This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Help Please! Urgent!

19 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Have been given the following advice from one of our other members.

If any of the system files are corrupt you can use windows sfc (system file checker) You'd need your Windows CD to make this work.

Click Start> Run> type in sfc /scannow Please take note of the space

Please let me know how you get on.
Crunchie,

Did as you suggested and deleted the following entry:

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1109893810765

tried the Windows Update again with the same results, nothing downloaded and it said that Windows is up-to-date…

Downloaded and ran Silent Runners, please find below the resulting log…

Ran "sfc /scannow", it took more or less 5 minutes to run and it did not show any results nor any warnings, nor asked me for the Windows CD…

Microsoft Support haven't contacted me again…

—

"Silent Runners.vbs", revision 32, http://www.silentrunners.org/
Operating System: Windows XP
Output limited to non-default values, except where indicated by "{++}"


Startup items buried in registry:
———————————

HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
"Microsoft Works Update Detection" = "C:\Program Files\Microsoft Works\WkDetect.exe" ["Microsoft® Corporation"]

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
"VTPreset" = "VTPreset.exe" ["S3 Graphics, Inc."]
"THGuard" = ""C:\Program Files\TrojanHunter 4.2\THGuard.exe"" ["Mischel Internet Security"]
"tgcmd" = ""C:\Program Files\Support.com\BellSouth\hcenter.exe" /starthidden /tgcmdwrapper" ["BellSouth"]
"Symantec NetDriver Monitor" = "C:\PROGRA~1\SYMNET~1\SNDMon.exe" ["Symantec Corporation"]
"SSC_UserPrompt" = "C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe" ["Symantec Corporation"]
"RealTray" = "C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER" ["RealNetworks, Inc."]
"QuickTime Task" = ""C:\Program Files\QuickTime\qttask.exe" -atboottime" ["Apple Computer, Inc."]
"Lexmark X1100 Series" = ""C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"" ["Lexmark International, Inc."]
"ccRegVfy" = ""C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"" ["Symantec Corporation"]
"ccApp" = "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" ["Symantec Corporation"]
"BJCFD" = "C:\Program Files\BroadJump\Client Foundation\CFD.exe" ["BroadJump, Inc."]
"gcasServ" = ""C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"" [MS]

HKLM\Software\Microsoft\Active Setup\Installed Components\
{306D6C21-C1B6-4629-986C-E59E1875B8AF}\(Default) = (no title provided)
\StubPath = ""C:\WINDOWS\System32\rundll32.exe" "C:\Program Files\Messenger\msgsc.dll",ShowIconsUser" [MS]

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\(Default) = "AcroIEHlprObj Class" [from CLSID]
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx" [empty string]
{4A368E80-174F-4872-96B5-0B27DDD11DB2}\(Default) = "SpywareGuard Download Protection"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\SpywareGuard\dlprotect.dll" [null data]
{53707962-6F74-2D53-2644-206D7942484F}\(Default) = (no title provided)
-> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\SPYBOT~1\SDHelper.dll" ["Safer Networking Limited"]
{BDF3E430-B101-42AD-A544-FADC6B084872}\(Default) = "NAV Helper"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll" ["Symantec Corporation"]
{FDD3B846-8D59-4ffb-8758-209B6AD74ACC}\(Default) = (no title provided)
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Microsoft Money\System\mnyviewer.dll" [MS]

HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
"{88895560-9AA2-1069-930E-00AA0030EBC8}" = "HyperTerminal Icon Ext"
-> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\System32\hticons.dll" ["Hilgraeve, Inc."]
"{81559C35-8464-49F7-BB0E-07A383BEF910}" = "SpywareGuard.Handler" [from CLSID]
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\SpywareGuard\spywareguard.dll" [null data]
"{640167b4-59b0-47a6-b335-a6b3c0695aea}" = "Portable Media Devices"
-> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\System32\Audiodev.dll" [MS]
"{cc86590a-b60a-48e6-996b-41d25ed39a1e}" = "Portable Media Devices Menu"
-> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\System32\Audiodev.dll" [MS]
"{EBDF1F20-C829-11D1-8233-FF20AF3E97A9}" = "TrojanHunter Menu Shell Extension"
-> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\TROJAN~1.2\contmenu.dll" [null data]

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\
"{38D4D5D0-423E-4220-B6F9-30918C2AE4A4}" = (no title provided)
-> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\sasetup.dll" [file not found]


Enabled Scheduled Tasks:
————————

"Norton AntiVirus - Scan my computer" -> launches: "C:\PROGRA~1\NORTON~1\NORTON~1\NAVW32.exe /task:C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec\NORTON~1\Tasks\mycomp.sca" ["Symantec Corporation"]
"Norton SystemWorks One Button Checkup" -> launches: "C:\Program Files\Norton SystemWorks\OBC.exe /CUSTOM /SCHEDULE" ["Symantec Corporation"]
"Symantec NetDetect" -> launches: "C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE" ["Symantec Corporation"]


Running Services (Display Name, Service Name, Path {Service DLL}):
——————————————————————

LexBce Server, LexBceS, "C:\WINDOWS\system32\LEXBCES.EXE" ["Lexmark International, Inc."]
Norton AntiVirus Auto Protect Service, navapsvc, ""C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe"" ["Symantec Corporation"]
Norton Internet Security Accounts Manager, NISUM, "C:\Program Files\Norton Internet Security\NISUM.EXE" ["Symantec Corporation"]
Norton Unerase Protection, NProtectService, ""C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE"" ["Symantec Corporation"]
Speed Disk service, Speed Disk service, "C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe" ["Symantec Corporation"]
Symantec Event Manager, ccEvtMgr, ""C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"" ["Symantec Corporation"]
Symantec Proxy Service, ccPxySvc, "C:\Program Files\Norton Internet Security\ccPxySvc.exe" ["Symantec Corporation"]
WAN Miniport (ATW) Service, WANMiniportService, ""C:\WINDOWS\wanmpsvc.exe"" ["America Online, Inc."]
Windows User Mode Driver Framework, UMWdf, "C:\WINDOWS\System32\wdfmgr.exe" [MS]


Winsock2 Service Provider DLLs:
——————————-

Namespace Service Providers

HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}
000000000001\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]
000000000002\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS]
000000000003\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]

Transport Service Providers

HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}
0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:
%SystemRoot%\system32\mswsock.dll [MS], 01 - 03, 06 - 15
%SystemRoot%\system32\rsvpsp.dll [MS], 04 - 05


———-
This report excludes default entries except where indicated.
To see *everywhere* the script checks and *everything* it finds,
launch it from a command prompt or a shortcut with the -all parameter.
———-
Nothing really showing there. Are you positive that you are not up to date? Try the online scans again. I am pretty sure that one of them checks the critical updates installed.

Go here to TrendMicro for an on-line scan & set it to autoclean for you. When it completes, post back the full filename of any files that cannot be cleaned or deleted.

Try this scan at Panda as well.


The scan here does not require an active X install, but uses java instead.
http://fr.trendmicro-europe.com/consumer/p…call_launch.php
When I run "winver" it says that I have Service Pack 1, I should be able to update to Service Pack 2. And the Internet Firewall under Service Pack 1 cannot be activated, it just shows me an error trying to activate it… so those things are making me think that there is something well hidden that is blocking a couple of things (Norton's antivirus and firewall, Window's update and the well functions of other antispyware)… During this time I installed Microsft's Antispyware and it seems to be doing its job. It even asked what to do with the "sassetup" before you told me to delete it… When I ran Panda's and TrendMicro's online checks for the first time, they both found some problems that were solved, in fact, I still have the logs that resulted from those checks and the subsequent ones too if you would like to take a look at them… The last time I ran both of them, nothing was found, except for Panda that show a problem with a registry, but I haven't run it after your last instructions. Symantec's online check has never been able to run, it tries to download twice the activeX and after the second try it starts, but aborts right away saying that it cannot run it that computer… I will anyways try again Panda's and Trendmicro's, even fom the activeX-free link that you are giving me… I will be waiting for your instructions on how to send you the logs, the first from Panda is very large since it found over 600 probs…
Of those 600 problems, how many did Panda manage to fix? If you can edit out all files that were disinfected, you can then attach the log file to your post and I will check it out. May take a while though :).
Hi Crunchie, Below find the info requested and BTW, received good comments from you by the people at CastleCops… — On Panda's first run it did not disinfect the following… Adware:Adware/24-7-search (1 incident) Adware:Adware/BHO (1 incident) Adware:Adware/Comet (2 incidents) Adware:Adware/CWS (1 incident) Adware:Adware/CWS.Aboutblank (1 incident) Adware:Adware/CWS.Searchmeup (176 incidents) Adware:Adware/IESearchBar (2 incidents) Adware:Adware/IPInsight (1 incident) Adware:Adware/MyDailyHoroscope (1 incident) Adware:Adware/SearchExe (3 incidents) Adware:Adware/SuperSpider (1 incident) Adware:Adware/Tubby (2 incidents) Possible Virus (25 incidents) Spyware:Spyware/Altnet (1 incident) Spyware:Spyware/BetterInet (3 incident) Spyware:Spyware/IESearchToolbar (1 incident) Spyware:Spyware/ISTbar (1 incident) Spyware:Spyware/Searchcentrix (1 incident) Spyware:Spyware/Slimield (588 incidents) It recommended to delete those files, which I did and ran a second check… — On Panda's Second run it did not disinfect the following 24 files… Adware:Adware/Comet No disinfected C:\Documents and Settings\MICHELLI\Local Settings\Temp\unpack\CC_43.inf Adware:Adware/Comet No disinfected C:\Documents and Settings\MICHELLI\Local Settings\Temp\unpack\inst43.exe Possible Virus No disinfected C:\Documents and Settings\MICHELLI\Application Data\Microsoft\sr64\jbgclhho.exe Spyware:Spyware/BetterInet No disinfected C:\WINDOWS\Buddy.exe Spyware:Spyware/BetterInet No disinfected C:\WINDOWS\inf\ceres.inf Spyware:Spyware/ISTbar No disinfected Windows Registry Spyware:Spyware/Slimield No disinfected C:\WINDOWS\Tsr.exe Spyware:Spyware/Slimield No disinfected C:\WINDOWS\System32\Obn.exe Spyware:Spyware/Slimield No disinfected C:\WINDOWS\Ugu.exe Spyware:Spyware/Slimield No disinfected C:\WINDOWS\Mmc.exe Spyware:Spyware/Slimield No disinfected C:\WINDOWS\Eur.exe Spyware:Spyware/Slimield No disinfected C:\WINDOWS\System32\Bff.exe Spyware:Spyware/Slimield No disinfected C:\WINDOWS\Upq.exe Spyware:Spyware/Slimield No disinfected C:\WINDOWS\System32\Piu.exe Spyware:Spyware/Slimield No disinfected C:\WINDOWS\System32\Sep.exe Spyware:Spyware/Slimield No disinfected C:\WINDOWS\Eur.exe Spyware:Spyware/Slimield No disinfected C:\WINDOWS\Mmc.exe Spyware:Spyware/Slimield No disinfected C:\WINDOWS\system32\Bff.exe Spyware:Spyware/Slimield No disinfected C:\WINDOWS\system32\Obn.exe Spyware:Spyware/Slimield No disinfected C:\WINDOWS\system32\Piu.exe Spyware:Spyware/Slimield No disinfected C:\WINDOWS\system32\Sep.exe Spyware:Spyware/Slimield No disinfected C:\WINDOWS\Tsr.exe Spyware:Spyware/Slimield No disinfected C:\WINDOWS\Ugu.exe Spyware:Spyware/Slimield No disinfected C:\WINDOWS\Upq.exe It recommended to delete those files, which I did and ran a third check… — On Panda's Third run it did not disinfect the following 2 files… Spyware:Spyware/ISTbar No disinfected Windows Registry Possible Virus No disinfected C:\WINDOWS\system32\desktop.dll It recommended to delete those files, which I did and ran a fourth check… — On Panda's Fourh run it did not disinfect the following file and showed as disinfected one… Adware:Adware/SearchExe No disinfected Windows Registry Virus:Trj/Downloader.AXD Disinfected C:\WINDOWS\system32\chp.dll — I deleted directly from their locations the indicated files, where an incident ocurred with a Registry, I did not corrected it. Ever since, all runs from Panda show just one incident and it is a Windows Registry, the last one… — I still haven't run the check from the TrendMicro link that you told, should be doing that today and post any results, will run a Panda again too… Thanks!

Hi Crunchie, received good comments from you by the people at CastleCops…


Cool. Good to know :D.

Download, install and run Cleanup! from Steven Gould, then:

1. Click "Cleanup!"

(wait for the program to finish scanning your system, and selecting files to be removed.)

2. Exit the program and reboot the computer, if necessary.

-

For more information about using Cleanup! see here.
Hi Crunchie, Downloaded and ran Cleanup and rebooted… Ran TrendMicro's check from the link you gave me and found nothing… Ran Panda's check and found these infected files: Adware:Adware/CWS No disinfected C:\Documents and Settings\MICHELLI\Favorites\Clean Space.url (Haven't deleted it) Spyware:Spyware/Altnet No disinfected Windows Registry Ran McAfee's check and found the following: Exploit-MhtRedir.gen C:\Program Files\hijackthis.log Generic Downloader.h C:\WINDOWS\sys031.exe Generic Downloader.h C:\WINDOWS\sys059.exe Generic Downloader.h C:\WINDOWS\sys126.exe Generic Downloader.h C:\WINDOWS\sys5530.exe BackDoor-CLK.dll C:\WINDOWS\system32\w BTW, I see a lot of sys####.exe files within C:\WINDOWS\… Still unable to run Symantec's check… Updated SpywareBlaster… Ran Spybot and found nothing (I have TeaTimer still disabled)… Still unable to update nor to enable Internet Connection Firewall…
Problem is, where are those files coming from? If I were you I would get those suspicious files and either upload them here or go to the properties of each and get all the info you can from them.
As for the files found by McAfee and Panda, should I just delete them? and what about the Window Registry one, how do I find out which register to delete?… As for the sys####.exe, I'll follow your instructions… Thanks!
Delete the ones that Panda found.

Go here http://www.billsway.com/vbspage/ and download, unzip and run the Registry Search Tool. Type Altnet in the dialog box. Let it run and after a few minutes, a prompt will appear. Click OK to write the results to Notepad and post them here.
One thing that I do know is that Panda does give false positives and the Altnet entry in the registry must be one of them. How are you going with the other files?
Hi Crunchie, I started to check the other sys####.exe files that I mentioned earlier with the link you gave me and they all were malware, I did not check them all though, they were a lot so we gave up and decided to reformat and reinstall, which I did and now everything is up-to-date and working… I am just finishing everything up… I am sorry for not hanging in there but my friend was becoming more frustrated than I, so insisted on dumping the whole thing and start from scratch… Now he's on SP2, fully updated, with Norton Antvirus and Firewall fully working, besides MS AntiSpyware. SpywareBlaster and Spybot just in case… I hope he learns from this experience, I sure have… To you everyone else, thanks for all your support!…
Cool. Glad that you got it sorted out anyway.

This topic is now closed.

If you need this topic reopened, please request this by sending an email to us at the following link
(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI