This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] these just keep coming back

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

my hijackthis log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:10:51 AM, on 06/09/2009
Platform: Unknown Windows (WinNT 6.01.3164)
MSIE: Internet Explorer v8.00 (8.00.7260.0000)
Boot mode: Normal

Running processes:
A:\Windows\System32\smss.exe
A:\Windows\system32\csrss.exe
A:\Windows\system32\wininit.exe
A:\Windows\system32\csrss.exe
A:\Windows\system32\services.exe
A:\Windows\system32\lsass.exe
A:\Windows\system32\lsm.exe
A:\Windows\system32\svchost.exe
A:\Windows\system32\nvvsvc.exe
A:\Windows\system32\svchost.exe
A:\Windows\system32\winlogon.exe
A:\Windows\System32\svchost.exe
A:\Windows\System32\svchost.exe
A:\Windows\system32\svchost.exe
A:\Windows\system32\svchost.exe
A:\Windows\system32\WUDFHost.exe
A:\Windows\system32\Dwm.exe
A:\Windows\Explorer.EXE
A:\Windows\system32\svchost.exe
A:\Windows\system32\taskhost.exe
A:\Windows\system32\svchost.exe
A:\Windows\system32\svchost.exe
A:\Program Files\Google\Update\1.2.183.7\GoogleCrashHandler.exe
A:\Windows\system32\svchost.exe
A:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
A:\Windows\system32\svchost.exe
A:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
A:\Windows\System32\StikyNot.exe
A:\Windows\system32\SearchIndexer.exe
A:\Program Files\Windows Media Player\wmpnetwk.exe
A:\Windows\System32\svchost.exe
A:\Windows\system32\svchost.exe
A:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
A:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
A:\Windows\system32\sppsvc.exe
A:\Windows\system32\WUDFHost.exe
A:\Program Files\Internet Download Manager\IDMan.exe
A:\Windows\system32\SearchProtocolHost.exe
A:\Program Files\Mozilla Firefox\firefox.exe
A:\Windows\system32\taskhost.exe
A:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
A:\Windows\system32\SearchFilterHost.exe
A:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - A:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - A:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - A:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [VirtualCloneDrive] "A:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "A:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [RESTART_STICKY_NOTES] A:\Windows\System32\StikyNot.exe
O4 - HKUS\S-1-5-21-899037044-396731412-349137126-1001\..\Run: [RESTART_STICKY_NOTES] A:\Windows\System32\StikyNot.exe (User '?')
O8 - Extra context menu item: Download all links with IDM - A:\Program Files\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: Download FLV video content with IDM - A:\Program Files\Internet Download Manager\IEGetVL.htm
O8 - Extra context menu item: Download with IDM - A:\Program Files\Internet Download Manager\IEExt.htm
O13 - Gopher Prefix:
O16 - DPF: {2A0B9B82-D5C8-4D3D-8338-AD55B23662B1} (F5 Networks CacheCleaner) - https://employees.cpr.ca/vdesk/cachecleaner…,2008,0212,2003
O16 - DPF: {45B69029-F3AB-4204-92DE-D5140C3E8E74} (F5 Networks Auto Update) - https://employees.cpr.ca/vdesk/terminal/InstallerControl.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} (get_atlcom Class) - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O20 - Winlogon Notify: !SASWinLogon - A:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O22 - SharedTaskScheduler: Windows DreamScene - {E31004D1-A431-41B8-826F-E902F9D95C81} - A:\Windows\System32\DreamScene.dll
O23 - Service: Google Update Service (gupdate1ca16133877e5) (gupdate1ca16133877e5) - Google Inc. - A:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: MBAMService - Malwarebytes Corporation - A:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - A:\Windows\system32\nvvsvc.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - A:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: sofatnet Service (sofatnet) - Unknown owner - A:\Windows\system32\sofatnet.exe (file missing)
O23 - Service: @%SystemRoot%\System32\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software - A:\Windows\System32\TuneUpDefragService.exe
O23 - Service: @%SystemRoot%\System32\TUProgSt.exe,-1 (TuneUp.ProgramStatisticsSvc) - TuneUp Software - A:\Windows\System32\TUProgSt.exe




I've removed those files I mentioned in the description multiple times with Malwarebytes,Superantispyware and TrojanRemover,but they keep coming back.Makes my Firefox hang-up constantly,and my machine painfully slow at times.
Rootrepeal and dds aren't compatible with 7 unfortunately.Any help would be greatly appreciated.Thanks in advance.

I know nobody has asked for this,but this is an example of my Malwarebytes scan that I keep deleting,but they just keep comin' back:


Malwarebytes' Anti-Malware 1.40
Database version: 2720
Windows 6.1.7260

30/08/2009 22:47:48
mbam-log-2009-08-30 (22-47-48).txt

Scan type: Quick Scan
Objects scanned: 86477
Time elapsed: 3 minute(s), 44 second(s)

Memory Processes Infected: 1
Memory Modules Infected: 1
Registry Keys Infected: 7
Registry Values Infected: 11
Registry Data Items Infected: 0
Folders Infected: 1
Files Infected: 6

Memory Processes Infected:
A:\Windows\System32\sofatnet.exe (Backdoor.Bot) -> Unloaded process successfully.

Memory Modules Infected:
a:\Windows\System32\evdoserver.dll (Trojan.Agent) -> Delete on reboot.

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\evdoserver (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\evdoserver (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\evdoserver (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sofatnet (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sofatnet (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sofatnet (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Protection System (Rogue.ProtectionSystem) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\BuildW (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\FirstInstallFlag (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\guid (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\i (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\mEv (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\mso (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\udso (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\uid (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Ulrn (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Update (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\UpdateNew (Malware.Trace) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
A:\Program Files\Protection System (Rogue.ProtectionSystem) -> Quarantined and deleted successfully.

Files Infected:
a:\Windows\System32\evdoserver.dll (Trojan.Agent) -> Delete on reboot.
A:\Windows\System32\dvdpaly.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
A:\Windows\System32\wiwow64.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
A:\Windows\System32\FInstall.sys (Backdoor.Bot) -> Quarantined and deleted successfully.
A:\Windows\System32\sofatnet.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
A:\Windows\sc.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
Your post has been Moved, Closed or Edited for one of the following reasons:

1.) You posted multiple topics and only one is required

2.) You are spamming links to other places without approval

3.) Abusive language or other problems in your text

4.) Your topic is too old (20 days or more) and no replies from you after a volunteer tried to help you

This is a family oriented forum to help those that need help.

==============================

Posted at BC:
http://www.bleepingcomputer.com/forums/topic255770.html

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI