This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

"XP Antispyware 2012" with WinXP Pro SP3 [Solved]

19 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi shadow5,

When replying are you clicking Fast Reply or Add reply? The browse button is not availallble when you use Fast Reply. It's ok to copy and paste the logs. I perfer it that way as it's easier to work with the log. There are some logs that need to be attached. I'll let you know which ones.

Do you still use Norton (Symantec)?

That's a rather short aswMBR log. Is that all that is to it? There is quite a bit of it missing. Please run aswMBR again. When it's finished there should also be a log named mbr.dat on your desktop. I need you to zip it and attach it along with the mbr.txt.

Hi shadow5,

When replying are you clicking Fast Reply or Add reply? The browse button is not availallble when you use Fast Reply. It's ok to copy and paste the logs. I perfer it that way as it's easier to work with the log. There are some logs that need to be attached. I'll let you know which ones.

Do you still use Norton (Symantec)?

That's a rather short aswMBR log. Is that all that is to it? There is quite a bit of it missing. Please run aswMBR again. When it's finished there should also be a log named mbr.dat on your desktop. I need you to zip it and attach it along with the mbr.txt.



I do not use Norton–use AVG FREE.

aswMBR.txt follows:

aswMBR version 0.9.9.1297 Copyright© 2011 AVAST Software
Run date: 2012-01-19 02:19:07
—————————–
02:19:07.468 OS Version: Windows 5.1.2600 Service Pack 3
02:19:07.468 Number of processors: 2 586 0x1706
02:19:07.468 ComputerName: USER-A6AA68022B UserName: USER
02:19:41.046 Initialize success
02:19:59.640 AVAST engine defs: 12011801
02:21:04.125 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-16
02:21:04.125 Disk 0 Vendor: WDC_WD2500JS-00NCB1 10.02E01 Size: 238474MB BusType: 3
02:21:04.156 Disk 0 MBR read successfully
02:21:04.156 Disk 0 MBR scan
02:21:04.328 Disk 0 Windows XP default MBR code
02:21:04.343 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 238472 MB offset 63
02:21:04.375 Disk 0 scanning sectors +488392065
02:21:04.468 Disk 0 scanning C:\WINDOWS\system32\drivers
02:21:27.750 Service scanning
02:21:28.671 Modules scanning
02:21:43.062 Disk 0 trace - called modules:
02:21:43.078 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys PCIIDEX.SYS
02:21:43.078 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8afbdab8]
02:21:43.109 3 CLASSPNP.SYS[b80e8fd7] -> nt!IofCallDriver -> \Device\00000069[0x8af58f18]
02:21:43.109 5 ACPI.sys[b7f7f620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP2T0L0-16[0x8afe8d98]
02:21:43.859 AVAST engine scan C:\WINDOWS
02:22:13.765 AVAST engine scan C:\WINDOWS\system32
02:24:54.734 AVAST engine scan C:\WINDOWS\system32\drivers
02:25:09.140 AVAST engine scan C:\Documents and Settings\USER
02:33:23.468 AVAST engine scan C:\Documents and Settings\All Users
02:35:12.046 Scan finished successfully
02:36:12.734 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\USER\Desktop\MBR.dat"
02:36:12.734 The log file has been saved successfully to "C:\Documents and Settings\USER\Desktop\aswMBR.txt"

Attachments:

Hi shadow5,

Open windows explorer (right click the Start button and click Explore)

At the top of windows explorer, click tools, folder options, click the
view tab
  • uncheck Display the contents of system folders
  • check Do not show hidden files and folders
  • check "Hide extensions for known file types" box
  • check "Hide protecting operating system files" box
Click apply, click ok

Any of your icons or shortcut go missing after doing the above?

Can you access your programs from start > All programs

Download and save to your desktop Malwarebytes Anti-Malware

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.

Hi shadow5,

Open windows explorer (right click the Start button and click Explore)

At the top of windows explorer, click tools, folder options, click the
view tab

  • uncheck Display the contents of system folders
  • check Do not show hidden files and folders
  • check "Hide extensions for known file types" box
  • check "Hide protecting operating system files" box
Click apply, click ok

Any of your icons or shortcut go missing after doing the above?

Can you access your programs from start > All programs

Download and save to your desktop Malwarebytes Anti-Malware

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.


-ALL ICONS/SHORTCUTS SEEM TO BE IN TACT
-can access programs from "start>All programs

First Log:
Malwarebytes' Anti-Malware 1.51.1.1800
www.malwarebytes.org

Database version: 7614

Windows 5.1.2600 Service Pack 3
Internet Explorer 7.0.5730.13

8/30/2011 5:00:04 PM
mbam-log-2011-08-30 (17-00-04).txt

Scan type: Quick scan
Objects scanned: 163005
Time elapsed: 2 minute(s), 50 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

Second Log:
Malwarebytes Anti-Malware 1.60.0.1800
www.malwarebytes.org

Database version: v2012.01.19.01

Windows XP Service Pack 3 x86 NTFS
Internet Explorer 7.0.5730.13
USER :: USER-A6AA68022B [administrator]

1/19/2012 3:59:53 AM
mbam-log-2012-01-19 (03-59-53).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 196142
Time elapsed: 3 minute(s), 56 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 2
C:\Documents and Settings\USER\Local Settings\Temp\oiu0.9914124389852991.exe (Rogue.Chameleon2012) -> Quarantined and deleted successfully.
C:\Documents and Settings\USER\Local Settings\Application Data\qkm.old (Rogue.Chameleon2012) -> Quarantined and deleted successfully.

(end)

All seems to be working correctly. The 2 'checked malware-files' are saved in the MBAM 'Quarantine" file.
Thx for the expertise, time, effort & esp. the patience you demonstrated! You are a credit to the world of personal computers and a gracious servant!
s
Hi shadow5,

Click your start button < Control Panel > Add/Remove programs and uninstall

LiveUpdate 2.6 (Symantec Corporation)



Your java is out of date. Click your start button, open Control panel.
  • Locate the Java icon (it looks like a coffee cup)
  • double click it to open it
  • click the Update tab
  • Click update now

After the java is updated, reboot your computer if not prompted to.

Next, Double click on OTL.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Services

:Commands
[emptytemp]

Then click the Run Fix button at the top
  • Let the program run unhindered

One more scan to check for stragglers

*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



Go here to run an online scannner from
ESET

(Note: You can use Internet Explorer or FireFox for this scan. If you use FireFox you will be asked to install an additional component. Please allow this.)

  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Disable your Antivirus software. You can usually do this with its Notfication Tray icon near the clock
  • Click Start
  • Make sure that the option "Remove found threats" is Unchecked, and the option "Scan unwanted applications" is Checked.
  • Click Scan.
  • Wait for the scan to finish.
  • When the scan completes, click List of found threats
  • click Export to Text file and save the file to your desktop using a unique name, such as ESETScan.
  • Include the contents of this report in your next reply

    Note - when ESET doesn't find any threats, no report will be created.
  • Push the back button.
  • Push Finish
  • Re-enable your Antivirus software.

Please post back with the ESET log if there is one.
Hello oldman960, the ESET found no threats! Thus, no log to post. Again I thank you. Is there an anti-virus program you prefer over AVGFree? Thanks for your personal preference. s
Hi shadow5,

I don't really have any preference. Personaly I use AVast. Many say it is lighter on resources than AVG.

From your desktop, please delete, if present
  • any notepads/logs that we created
  • aswMBR.exe
  • mbr.dat
  • mbr.zip



Next, Double click on OTL.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:services

:files
C:\Program Files\mozilla.org\Mozilla\plugins\npzango.dll

:Commands
[CLEARALLRESTOREPOINTS]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.
Please post the OTL fix log.


After you save the log:

Open OTL if it's still not open, then click the Clean Up button. You may get prompted by your firewall that OTL wants to contact the internet - allow this. A cleanup.txt will be downloaded, a message dialog will ask you if you want to proceed with the cleanup process, click Yes. This will do some clean up tasks and delete some of the tools you have downloaded plus itself.


I suggest you keep MBAM. Keep it updated and use it regularly.


Updates and upgrades

Adobe Reader

You have an older version of Adobe Reader. You can download the current version HERE

You may want to consider Foxit Reader instead. It may be a bit lighter on resources. If you choose to install Foxit decline the Foxit toolbar.

Visit their support forum
Foxit Forum

In either case you should uninstall Adobe Reader 9.3 first. Be sure to move any PDF documents to another folder first though.



Some Recommendations and prevention tips

Basic security consists of 1 antivirus program, 1 resident antispyware program, 1 on demand antispyware program and a firewall. Add a firewall you have.

* If you are behind a router Windows firewall should be fine. Otherwise a 3rd party firewall with outbound monitoring is recommended.

Click FIREWALL for links and tutorials to good, free and paid for firewalls. (Note: Zone Alarm is becoming bloatware)


You have SpywareBlaster

- SpywareBlaster will add a large list of programs and sites into your Internet Explorer
settings that will protect you from running and downloading known malicious programs.

OR

A guide to understanding and using the hosts file.

Learn how your Hosts file can protect you and how you can protect it.
Besides the Hosts file information, there are links to a very good updated hosts file, a host file manager. and some programs that can protect your hosts file.
HOSTS


Please read the info on disabling the DNS Client before installing a custom hosts file.


-Secure your Internet Explorer

From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
  • Change the Download signed ActiveX controls to Prompt
  • Change the Download unsigned ActiveX controls to Disable
  • Change the Initialize and script ActiveX controls not marked as safe to Disable
  • Change the Installation of desktop items to Prompt
  • Change the Launching programs and files in an IFRAME to Prompt
  • Change the Navigate sub-frames across different domains to Prompt
  • When all these settings have been made, click on the OK button.
  • If it prompts you as to whether or not you want to save the settings, press the Yes button.
Next press the Apply button and then the OK to exit the Internet Properties page.


- Keeping your Windows up-to-date is crucial to your computer's security. Please go to the Windows Update Site (using Internet Explorer) and download and install all critical updates on a regular basis


- Make sure you have reset Automatic Updates to your chosen optionClick your start button > Control Panel > System > Updates tab


- Keep your antivirus program updated, as well as any other security programs you have.


-More tips and programs can be found HERE

Please post back with the OTL log or if you have any problems.

Hi shadow5,

I don't really have any preference. Personaly I use AVast. Many say it is lighter on resources than AVG.

From your desktop, please delete, if present

  • any notepads/logs that we created
  • aswMBR.exe
  • mbr.dat
  • mbr.zip



Next, Double click on OTL.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:services

:files
C:\Program Files\mozilla.org\Mozilla\plugins\npzango.dll

:Commands
[CLEARALLRESTOREPOINTS]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.
Please post the OTL fix log.


After you save the log:

Open OTL if it's still not open, then click the Clean Up button. You may get prompted by your firewall that OTL wants to contact the internet - allow this. A cleanup.txt will be downloaded, a message dialog will ask you if you want to proceed with the cleanup process, click Yes. This will do some clean up tasks and delete some of the tools you have downloaded plus itself.


I suggest you keep MBAM. Keep it updated and use it regularly.


Updates and upgrades

Adobe Reader

You have an older version of Adobe Reader. You can download the current version HERE

You may want to consider Foxit Reader instead. It may be a bit lighter on resources. If you choose to install Foxit decline the Foxit toolbar.

Visit their support forum
Foxit Forum

In either case you should uninstall Adobe Reader 9.3 first. Be sure to move any PDF documents to another folder first though.



Some Recommendations and prevention tips

Basic security consists of 1 antivirus program, 1 resident antispyware program, 1 on demand antispyware program and a firewall. Add a firewall you have.

* If you are behind a router Windows firewall should be fine. Otherwise a 3rd party firewall with outbound monitoring is recommended.

Click FIREWALL for links and tutorials to good, free and paid for firewalls. (Note: Zone Alarm is becoming bloatware)


You have SpywareBlaster

- SpywareBlaster will add a large list of programs and sites into your Internet Explorer
settings that will protect you from running and downloading known malicious programs.

OR

A guide to understanding and using the hosts file.

Learn how your Hosts file can protect you and how you can protect it.
Besides the Hosts file information, there are links to a very good updated hosts file, a host file manager. and some programs that can protect your hosts file.
HOSTS


Please read the info on disabling the DNS Client before installing a custom hosts file.


-Secure your Internet Explorer

From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
  • Change the Download signed ActiveX controls to Prompt
  • Change the Download unsigned ActiveX controls to Disable
  • Change the Initialize and script ActiveX controls not marked as safe to Disable
  • Change the Installation of desktop items to Prompt
  • Change the Launching programs and files in an IFRAME to Prompt
  • Change the Navigate sub-frames across different domains to Prompt
  • When all these settings have been made, click on the OK button.
  • If it prompts you as to whether or not you want to save the settings, press the Yes button.
Next press the Apply button and then the OK to exit the Internet Properties page.


- Keeping your Windows up-to-date is crucial to your computer's security. Please go to the Windows Update Site (using Internet Explorer) and download and install all critical updates on a regular basis


- Make sure you have reset Automatic Updates to your chosen optionClick your start button > Control Panel > System > Updates tab


- Keep your antivirus program updated, as well as any other security programs you have.


-More tips and programs can be found HERE

Please post back with the OTL log or if you have any problems.


OK. Here is the log. Looks to me, as a novice, that all looks clean! Thank you for ALL your help as well as your suggestions and preference of anti-virus programs.
s

========== SERVICES/DRIVERS ==========
========== FILES ==========
File\Folder C:\Program Files\mozilla.org\Mozilla\plugins\npzango.dll not found.
========== COMMANDS ==========
Restore points cleared and new OTL Restore Point set!

OTL by OldTimer - Version 3.2.31.0 log created on 01202012_103547
Hey oldman960. Could this be related to the virus we just eliminated: I cannot turn on "Automatic Updates" either from its icon or from Control System>Automatic Updates? Just noticed it after we finished the other. If it's unrelated, could you suggest a forum/topic to post it to? s
Hi shadow5,

Let's have a look.

Make sure that the startup type for the following services is set to Automatic, and that the status is set to Started:

Automatic Updates
Background Intelligent Transfer Service (BITS)

  • Click Start, click Run,
  • in the run box copy and paste services.msc and click OK.
  • In the list of services, right click Automatic Updates,
  • click properties
  • make sure the Startup type is set to automatic
  • if it isn't use the drop down menu to set it to automatic
  • Make sure the service status is Started
  • If it's not runing click the start button
  • Do the same for Background Intelligent Transfer
If you made any changes click Apply, and then click OK.

If those services are not in the list let me know.
Hi, and thanks. 'Automatic Updates' is not listed. However 'Background Intelligent Transfer' was there and was set to automatic and was started. s
Hi shadow5,

  • Click Start, click Run
  • In the run window, Copy/paste the bold line below into the white window then click ok

    REGSVR32 %SystemRoot%\System32\WUAUENG.DLL

Now check to see if Automatic Updates is present in services.msc

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI