This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Adware / Spyware/

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Still not luck with the AUNP search … Ad-Aware SE Personal Adobe Acrobat 5.0 Adobe Download Manager 2.0 (Remove Only) Adobe Photoshop Album 2.0 Starter Edition Adobe Reader 7.0 AIM Toolbar ALPS Touch Pad Driver America Online (Choose which version to remove) AOL Instant Messenger ATI Control Panel ATI Display Driver Broadcom Advanced Control Suite CCleaner (remove only) Command Dell Modem-On-Hold Dell Picture Studio - Dell Image Expert Dell Solution Center Dell Support DVDSentry Easy CD Creator 5 Basic ewido security suite Google Toolbar for Internet Explorer HijackThis 1.99.1 Internet Explorer Q818529 InterVideo WinDVD iPod for Windows 2005-01-11 iPod for Windows 2005-03-23 iPod for Windows User Guide iPod System Software Updater 2.0.1 iTunes Java 2 Runtime Environment Standard Edition v1.3.1_04 Kaspersky On-line Scanner Lavasoft VX2 Cleaner LiveUpdate 1.6 (Symantec Corporation) Microsoft .NET Framework 1.1 Microsoft Interactive Training Microsoft Office XP Media Content Microsoft Office XP Professional Microsoft Publisher 2002 MUSICMATCH iPod Plug-in MUSICMATCH® Jukebox MyDVD Norton AntiVirus Corporate Edition Outlook Express Update Q330994 Paint Shop Pro 7 Panda ActiveScan PCTEL 2304WT V.92 MDC Modem Drivers QuickTime RealOne Player sextension Spybot - Search & Destroy 1.4 SpywareBlaster v3.4 Viewpoint Media Player Windows XP Hotfix - KB821557 Windows XP Hotfix - KB823559 Windows XP Hotfix - KB823980 Windows XP Hotfix (SP2) [See Q329115 for more information] Windows XP Hotfix (SP2) [See Q329390 for more information] Windows XP Hotfix (SP2) [See Q329834 for more information] Windows XP Hotfix (SP2) Q328310 Windows XP Hotfix (SP2) Q329170 Windows XP Hotfix (SP2) Q329441 Windows XP Hotfix (SP2) Q810565 Windows XP Hotfix (SP2) Q810577 Windows XP Hotfix (SP2) Q810833 Windows XP Hotfix (SP2) Q811493 Windows XP Hotfix (SP2) Q814033 Windows XP Hotfix (SP2) Q815021 Windows XP Hotfix (SP2) Q817287 Windows XP Hotfix (SP2) Q817606 Windows XP Hotfix (SP2) Q819696 Wireless Yahoo! Toolbar
I had tried already, here's the log: ——————————————————— ewido security suite - Scan report ——————————————————— + Created on: 4:47:38 PM, 8/27/2005 + Report-Checksum: 1271BC67 + Scan result: C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP2\A0000052.exe -> TrojanDownloader.Qoologic.ac : Cleaned with backup C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP2\A0000053.exe -> TrojanDownloader.Qoologic.ac : Cleaned with backup C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP2\A0000054.dll -> TrojanDownloader.Qoologic.ac : Cleaned with backup C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP2\A0000055.dll -> TrojanDownloader.Qoologic.ac : Cleaned with backup C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP2\A0000056.exe -> TrojanDownloader.Qoologic.ac : Cleaned with backup C:\WINDOWS\SYSTEM32\silent_marketingsector.exe -> TrojanDropper.Agent.se : Cleaned with backup C:\WINDOWS\Temp\b.com -> TrojanDropper.Agent.pb : Error during cleaning ::Report End
Here's what I suggest:

Download Killbox from here:

Killbox.zip

Unzip it, but don't run it yet.
  • Launch Ewido, there should be an icon on your desktop double-click it.
  • The program will now go to the main screen
You will need to update Ewido to the latest definition files.
  • On the left hand side of the main screen click update
  • Then click on Start Update
The update will start and a progress bar will show the updates being installed.
If you are having problems with the updater, you can use this link to manually update Ewido.

After the definitions have been updated, close Ewido.

Do NOT run a scan yet.

Reboot in "safe" mode.

Now, run Ewido, then:
  • Click on scanner
  • Click on Complete System Scan and the scan will begin (do not open any folder's or open the windows control panel while the scan is in progress).
  • While the scan is in progress you will be prompted to clean files, click OK
  • When it asks if you want to clean the first file, put a check in the lower left corner of the box that says "Perform action on all infections" then choose clean and click OK.
  • Once the scan has completed, there will be a button located on the bottom of the screen named Save report
  • Click Save report.
  • Save the report.txt file to your desktop.
Now close Ewido security suite.

CLOSE ALL WINDOWS (even this one) AND PROGRAMS!!!!

Copy the file names in the quote box below to the clipboard by highlighting them and pressing
C (hold the key down, then press C):

C:\WINDOWS\Temp\b.com
C:\WINDOWS\SYSTEM32\silent_marketingsector.exe


Run Killbox, click File (in the upper left of Killbox), and choose "Paste from Clipboard".

Click the red dot with the white X in it, in the upper right of Killbox, then click "Yes", and "Yes" again.

After the reboot, "copy/paste" a new Hijack This! log file, and the report.txt file from the Ewido scan, into this thread. :)
Is there such a thing as hidden registry key?

Here's what I tried:

First I created a restore point.
Then I tried to add the value "AUNPS2" = "RUNDLL32 AUNPS2.DLL,_Run@16"
to the registry subkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run


This is when I got the message that the value already existed!!

Then I ran msconfig and unchecked the "AUNPS2" value from the startup tab.

I then chose to exit msconfig without restarting, which moved the invisible "AUNPS2" value to the subkey HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg and making it visible.

I went back to msconfig to verify that the value had been removed from the startup tab and restarted the system.

My AUNPS2.dll problem/error is GONE !!!

What is interesting is that most of the startup values in msconfig are invisible in the registry. I have admin rights and the permissions seems OK.
I can't explain it…



———————————————————
ewido security suite - Scan report
———————————————————

+ Created on: 10:46:04 PM, 8/27/2005
+ Report-Checksum: EE65A94

+ Scan result:

C:\WINDOWS\Temp\b.com -> TrojanDropper.Agent.pb : Error during cleaning


::Report End





Logfile of HijackThis v1.99.1
Scan saved at 10:53:08 PM, on 8/27/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\COMMON~1\aol\ACS\acsd.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\NavNT\defwatch.exe
C:\Program Files\NavNT\rtvscan.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\NavNT\vptray.exe
C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\Documents and Settings\John Doe\Desktop\repair\HijackThis.exe

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\GoogleToolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\GoogleToolbar1.dll
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &Google Search - res://C:\WINDOWS\GoogleToolbar.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://C:\WINDOWS\GoogleToolbar.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\WINDOWS\GoogleToolbar.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Si&milar Pages - res://C:\WINDOWS\GoogleToolbar.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page - res://C:\WINDOWS\GoogleToolbar.dll/cmtrans.html
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/downloads/kws/kav…can_unicode.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004033…all/xscan53.cab
O16 - DPF: {8EDAD21C-3584-4E66-A8AB-EB0E5584767D} - http://toolbar.google.com/data/GoogleActivate.cab
O16 - DPF: {8EF27A70-DD04-11D6-B7F6-00A0C9CD5F8A} - http://www.quikshield.com/qshsetup.exe
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{33BA8EFA-AA25-4FA2-85C5-2D2D6201152A}: Domain = usc.edu
O17 - HKLM\System\CCS\Services\Tcpip\..\{33BA8EFA-AA25-4FA2-85C5-2D2D6201152A}: NameServer = 128.125.253.183,128.125.253.166,128.125.253.136
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = usc.edu,hsc.usc.edu
O17 - HKLM\System\CS1\Services\Tcpip\..\{33BA8EFA-AA25-4FA2-85C5-2D2D6201152A}: Domain = usc.edu
O17 - HKLM\System\CS1\Services\Tcpip\..\{33BA8EFA-AA25-4FA2-85C5-2D2D6201152A}: NameServer = 128.125.253.183,128.125.253.166,128.125.253.136
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = usc.edu,hsc.usc.edu
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\aol\ACS\acsd.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\NavNT\defwatch.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\NavNT\rtvscan.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
The log looks good!!!

Is there such a thing as hidden registry key?


A recent post on one of our boards not avaible to the public talked about "invisible" keys in the registry, but only in the context of extremely long keys. That key wouldn't come under that category.

Strange…. :scratch:

I'm glad you got things working.

GOD bless you!!!

M68 :)

Items you may wish to consider to harden your defenses against future infections:

Read "How did I get infected in the first place?"

Download/install IE-Spyad

IE-Spyad puts over 4000 known malicious web sites into IE's "restricted zone" to help prevent you from getting infected.

Check your browser settings at Qualsys.com

A series of "tests" (and suggested fixes) to help tweak IE's settings to help prevent infections when surfing the web.

Follow safe Internet practices:

1. Keep your virus definitions up to date, and scan your system regularly.

2. Don't open email, or download attachments from unrecognized email addresses.

3. Be careful when downloading email attachments, EVEN FROM PEOPLE YOU KNOW! Many virii, worms, and trojans infect a persons system then immeadiately spread themselves to the people in the infected persons addressbook via email attachments.

4. Be careful downloading files from the Internet. Scan all downloaded files with a reliable UP-TO-DATE antivirus program. Scan "zip" files BEFORE unzipping, and scan all unzipped files BEFORE USING THEM.

5. Keep your Windows and IE current with all the latest patches and updates.

Micah_6:8 Thank you very much for your help. Is there a tool/way to make sure that my permissions are set correctly. There is at leat 80% of the entries in the msconfig startup tab that don't appear in the registry. I even tried to export the registry to a text file and searched that file!! That's really odd…
Last thing: Do you know if there's a way for me to save/get a "friendly version" one page of this entire thread for future reverence? Thank you again for your precious help
This topic is now closed.

If you need this topic reopened, please request this by sending an email to us at the following link

(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI