This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

please help, log included

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

ths so much from your patience. we just returned from a 5 day backpacking trip yesterday. ecoprincess says she will readdress this matter tonight. you can expect a reply from her. thx again for all your help.
the viruses were found with AVG free edition, here is the log from the virus vault it was put in excel format, I hope you are able to read it. I formated in in wrap text Trojan horse Downloader.Zlob.AOJ C:\Documents and Settings\sabrina\Local Settings\Temporary Internet Files\Content.IE5\UVWB1MRM\xpassman-v3.400[1].exe xpassman-v3.400[1].exe 52.72 KB Trojan horse Generic.DGK C:\WINDOWS\system32\st3.dll st3.dll 68.5 KB Trojan horse Downloader.Generic.IPF C:\System Volume Information\_restore{14157744-4FA2-4CAF-BAFB-72CC49941087}\RP170\A0045673.dll A0045673.dll 13.5 KB Trojan horse Generic.DGK C:\Documents and Settings\sabrina\Local Settings\Temporary Internet Files\Content.IE5\9JBN1XOA\st3m[1].dll st3m[1].dll 68.5 KB Trojan horse Generic.DGK C:\WINDOWS\system32\st3.dll st3.dll 68.5 KB Trojan horse Downloader.Generic.IPF C:\WINDOWS\g327120.dll g327120.dll 13.5 KB Trojan horse Generic.DGK C:\WINDOWS\system32\st3.dll st3.dll 68.5 KB Trojan horse Downloader.Generic.IPF C:\WINDOWS\g327120.dll g327120.dll 13.5 KB Trojan horse Generic.DGK C:\WINDOWS\system32\st3.dll st3.dll 68.5 KB Trojan horse Dialer.BCR C:\WINDOWS\system32\ccaccess.dll ccaccess.dll 16.5 KB Trojan horse Downloader.Generic.IPF C:\WINDOWS\g327120.dll g327120.dll 13.5 KB Trojan horse Generic.LAW C:\System Volume Information\_restore{14157744-4FA2-4CAF-BAFB-72CC49941087}\RP132\A0043988.exe A0043988.exe 34.5 KB Trojan horse Exploit.Downloader C:\Documents and Settings\sabrina\Local Settings\Temporary Internet Files\Content.IE5\TUKUN9TW\psg[1].anr psg[1].anr 912 bytes Trojan horse Generic.DGK C:\Documents and Settings\sabrina\Local Settings\Temporary Internet Files\Content.IE5\HR3JH5OE\st3m[1].dll st3m[1].dll 68.5 KB Trojan horse Generic.DGK C:\WINDOWS\system32\st3.dll st3.dll 68.5 KB Trojan horse Downloader.Generic.IPF C:\WINDOWS\g327120.dll g327120.dll 13.5 KB Trojan horse Generic.DGK C:\WINDOWS\system32\st3.dll st3.dll 68.5 KB Trojan horse Generic.DGK C:\Documents and Settings\sabrina\Local Settings\Temporary Internet Files\Content.IE5\HR3JH5OE\st3m[1].dll st3m[1].dll 68.5 KB Trojan horse Generic.LYA C:\System Volume Information\_restore{14157744-4FA2-4CAF-BAFB-72CC49941087}\RP134\A0045208.exe A0045208.exe 3.5 KB Trojan horse Generic.DGK C:\WINDOWS\system32\st3.dll st3.dll 68.5 KB Trojan horse Generic.LCY C:\WINDOWS\system32\oleext.dll oleext.dll 18 KB Trojan horse Downloader.Generic.IPF C:\WINDOWS\g327120.dll g327120.dll 13.5 KB Trojan horse Generic.BXY C:\System Volume Information\_restore{14157744-4FA2-4CAF-BAFB-72CC49941087}\RP134\A0045207.exe A0045207.exe 3.15 KB Trojan horse Generic.BXY C:\System Volume Information\_restore{14157744-4FA2-4CAF-BAFB-72CC49941087}\RP134\A0045206.exe A0045206.exe 3.15 KB Trojan horse Downloader.Generic.KWD C:\System Volume Information\_restore{14157744-4FA2-4CAF-BAFB-72CC49941087}\RP134\A0045205.exe A0045205.exe 6.5 KB Trojan horse Generic.LAW C:\System Volume Information\_restore{14157744-4FA2-4CAF-BAFB-72CC49941087}\RP133\A0044075.exe A0044075.exe 34.5 KB Trojan horse Generic.LYA C:\System Volume Information\_restore{14157744-4FA2-4CAF-BAFB-72CC49941087}\RP132\A0044041.exe A0044041.exe 3.5 KB Trojan horse Generic.LCY C:\System Volume Information\_restore{14157744-4FA2-4CAF-BAFB-72CC49941087}\RP132\A0044040.dll A0044040.dll 18 KB Trojan horse Generic.LAW C:\System Volume Information\_restore{14157744-4FA2-4CAF-BAFB-72CC49941087}\RP132\A0044025.exe A0044025.exe 34.5 KB Trojan horse Generic.LYA C:\System Volume Information\_restore{14157744-4FA2-4CAF-BAFB-72CC49941087}\RP132\A0044016.exe A0044016.exe 3.5 KB Trojan horse Generic.LCY C:\System Volume Information\_restore{14157744-4FA2-4CAF-BAFB-72CC49941087}\RP132\A0044015.dll A0044015.dll 18 KB Trojan horse Downloader.Generic.IPF C:\WINDOWS\q551503.dll q551503.dll 13.5 KB Trojan horse Downloader.Generic.IPF C:\WINDOWS\q387677.dll q387677.dll 13.5 KB Trojan horse Downloader.Generic.IPF C:\WINDOWS\q354209.dll q354209.dll 13.5 KB Trojan horse Downloader.Generic.IPF C:\WINDOWS\q300772.dll q300772.dll 13.5 KB Trojan horse Downloader.Generic.IPF C:\WINDOWS\q298909.dll q298909.dll 13.5 KB Trojan horse Downloader.Generic.IPF C:\WINDOWS\q294102.dll q294102.dll 13.5 KB Trojan horse Downloader.Generic.IPF C:\WINDOWS\q274785.dll q274785.dll 13.5 KB Trojan horse Downloader.Generic.IPF C:\WINDOWS\g327120.dll g327120.dll 13.5 KB Trojan horse Generic.LAW C:\Documents and Settings\sabrina\Local Settings\Temporary Internet Files\Content.IE5\RTR7ECT0\runapl[1].exe runapl[1].exe 34.5 KB Trojan horse Downloader.Generic.NON C:\Documents and Settings\sabrina\Local Settings\Temporary Internet Files\Content.IE5\RTR7ECT0\gdnUS250[1].exe gdnUS250[1].exe 13.53 KB Trojan horse Downloader.Generic.NON C:\Documents and Settings\sabrina\Local Settings\Temporary Internet Files\Content.IE5\K9YN81UZ\gdnUS2175[1].exe gdnUS2175[1].exe 11.27 KB Trojan horse Generic.LYA C:\WINDOWS\uninstIU.exe uninstIU.exe 3.5 KB Trojan horse Downloader.Generic.NON C:\Documents and Settings\sabrina\Local Settings\Temporary Internet Files\Content.IE5\32OB79C5\gdnUS2175[2].exe gdnUS2175[2].exe 11.27 KB Trojan horse Dialer.BCR C:\Documents and Settings\sabrina\Local Settings\Temp\ICD1.tmp\ccaccess.dll ccaccess.dll 16.5 KB Trojan horse Dialer.AOZ C:\Documents and Settings\sabrina\Local Settings\Temp\okfiopmd.exe okfiopmd.exe 13 KB Trojan horse Dialer.AOZ C:\Documents and Settings\sabrina\Local Settings\Temp\npodnpmd.exe npodnpmd.exe 13 KB Trojan horse Dialer.AOZ C:\Documents and Settings\sabrina\Local Settings\Temp\lfbcnpmd.exe lfbcnpmd.exe 13 KB Trojan horse Dialer.AOZ C:\Documents and Settings\sabrina\Local Settings\Temp\kdkgopmd.exe kdkgopmd.exe 13 KB Trojan horse Dialer.AOZ C:\Documents and Settings\sabrina\Local Settings\Temp\gejmcmmd.exe gejmcmmd.exe 13 KB Trojan horse Generic.BXY C:\ntdetecd.exe ntdetecd.exe 3.15 KB Trojan horse Generic.BXY C:\WINDOWS\system32\vmlib.exe vmlib.exe 3.15 KB Trojan horse Downloader.Generic.KWD C:\WINDOWS\system32\intell32.exe intell32.exe 6.5 KB The spyware was found with spybot and zone alarm I will finish the rest this evening, I am late for work! Thanks Ecoprincess
I finally finished it all…slacker that I am =.

I took off the adaware, found rx but not people. also see the virus report and a new hijack this.

thanks for your help.

Ecoprincess

———————————————————
AVG Anti-Spyware - Scan Report
———————————————————

+ Created at: 7:52:28 AM 10/17/2006

+ Scan result:



HKU\S-1-5-21-727973733-2893727954-3030875721-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5929CD6E-2062-44A4-B2C5-2C7E78FBAB38} -> Adware.Generic : No action taken.
HKLM\SOFTWARE\PerfectNav -> Adware.KeenValue : No action taken.
HKU\S-1-5-21-727973733-2893727954-3030875721-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{59879FA4-4790-461C-A1CC-4EC4DE4CA483} -> Adware.RXToolbar : No action taken.
HKU\S-1-5-21-727973733-2893727954-3030875721-1004\Software\RX Toolbar -> Adware.RXToolbar : No action taken.
C:\WINDOWS\Downloaded Program Files\Install.dll -> Adware.SpywareStorm : No action taken.
C:\Program Files\whInstall -> Adware.Webhancer : No action taken.
C:\Program Files\whInstall\license.txt -> Adware.Webhancer : No action taken.
C:\Program Files\whInstall\readme.txt -> Adware.Webhancer : No action taken.
C:\Program Files\whInstall\whAgent.inf -> Adware.Webhancer : No action taken.
C:\Program Files\whInstall\whAgent.ini -> Adware.Webhancer : No action taken.
C:\Program Files\whInstall\whInstaller.ini -> Adware.Webhancer : No action taken.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\ins -> Adware.WebRebates : No action taken.
HKU\S-1-5-21-727973733-2893727954-3030875721-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A8FB8EB3-183B-4598-924D-86F0E5E37085} -> Adware.WhyPPC : No action taken.
C:\Documents and Settings\sabrina\Application Data\WinHound.com -> Adware.WinHound : No action taken.
C:\Documents and Settings\sabrina\Application Data\WinHound.com\WinHound -> Adware.WinHound : No action taken.
C:\Documents and Settings\sabrina\Application Data\WinHound.com\WinHound\Autorun -> Adware.WinHound : No action taken.
C:\Documents and Settings\sabrina\Application Data\WinHound.com\WinHound\Autorun\HKCURun -> Adware.WinHound : No action taken.
C:\Documents and Settings\sabrina\Application Data\WinHound.com\WinHound\Autorun\HKCURun\RunOnce -> Adware.WinHound : No action taken.
C:\Documents and Settings\sabrina\Application Data\WinHound.com\WinHound\Autorun\HKCURun\RunOnceEx -> Adware.WinHound : No action taken.
C:\Documents and Settings\sabrina\Application Data\WinHound.com\WinHound\Autorun\HKLMRun -> Adware.WinHound : No action taken.
C:\Documents and Settings\sabrina\Application Data\WinHound.com\WinHound\Autorun\HKLMRun\RunOnce -> Adware.WinHound : No action taken.
C:\Documents and Settings\sabrina\Application Data\WinHound.com\WinHound\Autorun\HKLMRun\RunOnceEx -> Adware.WinHound : No action taken.
C:\Documents and Settings\sabrina\Application Data\WinHound.com\WinHound\Autorun\StartMenuAllUsers -> Adware.WinHound : No action taken.
C:\Documents and Settings\sabrina\Application Data\WinHound.com\WinHound\Autorun\StartMenuCurrentUser -> Adware.WinHound : No action taken.
C:\Documents and Settings\sabrina\Application Data\WinHound.com\WinHound\BrowserObjects -> Adware.WinHound : No action taken.
HKLM\SOFTWARE\WinHound.com -> Spyware.WinHound : No action taken.
HKLM\SOFTWARE\WinHound.com\WinHound -> Spyware.WinHound : No action taken.
HKLM\SOFTWARE\WinHound.com\WinHound\WinHound -> Spyware.WinHound : No action taken.
HKLM\SOFTWARE\WinHound.com\WinHound\WinHound\License -> Spyware.WinHound : No action taken.


::Report end



Logfile of HijackThis v1.99.1
Scan saved at 8:02:36 AM, on 10/17/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\ibmpmsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\QCONSVC.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\TpKmpSVC.exe
C:\PROGRA~1\xpoint\xpadmin\xpadmin.exe
C:\PROGRA~1\xpoint\agent\Xpagent.exe
C:\PROGRA~1\xpoint\EEClient\xpclient.exe
C:\WINDOWS\system32\cmd.exe
C:\PROGRA~1\xpoint\SAS\jre\bin\javaw.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe
C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe
C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\VERITAS Software\Update Manager\sgtray.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\ThinkPad\CONNEC~1\QCTray.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\dumprep.exe
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Ares\Ares.exe
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\Program Files\Belkin\Belkin 802.11g Wireless Card Configuration Utility\utility.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\dwwin.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\hijackgthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O4 - HKLM\..\Run: [S3TRAY2] S3Tray2.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
O4 - HKLM\..\Run: [BMMLREF] C:\Program Files\ThinkPad\Utilities\BMMLREF.EXE
O4 - HKLM\..\Run: [QCWLICON] C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
O4 - HKLM\..\Run: [TP4EX] tp4ex.exe
O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [StorageGuard] "c:\Program Files\VERITAS Software\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QCTray] C:\PROGRA~1\ThinkPad\CONNEC~1\QCTray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: Belkin 802.11g Wireless Card Utility.lnk = ?
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {072D3F2E-5FB6-11D3-B461-00C04FA35A21} (CFForm Runtime) - http://www.judicial.state.sc.us/CFIDE/classes/CFJava.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {74F939E3-7FE2-45A1-B8AB-E93AAC031D68} (PaceRegCheckControl.RegCheckControl) - https://ssoserv.pace.edu/PatchCheck/RegCheck.CAB
O16 - DPF: {74FFE28D-2378-11D5-990C-006094235084} (IBM Access Support) - file://C:\Program Files\Support.com\Bin\IBMAccessSupport\common\install\ibmegath.cab
O16 - DPF: {9D190AE6-C81E-4039-8061-978EBAD10073} (F-Secure Online Scanner 3.0) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\System32\ibmpmsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Xpoint PCRadmin Server (PCRadminServer) - Unknown owner - C:\PROGRA~1\xpoint\pe\pcradmin.exe
O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe
O23 - Service: QCONSVC - Unknown owner - C:\WINDOWS\System32\QCONSVC.EXE
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Xpoint Admin Server (XPadminServer) - Unknown owner - C:\PROGRA~1\xpoint\xpadmin\xpadmin.exe
O23 - Service: Xpoint Agent Server (xpAgentServer) - Unknown owner - C:\PROGRA~1\xpoint\agent\Xpagent.exe
Hi ecoprincess.

Thanks for posting the logs. Unfortunately, when you ran the AVG Anti-Spyware scan, you didn't click on the Apply all Actions button before saving the report. This means that, although AVG Anti-Spyware found the malware, it didn't get rid of it. Please run the program again and make sure that you follow the instructions exactly.

You will need to reboot your computer into Safe Mode for the next steps. It would be a good idea for you to print these instructions, as you will not have access to the internet.

Important: If you have an always on connection to the internet, physically disconnect that connection until you are finished with Safe Mode and have rebooted back into normal mode.

Boot to Safe Mode. To do this:
  • Restart your computer.
  • Continually tap the F8 button as your computer is booting (a menu appears).
  • Use up-arrow key to select Safe Mode and press Enter.
Close all open windows and then start AVG Anti-Spyware
  • Click on Scanner on the toolbar.
  • Click on the Settings tab.
    • Under How to act? - make sure that Quarantine is selected.
    • Under How to scan? - All checkboxes should be ticked.
    • Under Possibly unwanted software - All checkboxes should be ticked.
    • Under Reports - Select Automatically generate report after every scan and uncheck Only if threats were found.
    • Under What to scan? - Select Scan every file.
  • Click on the Scan tab.
  • Click on Complete System Scan to start the scan process.
  • Let the program scan your computer.
  • When the scan has finished, follow the instructions below:
    • Make sure that Set all elements to: shows Quarantine
    • Important: Click on the Apply all Actions button (this must done before saving the report). << Make sure this is done!
    • When the program has finished, it will display the message All actions have been applied.
    • Then click the Save Scan Report button.
    • Click the Save Report as button.
    • Save the report to your Desktop.
  • Right-click the AVG Tray Icon and select Exit.
Reboot in Normal Mode.

Please post, as a reply to this thread:
  • The AVG Anti-Spyware report
  • A new HijackThis report
Please also let me know how your computer is running now.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI