This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

They got me! Drats....

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

When I use Spybot's "Tools->System Startup" I get interesting descriptions for some of the items. It suggests that two are not needed and that three of them are added by various trojans.
I once again tried to run the "eTrust Antivirus Web Scanner". It quickly found five items in C:\_RESTORE\ARCHIVE, the same four that MicroWorld found and one more "opaserve". I stopped the scan to prevent a crash. The scan says that it "cannot cure" the files but does offer me the option of deleting them. Should I delete them?
Running "eTrust Antivirus Web Scanner" from start to finish hasn't worked. I have been able to run it one folder at a time with no more results than previously found.
I uninstalled adaware, downloaded a new copy and reinstalled it. I started the first scan before I realized that I should try it in safe mode. I stopped it long before it finished but it had already found the Alexa file, first item on the list. I then reran the scan in safe mode and it generated the "MRU" list. I'm going to get back offline and try to run a complete normal adaware scan. The eight cookies found aren't included in the adaware log- ALEXA »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» obj[0]=RegValue : .DEFAULT\software\microsoft\internet explorer\extensions\cmdmapping "{c95fe080-8f5d-11d2-a20b-00aa003c157a}" MRU LIST »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» obj[0]=MRU RegReference : .DEFAULT\software\microsoft\direct3d\mostrecentapplication name obj[1]=MRU RegReference : software\microsoft\direct3d\mostrecentapplication name obj[2]=MRU RegReference : .DEFAULT\software\microsoft\direct3d\mostrecentapplication name obj[3]=MRU RegReference : software\microsoft\direct3d\mostrecentapplication name obj[4]=MRU RegReference : software\microsoft\directdraw\mostrecentapplication name obj[5]=MRU RegReference : .DEFAULT\software\microsoft\directinput\mostrecentapplication name obj[6]=MRU RegReference : .DEFAULT\software\microsoft\directinput\mostrecentapplication id obj[7]=MRU RegReference : .DEFAULT\software\microsoft\internet explorer download directory obj[8]=MRU RegReference : .DEFAULT\software\microsoft\internet explorer\main save directory obj[9]=MRU RegReference : .DEFAULT\software\microsoft\internet explorer\typedurls obj[10]=MRU RegReference : .DEFAULT\software\microsoft\mediaplayer\player\recentfilelist obj[11]=MRU RegReference : .DEFAULT\software\microsoft\mediaplayer\player\settings saveasdir obj[12]=MRU RegReference : .DEFAULT\software\microsoft\mediaplayer\player\settings opendir obj[13]=MRU RegReference : .DEFAULT\software\microsoft\mediaplayer\preferences cdrecordpath obj[14]=MRU RegReference : .DEFAULT\software\microsoft\mediaplayer\preferences lastplaylistindex obj[15]=MRU RegReference : .DEFAULT\software\microsoft\mediaplayer\preferences lastplaylist obj[16]=MRU RegReference : .DEFAULT\software\microsoft\windows\currentversion\applets\paint\recent file list obj[17]=MRU RegReference : .DEFAULT\software\microsoft\windows\currentversion\applets\regedit lastkey obj[18]=MRU RegReference : .DEFAULT\software\microsoft\windows\currentversion\applets\wordpad\recent file list obj[19]=MRU RegReference : .DEFAULT\software\microsoft\windows\currentversion\explorer\comdlg32\lastvisitedmru obj[20]=MRU RegReference : .DEFAULT\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru\* obj[21]=MRU RegReference : .DEFAULT\software\microsoft\windows\currentversion\explorer\recentdocs\.HTM obj[22]=MRU RegReference : .DEFAULT\software\microsoft\windows\currentversion\explorer\recentdocs\Folder obj[23]=MRU RegReference : .DEFAULT\software\microsoft\windows\currentversion\explorer\recentdocs\.jpg obj[24]=MRU RegReference : .DEFAULT\software\microsoft\windows\currentversion\explorer\recentdocs\.INI obj[25]=MRU RegReference : .DEFAULT\software\microsoft\windows\currentversion\explorer\recentdocs\.WAB obj[26]=MRU RegReference : .DEFAULT\software\microsoft\windows\currentversion\explorer\recentdocs\.inf obj[27]=MRU RegReference : .DEFAULT\software\microsoft\windows\currentversion\explorer\recentdocs\.Txt obj[28]=MRU RegReference : .DEFAULT\software\microsoft\windows\currentversion\explorer\recentdocs\.zip obj[29]=MRU RegReference : .DEFAULT\software\microsoft\windows\currentversion\explorer\recentdocs\.sid obj[30]=MRU RegReference : .DEFAULT\software\microsoft\windows\currentversion\explorer\recentdocs\.doc obj[31]=MRU RegReference : .DEFAULT\software\microsoft\windows\currentversion\explorer\recentdocs\.bmp obj[32]=MRU RegReference : .DEFAULT\software\microsoft\windows\currentversion\explorer\recentdocs\.exe obj[33]=MRU RegReference : .DEFAULT\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru\mpg obj[34]=MRU RegReference : .DEFAULT\software\microsoft\windows\currentversion\explorer\runmru obj[35]=MRU RegReference : .DEFAULT\software\microsoft\windows media\wmsdk\general computername obj[36]=MRU RegReference : .DEFAULT\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru\sample obj[37]=MRU RegReference : .DEFAULT\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru\mpeg obj[38]=MRU RegReference : .DEFAULT\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru\sized obj[39]=MRU RegReference : .DEFAULT\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru\rm obj[40]=MRU RegReference : .DEFAULT\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru\avi obj[41]=MRU RegReference : .DEFAULT\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru\wmv obj[42]=MRU RegReference : .DEFAULT\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru\wav obj[43]=MRU RegReference : .DEFAULT\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru\txt obj[44]=MRU RegReference : .DEFAULT\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru\sid obj[45]=MRU RegReference : .DEFAULT\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru\tif obj[46]=MRU RegReference : .DEFAULT\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru\com02 obj[47]=MRU RegReference : .DEFAULT\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru\ssd obj[48]=MRU RegReference : .DEFAULT\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru\gz obj[49]=MRU RegReference : .DEFAULT\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru\lnk obj[50]=MRU RegReference : .DEFAULT\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru\log
I was able to run a normal adaware scan, found two more MRU's- MRU LIST »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» obj[0]=MRU RegReference : .DEFAULT\software\microsoft\directinput\mostrecentapplication name obj[1]=MRU RegReference : .DEFAULT\software\microsoft\directinput\mostrecentapplication id I tried twice to run a normal WMAV scan but it shut down both times. Tried to get online and was shut down and sent off to safe mode. Ran WMAV in safe mode and came up with 1 invalid object and the following- Object "AltNet Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "iSearch Spyware/Adware" found in File System! Action Taken: No Action Taken. Following advice found on eTrust I disabled/enabled system restore, removing the the items that the previous MWAV scan found in _RSTORE\ARCHIVES.
I am checking with some site experts now to see what we can do next. The instability of the system is the major problem to diagnosing what's going on. Do you get any sort of error message when it shuts down?
Please click this link to download Silent Runners >>>>> http://www.silentrunners.org/Silent%20Runners.vbs
* Save it to the desktop.
* Run Silent Runner's by doubleclicking the "Silent Runners" icon on your desktop.
* You will see a text file appear on the desktop - it's not done yet, just let it run (it won't appear to be doing anything!)
* Once you receive the prompt "All Done!", double-click on the new text file on the desktop and copy that entire log and paste it here.

*NOTE* If you receive any warning message about scripts, please choose to allow the script to run.
Sorry for the delay in responding, got called into work today. I don't get an error message on shut down. Am going to go play with "Silent Runners".
Here's the log from Silent Runners-

"Silent Runners.vbs", revision 39, http://www.silentrunners.org/
Operating System: Windows Me (Millennium Edition)
Output limited to non-default values, except where indicated by "{++}"


Startup items buried in registry:
———————————

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
"ScanRegistry" = "C:\WINDOWS\scanregw.exe /autorun" [MS]
"TaskMonitor" = "C:\WINDOWS\taskmon.exe" [MS]
"PCHealth" = "C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s" [MS]
"SiS KHooker" = "C:\Program Files\SiS630_V1.04.54\utility\3d\khooker.exe" ["Silicon Integrated Systems Corporation"]
"SystemTray" = "SysTray.Exe" [MS]
"SiS Tray" = (empty string)
"LoadPowerProfile" = "Rundll32.exe powrprof.dll,LoadCurrentPwrScheme" [MS]
"THGuard" = ""C:\PROGRAM FILES\TROJANHUNTER 4.2\THGUARD.EXE"" ["Mischel Internet Security"]

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices\ {++}
"LoadPowerProfile" = "Rundll32.exe powrprof.dll,LoadCurrentPwrScheme" [MS]
"SchedulingAgent" = "mstask.exe" [MS]
"SSDPSRV" = "C:\WINDOWS\SYSTEM\ssdpsrv.exe" [MS]
"*StateMgr" = "C:\WINDOWS\System\Restore\StateMgr.exe" [MS]
"KB891711" = "C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE" [MS]

HKLM\Software\Microsoft\Active Setup\Installed Components\
PerUser_CVT_Inis\(Default) = "Windows Setup - FAT32 Converter"
\StubPath = "rundll.exe C:\WINDOWS\SYSTEM\setupx.dll,InstallHinfSection PerUser_CVT_Inis 64 C:\WINDOWS\INF\applets1.inf" [MS]
PerUser_Enable_Inis\(Default) = "Windows Setup - Accessibility"
\StubPath = "rundll.exe C:\WINDOWS\SYSTEM\setupx.dll,InstallHinfSection PerUser_Enable_Inis_remove 64 C:\WINDOWS\INF\enable.inf" [MS]
PerUser_ZoneGame_Inis\(Default) = "Windows Setup - Internet Games"
\StubPath = "rundll.exe C:\WINDOWS\SYSTEM\setupx.dll,InstallHinfSection PerUser_ZoneGame_Rem_Inis 64 C:\WINDOWS\INF\games.inf" [MS]
PerUser_PBGame_Inis\(Default) = "Windows Setup - Plus! Games"
\StubPath = "rundll.exe C:\WINDOWS\SYSTEM\setupx.dll,InstallHinfSection PerUser_PBGame_Rem_Inis 64 C:\WINDOWS\INF\games.inf" [MS]
{44BBA842-CC51-11CF-AAFA-00AA00B6015C}\(Default) = "NetMeeting 3.01"
\StubPath = "rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Remove.PerUser.W95" [MS]

HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
"{e57ce731-33e8-4c51-8354-bb4de9d215d1}" = "Universal Plug and Play Devices"
-> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\SYSTEM\UPNPUI.DLL" [MS]
"{EFA24E64-B078-11d0-89E4-00C04FC9E26E}" = "Explorer Band"
-> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\SYSTEM\BROWSEUI.DLL" [MS]

HKLM\Software\Classes\*\shellex\ContextMenuHandlers\
TrojanHunter\(Default) = "{EBDF1F20-C829-11D1-8233-FF20AF3E97A9}"
-> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\TROJAN~1.2\CONTMENU.DLL" [null data]

HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\
TrojanHunter\(Default) = "{EBDF1F20-C829-11D1-8233-FF20AF3E97A9}"
-> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\TROJAN~1.2\CONTMENU.DLL" [null data]

HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\
TrojanHunter\(Default) = "{EBDF1F20-C829-11D1-8233-FF20AF3E97A9}"
-> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\TROJAN~1.2\CONTMENU.DLL" [null data]


Active Desktop and Wallpaper:
—————————–

Active Desktop is disabled at this entry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState


Startup items in "Startup" & "All Users…Startup" folders:
———————————————————–

C:\WINDOWS\Start Menu\Programs\StartUp
"Refresh" -> shortcut to: "C:\Program Files\Iomega\Tools\REFRESH.EXE" ["Iomega"]


Enabled Scheduled Tasks:
————————

"PCHealth Scheduler for Data Collection" -> launches: "C:\WINDOWS\PCHEALTH\SUPPORT\PCHSCHD.EXE -c" [MS]
"Tune-up Application Start" -> launches: "walign" [MS]


Winsock2 Service Provider DLLs:
——————————-

Namespace Service Providers

HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}
000000000001\LibraryPath = "C:\WINDOWS\SYSTEM\rnr20.dll" [MS]

Transport Service Providers

HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}
00000000000#\PackedCatalogItem (contains) DLL [Company Name], (at) # range:
C:\WINDOWS\SYSTEM\mswsosp.dll [MS], 1
C:\WINDOWS\SYSTEM\msafd.dll [MS], 2 - 4
C:\WINDOWS\SYSTEM\rsvpsp.dll [MS], 5 - 6


———-
+ This report excludes default entries except where indicated.
+ To see *everywhere* the script checks and *everything* it finds,
launch it from a command prompt or a shortcut with the -all parameter.
+ The search for DESKTOP.INI DLL launch points on all local fixed drives
took 9 seconds.
+ The search for all Registry CLSIDs containing dormant Explorer Bars
took 13 seconds.
———- (total run time: 43 seconds)
Hmm, I don't see anything there. Let's try another specialized scanner. Please download StartDreck from here. Unzip it to the desktop and run it. Click Config, and choose "Unmark all". Then select only "Run Keys" under "Registry" and "Running Processes" under "System/Drivers" and click OK. Click Refresh, and Save to save a log. Then post the log here for me.
Here's the StartDreck log- StartDreck (build 2.1.7 public stable) - 2005-07-19 @ 00:12:39 (GMT -04:00) Platform: Windows ME (Win 4.90.3000 ) Internet Explorer: 5.50.4134.0100 Logged in as user at Z9H6E0 »Registry »Run Keys »Current User »Run »RunOnce »Default User »Run »RunOnce »Local Machine »Run *ScanRegistry=C:\WINDOWS\scanregw.exe /autorun *TaskMonitor=C:\WINDOWS\taskmon.exe *PCHealth=C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s *SiS KHooker=C:\Program Files\SiS630_V1.04.54\utility\3d\khooker.exe *SystemTray=SysTray.Exe *SiS Tray= *LoadPowerProfile=Rundll32.exe powrprof.dll,LoadCurrentPwrScheme *THGuard="C:\PROGRAM FILES\TROJANHUNTER 4.2\THGUARD.EXE" »RunOnce »RunServices *LoadPowerProfile=Rundll32.exe powrprof.dll,LoadCurrentPwrScheme *SchedulingAgent=mstask.exe *SSDPSRV=C:\WINDOWS\SYSTEM\ssdpsrv.exe **StateMgr=C:\WINDOWS\System\Restore\StateMgr.exe *KB891711=C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE »RunServicesOnce »RunOnceEx »RunServicesOnceEx »Files »System/Drivers »Running Processes +FFEF5CE9=C:\WINDOWS\SYSTEM\KERNEL32.DLL +FFFF9A09=C:\WINDOWS\SYSTEM\MSGSRV32.EXE +FFFF9271=C:\WINDOWS\SYSTEM\SPOOL32.EXE +FFFFFD69=C:\WINDOWS\SYSTEM\MPREXE.EXE +FFFE13E9=C:\WINDOWS\SYSTEM\mmtask.tsk +FFFEB5F9=C:\WINDOWS\SYSTEM\MSTASK.EXE +FFFE9DB5=C:\WINDOWS\SYSTEM\SSDPSRV.EXE +FFFEDFD9=C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE +FFFE460D=C:\WINDOWS\EXPLORER.EXE +FFE14061=C:\WINDOWS\TASKMON.EXE +FFE15625=C:\PROGRAM FILES\SIS630_V1.04.54\UTILITY\3D\KHOOKER.EXE +FFE1FE0D=C:\WINDOWS\SYSTEM\SYSTRAY.EXE +FFE07271=C:\WINDOWS\SYSTEM\WMIEXE.EXE +FFE0F03D=C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE +FFE3B895=C:\WINDOWS\SYSTEM\STIMON.EXE +FFE57931=C:\WINDOWS\SYSTEM\DDHELP.EXE +FFE23609=C:\WINDOWS\SYSTEM\PSTORES.EXE +FFE5BD8D=C:\WINDOWS\SYSTEM\RNAAPP.EXE +FFE2AC91=C:\WINDOWS\SYSTEM\TAPISRV.EXE +FFE5CC01=C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE +FFE51ADD=C:\WINDOWS\SYSTEM\WBEM\WINMGMT.EXE +FFE776D1=C:\WINDOWS\DESKTOP\STARTDRECK.EXE »Application specific
I just refreshed it twice, that's all it gives me. Today I've found- Podre! Banda! natal!! marco! instit scrsvr brasil and three files in C\_RESTORE\TEMP- A0006342 A0006343 A0006408 All files have a modified date of 01/01/1970
Ok, let's try cleaning some things to see if that will help your problem with defragmenting. Download: CCleaner (freeware)
http://www.majorgeeks.com/download4191.html
Once installed, run CCleaner click the Windows
Select the following:
[external image: Posted Image]
Next: click Options click the Settings tab
Uncheck: "Only delete files older than 48 hrs.", click Ok
Then click Run Cleaner (bottom right) then Exit.

Reboot, then try running the Defragmenter again.

After that, please reboot your computer and post a new HJT log.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI