This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] hello again, i think i'm infected with something

24 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

i didn't know that….. i often edit if i mis-spell…and i just got another trojan. jeesh, this makes four. i can't keep staying on line with no protection, i'm just being attacked left and right here…. here is what I said in my last post: cut and pasting here: ok….. i hit ok..it says the publisher cannot be verified, do you want to run this anyway…i hit yes or ok…and then a little rectangular box box approximately 1/4 inch wide by one inch long pops up in the middle of screen…. says combofix…and the little green bars like the program is trying to open fill the whole box….and then the error message pops up from prep.com…some infections can't be healed is this a serious trojan thing that will screw with my computer innards…..or just like it said, has something to do with adware….. and what was with that third trojan coming in? am I going to experience a glut of trojans now? especially since now I have all my security stuff turned off???? ok…i'm very nervous here with no security on now….. i'm shutting down….. don't want another trojan hitting me, and i so seem to be on the hit list. i'll log back on tomorrow night…. …..same thing applies, I'm outta here…. just got hit again…
ok…went back and turned on some of my stuff….. turned the windows firewall back on…… apparently the windows virus protection was still on….. i think i mentioned that earler, i couldn't seem to shut off the windows virus protection, but my avg, scotty and other stuff is all off.
went to turn stuff back on …… the scan is running as i type…so far i have 10 trojans…all of them BackDoor. Small X. VX….jeesh. ok, here's the problem probably….. WHAT THE HECK IS THIS SYSTEM TRAY I WAS SUPPOSED TO GO INTO TO SHUT THINGS OFF??? Because when i went into AVG, everything supposedly was still on except for email protection……so i did not shut off anything when i went into the lower right hand corner of my tool bar and hit "EXIT"……..exit doesn't turn everything off. I have spybot, the scotty dog and avg…and I was still getting trojans, the first ones were """ adload"….now these are BackDoor…. please tell me that these are not the ones they warned about a couple of weeks ago that steal all your passwords.
yesterday, I couldn't find anything about the trojan adload, but now i see this allows anyone to hack my computer. great. my scans take half an hour now….. my computer must be loaded with all kinds of junk files because it used to take about 15 minutes…now it takes a half an hour. hopefully when the scan finishes it will get rid of the virus…..
compudodo, The task bar is the bar at the very bottom of your screen. It has Start on the far left and the clock on the far right. You are correct that staying on the internet unprotected is a bad thing, if you only shut off the real time scanning portion of your security software, you are minimizing the risk. We just want it to run without interfering with the tools we are trying to run. The Anti-Virus programs often target our cleaning tools as trojans or viruses, it then doesn't let them work as intended. At this point, I don't see any backdoor trojan on your system. I do see a downloader though. The downloader will try to bring other trojans on to your system so we need to get rid of it. If your anti-virus catches the trojan and "cleans" it, it doesn't get installed on your system and nefarious persons do not gain access to your information. I need to know exactly what the error is that you get when you try to run Combofix.
Prep.com has encountered a problem…… is the message and as soon as I double clicked on combo fix, I got another trojan!!!! what the heck??? all my virus protection is on now…. how do I keep getting this???
oh….I get it….I am getting these backdoor trojans because the initial trojan just makes it easier….. but I got two of the "load" trojans at once……. but only one was quarantined or taken care of, the AVG couldn't do anything with the second one….I got both at the same time. why was that? why was the one trojan able to be healed and the other one not? …well, I'm running a scan again to get rid of the new back door trojan
yeah, ok…the scan is going to take another half hour…and then i have to go to work……. but still…… did i do the right thing by using the right side of the bottom tool bar to "temporarily" shut off those three programs, scotty, spybot and avg? because apparently not….. i kept getting notices I was getting trojans…heck, I got 10 in all this morning….. is the bottom tool bar what you are calling the system tray? I just hit the "exit" option on them the first time, was that sufficient in being able to access combo fix? apparently not, as I couldn't access combo fix…something was still turned on…… even when i went into the control panel and windows security settings, I could only shut off the firewall, I could not disable the virus protection …. the green button would not turn off.
compudodo,

Basically I think that you are doing everything right. What I'm thinking has happened is that AVG has "healed" part of ComboFix so that it won't work correctly,

We need AVG not to try to scan it, and if it does, you need to have AVG ignore it.

Try this, Drag your copy of ComboFix to your recycle bin (or Right click on it and select delete)

Download a new Copy of ComboFix to your desktop

Then try this to shut off real time protection of AVG, don't worry about any of the other programs.

AVG
Please open the AVG Control Center program -> double-click on the "AVG Resident Shield" component (looks like this: [external image: Posted Image]) -> deselect the "Turn on AVG Resident Shield" checkmark and save the setting.
When you need to enable the AVG Resident Shield, ( I will let you know when) just open the AVG Control Center program -> double-click on the "AVG Resident Shield" component -> select the "Turn on AVG Resident Shield" checkmark and save the setting.

Then:

Go to [external image: Posted Image] -> Run -> copy/paste the following single line command in the runbox & click OK

"%userprofile%\desktop\combofix.exe" /killall

[external image: Posted Image]
  • DO NOT USE your computer for any other purpose while ComboFix is running.
  • ComboFix may restart your computer, this is normal.
  • When finished, it will produce a log, ComboFix.txt.
  • Please post ComboFix.txt in your next reply along with a new HijackThis log.

PS: Congratulations on finding a job. :notworthy:
i'm at work now…… checking all my stuff, cause i'm afraid to use the computer at home….. i'll do all you said to do when i get home, OK???? Yeah, I have a job…. got hired because the man was totally desperate LOL…….. it's a small internet company actually LOL…we do all our business online, have no retail outlets….. i can get by with my cut and paste skills….I am (ahem) THE CUSTOMER SERVICE/SHIPPING/OFFICE MANAGER (ta-dahhh) for Gunter Wilhelm …..it's just the two of us!!! I was NOT the first choice …oh no….he hired someone much younger…but go figure, there was someone even stupider than me in the world, the guy couldn't cut and paste!!! LOL……so he was desperate, called me up, told me to come in…no resume, no references, no background check, he just hired me!!!!!!! He was leaving the country for just over 3 weeks between Dec. 22 and January 14….. so he needed someone pronto to learn the ropes quickly….so here I am…it's not full time, but he is a wonderful man to have given me this chance…no one else would hire an almost 60 year old woman…….. he has a heart of gold, really…so I am very grateful to have this…am just squeaking by, but it's better than having nothing at all, like all of last year. If you need any superduper cutlery ….truly this man has designed just beautiful knives, you let me know…also cookware, we are coming out with a revolutionary design in cookware too…..so I'll take great care of you if you need anything, I truly will…… least I can do for all the help and kindness you guys have shown me. LOVE YOU GUYS!!!! YOU ARE THE BEST…ok, I have shipments to get out….. talk to you tonite after i get home.
ok, here are my logs…and i turned everything back on….but i don't know what to do about the spybot …it came on during the combo fix reboot, it said a registry entry was changed…this happens occasionally and I never know whether to say yes or no….. It said a helper object key was deleted and wants to know if I want to allow this change….do I say yes or no?????

ComboFix 09-02-02.04 - User 2009-02-02 19:36:48.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.894.544 [GMT -5:00]
Running from: c:\documents and settings\[removed]\desktop\combofix.exe
Command switches used :: /killall
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated)
* Created a new restore point
.

((((((((((((((((((((((((( Files Created from 2009-01-03 to 2009-02-03 )))))))))))))))))))))))))))))))
.

2009-01-29 19:30 . 2009-01-29 20:16 d——– c:\documents and settings\User\Application Data\mjusbsp
2009-01-29 19:29 . 2008-04-13 14:45 60,032 –a—— c:\windows\system32\drivers\USBAUDIO.sys
2009-01-29 19:29 . 2008-04-13 14:45 60,032 –a–c— c:\windows\system32\dllcache\usbaudio.sys
2009-01-29 19:28 . 2008-04-13 14:45 32,128 –a—— c:\windows\system32\drivers\usbccgp.sys
2009-01-29 19:28 . 2008-04-13 14:45 32,128 –a–c— c:\windows\system32\dllcache\usbccgp.sys
2009-01-28 02:00 . 2009-01-28 02:00 d——– c:\documents and settings\User\LocalLow
2009-01-28 02:00 . 2009-01-28 02:00 d——– c:\documents and settings\All Users\Application Data\TVU Networks
2009-01-15 02:15 . 2009-01-15 02:15 d——– C:\61df232c486c6796dd2d
2009-01-15 01:29 . 2009-01-15 01:29 0 –a—— c:\windows\nsreg.dat
2009-01-07 05:20 . 2009-01-07 05:20 d——– c:\program files\Microsoft Games
2009-01-07 05:16 . 2009-01-07 05:16 d——– c:\program files\Alawar
2009-01-06 00:44 . 2009-01-06 00:45 d——– c:\documents and settings\User\Application Data\ErrorFix

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.

and hijack this:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:51, on 2009-02-02
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\system32\S3trayp.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Program Files\Verizon\McciTrayApp.exe
C:\Program Files\Verizon\VSP\VerizonServicepoint.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\DV Series\Console\Watch.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\trend micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://my.netzero.net/s/search?r=minisearch
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [S3Trayp] S3trayp.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [Verizon_McciTrayApp] C:\Program Files\Verizon\McciTrayApp.exe
O4 - HKLM\..\Run: [VerizonServicepoint.exe] "C:\Program Files\Verizon\VSP\VerizonServicepoint.exe" /AUTORUN
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe -expressboot
O4 - HKCU\..\Run: [MSMSGS] C:\Program Files\Messenger\msmsgs.exe /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: Watch.lnk = C:\Program Files\DV Series\Console\Watch.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - https://activatemydsl.verizon.net/sdcCommon…20Installer.cab
O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} (CTVUAxCtrl Object) - http://dl.tvunetworks.com/TVUAx.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

–
End of file - 6757 bytes


There you go……and no trojans have been popping up every two minutes, that's a good sign if you ask me!!!!!!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI