This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Computer Being taken over by a software called AntiMalware

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

When my computer turns on it takes a longer time than usual. All the time I will get pop ups to buy spyware software and every few minutes AntiMalware (symbol is a shield like its supposed to be on your computer) will tell me there are many defects in my computer and also if I unistall it, it repetitively installs itself. I tried running programs such as HijackThis logs, spyware doctor, and malware bytes. Such programs will not let me hit the scan button for god who knows, or the program will not even open up. I would have posted a Hijack this log but my PC will not allow me to download it. I'm not sure if it is from the program that keeps installing itself(AntiMalware)? Thank you for your help!!! -Ryan
[external image: Posted Image]

DO NOT use any TOOLS such as Combofix, SmitfraudFix, Vundofix, or HijackThis fixes without supervision.

Doing so could make your pc inoperatible and could require a full reinstall of your OS, losing all your programs and data.


Stay with this topic until I give you the final 'All clean' post.


Vista users:
1. These tools MUST be run from the executable. (.exe)
2. With Admin Rights (Right click, choose "Run as Administrator") every time you run them



1) exeHelper
Please download exeHelper to your desktop.
Double-click on exeHelper.com to run the fix.
A black window should pop up, press any key to close once the fix is completed.
Post the contents of log.txt (Will be created in the directory where you ran exeHelper.com)
Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).
Here is the exehelperlog text… exeHelper by Raktor Build 20091204 Run at 19:53:58 on 12/11/09 Now searching… Checking for numerical processes… Checking for sysguard processes… Checking for bad processes… Killed process antimalware.exe Killed process wscsvc32.exe Checking for bad files… Deleting file C:\Program Files\AntiMalware\antimalware.exe Checking for bad registry entries… Removing HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\AntiMalware Resetting filetype association for .exe Resetting filetype association for .com Resetting userinit and shell values… Resetting policies… –Finished– exeHelper by Raktor Build 20091204 Run at 19:55:26 on 12/11/09 Now searching… Checking for numerical processes… Checking for sysguard processes… Checking for bad processes… Killed process wscsvc32.exe Checking for bad files… Checking for bad registry entries… Resetting filetype association for .exe Resetting filetype association for .com Resetting userinit and shell values… Resetting policies… –Finished– Thanks for your help! -Ryan
Malwarebytes antimalware will not open. I keep getting pop ups saying malware antimalware bytes is a threat to my computer and to remove it in order for AntiMalware to full work. As I'm typing this a "Security center alert popped up saying there is a virus. But ive never seen this type of alert before and AntiMalware keeps popping up in the corner saying I have an attack from an IP address. Like I said before if I uninstall AntiMalware, it installs itself again. Thanks -Ryan
Sorry, I didn't complete it right the first time. I didn't run MBAB with administer. I just tried and it says I need a password which I have no idea what that is. Thanks -Ryan
Download Combofix from any of the links below but rename it to ABCD.exe before saving it to your desktop.

* IMPORTANT !!! Save ABCD.exe (ComboFix) to your Desktop

Link 1
Link 2


Double click on the ABCD.exe ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt so we can continue cleaning the system.
Here is the text for ComboFix…

ComboFix 09-12-11.05 - Ryan B 12/12/2009 14:17:28.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.894.637 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\AB.exe.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\docume~1\RYANB~1\LOCALS~1\Temp\wscsvc32.exe
c:\documents and settings\All Users\Desktop\AntiMalware Support.lnk
c:\documents and settings\All Users\Desktop\AntiMalware.lnk
c:\documents and settings\All Users\Start Menu\Programs\AntiMalware
c:\documents and settings\All Users\Start Menu\Programs\AntiMalware\AntiMalware Support.lnk
c:\documents and settings\All Users\Start Menu\Programs\AntiMalware\AntiMalware.lnk
c:\documents and settings\All Users\Start Menu\Programs\AntiMalware\Uninstall AntiMalware.lnk
c:\windows\system32\drivers\H8SRTrhqaqpulba.sys
c:\windows\system32\H8SRTrumqsntsmr.dll
c:\windows\system32\H8SRTsmkxypupfw.dll
c:\windows\system32\H8SRTsqxgrdhpbw.dat
c:\windows\system32\srcr.dat
c:\windows\system32\st325602.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_H8SRTd.sys
——-\Legacy_H8SRTd.sys


((((((((((((((((((((((((( Files Created from 2009-11-12 to 2009-12-12 )))))))))))))))))))))))))))))))
.

2009-12-10 18:13 . 2009-10-30 16:11 233136 —-a-w- c:\windows\system32\drivers\pctgntdi.sys
2009-12-10 18:13 . 2009-11-09 16:20 207792 —-a-w- c:\windows\system32\drivers\PCTCore.sys
2009-12-10 18:13 . 2009-10-06 21:31 87784 —-a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2009-12-10 18:12 . 2009-09-03 14:45 70408 —-a-w- c:\windows\system32\drivers\pctplsg.sys
2009-12-10 18:12 . 2009-12-10 18:13 ——– d—–w- c:\program files\Spyware Doctor
2009-12-10 18:12 . 2009-12-10 18:13 ——– d—–w- c:\program files\Common Files\PC Tools
2009-12-10 18:12 . 2009-12-10 18:12 ——– d—–w- c:\documents and settings\Ryan B\Application Data\PC Tools
2009-12-10 18:12 . 2009-12-10 18:12 ——– d—–w- c:\documents and settings\All Users\Application Data\PC Tools
2009-12-10 18:12 . 2009-12-12 19:02 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-12-04 04:10 . 2009-12-04 04:10 ——– d—–w- c:\documents and settings\Visitor\Local Settings\Application Data\Mozilla
2009-12-03 01:48 . 2009-12-03 01:48 ——– d—–w- c:\documents and settings\Default User\Local Settings\Application Data\Microsoft Help
2009-12-02 23:17 . 2009-06-21 21:44 153088 -c—-w- c:\windows\system32\dllcache\triedit.dll
2009-12-02 23:06 . 2009-08-07 00:23 274288 —-a-w- c:\windows\system32\mucltui.dll
2009-12-02 23:06 . 2009-08-07 00:23 215920 —-a-w- c:\windows\system32\muweb.dll
2009-11-23 05:09 . 2009-12-08 14:35 ——– d—–w- c:\documents and settings\Ryan B\Local Settings\Application Data\Yahoo
2009-11-23 05:06 . 2009-11-23 05:06 ——– d—–w- c:\documents and settings\Ryan B\Local Settings\Application Data\Yahoo!
2009-11-23 05:06 . 2009-12-08 14:36 ——– d—–w- c:\documents and settings\All Users\Application Data\Yahoo! Companion
2009-11-23 05:06 . 2009-11-23 05:09 ——– d—–w- c:\documents and settings\Ryan B\Application Data\Yahoo!
2009-11-23 05:05 . 2009-11-23 05:06 ——– d—–w- c:\documents and settings\All Users\Application Data\Yahoo!
2009-11-23 05:05 . 2009-11-10 19:39 607472 —-a-w- c:\documents and settings\All Users\Application Data\Yahoo!\YUpdater\yupdater.exe
2009-11-23 05:04 . 2009-11-23 05:06 ——– d—–w- c:\program files\Yahoo!
2009-11-17 04:29 . 2009-11-17 04:29 ——– d—–w- c:\documents and settings\Visitor\Local Settings\Application Data\Apple Computer

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-12 02:44 . 2009-09-13 02:09 ——– d—–w- c:\documents and settings\Ryan B\Application Data\FrostWire
2009-12-10 04:53 . 2009-08-27 00:22 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-12-07 23:06 . 2009-09-19 00:13 664 —-a-w- c:\windows\system32\d3d9caps.dat
2009-10-29 07:46 . 2006-03-04 03:33 832512 —-a-w- c:\windows\system32\wininet.dll
2009-10-29 07:46 . 2004-08-04 10:00 78336 —-a-w- c:\windows\system32\ieencode.dll
2009-10-29 07:46 . 2004-08-04 10:00 17408 —-a-w- c:\windows\system32\corpol.dll
2009-10-21 05:38 . 2004-08-04 10:00 75776 —-a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:38 . 2004-08-04 10:00 25088 —-a-w- c:\windows\system32\httpapi.dll
2009-10-20 16:20 . 2004-08-04 10:00 265728 —-a-w- c:\windows\system32\drivers\http.sys
2009-10-13 10:30 . 2004-08-04 10:00 270336 —-a-w- c:\windows\system32\oakley.dll
2009-10-12 13:38 . 2004-08-04 10:00 149504 —-a-w- c:\windows\system32\rastls.dll
2009-10-12 13:38 . 2004-08-04 10:00 79872 —-a-w- c:\windows\system32\raschap.dll
2009-10-11 16:51 . 2009-10-11 16:51 126970 —-a-w- c:\documents and settings\Ryan B\Application Data\Move Networks\uninstall.exe
2009-10-11 16:51 . 2009-08-03 21:48 4187512 —-a-w- c:\documents and settings\Ryan B\Application Data\Move Networks\plugins\npqmp071505000010.dll
2009-09-14 18:10 . 2009-09-14 18:10 0 —-a-w- c:\documents and settings\Ryan B\Application Data\FrostWire\.NetworkShare\Incomplete\T-4506256-LimeWireWin4.16.6.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"Aim6"="c:\program files\AIM6\aim6.exe" [2009-07-09 49968]
"Messenger (Yahoo!)"="c:\progra~1\Yahoo!\Messenger\YahooMessenger.exe" [2009-11-10 5244216]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-12-10 49152]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-09-08 122940]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 81920]
"SigmatelSysTrayApp"="c:\program files\SigmaTel\C-Major Audio\WDM\stsystra.exe" [2007-05-10 405504]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-08 761947]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2007-03-16 1392640]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-05 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-09-09 305440]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-09-13 149280]
"ISTray"="c:\program files\Spyware Doctor\pctsTray.exe" [2009-11-18 1243088]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-4-23 29696]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\FrostWire\\FrostWire.exe"=
"c:\\WINDOWS\\system32\\java.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=

R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [12/10/2009 1:13 PM 207792]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [8/24/2009 10:11 PM 24652]
S3 ADM8511;ADMtek ADM8511/AN986 USB To Fast Ethernet Converter;c:\windows\system32\drivers\ADM8511.SYS [8/24/2009 12:27 PM 20160]
.
——- Supplementary Scan ——-
.
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Ryan B\Application Data\Mozilla\Firefox\Profiles\gsusvlym.default\
FF - plugin: c:\documents and settings\Ryan B\Application Data\Move Networks\plugins\npqmp071505000010.dll
FF - plugin: c:\documents and settings\Ryan B\Local Settings\Application Data\Yahoo!\BrowserPlus\2.4.17\Plugins\npybrowserplus_2.4.17.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX POLICIES —-
FF - user.js: yahoo.ytff.general.dontshowhpoffer - truec:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-AntiMalware - c:\program files\AntiMalware\antimalware.exe
AddRemove-360Share Pro - c:\program files\360Share Pro\bt-uninst.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-12-12 14:23
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(852)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2009-12-12 14:24:59
ComboFix-quarantined-files.txt 2009-12-12 19:24

Pre-Run: 104,526,307,328 bytes free
Post-Run: 105,771,319,296 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect /usepmtimer

- - End Of File - - 686DA2ECDCA38A78D62593B5882EDAA1




Thanks.
-Ryan
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI