[Resolved] Help Needed Pop Ups, Winantivirus, & Software In S
53 min read
Damage Cleanup Engine (DCE) 5.3(Build 1103)
Windows XP(Build 2600: Service Pack 2)
Start time : Thu Sep 06 2007 19:51:44
Load Damage Cleanup Template (DCT) "C:\Documents and Settings\David\Desktop\Sysclean\TMRDCT.ptn" (version ) [fail]
Load Damage Cleanup Template (DCT) "C:\Documents and Settings\David\Desktop\Sysclean\tsc.ptn" (version 894) [success]
Complete time : Thu Sep 06 2007 19:52:26
Execute pattern count(2908), Virus found count(0), Virus clean count(0), Clean failed count(0)
I found this file
TSCDebug.txt
Debug Information Level=0
********************************************************************************
*************************************************************
Then the program ran the following program: It found 3 files containing viruses. WERE THEY REMOVED?
********************************************************************************
*************************************************************
/————————————————————–\
| Trend Micro System Cleaner |
| Copyright 2006, Trend Micro, Inc. |
| http://www.antivirus.com |
\————————————————————–/
2007-09-06, 19:51:42, Auto-clean mode specified.
2007-09-06, 19:51:42, Running scanner "C:\Documents and Settings\David\Desktop\Sysclean\TSC.BIN"…
2007-09-06, 19:52:56, Scanner "C:\Documents and Settings\David\Desktop\Sysclean\TSC.BIN" has finished running.
2007-09-06, 19:52:56, TSC Log:
2007-09-06, 20:59:11, Files Detected:
Copyright © 1990 - 2004 Trend Micro Inc.
Report Date : 9/6/2007 19:55:59
VSAPI Engine Version : 8.000-1001
VSCANTM Version : 1.1-1001
Virus Pattern Version : 699 (223633 Patterns) (2007/09/06) (469900)
Command Line: C:\Documents and Settings\David\Desktop\Sysclean\VSCANTM.BIN /NBPM /S /CLEANALL /DCEGENCLEAN /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 C:\*.* /P=C:\Documents and Settings\David\Desktop\Sysclean
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1321\A0307074.exe [TROJ_PURITYSC.AX]
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1321\A0307126.exe [TROJ_FAKEALER.X]
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1321\A0307127.exe [TROJ_DLOADER.NUU]
100948 files have been read.
100948 files have been checked.
90041 files have been scanned.
116766 files have been scanned. (including files in archived)
3 files containing viruses.
Found 3 viruses totally.
Maybe 0 viruses totally.
Stop At : 9/6/2007 20:59:11
———*———*———*———*———*———*———*———*
2007-09-06, 20:59:11, Files Clean:
Copyright © 1990 - 2004 Trend Micro Inc.
Report Date : 9/6/2007 19:55:59
VSAPI Engine Version : 8.000-1001
VSCANTM Version : 1.1-1001
Virus Pattern Version : 699 (223633 Patterns) (2007/09/06) (469900)
Command Line: C:\Documents and Settings\David\Desktop\Sysclean\VSCANTM.BIN /NBPM /S /CLEANALL /DCEGENCLEAN /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 C:\*.* /P=C:\Documents and Settings\David\Desktop\Sysclean
Success Clean [TROJ_PURITYSC.AX]( 1) from C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1321\A0307074.exe
Success Clean [ TROJ_FAKEALER.X]( 1) from C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1321\A0307126.exe
Success Clean [TROJ_DLOADER.NUU]( 1) from C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1321\A0307127.exe
100948 files have been read.
100948 files have been checked.
90041 files have been scanned.
116766 files have been scanned. (including files in archived)
3 files containing viruses.
Found 3 viruses totally.
Maybe 0 viruses totally.
Stop At : 9/6/2007 20:59:11 1 hour 3 minutes 12 seconds (3791.19 seconds) has elapsed.
———*———*———*———*———*———*———*———*
2007-09-06, 20:59:11, Clean Fail:
Copyright © 1990 - 2004 Trend Micro Inc.
Report Date : 9/6/2007 19:55:59
VSAPI Engine Version : 8.000-1001
VSCANTM Version : 1.1-1001
Virus Pattern Version : 699 (223633 Patterns) (2007/09/06) (469900)
Command Line: C:\Documents and Settings\David\Desktop\Sysclean\VSCANTM.BIN /NBPM /S /CLEANALL /DCEGENCLEAN /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 C:\*.* /P=C:\Documents and Settings\David\Desktop\Sysclean
100948 files have been read.
100948 files have been checked.
90041 files have been scanned.
116766 files have been scanned. (including files in archived)
3 files containing viruses.
Found 3 viruses totally.
Maybe 0 viruses totally.
Stop At : 9/6/2007 20:59:11 1 hour 3 minutes 12 seconds (3791.19 seconds) has elapsed.
———*———*———*———*———*———*———*———*
2007-09-06, 20:59:11, Scanner "C:\Documents and Settings\David\Desktop\Sysclean\VSCANTM.BIN" has finished running.
catcher33
OK good news, both your scans have come back clean.
The "infections" found by both are in your System Restore files, the only way those files can re-infect you is if you do a System Restore. We'll remove them in a minute to take away that possibility.
I've known about the infected RPs since the first Kaspersky scan, but the reason we don't remove them straight away is that it would take away your restore points. If we had any problems during the cleaning of your computer it's better to have an infected RP than no RP. We always clean them out last of all when there's no longer a chance of there being any unforseen problems.
OK, little bit of cleaning up to do now.
Let's clear out the programmes we've been using to clean up your computer, they are not suitable for general malware removal and could cause damage if used inappropriately. Besides they're updated regularly so won't be of any use against future infections.
- Double click OTMoveIt.exe to launch the programme.
- Click on the CleanUp! button.
- OTMoveIt will download a list from the Internet, if your firewall or other defensive programmes alerts you, allow it access.
- You will be prompted to allow the clean up procedure, click Yes
- When finished exit out of OTMoveIt
- Now delete OTMoveIt.exe (if present).
As far as I can see, your computer looks clear of infection now.
Are you still noticing any problems ?
- If you are let me know about them.
- If not it's time to make your computer more secure.
THESE STEPS ARE VERY IMPORTANT
Lets reset system restore
Reset and Re-enable your System Restore to remove infected files that have been backed up by Windows. The files in System Restore are protected to prevent any programs changing those files. This is the only way to clean these files: You will lose all previous restore points which we know are infected. Please note you need Administrator Access to clean the restore points.
- Turn off System Restore.
- On the Desktop, right-click My Computer.
- Click Properties.
- Click the System Restore tab.
- Check Turn off System Restore.
- Click Apply, and then click OK.
- Reboot.
- Turn ON System Restore.
- On the Desktop, right-click My Computer.
- Click Properties.
- Click the System Restore tab.
- UN-Check *Turn off System Restore*.
- Click Apply, and then click OK.
- NOTE: only do this once, NOT on a regular basis.
Older versions have vulnerabilities that malware can and are using to infect systems.
Please follow these steps to remove older version Java components. This is important as it's still possible to get infected through an old install even if you're using the latest version of Java.
- Close any programmes you may have running, ESPECIALLY your web browser
- Click Start > Control Panel.
- Click Add/Remove Programs.
- Check any item with Java Runtime Environment (JRE) in the name.
- Click the Remove or Change/Remove button.
- Repeat as many times as necessary to remove all versions of Java.
- Reboot your computer once all Java components are removed.
Updating Windows and Internet Explorer
It is essential you keep your Operating System up to date with all the latest patches. The bad guys watch for the latest exploits, as soon as Microsoft brings out a patch, the bad guys will bring out an infection to exploit that vulnerability. If you don't have all the latest patches your computer is vulnerable. Please go to the windows update site and get the critical updates.
Use a "secure" browser
Install Internet Explorer 7 or an alternative browser like Firefox or Opera for more secure surfing.
Please remember that there is no such thing as a totally secure browser. Your browsing habits will be the major factor in determining just how safe you are online. If you visit, Crack/Warez sites, Porn sites, or other sites of a questionable nature, you still run a severe risk of getting infected.
The following are free programs that are designed to keep your computer clean. A brief description is included with each item, click on name to go to download site.
- Adaware SE Personal
Adaware is a free program. It scans for known spyware on your computer. These scans should be run at least once every two weeks. For more information, see this tutorial
- Spybot S & D
Spybot is a scanner like Adaware. It scans for spyware and other malicious programs. It is important to have both Adaware and Spybot on your computer because each program provides unique detection and protection measures. Spybot has preventitive tools that stop programs from even installing on your computer.
To see how to set this up as well as more spybot features, see here
- SpywareBlaster
Spyware blaster is a program that stops known malicious activex controls from installing on your computer. It works by changing settings in your registry. It makes "kill bits" in the registry, so that certain activex controls can't install.
If you don't know what activex controls are, see here
- IE Spyad
It puts many bad webpages on your restricted zones LIST. This means that you can still view the "bad" webpages, but the webpages can't do certain things (such as use javascripts and cookies). Use IE Spyad for single account computers, and IE Spyad 2 for multi account computers.
- Hosts file:
- Make sure you read the instructions on how to install the hosts file, here.
- Every version of windows has a hosts file as part of them.
- In a very basic sense, they are used to locate webpages.
- We can customize a hosts file so that it blocks certain webpages.
- However, it can slow down certain computers.
- If you decide to download the hosts file, the slowdown problems can usually be avoided by following these steps:
- Click the start button (at the lower left hand corner of your screen)
- Click run
- In the dialog box, type services.msc
- hit enter, then locate dns client
- Highlight it, then double-click it.
- On the dropdown box, change the setting from automatic to manual.
- Click ok
- Use an Anti Virus Software - It's very important that your computer has an anti-virus software running. This alone can save you a lot of trouble with malware in the future. See this link for a listing of some on line & their stand-alone anti virus programs:
Computer Safety On line - LIST of free Anti virus programs
- Use a Firewall - I cannot stress enough how important it is that you use a Firewall on your computer. Without a firewall your computer is susceptible to being hacked and taken over. Simply using a Firewall in its default configuration can lower your risk greatly. For more info, check this webpage out.
See here to choose one.
- Site Advisor This is a utility that can be downloaded and installed. It loads an icon to the taskbar of your browser (versions for IE and Firefox), indicating the trustworthiness of the site you are on. Green for safe, Red for suspicious. Click on the icon to access details that SiteAdvisor has about the site.
Here's links to a few articles which are well worth reading
- The Spyware Warrior Guide to Getting help with Spyware
- Microsoft - Security at Home
- Top Ten excuses why people don't want to secure their computer and why they are wrong - by Budfred
- How did I get infected in the first place - by TonyKlein
- Prevent Re-infection
- Simple and easy ways to keep your computer safe and secure on the Internet
- Help! My computer is slow! - How to improve system performance after malware removal - by Miekiemoes
NOW is the time you can start to hit back at the people who infected you.
[external image: Posted Image]
Please take the time to go and complain - that forum has a topic for your infection which is Vundo…… (if not, post in the Is your infection not listed here? topic). Please post as a reply, you do not need to register to do so (but you can if you wish). It will also have a list of other places you can go to to register your complaint, depending on the country you are resident in. Please read the topics and complain, it is only with such complaints to goverment or government agencies that something will get done.
2. From what I can find, the files and folders VSE80iLEN, VSE80P11, backups, log, and Q3 seem to be connected with Virus Scan by Mc Afee, if you're not using that programme delete them.
3.The sgtray entry in HJT is not necessary for the running of Sonic Record now.
Run a scan with HJT and when finished check the following items (if found).
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
Now close all open windows and click Fix Checked to remove them.
Don't delete the file.
Reboot your computer.
By removing the HJT entry you will prevent it loading at startup, which should remove the problem.
If it doesn't, I'm afraid you'll need to seek help within Sonic or any forums associated with their products. This is not malware related, and so is outside my area of expertise.
Hope this helps.
Gary
Try going to http://www.ie-vista.com/index.html a site by Sandi Hardmeier who specialises in IE problems.
After first installing IE7 did you reboot twice before trying to use it, Sandi seems to think it is important that you do. If not, try Uninstalling IE7 http://www.ie-vista.com/kbase2.html then re-installing using the advice on this page. http://www.ie-vista.com/known_issues.html#pre-install
Also try the Internet Explore Community at Microsoft http://www.microsoft.com/windows/using/com…ie/default.mspx there are people there with a great deal of IE7 troubleshooting experience.
Either that or Uninstall IE7 http://www.ie-vista.com/kbase2.html and use another browser like Firefox.
Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI