This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] TrustedAntivirus Problem

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hey, this all started with Trustedantivirus getting on my comp. I tried several programs to get rid of it to no avail.

When i luckily came across your website, i did as instructed and used ATF cleaner and ran spybot, it seemed to kill it.

I no longer have the icon in the bottom right taskbar, nor do i have pop ups shooting up all the time, or websites being redirected, Also iam able to get into my task manager again smile.gif

I do have one problem left, without seeing anything i hear advertisements, i did find, that i could go to the task manager and go to processes and i found a iexplorer was running, once i stopped it, the advertisements stopped. (I normally use Firefox, so it seemed odd that iexplorer was running).


Anyways, am not 100% that its gone because of that, the following is my hijackthis log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:37:52 PM, on 2/27/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\Ati2evxx.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\Ati2evxx.exe
D:\WINDOWS\system32\spoolsv.exe
D:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
D:\Program Files\Bonjour\mDNSResponder.exe
D:\Program Files\Viewpoint\Common\ViewpointService.exe
D:\WINDOWS\system32\ctfmon.exe
D:\Program Files\Windows Live\Messenger\msnmsgr.exe
D:\WINDOWS\explorer.exe
D:\Program Files\Windows Live\Messenger\usnsvc.exe
D:\Program Files\Windows Media Player\wmplayer.exe
D:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
D:\WINDOWS\system32\wisptis.exe
D:\WINDOWS\System32\svchost.exe
D:\Program Files\Mozilla Firefox\firefox.exe
D:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
D:\WINDOWS\system32\NOTEPAD.EXE
D:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://softwarereferral.com/jump.php?wmid=…6Ojg5&lid=2
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SXG Advisor - {4C0C8119-1DF3-43EB-9551-B58AF1E04CA9} - D:\WINDOWS\dgtxrdfknf.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - D:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: ekvgsnw - {CBBF7BAC-D39B-4FC2-930E-8C2F6C73B45F} - D:\WINDOWS\ekvgsnw.dll (file missing)
O4 - HKLM\..\RunOnce: [SpybotDeletingA4316] command /c del "D:\WINDOWS\bxlrvps.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7051] cmd /c del "D:\WINDOWS\bxlrvps.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4572] command /c del "D:\WINDOWS\ekvgsnw.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9083] cmd /c del "D:\WINDOWS\ekvgsnw.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA291] command /c del "D:\WINDOWS\bxlrvps.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5349] cmd /c del "D:\WINDOWS\bxlrvps.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6598] command /c del "D:\WINDOWS\ekvgsnw.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC303] cmd /c del "D:\WINDOWS\ekvgsnw.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2064] command /c del "D:\WINDOWS\bxlrvps.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3002] cmd /c del "D:\WINDOWS\bxlrvps.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5974] command /c del "D:\WINDOWS\ekvgsnw.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9203] cmd /c del "D:\WINDOWS\ekvgsnw.dll_old"
O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "D:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] D:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\RunOnce: [SpybotDeletingB8459] command /c del "D:\WINDOWS\bxlrvps.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4745] cmd /c del "D:\WINDOWS\bxlrvps.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8994] command /c del "D:\WINDOWS\ekvgsnw.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4553] cmd /c del "D:\WINDOWS\ekvgsnw.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5199] command /c del "D:\WINDOWS\bxlrvps.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8088] cmd /c del "D:\WINDOWS\bxlrvps.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8380] command /c del "D:\WINDOWS\ekvgsnw.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7263] cmd /c del "D:\WINDOWS\ekvgsnw.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1394] command /c del "D:\WINDOWS\bxlrvps.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7476] cmd /c del "D:\WINDOWS\bxlrvps.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7820] command /c del "D:\WINDOWS\ekvgsnw.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4701] cmd /c del "D:\WINDOWS\ekvgsnw.dll_old"
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {37A273C2-5129-11D5-BF37-00A0CCE8754B} (TTestGenXInstallObject) - http://asp.mathxl.com/wizmodules/testgen/i…GenXInstall.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1201476623038
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1201482720827
O16 - DPF: {95D88B35-A521-472B-A182-BB1A98356421} (Pearson Installation Assistant 2) - http://asp.mathxl.com/books/_Players/PearsonInstallAsst2.cab
O16 - DPF: {E6D23284-0E9B-417D-A782-03E4487FC947} (Pearson MathXL Player) - http://asp.mathxl.com/books/_Players/MathPlayer.cab
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} (PCPitstop Exam) - http://utilities.pcpitstop.com/optimize2/pcpitstop2.dll
O21 - SSODL: bxlrvps - {558B43FC-E4CA-4B68-8698-7E684A53B786} - D:\WINDOWS\bxlrvps.dll (file missing)
O21 - SSODL: alofkmn - {A5B24AB2-E5F8-4BE9-A799-2B266A1B31C1} - D:\WINDOWS\alofkmn.dll
O21 - SSODL: CheckKbd - {2c22162d-92b7-4058-b7f8-23e16a543822} - D:\WINDOWS\Installer\{2c22162d-92b7-4058-b7f8-23e16a543822}\CheckKbd.dll
O21 - SSODL: KernelSys - {f0485443-ec6b-439a-8827-9d0871ec8bf0} - D:\WINDOWS\Installer\{f0485443-ec6b-439a-8827-9d0871ec8bf0}\KernelSys.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - D:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - D:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - D:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Bonjour Service - Apple Inc. - D:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: iPod Service - Apple Inc. - D:\Program Files\iPod\bin\iPodService.exe
O23 - Service: SiSoftware Database Agent Service (SandraDataSrv) - SiSoftware - D:\Program Files\SiSoftware\SiSoftware Sandra Lite XI\Win32\RpcDataSrv.exe
O23 - Service: SiSoftware Sandra Agent Service (SandraTheSrv) - SiSoftware - D:\Program Files\SiSoftware\SiSoftware Sandra Lite XI\RpcSandraSrv.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - D:\Program Files\Viewpoint\Common\ViewpointService.exe

–
End of file - 8407 bytes





Any and all help is much appreciated smile.gif
Hello

Before we begin, you should save these instructions in Notepad to your desktop, or print them, for easy reference. Much of our fix will be done in Safe mode, and you will be unable to access this thread at that time. If you have questions at any point, or are unsure of the instructions, feel free to post here and ask for clarification before proceeding.


Please download SmitfraudFix (by S!Ri) to your Desktop.

Next, please reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, a menu with options should appear;
  • Select the first option, to run Windows in Safe Mode, then press "Enter".
  • Choose your usual account.
Once in Safe Mode, double-click on SmitfraudFix.exe
Select option #2 - Clean by typing 2 and press "Enter" to delete infected files.

You will be prompted : "Registry cleaning - Do you want to clean the registry ?"; answer "Yes" by typing Y and press "Enter" in order to remove the Desktop background and clean registry keys associated with the infection.

The tool will now check if wininet.dll is infected. You may be prompted to replace the infected file (if found); answer "Yes" by typing Y and press "Enter".

The tool may need to restart your computer to finish the cleaning process; if it doesn't, please restart it into Normal Windows.
A text file will appear onscreen, with results from the cleaning process; please copy/paste the content of that report into your next reply.
The report can also be found at the root of the system drive, usually at C:\rapport.txt

Warning : running option #2 on a non infected computer will remove your Desktop background.



Please download Deckard's System Scanner (DSS) and save it to your Desktop.
  • Close all other windows before proceeding.
  • Double-click on dss.exe and follow the prompts.
  • If your anti-virus or firewall complains, please allow this script to run as it is not malicious.
  • When it has finished, dss will open two Notepads main.txt and extra.txt – please copy (CTRL+A and then CTRL+C) and paste (CTRL+V) the contents of main.txt and extra.txt in your next reply.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI