This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Ghost on the Keyboard?

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Funny, but the IE changes I had made before and were still there. The View Folder Options changes I had made before to see all those things were already changed back to the (default?) settings you recommended. Do the IE changes apply to Mozilla Firefox, too? I'll keep an eye on things and let you know how it's running.
Well,….i just walked into the room and that calculator was pulled up again. Also, my wife said that while logged onto AOL and playing a game, aol log-on screen came up by itself. I guess we're not out of the woods yet.
* Download Dr.Web CureIt to the desktop:
ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe
  • Doubleclick the drweb-cureit.exe file and Allow to run the express scan
  • This will scan the files currently running in memory and when something is found, click the yes button when it asks you if you want to cure it. This is only a short scan.
  • Once the short scan has finished, mark the drives that you want to scan.
  • Select all drives. A red dot shows which drives have been chosen.
  • Click the green arrow at the right, and the scan will start.
  • Click 'Yes to all' if it asks if you want to cure/move the file.
  • When the scan has finished, look if you can click next icon next to the files found: [external image: Posted Image]
  • If so, click it and then click the next icon right below and select Move incurable as you'll see in next image:
    [external image: Posted Image]
    This will move it to the %userprofile%\DoctorWeb\quarantaine-folder if it can't be cured. (this in case if we need samples)
  • After selecting, in the Dr.Web CureIt menu on top, click file and choose save report list
  • Save the report to your desktop. The report will be called DrWeb.csv
  • Close Dr.Web Cureit.
  • Reboot your computer!! Because it could be possible that files in use will be moved/deleted during reboot.
  • After reboot, post the contents of the log from Dr.Web you saved previously in your next reply.
Here are the results of the Dr. Web CureIt run: aolconnfix.exe;C:\;Trojan.PWS.Gamania.origin;Incurable.Moved.; inst.exe;C:\Documents and Settings\All Users\Application Data\AOL Downloads\AIMSUD338;Probably BACKDOOR.Trojan;Incurable.Moved.; setup.exe;C:\Documents and Settings\All Users\Application Data\AOL Downloads\CCU_SUITE_1.0.48.1;Probably BACKDOOR.Trojan;Incurable.Moved.; config.000;C:\Documents and Settings\All Users\Application Data\AOL Downloads\ssc_suite_installer_1.10.7.1;Probably BACKDOOR.Trojan;Incurable.Moved.; inst.exe;C:\Documents and Settings\All Users\Application Data\AOL Downloads\ssc_suite_installer_1.210.2.4_suite;Probably BACKDOOR.Trojan;Incurable.Moved.; inst.exe;C:\Documents and Settings\All Users\Application Data\AOL Downloads\SUD4024;Probably BACKDOOR.Trojan;Incurable.Moved.; inst.exe;C:\Documents and Settings\All Users\Application Data\AOL Downloads\SUD4028;Probably BACKDOOR.Trojan;Incurable.Moved.; setup.exe;C:\Documents and Settings\All Users\Application Data\AOL Downloads\SUD4131;Probably BACKDOOR.Trojan;Incurable.Moved.; setup.exe;C:\Documents and Settings\All Users\Application Data\AOL Downloads\triton_suite_install_2.0.6.1;Probably BACKDOOR.Trojan;Incurable.Moved.; config.000;C:\Program Files\AOL\Installers\AOL Safety & Security Center 1.0;Probably BACKDOOR.Trojan;Incurable.Moved.; inst.exe;C:\Program Files\AOL\Installers\AOL Safety & Security Center 1.0;Probably BACKDOOR.Trojan;Incurable.Moved.; inst.exe;C:\Program Files\AOL\Installers\AOL Safety & Security Center 1.02;Probably BACKDOOR.Trojan;Incurable.Moved.; setup.exe;C:\Program Files\AOL\Internet Access Controls\Installer;Probably BACKDOOR.Trojan;Incurable.Moved.; ppctl.dll;C:\Program Files\Common Files\AOL\1141430684\EE\services\antispyware\ver2_4_9_1\resources;Probably DLOADER.Trojan;Incurable.Moved.; GTDownAO_106.ocx;C:\Program Files\Common Files\AolCoach\en_en;Adware.Gdown;Incurable.Moved.; ppctl.dll;C:\Program Files\Common Files\Scanner;Probably DLOADER.Trojan;Incurable.Moved.; A0001469.exe;C:\System Volume Information\_restore{9F5B8467-C0CD-484D-AC3E-FAF06F4DB308}\RP9;Trojan.PWS.Gamania.origin;Incurable.Moved.; popcaploader.dll;C:\WINDOWS\Downloaded Program Files;Program.PopcapLoader;Incurable.Moved.;
I ran AimFix and it found and disabled and deleted NPKCSVC Service and quarantined c:\WINDOWS\system32\NPKCSVC.exe. Then I rebooted. It said a reboot was needed to finish doing it's job. Any other ideas on things to do? I haven't even tried to access any AOL products. Do you think it would be worth uninstalling all of it (saving the user data) and reloading from a CD or a fresh download? Also, should i dump the restore files by turning off the feature and then turn it on again after a reboot? Any need for a new HJT log or start-up list?
Here is the AIMFix Note: AIMFix version: 1.6.1220.935 (Dec 20 2007 09:35:55) SeDebug Privilege set successfully ***ANY VIRUS FILES REMOVED WILL BE LISTED BELOW*** BlockRemove(): Now checking for Block-Checker: .5 BlockRemove(): Block-Checker not found IMNamesRemove(): Now checking for IMNames: .2 IMNamesRemove(): IM Names not found ServiceExists(): Found service npkcsvc StopService(): failed on call to ControlService() for "npkcsvc": The service has not been started. KillService(): Unable to stop service, trying kill Service npkcsvc successfully disabled Service npkcsvc successfully deleted Now attempting quarantine of "npkcsvc" executable: C:\WINDOWS\system32\npkcsvc.exe File::Quarantine(): attempting to quarantine C:\WINDOWS\system32\npkcsvc.exe quarantine(): C:\WINDOWS\system32\npkcsvc.exe quarantined CleanMstc(): mstc not found ***RUN COMPLETED. ANY FILES REMOVED LISTED ABOVE*** ———————————————————-
I ran Dr.Web CureIt again. Here is the file: A0001470.exe;C:\System Volume Information\_restore{9F5B8467-C0CD-484D-AC3E-FAF06F4DB308}\RP9;Probably BACKDOOR.Trojan;Incurable.Moved.; A0001471.exe;C:\System Volume Information\_restore{9F5B8467-C0CD-484D-AC3E-FAF06F4DB308}\RP9;Probably BACKDOOR.Trojan;Incurable.Moved.; A0001472.exe;C:\System Volume Information\_restore{9F5B8467-C0CD-484D-AC3E-FAF06F4DB308}\RP9;Probably BACKDOOR.Trojan;Incurable.Moved.; A0001473.exe;C:\System Volume Information\_restore{9F5B8467-C0CD-484D-AC3E-FAF06F4DB308}\RP9;Probably BACKDOOR.Trojan;Incurable.Moved.; A0001474.exe;C:\System Volume Information\_restore{9F5B8467-C0CD-484D-AC3E-FAF06F4DB308}\RP9;Probably BACKDOOR.Trojan;Incurable.Moved.; A0001475.exe;C:\System Volume Information\_restore{9F5B8467-C0CD-484D-AC3E-FAF06F4DB308}\RP9;Probably BACKDOOR.Trojan;Incurable.Moved.; A0001476.exe;C:\System Volume Information\_restore{9F5B8467-C0CD-484D-AC3E-FAF06F4DB308}\RP9;Probably BACKDOOR.Trojan;Incurable.Moved.; A0001477.exe;C:\System Volume Information\_restore{9F5B8467-C0CD-484D-AC3E-FAF06F4DB308}\RP9;Probably BACKDOOR.Trojan;Incurable.Moved.; A0001478.exe;C:\System Volume Information\_restore{9F5B8467-C0CD-484D-AC3E-FAF06F4DB308}\RP9;Probably BACKDOOR.Trojan;Incurable.Moved.; A0001479.exe;C:\System Volume Information\_restore{9F5B8467-C0CD-484D-AC3E-FAF06F4DB308}\RP9;Probably BACKDOOR.Trojan;Incurable.Moved.; A0001480.dll;C:\System Volume Information\_restore{9F5B8467-C0CD-484D-AC3E-FAF06F4DB308}\RP9;Probably DLOADER.Trojan;Incurable.Moved.; A0001481.ocx;C:\System Volume Information\_restore{9F5B8467-C0CD-484D-AC3E-FAF06F4DB308}\RP9;Adware.Gdown;Incurable.Moved.; A0001482.dll;C:\System Volume Information\_restore{9F5B8467-C0CD-484D-AC3E-FAF06F4DB308}\RP9;Probably DLOADER.Trojan;Incurable.Moved.; Looks like they were all in that restore file, so I turned off system restore - no sense keeping what I don't want to go back to.
I suggest you now create a new clean System Restore.

You need to create a new Clean restore point.

Note: This will remove all previous Restore Points

Click Start Menu > Run > copy and paste

%SystemRoot%\System32\restore\rstrui.exe

Press OK. Choose Create a Restore Point then click Next. Name it (something you'll remember) and click Create, when the confirmation screen shows the restore point has been created click Close.

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Check "Hide file extensions for known file types."
Under the "Hidden files" folder, Uncheck "Show hidden files and folders."
Check "Hide protected operating system files."
Click Apply, and then click OK.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI