This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Hd Space Shrinking And Fast!

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, My computer's been infected with some sort of virus. I can't get rid of it, and every time I scan my computer, it just replicates itself even more!. It resides in C:\Program Files\Norton Antivirus\Quarantine, and is usually in the form of a .TMP file or .htm file. They're usually around 20 MB, and every time i delete them, they just come out again. In C:\Program Files\Norton Antivirus\Quarantine\Incoming, files starting from AP0.TMP to AP999.TMP is created, and some are deletable, but most of them aren't. When I try to delete them, it says it's being used by another program. I've run Ad-Aware, after updating it today and there's still no change. I'm running windows 2000, my computer is usually from 9% - 20% CPU usage, and is using 238166 KB out of 523756 physical memory. (RAM) The processes that I have running now are:
System Idle Process
System
taskmgr.exe
smss.exe
winlogon.exe
csrss.exe
services.exe
lsass.exe
Ati2evxx.exe
smc.exe
svchost.exe
spoolsv.exe
ccEvtMgr.exe
AVGUARD.EXE
avgupsvc.exe
AVWUPSRV.EXE
Ati2evxx.exe
svchost.exe
GHOSTS~2.EXE
navapsvc.exe
regsvc.exe
svchost.exe
MSTask.exe
WinMgmt.exe
svchost.exe
IEXPLORE.EXE
Explorer.EXE
atiptaxx.exe
jusched.exe
LCDPlyer.exe
avgcc.exe
MsgPlus.exe
AVGNT.EXE
SOUNDMAN.EXE
realsched.exe


Here is my HJT Log:
Logfile of HijackThis v1.99.1
Scan saved at 8:55:31 PM, on 3/25/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\SYSTEM32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\Ati2evxx.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\AVPersonal\AVGUARD.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\AVPersonal\AVWUPSRV.EXE
C:\WINNT\system32\svchost.exe
C:\PROGRA~1\Symantec\NORTON~1\GHOSTS~2.EXE
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\SYSTEM32\Ati2evxx.exe
C:\WINNT\Explorer.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Messenger Plus! 3\MsgPlus.exe
C:\Program Files\AVPersonal\AVGNT.EXE
C:\WINNT\SOUNDMAN.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\SPACE INTERNATIONAL\CDSpace 4.1\LCDPlyer.exe
C:\WINNT\system32\notepad.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\DOCUME~1\Donald\LOCALS~1\Temp\Rar$EX00.375\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: (no name) - {B8D60EBB-5565-4392-957B-7164BA087AD4} - C:\PROGRA~1\INSTAN~1\INSTAN~1.DLL (file missing)
O3 - Toolbar: Instant Bu&zz - {7475D3FD-5D85-49DB-8B9B-6968467B2D80} - C:\PROGRA~1\INSTAN~1\INSTAN~1.DLL (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\Messenger Plus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [AVGCtrl] C:\Program Files\AVPersonal\AVGNT.EXE /min
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvCplScan] nvsc32.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\RunServices: [NvCplScan] nvsc32.exe
O4 - HKCU\..\Run: [NvCplScan] nvsc32.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Symantec Fax Starter Edition Port.lnk = C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
O4 - Global Startup: LCDPlayer.lnk = C:\Program Files\SPACE INTERNATIONAL\CDSpace 4.1\LCDPlyer.exe
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Download with GetRight - C:\Program Files\GetRight\GRdownload.htm
O8 - Extra context menu item: Open with GetRight Browser - C:\Program Files\GetRight\GRbrowse.htm
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: Instant Buzz - {066040F0-5018-4E15-8AA0-81D36136D989} - C:\PROGRA~1\INSTAN~1\INSTAN~1.DLL (file missing)
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_04\bin\npjpi142_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_04\bin\npjpi142_04.dll
O14 - IERESET.INF: START_PAGE_URL=http://hispeed.rogers.com
O16 - DPF: {1DF36010-E276-11D4-A7C0-00C04F0453DD} (Stamps.com Secure Postal Account Registration) - https://secure.stamps.com/download/us/regis…32/sdcregie.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_1_0_0_44.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by13fd.bay13.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Program Files\AVPersonal\AVGUARD.EXE
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINNT\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINNT\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Program Files\AVPersonal\AVWUPSRV.EXE
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: DHCP Management - Unknown owner - C:\WINNT\system32\srvany.exe
O23 - Service: dllhost - Unknown owner - C:\WINNT\system32\srvany.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: DNS - Unknown owner - C:\WINNT\system32\srvany.exe
O23 - Service: FireDaemon Service: eventsec (eventsec) - Unknown owner - C:\winnt\system32\dllcache\FireDaemon.EXE (file missing)
O23 - Service: GhostStartService - Symantec Corporation - C:\PROGRA~1\Symantec\NORTON~1\GHOSTS~2.EXE
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: FireDaemon Service: ntsysvers (ntsysvers) - Unknown owner - C:\winnt\system32\dllcache\FireDaemon.EXE (file missing)
O23 - Service: NvCplScan - Unknown owner - C:\WINNT\system32\nvsc32.exe" -netsvcs (file missing)
O23 - Service: nvscv - Unknown owner - C:\WINNT\system32\srvany.exe
O23 - Service: QTask Management - Unknown owner - C:\WINNT\system32\srvany.exe
O23 - Service: FireDaemon Service: runbatch (runbatch) - Unknown owner - C:\winnt\system32\dllcache\FireDaemon.EXE (file missing)
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: scvhost - Unknown owner - C:\WINNT\system32\srvany.exe
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

Please help me! Thank you

-Darkraver
Hi Darkraver

Sorry for the delay but wanted to check somethings before we started. I will do my best to help you. You seem to have a bunch of Trojans on your computer.


RED or UNDERLINED words are links that can be clicked.

HOW TO

Should you need instructions for:
Showing hidden files and folders in Windows.
Reboot in safe mode. (If you have a keyboard with a "F Lock" key click it so that the "F" light above it is on when you start tapping the "F8" key.)
How to print the fix instructions
Click the red links above.

How to unzip a downloaded zip file.
Place the zip file in the folder where you want the unzipped program to be.
If you are running Windows XP you simply right click the zip file and select "Extract Files".
For the other versions of Windows you will need a program like 7-Zip . Open 7-Zip. Navigate to to the downloaded zipfile and highlight it. Right click and select "Extract Here"

When asked to post a new HijackThis log please
Close all windows and browsers.
Find the HijackThis folder. Open it and double click "HijackThis.exe". Click "Do a system scan" and save a "logfile". (If Hijack this shows you a "Scan" button it is OK.)
The "Scan" button will change into a "Save Log" button. Click it. Click "Ctrl-A" (the "Ctrl" key and the "A" key at the same time) to highlight the whole log. Now click "Ctrl-C" to copy the text. Open this topic and click the "Add Reply" button at the bottom of the page. Paste the log into the window that opens up by clicking "Ctrl-V". Click "Add Reply" to post.


1. Please copy the instructions to a notepad or preferably print them.

2. Make sure to work through the fixes exactly as given and in the exact order they are mentioned below.

3. If there's anything that you don't understand, ask your question(s) before proceeding with the fixes.

4. IMPORTANT. Must be done before start of cleanup.
Your copy of HijackThis needs to be in a permanent folder of it's own. When HJT fixes anything, it makes backups of the original files in the folder it is in. For this reason it cannot be run from a Zip file or from Temporary folders because the backups will be deleted. Having the backups could be VITAL to restoring your system if something went wrong in the FIX process!

a. Please go to your 'My Documents' folder, right-click and select 'New > Folder' then name the folder 'HJT'.

b. Copy and paste HijackThis.exe to the new folder.

DO NOT MAKE ANY CHANGES OR CLICK "FIX CHECKED" UNTIL INSTRUCTED TO DO SO. SOME OF THE FILES ARE LEGIT AND VITAL TO YOUR COMPUTER'S HEALTH

5. Configure Windows to show all files.

6. IMPORTANT You have more than one (it looks like three) antivirus pograms running. Decide which one you want to keep running and disable the others. If they are running simultanious there is a high likelyhood of problems. This is a case wher more is not better as the can interact with eachother and cuse instability and other problems.

6. Download "Stinger" here . Read the instructions. Click on download "Stinger.exe". Find the downloaded file and run it. save the log and post it with your next post.

7. I know that you have run Ad-Aware but I want to be sure that it run insuch a way that it has the best chances to clean up what it finds.
Download the latest version of Ad-Aware SE (Ad-Aware SE Build 1.05).

If you have a previous version of Ad-Aware installed, during the installation of the new version you will be prompted to uninstall or keep the older version - be sure to uninstall the previous version.

After installing Ad-aware, you will be prompted to update the program and run a full scan. De-select all boxes so that it does not run.

Manually run "Ad-Aware SE Personal" and from the main screen Click on "Check for Updates Now".

Once the definitions have been updated:

Reconfigure Ad-Aware for Full Scan as per the following instructions:

-Launch the program, and click on the Gear at the top of the start screen.

-Under General Settings the following boxes should all be checked off: (Checked will be indicated by a green circle with a check mark in it, Un-Checked is a red circle with an X in it. If it is greyed out, those features are only available in the retail version.)

- Automatically save logfile"
- Automatically quarantine objects prior to removal"
- Safe Mode (always request confirmation)
- Prompt to update outdated confirmation) - Change to 7 days.
- Click the "Scanning" button (On the left side).
- Under Drives & Folders, select "Scan within Archives"
- Click "Click here to select Drives + folders" and select your installed hard drives.
- Under Memory & Registry, select all options.
- Click the "Advanced" button (On the left hand side).
- Under "Shell Integration", select "Move deleted files to Recycle Bin".
- Under "Log-file detail", select all options.
- Click on the "Defaults" button on the left.
- Type in the full url of what you want as your default homepage and searchpage e.g. http://www.google.com.
- Click the "Tweak" button (Again, on the left hand side).
- Expand "Scanning Engine" by clicking on the "+" (Plus) symbol) and select the following:
- "Unload recognized processes during scanning."
- "Obtain command line of scanned processes"
- "Scan registry for all users instead of current user only"
- Under "Cleaning Engine", select the following:
-"Automatically try to unregister objects prior to deletion."
-"During removal, unload explorer and IE if necessary"
-"Let Windows remove files in use at next reboot."
- "Delete quarrantined objects after restoring"
- Click on "Safety Settings" and select "Write-protect system files after repair (Hosts file, etc)"
- Click on "Proceed" to save these Preferences.
- Click on the "Scan Now" button on the left.
- Under "Select Scan Mode, be sure to select "Use Custom Scanning Options".

- Close all programs except ad-aware.
- Click on "Next" in the bottom right corner to start the scan.
- Run the Ad-Aware scan and allow it to remove everything it finds and then REBOOT - Even if not prompted to.
- After you log back in, Ad-Aware may run to finalize the scan and remove any locked files that it may of found. Allow it to finish.

Plug-Ins for Ad-Aware (VX2 Cleaner)
Download the free VX2 Cleaner here

Close Ad-Aware SE build 1.05 and Ad-Watch (if running)
Install the VX2 Cleaner
Start Ad-Aware SE build 1.05
Go to “Plug-ins”
Select the VX2 Cleaner plug-in and click “Run Plugin”
If your computer isn’t infected, click “Close”.

If your computer is infected:

Select “Clean System”
Reboot your computer
Scan your computer with Ad-Aware
Remove any VX2 objects detected
Reboot your computer again
Run a second scan to make sure the files have been removed from your computer

Virus warnings while performing a scan with Ad-Aware

While performing a scan with Ad-Aware, a background antivirus monitor may issue an alert, stating that a virus has been found in the temporary directory (%temp%) for the current user. This does not necessarily mean your computer has been infected with an active virus. Most antivirus resident scanners will not scan compressed files and only monitor your memory for the sign of an active viral process.

During a scan, Ad-Aware will temporarily decompress files to scan their contents without activating the content, but in doing so, the file is noticed by the antivirus' resident scanner.

Also, some antivirus applications include an option to quarantine infected files, and when Ad-Aware decompresses these quarantined files, the antivirus background scanner detects the virus moving outside the quarantine area. To avoid this you can either remove the quarantined files via your antivirus application, or have Ad-Aware ignore the antivirus program's quarantine folders/files during a scan.
Then,

8.Download SPYBOT Search and Destroy here if it is not already installed on your computer.

Install the program and then start it. Once the program has started make sure you are in the Spybot-S&D section. Click on the "Search for Updates" button. Download all updates. In some cases the program will restart after an update. When updated, click on the "Check for Problems" button. When the Check is over All problems displayed in red are regarded as real threats and should be dealt with. Make sure they are all selected and click the "Fix selected problems" button.

9. Please use the following link to run the online Virus Scanner and let it fix whatever it finds.
Trend Micro: http://housecall.trendmicro.com/housecall/start_corp.asp

And here are links to two online Trojan Scanners. Run one and let it fix what it finds.
Here: http://scan.sygatetech.com/pretrojanscan.html
Or here: http://www.windowsecurity.com/trojanscan/

10. I would like you to Download a trial version of “TrojanHunter” , update it. Select full scan and select all your hard drives. Run it and let it remove anything it finds. When the scan is finished please save the log and copy it into your next post.

11. We need more information about all the services that running. Please download the following file Getservice.zip
a. Extract the file to the c:\ drive.
b. Then navigate to the c:\getservices and double-click on the getservices.bat file. A notepad will open up with the log.
c. Please paste the contents of that notepad as a reply to this post.

12. Post a new Hijackthis log together with all the other logs and let's take a new look.

I will not be avaiable to answer your next post until tomorrow evening or Sunday morning depending where in the world you reside. Therefore you have a bit of time for all this work.
First off, thanks for all your help. I followed your instructions with these problems:
1. Both of the trojan scanners you told me to go to couldn't scan my ports, since they were blocked, even when I disabled my firewall. (I use sygate)
2. Getservice.bat can't be found by the computer when I double-click it. Every time i try, a window pops up telling me it can't find it.
3. Every few times i go on the internet and go to different pages, Trojanhunter pops up and says I'm infected with Adware.CoolWebSearch.142, even when I clean it.

For some reason, I can't copy and paste my logs into here, so please go here to download the zipped files. Sorry for the inconvenience.

Darkraver
Hi Darkraver:)
I have not forgotten you but your log has forced me to do quite a lot of research. :scratch:
While I am preparing the next set of instructions I have a question: Have you any idea what these services are. Have you set them up or has an administrator or IT person done so to your knowledge? :huh:
O23 - Service: DHCP Management - Unknown owner - C:\WINNT\system32\srvany.exe
O23 - Service: dllhost - Unknown owner - C:\WINNT\system32\srvany.exe
O23 - Service: DNS - Unknown owner - C:\WINNT\system32\srvany.exe
O23 - Service: nvscv - Unknown owner - C:\WINNT\system32\srvany.exe
O23 - Service: QTask Management - Unknown owner - C:\WINNT\system32\srvany.exe
O23 - Service: scvhost - Unknown owner - C:\WINNT\system32\srvany.exe
O23 - Service: FireDaemon Service: eventsec (eventsec) - Unknown owner - C:\winnt\system32\dllcache\FireDaemon.EXE (file missing)
O23 - Service: FireDaemon Service: ntsysvers (ntsysvers) - Unknown owner - C:\winnt\system32\dllcache\FireDaemon.EXE (file missing)
O23 - Service: FireDaemon Service: runbatch (runbatch) - Unknown owner - C:\winnt\system32\dllcache\FireDaemon.EXE (file missing)


Please post your reply as soon as convenient.
Well actually, I have no idea what they are. Firedameon doesn't appear to exist in my system, and I have no idea what srvany does. I did some looking up on Firedameon last year (this problem has been here since then, couldn't fix it before so I'm trying again) and I think it's one of those programs where you can access your computer from another terminal. This probably isn't it, but it was from last year. Also, I've never installed any of the programs where you can access your HD through the internet, too risky. Hope this help! -Darkraver
Hi again Darkraver

The first round got rid of some of the junk and gave me some information about trojans lurking in your system.

However it looks to me as if you still have two antivirus programs runnuing, AVG 7 Free and Norton Antivirus. Please disable one of them You can keep it and use it to do a scan on comand but the realtime scanning is a problem.

1. As Getservices does not seem to work correctly we will try to get the necessary information directly.

a. Copy the following line by highltighting it and using "Ctrl+c" (presssing "Ctrl" and "c" at the same time).
regedit /e C:\Service1.txt HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DHCP Management
b. Go to "Start" > "Run". Paste ("Ctrl+v") the line into the window that opens. Click "Enter". Nothing much seems to happen and the window closes.
c. Repeat the process for each of the following lines:
regedit /e C:\Service2.txt HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\dllhost
regedit /e C:\Service3.txt HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DNS
regedit /e C:\Service4.txt HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\nvscv
regedit /e C:\Service5.txt HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\QTask Management
regedit /e C:\Service6.txt HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\scvhost
regedit /e C:\Service6.txt HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\eventsec
regedit /e C:\Service6.txt HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ntsysvers
regedit /e C:\Service7.txt HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\runbatch


Now go to "Windows explorer" and find C:\Service1.txt. Open it. Copy and paste the context of it to your next post.
Repeat for C:\Service2.txt through C:\Service7.txt.

2. Open HijackThis and click "Do a System Scan Only". (If HijackThis shows a "Scan" button instead of "Do a System Scan Only" that is OK. In that case click "Scan".) When the scan is finished put a check mark by the items that are listed in bold below. If you can not find an item, that is OK. Just continue but inform me with your next post. Do not click fix until instructed to do so:
O2 - BHO: (no name) - {B8D60EBB-5565-4392-957B-7164BA087AD4} - C:\PROGRA~1\INSTAN~1\INSTAN~1.DLL (file missing)
O3 - Toolbar: Instant Bu&zz - {7475D3FD-5D85-49DB-8B9B-6968467B2D80} - C:\PROGRA~1\INSTAN~1\INSTAN~1.DLL (file missing)
O9 - Extra button: Instant Buzz - {066040F0-5018-4E15-8AA0-81D36136D989} - C:\PROGRA~1\INSTAN~1\INSTAN~1.DLL (file missing)

Close all open windows except HijackThis and then click the "Fix checked" button.

3. Download Killbox.zip here
Extract it from the zip file.
Double-click on Killbox.exe to run it. In the 'Paste Full Path of File to Delete' box, copy and paste this entry:
C:\WINNT\system32\root\Fire.exe
Select "Delete on Reboot". Then click the the white X in the red circle. Click yes in the first dialog box to delete at reboot.Click no at the second dialog box and repeat what you just did for each of the following files.
C:\WINNT\system32\hidden32.exe
C:\WINNT\system32\dllcache\runbatch.exe
.
After the last file click yes at the second dialog box to force a reboot.

4. Reboot in "Safe Mode". (Instructions can be found in begining of my second post).

5. Using Windows Explorer please deletethe following folder:
C:\PROGRA~1\INSTAN~1 (~1 means that the name starts with the six letters you see and has at least three more letters.)

6. Reboot in normal mode.

7. * Close ALL windows except "HijackThis"
* SCAN with "HijackThis"
* POST the new log in this thread ogether with the information from the seven Service.txt files using "Add Reply".

This will take at least one more go around to solve but could be more. Sorry about the slow pace of the cleanup.
Thanks for your quick reply! I followed your instructions, and had these problems: 1. I could only find services 2-4, 6, 7. Services1 and Services5 was missing 2. I don't get step number 5. I can't find the folder 3. I can no longer use the delete button on websites, I can't delete the stuff in the history (no delete button), and I can't rightclick. Also, buttons that usually say browse don't work anymore, so I've decided to send my logs to this email: [removed]. The password is in the PM I sent you. As well, I can't copy and paste things into anything web-based (email, here, toolbar, everything) Sorry for the inconvienince. Darkraver
the edit button is missing, so I'll continue my rant here. The history doesn't have any titles (monday, tuesday, etc), I can't copy/paste anything from/to anything web-based. So I can't copy my logs into here, and I can't copy instructions into word. Also, when I try to print, a message pops up and tells me to send a report to microsoft. Also, I cannot right-click on anything on anything web-based, so that means that I can't download (save target as) anything. Also, I cannot download anything period. I click on the download links, but nothing happens. The internet still works, but I'm wondering when that will mess up. I'm at my wits end here, and I just want to format my HD and be done with it. Darkraver
Hi Darkraver.
Sorry for the delay. I have asked some of the experts her at Tom Coyote to advice me as this is an odd looking case.

We suspect that you have been infected with something called a root kit. You also had at least three serious trojans on the machine. The risk is large that any material that you had on the computer has been copied and I would advice you to inform any financial institutions about any account information you had on the computer. Also all passwords are at risk.

The question is if it is not better to your losses and reformat. Your computer seems to deteriorating all the time.

If you decide to continue then

Let's see if we can make any inroads into the infections.

1. Download the trial version of tds-3 anti trojan from here:

http://www.diamondcs.com.au/tds/downloads/tds3setup.exe

install it, but do not launch it yet

update it: right click the link below, select "save as"

http://www.diamondcs.com.au/tds/radius.td3

Save it to the directory where you installed tds-3, overwriting the previous radius.td3.

2. Reboot in safe mode.

3. Launch tds-3. in the top bar of tds window click system testing> full system scan.
Detections will appear in the lower pane of tds window.
After the scan is finished ( it'll take a while ) right click the list> select save as txt.
Save it and post the contents of the scandump.txt here when you get back to normal windows.

After saving the scandump go ahead and right click the list of alarms again, this time select delete…only delete those with POSITIVE IDENTIFICATION.

4. Reboot in Normal Mode.

5. Open HiJackThis, click "Open the Misc Tools Section", and click "Generate StartupList log". Check mark "List also minor sections (Full)" Notepad will open with a log in it. Please add this log to your next post.

6. I would like you to download RootKitRevealer by Sysinternals.com from: http://www.sysinternals.com/ntw2k/freeware…kitreveal.shtml
The web page has a small tutorial about root kits and instructions how to use the program.
Click on SCAN and be prepared to wait. It may take a while.
A log will be produced which I ask you to Post.

7. * Close ALL windows except "HijackThis"
* SCAN with "HijackThis"
* POST the new log together with the other logs in this thread using the method you used last time.

If you decide to reformat I would be very thankful to you if you would run the scans before you do so. I know that it will be time consuming but everything we learn about these infections helps us.

Good luck and if you reformat I am sorry that I could not be of more help to you


Per
I am getting some help now with helping you both here at Tom Coyote and at other forums. It is generating some interest because we do not seemany of this infection and want to know more as well as getting your computer clean. Especially interesting is the Rootkit Revealer log. Per
Thanks for all your help. In light of the new circumstances, I'll probably reformat my HD. But I will run the logs, and attempt to post them here before I reformat. This may take a while before I reply, as I have to back up all my files. Can you please tell me how to reformat the HD? Thank you. Darkraver :(
Hi Darkraver. Do the backup all your files. Do you have your operatiing system and all your necessay progeams available to reinstall? If not then perhaps we should try to get rid of the infection. I know that it is a time consuming task but perhaps it is worthwhile. Per
I think I do, but I'll back up first, since I can't download anything at my own computer. I'll get the logs up ASAP, once I get to another computer. Now, I just have to backup all my stuff first, then if we start making any progress, then I'll probably try getting rid of the infection. If not, I'll have to consider reformatting. Darkraver

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI