This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Last Check Up Before All Clear

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hey guys, this is spike again. I had just wiped my computer and I just installed Avira Antivirus. Just to make sure everything was working ok, I had updated the program to it's current database, and ran a scan. I run a scan, and this is what I found…



Avira AntiVir Personal
Report file date: Wednesday, October 15, 2008 22:16

Scanning for 1686590 virus strains and unwanted programs.

Licensed to: Avira AntiVir PersonalEdition Classic
Serial number: 0000149996-ADJIE-0001
Platform: Windows XP
Windows version: (Service Pack 2) [5.1.2600]
Boot mode: Normally booted
Username: SYSTEM
Computer name: BOBSON-2KNV81CD

Version information:
BUILD.DAT : 8.1.0.331 16934 Bytes 8/12/2008 11:46:00
AVSCAN.EXE : 8.1.4.7 315649 Bytes 6/26/2008 14:57:53
AVSCAN.DLL : 8.1.4.0 40705 Bytes 5/26/2008 13:56:40
LUKE.DLL : 8.1.4.5 164097 Bytes 6/12/2008 18:44:19
LUKERES.DLL : 8.1.4.0 12033 Bytes 5/26/2008 13:58:52
ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 7/18/2007 16:33:34
ANTIVIR1.VDF : 7.0.5.1 8182784 Bytes 6/24/2008 19:54:15
ANTIVIR2.VDF : 7.0.7.12 4066816 Bytes 10/8/2008 02:13:29
ANTIVIR3.VDF : 7.0.7.45 241664 Bytes 10/15/2008 02:13:32
Engineversion : 8.2.0.4
AEVDF.DLL : 8.1.0.6 102772 Bytes 10/16/2008 02:13:52
AESCRIPT.DLL : 8.1.1.8 319866 Bytes 10/16/2008 02:13:51
AESCN.DLL : 8.1.1.3 123252 Bytes 10/16/2008 02:13:49
AERDL.DLL : 8.1.1.2 438644 Bytes 10/16/2008 02:13:48
AEPACK.DLL : 8.1.2.4 369014 Bytes 10/16/2008 02:13:46
AEOFFICE.DLL : 8.1.0.28 196987 Bytes 10/16/2008 02:13:44
AEHEUR.DLL : 8.1.0.59 1438071 Bytes 10/16/2008 02:13:43
AEHELP.DLL : 8.1.1.2 115062 Bytes 10/16/2008 02:13:38
AEGEN.DLL : 8.1.0.41 319861 Bytes 10/16/2008 02:13:37
AEEMU.DLL : 8.1.0.9 393588 Bytes 10/16/2008 02:13:35
AECORE.DLL : 8.1.2.6 172406 Bytes 10/16/2008 02:13:34
AEBB.DLL : 8.1.0.3 53618 Bytes 10/16/2008 02:13:33
AVWINLL.DLL : 1.0.0.12 15105 Bytes 7/9/2008 14:40:05
AVPREF.DLL : 8.0.2.0 38657 Bytes 5/16/2008 15:28:01
AVREP.DLL : 8.0.0.2 98344 Bytes 10/16/2008 02:13:32
AVREG.DLL : 8.0.0.1 33537 Bytes 5/9/2008 17:26:40
AVARKT.DLL : 1.0.0.23 307457 Bytes 2/12/2008 14:29:23
AVEVTLOG.DLL : 8.0.0.16 119041 Bytes 6/12/2008 18:27:49
SQLITE3.DLL : 3.3.17.1 339968 Bytes 1/22/2008 23:28:02
SMTPLIB.DLL : 1.2.0.23 28929 Bytes 6/12/2008 18:49:40
NETNT.DLL : 8.0.0.1 7937 Bytes 1/25/2008 18:05:10
RCIMAGE.DLL : 8.0.0.51 2371841 Bytes 6/12/2008 19:48:07
RCTEXT.DLL : 8.0.52.0 86273 Bytes 6/27/2008 19:34:37

Configuration settings for the scan:
Jobname……………………..: Complete system scan
Configuration file……………: c:\program files\avira\antivir personaledition classic\sysscan.avp
Logging……………………..: low
Primary action……………….: interactive
Secondary action……………..: ignore
Scan master boot sector……….: on
Scan boot sector……………..: on
Boot sectors…………………: C:,
Process scan…………………: on
Scan registry………………..: on
Search for rootkits…………..: off
Scan all files……………….: Intelligent file selection
Scan archives………………..: on
Recursion depth………………: 20
Smart extensions……………..: on
Macro heuristic………………: on
File heuristic……………….: medium

Start of the scan: Wednesday, October 15, 2008 22:16

The scan of running processes will be started
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'avcenter.exe' - '1' Module(s) have been scanned
Scan process 'avgnt.exe' - '1' Module(s) have been scanned
Scan process 'avguard.exe' - '1' Module(s) have been scanned
Scan process 'sched.exe' - '1' Module(s) have been scanned
Scan process 'WlanCU.exe' - '1' Module(s) have been scanned
Scan process 'atidtct.exe' - '1' Module(s) have been scanned
Scan process 'winampa.exe' - '1' Module(s) have been scanned
Scan process 'Directcd.exe' - '1' Module(s) have been scanned
Scan process 'hkcmd.exe' - '1' Module(s) have been scanned
Scan process 'alg.exe' - '1' Module(s) have been scanned
Scan process 'explorer.exe' - '1' Module(s) have been scanned
Scan process 'wdfmgr.exe' - '1' Module(s) have been scanned
Scan process 'SiSWLSvc.exe' - '1' Module(s) have been scanned
Scan process 'HPZipm12.exe' - '1' Module(s) have been scanned
Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'lsass.exe' - '1' Module(s) have been scanned
Scan process 'services.exe' - '1' Module(s) have been scanned
Scan process 'winlogon.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'smss.exe' - '1' Module(s) have been scanned
26 processes with 26 modules were scanned

Starting master boot sector scan:
Master boot sector HD0
[INFO] No virus was found!

Start scanning boot sectors:
Boot sector 'C:\'
[INFO] No virus was found!

Starting to scan the registry.
The registry was scanned ( '54' files ).


Starting the file scan:

Begin scan in 'C:\'
C:\pagefile.sys
[WARNING] The file could not be opened!
C:\To Back UP\Sumotori\sumotori102.zip
[0] Archive type: ZIP
–> sumotori87k.exe
[DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
[NOTE] The file was moved to '4963a622.qua'!
C:\To Back UP\Sumotori\sumotori87k.exe
[DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
[NOTE] The file was moved to '481e3d03.qua'!


End of the scan: Wednesday, October 15, 2008 22:34
Used time: 18:19 Minute(s)

The scan has been done completely.

2241 Scanning directories
104095 Files were scanned
2 viruses and/or unwanted programs were found
0 Files were classified as suspicious:
0 files were deleted
0 files were repaired
2 files were moved to quarantine
0 files were renamed
1 Files cannot be scanned
104092 Files not concerned
729 Archives were scanned
1 Warnings
2 Notes

Now after seeing this, I delete the two files that were infected. And then I ran a second scan:



Avira AntiVir Personal
Report file date: Wednesday, October 15, 2008 22:41

Scanning for 1686590 virus strains and unwanted programs.

Licensed to: Avira AntiVir PersonalEdition Classic
Serial number: 0000149996-ADJIE-0001
Platform: Windows XP
Windows version: (Service Pack 2) [5.1.2600]
Boot mode: Normally booted
Username: Owner
Computer name: BOBSON-2KNV81CD

Version information:
BUILD.DAT : 8.1.0.331 16934 Bytes 8/12/2008 11:46:00
AVSCAN.EXE : 8.1.4.7 315649 Bytes 6/26/2008 14:57:53
AVSCAN.DLL : 8.1.4.0 40705 Bytes 5/26/2008 13:56:40
LUKE.DLL : 8.1.4.5 164097 Bytes 6/12/2008 18:44:19
LUKERES.DLL : 8.1.4.0 12033 Bytes 5/26/2008 13:58:52
ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 7/18/2007 16:33:34
ANTIVIR1.VDF : 7.0.5.1 8182784 Bytes 6/24/2008 19:54:15
ANTIVIR2.VDF : 7.0.7.12 4066816 Bytes 10/8/2008 02:13:29
ANTIVIR3.VDF : 7.0.7.45 241664 Bytes 10/15/2008 02:13:32
Engineversion : 8.2.0.4
AEVDF.DLL : 8.1.0.6 102772 Bytes 10/16/2008 02:13:52
AESCRIPT.DLL : 8.1.1.8 319866 Bytes 10/16/2008 02:13:51
AESCN.DLL : 8.1.1.3 123252 Bytes 10/16/2008 02:13:49
AERDL.DLL : 8.1.1.2 438644 Bytes 10/16/2008 02:13:48
AEPACK.DLL : 8.1.2.4 369014 Bytes 10/16/2008 02:13:46
AEOFFICE.DLL : 8.1.0.28 196987 Bytes 10/16/2008 02:13:44
AEHEUR.DLL : 8.1.0.59 1438071 Bytes 10/16/2008 02:13:43
AEHELP.DLL : 8.1.1.2 115062 Bytes 10/16/2008 02:13:38
AEGEN.DLL : 8.1.0.41 319861 Bytes 10/16/2008 02:13:37
AEEMU.DLL : 8.1.0.9 393588 Bytes 10/16/2008 02:13:35
AECORE.DLL : 8.1.2.6 172406 Bytes 10/16/2008 02:13:34
AEBB.DLL : 8.1.0.3 53618 Bytes 10/16/2008 02:13:33
AVWINLL.DLL : 1.0.0.12 15105 Bytes 7/9/2008 14:40:05
AVPREF.DLL : 8.0.2.0 38657 Bytes 5/16/2008 15:28:01
AVREP.DLL : 8.0.0.2 98344 Bytes 10/16/2008 02:13:32
AVREG.DLL : 8.0.0.1 33537 Bytes 5/9/2008 17:26:40
AVARKT.DLL : 1.0.0.23 307457 Bytes 2/12/2008 14:29:23
AVEVTLOG.DLL : 8.0.0.16 119041 Bytes 6/12/2008 18:27:49
SQLITE3.DLL : 3.3.17.1 339968 Bytes 1/22/2008 23:28:02
SMTPLIB.DLL : 1.2.0.23 28929 Bytes 6/12/2008 18:49:40
NETNT.DLL : 8.0.0.1 7937 Bytes 1/25/2008 18:05:10
RCIMAGE.DLL : 8.0.0.51 2371841 Bytes 6/12/2008 19:48:07
RCTEXT.DLL : 8.0.52.0 86273 Bytes 6/27/2008 19:34:37

Configuration settings for the scan:
Jobname……………………..: Manual Selection
Configuration file……………: C:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\PROFILES\folder.avp
Logging……………………..: low
Primary action……………….: interactive
Secondary action……………..: ignore
Scan master boot sector……….: on
Scan boot sector……………..: on
Boot sectors…………………: C:,
Process scan…………………: on
Scan registry………………..: on
Search for rootkits…………..: off
Scan all files……………….: Intelligent file selection
Scan archives………………..: on
Recursion depth………………: 20
Smart extensions……………..: on
Macro heuristic………………: on
File heuristic……………….: medium

Start of the scan: Wednesday, October 15, 2008 22:41

The scan of running processes will be started
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'notepad.exe' - '1' Module(s) have been scanned
Scan process 'avcenter.exe' - '1' Module(s) have been scanned
Scan process 'avgnt.exe' - '1' Module(s) have been scanned
Scan process 'avguard.exe' - '1' Module(s) have been scanned
Scan process 'sched.exe' - '1' Module(s) have been scanned
Scan process 'WlanCU.exe' - '1' Module(s) have been scanned
Scan process 'atidtct.exe' - '1' Module(s) have been scanned
Scan process 'winampa.exe' - '1' Module(s) have been scanned
Scan process 'Directcd.exe' - '1' Module(s) have been scanned
Scan process 'hkcmd.exe' - '1' Module(s) have been scanned
Scan process 'alg.exe' - '1' Module(s) have been scanned
Scan process 'explorer.exe' - '1' Module(s) have been scanned
Scan process 'wdfmgr.exe' - '1' Module(s) have been scanned
Scan process 'SiSWLSvc.exe' - '1' Module(s) have been scanned
Scan process 'HPZipm12.exe' - '1' Module(s) have been scanned
Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'lsass.exe' - '1' Module(s) have been scanned
Scan process 'services.exe' - '1' Module(s) have been scanned
Scan process 'winlogon.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'smss.exe' - '1' Module(s) have been scanned
27 processes with 27 modules were scanned

Starting master boot sector scan:
Master boot sector HD0
[INFO] No virus was found!

Start scanning boot sectors:
Boot sector 'C:\'
[INFO] No virus was found!

Starting to scan the registry.
The registry was scanned ( '54' files ).


Starting the file scan:

Begin scan in 'C:\'
C:\pagefile.sys
[WARNING] The file could not be opened!


End of the scan: Wednesday, October 15, 2008 23:01
Used time: 20:26 Minute(s)

The scan has been done completely.

2138 Scanning directories
98720 Files were scanned
0 viruses and/or unwanted programs were found
0 Files were classified as suspicious:
0 files were deleted
0 files were repaired
0 files were moved to quarantine
0 files were renamed
1 Files cannot be scanned
98719 Files not concerned
720 Archives were scanned
1 Warnings
0 Notes

Now I'm not really sure what this pagefile.sys file is, and it's rather large, so I'm a little nervous about it being a hidden system file. I also put up a hijackthis log just to see if everything is all clear…

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:02:40 PM, on 10/15/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\Program Files\802.11 Wireless LAN\802.11g Pen Size Wireless USB 2.0 Adapter HW.32 V1.10\SiSWLSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\ATI Multimedia\main\ATIDtct.EXE
C:\Program Files\802.11 Wireless LAN\802.11g Pen Size Wireless USB 2.0 Adapter HW.32 V1.10\WlanCU.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avcenter.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [ATI Launchpad] "C:\Program Files\ATI Multimedia\main\launchpd.exe"
O4 - HKCU\..\Run: [ATI DeviceDetect] C:\Program Files\ATI Multimedia\main\ATIDtct.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Wireless Configuration Utility HW.32.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - C:\Program Files\ATI Multimedia\tv\EXPLBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1224116669249
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1224116657640
O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: SiS WirelessLan Service (SiSWLSvc) - Unknown owner - C:\Program Files\802.11 Wireless LAN\802.11g Pen Size Wireless USB 2.0 Adapter HW.32 V1.10\SiSWLSvc.exe

–
End of file - 3574 bytes


I don't know if this was the correct thing to do as far as rather I should be using my old topic or not, but if I did something wrong, I'll get on top of it right away.
Hi :)

pagefile.sys is perfectly legit - it is a file used by Windows for something called paging, also known as Virtual Memory. See this wiki article for a bit more technical information if you are interested:
http://en.wikipedia.org/wiki/Paging#Windows_NT
(I've linked to the Windows section that mentions pagefile.sys, the article as a whole describes the paging process).

The second Avira scan came back clean, and your HJT log is fine. If you aren't having any problems then I would say you are good to go :thumbup:

I do have one or two things to mention as for security though.

You don't appear to be running any third party Firewall software.

Install a firewall! Without a firewall you are very susceptible to being hacked, and people could gain access to your computer. If you don't have a firewall I strongly recommend you download ONE of the following:
1) Comodo
2) Agnitum
3) Sunbelt/Kerio
Alternatively, if you are using a Router to connect to the internet, then it would suffice to use Windows Firewall as your Firewall, since the Router should have a hardware Firewall built in. Should you wish to use Windows Firewall, make sure you are logged in as an Administrator and you can find it in Start >> Control Panel >> Windows Firewall.


You need to upgrade to Windows XP Service Pack 3. Keeping your Windows up-to-date is crucial to your computer's security. Please go to the Windows Update Site (using Internet Explorer) and download and install Windows XP - Service Pack 3.

Any more questions or problems?

Thanks.
Alright, that's great to know. I'm a little bit more at ease, knowing that my computer is squeaky clean, and I appreciate the exclamation to that file in question. I've recently reformatted, so I've been trying to install things as quickly as possible. I've just downloaded the ZoneAlarm firewall that Noviciate had suggested, but I'm uncertain I may keep this, since it makes my computer run rather slow… Almost makes me think of my computer as a pile of inpenetrable bricks, but I'd rather have a guarded computer than a fast one. I'll install the XP Service Pack 3 ASAP. Thanks a lot for your exclamation! Spike
Well, I have one more question. In your personal opinion, which fire wall would be the best choice for an old computer? I've had this bucket of bolts for about 5 years, and it can't handle as much as newer computers these days. I'll stick with the one I have if need be, but if there's one that isn't so CPU consuming, I'll more than likely switch over to another one.
I personally switched from ZoneAlarm to Comodo a while back, and haven't had any need for a change. It's hard to say without testing which would use less CPU/Memory but I've personally never had any problems with Comodo. As for protection the personally I think Comodo is right up there, and the other two I recommended above are pretty good too. Often it does take a bit of trial and error to find a piece of security software that works for you. Everybody has different standards, wants different features and has different preferences when it comes to these pieces of software. So in conclusion, I'm afraid I don't have a direct answer to your question. I can only recommend the above Firewalls based on the fact that they are free, have good protection, and aren't flagged as high resource hogs (although in reality this may differ). Hope that helps.
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI