This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] XP w/ Lando/Generic!Artemis Trojan/Virus

18 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

This is the one we were after. The other 2 should be OK.

O18 - Filter hijack: text/html - {64c30d50-5dd7-4cf5-a946-173d206bb5fb} - C:\WINDOWS\system32\mst120.dll

Did you do this?

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Uncheck "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Uncheck "Hide protected operating system files."
Click Apply, and then click OK.


Get a free one.

Only run one AVG at a time.

Grisoft AVG
http://free.avg.com/download-avg-anti-virus-free-edition

or

avast! 4
http://www.avast.com/eng/download-avast-home.html

Or

Avira AntiVir Personal - FREE Antivirus
http://www.free-av.com/en/download/1/downl…_antivirus.html


Run a full scan and let us know what it finds along with a new HijackThis log.

Also please describe how your computer behaves at the moment
I ran HJT and checked (O18) and selected fix but it doesn't remove it. When I do a scan (either before or after re-boot) it still shows up in the scan. When I select fix, the HJT screen empties (nothing shown). As for the mst120.dll file. I do have hidden files and I have unhidden files and folders, protected ops system files and extensions for known file types. The two locations I mentioned in previous post are the only places I can find that file name. Do you want me to run one of these antivirus scans now or given the above, is there something more we want to do first? If yes, is there a preferred one? One more thing. The computer locked up again in the past hour and I got "Generic Host Process for Win32 Services has encountered a problem and needs to close" After that, she's locked up. I believe that's the same thing that happened at least once if not twice earlier in the day (and not previously) Thanks
Installed Avira…..tried to update before first scan….couldn't. Log of update is below. Avira AntiVir Personal - Free Antivirus Updater Creation time: Fri Apr 03 19:09:42 2009 Operating system: Windows XP (Service Pack 3) [5.1.2600] Product information: Product version: 9.0.0.386 Updater: C:\Program Files\Avira\AntiVir Desktop\update.exe 09.00.00.42 Plugin: C:\Program Files\Avira\AntiVir Desktop\updext.dll 09.00.00.06 Temp Directory: C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\UPDATE\ Backup folder: C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\BACKUP\ Installation Directory: C:\Program Files\Avira\AntiVir Desktop\ Updater folder: C:\Program Files\Avira\AntiVir Desktop\ AppData folder: C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\ [UPD] [INFO] Checking whether newer files are available. [UPD] [INFO] Select update server 'http://80.190.143.230/update'. [UPD] [INFO] Downloading of 'http://80.190.143.230/update/idx/master.idx' to 'C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\UPDATE\idx\master.idx'. [UPDLIB] [ERROR] IDX- integrity check failed. [UPD] [INFO] Select update server 'http://80.190.143.230/update'. [UPD] [INFO] Downloading of 'http://80.190.143.230/update/idx/master.idx' to 'C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\UPDATE\idx\master.idx'. [UPDLIB] [ERROR] IDX- integrity check failed. [UPD] [ERROR] Generation of update structure failed. UpdateLib delivers error 19. Summary: ******** 0 Files downloaded 0 Files installed 19:10:13 The update failed! I will run the scan without the update and see what I get and report with HJT lgo
Here is what we got. 1 file that could not be scanned. Avira AntiVir Personal Report file date: Friday, April 03, 2009 19:12 Scanning for 1284893 virus strains and unwanted programs. Licensee : Avira AntiVir Personal - FREE Antivirus Serial number : 0000149996-ADJIE-0000001 Platform : Windows XP Windows version : (Service Pack 3) [5.1.2600] Boot mode : Normally booted Username : SYSTEM Computer name : YOUR-4DACD0EA75 Version information: BUILD.DAT : 9.0.0.386 17962 Bytes 3/11/2009 15:55:00 AVSCAN.EXE : 9.0.3.3 464641 Bytes 2/24/2009 17:13:26 AVSCAN.DLL : 9.0.3.0 40705 Bytes 2/27/2009 15:58:24 LUKE.DLL : 9.0.3.2 209665 Bytes 2/20/2009 16:35:49 LUKERES.DLL : 9.0.2.0 12033 Bytes 2/27/2009 15:58:52 ANTIVIR0.VDF : 7.1.0.0 15603712 Bytes 10/27/2008 17:30:36 ANTIVIR1.VDF : 7.1.2.12 3336192 Bytes 2/11/2009 01:33:26 ANTIVIR2.VDF : 7.1.2.105 513536 Bytes 3/3/2009 12:41:14 ANTIVIR3.VDF : 7.1.2.127 110592 Bytes 3/5/2009 19:58:20 Engineversion : 8.2.0.100 AEVDF.DLL : 8.1.1.0 106868 Bytes 1/27/2009 22:36:42 AESCRIPT.DLL : 8.1.1.56 352634 Bytes 2/27/2009 01:01:56 AESCN.DLL : 8.1.1.7 127347 Bytes 2/12/2009 16:44:25 AERDL.DLL : 8.1.1.3 438645 Bytes 10/29/2008 23:24:41 AEPACK.DLL : 8.1.3.10 397686 Bytes 3/4/2009 18:06:10 AEOFFICE.DLL : 8.1.0.36 196987 Bytes 2/27/2009 01:01:56 AEHEUR.DLL : 8.1.0.100 1618295 Bytes 2/25/2009 20:49:16 AEHELP.DLL : 8.1.2.2 119158 Bytes 2/27/2009 01:01:56 AEGEN.DLL : 8.1.1.24 336244 Bytes 3/4/2009 18:06:10 AEEMU.DLL : 8.1.0.9 393588 Bytes 10/9/2008 19:32:40 AECORE.DLL : 8.1.6.6 176501 Bytes 2/17/2009 19:22:44 AEBB.DLL : 8.1.0.3 53618 Bytes 10/9/2008 19:32:40 AVWINLL.DLL : 9.0.0.3 18177 Bytes 12/12/2008 13:47:59 AVPREF.DLL : 9.0.0.1 43777 Bytes 12/5/2008 15:32:15 AVREP.DLL : 8.0.0.3 155905 Bytes 1/20/2009 19:34:28 AVREG.DLL : 9.0.0.0 36609 Bytes 12/5/2008 15:32:09 AVARKT.DLL : 9.0.0.1 292609 Bytes 2/9/2009 12:52:24 AVEVTLOG.DLL : 9.0.0.7 167169 Bytes 1/30/2009 15:37:08 SQLITE3.DLL : 3.6.1.0 326401 Bytes 1/28/2009 20:03:49 SMTPLIB.DLL : 9.2.0.25 28417 Bytes 2/2/2009 13:21:33 NETNT.DLL : 9.0.0.0 11521 Bytes 12/5/2008 15:32:10 RCIMAGE.DLL : 9.0.0.21 2438401 Bytes 2/9/2009 16:45:45 RCTEXT.DLL : 9.0.35.0 87297 Bytes 3/11/2009 20:55:12 Configuration settings for the scan: Jobname………………………..: Complete system scan Configuration file………………: c:\program files\avira\antivir desktop\sysscan.avp Logging………………………..: low Primary action………………….: interactive Secondary action………………..: ignore Scan master boot sector………….: on Scan boot sector………………..: on Boot sectors……………………: C:, D:, Process scan……………………: on Scan registry…………………..: on Search for rootkits……………..: on Integrity checking of system files..: on Scan all files………………….: All files Scan archives…………………..: on Recursion depth…………………: 20 Smart extensions………………..: on Macro heuristic…………………: on File heuristic………………….: medium Start of the scan: Friday, April 03, 2009 19:12 Initiating scan of system files: Signed -> 'C:\WINDOWS\system32\svchost.exe' Signed -> 'C:\WINDOWS\system32\winlogon.exe' Signed -> 'C:\WINDOWS\explorer.exe' Signed -> 'C:\WINDOWS\system32\smss.exe' Signed -> 'C:\WINDOWS\system32\wininet.DLL' Signed -> 'C:\WINDOWS\system32\wsock32.DLL' Signed -> 'C:\WINDOWS\system32\ws2_32.DLL' Signed -> 'C:\WINDOWS\system32\services.exe' Signed -> 'C:\WINDOWS\system32\lsass.exe' Signed -> 'C:\WINDOWS\system32\csrss.exe' Signed -> 'C:\WINDOWS\system32\drivers\kbdclass.sys' Signed -> 'C:\WINDOWS\system32\spoolsv.exe' Signed -> 'C:\WINDOWS\system32\alg.exe' Signed -> 'C:\WINDOWS\system32\wuauclt.exe' Signed -> 'C:\WINDOWS\system32\advapi32.DLL' Signed -> 'C:\WINDOWS\system32\user32.DLL' Signed -> 'C:\WINDOWS\system32\gdi32.DLL' Signed -> 'C:\WINDOWS\system32\kernel32.DLL' Signed -> 'C:\WINDOWS\system32\ntdll.DLL' Signed -> 'C:\WINDOWS\system32\ntoskrnl.exe' Signed -> 'C:\WINDOWS\system32\ctfmon.exe' The system files were scanned ('21' files) Starting search for hidden objects. '75889' objects were checked, '0' hidden objects were found. The scan of running processes will be started Scan process 'avscan.exe' - '1' Module(s) have been scanned Scan process 'notepad.exe' - '1' Module(s) have been scanned Scan process 'avcenter.exe' - '1' Module(s) have been scanned Scan process 'iPodService.exe' - '1' Module(s) have been scanned Scan process 'iTunesHelper.exe' - '1' Module(s) have been scanned Scan process 'realsched.exe' - '1' Module(s) have been scanned Scan process 'avgnt.exe' - '1' Module(s) have been scanned Scan process 'sched.exe' - '1' Module(s) have been scanned Scan process 'avguard.exe' - '1' Module(s) have been scanned Scan process 'hpsysdrv.exe' - '1' Module(s) have been scanned Scan process 'iexplore.exe' - '1' Module(s) have been scanned Scan process 'HijackThis.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'aolsoftware.exe' - '1' Module(s) have been scanned Scan process 'explorer.exe' - '1' Module(s) have been scanned Scan process 'DiscStreamHub.exe' - '1' Module(s) have been scanned Scan process 'ehmsas.exe' - '1' Module(s) have been scanned Scan process 'aim6.exe' - '1' Module(s) have been scanned Scan process 'msmsgs.exe' - '1' Module(s) have been scanned Scan process 'ctfmon.exe' - '1' Module(s) have been scanned Scan process 'DACSMiniApp.exe' - '1' Module(s) have been scanned Scan process 'jusched.exe' - '1' Module(s) have been scanned Scan process 'kbd.exe' - '1' Module(s) have been scanned Scan process 'hpwuSchd2.exe' - '1' Module(s) have been scanned Scan process 'wmiprvse.exe' - '1' Module(s) have been scanned Scan process 'DISCUpdMgr.exe' - '1' Module(s) have been scanned Scan process 'DISCover.exe' - '1' Module(s) have been scanned Scan process 'arpwrmsg.exe' - '1' Module(s) have been scanned Scan process 'RTHDCPL.EXE' - '1' Module(s) have been scanned Scan process 'ehtray.exe' - '1' Module(s) have been scanned Scan process 'wscntfy.exe' - '1' Module(s) have been scanned Scan process 'alg.exe' - '1' Module(s) have been scanned Scan process 'dllhost.exe' - '1' Module(s) have been scanned Scan process 'mcrdsvc.exe' - '1' Module(s) have been scanned Scan process 'WUSB54GC.exe' - '1' Module(s) have been scanned Scan process 'WLService.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'QBDBMgrN.exe' - '1' Module(s) have been scanned Scan process 'nvsvc32.exe' - '1' Module(s) have been scanned Scan process 'MDM.EXE' - '1' Module(s) have been scanned Scan process 'LSSrvc.exe' - '1' Module(s) have been scanned Scan process 'jqs.exe' - '1' Module(s) have been scanned Scan process 'ehSched.exe' - '1' Module(s) have been scanned Scan process 'ehrecvr.exe' - '1' Module(s) have been scanned Scan process 'arservice.exe' - '1' Module(s) have been scanned Scan process 'spoolsv.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'lsass.exe' - '1' Module(s) have been scanned Scan process 'services.exe' - '1' Module(s) have been scanned Scan process 'winlogon.exe' - '1' Module(s) have been scanned Scan process 'csrss.exe' - '1' Module(s) have been scanned Scan process 'smss.exe' - '1' Module(s) have been scanned 57 processes with 57 modules were scanned Starting master boot sector scan: Start scanning boot sectors: Starting to scan executable files (registry). The registry was scanned ( '77' files ). Starting the file scan: Begin scan in 'C:\' C:\pagefile.sys [WARNING] The file could not be opened! [NOTE] This file is a Windows system file. [NOTE] This file cannot be opened for scanning. Begin scan in 'D:\' End of the scan: Friday, April 03, 2009 20:11 Used time: 58:33 Minute(s) The scan has been done completely. 12362 Scanned directories 683549 Files were scanned 0 Viruses and/or unwanted programs were found 0 Files were classified as suspicious 0 files were deleted 0 Viruses and unwanted programs were repaired 0 Files were moved to quarantine 0 Files were renamed 1 Files cannot be scanned 683548 Files not concerned 17266 Archives were scanned 1 Warnings 1 Notes 75889 Objects were scanned with rootkit scan 0 Hidden objects were found
That scan looked good to me.

You don't need to download again but follow the instructions.

Please download this file - combofix.exe by sUBs
  • Save it to your Desktop
  • Now physically disconnect from the internet and STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields)
  • Click on your START button and choose Run. Then copy/paste the entire content of the following quotebox (Including the "" marks and the Symbols) into the run box.

    Go to [external image: Posted Image] -> Run -> copy/paste in the following single line command & click OK

    "%userprofile%\desktop\combofix.exe" /killall


    [external image: Posted Image]
  • Click OK and this will start ComboFix in a special way.
  • When finished, it will produce a log. Please save that log to a Notepad File to post in your next reply along with a fresh HJT log.

Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.

* After you have saved the logs, restart your system to re-enable all the programs that were disabled during the running of ComboFix.

* Reconnect to the internet

* Post the following logs/Reports:
  • ComboFix.txt
  • Fresh HijackThis log run after all the other tools have performed their cleanup.
Okay. I could not download the Combofix from that link. I just get a blank page at this address: http://download.bleepingcomputer.com/sUBs/Beta/ComboFix.exe

Tried to use existing copy of Combofix that was still on the desktop since you said I didn't really need to download. Turned off my wireless access (so no internet), made sure Avira was off (only thing on the computer now I think).

Copied, pasted, run…..Combofix box comes up, goes green, 10 seconds or so later it goes away with no further action (that I can discern). No log found.
Delete the combofix that's on your desktop now.

After the above:

Please do not delete anything unless instructed to.

NOTE: worksnow is actually Combofix renamed so user is able download and run Combofix

Download worksnow from HERE:


* IMPORTANT !!! Save worksnow to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : Protective Programs

  • Double click on worksnow & follow the prompts.

    Note: worksnow will run without the Recovery Console installed.

    Note: Combofix will run without the Recovery Console installed.

  • As part of it's process, combofix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
"copy/paste" a new HijackThis log file into this thread as well.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Give it atleast 20-30 minutes to finish if needed.


Also please describe how your computer behaves at the moment.
This got me back to the same spot…combofix comes up, goes green, disappears. I couldn't take it anymore so I actually decided to go ahead and just blow everything away and start over. I backed up my files and wiped everything today and reinstalled. So far, so good. I really appreciate your time and effort in trying to work me through this. I have learned quite a bit about both the importance of keeping security up and that there is someplace to go for help if and when I need it again (heaven forbid). Thanks again for working with me.
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI