This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Trojans Gone?

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi there.
Have been asked by a neighbour to clear their PC after slow running etc.. and difficulty accessing web sites. They're ADSL conected, though unfortunately had neither AV or ZoneAlarm running initially. I loaded/ran ad-aware, spybot & grisoft AVG and removed a number of trojans (20+) and malware.
Subsequently AVG has run a clean test 3 times, but the internet connection now appears to be not working. I'm still suspicious that trojans may still be there as there seems to be a lot of traffic going up the DSL connection, but not much down.
I've run hijack this to give the following log;

Logfile of HijackThis v1.99.0
Scan saved at 6:37:34 p.m., on 27/02/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\wsctl.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\DSE\ADSL\CnxDslTb.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\ZoneAlarm\zlclient.exe
C:\WINDOWS\System32\wsctl.exe
C:\WINDOWS\System32\wsctl.exe
C:\WINDOWS\System32\wxmst.exe
C:\WINDOWS\System32\wsctl.exe
C:\Program Files\WebSecureAlert\WebSecureAlert.exe
C:\Program Files\MSWorks\Calendar\WKCALREM.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\system32\cidaemon.exe
C:\PROGRA~1\WINZIP\winzip32.exe
C:\Documents and Settings\user\Local Settings\Temp\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ascent.co.nz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.ascent.co.nz
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [CnxDslTaskBar] C:\Program Files\DSE\ADSL\CnxDslTb.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [*wuauclt.exe] wxmst.exe
O4 - HKLM\..\Run: [*windows update] wsctl.exe
O4 - HKLM\..\RunServices: [*windows update] wsctl.exe
O4 - HKLM\..\RunServices: [*wuauclt.exe] wxmst.exe
O4 - HKCU\..\Run: [*wuauclt.exe] wxmst.exe
O4 - HKCU\..\Run: [*windows update] wsctl.exe
O4 - Startup: Microsoft Works Calendar Reminders.lnk = C:\Program Files\MSWorks\Calendar\WKCALREM.EXE
O4 - Global Startup: WebSecureAlert.lnk = C:\Program Files\WebSecureAlert\WebSecureAlert.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O14 - IERESET.INF: START_PAGE_URL=http://www.ascent.co.nz
O16 - DPF: RaptisoftGameLoader - http://www.miniclip.com/hamsterball/raptisoftgameloader.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O17 - HKLM\System\CCS\Services\Tcpip\..\{BF88EDC6-EBD5-4A47-9A8C-97090B29D660}: NameServer = 202.27.158.40,202.27.156.72
O23 - Service: *windows update - Unknown - C:\WINDOWS\System32\wsctl.exe
O23 - Service: *wuauclt.exe - Unknown - C:\WINDOWS\System32\wxmst.exe
O23 - Service: ATI Smart - Unknown - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: TrueVector Internet Monitor - Zone Labs LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

Any assistance gratefully received.
hello ptatenz, we will some files, use hjt, boot to safe mode, delete more files–ok look in add/remove programs panel and uninstall this if present: WebSecureAlert ————————- make sure files are setr to show; FOr XP: on the desktop double click my computer,go to tools>folder options>view> then select "show hidden files and folders", then UNcheck "hide protected operating system files " also UNcheck "hide extensions for known file types" click apply to all folders, apply then ok ————————- scan with HJT, put a checkmark beside the items below, close all windows and click fix checked O4 - HKLM\..\Run: [*wuauclt.exe] wxmst.exe O4 - HKLM\..\Run: [*windows update] wsctl.exe O4 - HKLM\..\RunServices: [*windows update] wsctl.exe O4 - HKLM\..\RunServices: [*wuauclt.exe] wxmst.exe O4 - HKCU\..\Run: [*wuauclt.exe] wxmst.exe O4 - HKCU\..\Run: [*windows update] wsctl.exe O4 - Global Startup: WebSecureAlert.lnk = C:\Program Files\WebSecureAlert\WebSecureAlert.exe O23 - Service: *windows update - Unknown - C:\WINDOWS\System32\wsctl.exe O23 - Service: *wuauclt.exe - Unknown - C:\WINDOWS\System32\wxmst.exe ——————————– now boot computer into safe mode by tapping the f8 key at restart, chose safe mode from the options, once in safe mode find and delete these exe C:\WINDOWS\System32\wsctl.exe C:\WINDOWS\System32\wsctl.exe C:\WINDOWS\System32\wxmst.exe C:\WINDOWS\System32\wsctl.exe for this one: WebSecureAlert delete entire folder here>>C:\Program Files alos in safe mode: Click Start>Run then type %temp% Hit OK. Delete all the files you can. Empty your Temp folders. Go to Start > Run and type:cleanmgr. Windows will scan. When done check these 3 and press *ok* to remove: Temporary Files Temporary Internet Files Recycle Bin ———————————– reboot normally, rescan and post new hjt log, anything unusual asks for connection in ZA, deny it—is connection working?
Hi Shelf Life.
Thanks for getting back to me on this - sorry for the delay as I'm doing this as a favour between day jobs!
I went through the process you described and unfortunately ADSL still isn't working…well that's not strictly true. I think in fact ADSL's working too well as the upload traffic is many times greater than the download. It's just not letting either Firefox or IE get a look in.
I therefore think my post title is incorrect as I'm pretty sure my Trojan's alive and well and happily using the resources of the PC.
My next step was to unplu the PC, bring it back to my place and hook up to my cable connection (this to test if there's a fault with the ADL modem as suggested by the ISP…yeah right). Similar story with the cable connection…though it did manage to download an update for AVG which upon scanning immediately found the Padobot.V worm. I'd deleted all programme permissions from ZA and got a warning that "pingpac.exe" was trying to get out - denied.
The latest hjt log is as follow;
Logfile of HijackThis v1.99.0
Scan saved at 8:19:46 a.m., on 1/03/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\userinit.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\DSE\ADSL\CnxDslTb.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\ZoneAlarm\zlclient.exe
C:\WINDOWS\System32\pingppac.exe
C:\Program Files\MSWorks\Calendar\WKCALREM.EXE
C:\Documents and Settings\user\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ascent.co.nz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.ascent.co.nz
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [CnxDslTaskBar] C:\Program Files\DSE\ADSL\CnxDslTb.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [PPPOEO] pingppac.exe
O4 - HKLM\..\RunServices: [PPPOEO] pingppac.exe
O4 - Startup: Microsoft Works Calendar Reminders.lnk = C:\Program Files\MSWorks\Calendar\WKCALREM.EXE
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O14 - IERESET.INF: START_PAGE_URL=http://www.ascent.co.nz
O16 - DPF: RaptisoftGameLoader - http://www.miniclip.com/hamsterball/raptisoftgameloader.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O17 - HKLM\System\CCS\Services\Tcpip\..\{92A3F364-695F-49C7-ADCD-598533514D85}: NameServer = 203.96.152.4,203.96.152.12
O23 - Service: ATI Smart - Unknown - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: TrueVector Internet Monitor - Zone Labs LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

Apart from Pingpac, I'm a little suspicious of MSMSGS.EXE as I note from other logs that it seems to get knobbled by virus's.
My next move is to try and hit the thing with as many AV programmes as poss (e.g. Kaspersky) + McAfee's Stinger which I understand is a specific trojan killer.

Any further thoughts you may have appreciated.
hello ptatenz,

good work, log is look ing better. that pingppac.exe has to go:

run hjt and fix:

O4 - HKLM\..\Run: [PPPOEO] pingppac.exe
O4 - HKLM\..\RunServices: [PPPOEO] pingppac.exe

next boot into safe mode and delete>> pingppac.exe located here>>C:\WINDOWS\System32

MSMSGS.EXE is windows messanger, the chat client its ok.

could you get online to do some online scans:
MicroWorld
Bitdefender
Norton
Panda Activescan
TrendMicro

Specific for trojans;
a2 free
Ewido Security Suite
Trojan Hunter (30 day trial version)

other things to try:
download files and latest updates on another computer, burn to cd, install on "bad" computer.
remove "bad" Harddrive, install as slave on good computer, scan bad hardrive with software from good computer, reinstall cleaned drive back in computer

let me know how its going………later
Hi there Shelf Life Progress since we last communicated is that I decided to go straight to your plan B and reckon I'm finally on top of them (unless you tell me otherwise!). I configured the bad disk as a slave (E:\) and installed it in my clean machine. Went through repeated iterations of various AV systems. (I’ve omitted the results to keep this post as short as poss., but I can send any through you might like to see.) Where the respective tool didn’t itself eradicate the virus I went into the affected directory and deleted the file. Norton was the trickiest as it kept reporting 2 outstanding trojans as follows; E:\RECYCLER\S-1-5-21-484763869-1644491937-839522115-1003\Dc34.exe is infected with W32.Spybot.Worm E:\RECYCLER\S-1-5-21-484763869-1644491937-839522115-1003\Dc43.exe is infected with W32.Spybot.Worm Even with the hidden and protected files settings unchecked in W2k it was unable to see them. Went into DOS mode and managed to list the files using /s (a lucky guess). Did a *.* on the directory and reran Norton. Now I can run clear on Norton online, Grisoft AVG, S&D, Ad-Aware, Trojan Hunter, a2 & Stinger. My question relates to o/p from MicroWorld AntiVirus Toolkit. Despite the clean runs above, the latest scan came back reporting 151 viruses (edited log file below – most ad-ware, but also a few trojans esp. Backdoor.Win32.Rbot.gen). I note that all instances are reported under E:\System Volume Information\_restore… I’m assuming that I’ve now eradicated all the viruses except in the area which the system will revert to if a roll-back to the last good system function is used. I also assume that if this is done the system will be re-infected. What’s the options for getting rid of them now to fully finish the job? Can I just delete the files or will this corrupt the system? Many thanks. MicroWorld AntiVirus Toolkit Utility. Virus Database Date: 2005/03/01 Virus Database Count: 119806 Version 5.1.1 (C:\DOCUME~1\ADMINI~1.PEN\LOCALS~1\Temp\mwavscan.com) Latest Date of files inside MWAV: 01 Mar 2005 06:24:09. Options Selected by User: Memory Check: Disabled Registry Check: Disabled StartUp Folder Check: Disabled System Folder Check: Disabled System Area Check: Disabled Services Check: Disabled Drive Check: Disabled All Drive Check :Enabled Folder Check: Enabled Folder Selected = E:\ E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP198\A0028322.exe infected by "not-a-virus:AdWare.Gator.6041" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP198\A0028323.exe infected by "not-a-virus:AdWare.Gator.6034" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP198\A0028324.exe infected by "not-a-virus:AdWare.Gator.6041" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP198\A0028325.dll infected by "not-a-virus:AdWare.Gator.6041" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP198\A0028326.dll infected by "not-a-virus:AdWare.Gator.6041" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP198\A0028327.dll infected by "not-a-virus:AdWare.Gator.5017" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP198\A0028328.dll infected by "not-a-virus:AdWare.Gator.6041" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP198\A0028329.dll infected by "not-a-virus:AdWare.Gator.6041" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP198\A0028331.exe infected by "not-a-virus:AdWare.Gator.6034" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP198\A0028332.dll infected by "not-a-virus:AdWare.Gator.6041" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP198\A0028333.dll infected by "not-a-virus:AdWare.Gator.6041" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP198\A0028334.dll infected by "not-a-virus:AdWare.Gator.6041" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP198\A0028335.dll infected by "not-a-virus:AdWare.Gator.3124" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP198\A0028336.dll infected by "not-a-virus:AdWare.Gator.6041" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP198\A0028337.dll infected by "not-a-virus:AdWare.Gator.6041" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP198\A0028338.dll infected by "not-a-virus:AdWare.Gator.6041" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP198\A0028339.dll infected by "not-a-virus:AdWare.Gator.6041" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP198\A0028340.dll infected by "not-a-virus:AdWare.Gator.6041" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP198\A0028341.dll infected by "not-a-virus:AdWare.Gator.6041" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP198\A0028342.dll infected by "not-a-virus:AdWare.Gator.6041" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP198\A0028345.exe infected by "not-a-virus:AdWare.Gator.6034" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP298\A0055995.exe infected by "not-a-virus:AdWare.WinAD.s" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP298\A0055996.dll infected by "not-a-virus:AdWare.WinAD.u" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP298\A0055997.exe infected by "not-a-virus:AdWare.WinAD.k" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP298\A0056199.dll infected by "not-a-virus:AdWare.Gator.b" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP298\A0056202.exe infected by "not-a-virus:AdWare.Gator.6040" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP298\A0056205.exe infected by "not-a-virus:AdWare.Gator.6040" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP300\A0056212.dll infected by "not-a-virus:AdWare.Gator.6051" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP300\A0056213.exe infected by "not-a-virus:AdWare.Gator.6034" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP300\A0056214.dll infected by "not-a-virus:AdWare.Gator.6051" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP300\A0056215.dll infected by "not-a-virus:AdWare.Gator.6051" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP300\A0056216.dll infected by "not-a-virus:AdWare.Gator.3124" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP300\A0056217.dll infected by "not-a-virus:AdWare.Gator.6051" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP300\A0056218.dll infected by "not-a-virus:AdWare.Gator.6051" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP300\A0056219.dll infected by "not-a-virus:AdWare.Gator.6051" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP300\A0056220.dll infected by "not-a-virus:AdWare.Gator.6051" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP300\A0056222.dll infected by "not-a-virus:AdWare.Gator.6051" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP300\A0056223.dll infected by "not-a-virus:AdWare.Gator.6051" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP300\A0056224.dll infected by "not-a-virus:AdWare.Gator.6051" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP300\A0056229.dll infected by "not-a-virus:AdWare.Gator.6051" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP300\A0056231.dll infected by "not-a-virus:AdWare.Gator.6041" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP300\A0056232.dll infected by "not-a-virus:AdWare.Gator.5017" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP300\A0056233.dll infected by "not-a-virus:AdWare.Gator.6041" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP300\A0056234.exe infected by "not-a-virus:AdWare.Gator.6034" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP300\A0056262.exe infected by "not-a-virus:AdWare.Gator.6034" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP301\A0056284.exe infected by "not-a-virus:AdWare.WinAD.y" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP302\A0056286.exe infected by "not-a-virus:AdWare.WinAD.y" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP303\A0056293.exe infected by "not-a-virus:AdWare.WinAD.y" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP303\A0056335.exe infected by "not-a-virus:AdWare.WinAD.z" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP303\A0056355.exe infected by "not-a-virus:AdWare.WinAD.y" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP303\A0056356.exe infected by "not-a-virus:AdWare.WinAD.z" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP303\A0056375.exe infected by "not-a-virus:AdWare.WinAD.y" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP303\A0056377.exe infected by "not-a-virus:AdWare.WinAD.z" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP304\A0057374.exe infected by "not-a-virus:AdWare.WinAD.y" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP305\A0058375.exe infected by "not-a-virus:AdWare.WinAD.y" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP305\A0058377.exe infected by "not-a-virus:AdWare.WinAD.z" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP305\A0058394.exe infected by "not-a-virus:AdWare.WinAD.y" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP307\A0061393.exe infected by "not-a-virus:AdWare.WinAD.y" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP307\A0061394.exe infected by "not-a-virus:AdWare.WinAD.z" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP307\A0062394.exe infected by "not-a-virus:AdWare.WinAD.z" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP308\A0062397.exe infected by "not-a-virus:AdWare.WinAD.z" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP308\A0062398.exe infected by "not-a-virus:AdWare.WinAD.z" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP308\A0063393.exe infected by "not-a-virus:AdWare.WinAD.z" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP308\A0063394.exe infected by "Backdoor.Win32.Rbot.gen" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP308\A0063395.exe infected by "not-a-virus:AdWare.WinAD.z" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP309\A0063414.exe infected by "not-a-virus:AdWare.WinAD.z" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP309\A0063432.exe infected by "not-a-virus:AdWare.WinAD.z" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP309\A0063435.exe infected by "not-a-virus:AdWare.WinAD.z" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP309\A0064513.exe infected by "not-a-virus:AdWare.WinAD.z" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP309\A0064517.exe infected by "not-a-virus:AdWare.WinAD.z" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP309\A0064518.exe infected by "not-a-virus:AdWare.WinAD.z" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP313\A0064794.exe infected by "not-a-virus:AdWare.WinAD.z" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP313\A0064795.exe infected by "not-a-virus:AdWare.WinAD.z" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP313\A0065792.exe infected by "not-a-virus:AdWare.WinAD.z" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP313\A0065794.exe infected by "not-a-virus:AdWare.WinAD.z" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP313\A0065817.exe infected by "Backdoor.Win32.Rbot.gen" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP313\A0066816.exe infected by "not-a-virus:AdWare.WinAD.z" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP313\A0066819.exe infected by "not-a-virus:AdWare.WinAD.z" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP313\A0066820.exe infected by "not-a-virus:AdWare.WinAD.z" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP314\A0066821.exe infected by "not-a-virus:AdWare.WinAD.z" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP314\A0066823.exe infected by "not-a-virus:AdWare.WinAD.z" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP314\A0066824.exe infected by "not-a-virus:AdWare.WinAD.z" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP314\A0067814.exe infected by "Backdoor.Win32.Rbot.gen" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP314\A0067815.exe infected by "not-a-virus:AdWare.WinAD.z" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP314\A0067816.exe infected by "not-a-virus:AdWare.WinAD.z" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP315\A0067863.exe infected by "not-a-virus:AdWare.WinAD.z" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP315\A0067864.exe infected by "not-a-virus:AdWare.WinAD.z" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP315\A0067879.exe infected by "not-a-virus:AdWare.WinAD.z" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP316\A0067996.exe infected by "not-a-virus:AdWare.WinAD.z" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP327\A0069210.exe infected by "Backdoor.Win32.Rbot.gen" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP327\A0069211.exe infected by "Backdoor.Win32.Rbot.iq" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP327\A0069214.exe infected by "Backdoor.Win32.Rbot.gen" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP327\A0069215.exe infected by "Backdoor.Win32.Rbot.iq" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP327\A0069217.exe infected by "Backdoor.Win32.Rbot.gen" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP327\A0069221.exe infected by "Backdoor.Win32.Rbot.gen" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP327\A0069223.exe infected by "Backdoor.Win32.Rbot.gen" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP327\A0069226.exe infected by "Backdoor.Win32.Rbot.gen" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP327\A0069229.exe infected by "Backdoor.Win32.Rbot.gen" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP327\A0069230.exe infected by "Backdoor.Win32.Rbot.gen" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP327\A0069231.exe infected by "Backdoor.Win32.Rbot.gen" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP327\A0069234.exe infected by "Backdoor.Win32.Rbot.gen" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP327\A0069235.exe infected by "Backdoor.Win32.Rbot.iq" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP327\A0069237.exe infected by "Backdoor.Win32.Rbot.gen" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP327\A0069238.exe infected by "Backdoor.Win32.Rbot.gen" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP327\A0069239.exe infected by "Backdoor.Win32.Rbot.iq" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP327\A0069240.exe infected by "Backdoor.Win32.Rbot.gen" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP327\A0069242.exe infected by "Backdoor.Win32.Rbot.gen" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP327\A0069243.exe infected by "Backdoor.Win32.Rbot.gen" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP327\A0069247.exe infected by "Backdoor.Win32.Rbot.gen" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP327\A0069248.exe infected by "Backdoor.Win32.Rbot.gen" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP327\A0069249.exe infected by "Backdoor.Win32.Rbot.gen" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP327\A0069252.exe infected by "Backdoor.Win32.Rbot.gen" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP327\A0069255.exe infected by "Backdoor.Win32.Rbot.gen" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP327\A0069257.exe infected by "Backdoor.Win32.Rbot.iq" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP327\A0069262.exe infected by "Backdoor.Win32.Rbot.gen" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP327\A0069263.exe infected by "Backdoor.Win32.Rbot.gen" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP327\A0069265.exe infected by "Backdoor.Win32.Rbot.iq" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP327\A0069267.exe infected by "Backdoor.Win32.Rbot.gen" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP327\A0069268.exe infected by "Backdoor.Win32.Rbot.gen" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP327\A0069269.exe infected by "Backdoor.Win32.Rbot.gen" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP327\A0069271.exe infected by "Backdoor.Win32.Rbot.gen" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP327\A0069272.exe infected by "Backdoor.Win32.Rbot.gen" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP327\A0069273.exe infected by "Backdoor.Win32.Rbot.iq" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP327\A0069275.exe infected by "Backdoor.Win32.Rbot.gen" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP327\A0069276.exe infected by "not-a-virus:AdWare.Gator.4010" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP327\A0069277.exe infected by "Backdoor.Win32.Rbot.gen" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP327\A0069286.exe infected by "Backdoor.Win32.Rbot.gen" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP327\A0069287.exe infected by "Backdoor.Win32.Rbot.gen" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP327\A0069289.exe infected by "Backdoor.Win32.Rbot.gen" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP327\A0069291.exe infected by "Backdoor.Win32.Rbot.gen" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP327\A0069295.exe infected by "Backdoor.Win32.Rbot.iq" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP327\A0069299.exe infected by "Backdoor.Win32.Rbot.gen" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP327\A0069300.exe infected by "Backdoor.Win32.Rbot.gen" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP327\A0069301.exe infected by "Backdoor.Win32.Rbot.gen" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP327\A0069303.exe infected by "Backdoor.Win32.Rbot.gen" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP327\A0069304.exe infected by "Backdoor.Win32.Rbot.gen" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP327\A0069305.exe infected by "Backdoor.Win32.Rbot.iq" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP327\A0069306.exe infected by "Backdoor.Win32.Rbot.iq" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP327\A0069307.exe infected by "Backdoor.Win32.Rbot.gen" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP327\A0069309.exe infected by "Backdoor.Win32.Rbot.iq" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP327\A0069310.exe infected by "Backdoor.Win32.Rbot.gen" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP327\A0069311.exe infected by "Backdoor.Win32.Rbot.gen" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP327\A0069312.exe infected by "Backdoor.Win32.Rbot.gen" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP327\A0069314.exe infected by "Backdoor.Win32.Rbot.gen" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP327\A0069319.exe infected by "Backdoor.Win32.Rbot.gen" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP329\A0072469.exe infected by "not-a-virus:AdWare.Gator.10021" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP329\A0072472.dll infected by "not-a-virus:AdWare.ToolBar.DashBar.c" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP329\A0072479.exe infected by "Backdoor.Win32.Rbot.gen" Virus. E:\System Volume Information\_restore{462DB72B-260E-45F9-9C01-379240A9EF18}\RP329\A0072480.exe infected by "Backdoor.Win32.Rbot.gen" Virus. Fri Mar 04 17:25:44 2005 => Total Files Scanned: 44760 Fri Mar 04 17:25:44 2005 => Total Virus(es) Found: 151 Fri Mar 04 17:25:44 2005 => Total Disinfected Files: 0 Fri Mar 04 17:25:44 2005 => Total Files Renamed: 0 Fri Mar 04 17:25:44 2005 => Total Deleted Files: 0 Fri Mar 04 17:25:44 2005 => Total Errors: 40 Fri Mar 04 17:25:44 2005 => Time Elapsed: 02:38:41 Fri Mar 04 17:25:44 2005 => Virus Database Date: 2005/03/01 Fri Mar 04 17:25:44 2005 => Virus Database Count: 119806 Fri Mar 04 17:25:44 2005 => Scan Completed.
hello ptatenz, good work. lets try making new >clean< restore points: windows can incorporate infected files into restore archives, so when you scan with antivirus etc—it can pick up stuff in the archives or restore points. (winXP) 1. Turn off System Restore. (deletes old>> possibly infected restore point) On the Desktop, right-click My Computer. Click Properties. Click the System Restore tab. Check Turn off System Restore. Click Apply, and then click OK. 2. Reboot. 3. Turn ON System Restore.(new restore points on a clean system) On the Desktop, right-click My Computer. Click Properties. Click the System Restore tab. UN-Check *Turn off System Restore*. Click Apply, and then click OK, then reboot ————————- E:\RECYCLER this is the recycle bin, just empty it from the desktop like normal now rescan with av etc…… shelf life
Hi Shelflife. Reinstalled the drive back into the PC, after a couple of attempts got a good restore point and then ran a full MicroWorld AntiVirus check cleanly. + AVG, Spybot & Adaware this leaves me pretty confident that we've nailed them all. However… Whilst subsequently installing SP2 the machine hung and despite best efforts I had to do a cold restart. It came back up into Windows but, informed me that the OS was unstable and that I should delete SP2 from the Add/Delete Programs function. Did this and it's packed a real sad…will now not boot. Brings me up to a screen which informs me that it didn't shut down gracefully and that I now have a number of options to bring the machine up; Safe Mode, S + Net, S + Command, Known Last Good Cofig or Normal. None work as it just goes back to scratch and brings me back to the same screen in a perpetual loop. To say this is disappointing is to put it mildly…the machine's lucky not to have a sledgehammer through the case right now! Anyway, unless you can suggest a less drastic plan, I don't think I've got much choice other than to re-install the OS. I can use the opportunity to take off any user data through my own machine and format the drive so it's a truly clean install. Hindsights great…I could have done this 2 weeks ago and saved us a heap of bother..though we have learnt a fair deal on the way through.
Hi Shelflife.
Thanks I'll give it a go.
I was kicking myself for being too smart and installing the latest system versions..should have just handed the PC back as it was.. working!
Looking at TechRepublic though suggests to me this a problem others have experienced (see http://techrepublic.com.com/5100-6268_11-5330486.html). I've tried both renaming update.sys and disabling L1 & L2 cache with no success so far. The cache discable did take me a bit further though and I got to the Windows XP screen before it crapped out and went back to restart.
Such is life and the joys of MS operating systems I guess.
If you need this topic reopened, please request this by sending an email to us at the following link
(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI