so i ran the scan log thing and this is what it came up with:

---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------
+ Created at: 10:41:44 PM 2/13/2007
+ Scan result:

C:\Program Files\AWS\WeatherBug\MiniBugTransporter.dll -> Adware.Aws : Cleaned with backup (quarantined).
C:\WINNT\dhp2.dll -> Adware.DealHelper : Cleaned with backup (quarantined).
C:\Documents and Settings\Owner\Local Settings\Temp\upd50.tmp/ME.dll -> Adware.MediaPops : Cleaned with backup (quarantined).
C:\Documents and Settings\Owner\Local Settings\Temp\upd94.tmp/ME.dll -> Adware.MediaPops : Cleaned with backup (quarantined).
C:\WINNT\NDNuninstall4_50.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\WINNT\NDNuninstall4_80.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\WINNT\NDNuninstall4_88.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\WINNT\NDNuninstall4_94.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\WINNT\NDNuninstall5_20.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\WINNT\NDNuninstall5_40.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\WINNT\NDNuninstall5_48.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\WINNT\NDNuninstall5_64.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\WINNT\NDNuninstall6_10.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\WINNT\NDNuninstall6_22.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\WINNT\NDNuninstall6_30.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\WINNT\NDNuninstall7_14.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\Documents and Settings\Owner\Local Settings\Temp\p2psetup.exe -> Adware.P2PNet : Cleaned with backup (quarantined).
C:\Documents and Settings\Owner\Local Settings\Temp\MiniBug.exe -> Adware.SuspectModule : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP733\A0758896.dll -> : Cleaned with backup (quarantined).
C:\WINNT\system32\xcttgs.dll -> : Error during cleaning.
[408] C:\WINNT\system32\xcttgs.dll -> : Error during cleaning.
C:\Documents and Settings\Owner\Local Settings\Temp\ARTA106.exe -> : Cleaned with backup (quarantined).
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\S16J4X6F\index[1].htm -> : Cleaned with backup (quarantined).
C:\Documents and Settings\Owner\Desktop\Magic-Login-Final\Magic-Login-Final.exe -> Downloader.Zlob.bke : Cleaned with backup (quarantined).
C:\RECYCLER\S-1-5-21-1371315241-4271176276-1453689397-1003\Dc600.zip/Magic-Login-Final/Magic-Login-Final.exe -> Downloader.Zlob.bke : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP746\A0778937.exe -> Downloader.Zlob.bke : Cleaned with backup (quarantined).
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\S16J4X6F\elusiive[1].htm -> Not-A-Virus.Exploit.HTML.Mht : Cleaned with backup (quarantined).
C:\Documents and Settings\Owner\Cookies\owner@2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\RECYCLER\S-1-5-21-1371315241-4271176276-1453689397-1003\Dc608.txt -> TrackingCookie.2o7 : Cleaned.
C:\RECYCLER\S-1-5-21-1371315241-4271176276-1453689397-1003\Dc710.txt -> TrackingCookie.2o7 : Cleaned.
C:\RECYCLER\S-1-5-21-1371315241-4271176276-1453689397-1003\Dc780.txt -> TrackingCookie.2o7 : Cleaned.
C:\RECYCLER\S-1-5-21-1371315241-4271176276-1453689397-1003\Dc781.txt -> TrackingCookie.2o7 : Cleaned.
C:\RECYCLER\S-1-5-21-1371315241-4271176276-1453689397-1003\Dc807.txt -> TrackingCookie.2o7 : Cleaned.
C:\RECYCLER\S-1-5-21-1371315241-4271176276-1453689397-1003\Dc619.txt -> TrackingCookie.Adbrite : Cleaned.
C:\Documents and Settings\Owner\Cookies\juggler[1].txt -> TrackingCookie.Adjuggler : Cleaned.
C:\RECYCLER\S-1-5-21-1371315241-4271176276-1453689397-1003\Dc622.txt -> TrackingCookie.Adrevolver : Cleaned.
C:\Documents and Settings\Owner\Cookies\owner@bluestreak[1].txt -> TrackingCookie.Bluestreak : Cleaned.
C:\RECYCLER\S-1-5-21-1371315241-4271176276-1453689397-1003\Dc642.txt -> TrackingCookie.Bluestreak : Cleaned.
C:\RECYCLER\S-1-5-21-1371315241-4271176276-1453689397-1003\Dc787.txt -> TrackingCookie.Bluestreak : Cleaned.
C:\RECYCLER\S-1-5-21-1371315241-4271176276-1453689397-1003\Dc652.txt -> TrackingCookie.Bridgetrack : Cleaned.
C:\RECYCLER\S-1-5-21-1371315241-4271176276-1453689397-1003\Dc644.txt -> TrackingCookie.Burstnet : Cleaned.
C:\RECYCLER\S-1-5-21-1371315241-4271176276-1453689397-1003\Dc761.txt -> TrackingCookie.Burstnet : Cleaned.
C:\RECYCLER\S-1-5-21-1371315241-4271176276-1453689397-1003\Dc647.txt -> TrackingCookie.Casalemedia : Cleaned.
C:\RECYCLER\S-1-5-21-1371315241-4271176276-1453689397-1003\Dc655.txt -> TrackingCookie.Com : Cleaned.
C:\RECYCLER\S-1-5-21-1371315241-4271176276-1453689397-1003\Dc677.txt -> TrackingCookie.Fastclick : Cleaned.
C:\RECYCLER\S-1-5-21-1371315241-4271176276-1453689397-1003\Dc707.txt -> TrackingCookie.Overture : Cleaned.
C:\RECYCLER\S-1-5-21-1371315241-4271176276-1453689397-1003\Dc624.txt -> TrackingCookie.Pointroll : Cleaned.
C:\Documents and Settings\Owner\Cookies\owner@questionmarket[1].txt -> TrackingCookie.Questionmarket : Cleaned.
C:\RECYCLER\S-1-5-21-1371315241-4271176276-1453689397-1003\Dc719.txt -> TrackingCookie.Questionmarket : Cleaned.
C:\RECYCLER\S-1-5-21-1371315241-4271176276-1453689397-1003\Dc721.txt -> TrackingCookie.Realmedia : Cleaned.
C:\RECYCLER\S-1-5-21-1371315241-4271176276-1453689397-1003\Dc736.txt -> TrackingCookie.Statcounter : Cleaned.
C:\RECYCLER\S-1-5-21-1371315241-4271176276-1453689397-1003\Dc801.txt -> TrackingCookie.Statcounter : Cleaned.
C:\RECYCLER\S-1-5-21-1371315241-4271176276-1453689397-1003\Dc742.txt -> TrackingCookie.Trafficmp : Cleaned.
C:\Documents and Settings\Owner\Cookies\owner@tribalfusion[2].txt -> TrackingCookie.Tribalfusion : Cleaned.
C:\RECYCLER\S-1-5-21-1371315241-4271176276-1453689397-1003\Dc743.txt -> TrackingCookie.Tribalfusion : Cleaned.
C:\RECYCLER\S-1-5-21-1371315241-4271176276-1453689397-1003\Dc750.txt -> TrackingCookie.Web-stat : Cleaned.
C:\RECYCLER\S-1-5-21-1371315241-4271176276-1453689397-1003\Dc617.txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\RECYCLER\S-1-5-21-1371315241-4271176276-1453689397-1003\Dc782.txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\RECYCLER\S-1-5-21-1371315241-4271176276-1453689397-1003\Dc779.txt -> TrackingCookie.Zedo : Cleaned.

::Report end

i want to get rid of everything and protect myself better in the future.
i'm using aol, windows xp, i have a gateway pc, and im using service pack #1 cuz i think #2 jacked my computer up.
thanks.

Dani AI

Generated

A short, practical plan to follow after the AVG log and the helpful replies from and .

The immediate checklist (do these in order): disconnect the PC from the network; back up personal documents and media to external storage and verify those backups on a different, clean computer (do not copy executables or installer packages); empty the AVG quarantine/virus vault and the Recycle Bin as advised; reboot into Safe Mode and run a full, fully updated scan. The thread shows AVG quarantined many items — that’s a good start — but a hidden/driver-level component was suspected by , so a deeper check is required.

Next-level checks: run specialized rootkit detectors and interpret their logs before removing anything (many legitimate drivers and services can look suspicious). Two well-known tools for detection are GMER and Microsoft’s RootkitRevealer; both are aimed at uncovering hidden drivers/services but require cautious log-review or expert help before deleting entries. (GMER guide) (RootkitRevealer).

If a kernel/boot-level component is suspected or scans keep failing to clean stubborn objects, run an offline rescue scan from bootable media (examples: Kaspersky Rescue Disk or similar rescue ISOs). Offline scanning prevents active malware from hiding itself during remediation. After confirmed cleaning, purge older restore points (System Restore can contain archived infected files) — use Disk Cleanup or disable/re-enable System Restore to purge the store so old infected snapshots cannot reinfect the system. (Kaspersky Rescue Disk info) (how to clear restore points).

If the infection cannot be reliably eliminated or a backdoor/rootkit was present, a full wipe and clean reinstall is the only way to be confident the system is safe; back up only data (scan backups on another machine), reinstall from official media, patch fully, then install protection before reconnecting. The security community consistently recommends reimaging/reformat-and-reinstall when kernel-level compromises cannot be proven clean. (discussion and guidance)

Notes and cautions: rootkit tools and rescue ISOs are powerful and can produce confusing output — preserve logs and, if uncertain, post them for experienced reviewers rather than blindly deleting drivers or registry entries.

Recommended Answers

All 6 Replies

1. empty the quarantine/virus vault in AVG
2. empty the recyle bins of all users

Try scan again and post new log

i have no idea how to do that...explain please?

In AVG antispyware go to infections menu then remove them. then empty your recyle bin too and rerun the test

You have a fairly serious baddie that is protected by a rootkit. If nobody else is here able to help you clean your compy, I will try - I do not have a lot of Forum time these days....

C:\WINNT\system32\xcttgs.dll -> : Error during cleaning.
[408] C:\WINNT\system32\xcttgs.dll -> : Error during cleaning.

There will probably be a rootkit driver labeled xcttgs.sys in addition to the above.

Best Luck :)
PP

aww your so sweet well this is what i have come up with now:

---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------
+ Created at: 4:28:28 PM 2/14/2007
+ Scan result:

C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP748\A0783988.dll -> Adware.Aws : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP748\A0783989.dll -> Adware.DealHelper : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP748\A0783990.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP748\A0783991.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP748\A0783992.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP748\A0783993.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP748\A0783994.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP748\A0783995.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP748\A0783996.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP748\A0783997.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP748\A0783998.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP748\A0783999.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP748\A0784000.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP748\A0784001.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\WINNT\system32\xcttgs.dll -> : Cleaned with backup (quarantined).
[1640] C:\WINNT\System32\xcttgs.dll -> : Cleaned with backup (quarantined).
[408] C:\WINNT\system32\xcttgs.dll -> : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP748\A0783987.exe -> Downloader.Zlob.bke : Cleaned with backup (quarantined).
C:\Documents and Settings\Owner\Cookies\owner@2o7[2].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Owner\Cookies\juggler[2].txt -> TrackingCookie.Adjuggler : Cleaned.
C:\Documents and Settings\Owner\Cookies\owner@bluestreak[2].txt -> TrackingCookie.Bluestreak : Cleaned.
C:\Documents and Settings\Owner\Cookies\owner@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : Cleaned.
C:\Documents and Settings\Owner\Cookies\eldmanager[2].txt -> TrackingCookie.Yieldmanager : Cleaned.

::Report end

C:\WINNT\system32\xcttgs.dll -> : Cleaned with backup (quarantined).
[1640] C:\WINNT\System32\xcttgs.dll -> : Cleaned with backup (quarantined).
[408] C:\WINNT\system32\xcttgs.dll -> : Cleaned with backup (quarantined).

It appears that AVG was able to clean that particular baddie.

Are you still having any problems? If so, we can try a few additional scans.....


Cheers :)
PP

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.