This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

help please =(

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

the exe fix didnt solve the problem, still getting the same message as before about not having permission or whatever.

I cant get active scan to work at the link on the site for some reason….
also there was some information for XP users on the site….

"In Windows Millennium and Windows XP computers you may find that after the virus has been removed, the antivirus detects it in _restore folder over and over again, and is not able to delete it. This happens because of a special feature of Windows Millennium and Windows XP, which does not pose any threat. However, it can worry users who are not familiar with the functioning of this folder."

the AVG is repeatedly finding the virus and unable to heal or delete it so it sounds like this may be why… however the clicky there for XP users is not working for me… looks like a javascript problem, but i added the site to my trusted zone which should have that enabled. dont know what the problem is but think that this may help me resolve some of the problems.

http://www.pandasoftware.com/support/card….VirEnciclopedia
heh yeah but it doesnt say anything about a restore folder.. the detection keeps specifying the paths to each exe file like the one i mentioned before for my isp dialer. another example is this one which is popped up now: C:\Program Files\InterActual Player\iPlayer.exe Virus found Win32/Parite
Well lets do this and see what happens:

1.
Open C:\Windows\Prefetch\ Delete ALL files in this folder.


2.
1. Open My Computer
2. Right click on your hard drive that you wish to clean (C drive, for example)
3. In the context menu that opens, select properties
4. Under the general tab you should select Disk Cleanup
5. Windows will scan your drive which will take a few seconds/minutes
6. A box will display the various files you can remove.
Check all boxes except compress old files (If listed)
7. Click OK and windows will comply.


3.
Note: This will remove all previous Restore Points

Turn off System Restore:

On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply, and then click OK.

Restart your computer, turn it back on.

On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Remove the Check Turn off System Restore.
Click Apply, and then click OK.

Click Start> My Computer, select the Tools menu and then Folder Options, after the new window appears select the View tab…]
This time select the: Restore Defaults
Select: Apply, and click OK
ok something bad happened.. i dont know if the virus did it or if i deleted something on accident but on reboot windows would not start and some file was missing or not working… so i put the XP disc in but wasnt able to repair so it reinstalled windows over the previous installation which wiped a lot of things out. it did not format the drive tho… so now a lot of programs dont work and windows was reinstalled… the virus is still intact im sure so im aggrivated.. if i format my drive and completely wipe it then reinstall everything will it solve my problems?

if i format my drive and completely wipe it then reinstall everything will it solve my problems?

If you go that route, be sure to have Ad-Aware, SpyBot and a Anti-Virus program loaded before launching the internet.
I didnt want to reformat… i had like 6 months ago. i dont have really that much to worry about losing… at least i got back in windows to save some of my old files that i did want to keep. going to burn them to disc, reformat, install the spybot, adaware, AVG, antispyware beta, and the other software related. then once i get internet up ill post here once more with logs from ewido and hijack this just to be sure nothing survived. last time i was infected a virus called systmesy survived a format somehow. stuff is so messed up now its prolly better i just wipe and as frustrating as it is, it will be done quick enough and id be happy to just be done with this. thanks again for your help
Glad you were able to save the important stuff. Try to have as much protection as possible before launching the internet. After you're finished, post a new log back here :thumbup:
ok i did install everything i could before connecting to the internet…
ewido picked up on two items that were infecting me still

one was in w32 named backdoor.fb or something.. exe file
and the other was named mousehs which tried to change lsp i believe but i blocked it with ms antispyware. it is in the hijack log.

im on the alternate computer because even though that computer does connect to the internet it gets hijacked by the time i get to the tomcoyote site… then everything is froze and i cant even get taskmanager open so have to shut down and restart.

i have ewido scanning currently which will take a bit. even tho it did find those files before the scan it was unable to cure them apparently. Ill save that scan log also and post it next.

Logfile of HijackThis v1.99.1
Scan saved at 10:15:08 PM, on 5/30/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Analog Devices\SoundMAX\spkrmon.exe
C:\Program Files\Verizon Online\WinPoET\WrOS.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Documents and Settings\Scott\Desktop\Misc\Anti-ScumWare\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://cgi.verizon.net/bookmarks/bmredir.a….0&bm=ho_search
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://cgi.verizon.net/bookmarks/bmredir.a…=4.0&bm=ho_home
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer customized for Verizon Online
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~2\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - Global Startup: Verizon Online Account Setup.lnk = C:\Program Files\Verizon Online\VOLSW\Accstp4.0.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O17 - HKLM\System\CCS\Services\Tcpip\..\{662255AB-5067-43A8-A36D-B429079B2F29}: NameServer = 151.202.0.84 151.203.0.84
O17 - HKLM\System\CS1\Services\Tcpip\..\{662255AB-5067-43A8-A36D-B429079B2F29}: NameServer = 151.202.0.84 151.203.0.84
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - Unknown owner - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe (file missing)
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - Unknown owner - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe (file missing)
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: Mouse Hardware Sync (mousehs) - Unknown owner - C:\WINDOWS\System32\mousehs.exe (file missing)
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: spkrmon - Unknown owner - C:\Program Files\Analog Devices\SoundMAX\spkrmon.exe
O23 - Service: WinPPPoverEthernet - iVasion, a Routerware Company - C:\Program Files\Verizon Online\WinPoET\WrOS.EXE
also the ewido scan did come up as clean…even though it did alert the two programs earlier (from post before this one) and was unable to clean them. AVG and antispyware both came up clean as well.
I suggest you do this:

Run hijackthis. Hit None of the above, Click Do a System Scan Only. Put a Check in the box on the left side on these:

O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm

O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm


O23 - Service: Mouse Hardware Sync (mousehs) - Unknown owner - C:\WINDOWS\System32\mousehs.exe (file missing)

Close ALL windows and browsers except HijackThis and click "Fix checked"


Empty Recycle Bin

Reboot and "copy/paste" a new log file into this thread.
Also please describe how your computer behaves at the moment.
overnight spybot found 3 things (alexa related and ipInsight), and adaware found 14 things… MRU lists and 5 alexa related.

i looked in the ewido quarantine also and found those other files.
backdoor.fb (w32\.exe) – (3 of these 2 were not start up and 1 was)
and the mousehs.exe

The first two items you posted to FIX on hijack this were gone, prolly from the spybotSD and adaware scans. so i fixed the mousehs.exe, emptied the quarantine, made sure recycle bin was empty, rebooted and ran hijack… the mousehs file came back again and while typing this ewido just popped up with alert for backdoor.SdBot.xd (C:\WINDOWS\System32\eraseme_48246). When i attempted to clean or quarantine it the ewido security guard crashed. rebooted the ewido guard and then it successfully quarantined it and i removed it permanently (i hope). :ph34r:


this scan shows mousehs again but i saved the scan and then hit fix on it again (second time since your last post).


Logfile of HijackThis v1.99.1
Scan saved at 9:38:56 AM, on 5/31/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Analog Devices\SoundMAX\spkrmon.exe
C:\Program Files\Verizon Online\WinPoET\WrOS.EXE
C:\Documents and Settings\Scott\Desktop\Misc\Anti-ScumWare\HijackThis.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\wuauclt.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://cgi.verizon.net/bookmarks/bmredir.a….0&bm;=ho_search
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://cgi.verizon.net/bookmarks/bmredir.a…=4.0&bm;=ho_home
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer customized for Verizon Online
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~2\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - Global Startup: Verizon Online Account Setup.lnk = C:\Program Files\Verizon Online\VOLSW\Accstp4.0.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{662255AB-5067-43A8-A36D-B429079B2F29}: NameServer = 151.202.0.84 151.203.0.84
O17 - HKLM\System\CS1\Services\Tcpip\..\{662255AB-5067-43A8-A36D-B429079B2F29}: NameServer = 151.202.0.84 151.203.0.84
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: Mouse Hardware Sync (mousehs) - Unknown owner - C:\WINDOWS\System32\mousehs.exe (file missing)
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: spkrmon - Unknown owner - C:\Program Files\Analog Devices\SoundMAX\spkrmon.exe
O23 - Service: WinPPPoverEthernet - iVasion, a Routerware Company - C:\Program Files\Verizon Online\WinPoET\WrOS.EXE

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI