Original Thread
i am helping to clean someone else's computer an i have run many scans including AVG, AD-Aware, Avira, Norton 360, Malwarebytes, SuperAnti-spyware, ccleaner, atf cleaner and dr web cure it.
the original symptoms were limited connectivity and redirected web pages, as well as spyware guard 2009 popping open repeatedly. i looked online and found walkthroughs to clean it by deleting registry files, and other files known to be associated with the program. i returned the computer as it seemed to work well and AVG and Ad-aware both cleared out some files. but in a week the connectivity problem returned without spyware guard 2009. i did some work on it and found relevant knowledge and did my best to remove it as recommended by different web pages. but the problem did not seem to be resolved and i started the original thread at about that point and followed his prescriptions bringing me to you here.
thank you very much for your help, here is my dds.txt:
DDS (Ver_09-02-01.01) - NTFSx86
Run by angie martain at 14:44:05.98 on Sun 02/15/2009
Internet Explorer: 7.0.5730.13
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.510.174 [GMT -5:00]
AV: AVG Anti-Virus Free *On-access scanning enabled* (Outdated)
AV: Avira AntiVir PersonalEdition *On-access scanning enabled* (Outdated)
AV: Norton 360 *On-access scanning enabled* (Outdated)
FW: Norton 360 *enabled*
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\PROGRA~1\Webshots\Webshots.scr
C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
C:\Documents and Settings\angie martain\Application Data\U3\0000060414049665\LaunchPad.exe
C:\Documents and Settings\angie martain\Desktop\dds.scr
============== Pseudo HJT Report ===============
uSearch Bar = hxxp://www.google.com/ie
uSearchMigratedDefaultUrl = hxxp://www.mywebsearch.com/jsp/cfg_redir2.jsp?id=ZRfox000&fl=0&ptb=7ZNLGBxDSmEdWg65uChw3Q&url=http://edits.mywebsearch.com/toolbaredits/barsearch.jhtml&st=sb&searchfor={searchTerms}
uStart Page = www.google.com
uInternet Connection Wizard,ShellNext = iexplore
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} -
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\DLASHX_W.DLL
BHO: NCO 2.0 IE BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\common files\symantec shared\coshared\browser\2.6\coIEPlg.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\progra~1\common~1\symant~1\ids\IPSBHO.dll
BHO: {89E9964C-A342-47A4-8061-37DC19CED2D5} - No File
BHO: AVG Security Toolbar: {a057a204-bacc-4d26-9990-79a187e2698e} - c:\progra~1\avg\avg8\AVGTOO~1.DLL
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.0.926.3450\swg.dll
BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_219B3E1547538286.dll
BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\bae\BAE.dll
TB: &Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll
TB: AVG Security Toolbar: {a057a204-bacc-4d26-9990-79a187e2698e} - c:\progra~1\avg\avg8\AVGTOO~1.DLL
TB: Show Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\common files\symantec shared\coshared\browser\2.6\CoIEPlg.dll
TB: {D7F30B62-8269-41AF-9539-B2697FA7D77E} - No File
TB: {4982D40A-C53B-4615-B15B-B5B5E98D167C} - No File
TB: {55FAF0F2-44D4-425F-B5F5-6B275B621EAB} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe
mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe
mRun: [DLCGCATS] rundll32 c:\windows\system32\spool\drivers\w32x86\3\DLCGtime.dll,_RunDLLEntry@16
mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe"
mRun: [osCheck] "c:\program files\norton 360\osCheck.exe"
mRun: [avgnt] "c:\program files\avira\antivir personaledition classic\avgnt.exe" /min
StartupFolder: c:\docume~1\angiem~1\startm~1\programs\startup\webshots.lnk - c:\program files\webshots\Launcher.exe
IE: {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - c:\program files\aim\aim.exe
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE}
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
Notify: igfxcui - igfxdev.dll
Notify: yayxWpnK - yayxWpnK.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
SecurityProviders: msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, digeste.dll
LSA: Authentication Packages = msv1_0 c:\windows\system32\jkkLDspQ
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\angiem~1\applic~1\mozilla\firefox\profiles\14npdc58.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - prefs.js: keyword.URL - hxxp://search.alot.com/web?&src_id=11088&client_id=713448afa54a78889c0bec78&camp_id=-1&install_time=2008-12-07T00:32:28Z&tb_version=2.0.0%28F%29pr=auto&q=
FF - component: c:\program files\avg\avg8\firefox\components\avgssff.dll
FF - component: c:\program files\avg\avg8\toolbarff\components\vmAVGConnector.dll
FF - component: c:\program files\components\dompilot3.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npunagi2.dll
FF - plugin: c:\program files\picasa2\npPicasa2.dll
FF - HiddenExtension: *xg.dll: {6E19037A-12E3-4295-8915-ED48BC341614} - c:\program files\
============= SERVICES / DRIVERS ===============
R1 avgio;avgio;c:\program files\avira\antivir personaledition classic\avgio.sys [2009-2-10 11840]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-1-16 97928]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2009-1-16 26824]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2009-1-15 8944]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-1-15 55024]
R2 AntiVirScheduler;Avira AntiVir Personal - Free Antivirus Scheduler;c:\program files\avira\antivir personaledition classic\sched.exe [2009-2-10 68865]
R2 AntiVirService;Avira AntiVir Personal - Free Antivirus Guard;c:\program files\avira\antivir personaledition classic\avguard.exe [2009-2-10 151297]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\avg\avg8\avgemc.exe [2009-1-16 875288]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2009-1-16 231704]
R2 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-1-16 76040]
R2 ccEvtMgr;Symantec Event Manager;c:\program files\common files\symantec shared\ccSvcHst.exe [2008-2-18 149352]
R2 ccSetMgr;Symantec Settings Manager;c:\program files\common files\symantec shared\ccSvcHst.exe [2008-2-18 149352]
R2 LiveUpdate Notice;LiveUpdate Notice;c:\program files\common files\symantec shared\ccSvcHst.exe [2008-2-18 149352]
R3 avgntflt;avgntflt;c:\program files\avira\antivir personaledition classic\avgntflt.sys [2009-2-10 52032]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2009-2-7 109616]
R3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20080213.036\NAVENG.SYS [2009-2-7 82256]
R3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20080213.036\NAVEX15.SYS [2009-2-7 895312]
R3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-1-15 7408]
R3 Symantec Core LC;Symantec Core LC;c:\progra~1\common~1\symant~1\ccpd-lc\symlcsvc.exe [2009-2-7 1245064]
=============== Created Last 30 ================
2009-02-14 20:50
2009-02-12 19:43
2009-02-12 19:43
2009-02-12 19:43
2009-02-10 07:01
2009-02-10 07:01
2009-02-09 21:39
2009-02-09 17:56 15,504 a------- c:\windows\system32\drivers\mbam.sys
2009-02-09 17:56 38,496 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2009-02-07 01:43
2009-02-07 00:07
2009-02-07 00:05 123,952 a------- c:\windows\system32\drivers\SYMEVENT.SYS
2009-02-07 00:05 60,800 a------- c:\windows\system32\S32EVNT1.DLL
2009-02-07 00:05 10,563 a------- c:\windows\system32\drivers\SYMEVENT.CAT
2009-02-07 00:05 805 a------- c:\windows\system32\drivers\SYMEVENT.INF
2009-02-06 20:28
2009-02-06 20:23 389,120 a------- c:\windows\system32\CF14157.exe
2009-02-06 20:23
2009-02-06 20:12
2009-02-06 18:53
2009-02-06 18:53
2009-01-17 16:16 664 a------- c:\windows\system32\d3d9caps.dat
2009-01-16 22:22
2009-01-16 22:10 10,520 a------- c:\windows\system32\avgrsstx.dll
2009-01-16 22:10 76,040 a------- c:\windows\system32\drivers\avgtdix.sys
2009-01-16 22:10 97,928 a------- c:\windows\system32\drivers\avgldx86.sys
2009-01-16 22:10
2009-01-16 22:10
2009-01-16 22:00
2009-01-16 22:00
2009-01-16 21:51 26,368 a------- c:\windows\system32\dllcache\usbstor.sys
==================== Find3M ====================
2009-01-15 21:17 0 a------- c:\program files\chrome.manifest
2009-01-15 21:13 1,690,112 a------- c:\program files\rlvknlg.exe
2009-01-15 21:13 372,736 a------- c:\program files\osmim.dll
2009-01-15 21:13 217,088 a------- c:\program files\dompilot.dll
2009-01-15 21:13 45,056 a------- c:\program files\OSSService.exe
2009-01-15 21:13 649 a------- c:\program files\install.rdf
2009-01-15 21:13 708,608 a------- c:\program files\osspdf.dll
2009-01-15 21:08 1,648,678 a--sh--- c:\windows\system32\QpsDLkkj.ini2
2008-12-13 01:40 3,593,216 a------- c:\windows\system32\dllcache\mshtml.dll
2008-12-11 05:57 333,952 -------- c:\windows\system32\dllcache\srv.sys
2008-08-29 19:37 164 a------- c:\docume~1\angiem~1\applic~1\wklnhst.dat
2008-08-22 14:46 61,224 a------- c:\documents and settings\angie martain\GoToAssistDownloadHelper.exe
============= FINISH: 14:45:11.54 ===============