This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

 All antivirus programs and related software blocked

16 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I think I have a pretty big problem…. Recently I booted my computer and realized none of my security software was running, and my browser was redirected from most virus related websites and other websites to advertising sites that no longer exist. My CPU is also constantly chugging along at about 80% Usage. The only thing I have been able to successfully run on my computer is the windows malicious software tool and it says I have been infected by the trojan alureon.bf and while the program says it removes the trojan, it does not. My biggest problem is that not even HiJack This will run. Please Help….
Hi,

Please try the following program,

  • Download OTListIt2 to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTListIt.Txt and Extras.Txt. These are saved in the same location as OTListIt2.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
Ok so I don't know if you can help with this, but last night I was posting from my laptop(not infected) while I left my PC(infected) running. When I returned to my PC the only thing on the screen where three vertical blue bars and my computer was unresponsive. Now when i try to boot my PC the bios screen is kind of messed up looking, the colors are off on the windows load screen and when it hits the login screen the graphics go nuts and the computer freezes. I don't know if you can help me with this but any advice would be appreciated. Do you think this maybe a hardware issue, the CPU was running at a very high load for about an hour or two? I think this would be unlikely though. Do you think this problem is fixable? If not, do you think I will be able to recover any data? I know I'm not giving you much to go on, but any help would be much appreciated
Hi

It's hard to know if this is malware related or you have suffered a hardware failure.

Are you able to boot into safe mode

(tap F8 repeatedly - a screen will pop up that gives you various options - arrow up to Safe Mode)


download this program onto a USB from the uninfected computer and try and run it in safe mode.

But first lets disinfect all your USB's so you don't transfer any infections to your clean computer:

To disinfect removable media do the following:

Download Flash_Disinfector.exe from HERE and save it to your desktop.

Double-click Flash_Disinfector.exe to run it and follow any prompts that may appear.
The utility may ask you to insert your flash drive and/or other removable drives including your mobile phone. Please do so and allow the utility to clean up those drives as well.
Wait until it has finished scanning and then exit the program.
Reboot your computer when done.


NEXT

Rename this program first - then transfer it over to the desktop of the infected computer.

Download Combofix from any of the links below. You must rename it before saving it. Save it to your desktop.

Link 1
Link 2
Link 3

[external image: Posted Image]


[external image: Posted Image]
——————————————————————–

Double click on Combo-Fix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt back into this thread.


If you cannot boot into safe mode. You may be faced with either a repair install or a complete reformat.
Do you know if you have the recovery console installed?

Please advise how you get on.
hey just an update my computer is able to boot into safe mode. I just need to get my hands on a flash drive i've seemed to have misplaced mine. I should have an actuall update for you within the next two days. Thanks alot.
Hey so I went to run combo fix and it through up some errors about AVG running and that it would be dangerous to continue. I was wondering how to stop it in safe mode. The Tray Icon is not active and their are no obvious processes running.
Hi,

Not sure what version of AVG you have - these are the instructions for AVG7 & 8

AVG
Please open the AVG Control Center program -> double-click on the "AVG Resident Shield" component (looks like this: [external image: Posted Image]) -> deselect the "Turn on AVG Resident Shield" checkmark and save the setting.
When you need to enable the AVG Resident Shield, ( I will let you know when) just open the AVG Control Center program -> double-click on the "AVG Resident Shield" component -> select the "Turn on AVG Resident Shield" checkmark and save the setting.

AVG 8
Please open the AVG 8 Control Center, by right clicking on the AVG 8 icon on the task bar.
  • Click on Tools.
  • Select Advanced Settings.
  • In the left hand pane, scroll down to "Resident Shield".
  • In the main pane, deselect the option to "Enable Resident Shield."
  • To re-enable AVG 8, please select "Enable Resident Shield" again.


If you can't do that in safe mode go to task manager and end any avg process
ok so i cant find any avg processes running but combo-fix still says that it is running the is no icon in the taskbar i cant use any of the functionality of the program to stop or close it cause it doesn't appear to be running at all the only indication that it is, is that combofix throws the error. again there are no processes running with avg anywhere in the name I am running avg 8
ComboFix 09-05-02.4 - Administrator 05/03/2009 12:38.1 - NTFSx86 MINIMAL
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1806 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\Combo2Fix.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated)

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\bcbbcbaceed.dll
c:\windows\system32\drivers\senekaxbjkyrsq.sys
c:\windows\system32\drivers\UACvkalxete.sys
c:\windows\system32\eedcbaae.dll
c:\windows\system32\mukmil.dll
c:\windows\system32\senekavnvtaitu.dll
c:\windows\system32\UACdtwwswut.log
c:\windows\system32\UAChtapqjeo.dll
c:\windows\system32\uacinit.dll
c:\windows\system32\UACjbfrmupt.dat
c:\windows\system32\UAClprrdkjf.dll
c:\windows\system32\UACmrletjkn.dll
c:\windows\system32\UAConqoqugy.log
c:\windows\system32\UACpqrkblmk.dll
c:\windows\system32\UACttrnskbw.log
c:\windows\system32\UACxtainahb.dll
c:\windows\Tasks\hetgyfnx.job
c:\windows\wiaserviv.log

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_SENEKA
——-\Service_UACd.sys


((((((((((((((((((((((((( Files Created from 2009-04-03 to 2009-05-03 )))))))))))))))))))))))))))))))
.

2009-05-03 16:11 . 2009-05-03 16:12 ——– d—–w C:\32788R22FWJFW.0.tmp
2009-05-03 16:09 . 2009-05-03 16:11 ——– d—–w C:\Combo-Fix
2009-05-03 13:32 . 2009-05-03 13:32 ——– d—–w c:\documents and settings\Administrator\Application Data\U3
2009-04-28 22:51 . 2009-04-28 22:51 ——– d—–w c:\program files\ERUNT
2009-04-22 01:20 . 2009-04-22 01:20 ——– d—–w C:\99a832757e1284ffe527
2009-04-21 22:25 . 2009-03-06 14:22 284160 -c—-w c:\windows\system32\dllcache\pdh.dll
2009-04-21 22:25 . 2009-02-09 12:10 401408 -c—-w c:\windows\system32\dllcache\rpcss.dll
2009-04-21 22:25 . 2009-02-06 11:11 110592 -c—-w c:\windows\system32\dllcache\services.exe
2009-04-21 22:25 . 2009-02-09 12:10 473600 -c—-w c:\windows\system32\dllcache\fastprox.dll
2009-04-21 22:25 . 2009-02-06 10:10 227840 -c—-w c:\windows\system32\dllcache\wmiprvse.exe
2009-04-21 22:25 . 2009-02-09 12:10 453120 -c—-w c:\windows\system32\dllcache\wmiprvsd.dll
2009-04-21 22:25 . 2009-02-09 12:10 729088 -c—-w c:\windows\system32\dllcache\lsasrv.dll
2009-04-21 22:25 . 2009-02-09 12:10 617472 -c—-w c:\windows\system32\dllcache\advapi32.dll
2009-04-21 22:25 . 2009-02-09 12:10 714752 -c—-w c:\windows\system32\dllcache\ntdll.dll
2009-04-21 22:24 . 2008-05-03 11:55 2560 ——w c:\windows\system32\xpsp4res.dll
2009-04-21 22:24 . 2008-04-21 12:08 215552 -c—-w c:\windows\system32\dllcache\wordpad.exe
2009-04-16 21:00 . 2009-04-16 21:00 ——– d—–w c:\documents and settings\Administrator\Local Settings\Application Data\Mozilla
2009-04-09 23:16 . 2009-04-09 23:16 184848 —-a-w c:\windows\93827AAFCDFB6311DC8F9B759425E4F.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-03 13:37 . 2009-01-14 01:26 42960 —-a-w c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-28 22:15 . 2009-01-21 00:42 ——– d—–w c:\program files\Malwarebytes' Anti-Malware
2009-04-28 22:00 . 2008-03-30 20:36 ——– d—–w c:\program files\Digsby
2009-04-28 21:52 . 2007-04-08 20:04 6 —ha-w c:\windows\Tasks\SA.DAT
2009-04-10 00:10 . 2007-11-12 23:17 ——– d—–w c:\program files\Spybot - Search & Destroy
2009-03-18 01:30 . 2007-04-12 23:39 ——– d—–w c:\program files\Steam
2009-03-06 14:22 . 2004-08-04 12:00 284160 —-a-w c:\windows\system32\pdh.dll
2009-02-20 08:10 . 2004-08-04 12:00 666112 —-a-w c:\windows\system32\wininet.dll
2009-02-20 08:10 . 2004-08-04 12:00 81920 —-a-w c:\windows\system32\ieencode.dll
2009-02-09 12:10 . 2004-08-04 12:00 729088 —-a-w c:\windows\system32\lsasrv.dll
2009-02-09 12:10 . 2004-08-04 12:00 714752 —-a-w c:\windows\system32\ntdll.dll
2009-02-09 12:10 . 2004-08-04 12:00 617472 —-a-w c:\windows\system32\advapi32.dll
2009-02-09 12:10 . 2004-08-04 12:00 401408 —-a-w c:\windows\system32\rpcss.dll
2009-02-09 11:13 . 2004-08-04 12:00 1846784 —-a-w c:\windows\system32\win32k.sys
2009-02-06 11:11 . 2004-08-04 12:00 110592 —-a-w c:\windows\system32\services.exe
2009-02-06 11:06 . 2004-08-04 12:00 2145280 —-a-w c:\windows\system32\ntoskrnl.exe
2009-02-06 10:39 . 2004-08-04 12:00 35328 —-a-w c:\windows\system32\sc.exe
2009-02-06 10:32 . 2004-08-03 22:59 2023936 —-a-w c:\windows\system32\ntkrnlpa.exe
2009-02-03 23:04 . 2009-01-14 01:11 10520 —-a-w c:\windows\system32\avgrsstx.dll
2009-02-03 23:04 . 2009-01-14 01:11 325128 —-a-w c:\windows\system32\drivers\avgldx86.sys
2009-02-03 23:04 . 2009-01-14 01:11 107272 —-a-w c:\windows\system32\drivers\avgtdix.sys
2009-02-03 19:59 . 2004-08-04 12:00 56832 —-a-w c:\windows\system32\secur32.dll
2009-04-21 22:37 . 2009-04-09 23:38 66576 —-a-w c:\program files\mozilla firefox\components\bcbbcbaceed.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-05-28 335872]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 39792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-02-03 1601304]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" - c:\windows\KHALMNPR.Exe [2004-04-26 29696]
"CTHelper"="CTHELPER.EXE" - c:\windows\CTHELPER.EXE [2006-08-11 17920]
"CTxfiHlp"="CTXFIHLP.EXE" - c:\windows\system32\CTXFIHLP.EXE [2006-08-11 18944]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2007-7-23 67128]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\KEM.exe [2007-4-8 573440]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-02-03 23:04 10520 —-a-w c:\windows\system32\avgrsstx.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\DC++\\DCPlusPlus.exe"=
"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Steam\\Steam.exe"=
"c:\\Program Files\\Steam\\steamapps\\bmac85\\team fortress 2\\hl2.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\system32\\rtcshare.exe"=
"c:\\Program Files\\NetMeeting\\conf.exe"=
"c:\\Program Files\\Steam\\steamapps\\bmac85\\source sdk base\\hl2.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Steam\\steamapps\\bmac85\\counter-strike source\\hl2.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Digsby\\lib\\digsby-app.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\left 4 dead\\left4dead.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\Drivers\avgldx86.sys [2009-02-03 325128]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\System32\Drivers\avgtdix.sys [2009-02-03 107272]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2009-02-03 903960]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-02-03 298264]
R2 PfDetNT;PfDetNT;c:\windows\system32\drivers\PfModNT.sys [2006-08-11 8192]
R2 Viewpoint Manager Service;Viewpoint Manager Service; [x]
R3 DCamUSBIntel;USB 202 PC Cam; [x]


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\I]
\Shell\AutoRun\command - I:\LaunchU3.exe -a
.
Contents of the 'Scheduled Tasks' folder

2008-12-31 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]
.
- - - - ORPHANS REMOVED - - - -

BHO-{1428A472-5260-404E-9977-7ECDF1DAF936} - c:\windows\system32\mukmil.dll
HKLM-Run-TPPOLL - c:\program files\Topro\tppoll.exe


.
——- Supplementary Scan ——-
.
Trusted Zone: gomyhit.com
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
FF - ProfilePath -
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-03 12:44
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …


c:\windows\system32\463a776efd4bb7471e1772fb6603dc0c.sys 39936 bytes executable
c:\windows\system32\_463a776efd4bb7471e1772fb6603dc0c.sys_.vir 39936 bytes executable

scan completed successfully
hidden files: 2

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(304)
c:\windows\system32\Ati2evxx.dll
.
———————— Other Running Processes ————————
.
c:\program files\Lavasoft\Ad-Aware 2007\aawservice.exe
.
**************************************************************************
.
Completion time: 2009-05-03 12:47 - machine was rebooted
ComboFix-quarantined-files.txt 2009-05-03 16:47

Pre-Run: 73,768,165,376 bytes free
Post-Run: 74,513,788,928 bytes free

Current=3 Default=3 Failed=1 LastKnownGood=4 Sets=1,2,3,4
174 — E O F — 2009-03-15 07:02
Hi,

Can you now boot into normal mode?

Please do the following:

Please download Malwarebytes' Anti-Malware
  • Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT


Go to Kaspersky website and perform an online antivirus scan.
  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button. Then post it here.

In your next reply please include
  • MBAM Log
  • Kaspersky report
Please describe in detail what happens when you try and boot into normal mode try and copy down any error messages that you receive.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI