2 2010.04.10 - AntiVir 7.10.6.55 2010.04.09 - Antiy-AVL 2.0.3.7 2010.04.09 - Authentium 5.2.0.5 2010.04.10 - Avast 4.8.1351.0 2010.04.10 - Avast5 5.0.332.0 2010.04.10 - AVG 9.0.0.787 2010.04.10 - BitDefender 7.2 2010.04.10 - CAT-QuickHeal 10.00 2010.04.10 - ClamAV 0.96.0.3-git 2010.04.10 - Comodo 4558 2010.04.10 - DrWeb 5.0.2.03300 2010.04.10 - eSafe 7.0.17.0 2010.04.08 - eTrust-Vet 35.2.7418 2010.04.09 - F-Prot 4.5.1.85 2010.04.10 - F-Secure 9.0.15370.0 2010.04.10 - Fortinet 4.0.14.0 2010.04.10 - GData 19 2010.04.10 - Ikarus T3.1.1.80.0 2010.04.10 - Jiangmin 13.0.900 2010.04.10 - Kaspersky 7.0.0.125 2010.04.10 - McAfee-GW-Edition 6.8.5 2010.04.09 - Microsoft 1.5605 2010.04.10 - NOD32 5016 2010.04.10 - Norman 6.04.11 2010.04.10 - nProtect 2009.1.8.0 2010.04.06 - Panda 10.0.2.2 2010.04.10 - PCTools 7.0.3.5 2010.04.10 - Prevx 3.0 2010.04.10 - Rising 22.42.04.03 2010.04.09 - Sophos 4.52.0 2010.04.10 - Sunbelt 6161 2010.04.10 - Symantec 20091.2.0.41 2010.04.10 - TheHacker 6.5.2.0.259 2010.04.10 - TrendMicro 9.120.0.1004 2010.04.10 - VBA32 3.12.12.4 2010.04.09 - ViRobot 2010.4.10.2270 2010.04.10 - VirusBuster 5.0.27.0 2010.04.10 - Additional information File size: 80920 bytes MD5…: 1c0733bb218bb9da1ac7281a9b3c727d SHA1..: 1fa96aa6acecfabc14e3b0fbaf7271aa3d85ce9c SHA256: 5c8d16b2358f6735d09dc37332545d589ab3cb3dbb6d0ba9c4712fbb94665e9c ssdeep: 1536:lGnzmy3SGnxvoUJylOUNt6P0mb8qygly6L:l23hRJmOUNt6MCv PEiD..: - PEInfo: PE Structure information ( base data ) entrypointaddress.: 0x15005 timedatestamp…..: 0x4ae0ec1b (Thu Oct 22 23:34:51 2009) machinetype…….: 0x14c (I386) ( 6 sections ) name viradd virsiz rawdsiz ntrpy md5 .text 0x1000 0xf25b 0xf400 6.43 dd20a66088b16ab24b0129449bc5ca88 .rdata 0x11000 0x604 0x800 3.52 a58bbd792b386d160527f52ca8b96536 .data 0x12000 0x22a8 0x200 0.82 be8843394970a147f8a2e6b04edaca19 INIT 0x15000 0x48a 0x600 4.58 26d421ef1b00efe49b1b966a6d8203a7 .rsrc 0x16000 0x350 0x400 2.86 9d0e7fc248c997d169e436a0ae237c62 .reloc 0x17000 0x140e 0x1600 5.49 0d74907067a0de50cb01ffaacea48bb6 ( 3 imports ) > ntoskrnl.exe: KeBugCheckEx, KeTickCount, MmMapLockedPagesSpecifyCache, IofCompleteRequest, strncpy, memcpy, _alldiv, KeQuerySystemTime, memset, sprintf, KeGetCurrentThread, _except_handler3, ZwOpenKey, ZwClose, ZwQueryValueKey, ObfDereferenceObject, IoDeleteDevice, IoDeleteSymbolicLink, KeSetEvent, KeResetEvent, KeWaitForSingleObject, IofCallDriver, IoBuildDeviceIoControlRequest, KeInitializeEvent, IoGetDeviceObjectPointer, RtlInitUnicodeString, IoCreateSymbolicLink, IoCreateDevice, DbgPrint, KeInitializeSpinLock > HAL.dll: KfLowerIrql, KeGetCurrentIrql, KfRaiseIrql, KfReleaseSpinLock, KfAcquireSpinLock > NDIS.SYS: NdisResetEvent, NdisWaitEvent, NdisSetTimer, NdisCancelTimer, NdisInitializeEvent, NdisInitializeTimer, NdisFreeMemory, NdisAllocateMemory ( 0 exports ) RDS…: NSRL Reference Data Set - pdfid.: - trid..: Win32 Executable Generic (68.0%) Generic Win/DOS Executable (15.9%) DOS Executable Generic (15.9%) Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%) sigcheck: publisher….: Citrix Systems, Inc. copyright….: Copyright © 2009 product……: n/a description..: Access Gateway 32bit Plugin original name: cag.sys internal name: cag file version.: 1.1.0.231 comments…..: n/a signers……: Citrix Systems, Inc VeriSign Class 3 Code Signing 2004 CA Class 3 Public Primary Certification Authority signing date.: 1:38 AM 10/23/2009 verified…..: -
Hello neuro

Thank you for the logs.

I would like you to perform an online scan of your machine to check for anything else that needs our attention. Please do the following:


  • Please update your Java

    • Click on "Start", then on "Control Panel".
    • Go to "Add or Remove Programs" and uninstall any previous versions of Java that you find.
    • Reboot your computer.
    • Next, download the latest version of Java by clicking here
    • Scroll down the page until you reach "Java Platform Standard Edition".
    • Beneath this and to the right, you will see a red button marked "Download JRE".
    • Click the "Download JRE" button.
    • Select the platform (Windows, in your case), multi language.
    • Accept the license agreement and click on "Continue".
    • You do not have to register if you do not want to (the registration step is optional).
    • Scroll down and click on the file called jre-6u19-windows-i586.exe located under "Windows Offline Installation".
    • Save the file to your desktop.
    • Do not select Run.
    • Double click on the saved file (jre-6u18-windows-i586.exe) to install the update.
    • Delete the downloaded installation file after completing the above procedure and reboot your system if not prompted to do so.
  • Please perform the following scan:


    • This is a very deep scan that can take many hours. In some instances you may need to let it run overnight. Please be patient.


    • It is recommended that you disable your onboard antivirus program and antispyware programs while performing scans to eliminate software conflicts and to speed up scan time.
    • DO NOT surf the net while your resident protection is disabled!
    • Once the scan is finished remember to re-enable your resident antivirus protection along with whatever antispyware applications you use.

    Please perform a Kaspersky Online Scan of your computer by clicking here or here.

    You will be taken to a web page. It will look like this:
    [external image: Posted Image]
    • Click on the Accept button and install any components it needs.
    • The program will install and then begin downloading the latest definition files.
    • After the files have been downloaded on the left side of the page in the Scan section select My Computer.
    • This will start the program and scan your system.
    • The scan will take a while, so be patient and let it run (at times it may appear to stall).
    • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
    • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
    • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.

    • Once the scan is complete, click on View scan report. To obtain the report:
    • Click on: Save Report As
    • Next, in the Save as prompt, Save in area, select: Desktop
    • In the File name area, use KScan, or something similar In Save as type, click the drop arrow and select:Text file [*.txt]
    • Then, click: Save
    • Please post the Kaspersky Online Scanner Report in your reply.
    • If you need help performing the above steps, an animated tutorial can be found here.

    In your next reply please provide the Kaspersky Online Scan log.

    Also, please let me know how the machine is behaving now. Are you still experiencing problems?
JonTom, Kaspersky seemed to run clean; log is below. Shut down and startup now take only about 1:20 (wow!), no spikes to 100% CPU usage on perfomance monitor, limited web sites tested so far seem to work well (given the continued use of IE6). I am not sure what to check next, but imagine you will have more suggestions! neuro ——————————————————————————– KASPERSKY ONLINE SCANNER 7.0: scan report Monday, April 12, 2010 Operating system: Microsoft Windows XP Home Edition Service Pack 3 (build 2600) Kaspersky Online Scanner version: 7.0.26.13 Last database update: Sunday, April 11, 2010 22:47:50 Records in database: 3936384 ——————————————————————————– Scan settings: scan using the following database: extended Scan archives: yes Scan e-mail databases: yes Scan area - My Computer: A:\ C:\ D:\ E:\ Scan statistics: Objects scanned: 55696 Threats found: 0 Infected objects found: 0 Suspicious objects found: 0 Scan duration: 01:58:50 No threats found. Scanned area is clean. Selected area has been scanned.
Hello neuro

Thank you for the log. Things are looking much better.

Please scan your system again with DDS and post the log created so I can make sure that everything is as it should be.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI