Avast has found Trojan but can't delete?

hi guys
hope someone can help me as I’m at the end of my tether.
I’ll start at the beginning.
I run Windows XP
A few days back I updated a youtube program (dvd video soft) and I wish I hadn’t bothered, my pc went crazy. It downloaded all this junk ad stuff and something called Uline? Anyway I deleted it and thought everything was ok.
Then I started to get a Google desktop error read (please see attached .jpg)
so I thought I should just uninstall completely as I’ve never used it. But I was concerned that it would mess up my PC (if it was attached to other programs?) so I have left it.
anyway, long story short -
yesterday on the right hand side of my screen the google desktop pops up “thank you for installing google desktop”
I had no idea how this happened as a) I didn’t install, it was already on PC b) why on earth would that happen now when I’m contemplating uninstalling? does it know!? (haha)
since then my pc has been very slow, browser, opening files, etc.,
Did a boot scan and avast found 3 viruses, one is in chest, one has been deleted and the other (a trojan no less) is yet to be dealt with “on next boot scan” I’ve done a boot scan (twice) and the trojan is still there.
Why can’t avast delete it? am I doing something wrong?
please help as I need my pc for work etc., and honestly can’t do without it for more than a day or 2.

sorry guys, forgot to add the image for the trojan, see below! sorry.

Logs to assist in cleaning malware. https://forum.avast.com/index.php?topic=53253.0

hi Pondus
thanks for your reply.
I already have Malwarebytes on my PC and have completed a good few scans since finding virus, but Malwarebytes has come up with nothing. It says my PC is clear of threats (!!)
I really have no idea what to do next…

I really have no idea what to do next...
You follow instructions and attach requested logs

Hi Pondus
I’m busy doing a custom MBAM scan but its taking forever! (>.<)

I have just checked log again on Avast (regarding Trojan, that cannot be removed) and it says it is Google Desktop (!)

I have attached jpg… do you think I should just uninstall google desktop? will this solve problem??

thank you!

stop malwarebytes …

I have attached jpg... do you think I should just uninstall google desktop? will this solve problem??
i think diagnostic logs will tell us what to do .... then we dont have to guess

attach Farbar Recovery Scan Tool logs (two logs)

Hi it depends on the type of google desktop, as there is a bad version around

If you wish you can stop the MBAM scan

Please download Farbar Recovery Scan Tool and save it to your Desktop.

Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.

[*]Right click to run as administrator (XP users click run after receipt of Windows Security Warning - Open File). When the tool opens click Yes to disclaimer.
[*]Select additions at the bottom
[*]Press Scan button.

https://dl.dropboxusercontent.com/u/73555776/frst.JPG

[*]It will produce a log called FRST.txt in the same directory the tool is run from.
[*]Please attach both logs generated.

hi Pondus and essexboy,

thank you for your help, I’m beyond grateful!

(apologies for my stupidity!) but do you mean attach the scan log from Avast??

No FRST will produce two logs attach those :slight_smile:

hi essexboy

oh I’m so sorry! :-[

ok, I’m going to wait until this scan has finished then I will do the FRST thing. (is it safe?) thanks!

one other thing…I tried to put the trojan into chest but I got a error message "the system cannot find the file specified (2) " is this good or bad? has it spread? I am so confused right now… ??? :cry:

No it means it was probably detected in memory. I will be going off line now but will be back after lunch tomorrow

essexboy,

thank you for your help! hopefully by tomorrow I will have some more info for you. :slight_smile:

Hey essexboy
Having major problems today. Using my phone for this message.
Can’t open a browser connect to Internet and it won’t let me update
Avast.
I haven’t downloaded FRST yet either! So I don’t know what to do???

EDIT: finally downloaded! attached logs essexboy, many thx for your help! will await your instructions. also… should I delete the FRST or keep it on PC???

EDIT 2: re your Google desktop question, forgot to mention that I use XP (!) and have had this pc for about 7/8 years?? so not sure what version of GD this is. It was installed on pc when I got it. Never use it! I definitely want rid of it after this trojan is gone!

should I delete the FRST or keep it on PC???
essexboy will remove all tools used when he is finish working your computer follow his instructions, no more no less
AVG 2011 (Version: 10.0.1153 - AVG Technologies) Hidden AVG 2011 (Version: 10.0.424 - AVG Technologies) Hidden
do you have avast and AVG installed?

hi Pondus,
thank you for your reply, I shall await instructions :slight_smile:

I have Avast and MBAM installed. Used to have AVG years ago, but deleted that and used MS Essentials then when Microsoft stopped XP updates I had to delete MSE and that was when I started using Avast. There are leftover files from AVG and many other programs that I no longer have on my pc! (>.<)

EDIT hey Pondus / essexboy, I’m busy copying files onto a USB ( worried in case I lose stuff ) and I just got this message (attached jpg) Should I be worried?? Is it spreading???

Hi, the google desktop is the good version :slight_smile:

CAUTION : This fix is only valid for this specific machine, using it on another may break your computer

Open notepad and copy/paste the text in the quotebox below into it:

CreateRestorePoint: HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs,Tabs: "about:newtab" <======= ATTENTION Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll No File CHR HKLM\...\Chrome\Extension: [jfmjfhklogoienhpfnppmbcbjfjnkonk] - No Path S1 fdafujdy; \??\C:\WINDOWS\system32\drivers\fdafujdy.sys [X] CustomCLSID: HKU\S-1-5-21-1547161642-842925246-1801674531-1004_Classes\CLSID\{2D611968-B0FB-4B81-8AFA-D7486879D141}\InprocServer32 -> C:/Program Files/Scrivener/eWebClient.dll No File C:\WINDOWS\system32\drivers\fdafujdy.sys EmptyTemp: CMD: bitsadmin /reset /allusers

Save this as fixlist.txt, in the same location as FRST.exe

https://dl.dropboxusercontent.com/u/73555776/FRSTfix.JPG

Run FRST and press Fix
On completion a log will be generated please post that

THEN

Please download AdwCleaner by Xplode onto your desktop.

[*]Close all open programs and internet browsers.
[*]Double click on AdwCleaner.exe to run the tool.
[*]Click on Scan.
[*]After the scan is complete click on “Clean”
[*]Confirm each time with Ok.
[*]Your computer will be rebooted automatically. A text file will open after the restart.
[*]Please post the content of that logfile with your next answer.
[*]You can find the logfile at C:\AdwCleaner[S1].txt as well.

hey essexboy,
thank you so much, doing it now!
also, should I be concerned about that Data Execution prevention message?

Not just yet

not sure what’s happening but the FRST has frozen, should I stop it? run it again?

EDIT: FRST log attached!

EDIT 2: I’m attaching the threats Avast found, the one where it says move to chest - when I check chest it isn’t there (!) and the Trojan - action postponed until next reboot one - I rebooted twice after getting this message and its still there. Sorry if I’ve already told you this, I’m a total idiot when it comes to PCs and I’m worried…

EDIT 3: AdwCleaner log attached! I’ll await your instructions and once again thank you for helping me! :slight_smile:

What was the full folder path ? Were they in the temp internet folder ?

Download and Install Combofix

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

  • IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here

[*]Double click on ComboFix.exe & follow the prompts.
[*]Accept the disclaimer and allow to update if it asks

http://img.photobucket.com/albums/v706/ried7/NSIS_disclaimer_ENG.png

http://img.photobucket.com/albums/v706/ried7/NSIS_extraction.png

[*]When finished, it shall produce a log for you.
[*]Please include the C:\ComboFix.txt in your next reply.

Notes:

  1. Do not mouse-click Combofix’s window while it is running. That may cause it to stall.
  2. Do not “re-run” Combofix. If you have a problem, reply back for further instructions.
  3. If after the reboot you get errors about programmes being marked for deletion then reboot, that will cure it.

Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now