paulakaufman
Topic Starter
Hi paulakaufman,
I'm going to move your post over to the Malware Removal Forum where you can get help directly.
Please be patient, as our volunteers are quite busy.
Doug
Hi everyone…I just signed up for WTT to address a problem that has just occurred recently. First of all, thanks for being so accessible. i have been having problems w/ my computer recently and I'm not sure what to do. First of all, i do not know much about
computers, so I could really use some help. Anyway, my computer has just recently been infected, I believe. There is a flashing red "x" in the
bottom right part of the screen next to the volume and other things. And i keep getting warnings that say something along the lines of, "Your computer is infected! Click here to remove malicious software!" (or something like that). When i press "no" or close it, it leads to a website that begins to scan and tells me to buy this program to get rid of spy ware and malicious software. I read online and have heard several things. Out of all of the websites i have been to, i have found this one to have the most answers. I believe i have some type of trojan or something rather serious. Please help me if you can. I searched online on Kaspersky's free online scan (because they are reliable) and it said that i have some infected files. I have no idea what is going on. Oh and also, I have three programs or "icons" that appear every time the computer is restarted. These programs are as follows: Error Cleaner, Privacy Protector, and Spyware&Malware; Protection. I have already deleted these, and they keep reappearing. I'm really confused. I read something similar to this on another forum that was "closed" so i made a new topic and they had a "DSS" log, so i made one too.
Here it is: I do not know if this will help, but please let me know ASAP if you happen to find anything for me.
have a good new years. I just wanted to let people like you how much of help you are. I appreciate you people helping everyone out like this. Thank you very much.
Deckard's System Scanner v20071014.68
Run by [removed] on 2007-12-27 01:57:20
Computer is in Normal Mode.
——————————————————————————–
Backed up registry hives.
Performed disk cleanup.
– HijackThis Clone ————————————————————
Emulating logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2007-12-27 01:59:10
Platform: Windows 2000 Service Pack 4 (5.00.2195)
MSIE: Internet Explorer (6.00.2800.1106)
Boot mode: Normal
Running processes:
C:\WINNT\system32\SMSS.EXE
C:\WINNT\system32\WINLOGON.EXE
C:\WINNT\system32\SERVICES.EXE
C:\WINNT\system32\LSASS.EXE
C:\WINNT\system32\ati2evxx.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\hidserv.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\mstask.exe
C:\WINNT\system32\wbem\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\ati2evxx.exe
C:\WINNT\explorer.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\D-Link\AirPlus G\AirGCFG.exe
C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\TrustedAntivirus\bm.exe
C:\Program Files\ATI Multimedia\main\atidtct.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINNT\system32\wuauclt.exe
C:\Documents and Settings\User\Desktop\dss.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://softwarereferral.com/jump.php?wmid=…6Ojg5&lid;=2
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: CIEIntegrator Object - {5C3F6257-3E00-45C2-88D5-CB0F3A17BF0E} - C:\Program Files\TrustedAntivirus\Tools\pblock.dll
O2 - BHO: IEFW Object - {6F87F145-DC2D-4766-AF03-3A3B96FFAD98} - C:\Program Files\TrustedAntivirus\Tools\sbiebho.dll
O2 - BHO: BDEX System - {83CDEF6B-98D2-4C60-84FC-00C44606A4F8} - C:\WINNT\domnftwpto.dll
O3 - Toolbar: &Radio; - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O3 - Toolbar: The emlkdvo - {940EBD8D-A3B7-44F9-A850-F60E76BE3B22} - C:\DOCUME~1\User\LOCALS~1\Temp\ac8zt2\emlkdvo.dll (file missing)
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [UC_Start] C:\Program Files\IBM\Updater\\ucstartup.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [D-Link AirPlus G] C:\Program Files\D-Link\AirPlus G\AirGCFG.exe
O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\x86\LogMeInSystray.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [TrustedAntivirus] C:\Program Files\TrustedAntivirus\pgs.exe
O4 - HKLM\..\Run: [ugac] "C:\PROGRA~1\COMMON~1\TRUSTE~1\ugac.exe" -start
O4 - HKLM\..\Run: [bm] "C:\Program Files\Common Files\TrustedAntivirus\bm.exe" dm=http://trustedantivirus.com ad=http://trustedantivirus.com sd=http://ykeeper.trustedantivirus.com
O4 - HKLM\..\Run: [ptask] C:\Program Files\TrustedAntivirus\ptask.exe
O4 - HKCU\..\Run: [ATI DeviceDetect] C:\Program Files\ATI Multimedia\main\ATIDtct.EXE
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user')
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\Web\RELATED.HTM
O9 - Extra 'Tools' menuitem: @shdoclc.dll,-864 - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\Web\RELATED.HTM
O10 - Unknown file in Winsock LSP: C:\WINNT\system32\NWPROVAU.DLL
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/u…can_unicode.cab
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} () - http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} () - http://v4.windowsupdate.microsoft.com/CAB/…8209.5576041667
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.macromedia.com/pub/shock…ash/swflash.cab
O16 - DPF: {D9C91F28-6573-8D60-22C9-364560FE8054} () - http://content.onerateld.com/pcsecuresyste…/install_en.cab
O17 - HKLM\SYSTEM\CCS\Services\Tcpip\..\{47EB42D3-4C57-42EF-BDBD-985E3C8AFAE7}: NameServer = 208.67.220.220,208.67.222.222
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll
O20 - Winlogon Notify: ATINotify - C:\WINNT\system32\logonnfy.dll (file missing)
O21 - SSODL: alxvdvm - {26054626-6963-4A6C-A988-83EC09146CFB} - C:\WINNT\alxvdvm.dll
O21 - SSODL: bvtqfvx - {BDD59338-07EC-4298-9DC0-3FB994CBAB54} - C:\WINNT\bvtqfvx.dll
O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Alpha Networks Inc. - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINNT\system32\ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINNT\system32\ati2sgag.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\system32\dmadmin.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
–
End of file - 5518 bytes
– File Associations ———————————————————–
All associations okay.
– Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ———————
R0 dhlp - c:\winnt\system32\drivers\dhlp.sys
I'm going to move your post over to the Malware Removal Forum where you can get help directly.
Please be patient, as our volunteers are quite busy.
Doug
Hi everyone…I just signed up for WTT to address a problem that has just occurred recently. First of all, thanks for being so accessible. i have been having problems w/ my computer recently and I'm not sure what to do. First of all, i do not know much about
computers, so I could really use some help. Anyway, my computer has just recently been infected, I believe. There is a flashing red "x" in the
bottom right part of the screen next to the volume and other things. And i keep getting warnings that say something along the lines of, "Your computer is infected! Click here to remove malicious software!" (or something like that). When i press "no" or close it, it leads to a website that begins to scan and tells me to buy this program to get rid of spy ware and malicious software. I read online and have heard several things. Out of all of the websites i have been to, i have found this one to have the most answers. I believe i have some type of trojan or something rather serious. Please help me if you can. I searched online on Kaspersky's free online scan (because they are reliable) and it said that i have some infected files. I have no idea what is going on. Oh and also, I have three programs or "icons" that appear every time the computer is restarted. These programs are as follows: Error Cleaner, Privacy Protector, and Spyware&Malware; Protection. I have already deleted these, and they keep reappearing. I'm really confused. I read something similar to this on another forum that was "closed" so i made a new topic and they had a "DSS" log, so i made one too.
Here it is: I do not know if this will help, but please let me know ASAP if you happen to find anything for me.
Deckard's System Scanner v20071014.68
Run by [removed] on 2007-12-27 01:57:20
Computer is in Normal Mode.
——————————————————————————–
Backed up registry hives.
Performed disk cleanup.
– HijackThis Clone ————————————————————
Emulating logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2007-12-27 01:59:10
Platform: Windows 2000 Service Pack 4 (5.00.2195)
MSIE: Internet Explorer (6.00.2800.1106)
Boot mode: Normal
Running processes:
C:\WINNT\system32\SMSS.EXE
C:\WINNT\system32\WINLOGON.EXE
C:\WINNT\system32\SERVICES.EXE
C:\WINNT\system32\LSASS.EXE
C:\WINNT\system32\ati2evxx.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\hidserv.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\mstask.exe
C:\WINNT\system32\wbem\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\ati2evxx.exe
C:\WINNT\explorer.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\D-Link\AirPlus G\AirGCFG.exe
C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\TrustedAntivirus\bm.exe
C:\Program Files\ATI Multimedia\main\atidtct.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINNT\system32\wuauclt.exe
C:\Documents and Settings\User\Desktop\dss.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://softwarereferral.com/jump.php?wmid=…6Ojg5&lid;=2
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: CIEIntegrator Object - {5C3F6257-3E00-45C2-88D5-CB0F3A17BF0E} - C:\Program Files\TrustedAntivirus\Tools\pblock.dll
O2 - BHO: IEFW Object - {6F87F145-DC2D-4766-AF03-3A3B96FFAD98} - C:\Program Files\TrustedAntivirus\Tools\sbiebho.dll
O2 - BHO: BDEX System - {83CDEF6B-98D2-4C60-84FC-00C44606A4F8} - C:\WINNT\domnftwpto.dll
O3 - Toolbar: &Radio; - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O3 - Toolbar: The emlkdvo - {940EBD8D-A3B7-44F9-A850-F60E76BE3B22} - C:\DOCUME~1\User\LOCALS~1\Temp\ac8zt2\emlkdvo.dll (file missing)
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [UC_Start] C:\Program Files\IBM\Updater\\ucstartup.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [D-Link AirPlus G] C:\Program Files\D-Link\AirPlus G\AirGCFG.exe
O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\x86\LogMeInSystray.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [TrustedAntivirus] C:\Program Files\TrustedAntivirus\pgs.exe
O4 - HKLM\..\Run: [ugac] "C:\PROGRA~1\COMMON~1\TRUSTE~1\ugac.exe" -start
O4 - HKLM\..\Run: [bm] "C:\Program Files\Common Files\TrustedAntivirus\bm.exe" dm=http://trustedantivirus.com ad=http://trustedantivirus.com sd=http://ykeeper.trustedantivirus.com
O4 - HKLM\..\Run: [ptask] C:\Program Files\TrustedAntivirus\ptask.exe
O4 - HKCU\..\Run: [ATI DeviceDetect] C:\Program Files\ATI Multimedia\main\ATIDtct.EXE
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user')
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\Web\RELATED.HTM
O9 - Extra 'Tools' menuitem: @shdoclc.dll,-864 - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\Web\RELATED.HTM
O10 - Unknown file in Winsock LSP: C:\WINNT\system32\NWPROVAU.DLL
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/u…can_unicode.cab
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} () - http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} () - http://v4.windowsupdate.microsoft.com/CAB/…8209.5576041667
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.macromedia.com/pub/shock…ash/swflash.cab
O16 - DPF: {D9C91F28-6573-8D60-22C9-364560FE8054} () - http://content.onerateld.com/pcsecuresyste…/install_en.cab
O17 - HKLM\SYSTEM\CCS\Services\Tcpip\..\{47EB42D3-4C57-42EF-BDBD-985E3C8AFAE7}: NameServer = 208.67.220.220,208.67.222.222
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll
O20 - Winlogon Notify: ATINotify - C:\WINNT\system32\logonnfy.dll (file missing)
O21 - SSODL: alxvdvm - {26054626-6963-4A6C-A988-83EC09146CFB} - C:\WINNT\alxvdvm.dll
O21 - SSODL: bvtqfvx - {BDD59338-07EC-4298-9DC0-3FB994CBAB54} - C:\WINNT\bvtqfvx.dll
O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Alpha Networks Inc. - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINNT\system32\ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINNT\system32\ati2sgag.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\system32\dmadmin.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
–
End of file - 5518 bytes
– File Associations ———————————————————–
All associations okay.
– Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ———————
R0 dhlp - c:\winnt\system32\drivers\dhlp.sys