This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

PLease Help POPUP POPUP POPUP

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello Again, I did a Reg Search for aama.exe. It didn't find it. I searched for C:\WINNT\System32\?vchost.exe . No file found. I feel like we're on a sniper hunt. lol Dave :huh:
Let's not bring any snipes into this… :rofl:

We've got one to many "critters" as it is…..

I think that NOT finding it in the registry is a good thing. Sometimes when malware dies it gives out a "last gasp", and hopefully this was it for this bug.

Please download APT and unzip the contents to a new folder on your desktop.
  • Open the folder you just created and click on apt.exe and search in the window for C:\WINNT\System32\aama.exe.
  • Open your C:\Windows\system32 folder and search for C:\WINNT\System32\aama.exe.
    Don't delete it yet, just leave the system32 folder open so you can see the bad file.
  • In APT again, Select C:\WINNT\System32\aama.exe and Click Kill3
  • Then immediately delete C:\WINNT\System32\aama.exe from your system32 folder.
Close APT.

Reboot, make a log file and see if the critter comes back.
:)
Good Morning, I downloaded APT and unzipped it. Once I had the APT window open and located C:\WINNT\System32\aama.exe I attempted to hit KILL3. This came up on the screen: "Unable to open a handle to this process." Not sure of my next move so I'll wait to hear back from you. Thanks Jim, I'm leaving on vacation today around 9:30 a.m (EST) and won't be back untill August 22nd. so if you want to "back burner" this problem till then that would be fine w/ me. BEst Regards, Dave :wavey:
Lets' change it to use Kill1 in the APT program.

All other instructions remain the same.

By the time you read this, you will have returned from your vacation.

I hope you had a good time.
:)
Hello my Friend,

I'm back! Tan, Rested, and ready to finish this project!

This machine has been turned on and off several times while I was gone. (Do not turn off sign completely ignored)

I've added a new hyjack log for your veiwing pleasure just to make sure nothing nasty is hanging out in there.



Thanks again for your help. Dave :D

Logfile of HijackThis v1.99.1
Scan saved at 4:19:42 PM, on 8/24/2005
Platform: Windows 2000 SP2 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\PSSVC.EXE
C:\Program Files\NavNT\defwatch.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\NavNT\rtvscan.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\System32\mspmspsv.exe
C:\WINNT\Explorer.EXE
C:\WINNT\loadqm.exe
C:\Program Files\NavNT\vptray.exe
C:\Program Files\Microsoft Hardware\Mouse\point32.exe
C:\WINNT\System32\drivecheck.exe
C:\WINNT\System32\drivecheck.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\My Documents\Anti-Spy\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http://NTEXCHANGE:80
O2 - BHO: MainCtrl Class - {ACB9752A-FB42-436E-84AF-35EA8313A587} - C:\Program Files\Club5678\Ctrl\Club5678Login\ClubLogin40.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [vptray] C:\Program Files\NavNT\vptray.exe
O4 - HKLM\..\Run: [POINTER] point32.exe
O4 - HKLM\..\Run: [PsMgr] C:\Program Files\EveryZone\pcsafer\Psmgr.exe /update
O4 - HKCU\..\Run: [drivecheck] C:\WINNT\System32\drivecheck.exe
O9 - Extra button: Web Entry - {B4E30F61-16D9-11D3-85D1-005004229569} - c:\lotus\organize\bandobjs.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINNT\System32\Shdocvw.dll
O16 - DPF: {0C4A9D28-66B5-4A70-B915-B6AEA5112472} (Icon02 Control) - http://216.17.111.216/icon02.cab
O16 - DPF: {1A6B786C-9062-4B2F-BD76-AD4653FF480E} (Club5678 Update Control) - http://www.club5678.com/etc/activex/ClubCtrl.cab
O16 - DPF: {42291FF4-803F-4C7D-94D4-56A9C98B8376} - http://www.ulisesang.pe.kr/keyserver/f6mvft7h.cab
O16 - DPF: {4E452475-E8F6-4C26-9BA1-8105CB710199} (TvOnline Control) - http://www.everyzone.com/pcsafer/pcsafer.cab
O16 - DPF: {938527D1-CDB7-4147-998A-B20FCA5CC976} (Cdmcco Class) - http://cafeimg.hanmail.net/cab9/dmcc2.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O16 - DPF: {E7476A34-7790-4177-AE49-479CC08099B2} (WebEditor Control) - http://www.club5678.com/etc/activex/WebEditor.cab
O16 - DPF: {F919FBD3-A96B-4679-AF26-F551439BB5FD} - http://winfixer.com/pages/scanner/WinFixer…nnerInstall.cab
O23 - Service: AutoShutdown - Dell Computer Corporation - C:\WINNT\System32\PSSVC.EXE
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\NavNT\defwatch.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: Norton AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\NavNT\rtvscan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe
::rubs eyes:: :blink:

Do my eyes deceive me, or is that nastines finally gone from the log??!!!??

I don't see any malware at all….. :rofl:

I'm back! Tan, Rested, and ready to finish this project!


You're lookin "buff", Dude… ;)

Unless my eyes deceive me, the project is "finished"… :thumbup:
This topic is now closed.

If you need this topic reopened, please request this by sending an email to us at the following link

(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI