This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

They got me! Drats....

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I tried running Panda and I got shut down after about ten minutes. It only took two trips through safe mode to get back up. Don't know if it will help, but Dr. Watson mentions these two items- 1- "The following system modules have been modified("patched") in memory" Windows KB891711 component 2- "The following modules have intercepted ("hooked") various aspects of the system." HookType- Shell HookedBy- MMSYSTEM.DLL Application- mmtask.tsk
I have three new items on today's HijackThis log- Running processes: C:\WINDOWS\SPEEDY.SCR And- F1 - win.ini: run=c:\windows\speedy.scr O4 - HKLM\..\Run: [Spees1] C:\WINDOWS\Speedy.scr In the code for "speedy!" is this section- run=C:\WINDOWS\NATAL!.PIFc:\windows\natal!.pif,c:\windows\speedy.bat,c:\windows\speedy.scr,c:\windows\scrsvr.exe,c:\windows\marco!.scr,c:\windows\puta!!.com,c:\windows\instit.bat,c:\windows\speedy.pif,c:\windows\Brasil.pif,c:\windows\Brasil.exe,c:\windows\nat,c:\windows\alevir.exe Of the files listed in that section I can only find two of the speedy files. I'm back to having a constant data stream/exchange while online.
Ok, let's take another look at it.

Please reboot your computer in Safe Mode by doing the following:
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
  • Instead of Windows loading as normal, a menu should appear
  • Select the first option, to run Windows in Safe Mode.
For additional help in booting into Safe Mode, see this site.
Then run HJT and generate a new log. Save it to a file and then reboot into normal mode. Post the log here for me to review.
Here's the new HJT log generated while in safe mode-

Logfile of HijackThis v1.99.1
Scan saved at 12:00:40 PM, on 7/16/2005
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v5.50 (5.50.4134.0100)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\A - MY DOCUMENTS\HIJACK_THIS\HIJACKTHIS.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.metacrawler.com/index.html
F1 - win.ini: run=c:\windows\speedy.scr,c:\windows\speedy.bat
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [PCHealth] C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s
O4 - HKLM\..\Run: [SiS KHooker] C:\Program Files\SiS630_V1.04.54\utility\3d\khooker.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [THGuard] "C:\PROGRAM FILES\TROJANHUNTER 4.2\THGUARD.EXE"
O4 - HKLM\..\Run: [Spees1] C:\WINDOWS\Speedy.scr
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [SSDPSRV] C:\WINDOWS\SYSTEM\ssdpsrv.exe
O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
O4 - HKLM\..\RunServices: [KB891711] C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
O4 - Startup: Refresh.lnk = C:\Program Files\Iomega\Tools\REFRESH.EXE
O4 - Startup: Resume Windows Update Installation.lnk = C:\WINDOWS\Windows Update Setup Files\ie6setup.exe
O15 - Trusted Zone: http://forums.tomcoyote.org
O16 - DPF: {106E49CF-797A-11D2-81A2-00E02C015623} (AlternaTIFF ActiveX) - http://www.alternatiff.com/install/00/alttiff.cab
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - http://www.lizardtech.com/software/express…tall/isetup.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
Reboot into safe mode, then run HijackThis and click "Scan." Place checks next to the following entries:
F1 - win.ini: run=c:\windows\speedy.scr,c:\windows\speedy.bat
O4 - HKLM\..\Run: [Spees1] C:\WINDOWS\Speedy.scr


Close all browser and other windows except for HijackThis, and click "Fix Checked" to have HijackThis fix the entries you checked.

Delete the following files, if found:
c:\windows\speedy.scr <–This file
c:\windows\speedy.bat <–This file

Reboot your computer and post a new HJT log.
I ran HJT in safe mode, fixed the checked files (there were three speedy related entries to fix), and deleted three "speedy" files, one was an msdos batch file. Here's the new log which was done in safe mode-

Logfile of HijackThis v1.99.1
Scan saved at 12:32:27 PM, on 7/16/2005
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v5.50 (5.50.4134.0100)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\A - MY DOCUMENTS\HIJACK_THIS\HIJACKTHIS.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.metacrawler.com/index.html
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [PCHealth] C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s
O4 - HKLM\..\Run: [SiS KHooker] C:\Program Files\SiS630_V1.04.54\utility\3d\khooker.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [THGuard] "C:\PROGRAM FILES\TROJANHUNTER 4.2\THGUARD.EXE"
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [SSDPSRV] C:\WINDOWS\SYSTEM\ssdpsrv.exe
O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
O4 - HKLM\..\RunServices: [KB891711] C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
O4 - Startup: Refresh.lnk = C:\Program Files\Iomega\Tools\REFRESH.EXE
O15 - Trusted Zone: http://forums.tomcoyote.org
O16 - DPF: {106E49CF-797A-11D2-81A2-00E02C015623} (AlternaTIFF ActiveX) - http://www.alternatiff.com/install/00/alttiff.cab
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - http://www.lizardtech.com/software/express…tall/isetup.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
Ok, that looks good. Let's try a scan in safe mode. Please download the free MWAV antivirus tool from here. Save it to the desktop, but don't run it yet.

Reboot into safe mode, then run the MWave scanner. Follow the prompts to scan your system for viruses. Then please post for me the log of infected files from the BOTTOM panel of the scan window. Please remove any lines relating to "Invalid object" as they are not needed at this time.
I've spent a lot of time in safe mode today and once I go in it doesn't want to come out. Here's the list from MicroWorld AV (2 items related to invalid objects were removed)- Object "Alexa Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "AltNet Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "iSearch Spyware/Adware" found in File System! Action Taken: No Action Taken. File C:\Program Files\Lavasoft\Ad-aware 6\UNWISE.EXE tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File C:\Program Files\aaw6181.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File C:\_RESTORE\ARCHIVE\FS22.CAB infected by "Virus.Win9x.Spaces.1445.a" Virus! Action Taken: No Action Taken. File C:\_RESTORE\ARCHIVE\FS41.CAB infected by "Net-Worm.Win32.Opasoft.d" Virus! Action Taken: No Action Taken. File C:\_RESTORE\ARCHIVE\FS43.CAB infected by "Net-Worm.Win32.Opasoft.d" Virus! Action Taken: No Action Taken. File C:\_RESTORE\ARCHIVE\FS67.CAB infected by "Virus.Win32.FunLove.4070" Virus! Action Taken: No Action Taken.
Ok, two good scans. I think I might have a way now to check your system files. Let's see if it works. Please go to Start -> Programs -> Accessories -> System Tools -> System Information. From the Tools menu, choose the System File Checker. Choose the 'Scan for Altered Files' option. Click Ok, then click Start. This will run the System File Checker. Follow the prompts, and insert your Windows installation CD if requested. Then please restart your computer.
I don't have a System File Checker, according to Help I have System File Protection which only works through windows update.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI