This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Trojans, Malware, and who knows what else.

45 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I was browsing the web yesterday, and Avast! popped up and alerted me to a Trojan on a MediaFire link I clicked on to download something from a very trusted, well-known Sims 2 content creator. I immediately aborted connection via Avast!'s popup and canceled the download without another thought.

Later that night, while browsing, Spybot gave me a warning that "a.exe" was trying to edit my registry from the TEMP folder, to stick "Virtumond.sci" (I think was the spelling). I didn't like that thought and immediately stopped everything I was doing, closed my browser, and ran a Spybot scan. While that was running, I went and emptied my prefetch, as one of the entries included the prefix "a.exe", and I didn't trust it, even though Spybot had supposedly deleted the file.

Spybot turned back, even with supposedly killing the connection, two items it listed as HiJackers, one of which I remember was a registry key. I had it kill them, and immunized afterwards. I wasn't too sure of the entire thing, and even though it was getting late, I ran a SUPERAntiSpyware full scan, and it too turned back files; eight of them. They were as follows:

Malware.Trace
Trojan.Agent/Gen-Fuffan
Trojan.SVCHost/Fake

Some of them were in the registry, some of them were elsewhere. I immediately told them to remove them, and was told it needed to restart. EDIT: I forgot to mention that the files found by SUPER are still in its quarantine. I did so, and as the computer restarted, the Recovery Console "what would you like to start?" screen appeared as usual, but instead of having THREE second timer, it had a THIRTY second timer. I'm hoping, praying, this is because I emptied the prefetch.

Once Windows restarted, a Spybot scan immediately started without any prompting from me. I'm assuming, hoping, and praying here as well that this too is because I emptied the prefetch. I wound up falling asleep on the scan, which took well over 3 hours to complete, but woke periodically to see what it was doing. It turned back a clean scan. By this time it was near 4am, and I shut everything down for the evening.

This morning, I turned the computer on to post here, and the same thirty second countdown was on the Recovery Console, but Spybot didn't run on startup.

Below is my HiJackThis log, run as soon as I got it downloaded this morning after startup. I'm running Windows XP, with the latest Service Pack (which I believe is now SP3), with Spybot, SUPERAntispyware Free, MalwareBytes Free, and Avast! Free installed, if that helps:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:41:59 AM, on 10/28/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\DOCUME~1\Family\LOCALS~1\Temp\dwm.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\PROGRA~1\LAUNCH~1\LManager.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Nero\Nero8\InCD\NBHGui.exe
C:\Program Files\Nero\Nero8\InCD\InCD.exe
C:\Program Files\Prolific\EZ-DUB Finder\OneBtn.exe
C:\WINDOWS\WebCam\M3000\M3000Mnt.exe
C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe
C:\Program Files\Canon\MyPrinter\BJMyPrt.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
C:\Program Files\Nero\Nero8\InCD\InCDsrv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\igfxext.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Linksys\Linksys Updater\bin\LinksysUpdater.exe
C:\Program Files\Nero\Nero8\InCD\NBHRegInCDSrv.exe
C:\WINDOWS\system32\java.exe
C:\WINDOWS\system32\IoctlSvc.exe
C:\Program Files\Acer\Acer VCM\RS_Service.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
C:\Program Files\Linksys\Linksys EasyLink Advisor\Linksys EasyLink Advisor.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Carbonite\CarbonitePreinstaller.exe
C:\Documents and Settings\Family\Desktop\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/accounts/ServiceLogi…mp;ltmplcache=2
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:50370
F3 - REG:win.ini: load=C:\DOCUME~1\Family\LOCALS~1\Temp\dwm.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5612.1312\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [AzMixerSel] C:\Program Files\Realtek\Audio\Drivers\AzMixerSel.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\LManager.exe
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [CarboniteSetupLite] "C:\Program Files\Carbonite\CarbonitePreinstaller.exe" /preinstalled
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [M3000Mnt] Rundll32.exe M3000Rmv.dll ,WinMainRmv /StartStillMnt
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [SecurDisc] C:\Program Files\Nero\Nero8\InCD\NBHGui.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Nero\Nero8\InCD\InCD.exe
O4 - HKLM\..\Run: [Prolific2571_OneButton] C:\Program Files\Prolific\EZ-DUB Finder\OneBtn.exe
O4 - HKLM\..\Run: [nmctxth] "C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe"
O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Family\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - Global Startup: Acer VCM.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {BF985246-09BF-11D2-BE62-006097DF57F6} (SimCityX Control) - http://simcity.ea.com/play/classic/SimCityX.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} -
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Acer\Acer VCM\Skype4COM.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: McAfee Application Installer Cleanup (0046591276984199) (0046591276984199mcinstcleanup) - Unknown owner - C:\DOCUME~1\Family\LOCALS~1\Temp\004659~1.EXE (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Google Desktop Manager 5.9.911.3589 (GoogleDesktopManager-110309-193829) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: PIXMA Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Nero\Nero8\InCD\InCDsrv.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Linksys Updater (LinksysUpdater) - Unknown owner - C:\Program Files\Linksys\Linksys Updater\bin\LinksysUpdater.exe
O23 - Service: Nero Registry InCD Service (NeroRegInCDSrv) - Nero AG - C:\Program Files\Nero\Nero8\InCD\NBHRegInCDSrv.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: Pure Networks Platform Service (nmservice) - Cisco Systems, Inc. - C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing)
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
O23 - Service: Raw Socket Service (RS_Service) - Acer Incorporated - C:\Program Files\Acer\Acer VCM\RS_Service.exe

–
End of file - 12411 bytes
Hello mediaklepto and welcome to the WTT forum.

My name is Satchfan and I would be glad to help you with your computer problem. Please read the following guidelines which will help to make cleaning your machine easier:
• Please do not install/uninstall any programs unless asked to.
• Please do not run any scans other than those requested
• Please follow all instructions in the order posted
• Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
• If you don't understand something, please don't hesitate to ask for clarification before proceeding
• The fixes are specific to your problem and should only be used for this issue on this machine.
• Please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!
Please note that I am still in training and my replies need to be checked by an expert in order for you to receive the best possible advice. This may result in a small delay between my posts but I shall try to keep this to a minimum.

I am looking through your log now and will reply as soon as possible.

Satchfan
Hello again mediaklepto

Thanks for the detailed explanation. You do have some remaining infections so we’ll need to run some tools that will look deeper to see what else may be about.


Disable Spybot - Search and Destroy TeaTimer

You have Spybot’s TeaTimer running on your computer. This can interfere when trying to clean up your computer so please temporarily disable it.

Right click the running icon on the taskbar at the bottom right of your screen and click Resident Protection to remove the check mark. You can re-enable it by doing the same again.


Remove any remnants of McAfee

You appear to have previously used McAfee. You can run this removal tool from McAfee that will remove all remnants of that program

http://majorgeeks.com/McAfee_Consumer_Prod…Tool_d5420.html


OTL Custom Scan

Download OTL to your Desktop
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Click on Minimal Output at the top
  • Download the following file scan.txt to your Desktop. Click here to download it. You may need to right click on it and select "Save"
  • Double click inside the Custom Scan box at the bottom
  • A window will appear saying "Click OK to load a custom scan from a file or Cancel to cancel"
  • Click the OK button and navigate to the file scan.txt which we just saved to your desktop
  • Select scan.txt and click Open. Writing will now appear under the Custom Scan box
  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan won’t take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time and post them in your topic.

Please download DeFogger to your desktop.

Double click DeFogger to run the tool.
  • The application window will appear
  • Click the Disable button to disable your CD Emulation drivers
  • Click Yes to continue
  • A 'Finished!' message will appear
  • Click OK
  • DeFogger will now ask to reboot the machine - click OK
IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_disable which will appear on your desktop.

Do not re-enable these drivers until otherwise instructed.


Download the GMER Rootkit Scanner

[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • All drives/partitions except C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


Logs to include with next post:

OTL.txt
Extras.txt
Gmer.txt


Thanks

Satchfan
Thanks for your suggestions, but we appear to have a major problem at the moment. While running the remover for McAfee (which yes, we did use in the past), I was bombarded with warnings from Avast! telling me that "DWM.exe" in the Local~1/TEMP folder was apparently attempting to run, and was trying to install "Win32:FakeAlert-RO [TRJ]". It gave me the option to ignore it, delete the file, or put it in the chest. I told it to put it in the chest, but directly behind that warning was a duplicate warning. I told it again to move it to the chest, and it said that it was unable to find the file (I assume because it was already in the chest). I told it then to delete it, and to do so on startup if necessary. When it restarted after the McAfee removal, it again informed me that the file was nowhere to be found. I connected to the internet to download the next program you asked me to run, and was told that the proxy was refusing connection (on Firefox), and that the page couldn't be displayed (on Chrome). I disconnected and connected again, to the same result. Apparently, the computer is now dead in the water, as the internet is no longer functioning. Right now, we're attempting to find out if the computer is covered under warranty, to see if we can simply return the jumbled mess and have it scrapped, and get a new one. However, I have a very deep concern that as the other two computers (this one and the desktop) which use the same router to connect could be in danger of the virus transmitting via the internet. File sharing is turned completely off on both this machine and the desktop. Is there anything I can do to be sure there's nothing hiding in the temp files that may run and cause mischief? This computer is identical to the one we were attempting to work on, and the other is a Vista machine. Can you recommend any way to ensure their safety?
mediaklepto

If the other computers can access the Internet it’s unlikely that they have been infected.

These infections can quite likely be cleared up so please be patient while we get this cleaned up.

Restore Windows XP to a previous state

Let’s see if restoring the system to an earlierstate helps. • Log on to Windows as an administrator.
• Click Start, All Programs, Accessories, System Tools and then click System Restore.
• On the “Welcome to System Restore” page, click to select the Restore my computer to an earlier time option, and then click Next.
• On the “Select a Restore Point" page, click the most recent system restore point when you believe your system was working OK and then click Next.
Note A System Restore message may appear that lists configuration changes that System Restore will make. Click OK.
• On the “Confirm Restore Point Selection” page, click Next. System Restore restores the previous Windows XP configuration, and then restarts the computer.
• Log on to the computer as an Administrator. Then click OK on the System Restore “Restoration Complete” page.
If this allows you to connect to the Internet, please follow the previous instructions.

If not, it’s not a major problem so don’t worry, just let me know and I’ll send new instructions.

Satchfan
Thanks for replying again, satchfan. I have a couple of questions before I try restoring the system, if you wouldn't mind. Firstly, I'm not sure how to log on as an administrator, or if I need to. The only user on the computer (which does not require a password) is the one we always use - named "Family". Is this administrator, or is there some other way to log on as such? Secondly, should I attempt to restore the system to a time before the infection first seemed to show itself, or just to a time before the computer was unable to navigate the internet? And lastly, if I can in fact restore to a previous point that allows me to access the internet, should I once again run the McAfee removal tool? Thanks, and sorry for the abundant questions!
Mediaklepto

sorry for the abundant questions!

Any amount of questions is not a problem – it’s always best to ask if you are unsure.

I'm not sure how to log on as an administrator, or if I need to. The only user on the computer (which does not require a password) is the one we always use - named "Family". Is this administrator, or is there some other way to log on as such?

Having no password and being the only “user” does not mean that you are definitely logged on as administrator. Some computer manufacturers make themselves the admin which has to be changed.

The best way to check is to do the following:• click on Start, Settings, Control Panel
• double-click on User Accounts
Below your user name, you should see either Limited account or Computer administrator. If your account is a limited account, you cannot install software or change certain computer settings. If you are named as Administrator, that’s fine and you can proceed.

If you are not, click Start, and then click Log Off. When prompted, click Switch User. If you are not the administrator there will be an option to log on as Administrator. Click on that option to log in, (you shouldn’t need a password as none was set)

should I attempt to restore the system to a time before the infection first seemed to show itself, or just to a time before the computer was unable to navigate the internet?

If there is a time prior to infection that’s fine, if not, just choose a time before the computer was unable to navigate the internet

if I can in fact restore to a previous point that allows me to access the internet, should I once again run the McAfee removal tool?

No, I should leave that for now – we can deal with it later.

Satchfan
Thanks for getting back to me, satchfan; I really appreciate the help. I'm getting ready to start the attempt at system restoring as you suggested. I just wanted to drop a line and apologize for not getting back to you yesterday. Between the weekend and the "holiday" with Halloween, I was fairly busy and didn't have time to sit and go over the computer. I was wondering though if you can answer a question for me. When the SpyBot warning showed up mentioning Virtumond, I had two different sites open. DeviantArt, ModTheSims, and Meebo. I've never before had an issue with ModTheSims or Meebo, but DeviantArt is known to have quite a few nasties squirreling around in their ads. I was, at the time, logged in to all three sites, but was deleting messages actively on DA, while receiving IMs from very trusted friends on Meebo, and leaving MTS to sit in another tab. My question is, is it possible that this infection came from somewhere ELSE, as it alerted me to files in the TEMP folder, or was it most likely caused by sometime I was doing at the time - meaning more than likely one of those three sites? The reason I ask is that I had gotten that warning from that Mediafire download earlier that day, and had been looking for images on various sites using Google image search, and would like to do my best to stay away from whatever caused this initially (though I have resolved to never return to DeviantArt again). Thank you again, and once more, sorry for the questions!
mediaklepto

No problem about the reply time as long as you don't leave it more than 3 days without informing us of any problems.


McAfee recently tested the site and found no significant problems – see http://www.siteadvisor.com/sites/deviantart.com/summa

However, I have read that DeviantArt, although a legitimate site, was being targeted and had caused problems recently, so really it’s up to you. I would advise you not to use any sites that you are unsure of while we are cleaning your computer.

Please follow the previous instructions.

Thanks

Satchfan
Thanks again, satchfan, for replying! I've had numerous warnings thrown at me for trojans while browsing DeviantArt, and have had quite a few people inform me of the same kind of issues. Better safe than sorry, I say! I've been busy most of the day since attempting to use the system restore as you suggested, so I'm late replying once again. I did determine that the user we use is in fact the computer administrator, but upon clicking system restore, I received a notice informing me that system restore had been turned off. This, in fact, should be untrue, as per the result of another post I made here a few months ago regarding a possible infection. I wasn't sure if I should attempt to turn it on as it asked if it should, so I selected not to and shut the computer back down. Do you have any other suggestions that may help, or any information on what I should do with the system restore?
mediaklepto

You could try saying “Yes” when asked about turning system restore on but it may still not allow you to.

We’ll try a couple more things to get your computer running and Internet restored

First
• restart your computer and hit the F8 key constantly until a menu shows up
• use the arrow keys to navigate to Last known good configuration
• press Enter
If this has worked and you can access the Internet, please run the programs I previously requested. If you are still unable to access the Internet do the following:


Reset Proxy settings

Firefox Proxy settings: • Open Firefox, click Tools > Options > Advanced and click the Network Tab.
• Under the Connection section click on the Settings button.
• Under Configure Proxies to Access the Internet, check No proxy. This is the default option if you don't use a proxy.
• Click OK then click OK again.
• Close Firefox and -restart- the computer.
Internet Explorer Proxy settings: • Open Internet Explorer > click Tools > Internet Options > Connections tab.
• Click the LAN Settings… button and uncheck "Use a proxy server for your LAN"
or change the settings to the proxy you normally use if you previously reconfigured it.
• Remove any unknown addresses from the Address box - 80 is the default Port so it does not have to be changed.
• Click OK… then click OK again.
• Close Internet Explorer and -restart- the computer.
If you are still having Internet problems, please let me know if you have access to a memory stick or some other method of saving files and transferring them to the infected computer.

Satchfan
Thanks for your continued suggestions, satchfan. Changing the proxy settings via the browser successfully allowed us to get back online on the other computer. Trying the last known good configuration didn't help, just for the record. I've downloaded the tools onto that computer, but as it is rather late, I'll pick up and begin scanning at some point hopefully before noon tomorrow. Thanks again!
Thanks again for your ongoing support, satchfan. It's much appreciated. At the moment though, I have a couple of things that require your opinion/assistance. As I said in my previous post, we were able to download the tools you requested we run. This morning, when we were getting ready to run OTL, my husband ran ATF Cleaner just after startup (as we always do just before shutdown and just after startup), not knowing that I was avoiding doing so until after the computer had been cleared. I greatly, sincerely apologize if this causes any issues in your examination of the system. I'm having an issue with OTL, I believe of my own doing. As I was scrolling back over after checking "minimal output" on OTL before inputting the scan.txt file, the track pad on the laptop stuck and clicked quick scan. I have since dug out and attached a USB mouse to remedy any further such mis-click issues, however, after completion of the quick scan without scan.txt input, OTL created an OTL.txt and an Extras.txt on the desktop. As this was not the correct scan as you requested it, I deleted the two files, closed and reopened OTL, and attached scan.txt. After it finished this quick scan, it created and opened only OTL.txt. I attempted a few more times, after restarting the computer, and after deleting OTL from the desktop and re-downloading, to gather BOTH .txt files, but have only been given OTL.txt. I'm truly very sorry for making this even more complicated, but is there anything I can do to get both of the txt files before moving on?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI