Computer Support Forum

.lnk files keeps coming back whatever I do. Please help me!

Question: .lnk files keeps coming back whatever I do. Please help me!

Please help me to totally remove these .lnk viruses and others from the all folders and hard drives. It keeps coming back whatever I do. I did the following:
1. Deleted those .lnk
2. Installed Avast and Malwarebytes and did a scan then deleted all those quarantined viruses.
3. Reformatted my computer.
 
After all what I've done, it still goes back to almost all folders and my hard drives.
 
Here are a few screenshots to help describe what I'm saying: (There are still lots of .lnk viruses from other file locations based on the deleted by Avast and Malwarebytes quarantine before I reformatted my computer)
 

Spoiler

Spoiler

Spoiler

Spoiler

Spoiler

Spoiler

Spoiler

Spoiler

Spoiler

Spoiler

Spoiler


 
Here are the screenshots of the other viruses from the hard drives:
 

Spoiler

Spoiler

Spoiler

Relevance 100%
Preferred Solution: .lnk files keeps coming back whatever I do. Please help me!

I recommend downloading and running Reimage. It's a computer repair tool that has been proven to identify and fix many Windows problems with a high level of success.

I've used it in the past to identify and fix everything from blue screens (BSOD's), ActiveX errors, corrupt files and processes, dll/exe/sys errors, recover lost memory, Windows update problems, defragging, malware removal etc.

You can download it direct from this link http://downloadreimage.com/download.php. (This link will automatically start a download of Reimage that you can save to your computer.)

Answer: .lnk files keeps coming back whatever I do. Please help me!

Hello and welcome to Bleeping Computer! I am HelpBot: an automated program designed to help the Bleeping Computer Staff better assist you! This message contains very important information, so please read through all of it before doing anything.
We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.
To help Bleeping Computer better assist you please perform the following steps:
*************************************************** In order to continue receiving help at BleepingComputer.com, YOU MUST tell me if you still need help or if your issue has already been resolved on your own or through another resource! To tell me this, please click on the following link and follow the instructions there.CLICK THIS LINK >>> http://www.bleepingcomputer.com/logreply/578571 <<< CLICK THIS LINK
If you no longer need help, then all you needed to do was the previous instructions of telling me so. You can skip the rest of this post. If you do need help please continue with Step 2 below.
***************************************************If you still need help, I would like you to post a Reply to this topic (click the "Add Reply" button in the lower right hand of this page). In that reply, please include the following information:If you have not done so already, include a clear description of the problems you're having, along with any steps you may have performed so far.A new FRST log. For your convenience, you will find the instructions for generating these logs repeated at the bottom of this post.Please do this even if you have previously posted logs for us.If you were unable to produce the logs originally please try once more.If you are unable to create a log please provide detailed information about your installed Windows Operating System including the Version, Edition and if it is a 32bit or a 64bit system.If you are unsure about any of these characteristics just post what you can and we will guide you.Please tell us if you have your original Windows CD/DVD available. Upon completing the above steps and posting a reply, another staff member will review your topic and do their best to resolve your issues.
Thank you for your patience, and again sorry for the delay.
***************************************************
We need to see some information about what is happening in your machine. Please perform the following scan again: Download FRST by Farbar from the following link if you no longer have it available and save it to your destop.FRST Download LinkWhen you go to the above page, there will be 32-bit and 64-bit downloads available. Please click on the appropriate one for your version of Windows. If you are unsure as to whether your Windows is 32-bit or 64-bit, please see this tutorial.Double click on the FRST icon and allow it to run. Agree to the usage agreement and FRST will open. Do not make any changes and click on the Scan button. Notepad will open with the results. Post the new logs as explained in the prep guide. Close the program window, and delete the program from your desktop.As I am just a silly little program running on the BleepingComputer.com servers, please do not send me private messages as I do not know how to read and reply to them! Thanks!

2 more replies
Relevance 65.19%

Hello I was wondering if someone could help me on this issue. I have no clue if I am infected with a virus or something because I have never seen this file before and there are a lot of them all named the same thing. well what am I saying I know im infected because along with these files it made two folders one folder that records my key strokes and the other I have no clue what its for. its empty. I have tried the simple delete or using a virus scanner/remover to get rid of it. no cigar. along with the files in my task manager "javaw.exe" apears and a lot of them the same amount as the files that are in the folder. hope this makes any sense if someone could please get back to me on this. the file names are "jspyb"(random letters and number) its also a java file. the other two folder are called "js_logs(records my key strokes)" and " js_plugins(empty)" someone please help me thanks in advance!

Moderator note: Moving to V & M Removal forum.
 

Answer:Files Keep Coming Back

Welcome aboard

Please, complete all steps listed here: http://www.techspot.com/vb/topic58138.html
Make sure, you PASTE all logs. If some log exceeds 50,000 characters post limit, split it between couple of replies.
Attached logs won't be reviewed.

Please, observe following rules:

Read all of my instructions very carefully. Your mistakes during cleaning process may have very serious consequences, like unbootable computer.
If you're stuck, or you're not sure about certain step, always ask before doing anything else.
Please refrain from running any tools, fixes or applying any changes to your computer other than those I suggest.
Never run more than one scan at a time.
Keep updating me regarding your computer behavior, good, or bad.
The cleaning process, once started, has to be completed. Even if your computer appears to act better, it may still be infected. Once the computer is totally clean, I'll certainly let you know.
If you leave the topic without explanation in the middle of a cleaning process, you may not be eligible to receive any more help in malware removal forum.
I close my topics if you have not replied in 5 days. If you need more time, simply let me know. If I closed your topic and you need it to be reopened, simply PM me.

 

1 more replies
Relevance 64.37%

This has been happening on my mother's computer.  She claims to have deleted files and then they're back the next day.  Then I noticed files that I deleted were also coming back.  This has happened for sure with .bmp files and shortcuts.  These are files that are created by me and deleted regularly.  Haven't noticed any other types returning.  I did a google search, but all I got was results for how to recover deleted files.  Are we the only ones having this problem?

Answer:Deleted files coming back

Hi RRguy,
 
I'm just curious if after you have deleted the file/s, then emptied the trash, do a F5 refresh while on the desktop, if the files reappear?
 
Give it a try, and let me know.
 
Take care,
 
Kurt

15 more replies
Relevance 64.37%

My Windows XP machine picked up this *nasty* Malware a couple of weeks ago and I've been struggling to get rid of it. I've tried to use McAfee to clean it off, but have had no success. It's manifesting itself in various ways, but the one constant it the appearance of files starting with OVFSTHX*.DLL and .SYS. These files are ID'ed by McAfee, but are never really removed. Other files are PROTECT.DLL, CHKDISK.DLL, AUTOCHK.DLL, LMN_SETUP.EXE. Copies into Start-up as hidden/system files. Used to turn off REGEDIT, change system parameters. McAfee may have gotten rid of some of it, but the OVFSTHX*.* files keep coming back. Also, about every 7 minutes, it re-adds the following to the Registry Run section, either Local Machine or Current user:

rundll32.exe C:\WINDOWS\system32\autochk.dll,[email protected]
DDS (Ver_09-03-16.01) - NTFSx86
Run by Ward at 16:33:51.15 on Sat 05/09/2009
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1455 [GMT -7:00]

AV: McAfee VirusScan *On-access scanning enabled* (Updated)
FW: McAfee Personal Firewall *enabled*

============== Running Processes ===============

C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:&#... Read more

Answer:OVFSTHX*.* Files Keep Coming Back

Update ...

Somewhere between automatic Microsoft and McAfee downloads, a McAfee Anti-Virus call ($89), and my own tinkering, my computer seems to be Mal-ware-free. It involved a Service that was flagged as a hidden, system Service and a bunch of hidden files in SYSTEM32 and SYSTEM32/Drivers and hidden records in the Registry, all beginning with OVFSTX. Once the Service was killed and the files were deleted, everything seems to be back to normal.

I don't entirely trust McAfee's work and software, so, if someone is still interested in assisting me, I would appreciate the help. Otherwise, here's hoping I stay Mal-ware-free. Thanks for listening.

Ward

4 more replies
Relevance 64.37%

My computer runs Windows 7 Home Premium.

I have been going through my Library directories, (in particular my Document directory), doing some housekeeping. You know the procedure, deleting old files which are no longer relevant and deleting stuff that I no longer want and stuff that somehow I have repeatedly located in different directories, getting everything rationalised and organised.

The sort of files that I am deleting are Word and Excel files, .pdf Adobe files, downloaded program files that I scan prior to installing, zip files and folders and folders containing files - nothing out of the ordinary really!

A couple of days later I notice those damned files that I know I deleted, (and I made sure that the Recycle Bin was cleared out too), have all somehow been reinstated to exactly where I deleted them from.

I repeat the exercise and it happens again!

I don't understand why - it's like the candle you can't blow out!

I'm not sure if the same thing has happened with any other areas of the Library.

I do perform a backup to an external hard drive once a week. The drive is a Seagate and I am using the Seagate backup software, but this shouldn't be causing this - should it? I'm only backing up, I'm not asking for it to restore anything.

Can anyone tell me what is going on and how I can fix it?

Answer:Files that I have deleted keep coming back on their own!

  
Quote: Originally Posted by Barneyboy48


My computer runs Windows 7 Home Premium.

I have been going through my Library directories, (in particular my Document directory), doing some housekeeping. You know the procedure, deleting old files which are no longer relevant and deleting stuff that I no longer want and stuff that somehow I have repeatedly located in different directories, getting everything rationalised and organised.

The sort of files that I am deleting are Word and Excel files, .pdf Adobe files, downloaded program files that I scan prior to installing, zip files and folders and folders containing files - nothing out of the ordinary really!

A couple of days later I notice those damned files that I know I deleted, (and I made sure that the Recycle Bin was cleared out too), have all somehow been reinstated to exactly where I deleted them from.

I repeat the exercise and it happens again!

I don't understand why - it's like the candle you can't blow out!

I'm not sure if the same thing has happened with any other areas of the Library.

I do perform a backup to an external hard drive once a week. The drive is a Seagate and I am using the Seagate backup software, but this shouldn't be causing this - should it? I'm only backing up, I'm not asking for it to restore anything.

Can anyone tell me what is going on and how I can fix it?


Try deleteing your files and check to see if they are in the recycle bin. Reboot your s... Read more

9 more replies
Relevance 64.37%

Whenever I delete a file in "my documents", it copies itself. "my documents" keeps growing and growing the more I delete.

Answer:deleted files keep coming back

Could be a virus or hacker.

7 more replies
Relevance 64.37%

The files keep coming back even though I sent to the recycle bin and empty them again and again.
But the files just keep coming back when I restart or shut down.Please help if you know any answer.

Answer:Files cannot be deleted and keep coming back

SlientThinker,

What kind of files keep coming back? I ask because Windows has a feature to prevent the deletion of necessary operating system files.

Another possibility is that the files that keep coming back are being generated automatically by an application or operating system component.

If you provide a bit more detail about the types and location(s) of files in question - I might be able to provide more detail.

- John

5 more replies
Relevance 64.37%

Here is a list of my hijack log...

Logfile of HijackThis v1.97.7
Scan saved at 1:11:58 PM, on 7/11/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\System32\ScsiAccess.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32\ezSP_Px.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\D-Link AirPlus\AirPlus.exe
C:\Program Files\Outlook Express\msimn.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
C:\WINDOWS\System32\odjiwjf.exe
C:\Program Files\Common Files\Sony Shared\AVLib\Sptisrv.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Symantec\LiveUpdate\LUAll.exe
C:\PROGRA~1\... Read more

Answer:Can not delete files, keep coming back

Have you tried doing this in Safe Mode?

Preliminaries: Have these instructions printed or in a convenient Notepad (or Wordpad) file so you can view them in Safe Mode. Have "show hidden (or all) files" checked in Folder Options > View in case you have to search for any hidden files to delete. Also ensure you do NOT have "hide file extensions..." enabled in Folder Options > View

Then:

1 >> Restart in Safe Mode: http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001052409420406

2 >> In Safe Mode run HijackThis and check and "fix" the following entries:

O4 - HKLM\..\Run: [Microsoft Sinsup] odjiwjf.exe
O4 - HKLM\..\RunServices: [Microsoft Sinsup] odjiwjf.exe
O4 - HKCU\..\Run: [Microsoft Sinsup] odjiwjf.exe

3 >> Go to Start > Run, enter cmd and a command shell will open; at the command prompt type and enter:

del C:\WINDOWS\System32\odjiwjf.exe

If you get an access denied message, rename it instead:

ren C:\WINDOWS\System32\odjiwjf.exe odjiwjf.bad

4 >> reboot and see if the entries and the file stay deleted or reappear immediately, or after you have been online for some time.
 

3 more replies
Relevance 63.55%

Hi, recently I was infected by a whole bunch of trojan and rootkit viruses, including the insidious rogue ?antivirus? program Security Tool. I was able to remove them and restore my computer?s functionality. Since then, I?ve run Malwarebytes several times over the past few weeks, but each time the scan log says I have three files associated with Rogue.Antivirus2010 and one file associated with Malware.Trace. Each time I run the software, I get a message saying that these files were ?quarantined and deleted successfully,? but after I restart my computer and rerun the software, the four files reappear. Although my computer appears to running well at the moment, I am worried these are latent infections. Below is the log from my latest scan:alwarebytes' Anti-Malware 1.46www.malwarebytes.orgDatabase version: 4746Windows 5.1.2600 Service Pack 3Internet Explorer 8.0.6001.187022010-10-12 오후 4:53:32mbam-log-2010-10-12 (16-53-32).txtScan type: Quick scanObjects scanned: 150087Time elapsed: 9 minute(s), 19 second(s)Memory Processes Infected: 0Memory Modules Infected: 0Registry Keys Infected: 0Registry Values Infected: 0Registry Data Items Infected: 2Folders Infected: 0Files Infected: 1Memory Processes Infected:(No malicious items detected)Memory Modules Infected:(No malicious items detected)Registry Keys Infected:(No malicious items detected)Registry Values Infected:(No malicious items detected)Registry Data Items Infected:HKEY_LOCAL_MACHINE\SOFTWARE\Microsof... Read more

Answer:Malwarebytes removes files, but they keep coming back

It seems I have resolved the issue on my own. Please consider this thread closed, and thanks again!

2 more replies
Relevance 63.55%

Im at my wits end with what to do about this.

I have a brand new pc that is turning up with corrupted files when i run the scannow.. ive dism restored it multiple times and re-scanned and it keeps coming back with errors.

pc specs:

AMD A6-7310 APU 2.00 GHZ, 64 bit processor
AMD Radeon R4 graphics
4 GB RAM
500 GB HDD
Windows 10 home, 64 bit OS
i performed the dism repairs multiple ways. first i did the standard dism online restore.. it says that its completed successfully. then i reboot and run scannow and it comes back corrupted.

then i downloaded a copy of windows 10, mounted it to my desktop, entered the commands to repair. it said it was successful. then i rebooted and scannow and its still corrupted.

this is the website i followed to fix the corruption:

https://www.easytechguides.com/sfc-unable-to-fix-corrup...

im going to post links to the dism and cbs logs, as well as my dxdiag and msinfo

dxdiag:

http://s000.tinyupload.com/index.php?file_id=7845547486...

msinfo:

http://s000.tinyupload.com/index.php?file_id=0243830597...

cbs log:

http://s000.tinyupload.com/index.php?file_id=9628735986...

dism log:

http://s000.tinyupload.com/index.php?file_id=2785341797...

i dont know what else to do. any help would be greatly appreciated. thank you

Answer:Need help with sfc scannow. keeps coming back with corrupted files

Hi darx888. Welcome to the Tenforums @darx888

I boiled down your CBS log. It appears to be having problems with some wav files. It also says your store is also corrupted.

sfcdetails.txt

You said this machine is brand new. What version of Windows 10 (V1607 or V1703) are you running?

Here is our tutorial on DISM. Note the info in the tip.

Use DISM to Repair Windows 10 Image

If you are on 1703 it may be easier to do an inplace repair / upgrade following this tutorial.

Repair Install Windows 10 with an In-place Upgrade

Before doing these type of things I recommend you have a system image created with a tool like Macrium Reflect. Always want a fall back.

Ken

more replies
Relevance 63.55%

I run xp on my computer and have Norton 360 and Malware Antibytes. However after temp files are deleted they keep reappearing. What can I do??? Thnaks for your help in advance.:cry
 

Answer:Help Temp Files will not delete keep coming back!!!

Well that is quite vague, are they temp files that are being flagged by your anti virus? Temp files and folders will be created on your computer all the time. Most of them are harmless, if quite a few have accumulated, then we sometimes advise to run software such as Ccleaner (but not the registry side of it, just the cleaner itself)
 

5 more replies
Relevance 63.55%

I delete a file or multiple files, usually it happens with files of the media type; pictures, videos, music, etc. I will delete the file, and empty the recycle bin just to see the file returns to its original directory a week to a few months later. I've only seen this behavior on Windows 7 machines, all of them I've previously owned has experienced this problem, my computer now isn't any different. I deleted a Xerneas pictures back in May because I already posted it to Twitter, just today, that same image is back into my 'Twitter Upload' folder in the 'My Documents' of my user folder. I have emptied the recycle bin a few different times since, but the file has returned today. I did some searching around and saw that this question has been asked on various forums but no valid answer.

Answer:Deleted files reappearing (coming back)

Not sure what the problem is here. It may help if you state what steps you have already taken to attempt to resolve the issue.

Recyle Bin (All Drives)

Open an elevated Elevated Command Prompt: Elevated Command Prompt Tutorial

Type:

RD /S /Q C:\$Recycle.bin

Assuming that drive C: is your windows partition. If it uses a different drive letter replace C: in the line above with the correct letter.

Press Enter

Repeat the above for all other drives.

Then right click desktop and choose "Refresh"

You might need to reboot and fresh recycle bins will be created.

Other than that try setting all recycle bins to delete files immediately.

Right click the recycle bin icon and choose "Properties". For each drive set it like this:

Question. What's a Xerneas picture?

Also what created this "Twitter Upload Folder" ?

Is that a folder you created yourself or was it created by an application and used as the default save location for images when you use that application? Is anything set to sync with that folder?

Thanks.

2 more replies
Relevance 63.55%

Hi, o;m new to this sort of site and i really really need a hand
I have a file in my flash drive and it's a normal one , i keep deleting it and it keep coming back i tried shift+del. but nothing not a min. and the file is there a gain...........

Note: when i deleted the file i noticed that the file isn't on the recycle bin so please please help T_T
 

Answer:files keep coming back on my USB flash drive

10 more replies
Relevance 63.55%

Hey guys looking for some help with my Windows 10 Acer. I have these files that i keep deleting and they keep coming back. Any idea what could cause this ? Thanks.

Answer:Log Files keep coming back after deleted (Pics)

I have all these files, and then some, in the same directory on my production machine. I think these are automatically generated by IE. Yes, they are: and here's an MS blog post that addresses the size issue and provides a batch file to get rid of the database stored in WebCacheV01.dat. I guess you should be glad you're not handling 1,000 users via Terminal Server! ;-)
HTH,
--Ed--

2 more replies
Relevance 63.14%

I work at a local computer shop and am familar with removing viruses but this one keeps coming back. Every time I believe I have it gone it comes back. I have run malwarebytes, nod32, Comboxfix, Hijackthis. None of these programs seems the find the root of the problem they all point to were I might continue looking but do not resolve the problem. The problem is on the root there a randomly named batch and exe files that I can shift delete. I restart the computer and it runs fine for about ten mins. I have the task manager open and then the randomly named exe's start to show up. Then I go look in the root and there they are again. Combo fix pointed to this in the reg
[HKEY_CURRENT_USER\software\microsoft\windows\Currentversion\policies\explorer\Run]
"Msn"="c:\OxOr.exe" [2009-04-14 245248]
"MsnHost"="c:\OxOr.exe" [2009-04-14 245248]
"MsnLoad"="c:\OxOr.exe" [2009-04-14 245248]
So I checked it out deleted them and restarted again. Once again about ten mins into the computer running everthing is back again only with different names. Even in the reg entry. There are two batch files the contents of one appears to shut off the firewall and then try to run one of the randomly named exes. The other points to what appears to be a randomly generated website a long string of numbers and letters .cn every 15 mins. Sorry if I jumped ahead by running all the above but I usually can... Read more

Answer:random named batch files and .exe's that keep coming back

Hi neelhow,Welcome to BC HijackThis forum and sorry for the delay. I am farbar. I am going to assist you with your problem.Please refrain from making any changes to your system (updating Windows, installing applications, removing files, etc.) from now on as it might prolong handling your log and make the job for both of us more difficult.Go to start > Run copy/paste the following lines one by one in the run box and click OK after each line.

cmd /c dir /o:d /a "C:\" > "%userprofile%\desktop\log1.txt"
cmd /c dir /a /s C:\WINDOWS\tasks >> "%userprofile%\desktop\log1.txt"

A log1.txt file will be created on your desktop. Please post the content to your reply.

Please run Hijackthis. Click Do a system scan and save a logfile then copy and paste the content of the log to your reply.

8 more replies
Relevance 63.14%

I have a USB flash drive with a SanDisk MicroSD card in it, and whenever I delete everything on it the files just keep coming back whenever I plug it back into my computer. This never happened before so I'm not sure what to do. I tried right clicking on the removable drive and formatting, but I always get a message that says "Windows could not format this drive." Same thing happens when I go under disc management and try to format it from there. Also, when I right click on the drive the option to delete partition is grayed out.

Anyway, if anyone can help out in anyway I would be really grateful. This has really been driving me crazy.

Answer:Files I delete on my USB flash drive keep coming back

make sure you have admin permissions and that it's not set as read-only....if that still doesnt work try deleting the partition table in disk management (right click my computer then Manage) and recreate then format

8 more replies
Relevance 62.32%

Greetings All,

I'm not very keen on how this all works. I know I have TrojanDownloader.xs infecting my computer with a lot of crap from CoolWebSearch. I've located the files and am trying to go about deleting but nothing sticks. I have no access to Task Manager as that has been disabled. The dll's I'm trying to unregister in the Command Prompt section all come back as non executed files so can't delete. And when I try to get rid of keys in Registry Editor, I can right click and delete but it always comes back. PLEASE HELP! Anyone.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:13:58, on 6/14/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\system32\iftuyszv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\portsv.exe ... Read more

Answer:Help! I can't delete corrupt files from Registry Editor. It keeps coming back! HELP

Hello and Welcome.

Please subscribe to this thread to get immediate notification of replies as soon as they are posted. To do this click Thread Tools, then click Subscribe to this Thread. Make sure it is set to Instant Notification, then click Subscribe.

We want all our members to perform the steps outlined in the link I'll give you below, before posting for assistance. There's a sticky at the top of this forum, and a
Quote:




Having problems with spyware and pop-ups? First Steps




link at the top of each page.
---------------------------------------------------------------------------------------------

Please follow our 5 Step process outlined here:

http://www.techsupportforum.com/secu...oval-help.html

After running through all the steps, you shall have a proper set of logs. Please post them.

If you have trouble with one of the steps, simply move on to the next one, and make note of it in your reply.

1 more replies
Relevance 62.32%

After I delete files from my Windows 10 PC, the get deleted and go to Recycle Bin. I empty the Recycle Bin and the files get deleted there too and the Recycle Bin is empty.
Now after I restart my computer, the deleted files reappear in Recycle Bin,
Weird!

Answer:Deleted files keep coming back or reappearing in Windows Recycle Bin

Maybe your Recycle Bin is corrupted. Reset your Recycle Bin and see if that helps.

3 more replies
Relevance 62.32%

Hi!
So, last Friday my OfficeScan software found a couple infected files that it couldn't clean off. So I ran Ad-Aware and Spy-Bot and RegistryCC and cleaned things up as best I could. But the pop-ups didn't stop. In fact it got worse. I turned the TeaTimer off on Spybot because it kept popping up telling me about registry changes and the virus started looping and creating new files when I denied the changes.

I've been reading replies to other people's messages that have similiar problems and tried to do what I could. I updated all my anti-virus software, I updated my Java (which was probably the weakness that let it in in the first place). I've been running Malwarebytes frequently. Sometimes it finds something, sometimes it doesn't. I've run VundoFix and it cleared a couple files off too. One I wrote down because it took a couple tries to get rid of : system32/uljeuf.dll Malware identified a few files as TrojanVundo.

It keeps coming back and I'm not sure what to do next. I used the add/remove to get rid of IE because I never use it anyway and I naively thought that might stop the pop-ups. But now they just come in streams of empty IE pages and system errors that say "An attempt was made to reference a token that does not exist."

Also there's a program in my add/remove called Mirar. I googled it and it doesn't sound good. I can't get that off either.

I don't have the knowledge to go deeper into my sys... Read more

More replies
Relevance 55.35%

I've been having a a problem with the back left corner hinge since October of last year I poisted to another board about this problem hving been told that this issue would be passed onto support in my region. I'm currious as to weather I'll hear from these people in this lifetime or the next. I enjoy my Laptop and would like to continue using it but as time goes on it keeps seperating more and more and I have to snap it back into place to keep in together. I'm hoping to actually hear back from someone this time that will be able to help me in fixing this issue.

Answer:Back Corner coming from the back left side by the hinge

@jmb1313

 

I have brought your issue to the attention of an appropriate team within HP. They will likely request information from you in order to look up your case details or product serial number. Please look for a private message from an identified HP contact. Additionally, keep in mind not to publicly post personal information (serial numbers and case details).

If you are unfamiliar with how the Forum's private message capability works, you can learn about that here.

Thank you for visiting the HP Support Forum.

1 more replies
Relevance 53.71%

I already posted in How to remove Windows 10 upgrade updates in Windows 7 and 8
In this thread after the starting post from Tookeri other updates that had to be deleted were mentioned. I made a list in post 841
I did not have all these updates on the pc but those that were on it I hid.
Some of them came back and I hid them again.
Now today they are back - with some that I had not seen before.

I made an attachment that shows them and also shows that I hid them again

Will I have to check Windows Update for the rest of my live?????

More replies
Relevance 52.89%

Hello,
I have a problem ,which ive tried to fix serveral times but it keeps coming back.
This virus is located in Systems 32 folder, Pc Cilling 2005 identified it as TROJ_ROOTKIN.N . Ive gone
to safe mode, deleted it, returned to windows and the virus reapeared, wats more it clogs up Pc Cillin, so now under quarantine i have 100+ instances of this virus, and its increasing.
The virus is labelled hpr34k8

Im sure my Hijack Log is fairly clean... -------------------------------------

Logfile of HijackThis v1.99.1
Scan saved at 5:27:53 PM, on 14/08/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\RunDll32.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\Program Files\Trend Micro\Internet Security 2005\pccguide.exe
C:\Program Files\Telstra\Cable Login\bpcable.exe
C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe
C:\Program Files\D-Tools\daemon.exe
C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe
C:\Program Files\Telstra\Toolbar\bpumTray.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\Program Files\Winamp\winampa.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin... Read more

Answer:Virus that keeps coming back and back and back, so on

bump, hopefully someone takes notice

19 more replies
Relevance 49.2%

Hey everyone this is the first time I have posted anything but i am having some serious problems. I let my brother borrow my laptop and when i got it back it was infected bad.
I have pc-cillin, Malwarebytes, and SuperAnti-Spyware.
SuperAnti-Spyware seems to clean everything after i scan and reboot but there are two things that keep coming back on the next re-boot.
1. Pc-cillin keeps giving me a waring telling me to close the browser when its not open with the web address of 110/rjsa/select.php?a=6707a0a cd82d9318fa98c6ee396eed8e61fcf4200553e0c95d8b1d81bbda3c1b&b=1001&c=1
2. There is a sys32 file that gets deleted and always comes back on reboot its MoIXWA40.dll
Pc-Cillin tells me this is a trojan.bho and says its will delete on reboot.
please help me this is so frustrating it slows everything down sooo slow.
 

Answer:Pop-Ups keep coming back

Hi, Welcome to TSG!!
Click here to download HJTInstall.exe

Save HJTInstall.exe to your desktop.
Doubleclick on the HJTInstall.exe icon on your desktop.
By default it will install to C:\Program Files\Trend Micro\HijackThis .
Click on Install.
It will create a HijackThis icon on the desktop.
Once installed, it will launch Hijackthis.
Click on the Do a system scan and save a logfile button. It will scan and the log should open in notepad.
Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log.
Come back here to this thread and Paste the log in your next reply.
DO NOT have Hijackthis fix anything yet. Most of what it finds will be harmless or even required.

 

1 more replies
Relevance 49.2%
Question: Keeps coming back

Ok guys not sure what I keep missing but the 020 line keeps coming back and changing it name.

I have ran CWS, ewido, Killbox ( and delete after reboot) VirtumundoBegone
Logfile of HijackThis v1.99.1
Scan saved at 11:25:30 AM, on 1/22/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Hijack This\TrojanHunter 4.2\THGuard.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijack This\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
O3 - Toolbar: AIM Search - {40D41A8B-D79B-43d7-99A7-9EE0F344C385} - C:\Program Files\AIM Toolbar\AIMBar.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [NvCplDae... Read more

Answer:Keeps coming back

10 more replies
Relevance 49.2%

Hello, after removing numerous malwares, str.sys keep coming back even though i removed it several times.Here's the log, thanks for your help.Logfile of Trend Micro HijackThis v2.0.2Scan saved at 8:22:19 PM, on 7/16/2009Platform: Windows Vista SP1 (WinNT 6.00.1905)MSIE: Internet Explorer v7.00 (7.00.6001.18000)Boot mode: NormalRunning processes:C:\Windows\system32\Dwm.exeC:\Windows\Explorer.EXEC:\Windows\system32\taskeng.exeC:\Program Files\Synaptics\SynTP\SynTPEnh.exeC:\Program Files\Toshiba\Utilities\KeNotify.exeC:\Program Files\Common Files\Symantec Shared\ccApp.exeC:\Program Files\Symantec AntiVirus\VPTray.exeC:\Windows\System32\hkcmd.exeC:\Windows\System32\igfxpers.exeC:\Program Files\QuickTime\QTTask.exeC:\Program Files\iTunes\iTunesHelper.exeC:\Program Files\Synaptics\SynTP\SynToshiba.exeC:\Windows\system32\igfxsrvc.exeC:\Windows\ehome\ehtray.exeC:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exeC:\Windows\ehome\ehmsas.exeC:\Program Files\Internet Explorer\iexplore.exeC:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exeC:\Program Files\Symantec AntiVirus\DoScan.exeC:\Program Files\Synaptics\SynTP\SynTPHelper.exeC:\Program... Read more

Answer:Str.sys keep coming back, help!

Hello and welcome to Bleeping ComputerWe apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.If you have since resolved the original problem you were having, we would appreciate you letting us know. If not please perform the following steps below so we can have a look at the current condition of your machine. If you have not done so, include a clear description of the problems you're having, along with any steps you may have performed so far.Upon completing the steps below another staff member will review and take the steps necessary with you to get your machine back in working order clean and free of malware.If you have already posted a DDS log, please do so again, as your situation may have changed.Use the 'Add Reply' and add the new log to this thread.Thanks and again sorry for the delay.We need to see some information about what is happening in your machine. Please perform the following scan:Download DDS by sUBs from one of the following links. Save it to your desktop.DDS.scrDDS.pifDouble click on the DDS icon, allow it to run.A small box will open, with an explaination about the tool. No input is needed, the scan is running.Notepad will open with the results.Foll... Read more

2 more replies
Relevance 49.2%

I have a problem with pop-up ads that keep on appearing randomly on my computer. I tried using adaware which picked up a lot of them, but they keep coming back later.

Hijack this log (Created with Hijack-this Analyzer)

====================================================================
Log was analyzed using KRC HijackThis Analyzer - Updated on 4/1/05
Get updates at http://www.greyknight17.com/download.htm#programs

***Security Programs Detected***

C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Fil... Read more

Answer:Pop-Ups that keep coming back

Hi and welcome to TSF.

I am currently reviewing your log. Please note that this is under the supervision of an expert analyst, and I will be back with a fix for your problem a.s.a.p

Please be patient with me during this time.

4 more replies
Relevance 49.2%

Hi everyone,

i had this fake FBI Virus on a laptop couple days ago, it would not let the windows to boot, not even in safe mode. i got it to clean with kaspersky boot disc, and also scanned it with avg, malwarebytes, avast. send it back to customer, same night he called me saying avast kept picking up something but was not able to remove it! so i picked it up again the next day, scanned with avg & malwarebytes seemed to be cleaned up again, nothing was picking up any viruses. but guess what? this morning i have a text from a custoemr, saying he was locked up out of screen and he was able to get into it, but now avg is picking up something again!!! i asked him if he uses usb drive or external or anything but he said he did not use any of those! PLEASE HELP WITH REMOVAL OF THIS!!!!

Answer:It keeps coming back!!!!

Hello sapikest,
my name is Marius and I will be assisting you with your Malware related problems.

Before we move on, please read the following points carefully.
First, read my instructions completely. If there is anything that you do not understand kindly ask before proceeding.
Perform everything in the correct order. Sometimes one step requires the previous one.
If you have any problems while you are follow my instructions, Stop there and tell me the exact nature of your problem.
Do not run any other scans without instruction or Add/ Remove Software unless I tell you to do so. This would change the output of our tools and could be confusing for me.
Post all Logfiles as a reply rather than as an attachment unless I specifically ask you. If you can not post all logfiles in one reply, feel free to use more posts.
If I don't hear from you within 3 days from this initial or any subsequent post, then this thread will be closed.
Stay with me. I will give you some advice about prevention after the cleanup process. Absence of symptoms does not always mean the computer is clean.
My first language is not english. So please do not use slang or idioms. It could be hard for me to read. Thanks for your understanding.

Before we start, please note:

Please be advised that this free service is typically for home users. We'll help you out this time, but in the future if you are unable to clean a machine via standard methods, then either backup the client's data and rein... Read more

2 more replies
Relevance 49.2%
Question: Keeps coming back!

I thought I wiped it off already but it's back AGAIN! And my SpyBot S&D is missing all sorts of components so it's not working right and it's the only one that has found any. The Microsoft one found one and deleted it but SpyBot found 16 but only deleted 2 before running into problems. EliteBar is back also. Help again!
 

Answer:Keeps coming back!

- Run ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus RemovalMake sure you check version numbers and get all updates.

- Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
After doing ALL of the above you still have a problem:

- Download HijackThis 1.99.1

- Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

- Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

- Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

- Run HijackThis and save your log file.

- Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
 

3 more replies
Relevance 49.2%

I can't get rid of this crap - I've ran everything on here that people say. I have SAV installed and up to date, I have SpywareGuard installed, I have ran HJT, I've ran Ewido software, nothing can get rid of this - Everytime I clean everything while in Safe mode and reboot, Spywareguard immediately starts popups saying a BHO has been added (suchs as C:\WINDOWS\system32\wvuvspq.dll) - I click remove BHO, and it comes back over and over...

Someone please help - this has totally destroyed my computer...
 

Answer:Someone please help - These BHO's keep coming back!!

Closing duplicate thread. Please continue to reply here: http://forums.techguy.org/malware-removal-hijackthis-logs/648572-please-help-my-hijackthis-log.html
 

1 more replies
Relevance 49.2%

okay, so yesterday i cleaned my pc with "malwarebytes anti-malware and there were like 11 viruses. then i scanned after t, none, so i get up this morning and scan my pc because everything is going SO SLOW! and now i got 10 viruses. can anyone please help? yesterday i had like 2 injections, 2 clickers, 2 malware.packs, and like 6 agents.
heres my log for yesterday: http://pastebin.com/panEZfVS
and heres todays: http://rhymingcolors.pastebin.com/G7gJ51nr
please help. 5 of those kinds ive never seen before :/ please comment below
 

Answer:they keep coming back >:(

8 more replies
Relevance 49.2%
Question: keeps coming back

I keep running scans and it cleans the computer sometimes. I will encounter xp antispyware 2009 and 2008 telling me that my computer is infected. It posts a permanent box on my desktop saying infected and keeps popping up at bottom right by time clock saying infected. I will run anti malwarebytes and it will clean it only if i do quick scan. But then i will run full scan and it freezes so i know it is still infected. And sure enough a few days later it is all back. Please help. I also run cc cleaner and norton but norton freezes too. I have also tried in safemode but still freezes. Thanks Any and all help is greatly appreciated.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:56:21 PM, on 10/8/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Intel\Inte... Read more

Answer:keeps coming back

bump
 

2 more replies
Relevance 49.2%

I am trying to clean out a co-worker's computer. I have restored to over a month ago and continue to find malware during scans. Any help appreciaded. Have not yet restarted to fully remove. Do I need to kill some files will killbox prior to the restart? Thanks, Jeff

Malwarebytes' Anti-Malware 1.45
www.malwarebytes.org

Database version: 3930

Windows 6.0.6001 Service Pack 1
Internet Explorer 7.0.6001.18000

3/31/2010 2:19:22 PM
mbam-log-2010-03-31 (14-19-22).txt

Scan type: Full scan (C:\|)
Objects scanned: 231065
Time elapsed: 1 hour(s), 11 minute(s), 19 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 1
Files Infected: 5

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\Windows\System32\config\systemprofile\AppData\Roaming\AntiVirus Plus (Rogue.AntiVirusPlus) -> Quarantined and deleted successfully.

Files Infected:
C:\$Recycle.Bin\S-1-5-21-2658977195-169558386-357108580-1000\$RR7NTAN.tmp (Trojan.Agent.Gen) -> Quarantined and deleted successfully.
C:\Windows\System32\config\systemprofile\AppData\Roaming\avp.ico (Rogue.AntiVirusPlus) -> Quarantined and deleted successfully.
C:\Wi... Read more

Answer:ave.exe keeps coming back

Windows restarted for updates while sleeping last night. Running malwarebytes again. Final rid of Hijackthis entries
O20 - AppInit_DLLs: C:\ProgramData\nuvanifi\nuvanifi.dll
2658977195-169558386-357108580-1000

Malwarebytes came out clean as well as a full McAfee virus scan. Hijackthis log appears clean too. With persistance I think I have this cleaned finally. I have both a dds scan and gmer report but don't really know what to look for. I can post these if someone has time to review them. I ran both prior to the windows update restart. Also updated and ran spywareblaster. Pop ups and redirects are gone too.

Partial log of items cleaned.
3/31/2010 2:19:22 PM
mbam-log-2010-03-31 (14-19-22).txt

Folders Infected:
C:\Windows\System32\config\systemprofile\AppData\Roaming\AntiVirus Plus (Rogue.AntiVirusPlus) -> Quarantined and deleted successfully.

Files Infected:
C:\$Recycle.Bin\S-1-5-21-2658977195-169558386-357108580-1000\$RR7NTAN.tmp (Trojan.Agent.Gen) -> Quarantined and deleted successfully.
C:\Windows\System32\config\systemprofile\AppData\Roaming\avp.ico (Rogue.AntiVirusPlus) -> Quarantined and deleted successfully.
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\AntiVirus Plus.lnk (Rogue.AntiVirusPlus) -> Quarantined and deleted successfully.
C:\Windows\System32\config\systemprofile\Local Settings\Application Data\ave.exe (Rogue.MultipleAV) -> Quarantined and deleted successfully.
C:\Windows\System32\co... Read more

1 more replies
Relevance 49.2%

Hello
For many years a succeeded in keeping my computers safe - then, not even a month ago, something surfaced. A Virut thing after I visited an insecure site.
If this can help, a few days before I had for the first time in my pc life installed a downloader program called Flashget-
Well I tried at first to clean up with Spybot and Spyware Doctor (who had not by the way intercepted the hostile item). But the machine had still a strange behaviour so I downloaded some Linux based Rescue CD .iso files (Kaspersky, BitDefender, WebDoctor), burned the CDs and went on scanning without Windows. Those found a wealth of infections by Trojans as well as by the Virut thing, so I kept cleaning and cleaning (desinfecting and/or deleting that is) until nothing more was found.
I then restarted Windows, uninstalled Flashget and installed Avast antivirus. Unfortunately when using my browser I started to get redirected to a "stolnik.net" whatever search I did. Plus Avast began to show infections spreading in the system by a "W32.Vitro" virus. So I tried again with the rescue CDs - Kaspersky found a couple issues but nothing else - and Avast still claiming I have the W32.Vitro everywhere.
At this point I used the VirutCF removal tool by Norton, but to no avail - there is no Virut infection in the machine.
I was beginning to get nervous so I downloaded the Combofix tool, disabled all and every anti-virus and -spyware - as requested - and tried to start Combofix: nothing happens... Read more

Answer:They keep coming back

If you truley have Virut the only real alternative is to do a complete wipe and reinstall. See boopme's post here:http://www.bleepingcomputer.com/forums/ind...t&p=1260380That will help you determine if you have virut, and if you do, what you need to do.

13 more replies
Relevance 49.2%

Everytime I run webroots spysweeper It finds a cws threat. I don't understand why it keeps popping up, even after I tell spysweeper to remove it. Someone want to help me....

Logfile of HijackThis v1.99.1
Scan saved at 7:44:30 PM, on 10/25/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\System32\nvsvc32.exe
D:\programfiles\Spy Sweeper\Spy Sweeper\WRSSSDK.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\Program Files\Eset\nod32kui.exe
D:\programfiles\Spy Sweeper\Spy Sweeper\SpySweeper.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
D:\programfiles\MicrosoftAntivirus\gcasServ.exe
C:\Program Files\QuickTime\qttask.exe
D:\programfiles\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
D:\programfiles\MicrosoftAntivirus\gcasDtServ.exe
C:\Program Files\LIUtilities\WinTasks\wintasks.exe
D:\programfiles\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.... Read more

Answer:CWS keeps coming back

8 more replies
Relevance 49.2%

I have a PC i believe is infected.
i have run Combofix, it appears to find something and reboot but i am unable to tell by the log what it found.
i think it is still infected because if i run CF again, it says it needs to reboot to continue.
 ComboFix.txt   29.88KB
  5 downloads
 ComboFix2.txt   30.15KB
  3 downloads
 ComboFix3.txt   26.11KB
  2 downloads
 ComboFix4.txt   29.75KB
  3 downloads

Answer:it keeps coming back

Hello cgtrott, I will be handling your log to help you get cleaned up. I apologize for the delay but the forum is very busy and as you can see the logs we ask for are very extensive and take a lot of time to investigate. Please subscribe to this topic. Click on the Watch Topic button, select Immediate Notification and click on proceed.Make sure Word Wrap in notepad is turned off. When copying and pasting logs paste them directly in the reply box only attach logs if asked to. Do not wrap logs in codebox or code tags. It makes it very difficult to read and analyze them. Please paste them directly into the reply box. Do not make any changes to your system until we are through. Fixes are based upon information that is current from your system so any changes can affect our strategy. Please refrain from running any tools we may use without specific instructions.If your operating system is Windows Vista or Windows 7 it may be necessary to right click then choose Run as Administrator any programs we use.Before we begin please check and follow the instructions on How to Show Hidden Files and Folders in Windows Vista and Windows XP and How to show hidden files in Windows 7Because the e-mail notification system is not completely reliable, please check your topic once a day for responses.Please read carefully all directions and instructions. If you are instructed to save a tool to the desktop please save it to the desktop. If you have since resolved the original problem you were ha... Read more

2 more replies
Relevance 49.2%

I uses Vundofix, ad-aware, spybot, xoft, avg, House call, Microtrend, Don't know what to do next? here is my infoLogfile of HijackThis v1.99.1Scan saved at 1:48:37 PM, on 3/22/2006Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\spoolsv.exeC:\Program Files\NavNT\defwatch.exeC:\Program Files\NavNT\rtvscan.exeC:\Program Files\Norton Utilities\NPROTECT.EXEC:\WINDOWS\Explorer.EXEC:\WINDOWS\System32\svchost.exeC:\Program Files\NavNT\vptray.exeC:\Program Files\BearShare\BearShare.exeC:\Program Files\ArcSoft\PhotoImpression 5\PI Monitor.exeC:\Program Files\Yahoo!\Messenger\ymsgr_tray.exeC:\WINDOWS\system32\wuauclt.exeC:\WINDOWS\system32\rundll32.exeC:\Program Files\Internet Explorer\iexplore.exeC:\Program Files\HijackThis\HijackThis.exeR1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.Begin2Search.com/search.htmlO4 - HKLM\..\Run: [vptray] C:\Program Files\NavNT\... Read more

Answer:Pop Up's Keep Coming Back

Hello Mhenry, Welcome to BleepingComputer!My name is Nick and I will be checking over your log.Let's get started.You will want to print or save these instructions.Please download Look2Me-Destroyer.exe to your desktop.Close all windows before continuing.Double-click Look2Me-Destroyer.exe to run it.Put a check next to Run this program as a task.You will receive a message saying Look2Me-Destroyer will close and re-open in approximately 1 minute. Click OKWhen Look2Me-Destroyer re-opens, click the Scan for L2M button, your desktop icons will disappear, this is normal.Once it's done scanning, click the Remove L2M button.You will receive a Done Scanning message, click OK.When completed, you will receive this message: Done removing infected files! Look2Me-Destroyer will now shutdown your computer, click OK.Your computer will then shutdown.Turn your computer back on.Please post the contents of Look2Me-Destroyer.txt (it can be found wherever you saved Look2Me-Destroyer.exe) and a new HiJackThis log.If Look2Me-Destroyer does not reopen automatically, reboot and try again.I highly suggest you get rid of BearShare. It is a P2P program which is usually the cause for malware.Read here for more information on clean and infected File Sharing Programs.Click Start> Control Panel > Add/Remove Programs and remove:BearSharePlease note any other programs that you dont recognize in that list in your next responseReboot your computer once more.Please go HERE to run Panda's ActiveScanOn... Read more

1 more replies
Relevance 49.2%
Question: Back coming off?

My Lumia 640 is quite new and the back plastic panel writing logo is coming off the Microsoft logo has come off and some letters are coming away?
Is this normal?

More replies
Relevance 49.2%

I have done everything to get rid of my recent popups including runings spybot, adaware, microsoft Antispyware, Norton and Pandascan both in regular mode and safe mode. THey keep on finding stuff, but after restarting, they still come back. I have also empties the TEMP folder and cookies and temporary Internet files. I have included a HIJACK this log, hopefully someone can help. thanks.

Logfile of HijackThis v1.99.1
Scan saved at 6:34:55 PM, on 6/17/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\PROGRA~1\NORTON~1\NORTON~3\GHOSTS~2.EXE
C:\PROGRA~1\NORTON~1\NORTON~2\SPEEDD~1\NOPDB.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\fxssvc.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\WINDOWS\GWHotKey.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe... Read more

Answer:HJT Log because they keep coming back

16 more replies
Relevance 49.2%

hi, i hope somebody can help me. I'm running windows 95 b with internet explorer 5.5 and I keep getting "Error loading C:\WINDOWS\TEMP\se.dll". when I run IE, avg detects trojan horse startpage 16.bd and my start page is now advertising called "about: blank" I've deleted se.dll but it just keeps coming back. I'd appreciate any suggestions. thanx!
 

Answer:se.dll keeps coming back!

it sounds like you got hijacked. this should have been posted on the spyware specific board. follow the instructions on this link below.

http://forums.majorgeeks.com/showthread.php?t=35407 <--
Sticky: READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal

g/l - sos
 

1 more replies
Relevance 49.2%

Oh God help me... these anti-spyware pop ups keeps popping up and i always run a check on ad-aware 6 and Spybot once i see it. But once i connect to the net and open a site, it all comes back again n i haf to scan it all over again.... help please this is real miserable...

Thank you.

Answer:It just keeps coming back...

try manually removing, on www.doxdesk.com there are listings for spyware/parasites.

you could also go to run > msconfig and deselect any programs starting up that you dont recoginse.

also try going to http://www.symantec.com/homecomputing/
at the bottom is a link to a free online virus check, you may have one that persistantly downloads spyware.

and finally ensure you have a firewall and if you have one make sure its up to date. www.download.com has a free copy of zonealarm, thats a good one

6 more replies
Relevance 49.2%

Greetings everyone I need some help.

First off... I have followed all the proceedures listed on the READ ME thread that is asked and I STILL AM HAVING ISSUES.

I have Ad-Aware SE and with the VX add.

I have HiJackThis v1.99 and have followed the steps on that thread as well.

Here is the problem:

I run Ad-Aware everytime I log on, and even in safe mode. It finds beween 8 and 60 items. Mostly Malware and DataMiners. Then once I fix those I rescan and it comes up clean. However, I am still getting pop-ups, I have EnhanceMySearch, and when I log off and log back in... and re-run Ad-Aware I still have 8-60 items that show up and the same problem persists.

Can anyone help and point me in the right direction? It is a major annoyance. THANKS TO EVERYONE IN ADVANCE!!
 

Answer:It all just keeps coming back

Make sure you have HijackThis 1.99 and follow the guidelines on where to install it and how to post a log as an attachment. This is all covered in the sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

Now post a HijackThis log as an attachment to your message (Do not post the log inline). All running programs should be closed, including your web browser, e-mail. Close before running Hijack This!

To repeat: Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT
 

11 more replies
Relevance 49.2%

I think I may have finally scrubbed enough to keep the dll (IeBHOs.dll) from re-appearing, but the E2G folder keeps recreating itself. Any suggestions?

It's a friends system and had Norton on it. I installed NOD32 and PC Tools Spyware Doctor. Then read a few threads and ran HJT a few times and made some deletions that "may" have helped. I know that I managed to get rid of the TrojanDownLoader-AC2 but this E2G is stubborn.

Also ran SpySweeper many times in safe mode and in non-safe mode. Disabled Spyware Doctor from auto load with windows as it seemed to be interefering with the Spy Sweeper scan.

Here's the latest HJT log:

Thanks in advance for any suggestions!

Charlie

Logfile of HijackThis v1.99.1
Scan saved at 6:51:15 PM, on 4/18/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EX... Read more

Answer:E2G keeps coming back

Thread closed, please do not post duplicates!
Continue here: http://forums.techguy.org/security/460316-e2g-keeps-coming-back.html
 

1 more replies
Relevance 49.2%

This is my second attempt at help. I failed my first time and after reading the preparation guide here I am. I tried fixing it myself and loading MBAM and it says I have an infected regestry value, (Trojan.Agent) When I run the MBAM it says my computer must reboot to fix. It does, but then I have the same infection. I am confused, frustrated, and not really sure now what I am doing. Thankfully there are those here that can help...I am humbled.

Here is my DDS.txt
DDS (Ver_09-03-16.01) - NTFSx86
Run by Owner at 16:10:46.34 on Tue 03/31/2009
Internet Explorer: 7.0.5730.13
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.511.186 [GMT -4:00]

AV: Avira AntiVir PersonalEdition *On-access scanning enabled* (Updated)

============== Running Processes ===============

C:\WINNT\system32\svchost -k DcomLaunch
svchost.exe
C:\WINNT\System32\svchost.exe -k netsvcs
C:\WINNT\system32\svchost.exe -k WudfServiceGroup
svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\WINNT\system32\ezSP_Px.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\WINNT ... Read more

Answer:Not sure what I have...but it keeps coming back

Welcome to the BleepingComputer Forums. Since it has been a few days since you scanned your computer with HijackThis, we will need a new HijackThis log. If you have not already downloaded Random's System Information Tool (RSIT), please download Random's System Information Tool (RSIT) by random/random which includes a HijackThis log and save it to your desktop. If you have RSIT already on your computer, please run it again. Double click on RSIT.exe to run RSIT. Click Continue at the disclaimer screen. Please post the contents of log.txt. Thank you for your patience.Please see Preparation Guide for use before posting about your potential Malware problem. If you have already posted this log at another forum or if you decide to seek help at another forum, please let us know. There is a shortage of helpers and taking the time of two volunteer helpers means that someone else may not be helped. Please post your HijackThis log as a reply to this thread and not as an attachment. I am always leery of opening attachments so I always request that HijackThis logs are to be posted as a reply to the thread. I do not think that you are attaching anything scary but others may do so. While we are working on your HijackThis log, please: Reply to this thread; do not start another! Do not make any changes on your computer during the cleaning process or download/add programs on your computer unless instructed to do so. Do not run any other tool until ... Read more

2 more replies
Relevance 49.2%

Hot bar I am told is a parasite.That is its a freeby thats seems frindly but in reality is sucking all your secrets.So last night I deleted all trace of it from the system by norton and by Regedit.Tonight it back......What sort of mallet this this need ?

Answer:hot bar keeps a coming back

Please post a HJT log click hereYou may need to post in in two halves because of the 800 word limit.Please double space it by adding a blank line after each line so that it is legible with the site's formatting.

4 more replies
Relevance 49.2%

2 nights ago i was surfing the next and i starting getting reports such as :

Windows has detected spyware infection!
It is recomended to use special antispyware tools to prevent data loss. Windows will now download and install the most up-to-date antispyware for you
Click here to protect your computer from spyware!

and

Warning! Potential Spyware Operation!
Your computer is making unauthorized copies of your system and
Internet files. Run full scan now to pervent any unathorised access
to your files! Click here to download spyware remover ...

i started getting a lot of popups trying to send me to a site calling cookingluck (f3.cookingluck.com, f5.cookingluck.com, f7.cookingluck.com,
f9.cookingluck.com) i close them before they can finish loading.

Now i didnt do the smartest thing and i downloaded one of the "anti-spyware" things they told me too. "system-defender". well thats about when everything went from bad to worse, shell.dll was giving me hell, wowfax.dll was messing up. The control panel icon also disapeared and anything i tried to do with the system it wouldnt let me..pretty much telling me i didnt have administrative privliges.

So i came on this site and saw the self help page and was looking it over and saw the the "SmitFraud and It's Variants Removal Instructions" section fit my problem to a T, so i followed the steps exactly as they are written. I also got rid of the system defender. When i rebooted into norma... Read more

Answer:It just keeps coming back.....

Hi and welcome to TSF.

My name is Iain and I will be helping you clean your system.

You may wish to Subscribe to this thread (Thread Tools > Subscribe to this thread) so that you are notified when you receive a reply.

Please read these instructions carefully and then print out or copy this page to Notepad in order to assist you when carrying out the fix. You should not have any open browsers or live internet connections when you are following the procedures below.

Note that the fix may take several posts. Please continue to respond to my instructions until I confirm that your logs are clean. Remember that although your symptoms may vanish, this does NOT mean that your system is clean.

If there is anything you don't understand, please ask BEFORE proceeding with the fixes.

Please ensure that you follow the instructions in the order I have them listed.
We'll begin with ComboFix. Please visit this webpage for download links, and instructions for running the tool: http://www.bleepingcomputer.com/comb...o-use-combofix
When the tool is finished, it will produce a report for you.
Please post C:\ComboFix.txt along with a new HijackThis log so we may continue cleaning the system.

NOTE: Combofix prevents autorun of all CDs, floppies and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you - please let me know.

12 more replies
Relevance 49.2%
Question: Keeps Coming Back

Can someone please help me with this problem? All my AV programs detect a virus running in my system, but whenver I have it removed, it keeps coming back How can I stop this???


HJT Log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:22:13 AM, on 8/25/2008
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Nexon\Mabinogi\npkcmsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\WINDOWS\system32\csrcs.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.... Read more

Answer:Keeps Coming Back

Hello and Welcome. Please subscribe to this thread to get immediate notification of replies as soon as they are posted. To do this click Thread Tools, then click Subscribe to this Thread. Make sure it is set to Instant Notification, then click Subscribe.

---------------------------------------------------------------------------------------------

If you still require assistance with this issue, please do this:
Download RSIT by random/random and save it to your desktop.
Double click RSIT.exe to start the tool and click Continue at the disclaimer.
When the scan completes it will open a log named log.txt maximized, and a log named info.txt minimized.
Copy (Ctrl+A then Ctrl+C) and paste (Ctrl+V) the contents of log.txt here.
Please attach info.txt to your post.
To attach a file to a new post, simplyClick the[Manage Attachments] button under Additional Options > Attach Files on the post composition page, and
copy and paste the following into the "Upload File from your Computer" box:C:\rsit\info.txt

Click Upload.

---------------------------------------------------------------------------------------------

2 more replies
Relevance 49.2%

I've run Ad-awareSE, Trend Micro's housecall, and McAfee. I've also run Ad-aware while in safemode yet I still keep getting these popups and McAfee keeps telling me that " The file C:\\WINDOWS\system32\winupdt.exe was infected by the Downloader-LG trojan and has been deleted to complete the cleaning process. Its' says it repeatedly then stops then a few hours later it'll come back. Here is my Hijack This log:
Logfile of HijackThis v1.99.1
Scan saved at 6:07:30 PM, on 3/15/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wkogyo.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\WINDOWS\Mixer.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:... Read more

Answer:They just keep coming back...

16 more replies
Relevance 49.2%

windows securty 7 keeps coming bak after doing all the steps
 

Answer:it keeps coming back

Please attach the logs from both SUPERantispyware and MalwareBytes. Also run the below and attach the log.

I want you to run TDSSKiller so refer to the below for how to do so.

TDSSkiller - How to run
 

11 more replies
Relevance 49.2%

Here is my dilemna:

I've run Kazaabegone, CWShredder, Spybot and Adware with new updates and reboots in between. I've run Hijack This and removed what I knew to be suspicious files in safe mode. But one:

O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net

keeps reappearing on the HJT log after rebooting. I know I'm missing something; just don't know what.

Here is the entire log:

Logfile of HijackThis v1.97.7
Scan saved at 8:04:28 PM, on 2/1/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\cisvc.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
C:\WINDOWS\wanmpsvc.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
c:\program files\mcafee.com\agent\mcagent.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\Program Files\EarthLink 5.0\Con... Read more

Answer:New.net keeps coming back

6 more replies
Relevance 49.2%

Can't seem to get rid of the trusted zones, option is disabled in internet tools. I've run spybot, adware and avast but they still show.

Logfile of HijackThis v1.99.0
Scan saved at 10:18:03 AM, on 2/4/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Lexmark X6100 Series\lxbfbmgr.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\Program Files\Lexmark X6100 Series\lxbfbmon.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\America Online 9.0\aoltray.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.... Read more

Answer:they keep coming back!

Please print out or copy this page to Notepad. Make sure to work through the fixes in the exact order it is mentioned below. If there's anything that you don't understand, ask your question(s) before proceeding with the fixes. You should not have any open browsers when you are following the procedures below.

Go to My Computer->Tools/View->Folder Options->View tab and make sure that 'Show hidden files and folders' (or 'Show all files') is enabled. Also make sure that Display the contents of System Folders' is checked. Windows XP's search feature is a little different. When you click on 'All files and folders' on the left pane, click on the 'More advanced options' at the bottom. Make sure that Search system folders, Search hidden files and folders, and Search subfolders are checked.

For the options that you checked/enabled earlier, you may uncheck them after your log is clean. If we ask you to fix a program that you use or want to keep, please post back saying that (we don't know every program that exists, so we may tell you to delete a program that we think is bad to keep).

Turn off system restore by right clicking on My Computer and go to Properties->System Restore and check the box for Turn off System Restore. Click Apply and then OK. Restart your computer. After we are finished with your log file and verified that it's clean, you may turn it back on and create a new restore point.

Right click on this link http://www.greyknight17.com/spy/De... Read more

3 more replies
Relevance 49.2%

I think I may have finally scrubbed enough to keep the dll (IeBHOs.dll) from re-appearing, but the E2G folder keeps recreating itself. Any suggestions?

It's a friends system and had Norton on it. I installed NOD32 and PC Tools Spyware Doctor. Then read a few threads and ran HJT a few times and made some deletions that "may" have helped. I know that I managed to get rid of the TrojanDownLoader-AC2 but this E2G is stubborn.

Also ran SpySweeper many times in safe mode and in non-safe mode. Disables Spyware Doctor from auto load with windows as it seemed to be interefering with the Spy Sweeper scan.

Here's the latest HJT log:

Thanks in advance for any suggestions!

Charlie

Logfile of HijackThis v1.99.1
Scan saved at 6:51:15 PM, on 4/18/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EX... Read more

Answer:E2G keeps coming back

16 more replies
Relevance 49.2%

I think I may have finally scrubbed enough to keep the dll (IeBHOs.dll) from re-appearing, but the E2G folder keeps recreating itself. Any suggestions?

It's a friends system and had Norton on it. I installed NOD32 and PC Tools Spyware Doctor. Then read a few threads and ran HJT a few times and made some deletions that "may" have helped. I know that I managed to get rid of the TrojanDownLoader-AC2 but this E2G is stubborn.

Also ran SpySweeper many times in safe mode and in non-safe mode. Disables Spyware Doctor from auto load with windows as it seemed to be interefering with the Spy Sweeper scan.

Here's the latest HJT log:

Thanks in advance for any suggestions!

Charlie

Logfile of HijackThis v1.99.1
Scan saved at 6:51:15 PM, on 4/18/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EX... Read more

Answer:E2G keeps coming back

Three threads are not needed for the same problem.
 

2 more replies
Relevance 49.2%

I am having trouble getting rid of this BHO object.Everytime I manage to remove the dll and the BHO registry entry it comes back under a different name.I have run Spybot, AdAware and Trend Micro AV.Any help would be appreciated.Logfile of HijackThis v1.99.1Scan saved at 3:17:14 PM, on 04/16/07Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\Ati2evxx.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\spoolsv.exeC:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXEC:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exeC:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exeC:\WINDOWS\system32\fxssvc.exeC:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exeC:\WINDOWS\TEMP\EWE594.EXEC:\WINDOWS\Explorer.EXEC:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exeC:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exeC:\Program Files\Messenger\msmsgs.exeC:\WINDOWS\system32\ctfmon.exeC:\Program Files ... Read more

Answer:Bho Keeps Coming Back

Hello EBurritt, I am SifuMike and I will be helping you. Disable your antivirus program and go here http://www.bitdefender.com/scan8/ie.html and run an online scan with BitDefender (you will need to use Internet Explorer for this scan). When the ActiveX Control has loaded, click on "Click here to scan". Please be patient, as this scan may take a few hours. It all depends on the number of files on your computer. When BitDefender completes the scan, select the "Detected Problems" tab. Click on "Click here to export scan". Save the file as an HTML to your Desktop. Then click on the saved file and allow it to open with your browser. Go to Edit - Select All then copy/paste that log back here. Post the BitDefender log.******************Download ATF (Atribune Temp File) Cleaner? by Atribune DO NOT run it yet. Download and install AVG Anti-Spyware 7.5 (formerly Ewido) This is a 30 day trial of the programAVG Anti-Spyware is designed to be used to both scan for and remove malicious files and also to run in real-time alongside, but not replace, your existing anti-virus program to give an added layer of protection.Both the Resident Shield and Automatic Updates will only be available for the thirty day trial period, after that AVG Anti-Spyware will revert to a stand-alone scanner which you can keep and manually update for free and use in a similar way to Ad-Aware SE Personal, Spybot S&D etc.1. After download, double click on the file to launch the... Read more

11 more replies
Relevance 48.79%

I've tried every spyware program already....

Every time I restart my computer, the programs Cashback, Navisearch, and Webupdate come back. How can I trace the file that reinstalls these programs?

TIA for any help
 

Answer:Spyware keeps coming back....

Can you post a hijackthis log?
 

11 more replies
Relevance 48.79%

I ran CCleaner, then superantispyware, then Malwarebytes and removed the Trojan, I then ran Hitmanpro and removed all it came up with. I then run MB again and the same 4 Trojans keep coming up. Here is the log of MB

Malwarebytes Anti-Malware (PRO) 1.65.1.1000
www.malwarebytes.org

Database version: v2012.11.06.12

Windows 7 x64 NTFS
Internet Explorer 8.0.7600.16385
edteach :: EDTEACH-PC [administrator]

Protection: Enabled

11/7/2012 8:41:33 AM
mbam-log-2012-11-07 (08-41-33).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 234675
Time elapsed: 7 minute(s), 24 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 4
HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters|DhcpNameServer (Trojan.DNSChanger) -> Bad: (213.109.67.72) Good: () -> Quarantined and repaired successfully.
HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters|DhcpNameServer (Trojan.DNSChanger) -> Bad: (213.109.77.23) Good: () -> Quarantined and repaired successfully.
HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{77D50DC3-0F48-4B2D-99E0-19CCE6892D99}|DhcpNameServer (Trojan.DNSChan... Read more

Answer:TrojanDNSCHARGER keeps coming back

Please follow these instructions:

READ & RUN ME FIRST. Malware Removal Guide
 

1 more replies
Relevance 48.79%

Vundo Keeps coming back

OS:Windows XP, SP3

Hi,
I was forwarded from "http://www.bleepingcomputer.com/forums/t/203107/after-windows-update-multiple-program-errors-pc-restarting-on-its-own/" to post here.... That thread kinda died... anyway...

Over the past month I've found multiple instances of Vundo, and things seem to be getting worse.
Every time I try to clean my system, Vundo keeps coming back - even if I dont do any browsing.
Most recently, i've been experiencing applications freezing (Firefox, McAfee, Warcraft3)
The system has also crashed mid-scan using McAfee several times, but not lately.
I'm unsure if these problems are related to the Virus or other system issues - I figure get rid of the virus first and troubleshoot the rest later.
My system is fairly new (Dec 08), it came with McAfee Enterprise installed. I also installed the free version of Spyware Doctor on my computer.
Neither of which seem to be able to remove the Virus, and at times can not even detect it.

I've started to notice that sometimes McAfee is disabled after restarting the computer; I hadn't changed any settings for that to occur.

I've tried using Malwarebytes Anti-Malware as well as SUPER Anti-Spyware, both of which are doing a better job of finding and clearing traces of the virus (compared to McAfee). Also tried VirtumundoBeGone and in haste, ComboFix.

VirtumundoBeGone found no traces, and Combofix didnt do anything noticable.

Please help!
Let me know if there are any logs or reports you ... Read more

Answer:Vundo Keeps coming back, not sure what to do

Well the best we can do is get an MBAM and perhaps a SUPER Anti-Spyware log to start with.Open MBAM in normal mode and click Update tab, select Check for Updates,when doneclick Scanner tab,select Quick scan and scan.After scan click Remove Selected, Post new scan log and Reboot into normal mode.

3 more replies
Relevance 48.79%

Greetings all.
 
I have been struggling with Malware for most of the past day and am in need of some advice.
Malwarebytes has been run and deletes a bunch of files in safe mode, including svchost.exe.
After restart, it continually find and quarantines svchost.exe.  In other words, svchost.exe is coming back endlessly, and MalwareBytes keeps removing it.  The removal message pops up from the systray every 5 seconds (not kidding). 
There is also an issue sometimes when I click a link, I'm sent to some other site.  I think I see "seachzone" in the url briefly before the reroute.  Guessing these are separate issues.
 
Have run AVG, Nortons and Spybot S&D (which always freezes before finishing), but nothing has fixed this issue.
 
Any thoughts would be appreciated.
 
Thanks.
 
HKP

Answer:svchost.exe keeps coming back

Please download TDSSKiller from here and save it to your Desktop
Doubleclick on TDSSKiller.exe to run the application, then click on Change parameters
Check Loaded Modules and Detect TDLFS file system. Do not check Verify file digital signatures (even though it is checked in the example)
If you are asked to reboot because an "Extended Monitoring Driver is required" please click Reboot now
Click Start Scan and allow the scan process to run
If threats are detected select Skip for all of them unless I instruct you otherwise
Click Continue
Click Reboot computer
Please post the contents of TDSSKiller.[Version]_[Date]_[Time]_log.txt found in your root directory (typically c:\)in your reply
Due to forum upgrade you may face issues posting the TDSSkiller log.Just last few lines of log is sufficient
===================================================RKILL
Please download Rkill by Grinler from one of the 4 links below (if one of them does not work try another.) and save it to your desktop:
Link 1
Link 2
Link 3
Link 4
In order for Rkill to run properly you must disable your anti-malware software. Please refer to this page if you are not sure how.
Double-click on Rkill. (If you are using Windows Vista, please right-click on it and select Run As Administrator)
Note: You may have to run Rkill a few times before it is successful. You may also have to download Rkill from a different link which will save it as a different file name.
A black screen will appear and then disappear. Please do not... Read more

10 more replies
Relevance 48.79%

I have some kind of hijacker virus I can't get rid of for good. IE home page always returns to RES://iuucb.dll/index.html#23648 or some other number. I have used spybot, adware away, spykiller, spybuster, norton and trend micro to name a few and each time i think it's gone, it comes back...can anyone help me get this thing off my pc once and for all?
 

Answer:IE hijacker keeps coming back

HI, You may want to go to the following link.
http://forums.spywareinfo.com/index.php?showtopic=12609&st=30

Read the whole post (It is several pages) - it seems that at the end someone actually found a fix.
Also, if this is not the same issue - post a new thread there - they are pros in those issues and will reply shortly.
 

2 more replies
Relevance 48.79%

My sister-in-law dropped off her laptop hoping I can get it to work. It kept freezing up with a fake infection warning from SpySheriff (buy-to-disinfect scam). Spybot and ewido removed gobs of infected files, but when I rebooted it was back. I ran AdAware and did another HijackThis, but I'm not yet confident to boot out of safe mode. Could somebody please tell me if there is still anything suspicious here? Thanks for your help!Logfile of HijackThis v1.99.1Scan saved at 4:43:55 AM, on 5/28/2006Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\explorer.exeC:\WINDOWS\explorer.exeC:\Program Files\ewido anti-malware\SecuritySuite.exeC:\Program Files\Hijack This\HijackThis.exeR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.htmlR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.htmlR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.htmlR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = htt... Read more

Answer:Spysheriff Keeps Coming Back

Hi and welcome to Bleeping Computer! My name is Sam and I will be helping you. There are still several issues that show up in your log.Download SmitfraudFix (by S!Ri) to your Desktop.Extract all the files to your Destop. A folder named SmitfraudFix will be created on your Desktop.______________________________Open Ewido and update to the latest definition files.On the left-hand side of the main screen click the Update Button.Click on Start.The update will start and a progress bar will show the updates being installed.Once finished updating, close Ewido.If you are having problems with the updater, you can use this link to manually update ewido.Ewido manual updates. Make sure to close Ewido before installing the update.______________________________Open the SmitfraudFix folder and double-click smitfraudfix.cmdSelect option #1 - Search by typing 1 and press EnterThis program will scan large amounts of files on your computer for known patterns so please be patient while it works. When it is done, the results of the scan will be displayed and it will create a log named rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed. Please post that log.

2 more replies
Relevance 48.79%

Despite regular PC anti-virus scans, Avast, and online scanners like ESET and scans from Malwarebytes, which usually returns little, the one that captures malware best for me is Spybot.

But it seems I keep removing same malware like Fastclick etc.

Any other scans available?

I've posted Hijackthis scans many times in past, but stopped as I recently get no responses.

This forum must be really busy now.
 

More replies
Relevance 48.79%

I have a friend that, has WIN XP and on DSL, he also has, AVG antivirus which keeps catching a trogen, but the next day, it's back on his computer. He deletes it but it is in a different folder or location everyday. Is there anyone out there that can tell me how he can get completely rid of this trogen?Thanks
Lori
 

Answer:Trogen keeps coming back.

10 more replies
Relevance 48.79%
Relevance 48.79%

Hi, everyone. I have something Malwarebytes calls Trojan.BHO that I can't seem to get rid of. Malwarebytes apparently gets it but it always ends up reappearing after a couple of reboots.

I think it first showed up on the 14th of February during a routine checkup. It wasn't until after I tried to get rid of it that I started having problems.

For wathever reason it wouldn't allow me to launch either Firefox or Chrome - in fact, the folders where they were installed were off-limits to all users, regardless of their admistrator status. I could temporarily gain control of the folders by running Malwarebytes and have since uninstalled both.

I can still run IE, but -

1. Whenever I try to open a link on a new tab, it will ALSO open a new window. Yes, I checked the settings, and it's definitely the trojan since this behaviour goes away - temporarily - after I run Malwarebytes.

2. The Trojan also shows up as a toolbar add-on for IE ("jscript proxy auto-configuration"). It claims to be by "(unverified) Microsfot Corporation" and the option to disable it is greyed-out. The only way to get rid of it is to run Malwarebytes but, again, it comes back after a couple of reboots.

3. It doesn't do anything else that's noticeable. There's nothing on my toolbar, no pop-ups, no redirecting, etc.

If it matters, I have tried running Malwarebytes under safe mode after disabling system restore (that was following someone els... Read more

Answer:Trojan.BHO keeps coming back

Hi and welcome.

Re run Hitman Pro and have it delete everything it finds.

Delete these:

C:\Program Files (x86)\GUM4751.tmp
C:\Program Files (x86)\GUT4752.tmp


Please download Junkware Removal Tool to your desktop.

Shut down your protection software now to avoid potential conflicts.
Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
The tool will open and start scanning your system.
Please be patient as this can take a while to complete depending on your system's specifications.
On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
Attach JRT.txt to your next message.



Re run Malware Bytes and attach the new log.

Now explain how things are.
 

3 more replies
Relevance 48.79%

I have been paying increasing attention to W10 evolution as release date approaches. I am very much not convinced, but it does SEEM as if Win8 usability is coming back. In fact, some of the Win8 usability that got lost in 8.1 may even be making a reappearance? The issues I have been concerned about so far, and their current status as I am led to believe, are as follows:Full Metro immersive interface for Metro apps and Start Screen not enabled at boot - Corrected.Horizontal scroll (ideal for wide screen devices) replaced by vertical scroll in full Metro interface - Corrected.Task bar forced on in Metro interface - Corrected.Current desktop apps not showing on desktop task bar when full Metro interface enabled - Optional, can be switched back on.Charms bar not present - Corrected, when full Metro is enabled charms return.Share not present - It is present, but it is hidden in different places for every app? Sounds unlikely when MS's stated goal is a unified interface in all things, is there no option on the task bar or something? Is there any way to add an icon or tile or something as a shortcut so I don't have to keep searching for it? Otherwise I'll end up just going straight to the email app every time which would be a big backwards step. What's the procedure here? Or have I got this confused?Metro snap - Corrected kind of, it works but for some reason has been hidden with a double swipe, first down then from the left? Or something? Sounds awkward, is this action tweakable at... Read more

Answer:Win 8 features seem to be coming back... how far?

The fact that the desktop taskbar is even being offered as an option for use on a tablet says no. Its more like Windows 7, not 8.

31 more replies
Relevance 48.79%

http://www.bleepingcomputer.com/forums/topic433509.html/page__p__2516707__fromsearch__1#entry2516707

Answer:Virus keeps coming back

Please follow the guidance in post number 2 in that topic.

1 more replies
Relevance 48.79%

On my win XP desktop I found couple of viruses 1-trojan metajuan and 2 trojan virtumonde, while scanned with Norton antivirus.
NAV removed the virus not once twice but more than 4 times and keep coming back even after disabling the system restore.

I also used PC tools spyware doctor and scan the computer several times the same same viruses keep coming back.
Any help will be very much appreciated.
Please help me remove this viruses from computer.
Thank you.

Answer:Virtumonde Keeps Coming Back

You need to post in the correct forum. I'll move you there

9 more replies
Relevance 48.79%

here is the log:

Malwarebytes' Anti-Malware 1.34
Database version: 1823
Windows 5.1.2600 Service Pack 2

3/5/2009 9:18:09 PM
mbam-log-2009-03-05 (21-18-09).txt

Scan type: Quick Scan
Objects scanned: 65386
Time elapsed: 2 minute(s), 2 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\system32\meI6qj75.dll (Trojan.Agent) -> Quarantined and deleted successfully.

Answer:trojan keeps coming back!

Please print out and follow these instructions: "How to use SDFix". When using this tool, you must use the Administrator's account or an account with "Administrative rights"Disconnect from the Internet and temporarily disable your anti-virus, script blocking and any real time protection programs before performing a scan.When done, the SDFix report log will open in notepad and automatically be saved in the SDFix folder as Report.txt.If SDFix is unable to run after rebooting from Safe Mode, run SDFix in either Mode, and type F, then press Enter for it to finish the final stage and produce the report.Please copy and paste the contents of Report.txt in your next reply.Be sure to renable you anti-virus and and other security programs before connecting to the Internet.-- If the computer has been infected with the VirusAlert! malware warning from the clock and the Start Menu icons or drives are not visible, open the SDFix folder, right-click on either the XP_VirusAlert_Repair.inf or W2K VirusAlert_Repair.inf (depending on your version of Windows) and select Install from the Context menu. Then reboot to apply the changes.

10 more replies
Relevance 48.79%

I really need help. Whenever I scan with avast, it tells me there's a virus. I can't delete because it's being used by another program. So I got into safe mode and try to remove it. A while later after I deleted it and back into Windows, I scan again and it's back. It's always in the same place too:

C:\.....\Temporary Internet Files\Content.IE5\ZTNTM02A\movie[1]
HijackThis log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:50:08 PM, on 10/7/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\brss01a.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\Rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Internet ... Read more

Answer:Virus keeps coming back

Anyone?
 

1 more replies
Relevance 48.79%

Hello, ago 2-3 weeks I got some viruses, i tried to delete them but they come back everytime..
The viruses are in 3 drivers (D,E,C) and also i got another virus named Backdoor.Agent
By the way I use Windows XP
Can somebody help me?

Answer:ms-dos virus keeps coming back

Hey?

7 more replies
Relevance 48.79%

This is the 3rd time in maybe 3 weeks I've seen this.

My AVG anti virus scan comes up (though I don't have it scheduled to scan at a certain time) and starts running, showing in a small box, changes and threats"

It has CHANGE

C\WINDOWS\SYSTEM32\KERNAL32.dll
and also the same with

user.dll
shell32.dll
ntoskml.exe

and: TROJAN HORSE GENERIC_CEQ in MY DOCUMENTS\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT IE5\030MDFWH\MOVIE(1).qtl

Usually I either delete the temp files and/or wait for the AVG to finish and get rid of it.

But, I notice it's doing it again, now. I'm not sure if this is the exact same changes and trojan name as the previous times, but I rememer there were changes, and a trojan and it was in the TEMP files.

I get movies from Netflix and play them on the computer, but I've been doing this for 1 1/2 years and this (trojan) just started a few weeks ago. That's the only connection I can think of to "movie". I have dialup and have a hard time watching things on YouTube so don't do that much. I did try and download a free movie from a site that was passed around, but that was 2-3 weeks ago, and after seeing how big it was, and figuring it would take 2-3 months to ever download it (if I could leave the internet on, without getting knocked offline that long) I gave up.

Since this is in the temp files it will get dumped when I clear these, or AVG will take it out, but I'm wondering why it comes back in the fi... Read more

More replies
Relevance 48.79%

I recently got an 0x80004005 activation error on my XP Media Center 2005 computer. I changed the userinit registry data by using the following link http://forums.spybot.info/blog.php?b=14. It worked for a while but eventually I was forced to do a Recovery install over my current installation. I reactivated, using a real CD key, as I own an official version of XP Media Center 2005. My computer now boots up but the Userinit registry value is always changed after reboot. I used Spy Sweeper 5.5 and Malwarebytes' Anti-Malware 1.35. Upon startup Anti-Malware 1.35 detects the server.exe spyware and then deletes it and after a restart it is back. The Userinit registry value is C:\WINDOWS\system32\userinit.exe,"C:\WINDOWS\server.exe", after every restart even after Anti-Malware changes it back to C:\WINDOWS\system32\userinit.exe, The problem I am having is that after a certain period of time, none of my web browsers can connect to the internet anymore. Using a command-prompt I can ping yahoo.com so I am still connected, I just can't use my web browsers. I have attached the following hijackthis info. Thanks in advance for your help.DDS (Ver_09-03-16.01) - NTFSx86 Run by Ed at 5:13:22.15 on Sat 04/04/2009Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_13Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.3582.2654 [GMT -8:00]AV: Symantec AntiVirus Corporate Edition *On-access scanning enabled* (Updated)=============... Read more

Answer:server.exe keeps coming back

Hello.You have a nasty infection on board. One of them includes a backdoor.Backdoor ThreatIMPORTANT NOTE: Unfortunatly One or more of the identified infections is a backdoor trojan.This allows hackers to remotely control your computer, steal critical system information and download and execute files.I would counsel you to disconnect this PC from the Internet immediately. If you do any banking or other financial transactions on the PC or if it should contain any other sensitive information, please get to a known clean computer and change all passwords where applicable, and it would be wise to contact those same financial institutions to apprise them of your situation.Though the trojan has been identified and can be killed, because of it's backdoor functionality, your PC is very likely compromised and there is no way to be sure your computer can ever again be trusted. Many experts in the security community believe that once infected with this type of trojan, the best course of action would be a reformat and reinstall of the OS. Please read these for more information:How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud?When Should I Format, How Should I ReinstallWe can still clean this machine but I can't guarantee that it will be 100% secure afterwards. Let me know what you decide to do.With Regards,Extremeboy

7 more replies
Relevance 48.79%

I've been working on a user's laptop (Win XP SP3) that wouldn't boot, even into safe mode. I ran a windows repair from a Win SP SP3 installation CD, which allowed me to at least get into safe mode. There I found several trojans and viruses, including (these are Symantec names) Trojan.FakeAV!gen29, W32.Harakit, Trojan.Gen, Trojan.FakeAV. After cleaning, Malwarebytes found registry entries for Hijack.FolderOptions and Trojan.Agent. Finally satisfied that the system was clean, I restored the drivers and downloaded and installed all the Windows updates. Both processes required several reboots. I then returned the laptop to the user. Unfortunately, I made the mistake of not running final scans of the system first. But there had been no symptoms during the system restoration, so I was lulled into what was obviously a false sense of security.

Immediately after booting the system the next day, he got an alert from Symantec AV about two infected files: DWH9F.tmp and DWH1E.tmp, both in his profile's Local Settings\Temp folder. They were identified only as "Trojans" - no specifics. He was not yet connected to the internet and had no external devices attached. Laptop back to me. Malwarebytes found two infected registry items: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\svchost (Trojan.Agent) and HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\load (Trojan.Agent).

I'm conc... Read more

Answer:Trojan(s?) Keep Coming Back

Hello and welcome to Bleeping Computer We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here. If you have since resolved the original problem you were having, we would appreciate you letting us know. If not please perform the following steps below so we can have a look at the current condition of your machine. If you have not done so, include a clear description of the problems you're having, along with any steps you may have performed so far. Upon completing the steps below another staff member will review your topic an do their best to resolve your issues. If you have already posted a DDS log, please do so again, as your situation may have changed. Use the 'Add Reply' and add the new log to this thread. Thanks and again sorry for the delay. We need to see some information about what is happening in your machine. Please perform the following scan:Download DDS by sUBs from one of the following links. Save it to your desktop.DDS.scr DDS.pifDouble click on the DDS icon, allow it to run. A small box will open, with an explaination about the tool. No input is needed, the scan is running. Notepad will open with the results. Follow the instructions that... Read more

2 more replies
Relevance 48.79%

Hello,

I am using a 64 bit version of windows vista. I have a virus on my computer that keeps coming back. Usually I am able to remove viruses on my computer using a combination or rkill, malwarebytes, and super anti spyware, but this specific virus keeps coming back, even after I clear it with malwarebytes. Also the virus wont let me update my malwarebytes software. I have tried to do a sytem restore, but everytime I click on the icon, i am asked to select a program to open system restore with, and I am not sure which program to pick. On my desktop there is a suspicious icon named system restore. Any help would be greatly appreciated.
Thanks

Answer:Virus keeps coming back

Please follow the instructions in ==>This Guide<== starting at Step 6. If you cannot complete a step, skip it and continue.Once the proper logs are created, then make a NEW TOPIC and post it ==>HERE<== Please include a description of your computer issues, what you have done to resolve them, and a link to this topic.If you can produce at least some of the logs, then please create the new topic and explain what happens when you try to create the log(s) that you couldn't get. If you cannot produce any of the logs, then still post the topic and explain that you followed the Prep. Guide, were unable to create the logs, and describe what happens when you try to create the logs.It would be helpful if you post a note here once you have completed the steps in the guide and have started your topic in malware removal. Good luck and be patient.If HelpBot replies to your topic, PLEASE follow Step One so it will report your topic to the team members.

1 more replies
Relevance 48.79%

On Startup there is a program, spyware i guess, that is called jzppenc.exe in the process manager. All it does is create an ad on the homepage and a popup to come up when ever i go on IE. I just end in the the process manager and it doesnt come back till next startup. Whenever i take it out of the startup it comes back, same with deleting it from the regestry startup. Anyone hear of it or know what to do. I also cannot find it in C:\ where it says it is.

Answer:Jzppenc.exe? Keeps coming back!!!

It could be hidden. Run Microsoft antispyware and spysweeper. See if that helps.

9 more replies
Relevance 48.79%

Combofix just restarts my computer and won't run and nothing can find the virus but it's there. It started as a fake antivirus, then when I deleted it it created win 7 antivirus 2011. I think I got rid of that one too, but now everytime I click any link it takes me to some random add page instead. I've already did a system restore from days ago and even that didn't work, but it stopped my problem with running .exe's from the win antivirus.

Answer:Virus just keeps coming back!

Hello having run ComboFix we need to see that and a DDS log.As you now see Combofix is not to be run like a commmon tool. It's why we post this above the malware forums.ComboFix is a tool that should only be run under the supervision of someone who has been trained in its use. Using it on your own can cause problems with your computer. Please go here....Preparation Guide ,do steps 6 - 9.Create a DDS log and post it in the new topic explained in step 9 which is here Virus, Trojan, Spyware, and Malware Removal Logs and not in this topic,thanks.Skip the GMER step and instead post the ComboFix log you posted earlier.Let me know if that went well.

3 more replies
Relevance 48.79%

I'm not sure whether it's a virus, trojan, spyware etc but I have something running on processes which takes up around 180k memory. Everytime I close the process it re-appears but as a different name... For example, as of now the process is called 'xsggsz.exe' but now I've closed it and it's re-appeared as 'vzdfme.exe'

I've used spysweeper, McAfee, Ad-Aware and system mechanic to try and get rid of it but it just won't budge.

I'd appreciate any help regarding this.

Thanks!
 

Answer:Virus That Keeps Coming Back!

go to http://www.pandasoftware.com/products/activescan/com/activescan_principal.htm and click on



scan your pcClick to expand...

Panda has the most upto date scanner I've seen

also if you do not have a firewall - you really need one.
I've used the free version of zonealarm for a number of years, and never had a problem, except a couple of times when I turned it off to access a site (that was real dumb)
 

1 more replies
Relevance 48.79%

Need help removing this process... and yes, I know the dif between it and the legit svchost

Within Task Manager, a svchost.exe process keeps generating with a description of 'winrscmde' instead of Host Process For Windows Services. It was sucking up 600k of my RAM and my internet speed went to pot. My BullGuard firewall log shows that process is sending massive traffic out to misc sites. I've blocked it via the firewall and have tried at least a dozen times to remove it via Malwarebytes (it finds it, IDs it as a Trojan) but it comes back every time I tell it to delete it (and after the subsequent restart). I've even tried it in Safe Mode with the same results. My BullGuard AV portion doesn't even find it.

I've tried to System Restore to a prior point, but it's still there. I've also tried to physically delete the file it specifies in c:\windows. No joy - it returns after reboot.

Here is the log that a Malwarebytes quick scan produces after I tell it to remove the Trojan.
______________________________________________________________________________________________
______________________________________________________________________________________________

Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org

Database version: 7961

Windows 6.1.7600
Internet Explorer 8.0.7600.16385

10/16/2011 3:50:35 PM
mbam-log-2011-10-16 (15-50-35).txt

Scan type: Quick scan
Objects scanned: 195494
Time elapsed: 5 minute(s), 30 ... Read more

Answer:winrscmde Keeps Coming Back

With the information you have provided I believe you will need help from the malware removal team. Please make sure that you read the information about getting started first.Then start a new thread HERE and include or required logs.Including a link to this thread will be helpful. Good luck and be patient. Help is on the way!

6 more replies
Relevance 48.79%

Hi
Just got this issue three hours ago and it's getting on my nerves for real.. I'm really considering formatting my pc just because of it

I'll copy-paste what I wrote in the "steps taken in order to remove infection" field:

First I went into task manager and removed every weird and newly created task and its files.. they all had the same creation time. At the same time deleting any file with the same creation time near that location. Then looked around google and found someone recommending Adware Removal Tool by TSA which I used. It removed the mywebsearch hijacking and asked to restart, but then came another issue "tohot-something". And I ran adware removal tool again which did the job.. or so I thought because it came back. So I ran it again and it removed it again and I haven't restarted yet and running the tool again won't show "files found" but there're still ads everywhere.
One thing I noticed is, after running the tool and it fixing the issue there're no problems... until I enable an extension that is.. the moment I enable one everything comes back. I have RES and Mcafee site advisor but I removed them before making this thread.
Also when I first attempted to write the thread the laptop was being slow as hell and freezing and being noisy and the page crashed.. now nothing is happening.

Also I couldn't attach AdwareCleaner log because my system won't allow the software.
 

Answer:Adsware keep coming back

sorry for the double.. didn't realize it'll show it to readers.
 

10 more replies
Relevance 48.79%

Hi, I've had this problem for about a week now. Something seems to have gotten onto my computer. The main thing I notice is there is a program called brastk.exe that gets autorun on startup. There are also a number of startup entries in msconfig that reactivate even if I disable them. They are:
"rundll32" which runs a dll called drkly16j.dll
"dumprep 0 -u"
"brastk.exe"

If I delete brastk.exe or drkly16j.dll they just get recreated on the next boot. It appears that something besides a program is running at startup, possibly a service or a program running on shutdown. There is also something redirecting my google searches, and when I plug in my flash drive an autorun file gets created along with a file called system.exe.

EDIT: uh-oh, I just tried to run HJT and Spybot and neither will start! No error messages, just double clicking on the program and nothing happens.

Answer:Malware keeps coming back

Please download Malwarebytes Anti-Malware and save it to your desktop.Make sure you are connected to the Internet.Double-click on mbam-setup.exe to install the application.When the installation begins, follow the prompts and do not make any changes to default settings.When installation has finished, make sure you leave both of these checked:Update Malwarebytes' Anti-MalwareLaunch Malwarebytes' Anti-MalwareThen click Finish.MBAM will automatically start and you will be asked to update the program before performing a scan. If an update is found, the program will automatically update itself. Press the OK button to close that box and continue. If you encounter any problems while downloading the updates, manually download them from here and just double-click on mbam-rules.exe to install.On the Scanner tab:Make sure the "Perform Quick Scan" option is selected.Then click on the Scan button.If asked to select the drives to scan, leave all the drives selected and click on the Start Scan button. The scan will begin and "Scan in progress" will show at the top. It may take some time to complete so please be patient.When the scan is finished, a message box will say "The scan completed successfully. Click 'Show Results' to display all objects found".Click OK to close the message box and continue with the removal process.Back at the main Scanner screen, click on the Show Results button to see a list of any malware that was found.Make sure that e... Read more

8 more replies
Relevance 48.79%

I have not had such an issue removing malware until this one. I say Superfish since it comes up with MalWareBytes every scan. IT is located in C:\Users\*\AppData\Local\Google\Chrome\Default\Local Storage\. Everytime Chrome opens.
 
 
I can remove the PUP, restart and be good to go until a few minutes running chrome. IE is not affected. It will not replicate. I have used Rkill to stop processes and followed with MBAM. I have used AdWCleaner and JunkWare Removal Tool. I have run a sleugh of others as well.
 
I have cleaned up the Programs list with what I feel are neccessary. No unwanted as far as I can tell. I have done my due diligence with this.
 
I have also removed Flash, Reader, and Java and have updated with latest versions from valid sites. I have disabled PepperFlash in Chrome and tried a default Flash but came back as well.
 
I have traced the infection to the registry (made a back-up first, but am pretty comfortable around it as well) and removed the points of infection there. It works great with IE but a few seconds after Chrome is opened, it's back. I have use Chameleon as well, thinking the browser themselves could be infected.
 
I believe it is a file dropper located on the computer. I thought I was successful with a program located in the TEMP directory associated with Mozilla but no luck.
 
SAS only picks up Tracking Cookies.
MBAM will pick up Superfish Located in same Directory stated earlier but no Tracking Cookies
Rkill sto... Read more

Answer:SuperFish Keeps Coming back

Have you tried resetting the hosts file?
Also, try examining the shortcuts to Google Chrome. Sometimes a hyperlink is in the Target: 

24 more replies
Relevance 48.79%

 Hi all, my main computer has been infected with the ICE Malware twice now and I don't know what I can do to fix it at this point.
  I have done system restores, I have used malware and Kickstart pro and a couple of other programs and it still comes back.
 Any fix I make only lasts about 24 hours or so.
 I know the problem is with my Windows Registry. A window will pop up asking me if I want to allow the program to make changes to my computer via the registry and clicking no only brings up the window again and again until I click yes. 
Shortly after that, the ICE malware has shown up both time.
 At this point, I am thinking the only thing to do is do a system reformat but I've been told even that might not work.
At least I have everything I really care about backed up on external hard drives (learned my lesson from Cryptowall) but I would really like the stupid thing off my computer for good.
  Any help I can get will be greatly appreciated, as I am at my wit's end.

Answer:Ice Malware keeps coming back

Hello and welcome to Bleeping Computer! I am HelpBot: an automated program designed to help the Bleeping Computer Staff better assist you! This message contains very important information, so please read through all of it before doing anything.
We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.
To help Bleeping Computer better assist you please perform the following steps:
*************************************************** In order to continue receiving help at BleepingComputer.com, YOU MUST tell me if you still need help or if your issue has already been resolved on your own or through another resource! To tell me this, please click on the following link and follow the instructions there.CLICK THIS LINK >>> http://www.bleepingcomputer.com/logreply/555446 <<< CLICK THIS LINK
If you no longer need help, then all you needed to do was the previous instructions of telling me so. You can skip the rest of this post. If you do need help please continue with Step 2 below.
***************************************************If you still need help, I would like you to post a Reply to this topic (click the "Add Reply" button in the lower right hand of t... Read more

2 more replies
Relevance 48.79%

Hi,

I have tried to remove Exactsearch from my PC, but everytime I scan with Panda it says my memory is infected with it again.

My Hijack this log is:

Logfile of HijackThis v1.99.1
Scan saved at 12:21:17 PM, on 26/04/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Panda Software\Panda Titanium Antivirus 2005\PavProt.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\brsvc01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\brss01a.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Panda Software\Panda Titanium Antivirus 2005\Firewall\PavFires.exe
C:\Program Files\Panda Software\Panda Titanium Antivirus 2005\PavFnSvr.exe
C:\Program Files\Panda Software\Panda Titanium Antivirus 2005\Pavkre.exe
C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
C:\Program Files\Panda Software\Panda Titanium Antivirus 2005\pavsrv51.exe
C:\Program Files\Panda Software\Panda Titanium Antivirus 2005\prevsrv.exe
C:\Program Files\Panda Software\Panda Titanium Antivirus 2005\PsImSvc.exe
C:\Program Files\Panda Software\Panda Titanium Antivirus 2005\AVENGINE.EXE
C:\WINDOWS\Expl... Read more

Answer:Exactsearch keeps coming back

hi, Can you post the exact location of the Exactsearch item Panda says it found please?

Look in the program Results or Report from a scan where it was found and post where the item supposedly is.

One thing to try is to find the quarantine or items that were removed by Microsoft Antispyware, AdAware, Spybot or other program and delete those backed up items> Panda or another scanner may detect those.
 

3 more replies
Relevance 48.79%

I have updated and run CWSHREDDER, Spybot, AD-Ware all of those and low and behold this hijacker keeps coming back? I am curious if anyone knows something new i could try or just wait for something to be updated that includes this? Here is a HijackThis log. Thanks for any help.
Logfile of HijackThis v1.97.7
Scan saved at 11:51:31 AM, on 4/16/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\AIM95\aim.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Documents and Settings\J Vaughn\Desktop\Payton\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\System32\cfn.dll/sp.html (obfusc... Read more

Answer:About:Blank keeps coming back

Hi CG

Close your browser and check the following entries in HJT, click fix and Reboot afterwards.

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\System32\cfn.dll/sp.html (obfuscated)

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\System32\cfn.dll/sp.html (obfuscated)

R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\System32\cfn.dll/sp.html (obfuscated)

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\System32\cfn.dll/sp.html (obfuscated)

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\System32\cfn.dll/sp.html (obfuscated)

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\System32\cfn.dll/sp.html (obfuscated)

O2 - BHO: (no name) - {163B0301-160B-45F2-B290-AB5A089D8A46} - C:\WINDOWS\System32\cfn.dll

O2 - BHO: (no name) - {5DEC1638-C432-47BB-97DA-F376A54EB3AF} - c:\system volume information\_restore{b37680b2-ba0a-4e5d-bf30-83e44c588624}\rp134\a0028263.dll (file missing)
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52...meInstaller.exe

I've seen these entries on another log and they did keep coming back so lets' see what happens here.

Post back, okay?
 

3 more replies
Relevance 48.79%

Hi, I was wondering if someone could help...I have a recurring problem. I have not installed any new software or hardware, but have been having this problem since day 1.
I got a new hard drive, reformatted it on my laptop (thinkpad 600X), and installed XP. I periodically get BSOD with the same message each time...
The mini dump datafile is below. Could anyone shed some light as to the cause?
I really appreciate it...thanks in advance

BugCheck 100000D0, {81c00010, 2, 1, 80549fb8}

Probably caused by : HTTP.sys ( HTTP!UlIsLowNPPCondition+55 )

Followup: MachineOwner
---------

kd> !analyze -v
************************************************** *****************************
* *
* Bugcheck Analysis *
* *
************************************************** *****************************

DRIVER_CORRUPTED_MMPOOL (d0)
Arguments:
Arg1: 81c00010, memory referenced
Arg2: 00000002, IRQL
Arg3: 00000001, value 0 = read operation, 1 = write operation
Arg4: 80549fb8, address which referenced memory
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high. This is
caused by drivers that have corrupted the system pool. Run the driver
verifier against any new (or suspect) drivers, and if that doesn't turn up
the culprit, then use gflags to enable special pool. You can also set
HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\ProtectNonPagedPool
to a DWORD 1... Read more

Answer:BSOD keeps coming back

Hi .Http.sys is a Windows file, the scene of the crime.If it were me, I'd try the registry edit suggested...but lets's try something else first.Worth reading, http://www.linkroll.com/Operating-Systems-...ptedMmpool.htmlWhat I would suggest is running either sfc /scannow or doing a repair install of XP. A repair install will probably take the same amount of time as running sfc /scannow, but will result in your needing to reinstall critical updates issues since the date the CD used will have been created.Doing either of these...requires a CD that reflects the same version of XP and at least the same level of SPs installed as your system currently reflects.How To Use Sfc.exe To Repair System Files - http://www.bleepingcomputer.com/forums/t/43051/how-to-use-sfcexe-to-repair-system-files/ How to Perform a Windows XP Repair Install - http://www.michaelstevenstech.com/XPrepairinstall.htm OTOH..you can elect to try the registry edit suggested in the analysis you provided. Since this involves editing the registry, the typical caution goes out to you. Editing the registry is something that can produce unwanted effects, so users are requested to back up the registry before considering such. A good tool for backing up the registry can be found at ERUNT Registry Backup Tool - http://www.snapfiles.com/get/erunt.html .If you are comfortable editing the registry or attempting such, then I would consider that suggestion.Louis

1 more replies
Relevance 48.79%

Apologies for coming back so soon for more help..The problem started this morning when I opened up my Laptop..As you can see from the attached photo, I have a black band across the top of my screen.I would be obliged if someone knew what was the cause and how to fix it,
Regards. jud
 

Answer:Apologies for coming back so soon for more help

Check the screen resolution, either use the auto adjust button on the monitor itself or access the display resolution within Windows and check it there. It should match the monitor's native resolution.
 

2 more replies
Relevance 48.79%

hello

I have a virus Worm_RBOT.BCQ found on file C:\windows\system32\micront.exe

I have followed to the letter the removal instruction by Trend

I have deleted the file, deleted all Registry reference to this file, deleted all temp files and Bin , all in safe mode..

The virus seems to have been deleted. but when I connect to the net, after a while , virus is detected and all is back to square one..

Please Help!! how can I get rid of this Virus forever....

Thanx
Jadan
 

Answer:virus keeps coming back

10 more replies
Relevance 48.79%

Hello. I first found Vundo on Saturday, April 11. I left my email client (Thunderbird) open for a few hours and came back to loads of popups. I tried calling Microsoft, and they assisted me with removal - or so I thought. Afterwards, I installed every Windows update, bought and installed Trend Micro's Internet Security Pro, and started scanning with Malwarebyte's Anti-Malware twice a day, at least. Every day since then I have found instances of Vundo (depending on which I use first, my Antivirus or MBAM). Each day it has a different name, too. It started out with Vundo.H, then Vundo.HGO, and today, I have Vundo.V. Finally, last night I ran a Kaspersky scan, and it found two files that I had never seen mentioned before - a trojan-downloader.Win32.fraudload.edj and packed.win32.Mondera.c. I can't locate these files, and neither can any of the other programs. Here are the requested files: DDS.txt and my Kaspersky log (041609KOS.txt), and the Attach.txt file. Thank you so much for your help.DDS (Ver_09-03-16.01) - NTFSx86 Run by Jen at 12:33:38.40 on Thu 04/16/2009Internet Explorer: 7.0.5730.11 BrowserJavaVersion: 1.6.0_11Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.443 [GMT -4:00]AV: Trend Micro Internet Security Pro *On-access scanning enabled* (Updated)FW: Trend Micro Personal Firewall *enabled*============== Running Processes ===============C:\WINDOWS\system32\Ati2evxx.exeC:\WINDOWS\system32\svchost -k DcomLaunchsvchost.exeC... Read more

Answer:Vundo Keeps Coming Back

Please download The Comedian.exe to your desktopDouble click the program to run it. It will only take around several minutes to run.It will do a series of tasks and tell you when each one is finished.You will be prompted to press any key after each stepWhen it is done it will close and exit itself automatically.You can delete The_Comedian.exe once it is finishedNEXTPlease download Malwarebytes' Anti-Malware from HERE or HERENote: If you already have Malwarebytes' Anti-Malware, just run and update it.. Then do a "Perform Full Scan"Double Click mbam-setup.exe to install the application.Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.If an update is found, it will download and install the latest version.Once the program has loaded, select "Perform Full Scan", then click Scan.The scan may take some time to finish,so please be patient.When the scan is complete, click OK, then Show Results to view the results.Make sure that everything is checked, and click Remove Selected.When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.Copy&Paste the entire report in your next reply.Extra Note:If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfec... Read more

21 more replies
Relevance 48.79%

i scanned my flash drive with Avast antivirus and it detected a virus "antisys.exe". i had it removed but after using the disk and running a scan again, its back. I don't see the file on the drive but Avast kept telling me it is infected with the "antisys.exe" virus. and after deleting the file using avast and running a scan again, it's still there. Is it really a virus? how do i remove it without losing all the data in my flash drive. Any help is greatly appreciated. Thanks in advance.
 

More replies
Relevance 48.79%

Hello all, I seem to have malware or viruses that I cannot get rid of. I am running Windows 7 currently on my computer. The problem I am experiencing is that fake virus protection programs will run on my computer and cause my computer to blue screen (not sure of the message but will consciously look if it happens again and post here). It also sometimes just goes straight to the blue screen. I run malwarebytes and spybot on my computer and they always eliminate a lot of trojans (trojanproxy.agent, trojan.fakealert, trojan.agent, trojan.agent.gma, rogue.fakeHDD). I also noticed that some are the svchost.exe that I see other people have mentioned. So I remove all of these and they all seem to come back. I also have restored my computer back to previous points when I get so bogged down by error messages that I cant even get to the malware removal tools. Thanks.

Answer:Trojans keep coming back

Welcome aboard Download Security Check from HERE, and save it to your Desktop. * Double-click SecurityCheck.exe * Follow the onscreen instructions inside of the black box. * A Notepad document should open automatically called checkup.txt; please post the contents of that document.=============================================================================Please download Farbar Service Scanner (FSS) and run it on the computer with the issue.Make sure the following options are checked:
Internet ServicesWindows FirewallSystem RestoreSecurity Center/Action CenterWindows UpdateWindows DefenderPress "Scan".It will create a log (FSS.txt) in the same directory the tool is run.Please copy and paste the log to your reply.====================================================================================Please download MiniToolBox and run it.Checkmark following boxes:Report IE Proxy SettingsReport FF Proxy SettingsList content of HostsList IP configurationList Winsock EntriesList last 10 Event Viewer logList Installed ProgramsList Devices (do NOT change any settings here)List Users, Partitions and Memory sizeClick Go and post the result.=============================================================================Download Malwarebytes' Anti-Malware (aka MBAM): http://www.malwarebytes.org/products/malwarebytes_free to your desktop. * Double-click mbam-setup.exe and follow the prompts to install the program. * At the end, be sure a checkmark is placed next t... Read more

16 more replies
Relevance 48.79%

I've had some issues with this computer, ran Malwarebytes and seemed to be ok. Now, every time I run Malwarebytes, it finds multiple trojans and such.
see log:

alwarebytes Anti-Malware 1.60.0.1800
www.malwarebytes.org

Database version: v2012.01.13.02

Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
Dave :: DAVEANDBETS [administrator]

1/13/2012 9:35:40 AM
mbam-log-2012-01-13 (09-35-40).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 231858
Time elapsed: 24 minute(s), 20 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 18
C:\WINDOWS\Temp\tue0.025611008347881437.exe (Rogue.Chameleon2012) -> Quarantined and deleted successfully.
C:\WINDOWS\Temp\tue0.04322310983097066.exe (Trojan.FakeMS) -> Quarantined and deleted successfully.
C:\WINDOWS\Temp\tue0.11414868056561533.exe (Trojan.FakeMS) -> Quarantined and deleted successfully.
C:\WINDOWS\Temp\tue0.4467379515295722.exe (Trojan.Downloader.CBCGen) -> Quarantined and deleted successfully.
C:\WINDOWS\Temp\tue0.45533083493499504.exe (Rogue... Read more

Answer:Spyware keeps coming back

16 more replies
Relevance 48.79%

I've run into a relentless little piece of malware called AdAntiHS which I have not been able to get rid of in a friend's computer. There's barely any information on it from credible sources online. It digs its claws into the startup programs on Windows (running Windows 7) and won't let go. Not sure what kind of damage it's doing either.
 
I've disabled it from startup using msconfig, manually deleted it, and even ran MalwareBytes from a USB using Hiren's BootCD and removed it. But after restarting the computer it shows back up at C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup. I've also deleted keys in the registry associated with AdAntiHS but to no avail upon restarting the computer. 
 
I noticed that upon deleting AdAntiHS from startup, a commonstartup file is created at C:\Windows\pss. I deleted that too. There is a registry key of appcompatCache which I understand is more like a reference or history of programs that have executed on the computer. Those are the only registry keys I have not deleted that make mention of AdAntiHS.
 
So far, I installed BitDefender on the computer which manages to catch AdAntiHS everytime on startup, but even though I choose to delete the quarantined item, it comes back again on restart. So at best, I quarantine it on startup but I want to be able to permanently get rid of it.
 
Has anyone else encountered this piece of malware and been able to wipe it from their system?
 
Thanks in advance fo... Read more

More replies