This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Pop-ups

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

A. Download next removal tool to your desktop:
http://www.techsupportforum.com/sectools/s…Disinfector.exe
If you have any flashdrives being used previously, since this is a flashdrive infection, insert your flashdrive as well, because above tool will disinfect it as well.
Then doubleclick the Flash_Disinfector.exe to run the tool.
Your desktop and icons will disappear afterwards. This is normal.
When the tool has finished, reboot your computer.

B. Then, Open notepad and copy and paste next present in the codebox below in it:
(don't forget to copy and paste REGEDIT4) (Make sure you copy the bracket ] at the end of the registry entries, they are often difficult to see because of the frame that surrounds the codebox.

REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LaunchApp"=-

[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2a2e6f2f-1ac1-11dc-a226-000b6b5f2dc6}]

[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2a2e6f30-1ac1-11dc-a226-000b6b5f2dc6}]

[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2e02db27-ee6f-11db-a203-00c09fa4e666}]

[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2e2d6659-f683-11db-a20c-00c09fa4e666}]

[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{34602cdc-ff0d-11db-a20f-00c09fa4e666}]

[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{48a52eb0-0979-11dc-a21c-00c09fa4e666}]

[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6c928870-0638-11dc-a218-00c09fa4e666}]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6c928871-0638-11dc-a218-00c09fa4e666}]

[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8924b88c-ecf2-11db-a202-00c09fa4e666}]

[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{96ee14dd-f11d-11db-a205-8000600fe800}]

[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b23f494d-15e9-11dc-a225-00c09fa4e666}]

[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b23f495c-15e9-11dc-a225-8000600fe800}]

[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c1802a5a-f4b7-11db-a206-8000600fe800}]

[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c78da2e5-025b-11dc-a213-00c09fa4e666}]



Save this as fix.reg Choose to save as *all files and place it on your desktop.
It should look like a blue cube
Doubleclick on it and when it asks you if you want to merge the contents to the registry, click yes/ok.


C. Now, please run ComboFix again and post the ComboFix log and a fresh HJT log in your next reply.

Regards,

Trevuren
Hi Trevuren,

Hmm, something went wrong some where. I left my computer on (which i do usually) and when i got back, my anti-virus program was disabled. On top of that, i couldn't enable it. I had to go into safe mode and run the Flash_Disinfector.exe. Then, on top of that, a bunch of my normal running processors are not running. Last time i used to have like 54 processsors running, but now i have 34. I don't know if they were taken away because they slowed my computer down or something like that. I don't mind having less processors, just that, my usual prograns are not running. For example, Zone Alarm, Microsoft Activesync, Yahoo Messenger, Yahoo Widgets and quite a number more. I know they slow down my computer, but i need their services. Anyway, i did as you said and here's the combofix log.

ComboFix 07-06-21.3 - C:\Documents and Settings\Reuben\Desktop\ComboFix.exe
"Reuben" - 2007-06-24 0:32:22 - Service Pack 2


((((((((((((((((((((((((( Files Created from 2007-05-23 to 2007-06-23 )))))))))))))))))))))))))))))))


2007-06-23 22:39 26,112 –a—— C:\WINDOWS\system32\nircmd.exe
2007-06-23 22:39

drahs—- C:\autorun.inf
2007-06-23 15:45 271,224 –a—— C:\WINDOWS\system32\mucltui.dll
2007-06-22 15:26 d–hs—- C:\FOUND.001
2007-06-22 13:01 49,152 –a—— C:\WINDOWS\nircmd.exe
2007-06-22 11:47 786,432 –ah—– C:\DOCUME~1\ADMINI~1\NTUSER.DAT
2007-06-21 22:18 38,232 –a—— C:\WINDOWS\system32\cmdify.dll
2007-06-20 20:32 d–hs—- C:\FOUND.000
2007-06-18 11:27 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Sandlot Games
2007-06-18 11:25 d——– C:\Program Files\Tradewinds Legends
2007-06-18 11:25 d——– C:\Program Files\ReflexiveArcade
2007-06-15 10:15 d——– C:\Program Files\Shockwave.com
2007-06-14 23:29 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Trymedia
2007-06-14 23:23 d——– C:\Program Files\Tradewinds Full Game
2007-06-14 14:49 d——– C:\Program Files\DFX
2007-06-14 14:48 d——– C:\Program Files\Common Files\Wise Installation Wizard
2007-06-05 04:39 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\NtiDvdCopy
2007-06-02 10:41 d——– C:\Program Files\Microsoft Voice Command
2007-06-01 14:05 d——– C:\Program Files\eMule
2007-06-01 14:05 d——– C:\DOCUME~1\Reuben\APPLIC~1\eMule
2007-05-28 03:24 d——– C:\DOCUME~1\Reuben\APPLIC~1\VoipCheapCom
2007-05-26 02:34 d——– C:\Program Files\MobiPocket.com
2007-05-26 02:08 d——– C:\Skyscape
2007-05-26 00:15 d——– C:\WINDOWS\Skyscape
2007-05-25 14:18 d——– C:\Program Files\Common Files\Mobipocket Shared
2007-05-24 18:46 d——– C:\Program Files\mIRCv2
2007-05-24 04:15 d——– C:\Program Files\skyscape
2007-05-24 04:05 d——– C:\Program Files\Common Files\Skyscape
2007-05-24 02:09 d——– C:\DOCUME~1\Reuben\APPLIC~1\Help


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-06-23 19:22:40 12 —-a-w C:\WINDOWS\bthservsdp.dat
2007-06-02 00:11:22 4,212 —h–w C:\WINDOWS\system32\zllictbl.dat
2007-05-17 20:33:14 ——– d—–w C:\Program Files\Bible
2007-05-16 15:12:02 683,520 —-a-w C:\WINDOWS\system32\inetcomm.dll
2007-05-11 10:20:24 ——– d—–w C:\DOCUME~1\Reuben\APPLIC~1\Command & Conquer 3 Tiberium Wars
2007-05-10 22:51:02 ——– d—–w C:\Program Files\Westwood
2007-05-10 16:39:14 ——– d—–w C:\Program Files\Teleport Pro
2007-05-10 14:25:06 ——– d—–w C:\Program Files\Microsoft CAPICOM 2.1.0.2
2007-05-08 18:26:50 ——– d—–w C:\Program Files\r2 Studios
2007-05-08 11:22:22 ——– d—–w C:\Program Files\Advanced Port Scanner
2007-05-03 23:51:26 ——– d—–w C:\DOCUME~1\Reuben\APPLIC~1\LimeWire
2007-05-03 23:50:20 ——– d—–w C:\Program Files\LimeWire
2007-04-27 09:54:54 ——– d—–w C:\Program Files\Valve
2007-04-25 14:21:16 144,896 —-a-w C:\WINDOWS\system32\schannel.dll
2007-04-18 16:12:24 2,854,400 —-a-w C:\WINDOWS\system32\msi.dll
2007-04-16 19:47:36 33,624 —-a-w C:\WINDOWS\system32\wups.dll
2007-04-16 19:45:54 1,710,936 —-a-w C:\WINDOWS\system32\wuaueng.dll
2007-04-16 19:45:48 549,720 —-a-w C:\WINDOWS\system32\wuapi.dll
2007-04-16 19:45:42 325,976 —-a-w C:\WINDOWS\system32\wucltui.dll
2007-04-16 19:45:36 203,096 —-a-w C:\WINDOWS\system32\wuweb.dll
2007-04-16 19:45:28 92,504 —-a-w C:\WINDOWS\system32\cdm.dll
2007-04-16 19:45:20 53,080 —-a-w C:\WINDOWS\system32\wuauclt.exe
2007-04-16 19:45:20 43,352 —-a-w C:\WINDOWS\system32\wups2.dll
2007-04-16 19:44:18 208,248 —-a-w C:\WINDOWS\system32\muweb.dll
2007-04-14 13:04:00 471 —-a-w C:\WINDOWS\CLEANUP.CMD
2007-04-14 13:03:34 797 —-a-w C:\WINDOWS\HotFix.bat
2007-04-14 08:40:06 2,560 —-a-w C:\WINDOWS\_MSRSTRT.EXE


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"vptray"="C:\PROGRA~1\SYMANT~1\\vptray.exe" [2005-06-23 19:27]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 05:00]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 12:54]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cmdify]
cmdify.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs BthServ


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6c928871-0638-11dc-a218-00c09fa4e666}]
Auto\command- pagefile.pif
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL pagefile.pif


**************************************************************************

catchme 0.3.721 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-06-24 00:33:44
Windows 5.1.2600 Service Pack 2 FAT NTAPI

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\BTHPORT\Parameters\Services\{00001000-0000-1000-8000-00805f9b34fb}]


[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\BTHPORT\Parameters\Services\{00001101-0000-1000-8000-00805f9b34fb}]


[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\BTHPORT\Parameters\Services\{00001105-0000-1000-8000-00805f9b34fb}]


[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\BTHPORT\Parameters\Services\{00001115-0000-1000-8000-00805f9b34fb}]


Completion time: 2007-06-24 0:35:16
C:\ComboFix3.txt … 2007-06-23 03:07
C:\ComboFix-quarantined-files.txt … 2007-06-24 00:34
C:\ComboFix2.txt … 2007-06-23 12:30

— E O F —


While doing combofix, my windows encountered an error, and they asked me to send a report to Microsoft. At that time, i couldn't get connected to the internet. So, i didn't send the report, and continued with HJT. Here's the log…

Logfile of HijackThis v1.99.1
Scan saved at 12:40:05 AM, on 6/24/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Acer\eManager\anbmServ.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\PROGRA~1\SYMANT~1\vptray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Reuben\Desktop\HJT\Hijackthis\HijackThis.exe

O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\\vptray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - Winlogon Notify: cmdify - C:\WINDOWS\SYSTEM32\cmdify.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\
O23 - Service: Notebook Manager Service (anbmService) - OSA Technologies Inc. - C:\Acer\eManager\anbmServ.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZONELABS\vsmon.exe


I'm at wit's end with my computer. On one hand i want to reformat my computer, but it has too many things inside to reformat. Anyway, i hope you can help me out.

On a personal note, what is the best anti-virus and firewall? I'm currently using Symantec Corparate v10 and Zone Alarm Pro.

Regards,
Reuben
1. Was everything running correctly before you left your computer ? The only thing I can figure is that the worm had crawled its way through your files and the tool cleaned everything out as it was designed to do. But this was radical. 2. Do you remember what the message said? 3. Do you have current backups of your important data? 4. AVG Free and Kerio come in free versions and are both excellent. Kaspersky and ESET NOD32 are top-noth AVs if you can spend$40.00 give or take. I run Kaspersky AV and Kerio Firewall. Trevuren
Hi Trevuren,

I have yet to reformat my computer. I hope i could get rid of the problem and try to get on from there. Anyway, i scanned my computer with Kaspersky Online Scanner and this is the report.


——————————————————————————-
KASPERSKY ONLINE SCANNER REPORT
Sunday, June 24, 2007 6:47:11 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.83.0
Kaspersky Anti-Virus database last update: 24/06/2007
Kaspersky Anti-Virus database records: 330191
——————————————————————————-

Scan Settings:
Scan using the following antivirus database: standard
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
C:\
D:\
E:\
F:\

Scan Statistics:
Total number of scanned objects: 62254
Number of viruses found: 2
Number of infected objects: 6 / 0
Number of suspicious objects: 0
Duration of the scan process: 01:56:23

Infected Object Name / Virus Name / Last Action
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\SYSTEM Object is locked skipped
C:\WINDOWS\system32\config\SOFTWARE Object is locked skipped
C:\WINDOWS\system32\config\DEFAULT Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\OSession.evt Object is locked skipped
C:\WINDOWS\system32\config\ODiag.evt Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\drivers\sptd9117.sys Object is locked skipped
C:\WINDOWS\system32\drivers\sptd.sys Object is locked skipped
C:\WINDOWS\system32\drivers\vaxscsi.sys Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\temp\ZLT0448d.TMP Object is locked skipped
C:\WINDOWS\temp\ZLT04494.TMP Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Internet Logs\tvDebug.log Object is locked skipped
C:\WINDOWS\Internet Logs\IAMDB.RDB Object is locked skipped
C:\WINDOWS\Internet Logs\ACER-788D15BB1C.ldb Object is locked skipped
C:\WINDOWS\Internet Logs\fwpktlog.txt Object is locked skipped
C:\WINDOWS\Internet Logs\fwdbglog.txt Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\settings.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\16C80000.VBN/Setup.exe Infected: Worm.Win32.VB.an skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\16C80000.VBN ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\16C80000.VBN CryptZ: infected - 1 skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Reuben\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Reuben\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Reuben\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Reuben\Local Settings\History\History.IE5\MSHist012007062420070625\index.dat Object is locked skipped
C:\Documents and Settings\Reuben\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Reuben\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Reuben\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Reuben\Local Settings\Application Data\Microsoft\Outlook\Outlook.pst Object is locked skipped
C:\Documents and Settings\Reuben\Local Settings\Application Data\Microsoft\Outlook\~Outlook.pst.tmp Object is locked skipped
C:\Documents and Settings\Reuben\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat Object is locked skipped
C:\Documents and Settings\Reuben\Local Settings\Application Data\Ahead\Nero Home\indexstore.db Object is locked skipped
C:\Documents and Settings\Reuben\Local Settings\Application Data\Ahead\Nero Home\indexstore.db-journal Object is locked skipped
C:\Documents and Settings\Reuben\Local Settings\Application Data\Ahead\Nero Home\bl.db-journal Object is locked skipped
C:\Documents and Settings\Reuben\Local Settings\Application Data\Ahead\Nero Home\bl.db Object is locked skipped
C:\Documents and Settings\Reuben\Local Settings\Application Data\Yahoo\Widget Engine\Widgets DB\widgets.db Object is locked skipped
C:\Documents and Settings\Reuben\Local Settings\Temp\sqlite_awcUqtIdrQZ2yYP Object is locked skipped
C:\Documents and Settings\Reuben\Local Settings\Temp\sqlite_awcUqtIdrQZ2yYP-journal Object is locked skipped
C:\Documents and Settings\Reuben\Local Settings\Temp\~DFA12C.tmp Object is locked skipped
C:\Documents and Settings\Reuben\Local Settings\Temp\~DFA139.tmp Object is locked skipped
C:\Documents and Settings\Reuben\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Reuben\Application Data\$_hpcst$.hpc Object is locked skipped
C:\Documents and Settings\Reuben\Application Data\Azureus\ipfilter.cache Object is locked skipped
C:\Documents and Settings\Reuben\Application Data\Azureus\tmp\AZU27955.tmp Object is locked skipped
C:\Documents and Settings\Reuben\Application Data\Azureus\tmp\AZU27956.tmp Object is locked skipped
C:\Documents and Settings\Reuben\Application Data\Azureus\tmp\AZU27957.tmp Object is locked skipped
C:\Documents and Settings\Reuben\Application Data\Azureus\tmp\AZU27958.tmp Object is locked skipped
C:\Documents and Settings\Reuben\Application Data\Azureus\tmp\AZU27959.tmp Object is locked skipped
C:\Documents and Settings\Reuben\Application Data\Azureus\tmp\AZU27960.tmp Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPPolicy.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPStart.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPStop.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBValid.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBConfig.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBRefr.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBNotify.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetCfg.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetUsr.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBStHash.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetLoc.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetDev.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBDetect.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBDebug.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBStMSI.log Object is locked skipped
C:\Program Files\Symantec AntiVirus\SAVRT401NAV~.TMP Object is locked skipped
C:\Program Files\Symantec AntiVirus\SAVRT559NAV~.TMP Object is locked skipped
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\logs\starwind.2007-06-24.00-43-51.log Object is locked skipped
C:\System Volume Information\_restore{A71CAE99-B6C4-4DFF-9038-4A0D01EF4509}\RP111\change.log Object is locked skipped
C:\QooBox\Quarantine\C\DOCUME~1\Reuben\APPLIC~1\tmp4.tmp.exe.vir Infected: Trojan.Win32.Agent.aoy skipped
C:\QooBox\Quarantine\C\DOCUME~1\Reuben\APPLIC~1\tmp15.tmp.exe.vir Infected: Trojan.Win32.Agent.aoy skipped
C:\QooBox\Quarantine\C\DOCUME~1\Reuben\APPLIC~1\tmp16.tmp.exe.vir Infected: Trojan.Win32.Agent.aoy skipped
D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
D:\System Volume Information\_restore{A71CAE99-B6C4-4DFF-9038-4A0D01EF4509}\RP111\change.log Object is locked skipped

Scan process completed.


Here's a new HJT log, hopefully you still can help me.



Logfile of HijackThis v1.99.1
Scan saved at 6:54:51 PM, on 6/24/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Acer\eManager\anbmServ.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\system32\ZONELABS\vsmon.exe
C:\PROGRA~1\SYMANT~1\vptray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe
C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE
C:\Program Files\Azureus\Azureus.exe
C:\Program Files\internet explorer\iexplore.exe
C:\WINDOWS\system32\notepad.exe
C:\Documents and Settings\Reuben\Desktop\HJT\Hijackthis\HijackThis.exe

O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\\vptray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{5794AFD0-7274-4C74-8A5D-C5981D99BA52}: NameServer = 192.168.1.254
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - Winlogon Notify: cmdify - C:\WINDOWS\SYSTEM32\cmdify.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Notebook Manager Service (anbmService) - OSA Technologies Inc. - C:\Acer\eManager\anbmServ.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZONELABS\vsmon.exe


1. The last i remembered, my computer was running correctly, and everything was fine.

2. I don't remember what's the error message, normally they wouldn't tell what's the error, unless you go probe through some log file, right? Anyway, they just come up with a box stating that "microsoft windows has encounter an error." Then it was the usual send error report or don't send.

3. i'm backing up the important data that i have on my computer now. Then, if you still can't help me, i would reformat.

4. I've heard of Kaspersky but not Kerio. Anyway, thanks, when i reformat (if i reformat) i would get kaspersky. At least its better than my current one.

Thanks for taking your time replying and figuringout my problem.

Regards,
Reuben.
A. The only infections found were in Quarantine.

C:\QooBox
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine

Do not empty the C:\QooBox at this time. It contains backups of some of the files that were removed.

You may empty your Symantec AV Quarantine.

B. I need you to submit the following file to Jotti's for analysis.

1. Click HERE to get to Jotti's site.

2. At the top of the Jotti window, use the Browse button to locate the following file on your system:

C:\pagefile.pif

3. Once you have located the file, click SUBMIT and the content of the file will be uploaded by the site and analysed.

4. Please provide me with the results of the analysis.


Trevuren

Answer edited because your entire reply did not come through at once.
In your backups, please do not include any emails to or from. or any messages that you may have saved from your different Messenger services or IRC chat programs. That is how these worms and rootkits are propagated. You would just be incorporating the whole mess into your new set up. We could possible try to restore the registry from the first time ComboFix was used but I think we would just be restoring corrupt registry keys. You will never know the amount of destruction that has been caused on your machine by these infections. Your best bet is to start anew. That is what I would do and have done in the past. Trevuren
Hi Trevuren, I could not upload the file to Jotti's. They said either a firewall or malware is prohibiting me from doing so. Anyway, i guess i'll just reformat my computer. The worst part would be the softaware installations. Anyway, thanks a lot for your help. I would i have been totally lost without you. Another question, how can i get Windows updates without having to download them every single time i reformat my computer? Like store the installer on a CD or a flash drive or some thing like that… Regards, Reuben
Hi reuben,

I would recommend that you obtain them from the net each time you format. It sounds as if you do this often. Please beware of your P2P programs also. That is where most people pick up the bad bugs…there and on crack sites.

Kerio personal firewall is VERY well known in the antimalware community and very effective. It has been bought by Sunbelt.

If you don't mind, I would like to give you a few recommendations before closing the topic:

Here are some tips to reduce the potential for spyware infection in the future:

Make sure you keep your Windows OS current by visiting Windows update
regularly to download and install any critical updates and service packs. With out these you are leaving the backdoor open.

I strongly recommend installing the following applications:
  • Spywareblaster <= SpywareBlaster will prevent spyware from being installed.
  • Spywareguard <= SpywareGuard offers realtime protection from spyware installation attempts.
  • How to use Ad-Aware to remove Spyware <= If you suspect that you have spyware installed on your computer, here are instructions on how to download, install and then use Ad-Aware.
  • How to use Spybot to remove Spyware <= If you suspect that you have spyware installed on your computer, here are instructions on how to download, install and then use Spybot. Similar to Ad-Aware, I strongly recommend both to catch most spyware.
To protect yourself further:
  • Spyad <= IE/Spyad places over 4000 websites and domains in the IE Restricted list which will severely impair attempts to infect your system. It basically prevents any downloads (Cookies etc) from the sites listed, although you will still be able to connect to the sites.
  • MVPS Hosts file <= The MVPS Hosts file replaces your current HOSTS file with one containing well know ad sites etc. Basically, this prevents your coputer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer
  • Google Toolbar <= Get the free google toolbar to help stop pop up windows.
And also see TonyKlein's good advice
So how did I get infected in the first place?

Regards and Good Luck,

Trevuren
Trevuren, Yeap, i do actually reformat my computer quite often, almost every 6 months. Mostly because it's working too slow. And each time i do it, i have to wait about 12 hours before i finish all the windows updates. Then followed by anti-virus and firewall definitions. Then only i dare to install the rest of the rest of the softwares. Anyway, thanks for all your help. I'm gained new knowledge about computers once more. As much as i would like to know more about fixing computers, i have very little time for it. Studies are getting more and more. Thanks again! I might consider looking through your forums for more information from time to time. Reuben
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance.

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI