I cannot complete an antivirus scan. I've uninstalled and reinstalled AVG with no change. Malwarebytes also won't complete a scan. It stops about half way through and shuts down. I can't reopen the program after that, I get an error message that I don't have the right permissions to access. I've had the same results with several different Antivirus programs and malware removal programs. During one malware scan I watched the files being scanned closely, and shortly before the scan terminated and shut down, I noticed that the files being scanned were called Trojan.Win32 and Vundo. (I think these were the names, I only saw them once and they went be quickly)
The DDS text file and the Attach text file are attached.
GMER shuts down immediately after I click 'Scan' and so no log file is attached.
Any help would be great. Thanks!
DDS (Ver_2011-06-23.01) - NTFSx86 Avast Full Virus Scan Stuck
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_26
Run by Joanie at 11:43:27 on 2011-08-02
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3316.2046 [GMT -5:00]
AV: AVG Anti-Virus Free Edition 2011 *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: AVG Firewall *Disabled*
Running Processes
C:WINDOWSsystem32svchost -k DcomLaunch
svchost.exeAvast virus scan stuck at 26
C:WINDOWSSystem32svchost.exe -k netsvcs
C:Program FilesCommon FilesAppleMobile Device SupportAppleMobileDeviceService.exe
C:Program FilesAVGAVG10avgwdsvc.exe
C:Program FilesBonjourmDNSResponder.exe
C:Program FilesCarboniteCarbonite Backupcarboniteservice.exe
C:Program FilesDYMODYMO Label SoftwareDymoPnpService.exe
C:Program FilesAVGAVG10avgnsx.exe
C:Program FilesAVGAVG10avgemcx.exe
C:Program FilesCommon FilesIntuitQuickBooksQBCFMonitorService.exe
C:Program FilesMicrosoftBingBarSeaPort.EXE
C:WINDOWSsystem32svchost.exe -k imgsvc
C:Program FilesCommon FilesMicrosoft SharedWindows LiveWLIDSVC.EXE
C:Program FilesAVGAVG10Identity ProtectionAgentBinAVGIDSAgent.exe
C:Program FilesCommon FilesMicrosoft SharedWindows LiveWLIDSvcM.exe
C:Program FilesAdobeAdobe Version Cue CS2ControlPanelVersionCueCS2Tray.exe
C:Program FilesAdobeAdobe Acrobat 7.0DistillrAcrotray.exe
C:Program FilesDYMODYMO Label SoftwareDLSService.exe
C:Program FilesCarboniteCarbonite BackupCarboniteUI.exe
C:Program FilesAVGAVG10avgtray.exe
C:Program FilesAVGAVG10Identity Protectionagentbinavgidsmonitor.exe
C:Program FilesMicrosoft OfficeOfficeFINDFAST.EXE
C:Program FilesMicrosoft OfficeOfficeOSA.EXE
C:Program FilesCommon FilesIntuitQuickBooksQBUpdateqbupdate.exe
C:Program FilesYahoo!WidgetsYahooWidgets.exe
C:Program FilesOpenOffice.org 3programsoffice.exe
C:Program FilesOpenOffice.org 3programsoffice.bin
C:Program FilesYahoo!WidgetsYahooWidgets.exe
C:Program FilesAVGAVG10avgcsrvx.exe
C:Program FilesMozilla Firefoxfirefox.exe
C:Program FilesMozilla Firefoxplugin-container.exe
C:Program FilesiPodbiniPodService.exe
C:Program FilesiTunesiTunesHelper.exe
C:Program FilesJavajre6binjqs.exe
Pseudo HJT Report
uStart Page = hxxp://start.msn.iplay.com/?o=shp
uInternet Settings,ProxyOverride = *.local
uURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:program filesavgavg10toolbarIEToolbar.dll
uURLSearchHooks: H - No File
mURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:program filesavgavg10toolbarIEToolbar.dll
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:program filesadobeadobe acrobat 7.0activexAcroIEHelper.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:program filesavgavg10avgssie.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:program filescommon filesmicrosoft sharedwindows liveWindowsLiveLogin.dll
BHO: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:program filesavgavg10toolbarIEToolbar.dll
BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - c:program filesadobeadobe acrobat 7.0acrobatAcroIEFavClient.dll
BHO: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - 'c:program filesmicrosoftbingbarBingExt.dll'
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:program filesjavajre6binjp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:program filesjavajre6libdeployjqsiejqs_plugin.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:program filesadobeadobe acrobat 7.0acrobatAcroIEFavClient.dll
TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - c:program filesavgavg10toolbarIEToolbar.dll
TB: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - 'c:program filesmicrosoftbingbarBingExt.dll'
EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - c:program filesadobeadobe acrobat 7.0acrobatAcroIEFavClient.dll
uRun: [ctfmon.exe] c:windowssystem32ctfmon.exe
uRunOnce: [spchecker] 'c:program filesavgavg10notificationSPCheckerTE.exe'
mRun: [Recguard] c:windowssminstRECGUARD.EXE
mRun: [Persistence] c:windowssystem32igfxpers.exe
mRun: [NeroFilterCheck] c:windowssystem32NeroCheck.exe
mRun: [IgfxTray] c:windowssystem32igfxtray.exe
mRun: [HotKeysCmds] c:windowssystem32hkcmd.exe
mRun: [FTP Server] c:typsof~1ftpserv.exe
mRun: [Alcmtr] ALCMTR.EXE
mRun: [Adobe Reader Speed Launcher] 'c:program filesadobereader 8.0readerReader_sl.exe'
mRun: [Adobe Version Cue CS2] 'c:program filesadobeadobe version cue cs2controlpanelVersionCueCS2Tray.exe'
mRun: [Acrobat Assistant 7.0] 'c:program filesadobeadobe acrobat 7.0distillrAcrotray.exe'
mRun: [<NO NAME>]
mRun: [DLSService] 'c:program filesdymodymo label softwareDLSService.exe'
mRun: [Microsoft Default Manager] 'c:program filesmicrosoftsearch enhancement packdefault managerDefMgr.exe' -resume
mRun: [Intuit SyncManager] c:program filescommon filesintuitsyncIntuitSyncManager.exe startup
mRun: [QuickTime Task] 'c:program filesquicktimeqttask.exe' -atboottime
mRun: [QuickBooksDB20] c:progra~1intuitquickb~2qbdbmgrn.exe -n qb_admin-pc_20 -qs -gd all -gk all -gp 4096 -gu all -ch 256m -c 128m -x tcpip(broadcastlistener=no;port=55338) -ti 0 -ec simple -qi -qw -tl 120 -oe 'c:documents and settingsall usersapplication dataintuitquickbooksDBStartup.log' -y
mRun: [Carbonite Backup] c:program filescarbonitecarbonite backupCarboniteUI.exe
mRun: [iTunesHelper] 'c:program filesitunesiTunesHelper.exe'
mRun: [AVG_TRAY] c:program filesavgavg10avgtray.exe
mRun: [SunJavaUpdateSched] 'c:program filescommon filesjavajava updatejusched.exe'
StartupFolder: c:docume~1joaniestartm~1programsstartupopenof~1.lnk - c:program filesopenoffice.org 3programquickstart.exe
StartupFolder: c:docume~1joaniestartm~1programsstartupyahoo!~1.lnk - c:program filesyahoo!widgetsYahooWidgets.exe
StartupFolder: c:docume~1alluse~1startm~1programsstartupadobea~1.lnk - c:windowsinstaller{ac76ba86-1033-0000-7760-000000000002}SC_Acrobat.exe
StartupFolder: c:docume~1alluse~1startm~1programsstartupadobeg~1.lnk - c:program filescommon filesadobecalibrationAdobe Gamma Loader.exe
StartupFolder: c:docume~1alluse~1startm~1programsstartupmicros~2.lnk - c:program filesmicrosoft officeofficeFINDFAST.EXE
StartupFolder: c:docume~1alluse~1startm~1programsstartupoffice~1.lnk - c:program filesmicrosoft officeofficeOSA.EXE
StartupFolder: c:docume~1alluse~1startm~1programsstartupquickb~1.lnk - c:program filescommon filesintuitquickbooksqbupdateqbupdate.exe
IE: Convert link target to Adobe PDF - c:program filesadobeadobe acrobat 7.0acrobatAcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:program filesadobeadobe acrobat 7.0acrobatAcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:program filesadobeadobe acrobat 7.0acrobatAcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:program filesadobeadobe acrobat 7.0acrobatAcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:program filesadobeadobe acrobat 7.0acrobatAcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:program filesadobeadobe acrobat 7.0acrobatAcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:program filesadobeadobe acrobat 7.0acrobatAcroIEFavClient.dll/AcroIECapture.html
IE: Convert to existing PDF - c:program filesadobeadobe acrobat 7.0acrobatAcroIEFavClient.dll/AcroIEAppend.html
IE: E&xport to Microsoft Excel - c:progra~1micros~2office12EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%Network Diagnosticxpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:program filesmessengermsmsgs.exe
LSP: mswsock.dll
DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:program filesyahoo!commonYinsthelper.dll
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1238093120244
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {8FA2192F-B95D-40E3-898F-8D7ABB8E00D0} - hxxp://games.bigfishgames.com/en_mysterysolitairese/online/SpinTopGamesLauncher.cab
DPF: {CAFEEFAC-0014-0002-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
TCP: Interfaces{05DBC00F-4612-43F5-A1C9-4CF4169E9F5F} : NameServer =,
Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - c:program filesavgavg10toolbarIEToolbar.dll
Handler: intu-help-qb3 - {c5e479ea-0a65-4b05-8c6c-2fc8cc682eb4} - c:program filesintuitquickbooks 2010HelpAsyncPluggableProtocol.dll
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:program filesavgavg10avgpp.dll
Handler: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - c:windowssystem32mscoree.dll
Notify: igfxcui - igfxdev.dll
Notify: TPSvc - TPSvc.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:windowssystem32WPDShServiceObj.dll
FF - ProfilePath - c:documents and settingsjoanieapplication datamozillafirefoxprofilesowib4bcv.default
FF - prefs.js: browser.search.selectedEngine - AVG Secure Search
FF - prefs.js: browser.startup.homepage - hxxp://www.msn.com/
FF - prefs.js: keyword.URL - hxxp://search.avg.com/route/?d=4e380803&v=
FF - component: c:program filesavgavg10firefoxcomponentsavgssff.dll
FF - component: c:program filesavgavg10toolbarfirefoxavg@igearedcomponentsIGeared_tavgp_xputils3.dll
FF - component: c:program filesavgavg10toolbarfirefoxavg@igearedcomponentsIGeared_tavgp_xputils35.dll
FF - component: c:program filesavgavg10toolbarfirefoxavg@igearedcomponentsxpavgtbapi.dll
FF - plugin: c:progra~1mozilla firefoxpluginsnp32dsw.dll
FF - plugin: c:progra~1mozilla firefoxpluginsnpgcplug.dll
FF - plugin: c:progra~1mozilla firefoxpluginsnppl3260.dll
FF - plugin: c:progra~1mozilla firefoxpluginsnpracplug.dll
FF - plugin: c:progra~1mozilla firefoxpluginsnprjplug.dll
FF - plugin: c:progra~1mozilla firefoxpluginsnprpjplug.dll
FF - plugin: c:program filesdymodymo label softwareframeworknpDYMOLabelFramework.dll
FF - plugin: c:program filesjavajre6binnew_pluginnpdeployJava1.dll
FF - plugin: c:program filesmicrosoft silverlight4.0.60531.0npctrlui.dll
FF - plugin: c:program filesmozilla firefoxpluginsnpdeployJava1.dll
FF - plugin: c:program filesmozilla firefoxpluginsnpyaxmpb.dll
FF - plugin: c:program filesrealrealarcadepluginsmozillanpracplug.dll
R0 AVGIDSEH;AVGIDSEH;c:windowssystem32driversAVGIDSEH.sys [2010-9-13 22992]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:windowssystem32driversavgrkx86.sys [2011-3-16 32592]
R1 Avgldx86;AVG AVI Loader Driver;c:windowssystem32driversavgldx86.sys [2011-1-7 248656]
R1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:windowssystem32driversavgmfx86.sys [2011-3-1 34896]
R1 Avgtdix;AVG TDI Driver;c:windowssystem32driversavgtdix.sys [2010-9-7 297168]
R3 AVGIDSDriver;AVGIDSDriver;c:windowssystem32driversAVGIDSDriver.sys [2011-4-14 134480]
R3 AVGIDSFilter;AVGIDSFilter;c:windowssystem32driversAVGIDSFilter.sys [2011-2-10 24144]
R3 AVGIDSShim;AVGIDSShim;c:windowssystem32driversAVGIDSShim.sys [2011-2-10 27216]
RUnknown RegFilter;RegFilter; [x]
RUnknown UrlFilter;UrlFilter; [x]
Created Last 30
2011-08-02 14:50:12 -------- d-----w- c:documents and settingsjoanielocal settingsapplication dataAVG Security Toolbar
2011-08-02 13:59:05 -------- d-----w- c:documents and settingsall usersapplication dataAVG Security Toolbar
2011-08-01 22:07:22 -------- d-----w- C:8924e86a50142617a156
2011-08-01 21:50:59 -------- d-----w- c:windowssystem32XPSViewer
2011-08-01 21:29:13 -------- d-----w- c:windowssystem32URTTemp
2011-08-01 18:38:49 -------- d-----w- c:program filesVS Revo Group
2011-08-01 17:18:05 -------- d-----w- c:documents and settingsjoanieapplication dataIObit
2011-08-01 16:58:12 -------- d-----w- c:documents and settingsall usersapplication dataBIGFISHGAMESCACHE
2011-08-01 16:08:35 -------- d-----w- c:documents and settingsall usersapplication dataAVAST Software
2011-07-29 15:36:00 -------- d-----w- c:documents and settingsjoanieapplication dataAVG

2011-07-28 14:16:54 -------- d-----w- c:program filescommon filesiS3
2011-07-22 14:57:40 -------- d-----w- c:program filesBonjour
2011-07-12 20:32:27 -------- d-----w- c:documents and settingsjoanielocal settingsapplication datafd
2011-07-12 16:20:54 83816 ----a-w- c:windowssystem32dns-sd.exe
2011-07-12 16:20:54 73064 ----a-w- c:windowssystem32dnssd.dll
2011-06-17 14:52:19 404640 ----a-w- c:windowssystem32FlashPlayerCPLApp.cpl

2011-06-02 14:02:05 1858944 ----a-w- c:windowssystem32win32k.sys
2011-05-25 00:14:10 222080 -c----w- c:windowssystem32MpSigStub.exe
2010-11-29 23:00:38 445 ----a-w- c:program files1129201017003860.bat
2010-08-13 18:40:39 441 ----a-w- c:program files0813201013403923.bat
2010-05-10 15:39:39 460 ----a-w- c:program files0510201010393909.bat

FINISH: 11:44:31.51

Attached Files

  • attach.txt14.82KB2 downloads
  • dds.txt14.65KB2 downloads

Edited by Noviciate, 02 August 2011 - 02:55 PM.
Added DDS log.