This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

"Gremlin" Opens Run Box [Solved]

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Not sure what is is infecting and residing in my computer. What happens is something opens the Start-Run box and enters garbage in the blank space. It also makes pinging noises as if hitting a wrong key and My Computer or other icon on the desktop lights up as if the cursor is over it. I've run Ad-Aware, Avast, Malwarebytes, Spyware Doctor and have Zone Alarm. I've also installed Microsoft Security Essentials. None found anything wrong. Even this entry box is not immune. Before it decides to alter my text, I'm pasting the HijackThis log:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:33:10 PM, on 2/23/2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\Program Files\Microsoft Security Client\Antimalware\MpCmdRun.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
C:\WINDOWS\System32\GEARSec.exe
C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
D:\Program Files\PowerQuest\Drive Image 7.0\Agent\PQV2iSvc.exe
C:\WINDOWS\system32\pctspk.exe
C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\ctfmon.exe
D:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ycomp/def…/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ycomp/def…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://search.yahoo.com/search?fr=mcafee&p=%s
R3 - URLSearchHook: ZoneAlarm Security Toolbar - {91da5e8a-3318-4f8c-b67e-5964de3ab546} - C:\Program Files\ZoneAlarm_Security\prxtbZone.dll
F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\userinit.exe
O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6253\SiteAdv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6253\SiteAdv.dll
O4 - HKLM\..\Run: [PCTVOICE] "C:\WINDOWS\system32\pctspk.exe"
O4 - HKLM\..\Run: [NeroCheck] "C:\WINDOWS\System32\NeroCheck.exe"
O4 - HKLM\..\Run: [avast5] C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: $McRebootA5E6DEAA56$.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = D:\Program Files\Micorsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://www.aaa.com
O15 - Trusted Zone: http://www.arride.com
O15 - Trusted Zone: http://www.blogger.com
O15 - Trusted Zone: http://www.bluebottle.com
O15 - Trusted Zone: http://www.cingular.com
O15 - Trusted Zone: www.cnet.com
O15 - Trusted Zone: http://www.cnet.com
O15 - Trusted Zone: http://www.csaa.com
O15 - Trusted Zone: http://www.fastmail.fm
O15 - Trusted Zone: http://*.fontcraft.com
O15 - Trusted Zone: http://www.geocities.com
O15 - Trusted Zone: http://supportdownloads.homestead.com
O15 - Trusted Zone: http://www.homestead.com
O15 - Trusted Zone: http://www.kaiserpermanente.org
O15 - Trusted Zone: http://www.meriwest.com
O15 - Trusted Zone: http://oakland.athletics.mlb.com
O15 - Trusted Zone: http://*.msn.com
O15 - Trusted Zone: http://www.officedepot.com
O15 - Trusted Zone: http://www.pestscan.com
O15 - Trusted Zone: http://workcenter.probusiness.com
O15 - Trusted Zone: http://www.shockwave.com
O15 - Trusted Zone: http://www.spywareguide.com
O15 - Trusted Zone: http://www.ticketmaster.com
O15 - Trusted Zone: http://purchase.tickets.com
O15 - Trusted Zone: http://www.tickets.com
O15 - Trusted Zone: http://*.turbotax.com
O15 - Trusted Zone: http://*.windowupdate.com
O15 - Trusted Zone: http://www.xblock.com
O15 - Trusted IP range: 192.168.1.1
O16 - DPF: ppctlcab - http://www.pestscan.com/scanner/ppctlcab.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1263772900296
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1263772870233
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: McAfee Application Installer Cleanup (0317611234737805) (0317611234737805mcinstcleanup) - Unknown owner - C:\WINDOWS\TEMP\031761~1.EXE (file missing)
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: GEARSecurity - GEAR Software - C:\WINDOWS\System32\GEARSec.exe
O23 - Service: getPlus® Helper - Unknown owner - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe (file missing)
O23 - Service: Intuit Update Service (IntuitUpdateService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
O23 - Service: ZoneAlarm Toolbar IswSvc (IswSvc) - Check Point Software Technologies - C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft Limited - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: V2i Protector - PowerQuest Corporation - D:\Program Files\PowerQuest\Drive Image 7.0\Agent\PQV2iSvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

–
End of file - 8761 bytes


Thanks in advance!

Janet
Hi, and welcome to our malware removal forum!

My name is Richard and I'll be happy to help you with your computer problems.

Please be advised that I am currently in training, so my responses will need to be approved by one of our experts before I post them. This is only to ensure you are receiving accurate instructions. It may cause a delay in my replies.

Please note the following:
  • The cleaning process is not instant as logs can take time to research. Sit tight and please be patient.
  • I will be working on your malware issues. This may or may not solve other issues you may have with your system.
  • While we are fixing your problems, do NOT install/re-install any programs or run any fixes or scanners unless told to do so.
  • Ensure that your anti-virus definitions are up-to-date.
  • I would advise backing up all your important documents, personal data files and photos to a CD or DVD drive.
  • Do not back up any Applications (programs). These should be re-installed from the original source CD(s) or website(s).
  • During the course of our cleanup, please do not do any additional online work or surfing until we have verified that your system is clean.
  • I suggest printing out each set of instructions and reading the entire post before proceeding. It will make following them easier.
  • Be sure to follow the directions and run tools/scans in the order listed.
  • If you do not reply to your topic, it will be closed after 3 days.
I will return as soon as possible with more instructions.



Regards,

Richard :wavey:
Hi Janet,

Spyware Doctor's OnGuard protective functionality may interfere with certain fixes we need to make. Please follow these instructions to disable it:

De-activate Spyware Doctor's OnGuard Tools
  • From within Spyware Doctor, click the "OnGuard" button on the left side.
  • Uncheck "Activate OnGuard".
You can re-enable it once your system is clean.

Next

Download DDS by sUBs to your desktop.
Disable any script blocker/antivirus software temporarily.
  • Double click DDS.scr to run it and wait for the scan to finish
  • When finished DDS.txt will open
  • At the next prompt, press Yes
  • DDS will continue scanning
  • When done, Attach.txt will open
  • Save both reports to your Desktop.
  • Please post the contents of the logs in your next reply.
Next

GMER Rootkit Scanner
—————
Download GMER Rootkit Scanner from here to to your Desktop. It will be a randomly named executable.
  • Double click the exe file. If asked to allow gmer.sys driver to load, please consent.
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.
  • In the right panel, you will see several boxes that have been checked. uncheck the following:
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your Desktop, and attach it in reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


In your next reply, please provide the following:
  • DDS.txt
  • attach.txt
  • GMER log.



Regards,

Richard :wavey:
Hey Richard, I am sorry, but I've trying for the past 5 hours or so to try to log in to this forum and download the software you mentioned. My efforts are being blocked and bogged down by whatever is infecting my desktop. I have to use my laptop to enter this reply. The problems have intensified: My Computer, Narrator, Search Results, Magnifier, in addition to Run, dialog boxes are appearing. Keyboard isn't functioning properly; can't type in my password. Zone Alarm keeps trying to initialize but can't. I lost the taskbar and system tray for a short time as well as the desktop icons. I feel like throwing the computer out into the street! :pullhair: Since I can't get anywhere, I might have to start from scratch and do a clean install of Windows. I don't use the desktop much but it's still needed, and I have a usable backup on an external drive. Sorry to waste your efforts, and I do appreciate your time. Very quick response! :thumbup: Good luck on graduating to post-training work. Janet
Thank you for your kind words! ^_^

Given the problems you are having with the computer, restoring a previous image may be best.

I have some recommendations below about Antivirus and Antispyware programs which could help better protect your computer from future malware infections. :thumbup:

Security Programs:
  • Microsoft Security Essentials
  • Avast 5
  • Lavasoft Ad-Aware (with antivirus?)
  • Spyware Doctor
  • ZoneAlarm (with antivirus?)
You have multiple antivirus software installed. This is never advised as it only causes problems.

The real-time protection of two or more antivirus programs may conflict with each other, causing system lock ups and other performance issues.

I recommend that you choose one that you want to keep and uninstall the other antivirus programs.

Next

Resident Anti-Spyware Programs Notice

I would recommend leaving some of them turned off and using the disabled antispyware program(s) to scan manually. You should only have one antispyware utility running resident.

Good luck! :D

Do you have any questions to ask? Please do not hesitate to do so.



Regards,

Richard :wavey:
Hi Richard, Thanks for the tips! Avast & Spyware Doctor conflict so SD will go, as will MSE. I hate giving up so easily, but… I guess this topic can be closed now. Cheers, Janet

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI