Computer Support Forum

AWOLA has infected my system

Question: AWOLA has infected my system

hello guys/gals:



here with my computer again. it now has a phony anti-virus software on it "awola" the computer has been taken over, no task manager, no wallpaper, random shut downs, constant "warning" pop ups, i cant do anything anymore......


please help thanks


here are the logs:


DDS (Ver_09-03-16.01) - NTFSx86
Run by Owner at 18:02:31.03 on Mon 04/06/2009
Internet Explorer: 7.0.5730.11
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.894.500 [GMT -7:00]


============== Running Processes ===============

C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
svchost.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
svchost.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\awolaantispy.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Microsoft Security Adviser\msctrl.exe
C:\Program Files\Microsoft Security Adviser\msavsc.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\Microsoft Security Adviser\msscan.exe
C:\Program Files\Microsoft Security Adviser\msiemon.exe
C:\Program Files\Microsoft Security Adviser\msfw.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\AIM6\aim6.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\msupdate.exe
C:\Program Files\BigFix\BigFix.exe
C:\WINDOWS\system32\mkrnl.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\Microsoft Security Adviser\mssadv.exe
C:\Program Files\Microsoft Security Adviser\msctrlp.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Owner\Desktop\dds.scr

============== Pseudo HJT Report ===============

uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
uStart Page = hxxp://www.aol.com/?src=aim
uInternet Settings,ProxyOverride = 127.0.0.1;*.local
uURLSearchHooks: AIM Toolbar Search Class: {03402f96-3dc7-4285-bc50-9e81fefafe43} - c:\program files\aim toolbar\aimtb.dll
mURLSearchHooks: AIM Toolbar Search Class: {03402f96-3dc7-4285-bc50-9e81fefafe43} - c:\program files\aim toolbar\aimtb.dll
mWinlogon: Userinit=c:\windows\system32\userinit.exe,c:\windows\awolaantispy.exe
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: UberButton Class: {5bab4b5b-68bc-4b02-94d6-2fc0de4a7897} - c:\program files\yahoo!\common\yiesrvc.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: YahooTaggedBM Class: {65d886a2-7ca7-479b-bb95-14d1efb7946a} - c:\program files\yahoo!\common\YIeTagBm.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.5.0_06\bin\ssv.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: AIM Toolbar Loader: {b0cda128-b425-4eef-a174-61a11ac5dbf8} - c:\program files\aim toolbar\aimtb.dll
BHO: SidebarAutoLaunch Class: {f2aa9440-6328-4933-b7c9-a6ccdf9cbf6d} - c:\program files\yahoo!\browser\YSidebarIEBHO.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn1\yt.dll
TB: AIM Toolbar: {61539ecd-cc67-4437-a03c-9aaccbd14326} - c:\program files\aim toolbar\aimtb.dll
TB: {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No File
TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: [Aim6] "c:\program files\aim6\aim6.exe" /d locale=en-US ee://aol/imApp
uRun: [msctrl.exe] c:\program files\microsoft security adviser\msctrl.exe
uRun: [msavsc.exe] c:\program files\microsoft security adviser\msavsc.exe
uRun: [msscan.exe] c:\program files\microsoft security adviser\msscan.exe
uRun: [msiemon.exe] c:\program files\microsoft security adviser\msiemon.exe
uRun: [msfw.exe] c:\program files\microsoft security adviser\msfw.exe
uRun: [mssadv.exe]
uRun: [msupdate.exe] c:\windows\system32\msupdate.exe -check
mRun: [SoundMan] SOUNDMAN.EXE
mRun: [ehTray] c:\windows\ehome\ehtray.exe
mRun: [ATIPTA] "c:\program files\ati technologies\ati control panel\atiptaxx.exe"
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [msctrl.exe] c:\program files\microsoft security adviser\msctrl.exe
mRun: [msavsc.exe] c:\program files\microsoft security adviser\msavsc.exe
mRun: [msscan.exe] c:\program files\microsoft security adviser\msscan.exe
mRun: [msiemon.exe] c:\program files\microsoft security adviser\msiemon.exe
mRun: [msfw.exe] c:\program files\microsoft security adviser\msfw.exe
mRun: [mssadv.exe]
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\bigfix.lnk - c:\program files\bigfix\BigFix.exe
uPolicies-system: DisableTaskMgr = 1 (0x1)
uPolicies-system: NoDispBackgroundPage = 1
uPolicies-system: NoDispSettingsPage = 1
uPolicies-system: NoDispAppearancePage = 1
IE: &AIM Toolbar Search - c:\documents and settings\all users\application data\aim toolbar\ietoolbar\resources\en-us\local\search.html
IE: {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - c:\program files\aim95\aim.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBC} - c:\program files\java\jre1.5.0_06\bin\ssv.dll
IE: {0b83c99c-1efa-4259-858f-bcb33e007a5b} - {61539ecd-cc67-4437-a03c-9aaccbd14326} - c:\program files\aim toolbar\aimtb.dll
IE: {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - c:\program files\yahoo!\common\yiesrvc.dll
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
Trusted Zone: turbotax.com
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} - hxxp://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\yinsthelper.dll
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1138756188437
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} - hxxp://acs.pandasoftware.com/activescan/as5free/asinst.cab
DPF: {CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_04-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
Handler: ms-its51 - {F6F1E82D-DE4D-11D2-875C-0000F8105754} - c:\program files\common files\microsoft shared\information retrieval\itss51.dll
Notify: AtiExtEvent - Ati2evxx.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

================= FIREFOX ===================

FF - ProfilePath -

============= SERVICES / DRIVERS ===============

R2 IntuitUpdateService;Intuit Update Service;c:\program files\common files\intuit\update service\IntuitUpdateService.exe [2008-10-10 13088]
R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2009-2-13 24652]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2008-8-2 38472]

=============== Created Last 30 ================

2009-03-16 21:03 435,712 a------- c:\windows\awolaantispy.exe
2009-03-16 21:00 58 a------- c:\windows\system32\winwp.bmp
2009-03-16 21:00 253,952 a------- c:\windows\system32\msupdate.exe
2009-03-16 21:00 253,952 a------- c:\windows\system32\mkrnl.exe
2009-03-16 21:00 12,288 a------- c:\windows\msscan.dll
2009-03-16 21:00 12,288 a------- c:\windows\msiemon.dll
2009-03-16 21:00 12,288 a------- c:\windows\msfw.dll
2009-03-16 21:00 12,288 a------- c:\windows\msctrl.dll
2009-03-16 21:00 12,288 a------- c:\windows\msavsc.dll
2009-03-16 21:00 40,960 a------- c:\windows\mssadv.dll
2009-03-16 21:00 20,992 a------- C:\0xf9.exe
2009-03-07 18:24 <DIR> --d----- c:\program files\common files\AnswerWorks 5.0

==================== Find3M ====================

2009-03-07 17:13 10,022 a--sh--- c:\windows\system32\KGyGaAvL.sys
2009-02-09 04:13 1,846,784 a------- c:\windows\system32\win32k.sys
2008-11-30 13:09 32,768 a--sh--- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008113020081201\index.dat
2008-11-30 13:09 32,768 a--sh--- c:\windows\system32\config\systemprofile\local settings\temporary internet files\content.ie5\index.dat

============= FINISH: 18:03:04.15 ===============

Relevance 100%
Preferred Solution: AWOLA has infected my system

I recommend downloading and running Reimage. It's a computer repair tool that has been proven to identify and fix many Windows problems with a high level of success.

I've used it in the past to identify and fix everything from blue screens (BSOD's), ActiveX errors, corrupt files and processes, dll/exe/sys errors, recover lost memory, Windows update problems, defragging, malware removal etc.

You can download it direct from this link http://downloadreimage.com/download.php. (This link will automatically start a download of Reimage that you can save to your computer.)

Answer: AWOLA has infected my system

Hello and Welcome to TSF.

Please Subscribe to this Thread to get immediate notification of replies as soon as they are posted. To do this click Thread Tools, then click Subscribe to this Thread. Make sure it is set to Instant notification by email, then click Add Subscription.

Please note that the forum is very busy and if I don't hear from you within three days this thread will be closed.

------------------------------------------------------

Please explain why this computer has no antivirus program installed and running. This is an open invitation for infection.

It can take as little as eight seconds to infect an unprotected computer.

Please keep this computer offline except when downloading tools and posting in the forum until we get one installed. Let me know your intentions for an antivirus program.

------------------------------------------------------

Please note that these fixes are not instantaneous. Most infections require more than one round to properly eradicate.

Please stay with me until given the 'all clear' even if symptoms seemingly abate.

Kindly follow my instructions and please do no fixing on your own or running of scanners unless requested by a helper.

------------------------------------------------------

Please visit this webpage for download links, and instructions for running ComboFix:

http://www.bleepingcomputer.com/comb...o-use-combofix

* Ensure you have disabled all antivirus and antimalware programs so they do not interfere with the running of ComboFix.

Get help here

Please post the C:\ComboFix.txt in your next reply for further review.

------------------------------------------------------

2 more replies
Relevance 62.73%

Hi, my mother recently infected her PC with AWOLA, and ever since, everything has been running much worse. I've tried to use previous posts / fixes, but to no avail. I've included the DSS report below. Thank you so much.

Deckard's System Scanner v20071014.68
Run by sconstan on 2008-02-01 14:59:16
Computer is in Normal Mode.
--------------------------------------------------------------------------------



-- HijackThis Clone ------------------------------------------------------------


Emulating logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2008-02-01 14:59:34
Platform: Windows XP Service Pack 2 (5.01.2600)
MSIE: Internet Explorer (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\system32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\scardsvr.exe
C:\Progress\OpenEdge\bin\admsrvc.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Microsoft SQL ... Read more

Answer:Older PC Infected with AWOLA, Please Help

Bump. Thanks again.

8 more replies
Relevance 62.73%

I have a simular issue to other but I dont see a common fix - HELP!

I've ran all the programs you recommended. Here are the logs.

This virus puts a yellow bang in my tray and states i've been infected. After closing the message a few times it launches Awola.

I belive it hit me 2 weeks ago.
 

Answer:Awola virus has infected my pc

More files attached.
 

10 more replies
Relevance 62.73%

Hi there, I believe my computer was recently infected by the Awola Virus / Trojan, and I could really use some assistance. I thank you in advance for any suggestions and help, they are appreciated. I'll put up a detailed description here of what's happened so far, and can certainly provide any additional information that may be required. My computer knowledge is okay, but very limited in terms of spyware and troubleshooting complex problems like this one.

Operating System = Windows XP

A couple of days ago I was doing some stuff online at 7:45pm, preoccupied and in somewhat of a rush. I got a popup menu that a trojan had been found, I assumed it was from my McAfee Security Centre (as this has happened several times before) but I didn't really look at it that closely, and selected okay (I think). I then started to receive a bunch of popups about Spyware, and Awola spyware removal program. I kept closing them because I was in a rush, didn't really look that closely, thought it was just ads and may very well have clicked something I shouldn't have. I did see the Awola Program box come up at one point and I thought I attempted to close it, but I may have clicked on something inadvertently.

Upon rebooting later, I realized that the computer was probably infected. I cannot click or open any application, by double-clicking an icon or program name I always receive the same error message (tailored to whatever application I attempted to open). A black empty box a... Read more

Answer:Infected By Awola 6.0 And Could Really Use Some Help Removing It

if you have not already done so you could try the superantispyware program?http://www.superantispyware.com/superantis...efreevspro.htmldownload it fromhttp://www.superantispyware.com/downloadfi...ANTISPYWAREFREErun the installation program and start the program from the desktop icon; fully update the definitions , reboot the computer into safe mode if it will let you , then run superantispyware from the desktop icon on a full computer scan when the scan is complete, reboot your computer into normal mode, and come back and post the log report you should find by opening the program and go to preferences/statistics.logsleft mouse click on the most recent entry, click on 'view log' and copy and paste that report into here for examination so folks can see what help you may need

30 more replies
Relevance 61.91%

This is definitely not an anti-spyware program. It opens a window off the toolbar disguised as a Windows security update. It warns, "Your computer is infected! Click here to protect your computer...". The balloon does not go away. It worked its way onto the computer uninvited. I've followed all the procedures listed in the Preparation Guide but to no avail. Please help. Thanks for your time and expertise. Here's the hijack log:Logfile of Trend Micro HijackThis v2.0.2Scan saved at 10:35:13 PM, on 8/31/2007Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v7.00 (7.00.6000.16512)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\Ati2evxx.exeC:\WINDOWS\system32\svchost.exeC:\Program Files\Panda Security\Panda Antivirus 2008\pavsrv51.exeC:\Program Files\Panda Security\Panda Antivirus 2008\AVENGINE.EXEC:\WINDOWS\System32\svchost.exeC:\Program Files\Sygate\SPF\smc.exeC:\WINDOWS\system32\spoolsv.exeC:\WINDOWS\system32\acs.exeC:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exeC:\WINDOWS\system32\Ati2evxx.exeC:\WINDOWS\Explorer.EXEC:\Program Files\Common Files\Apple\M... Read more

Answer:Infected With "awola Anti-spyware 6.0"

Welcome to the BleepingComputer HijackThis Logs and Analysis forum rosevilledad My name is Richie and i'll be helping you to fix your problems.Your version of Sun Java is out of date.Older versions have vulnerabilities that malware can use to infect your system.Please follow these steps to remove older versions of Sun Java,and then update.1. Download the latest version of Java Runtime Environment (JRE)2. Scroll down to where it says 'Java Runtime Environment (JRE) 6u2'.3. Click the "Download" button to the right.4. Check the box that says: "Accept License Agreement".5. The page will refresh.6. Click on the link to download 'Windows Offline Installation, Multi-language' and save to your desktop.7. Close any programs you may have running - especially your web browser.8. Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.9. Check any item with Java Runtime Environment (JRE or J2SE) in the name.10. Click the Change/Remove button.11. Repeat as many times as necessary to remove each Java versions.12. Reboot your computer once all Java components are removed.13. Then from your desktop double-click on jre-6u2-windows-i586-p.exe to install the newest version.Download Combofix and save to your desktop:Note: It is important that it is saved directly to your desktop Close any open browsers. Double click on combofix.exe and follow the prompts. When it's finished it will produce a log. Post the entire contents of C:... Read more

7 more replies
Relevance 61.91%

Hi there. I believe I contracted a virus / trojan through Awola 6.0 a few weeks back. I started a thread in the 'Am I Infected' section, here's the link for that full thread: http://www.bleepingcomputer.com/forums/t/143729/infected-by-awola-60-and-could-really-use-some-help-removing-it/Long story short, I believe this virus was contracted on Wednesday, April 23 around 745pm. My operating system is Windows XP. Whenever I double-click on any .exe file I get an all-black window, and a little window above it with an error message similar to this: "16-bit MS-DOS SubsystemC:\Documents and Settings\All Users\Desktop\Winamp.InkThe NTVDM CPU has encountered an illegal instruction.CS:054d IP: 013d OP: f0 85 38 90 3a Choose 'Close' to terminate the application." I can right-click certain programs and select "Run As" to use them, but can't double-click on anything. I also think this virus has taken over Administrator duties, changed my registry and is preventing me from properly installing programs. It was also preventing me from running anti-virus scans, but I believe we have found a way around this, and I was finally able to process a scan with DSS (and Hijack This). I also did a scan using the Kaspersky scanner. I will copy and paste all logs below. Thanks in advance for all your help. HIJACK THIS MAIN.TXTDeckard's System Scanner v20071014.68Run by Mania on 2008-05-19 22:51:49Computer is in Normal Mode.---------------------------------------------------------------------------------- ... Read more

Answer:Infected With Awola 6.0 Virus / Trojan

HelloApologize for the delay in response we get overwhelmed at times but we are trying our best to keep up.If you have since resolved the original problem you were having would appreciate you letting us know If not please perform the following below so I can have a look at the current condition of your machine.Thanks and again sorry for the delay.Please download Deckard's System Scanner (DSS) and save to your Desktop.alternate download siteDSS will do the following:Create a new System Restore point in Windows XP and Vista.Clean your Temporary Files, Downloaded Program Files, Internet Cache Files, and empty the Recycle Bin on all drives.Check some important areas of your system and produce a report for an analyst to review.Automatically run HijackThis. It will also install and place a shortcut to HijackThis on your desktop if you do not already have it installed. So if HijackThis is not installed and DSS prompts you to download it, please answer yes.You must be logged onto an account with administrator privileges when using.Close all applications and windows.Double-click on dss.exe to run it and follow the prompts.If your anti-virus or firewall complains, please allow this script to run as it is not
malicious.When the scan is complete, two text files will open in Notepad:main.txt <- this one will be maximizedextra.txt <- this one will be minimizedIf not, they both can be found in the C:\Deckard\System Scanner folder.Please copy (Ctrl+C) and paste (Ctrl+V) the c... Read more

18 more replies
Relevance 61.91%

Ive had this infection for sometime. Tried a bunch of methods from computerforum but still cant finish the virus off. I constantly get CID popups and on my moms guest account she has this annoying AWOLA popup that appears to say its an anto virus program. Logfile of Trend Micro HijackThis v2.0.2Scan saved at 5:31:45 PM, on 5/10/2008Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v7.00 (7.00.6000.16640)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\Program Files\Windows Defender\MsMpEng.exeC:\WINDOWS\System32\svchost.exeC:\Program Files\Common Files\Symantec Shared\ccSvcHst.exeC:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exeC:\WINDOWS\system32\spoolsv.exeC:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exeC:\Program Files\Bonjour\mDNSResponder.exeC:\Program Files\Common Files\LightScribe\LSSrvc.exeC:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exeC:\WINDOWS\system32\nvsvc32.exeC:\WINDOWS\system32\svchost.exeC:\Program Files\Common Files\Ulead Systems\D... Read more

Answer:Badly Infected With Cid Popups And Awola

also in my c: folder I have like 200 TMP files that look like pos1A2F.tmp what are these??

3 more replies
Relevance 61.91%

Hi,

Earlier today I managed to get the Awola malware onto my computer. I have run Ad-Aware & Spybot S&D along with F-Prot anti-virus software. I have also ran Hijackthis! & removed the Awola line. I also ran a search of my computer files & removed all files relating to Awola. I have rebooted my computer & the annoying yellow triangle warning message continues to popup every 30 seconds. Could someone help to squash this pest?

Thanks in advance!
haroldff1082

Answer:Annoying "your Computer Is Infected!" Pop-up (awola)

Hello and welcome haroldff1082What antivirus procuct do you have installed and have you scanned with it in safe move.Please do this also Download Attribune's ATF Cleaner and then SUPERAntiSpyware , Free Home Version. Save both to desktop .. DO NOT run yet.Open SUPER from icon and install and Update itUnder Scanner Options make sure the following are checked (leave all others unchecked):Close browsers before scanning.Scan for tracking cookies.Terminate memory threats before quarantining.Click the "Close" button to leave the control center screen and exit the program. DO NOT run yet.Now reboot into Safe Mode: How to start Windows in Safe ModeDouble-click ATF-Cleaner.exe to run the program.Under Main "Select Files to Delete" choose: Select All.Click the Empty Selected button.If you use Firefox or Opera browser click it at the top and choose: Select AllClick the Empty Selected button.If you would like to keep your saved passwords, please click No at the prompt.Click Exit on the Main menu to close the program.NOW Scan with SUPEROpen from the desktop icon or the program Files listOn the left, make sure you check C:\Fixed Drive.Perform a Complete scan. After scan,Verify they are all checked.Click OK on the summary screen to quarantine all found items.If asked if you want to reboot, click "Yes" and reboot normally.To retrieve the removal information after reboot, launch SUPERAntispyware again.Click Preferences, then click the Statistics/Logs... Read more

3 more replies
Relevance 60.68%

I am attempting to clean my in-laws computer but I have been unable to remove AWOLA spyware from their system. I have downloaded Ad-Aware and also followed the steps that you suggested and I am still seeing the yellow box pop-up and AWOLA will uninstall and then re-install itself. I have been unable to locate the original file only shortcuts. Also, I have not been able to do any Windows Updates on their system. PLEASE HELP!

Deckard's System Scanner v20071014.68
Run by Owner on 2008-05-16 17:15:41
Computer is in Normal Mode.
--------------------------------------------------------------------------------

Total Physical Memory: 383 MiB (512 MiB recommended).


-- HijackThis (run as Owner.exe) -----------------------------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:15:55 PM, on 5/16/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Documents and Settings\Owner\Applicati... Read more

Answer:AWOLA Removal and Your computer is infected! Popup continuous

Hi, welcome to TSF!

If you still need assistance, please post a fresh main.txt log

1 more replies
Relevance 53.71%

I'm in an identical situation to another post. I'm not sure though if the response to other post was based on the reports or not. So, like the other guy:

Ran all the "READ & RUN ME FIRST" (Win XP) steps. Still have popups from yield sign in tray that say "Your computer is infected!" Also still have Awola Anti-spyware that either Spybot S&D or AVG had detected, and I thought, deleted.

Thank you so much for this forum!! Just let me know if I should simply follow what the other thread described.
 

Answer:AWOLA antispy and "Your Computer is Infected"

Hi kilgore!
I'll take a look at your logs and get back to you. This takes some time, so thanks for your patience. Please don't use your computer too much until we're sure it's clean.
abri
 

14 more replies
Relevance 52.89%

Ran all the "READ & RUN ME FIRST" (Win XP) steps. Still have popups from yield sign in tray that say "Your computer is infected!" Also still have Awola Anti-spyware that either Spybot S&D or AVG had detected, and I thought, deleted.

Attached Combofix and MGTools logs. AVG had no report to save even though I had "Automatically generate report after every scan" checked and "Only if threats are found" unchecked. The only thing AVG found was 9 cookies.

Thanks.
 

Answer:"Your computer is infected!" & Awola

Hi cee3!
Welcome to Major Geeks!

I'm looking at your logs.
abri
 

8 more replies
Relevance 44.69%
Question: Awola

Hi,

I've tried to clean Awola off of my system by piecing together what to do from the treads in this forum, and it appears to have removed the pop-ups. Can you guys take a look at my HJThis log and let me know if I missed anything? Also, please let me know if I should post anything else to be reviewed.

Thanks very much
 

Answer:Awola

Your HJT log is clean...although we recommend that the exe be renamed to analyse.

Are you still having problems? If you are:

Please follow the instructions in the below link and attach the requested logs when you finish these instructions.

READ & RUN ME FIRST. Malware Removal Guide
 

1 more replies
Relevance 44.69%
Question: Awola Bug?

There's a little bubble on the right side of my screen, near the clock, that keeps popping up (and won't go away, which is very annoying), saying "Your computer is infected!" Unknowingly, I clicked it and it presented me with "Awola Anti-Spyware 6.0" or something to that effect. I Googled Awola and found out that it was a rogue anti-spyware program, or something. So, I checked out Add/Remove Programs, and it wasn't in there. So I went through the Start menu to Uninstall Awola, and it said it was removed successfully, but the bubble will still not go away.

I am completely computer-stupid and have no idea what to do. Any help?
 

More replies
Relevance 44.69%
Question: Awola

thanks for your advice boopme.

i had so much trouble getting rid of awola and i finally did it thanks to your suggestions.
thanks alot!

Answer:Awola

You're welcome and welcome to BC. I split your post away into it's wn topic as that one is still working and you are further along. Always mke your own topic it is the better method and keeps things from being confused. As in The stpe for you to do is not the step for them,thanks. I would recommend you do this step now. Now you should Set a New Restore Point to prevent possible reinfection from an old one. Some of the malware you picked up could have been saved in System Restore. Since System Restore is a protected directory, your tools can not access it to delete these bad files which sometimes can reinfect your system. Setting a new restore point AFTER cleaning your system will help prevent this and enable your computer to "roll-back" to a clean working state. The easiest and safest way to do this is:Go to Start > Programs > Accessories > System Tools and click "System Restore".Choose the radio button marked "Create a Restore Point" on the first screen then click "Next". Give the R.P. a name then click "Create". The new point will be stamped with the current date and time. Keep a log of this so you can find it easily should you need to use System Restore.Then use Disk Cleanup to remove all but the most recently created Restore Point.Then go to Start > Run and type: CleanmgrClick "OK".Click the "More Options" Tab.Click "Clean Up" in the System Restore section to remove all ... Read more

3 more replies
Relevance 44.69%
Question: AWOLA

Just picked up Awola on my computer.Please help, how do I get rid of it??
 

Answer:AWOLA

have you tried any of the google search links?
http://www.google.com/search?aq=t&oq=awola+re&hl=en&safe=active&q=atwola+removal&btnG=Search

i havent had specific experience with this one.
 

1 more replies
Relevance 44.69%

I'm infected with Awola.

I don't know if that's what it's called exactly, and there could be more to my problem than that; but there are other threads on this very problem. As far as I could tell, netiquette on MajorGeeks says I should make my own thread rather than invade someone else's.

If I'm wrong, I'm very sorry for having made a redundant thread.

Symptoms:

- A yellow triangle with a black exclamation point in it sitting in my task bar. It spawns a large, intrusive word bubble telling me I'm infected with spyware and that Windows will download the Awola anti-spyware program if I click the bubble.

- My system will freeze for several seconds at a seemingly random frequency. It always unfreezes, and anything I've done during the 'frozen' period (words I've typed, things I've clicked on, etc.) eventually happens after things come unfrozen.

What I was doing when I first noticed the infection:

- I'd been gone for two days, and my computer had been left on. When I came back I noticed my internet browser was open, and the word bubble was staring at me. I don't believe anyone touched my computer while I was gone.

Hopefully I've attached everything properly.

I did an AVG scan, but the log reads:





"[1/21/2008 15:03:15 PM] synchronize database and filecache"Click to expand...

I followed the directions in the "read me first and do these thi... Read more

Answer:Awola, maybe others.

Welcome to Major Geeks!

Is your copy of Spywar Doctor a paid version or free trial? If free, uninstall it now.

Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

Uninstall the below software:
J2SE Runtime Environment 5.0 Update 11
Java(TM) 6 Update 3
Viewpoint Media Player <-- should have been uninstalled in step 0 of the READ ME

Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
R3 - URLSearchHook: (no name) - <default> - (no file)
O2 - BHO: Toolbar Helper - {D44BBB61-E17F-4AE6-A502-8D7E0B29E616} - C:\WINDOWS\system32\s1940.dll
O3 - Toolbar: Stumble&Upon - {22D003CE-6952-46C5-80B9-D19B479620AB} - C:\WINDOWS\system32\s1940.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [Microsoft Windows Adapter 5.1.3214] C:\Documents and Settings\RICHARD\Application Data\pzruv.exe
O4 - HKCU\..\Run: [Awola] "C:\Documents and Settings\RICHARD\Application Data\Awola\Awola.exe" /MIN
O8 - Extra context menu item: StumbleUpon: &Blog This - res://C:\WIND... Read more

4 more replies
Relevance 44.69%
Question: Awola

Well I got the AWola bug and it's a killer. Dang "Your Computer is infected!" pops up every 5 seconds after closing it and that is the good news. I can't go anywhere without being redirected. I am not even sure how I have made it to this site. Anyway I have done a HIJACK THIS log and I am posting it if anyone knows what to do I am all EARS.Thanks!Logfile of Trend Micro HijackThis v2.0.2Scan saved at 2:58:00 PM, on 12/28/2007Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\csrss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\system32\spoolsv.exeC:\WINDOWS\system32\svchosts.exeC:\WINDOWS\UmVlc2UgQnJpZGdlcw\command.exeC:\WINDOWS\system32\drivers\KodakCCS.exeC:\Program Files\Common Files\LightScribe\LSSrvc.exeC:\Program Files\Network Monitor\netmon.exeC:\Program Files\PC Tools AntiVirus\PCTAVSvc.exeC:\WINDOWS\system32\lpcywinp.exeC:\WINDOWS�... Read more

Answer:Awola

Hi and welcome to Bleeping Computer! My name is Sam and I will be helping you. Please download ComboFix and save it to your desktop.Double click combofix.exe and follow the prompts.When it's done running it will produce a log for you. Please post that log in your next reply.Important Note - Do not mouseclick combofix's window whilst it's running. That may cause it to stall.

3 more replies
Relevance 44.69%

I searched previous threads about this pesky malware, but I think my problem might be a little different...
So my computer automatically shut down, and then after rebooting I noticed a popup (from the taskbar only) telling me that my computer is infected and that I should download "special antispyware"...

I haven't clicked it, and don't plan on it, BUT I'm wondering if my computer is already infected ( I ran spybot and AVG and both found no infections.) and if not how do I stop that pop up from well popping up.

Thanks
 

Answer:Not sure if I have awola yet...

Welcome to Major Geeks!

Please follow the instructions in the below link and attach the requested logs when you finish these instructions.


If something does not run, write down the info to explain to us later but keep on going.
Do not assume that because one step does not work that they all will not.
READ & RUN ME FIRST. Malware Removal Guide

Notes:

If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode. You can try running steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
Starting your computer in Safe mode

If you have problems downloading on the problem PC, download the tools on another PC and burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.


Plus a guide on HOW TO: Attach Items To Your Post
 

1 more replies
Relevance 44.28%
Question: Awola Removal

dealt with AWOLA removal today. here are the following steps used to remove it:

0. DISABLE System Restore.

1. download, install and update Malwarebytes AntiMalware removal tool.
http://www.malwarebytes.org/

2. reboot your system into Safe Mode with networking.

3. verify that you have the latest update of Malwarebytes by performing the update again.

4. perform a FULL SCAN with Malwarebytes and, after the scan is complete, remove all items in the list.

5. perform a search on your computer for the following:
*awola*.*
this will search for ANY file in your system with the word 'awola' anywhere within its name, regardless of the file extension. DELETE any 'awola' files.

6. open the registry (ie. regedit) and do a search for 'awola' and remove any items you find.

7. perform another scan with Malwarebytes to be certain your system is clean.

8. restart your system.

if anyone has comments, please share them.
 

More replies
Relevance 44.28%
Question: Awola Removal!!!!

I got infected with Awola and cant get it off. Thanks for you help.

Incident Status Location

Spyware:Application/Awola Not disinfected c:\documents and settings\kris\application data\awola\awola.exe
Spyware:Application/Awola Not disinfected C:\Documents and Settings\Kris\load.exe
Potentially unwanted tool:Application/PRScheduler Not disinfected C:\Documents and Settings\Kris\Start Menu\Programs\Startup\PowerReg Scheduler V3.exe ... Read more

Answer:Awola Removal!!!!

Any suggestions on how to get rid of this. Plzzz my computer is crashing and i need help bad. Thanks

10 more replies
Relevance 44.28%
Question: Awola virus

How do I get rid of the awola virus?

Answer:Awola virus

Hi and welcome to TSF.

Please start here and follow the instructions.

http://www.techsupportforum.com/secu...sting-log.html

If you cannot complete any of the Steps, simply move on to the next one - remember to let the Analyst know about this when you post your logs.

Do not post your logs back in this thread - follow the guidance in the above link!

Please note that the Security Forum is always busy, so I would ask for your patience while waiting for a reply.

1 more replies
Relevance 44.28%
Question: Awola Invastion

Good Day Doctors, I'm helping another friend with their system. It looks like they got caught in one of those sites that pull you in and the next thing you know the software is on your system. I trying to uninstall a program called AWOLA. It states that it is an ANTI -SYPWARE and the system has been infected. I tried to uninstall it but no luck. It seems you have to buy the program to have the option available to uninstall it.

Has anyone heard of this program and how can I get it off my friend's system?
Thx in advance
Steve
 

More replies
Relevance 44.28%

Awola is driving me crazy!! And just about the time I get started on another paper, I get a pop-up. I can't tell you how many times I have had to re-connect to this site just to finish this thread.
I wasn't able to perform a Windows Update because the Windows Genuine Advantage Validation Tool wouldn't install. (KB892130).
Here is the log;

Deckard's System Scanner v20071014.68
Run by gc on 2008-01-18 13:44:27
Computer is in Normal Mode.
--------------------------------------------------------------------------------

-- System Restore --------------------------------------------------------------

System Restore is disabled; attempting to re-enable...success.


-- Last 1 Restore Point(s) --
1: 2008-01-18 19:44:32 UTC - RP1 - System Checkpoint


Backed up registry hives.
Performed disk cleanup.

Percentage of Memory in Use: 81% (more than 75%).
Total Physical Memory: 256 MiB (512 MiB recommended).


-- HijackThis (run as gc.exe) --------------------------------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:51:41 PM, on 1/18/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C... Read more

Answer:Awola & numerous pop-ups

Download SDFix from here and save it to your desktop.


Please then reboot your computer in Safe Mode by doing the following :
Restart your computer

After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
Instead of Windows loading as normal, a menu with options should appear;
Select the first option, to run Windows in Safe Mode, then press "Enter".
Choose your usual account.

In Safe Mode, right click the SDFix.zip folder and choose Extract All,
Open the extracted folder and double click RunThis.bat to start the script.
Type Y to begin the script.

It will remove the Trojan Services then make some repairs to the registry and prompt you to press any key to Reboot.
Press any Key and it will restart the PC.

Your system will take longer that normal to restart as the fixtool will be running and removing files.
When the desktop loads the Fixtool will complete the removal and display Finished, then press any key to end the script and load your desktop icons.

Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
(Report.txt will also be copied to Clipboard ready for posting back on the forum).

Finally paste the contents of the Report.txt back on the forum.


=========================================


Download Combofix from any of the links below, and save it to your desktop. For information regarding this d... Read more

3 more replies
Relevance 44.28%
Question: Awola infection!

My computer is infected with Awola anti spyware. I searched Google for some solutions for this aggrevating problem. This website caught my eye. I hope that I can be helped for my problem. As of right now my computer crashes on normal mode within 5 min's of startup. The only way I can use the computer is on safe mode.
Once I entered the website I was reading a forum for Awola removal and downloaded the file SDfix (this was from a link on the thread. I decided that is would be best if I discontinue any attemp at correcting the problem myself because I am not extremely knowledgable. Thanks for any help I can get.

Answer:Awola infection!

why doesnt anyone want to help me with my issue?

1 more replies
Relevance 44.28%
Question: Awola Removal!!!!

I have Awola virus on my computer and i cannot get it off. i have deleted the registry values and everything. I ran spybot s&d and ad-aware. Please help in any way you can. Thanks.

Answer:Awola Removal!!!!

help plzzzz, i can barely use my computer with it this bad. thanks

2 more replies
Relevance 44.28%
Question: awola removal

My brother-in-law has managed to install awola and now I have to get rid of it. Any ideas? He lives 60miles away and is techno-phobic.

Answer:awola removal

click here

10 more replies
Relevance 44.28%
Question: Awola.... sigh

I'm embarrassed that I got "suckered" into this spyware, but I clicked too quickly after seeing the security alert (bogus, of course). I've searched and read everything, and can't believe I'm unable to get rid of it!



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:37:36 AM, on 1/14/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\acs.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\ISS\BlackICE\blackd.exe
c:\em\opt\Tivoli\lcf\bin\w32-ix86\mrt\lcfd.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\mcshield.exe
C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\TDS\tdssvc.exe
C:\WINNT\System32\mspmspsv.exe
C:\WINNT\system32\wscntfy.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\igfxtray.exe
C:\WINNT\system32\hkcmd.exe
C:\WINNT\AGRSMMSG.exe
C:\Program Files\Network Associates\Common Framework\UdaterUI.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Network Associates\Common Framework\McTray.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
... Read more

Answer:Awola.... sigh

Stupid spyware! Ran SDFIX and COMBOFIX with fingers crossed

Anyways....the Awola popup from the tray is still there!!


SDFix: Version 1.129

Run by LocalAdmin on Tue 01/22/2008 at 10:54 PM

Microsoft Windows XP [Version 5.1.2600]

Running From: C:\SDFix

Safe Mode:
Checking Services:


Restoring Windows Registry Values
Restoring Windows Default Hosts File

Rebooting...


Normal Mode:
Checking Files:

No Trojan Files Found






Removing Temp Files...

ADS Check:

C:\WINNT
No streams found.

C:\WINNT\system32
No streams found.

C:\WINNT\system32\svchost.exe
No streams found.

C:\WINNT\system32\ntoskrnl.exe
No streams found.



Final Check:

catchme 0.3.1344.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-22 23:00:49
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden services & system hive ...

scanning hidden registry entries ...

scanning hidden files ...

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


Remaining Services:
------------------



Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" ... Read more

4 more replies
Relevance 44.28%
Question: awola help needed

my sweet husband contracted awola and I am left to figure out how to get rid of it... any help is much appreciated - here is the HijackThis Log I just ran



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:01:50 PM, on 1/23/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPZIPM12.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\keyhook.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\WINDOWS\system32\kmw_run.exe
C:\WINDOWS\system32\KMW_SHOW.EXE
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\system32\hphmon05.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09... Read more

Answer:awola help needed

I have now also completed ComboFix but the popup "Your computer is infected!" is still there... log listed below but not sure if I did it correctly. It is also affecting other programs and now I cannot print. Please help before I divorce my husband or at least throw the computer at him!!!




WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons

19 more replies
Relevance 44.28%
Question: Awola Malware

My computer has been infected with Awola. I am normally pretty good with computers but this has caused me to waste the last 6 hours on trying to removed it with no luck. From what I have read this is pretty common but extremly hard to remove. I really need help before me and my computer play fisty cuffs.Here is the log named main.txt:Deckard's System Scanner v20071014.68Run by Barry on 2008-04-22 22:52:31Computer is in Normal Mode.---------------------------------------------------------------------------------- System Restore --------------------------------------------------------------System Restore is disabled; attempting to re-enable...success.-- Last 1 Restore Point(s) --1: 2008-04-23 02:52:32 UTC - RP1 - System CheckpointBacked up registry hives.Performed disk cleanup.-- HijackThis (run as Barry.exe) -----------------------------------------------Logfile of Trend Micro HijackThis v2.0.2Scan saved at 10:57:25 PM, on 4/22/2008Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v7.00 (7.00.6000.16640)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\csrss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\Program Files\WIDCOMM\Bluetooth Software\... Read more

Answer:Awola Malware

Hello BarryCareyWelcome to BleepingComputer ========================If you are still in need of assistance please post a new Hijackthis log.

1 more replies
Relevance 44.28%

Hi can anyone assist me? I am trying to repair my cousin's computer which appears to have Awola installed on it.

I also unable to get the computer to detect any wireless signals even after manually entering the settings for my network. In addition, the user also installed SystemTech Spyware Cleaner. Is this is a good program to use? Am I better off using Windows Defender?

Below is a log file


Deckard's System Scanner v20071014.68
Run by RASHIDA XXXX on 2008-05-03 20:53:22
Computer is in Normal Mode.
--------------------------------------------------------------------------------

-- System Restore --------------------------------------------------------------

Failed to create restore point; System Restore is disabled (service is not running).


Backed up registry hives.
Performed disk cleanup.



-- HijackThis (run as RASHIDA ROACH.exe) ---------------------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:54:15 PM, on 5/3/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wirele... Read more

Answer:Please help Awola 6 on laptop

I am sorry to bump this thread. I was wondering if there was something that I left out or should have done before posting this thread.

I did complete steps 1-4. I was unable to connect to the internet to do an online scan.

I apologize if I incorrectly posted. Sorry for bumping this thread.

4 more replies
Relevance 44.28%
Question: Awola hijack

My sister's computer has been hijacked, any help will be much appreciated. Here's the HJT log:
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Farstone Url Blocker - {316AEF8D-3C37-423E-9E6E-13820A9DC37A} - C:\PROGRA~1\PCSECU~1\THESHI~1\IrlOnIE.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O2 - BHO: BndShell3 BHO Class - {875A1348-7674-42aa-ADAC-B4F36A004A2D} - C:\Program Files\QdrDrive\QdrDrive8.dll (file missing)
O2 - BHO: Farstone Popup Blocker - {E22F9B9D-1A1F-473E-BED6-D8BC152441F4} - C:\PROGRA~1\PCSECU~1\THESHI~1\FARPOP~1.DLL
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - ... Read more

More replies
Relevance 44.28%

Howdy!

My computer seems to have been infected with this malware Awola. It is driving me bonkers. I cannot seem to rid my computer of this program. I've tried my antispyware programs and uninstalling and basic registry deletions, but it keeps regenerating.

Any help would be tremendously appreciated.

Thanks,
Andrew
 

More replies
Relevance 44.28%
Question: awola virus

I am running windows xp and believe I caught the awola virus probably bundled with a lot of other things.
Ok, all I really want to do is copy my files to my external hard drive so I can reformat my computer. But, the virus has taken away my administrator status. It has disabled copying files to my external hard drive or dragging and dropping files. I cannot install Norton antivirus. The error message is "Setup was unable to update the MSI system component. If this problem continues please contact Microsoft at www.microsoft.com". I try to open my network connections, and they won't open.

Is my best bet just paying for the phishing scheme and going along with awola? Will it give me back these capabilities after I have paid, so I can reformat my computer?

Please help. I am desperate.

Answer:awola virus

Oh, I am also considering buying XoftSpySE. I downloaded the program of the internet, and it did locate many corrupt files. However, I am worried if I purchase it, I will not be able to install it fully and use it as I wasnt able to install Nortan Antivirus from disk. Is this a legitimate fear, or did this program already install, and when I purchase the license key, it will simply remove the corrupt files?

I hope I explained this well. Please reply.

19 more replies
Relevance 43.87%

Hello TechGuy users,
I am a new user to TechGuy after my friend had an encounter with... AWOLA.
They said they were getting pop-ups even if not on the internet and their whole Compaq Windows XP Laptop is slowing down. I told them to get Spybot Search & Destroy and update to the newest version and they did. They scanned their whole computer and they destroyed some AWOLA software, but it is still there.

What should they do?
Thanks,
Michael
 

Answer:AWOLA Spyware... AAAHHHHH!

More info:
I told my friend to do System Restore they said it didnt work, then also tried to uninstall it manually but they want them to pay for it...

 

1 more replies
Relevance 43.87%

Had a recent problem with malware. The main culprits seemed to be Awola, Security Toolbar, Kukkakreck taking over my home page with numerous pop-ups and slow performance. Followed your nine step program and am greatly appreciative for the concise advice. Most of my problems seemed to be solved but I will post the log and hope for the best. Thank you in advance.Logfile of Trend Micro HijackThis v2.0.2Scan saved at 3:24:34 PM, on 12/14/2007Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v7.00 (7.00.6000.16574)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\system32\LEXBCES.EXEC:\WINDOWS\system32\LEXPPS.EXEC:\WINDOWS\system32\spoolsv.exeC:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exeC:\Program Files\Network Associates\McAfee Desktop Firewall for Windows XP\FireSvc.exeC:\Program Files\Network Associates\Common Framework\FrameworkService.exeC:\Program Files\Network Associates\VirusScan\VsTskMgr.exeC:\Program Files\Sygate\SEA\smc.exeC:\WI... Read more

Answer:Awola, Kukkakreck, Etc. And Other Villains

Welcome to the BleepingComputer HijackThis Logs and Analysis forum Thom TMy name is Richie and i'll be helping you to fix your problems.Please disable Spybot S&D?s protection,or it will interfere.You can enable it after you're clean.Open Spybot and click on 'Mode' and check 'Advanced Mode'.Click on 'Tools' in bottom left hand corner.Click on the 'System Startup' icon.Uncheck 'Teatimer' box and/or uncheck 'Resident'.Click the 'Allow Change' box.Then, check next to the computer clock to see if the icon for Spybot is still there.If it is, right click it and choose 'exit Spybot-S&D Resident'.Restart the computer.If you find you're experiencing problems disabling Spybot's Tea-Timer,follow the info in the link below:http://www.russelltexas.com/malware/teatimer.htmViewpoint Manager is considered as foistware instead of malware since it is installed without users approval but doesn't spy or do anything "bad". This will change from what we know in 2006 read this article: http://www.clickz.com/news/article.php/3561546You are well advised to remove the program now. Go to Start > Settings > Control Panel > Add/Remove Programs and remove the following programs if present,then restart your pc:ViewpointViewpoint ManagerViewpoint Media PlayerYour version of Sun Java is out of date.Older versions have vulnerabilities that malware can use to infect your system.Please follow these steps to remove older versions of Sun Java,and then update.1. Download the latest versio... Read more

15 more replies
Relevance 43.87%

After reviewing the forums I have found that I have a common issue as others do. I have the same Windows balloon pop-up and when clicked it will install the fake AWOLA anti-spyware. I have already followed the steps required to generate logs and I am posting them now. Could someone please provide me with any additional help to remove this malware from my system and thank you in advance.
 

Answer:AWOLA virus removal help

Welcome to Major Geeks!

Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

Do you use MusicMatch Jukebox?

You need to go back and follow the instructions in step 1 of the READ ME for MSconfig. You must not use MSconfig to control any startups or services. Select Normal Startup mode and remain in that state.

Uninstall the below old versions of software:
J2SE Runtime Environment 5.0 Update 12
Java 2 Runtime Environment, SE v1.4.2
Viewpoint Media Player <-- should have been uninstalled in step 0 of the READ ME

Make sure you reboot after uninstalling the above!

After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [KernelDrv.exe] C:\WINDOWS\System32\KernelDrv.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_4\bin\jusched.exe"
O4 - Startup: PowerReg Scheduler V3.exe
O17 - HKLM\System\CS2\... Read more

3 more replies
Relevance 43.87%

Hi there I REALLY need help okay so first i got infected with awola its a flashy trojan virus that disguises itself as a antivirus spyware and i thought i removed it and then today i turn on my computer and i have 2 drives C and D and my D drive would not load like its would just show my background with no icons or side bars on it. Please if you know how to help would you please i would be forever grateful thank you
 

More replies
Relevance 43.87%

I keep getting pop-ups and a little notification at the bottom right of my screen saying: "Your computer is infected! Windows has detected spyware infection. It is recommended to use special antispyware tools to prevent data loss. Windows will now download and install the most up-to-date antispyware for you. Click here to protect your computer from spyware."

I clicked it and found that it was installing a program "Awola," which I later found to be some sort of spyware or something. I uninstalled and did some Ad Aware scans (both in normal and safe modes), but I keep getting this notification CONSTANTLY. It's really annoying. Can anyone help?

Thanks!!
 

Answer:Awola program--How do I remove it?

14 more replies
Relevance 43.87%

My Bosses computer got hit with AWOLA before finding your site I tried to fix it. We run McaFee antivirus. His firewall was down, which has been fixed.

His computer runs XP Pro, he can do what he needs to do however, he still is getting the message poping up. Your computer is infected.

Yes, I deleted files and some registry stuff already. I ran spybot and found a few more files. On the last run of spybot there are not offending files showing. Is there any way of ridding that annoying message?

Thanks,
 

Answer:AWOLA- Continued Pop Up Message

Welcome to Major Geeks!

Please follow the instructions in the below link and attach the requested logs when you finish these instructions.

READ & RUN ME FIRST. Malware Removal Guide
 

3 more replies
Relevance 43.87%

I have run the XP cleaning procedure with combofix, spybot, AVG and MG tools as suggeste by this great site, but I still have a nasty Awola bug on my computer. I will try to attach the logs, but AVG stated that it did not create one.

Please help, and thanks in advance!
 

Answer:awola still giving me fits

Welcome to Major Geeks!

Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

Uninstall the below old versions of software:
Spybot - Search & Destroy 1.3 <-- this has not been used for more than 2 years.
Viewpoint Media Player <-- should have been uninstalled in step 0 of the READ ME

Then install the proper version of Spybot as given in the READ ME. MAKE SURE to uncheck the option for using Teatimer.

Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

O4 - HKCU\..\Run: [Microsft Windows Adapter 5.1.3013] C:\Documents and Settings\Home\Application Data\zpbfwsb.exe
O4 - HKLM\..\Policies\Explorer\Run: [ngm] C:\WINDOWS\System32\ngm.exe
O4 - HKCU\..\Policies\Explorer\Run: [nhhp] C:\WINDOWS\System32\nhhp.exe
O15 - Trusted Zone: http://www.neededware.com
O16 - DPF: NDWCab - http://www.neededware.com/ndw4.cab
O20 - Winlogon Notify: khfdbxx - khfdbxx.dll (file missing)
O23 - Service: PLSRemote Service (PLSRemoteSvc) - Unknown owner - C:\WINDOWS\SYSTEM32\PLSRemote.exe (file missing)

After clicking Fix, exit HJT.

Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is ... Read more

9 more replies
Relevance 43.87%

My machine has been infected with AntivirusXP 08 and Awola. Have cleaned out alot but now am left with random non-fatal BSOD's that I think are a trademark of these infections. Kaspersky scan of the critical areas is clean so there is no log to attach.I am including to two logs from the DSS scan.Deckard's System Scanner v20071014.68Run by Samantha on 2008-07-19 14:35:13Computer is in Normal Mode.--------------------------------------------------------------------------------Total Physical Memory: 480 MiB (512 MiB recommended).-- HijackThis (run as Samantha.exe) --------------------------------------------Logfile of Trend Micro HijackThis v2.0.2Scan saved at 2:35:42 PM, on 7/19/2008Platform: Windows XP SP3 (WinNT 5.01.2600)MSIE: Internet Explorer v7.00 (7.00.6000.16674)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\SYSTEM32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\spoolsv.exeC:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exeC:\Program Files\Bonjour\mDNSResponder.exeC:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exeC:\Program Files... Read more

Answer:Antivirusxp 08 And Awola Infection

Hello, my name is fenzodahl512 and welcome to BC.. Please do the following...]Please uninstall Viewpoint Media Player from your computer..Please download ATF Cleaner by Atribune.Double-click ATF-Cleaner.exe to run the program.Under Main choose: Select AllClick the Empty Selected button.If you use Firefox browserClick Firefox at the top and choose: Select AllClick the Empty Selected button.NOTE: If you would like to keep your saved passwords, please click No at the prompt.If you use Opera browserClick Opera at the top and choose: Select AllClick the Empty Selected button.NOTE: If you would like to keep your saved passwords, please click No at the prompt.Click Exit on the Main menu to close the program.------------------------Please download the OTMoveIt2 by OldTimer.Save it to your desktop.Please double-click OTMoveIt2.exe to run it. (Vista users, please right click on OTMoveit2.exe and select "Run as an Administrator")Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

[kill explorer]
C:\Documents and Settings\Samantha\Application Data\internaldb6334.dat
C:\Documents and Settings\Samantha\Application Data\internaldb41.dat
C:\Documents and Settings\Sam\Application Data\shc3ubj0enb9
C:\WINDOWS\system32\blphc5ubj0enb9.scr
C:\Program Files\Viewpoint
EmptyTemp
puri... Read more

2 more replies
Relevance 43.87%

Hi, yesterday I starte getting some really annoying Awola anti-spywear popups on my PC. I used the information in some of the threads on this forum, and thought that I had it beat, but today, I'm having the same problem. Here's the HijackThis log. Any help is much appreciated. This is a really annoying issue.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:49:55 PM, on 1/18/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\aspimgr.exe
C:\WINDOWS\system32\basfipm.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Dell\QuickSet\bak\quickset.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\iTunes\iTunes... Read more

Answer:Solved: Awola Malware

16 more replies
Relevance 43.87%

gettin tons of pop ups, mainly says "internet speed monitor" or "outerinfo" on em, also awola self downloaed dis now automatically coming on and what not, and of course comp running slow as heck. Thanks for help, im computer stupid, haha.Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\Ati2evxx.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\Ati2evxx.exeC:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exeC:\WINDOWS\system32\spoolsv.exeC:\WINDOWS\Explorer.EXEC:\Program Files\M-Audio\Fast Track USB\MAUSBFTInst.exeC:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exeC:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYSC:\WINDOWS\system32\svchost.exeC:\Program Files\VentSrv\ventrilo_svc.exeC:\Program Files\VentSrv\ventrilo_srv.exeC:\WINDOWS\system32\wscntfy.exeC:\Program Files\Java\jre1.6.0_02\bin\jusched.exeC:\Program Files\Common Files\Real\Update_OB\realsched.exeC:\WINDOWS\system32\Rundll32.exeC:\Program Files\Java\jr... Read more

Answer:Pop Ups, Awola, Sloooow Comp, Help!

already fixed it, didnt know how to just delete the topic, thanks.

2 more replies
Relevance 43.87%

I have read that some others have gotten help on the Awola virus, can someone help guide me through removing this malware?

More replies
Relevance 43.46%

A big thanks in advance.Windows XP Professional SP2I am working on a friend's PC that was hit with Awola 6. He followed removal procedures described at http://www.spyware-techie.com/awola-or-awo...-removal-guide/He brought me the computer with no signs of the Awola 6 files or registry entries mentioned in the link above yet his network adapter stops receiving packets only about a minute after the Windows desktop has booted.I used system restore to take him back to before the attack but no help. Ran Smitfraud again and no help. I weeded through the running processes and ensured that there was no proxy set up in Internet options.Since the system has no available network connection I wasn't able to run the Kaspersky online scanner.I ran DSS and here is the log: Please note that I didn't have the computer hooked up to the router at the time of the DSS scan. If it is important I can hook the computer up and make a new log.Deckard's System Scanner v20071014.68Run by Santa B on 2008-06-20 04:50:22Computer is in Normal Mode.---------------------------------------------------------------------------------- System Restore --------------------------------------------------------------System Restore is disabled; attempting to re-enable...success.-- Last 1 Restore Point(s) --1: 2008-06-20 11:50:23 UTC - RP1 - System CheckpointBacked up registry hives.Performed disk cleanup.-- HijackThis (run as Santa B.exe) ---------------------------------------------Logfile of Trend Micro HijackThi... Read more

Answer:Awola 6 Removed But Packets Are Not Being Received.

I'm hoping somebody can get to solving this soon.

5 more replies
Relevance 43.46%

Have an AWOLA infection. was going to use info from this forum which suggested downloading a couple of files to help. But when I try to go to the sites, I get redirected to no page. Can't go anywhere.

Also, when doing a search now to locate and delete AWOLA files I get an error notice and Search shuts down.

Ad-Aware will run then stops about half way through.

Continuously get a little popup about infections. And there is a little yellow triangle on the startup menu bar (lower right) that, if clicked, will start Awola again.

Any suggestion, or do I just through the box away?

Thanks,

Pete

Answer:Awola - can't download fixes due to redirect

You should be able to download this tool. If not, use another machine, and a usb stick or CDR to carry it to the afflicted machine.

Please do this:

Download Deckard's System Scanner (DSS) to your Desktop. Note: You must be logged onto an account with administrator privileges.Close all applications and windows.
Double-click on dss.exe to run it, and follow the prompts.
When the scan is complete, two text files will open - main.txt <- this one will be maximized and extra.txt <-this one will be minimized
Copy (Ctrl+A then Ctrl+C) and paste (Ctrl+V) the contents of main.txt here.
Please attach extra.txt to your post.
To attach a file to a new post, simplyClick the[Manage Attachments] button under Additional Options > Attach Files on the post composition page, and
copy and paste the following into the "Upload File from your Computer" box:C:\Deckard\System Scanner\extra.txt

Click Upload.

What DSS will do: create a new System Restore point in Windows XP and Vista.
clean your Temporary Files, Downloaded Program Files, and Internet Cache Files, and also empty the Recycle Bin on all drives.
check some important areas of your system and produce a report for your analyst to review. DSS automatically runs HijackThis for you, but it will also install and place a shortcut to HijackThis on your desktop if you do not already have HijackThis installed.

------------------------------------------------------------------------------------... Read more

3 more replies
Relevance 43.46%

Hi everyone-

I'm trying to help my younger brother get his computer functioning properly.

Within the last couple of weeks, he's acquired the AWOLA problem, the machine runs incredibly slow and also his home page starts out at something completely different even though we've changed it back many times.

I've gone through the 5 steps and this is what I have.
Thank you all for your help.




Deckard's System Scanner v20071014.68
Run by Adam on 2008-04-25 23:30:56
Computer is in Normal Mode.
--------------------------------------------------------------------------------

-- System Restore --------------------------------------------------------------

System Restore is disabled; attempting to re-enable...success.


-- Last 1 Restore Point(s) --
1: 2008-04-26 04:31:07 UTC - RP1005 - System Checkpoint


Backed up registry hives.
Performed disk cleanup.

Total Physical Memory: 255 MiB (512 MiB recommended).
System Drive C: has 4.34 GiB (less than 15%) free.


-- HijackThis Clone ------------------------------------------------------------


Emulating logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2008-04-25 23:35:32
Platform: Windows XP Service Pack 2 (5.01.2600)
MSIE: Internet Explorer (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\SYSTEM32\smss.exe
C:\WINDOWS\SYSTEM32\csrss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\SYSTEM32\services.exe
C:\WINDOWS\SYSTEM32\lsass.exe
C:\WINDOWS\SYSTEM32\svchost.exe... Read more

Answer:AWOLA + Hijacked IE Home Page + others...

Hello and welcome to TSF.

Scan with HijackThis and put a checkmark against the following entries:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\WINDOWS\system32/left.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir...r=7&ar=msnhome
R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll (file missing)
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: (no name) - _{1C78AB3F-A857-482e-80C0-3A1E5238A565} - (no file)
R3 - URLSearchHook: (no name) - _{20EC3D2D-33C1-4C9D-BC37-C2D500688DA2} - (no file)
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
O15 - Trusted Zone: about://internet (HKCU)
O16 - DPF: {99802379-7362-40E2-9D28-8A3B9AF880B7} () - http://hotsearchbar.com/toolbar2/winhot32.cab

Close all browsers and windows other than HijackThis and click on "fix checked".

I am not sure if you set this as your start page yourself or not... Read more

11 more replies
Relevance 43.46%

Hey guys, I'm working on a PC for a friend, and she has the constant "Your Computer is infected!" crap going on... Here's the HJT and SmitFraud logs:

Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 9:18:29 PM, on 1/9/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messen... Read more

Answer:HijackThis/SmitFraud logs - Awola!

Please see the new post below... the above scan was old...
 

2 more replies
Relevance 43.46%

Here's my logfile. Is this the right thing to post?



Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 8:38:27 PM, on 5/21/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal

Running processes:
C:\WINXP\System32\smss.exe
C:\WINXP\system32\winlogon.exe
C:\WINXP\system32\services.exe
C:\WINXP\system32\lsass.exe
C:\WINXP\system32\svchost.exe
C:\WINXP\System32\svchost.exe
C:\WINXP\system32\spoolsv.exe
C:\WINXP\system32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINXP\Explorer.EXE
C:\WINXP\StartupMonitor.exe
C:\Program Files\Antivirus\Clamwin\bin\ClamTray.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINXP\system32\RDSHOST.exe
C:\WINXP\system32\sessmgr.exe
C:\WINXP\system32\winlogon.exe
C:\WINXP\system32\logonui.exe
C:\WINXP\system32\rdpclip.exe
C:\WINXP\system32\wuauclt.exe
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\WINXP\system32\logon.scr
C:\Program Files\Antivirus\HijackThis\HiJackThis_v2.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://runonce.msn.com/?v=msgrv75
R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareBlock Class - {0A87E45F-537A-40B4-B812-E2544C21A09F} - C:\Program Files\Antivirus\SpyCatcher\SCAc... Read more

Answer:Awola fake anti-spyware

Ok.We need to download ComboFix.exe. This will give a better view to the files running and also hidden on your computer.
Please visit this webpage for download links, and instructions for running ComboFix

When the tool is finished, it will produce a report for you. Please copy and paste the "C:\ComboFix.txt" along with a new 'HijackThis' log so that we can continue to do any further cleaning that your system may require.

Caution: Never run and remove files with Combofix unless supervised by a qualified security analyst who is experienced in the use of Combofix. Mal use can cause serious computer problems

NOTE: Combofix prevents autorun of all CDs, floppies and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you - please let me know.

=======================================

Please download SDFix from here and save it to your desktop

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)

Please then reboot your computer in Safe Mode by doing the following :
Restart your computer
After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
Instead of Windows loading as normal, the Advanced Options Menu should appear;
Select the first option, to run Windows in Safe Mode, then press Enter.
Choose your usual account.

Open the extra... Read more

1 more replies
Relevance 43.46%

This morning I had a little yellow triangle with a black exclamation mark appear in my toolbar . Upon doing some investigation and updating Spybot S&D and running it in the safe mode as well as searching files and deleting them from my program files , control panel and other locations , after re-booting , the yellow triangle continues to reappear as well as I can hear my pop-up blocker blocking tons of attempts . I need help getting rid of this cursed thing .I have included my HJT log which I just ran about 5 minutes ago .Thanks in advance for help . I look forward to hearing from anyone who can assist .

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:51:01 AM, on 3/16/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Bellsouth\HelpCenter40b\bin\sprtcmd.exe
C:\Program Files\ATT Internet Tools\blslo... Read more

Answer:AWOLA VIRUS - HJT log file included

Hello biddle1,

Infection is showing here, so assuming you have not made too made changes since posting this log let's work from what shows here for now.
To keep them from interfering with the repairs, be sure to temporarily disable all antivirus/anti-spyware softwares while these steps are being completed. This can usually be done through right clicking the software's Taskbar icons, or accessing each software through Start - Programs.
To keep them from interfering with the repairs, be sure to temporarily disable all antivirus/anti-spyware softwares while these steps are being completed. This can usually be done through right clicking the software's Taskbar icons, or accessing each software through Start - Programs.
Download ComboFix.exe from here to your desktop

Then disconnect from net access. Once you have done that, click the downloaded ComboFix.exe file to run the repair.
When starting ComboFix will cause your computer's internal speakers to produce two beeps, and during the start process display two warnings. These are intended to discourage people who are not getting help in the forum from just experimenting with tools they do not understand. Just to inform you so you will understand that the procedures are expected, and okay.

ComboFix will also change the drive autoplay settings there as it's own added security measure. When we have completed all repairs here we will return the default Windows settings.
A caution - do not touch you... Read more

3 more replies
Relevance 43.05%

Hello, new to the forum, think this is great learning for a novice like me and appreciate the help if I could get it here.

I have the AWOLA virus/scarewware on my system. My virus scan picks it up as Generic FakeAlert.b

A warning is posted on my right hand lower toolbar that says "Windows has detected syware infection. It is recommended to use a special antispyware to prevent data loss etc.."

I went through the 5 steps posted here and created this log, I hope I didn't screw this up.

Deckard's System Scanner v20071014.68
Run by Jeff on 2008-01-12 22:18:17
Computer is in Normal Mode.
--------------------------------------------------------------------------------

-- System Restore --------------------------------------------------------------

Successfully created a Deckard's System Scanner Restore Point.


-- Last 5 Restore Point(s) --
70: 2008-01-13 05:18:26 UTC - RP1052 - Deckard's System Scanner Restore Point
69: 2008-01-12 03:19:33 UTC - RP1051 - Removed QuickTime
68: 2008-01-12 03:08:02 UTC - RP1050 - Software Distribution Service 3.0
67: 2008-01-12 02:51:28 UTC - RP1049 - Spybot-S&D Spyware removal
66: 2008-01-11 03:57:49 UTC - RP1048 - Spybot-S&D Spyware removal


-- First Restore Point --
1: 2007-10-16 05:41:31 UTC - RP983 - System Checkpoint


Backed up registry hives.
Performed disk cleanup.



-- HijackThis Clone ------------------------------------------------------------


Emulating logfile of Trend Mic... Read more

Answer:AWOLA scareware help needed, Log posted inside.

Bump, any help would be appreciated. thx

- Installed Java 6.4

19 more replies
Relevance 41.82%

I'm not exactly sure at what time it happened or what I was doing, but the "Awola Anti-spyware 6.0" program is installed on my computer and won't uninstall. A pop-up box is constantly at the bottom right-hand corner of the taskbar saying Your computer is infected! , recomending that I use the tool to prevent data loss.

Also - on another note - I'm unable to use any open-source internet browers (ie. Firefox, Opera, Bonjour...). When I attempt to use Firefox (for example) I'm given the message "Firefox can't establish a connection to the server at www.google.com." It won't open any site. I'm given a similar message when I try to any other browser other than IE. The browser suggests that if my computer or network is protected by a firewall or proxy, to make sure make sure that Firefox is permitted to access the Web. I don't think this is the problem - but I really can't be sure. I never did anything to change these settings - nor would I know where to go to do such a thing. I'm not sure if these two things are related as the internet problem happened a good 2 months after the Awola problem started.

I really appreciate any help. From viewing other members' responses, your help seems very effective.

Thanks!

Deckard's System Scanner v20071014.68
Run by Frankie on 2008-02-22 23:17:18
Computer is in Normal Mode.
--------------------------------------------------------------------------------

-- System Restore -------------------------... Read more

Answer:Awola Virus :( .... May also be messing with my open-source internet browsers

One more thing I forgot to mention! --- On step 4 of what to do before posting a log - Updating the Operating System - I was unable to update Is there anything I can to do fix this?

Thanks so much!

13 more replies
Relevance 41.82%

the computer wont start properly in normal mode most of the time. the hard drive just constantly goes crazy and nothing will load windows explorer freezes. after multiple boots and leaving it on overnight it seems to settle down and run ok, all security programs, commodo, avast, SAS claim to need updating and windows also says this. however upon restart the above problems start again.

SAS and MAB were ran in safe mode. managed to run combofix and MGtools in normal mode. please help, thanks.
 

Answer:infected computer 64bit. logs attached. system file infected

* Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
If it is not on your Desktop, the below will not work.
* Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
* If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
* Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):

Code:

KILLALL::

File::
C:\Users\Francis\AppData\Local\4w1twtdbd4me
C:\Users\Francis\AppData\Roaming\Microsoft\Windows\Templates\4w1twtdbd4me
C:\ProgramData\4w1twtdbd4me

FCopy::
C:\Windows\ERDNT\cache86\svchost.exe | c:\windows\SysWow64\svchost.exe
* Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
* At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
* You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
If it asks you to overide the previous file with the same name, click YES.
* Now use your mouse to drag CFscript.txt on top of ComboFix.exe

* Follow the prompts.
* When it finishes, a log will be produced named c:\combofix.txt
* I will ask for this log below

Note:

Do not mouseclick combofix's window while it is running. That ... Read more

5 more replies
Relevance 41.41%

So at first I had the "Internet Security 2010" bug, but I think I fixed that with rkill. But now I got the green desktop with the "system is infected" message. I have heard of people who have this problem trying to restart only to find their system totally screwed, so I'm scared to turn off/restart. I have run DDS and Root Repeal. I know its Christmas, but please help!!!
DDS (Ver_09-12-01.01) - NTFSx86
Run by Michael at 3:25:14.42 on Fri 12/25/2009
Internet Explorer: 6.0.2900.5512
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.511.44 [GMT -5:00]

AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

============== Running Processes ===============

C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\eHome... Read more

Answer:Infected, Big Time... Green Desktop with "Your System is Infected" Message

Visit below website. Understand on how to use ComboFix >> download and run the program >> post the log here http://www.bleepingcomputer.com/combofix/how-to-use-combofix

9 more replies
Relevance 39.77%

Two days ago, I received an email that appeared to be from a known relative, opened it, then realized it was not sent to me by anyone I know, but attached to someone else's contact list and sent as a "spoof" email? (from what I've read). I checked the properties, made a copy, posted below, and deleted it. Did not click on any of the links. From what I've managed to gather, after entering keywords from the email into various sites, I found quite a few matches to this problem, however, I am getting mixed signals on probable affect on my system or best way to check. A copy of the properties are posted below. Have run several scans, but get no real "alerts" regarding my system. I ran the scans in safe mode and normal mode. Was referred to Hijack This to run a summary. Have pasted my log. My system is running slower than normal and when I log onto the internet, or just into my email account, the screen comes up, quickly flashes off, then comes up again. After this point it seems to run fairly normal, but slow. I am aware that I have limited "unused" space on my system and before backing up, and sending photos to online sites for storage, I want to ensure, with your help, whether or not an obvious problem is shown on the log. I am below the "amateur" level of this type of process so please have patience and let me know if you see anything that I should remove. Thanks so much! THE EMAIL PROPERTIES=============================... Read more

Answer:Received a "spoof?" email, system running extremely slow, not sure if system infected, need an expert

Hello and welcome to Bleeping ComputerWe apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help.If you have since resolved the original problem you were having, we would appreciate you letting us know. If not please perform the following steps below so we can have a look at the current condition of your machine. If you have not done so, include a clear description of the problems you're having, along with any steps you may have performed so far.Upon completing the steps below another staff member will review and take the steps necessary with you to get your machine back in working order clean and free of malware.If you have already posted a DDS log, please do so again, as your situation may have changed.Use the 'Add Reply' and add the new log to this thread.Thanks and again sorry for the delay.We need to see some information about what is happening in your machine. Please perform the following scan:Download DDS by sUBs from one of the following links. Save it to your desktop.DDS.comDDS.scrDDS.pifDouble click on the DDS icon, allow it to run.A small box will open, with an explaination about the tool. No input is needed, the scan is running.Notepad will open with the results.Follow the instructio... Read more

2 more replies
Relevance 39.77%

HiI thought PC Tools was suppose to find and eliminate these kind of threats,but it does not i am usingAVG 8 FreePlease help me find and fix this problem manually...When I click on "My Computer" and any other folder this thing pop up twice. "System Error!Your computer was infected by unknown Trojan.It's dangerous for your system (critical files can be lost)!Click OK to download the antispyware program to clean your system! (Recommended)" then it open my internetto:http://spywareadvancedscanner.com/2008/3/_freescan.php?aid=880202Or Click on Cancel which does not cancel but also open my internet to:http://spywareadvancedscanner.com/2008/3/_freescan.php?aid=880202How do I remove it?MY hijack this Log:Logfile of Trend Micro HijackThis v2.0.2Scan saved at 10:08:02 AM, on 7/11/2008Platform: Windows XP SP3 (WinNT 5.01.2600)MSIE: Internet Explorer v7.00 (7.00.6000.20815)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\Program Files\Lavasoft\Ad-Aware\aawservice.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\system32\spoolsv.exeC:\WINDOWS\system32\igfxtray.exeC:\WINDOWS\system32\hkcmd.exeC:\WINDOWS\system32\igfxpers.ex... Read more

Answer::angry: "system Error! Your Computer Was Infected By Unknown Trojan. It's Dangerous For Your System (critical Files...

Hi and welcome to Bleeping Computer! My name is Sam and I will be helping you. Please download Deckard's System Scanner (DSS) and save to your Desktop.alternate download siteDSS will do the following:Create a new System Restore point in Windows XP and Vista.Clean your Temporary Files, Downloaded Program Files, Internet Cache Files, and empty the Recycle Bin on all drives.Check some important areas of your system and produce a report for an analyst to review.Automatically run HijackThis. It will also install and place a shortcut to HijackThis on your desktop if you do not already have it installed. So if HijackThis is not installed and DSS prompts you to download it, please answer yes.You must be logged onto an account with administrator privileges when using.Close all applications and windows.Double-click on dss.exe to run it and follow the prompts.If your anti-virus or firewall complains, please allow this script to run as it is not
malicious.When the scan is complete, two text files will open in Notepad:main.txt <- this one will be maximizedextra.txt <- this one will be minimizedIf not, they both can be found in the C:\Deckard\System Scanner folder.Please copy (Ctrl+C) and paste (Ctrl+V) the contents of main.txt and extra.txt in your next reply.-- When running DSS, some firewalls may warn that it is trying to access the Internet especially if your asked to download the most current version of HijackThis. Please ensure that you allow it permission to do ... Read more

2 more replies
Relevance 39.77%

"System has been stopped due to a serious malfunction. Spyware activity has been detected." This is in red on a black square in the middle of the desktop, which is now Green.

It also brings up windows reference to Data Execution Provention "(DEP) helps prevent damage and other security treats . . ."

Another warning says "Attention! System detected a potential hazard (TrojanSPM/LX) on your computer . . ."

In late December my Google links started to be redirected, now this has happened. I hadn't used the computer in January so I could find some time to look into it.

I tried to run Ad-Aware, but it immediately crashed (never happened before), although I seem to be able to open some applications (like Excel) and Firefox still seems to be working.

Thank you for any assistance and/or direction you may be able to provide.

~scott
 

More replies
Relevance 39.36%

I got infected with one of the fake "System Alert!" icons that keeps popping a message up every few minutes. I've run Ad-Aware, Spybot, and McAfee Anti-Virus multiple times both in regular Windows mode and in Safe Mode. I've also run the McAfee Stinger application. None of these have solved the problem. Here's my HT log, thanks for any help!!Logfile of Trend Micro HijackThis v2.0.2Scan saved at 5:54:14 PM, on 2/19/2008Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 (6.00.2900.2180)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\svchost.exeC:\Program Files\Intel\Wireless\Bin\EvtEng.exeC:\Program Files\Intel\Wireless\Bin\S24EvMon.exeC:\Program Files\Intel\Wireless\Bin\WLKeeper.exeC:\Program Files\Common Files\Symantec Shared\ccSetMgr.exeC:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exeC:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\ehome\ehtray.exeC:\WINDOWS\system32\rundll32.exeC:\Program Files\Intel\Wireles... Read more

Answer:Infected With "system Alert!" In System Icon Tray

Hello Donnie M.,Welcome to Bleeping Computer Please download SmitfraudFix (by S!Ri)Extract the content (a folder named SmitfraudFix) to your Desktop.Open the SmitfraudFix folder and double-click smitfraudfix.cmdSelect option #1 - Search by typing 1 and press "Enter"; a text file will appear, which lists infected files (if present).Please copy/paste the content of that report into your next reply.Thanks,tea

14 more replies
Relevance 39.36%

A few days ago I believe I was infected with "system security" virus. System crashes, anti-virus software would not run, MBAM would not run. Multiple pop-up screens. Eventually was able to run computer in safe mode and ran MBAM. This improved computer but I am concerned that I was unprotected for some time and may have gotten another infection. Anyway browsers are being redirected, frequent crashes with blue screen that flashes by and system restarts. I ran MBAM, Super anti-spyware, spybot, adaware. They would find little or nothing, though today MBAM found 50 or so infected files which were just removed. so i think computer may be getting reinfected. Also another computer on my home network just appeared to get infected, so i turned it off. For what it is worth I noticed a program called "podmena" in my windows firewall exceptions and belive that maybe a virus so I unchecked it (though did not delete). I feel like L am getting reimfrcted. anyway the other forum told me to post my HJT/DDS logs. Topic referenced is here: http://www.bleepingcomputer.com/forums/t/235033/browser-hijacked-after-system-security-virus/ ~ OB so here they are. any help would be appreciated.DDS LOG:DDS (Ver_09-05-14.01) - NTFSx86 Run by steve at 19:35:33.12 on Thu 06/25/2009Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_14Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.510.151 [GMT -5:00]AV: Symantec AntiVirus Corporate Edition *On-access scanning enabled* (Update... Read more

Answer:System infected after system security virus and possibly others

Hello and welcome to Bleeping ComputerWe apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.If you have since resolved the original problem you were having, we would appreciate you letting us know. If not please perform the following steps below so we can have a look at the current condition of your machine. If you have not done so, include a clear description of the problems you're having, along with any steps you may have performed so far.Upon completing the steps below another staff member will review and take the steps necessary with you to get your machine back in working order clean and free of malware.If you have already posted a DDS log, please do so again, as your situation may have changed.Use the 'Add Reply' and add the new log to this thread.Thanks and again sorry for the delay.We need to see some information about what is happening in your machine. Please perform the following scan:Download DDS by sUBs from one of the following links. Save it to your desktop.DDS.scrDDS.pifDouble click on the DDS icon, allow it to run.A small box will open, with an explaination about the tool. No input is needed, the scan is running.Notepad will open with the results.Foll... Read more

22 more replies
Relevance 38.95%

I have a badly infected computer that I would like to make a copy of the whole system to mail to one of the av/am vendors. I think it has some new variants on it.
 
Can the drive it self become infected so that I may not be able to trust that anything else I create with this drive will not be also infected?
 
While this drive is not really exspensive I do not really have the finances to casually replace it.

Answer:Can a USB Cd/rom be infected plugging into a infected system

Hello dannyboy950:
 
If your computer is badly infected, then backing up the system will just copy the infections to any backup DVDs, which you obviously know.  I don't think you need to worry too much about your external DVD drive being infected, per se.  That would only happen if one or more of the infections could compromise the DVD firmware or the USB driver(s).
 
You should be aware though that many variants of viruses and malware will disable the Windows Volume Snapshot Service (VSS) which will prevent the creation of backups and system restore points.
 
My advice would be to follow the directions here and submit an Farbar Recovery and Scan Tool (FRST) log to the trained Bleeping Computer Malware Response Team members in the Virus/Trojan/Spyware and Malware Removal Logs Forum.
 
You should be aware that the anti-malware response community shares their information with other anti-malware/virus vendors and experts.  If you have been infected with zero-day malware and/or viruses, that information will be shared with those concerned,  Importantly, we need to restore your computer to full functionality, so I do recommend that you get it "disinfected" here.
 
I hope this is of some help.  Forum rules prohibit the posting of FRST logs in this particular Forum - they are only dealt with in the Forum I mentioned.  I am still in training, so I won't be able to assist you in the other Forum.
 
Have a great day.
 ... Read more

5 more replies
Relevance 38.54%

Hi,

I think I'm n the right section. Brand new Lenovo G570. Using Kaspersky Internet Security 2012 and I keep getting viruses. Restored to factory settings and I think the virus is still here. For Windows 7 update preference I chose to notify me before installing updates and let me choose which updates I want to install, computer keeps changing to update automatically @ 3am everyday. Desktop colors have change.

Each time I perform a full scan with Kaspersky and Malwarebytes, scan reports no viruses found. Internet explorer won't connect at all. I am using Safari as my default browser. The computer also randomly freezes.
Please help me.

Thanks.

Answer:System infected after removing trojan. System changes on its own.

A Clean Install may be the quickest & easiest way to go.

Clean Install Windows 7

5 more replies
Relevance 38.54%

When I turned on my Windows 7 laptop, I found that my background is gone and this notice was in place of it "YOUR SYSTEM IS INFECTED - System has been stopped due to a serious malfunction. Spyware activity has been detected. It is recommended to use spyware removal tool to prevent data loss. Do not use the computer before all spyware removed."Can anyone help me remove this spyware as soon as possible? Much appreciated.

Answer:YOUR SYSTEM IS INFECTED - System has been stopped due to a serious malfunction.

SUPERAntiSpyware Scan Loghttp://www.superantispyware.comGenerated 10/17/2010 at 08:57 PMApplication Version : 4.44.1000Core Rules Database Version : 5701Trace Rules Database Version: 3513Scan type       : Complete ScanTotal Scan Time : 01:11:47Memory items scanned      : 854Memory threats detected   : 0Registry items scanned    : 13616Registry threats detected : 0File items scanned        : 141362File threats detected     : 0

5 more replies
Relevance 38.54%

I am using XP2. I have installed Avg free 8.0 and do updates daily. 2 hours back some popups appeard frequently that tells 'your computer is infected'. It will show some online scanings and tell that there are several malwares in my computer. I tried to remove it by doing an online scan at http://www.bitdefender.com/scanner/online/free.html, but it failed. After some time the system automatically restarted. Then also so many popups came and after some time again restarted. (I am posting this before the system restarts). After restarting several popups were coming with showing a file scaning. After scaning it tell that my computer is infected. I can not open notepad, word or MS Outlook Express. In the start programs a new program named 'System Security 2009' is installed. (I am saving this)I tried to open 'Add & Remove' in control panel to remove this , but I couldn't. A popup in system tray says, 'Warning! Application can not be executed. The file rundll32.exe is infected. Please activate your anti-virus software!In system tray only clock is seen. No AVG or many other programs installed. When I clicked on the support icon of 'System Security 2009' in start, it leaded to www.supportnetcenter.com. A window is frequently appearing with address http://track.oainternetservices.com/doIn?id=503760&trackId=General&storeId=500014 and that page tells 'Forbidden'. Before shutting down, the blue desktop says, '... Read more

Answer:Help! My system is infected by 'System Security 2009'

Please follow the instructions from this link: http://www.computerhope.com/forum/index.php/topic,46313.0.htmlIf you have done those, it will be easier for a malware specialist to help you with your problem. 

11 more replies
Relevance 37.72%

Hello All,I placed this in the wrong forum last week, I home someone can help me.I seem to have a few problems on my PC, no Pop-ups but something has Hi-jacked both my active-desktop and IE 6. IE 6 is un-useable. I also have Awola Anti-spyware message in near the clock. Another that came up today which says it is Window's Security Center says you have been infected with Spyware.My active desktop has been hi-jacked again, it keeps bringing up a default.htm in the on my desktop. (what I have done for this is created a default.htm with a picture in it. So when the process calls up this default.htm it is something I want to look at.) Will explain more if it makes a difference.I also have a LoadLibrary Manager error???? It wants me to send an error report.Here are the steps that I have taken:1. Cleaned out Temporary internet files in IE6 and Cleared private data in Firefox.2. Ran Ad-Aware SE (Crashed several times)3. Ran Spy-Bot Search and Destroy selected all and clicked Fix and repair4. Rebooted and tried running Ad-Aware SE again and it crashed.5. Ran Spy-bot again and downloaded Ad-Aware SE and installed fresh copy.6. Rebooted and ran Ad-Aware SE selected all and quarantined.6. Reboot and ran Ad-Aware SE again. quarantined again.7. Ran Norton Anti-Virus cleaned everything.8. Ran House Call Anti-virus tried to clean.9. Attempted to run Panda and Bit defender to no avail, since IE has been hi-jacked.10. Ran McAfee AVERT Stinger. (really can't tell if it is cleaning anything sinc... Read more

Answer:Spyware That Has Taken Over My Active Desktop And Awola Anti-spyware

Hi,Your system is terribly infected. Problem with these infections nowadays is, it causes a lot of damage. Even if we clean the malware off your system, I can't guarantee that your system will be clean afterwards, because these infections/bundles leave a lot of leftovers behind that most scanners won't even recognise and logs won't show.Also, I can't promise you we can repair all the damage it caused... Even after cleaning the malware, you can still get errors afterwards because of the damage. Solving these is not always possible since it will be searching for a needle in a haystack to find the right cause and solution.So, we can try to clean this up and do what we can, but keep in mind that we can't solve ALL problems this malware already caused.In light of this it would be wise for you to back up any files and folders that you don't want to lose before we start. Reason I am telling this is because when a system is so terribly infected and we try to clean this up manually, the damage that is already present may interfere with our removal attempts. Before you proceed with the following steps, please do this first..Go to this page.Enter the url of this thread in the first field.Where it says, browse to the file that you want to submit, click the browse button next to it and browse to next file:C:\WINDOWS\system32\GE.dllSelect it and click ok:Then click the Send File button below.Then AFTER you did before...* Start HijackThis, close all open windows leaving only ... Read more

6 more replies
Relevance 37.31%

Hello, I have a laptop computer that is acting very funny! I have a Toshiba Satellite 9250 Windows XP Home, 60 GB Hard Drive 1.60 Ghz., 1.87 GB RAM computer, and there are severa problems with it. I keep getting a popup or Internet Security 2010 that keeps coming up and won't go away. On my desktop I have a picture that says "Your system is infected" and I can't get rid of it. Whenever I try to open task manager it says "Task Manager has been disabled by your administrator". I have done a HJT log, and will paste it below: I greatly appreciate ANY help you can give! Thanks!

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:05:19 PM, on 10-Feb-10
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\brsvc01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\acs.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\WINDOWS\system32\brss01a.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C... Read more

Answer:System Warning-Your System is Infected

14 more replies
Relevance 37.31%

Alright - I'm looking for big help! I really appreciate forums like these - I'm part of a forum myself, but we provide a very different service! SO thank you in advance!

So here's the breakdown. These are the various problems I've encountered within the last hour of the infection hitting.

It started with the blue background, with red on black writing saying YOUR SYSTEM IS INFECTED" and then Antivirus System PRO (which I understand to be a form of malaware) started popping up all over the place. I have no Task Manager (no Ctrl Alt Delete), and no keyboard. I even copy-pasted taskmgr.exe into the Run command and it is fully disabled.

I tried to restart in Safe-mode, and that was a no go - it simply couldn't start and asked me to chose from the Startup options again (Safe Mode, Safe Mode with Command Prompt ect ect ect). I also tried system restore, but surprise surprise that's not working either. Now I'm getting porn pop-ups as well.

Where the hell do I start killing this thing off?!?!?

Thanks in advance again,

Answer:"Your System is Infected" + Antivirus System Pro

hello bormac1lets have a look with this program http://www.malwarebytes.org/mbam.phpIf you have a previous version of MBAM, remove it via Add/Remove Programs and download a fresh copy. * Make sure you are connected to the Internet. * Double-click on mbam-setup.exe to install the application. * When the installation begins, follow the prompts and do not make any changes to default settings. * When installation has finished, make sure you leave both of these checked: o Update Malwarebytes' Anti-Malware o Launch Malwarebytes' Anti-Malware * Then click Finish.MBAM will automatically start and you will be asked to update the program before performing a scan. * If an update is found, the program will automatically update itself. * Press the OK button to close that box and continue. * If you encounter any problems while downloading the updates, manually download them from here and just double-click on mbam-rules.exe to install. Alternatively, you can update through MBAM's interface from a clean computer, copy the definitions (rules.ref) located in C:\Documents and Settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware from that system to a usb stick or CD and then copy it to the infected machine.On the Scanner tab: * Make sure the "Perform Quick Scan" option is selected. * Then click on the Scan button. * If asked to select the drives to scan, leave all the driv... Read more

5 more replies
Relevance 37.31%

I don't know how it happened, but this morning I found my laptop system infected with the PC System Security virus.

I first tried to run hitmanpro, but this didn't resolve the issue. Now hitmanpro will not start any longer.

I have downloaded all recommended removal tools, but cannot install any of them.

Furthermore, I cannot start Add/Remove programs or the System Administration to check for hidden plug and play drivers. Notepad won't start.

Can my system still be fixed, or is a reinstallation the best option?

Can you tell me what steps need to be taken?

Kind regards,

Duncan
 

Answer:System infected with System Security

snurbnacnud said:





I have downloaded all recommended removal tools, but cannot install any of them.Click to expand...

ComboFix requires no installation....are you saying you downloaded it to your desktop but nothing happens when you double click it?

MGTools also requires no installation....just copied to the C:\ drive ( assuming this is your root drive)...what happens when you double click it?

Have you tried doing any of the procedures in safe mode?
 

7 more replies
Relevance 37.31%

Hello there and thank you in advance for your help. I read the "new post" topic but, because of the state of my computer, I can't run DDS; I'm no longer able to login, even in safe mode. I did manage to run HijackThis in standard more before I could no longer login. So I'm posting that log instead of the DDS log. My apologies for that.The infected system has been showing random pop-ups, both pop-up browser windows and alerts from the system tray, both prompting me to download some AV software to remove the threat. I also found some new icons on my desktop pointing to some pr0n sites. Now, as soon as I login, I get a flash of the desktop and then am logged out back to the login screen. This is on Windows XP Home.Here's the HijackThis log file and again, thank you for any help.Logfile of Trend Micro HijackThis v2.0.2Scan saved at 9:05:38 PM, on 1/6/2009Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\Explorer.EXEC:\Program Files\Common Files\Symantec Shared\ccSvcHst.exeC:\Program Files\Common Files\Symantec Shared�... Read more

Answer:"System is infected" pop-ups from system tray

Hello kj123 Welcome to the BC HijackThis Log and Analysis forum. I ask that you refrain from running tools other than those we suggest to you while we are cleaning up your computer. The reason for this is so we know what is going on with the machine at any time. Some programs can interfere with others and hamper the recovery process.In the upper right hand corner of the topic you will see a button called Options. If you click on this in the drop-down menu you can choose Track this topic. By doing this and then choosing Immediate E-Mail notification and then clicking on Proceed you will be advised when we respond the your topic and facilitate the cleaning of your machine.After 5 days if a topic is not replied to we assume it has been abandoned and it is closed. I will need for you to reply to this post to confirm you still are seeking help.I also need to know if you have either a flash drive or CD that we can transfer programs with?Thanks,thewall

14 more replies
Relevance 37.31%

I am unable to run the System Restore program even though I can see many restore points. Error that comes up relates to "A Volume Shadow  Copy Service component encountered an unexpected error. Check the application event log for more information (0x80042302)". I logged on to safe mode with internet access and ran several anti virus programs, Spybot, Malawarebytes, Superantispyware. However, the virus had shut down any acces to the internet, sound and many other functions. I was able to get the internet access restored but I'm concerned since I still can't run a system restore.
I attached the requested files but I don't see them attached to this post.
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 11.0.9600.17420  BrowserJavaVersion: 10.55.2
Run by Dave at 13:22:48 on 2014-12-09
Microsoft Windows 7 Ultimate   6.1.7601.1.1252.1.1033.18.8190.4712 [GMT -5:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {4F35CFC4-45A3-FC37-EF17-759A02E39AB1}
AV: avast! Antivirus *Enabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
SP: Microsoft Security Essentials *Enabled/Updated* {F4542E20-6399-F3B9-D5A7-4EE87964D00C}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Spybot - Search and Destroy *Disabled/Updated* {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
SP: avast! Antivirus *Enabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
FW: avast! Antivirus *Enabled* {2F96FC65-F07D-9D1E-5A6E-3DA5C487EAF0}
.
============== Runni... Read more

Answer:Infected system-cannot do a system restore

Finally was able to run Microsoft Defender software and it found "Trojan:win32/Powessere.A!reg" on the system. Defender removed the virus but am still unable to run the System Restore. I am still able to see many restore points but the error message is still the same.

3 more replies
Relevance 37.31%

as the story goes...son was "exploring" the internet and was said a security pop-up told him to scan...which he did. Then, he was shown the results of the scan telling him that the system was infected and a security download would need to be purchased to purge. Thinking that shutting down the computer would erase his tracks and he could then deny, deny, deny.

I tried to repair by running the AT&T provided Macfee virus protection...but halfway through the repair the program quit. I then tried a "system restore" to a week before the infection. Experienced same results and the restore quit. The infection changed my desktop background to a blue screen with a black box in the center which has typed in Red Letters "YOUR SYSTEM IS INFECTED!" and in white letters: " System has been stopped due to a serious malfunction. Spyware activity has been detected. It is recommeded to use spyware removal tool to prevent data loss. Do not use the computer before all spyware removed." I went to display options on the control panel and cannot select a different background other than the "critical_warning" that is currently displayed.

The computer has not been used for several months...purchased new replacement on credit, but I need data and would like to use the infected computer as a homework/storage/game computer. So I very recently purchased iolo's System Mechanic v9. Installed the program and ran the scan. Program stopp... Read more

Answer:"your system is infected" "system has been stopped"

I just heard back from iolo. They told me to start my system in safe mode. "Once in Safe Mode with Networking, please attempt to operate our software as normal."

I'll wait for you're advise as to weather this will do the trick or not.

thanks,

-poppa_C

71 more replies
Relevance 37.31%

Hello I've joined this forum looking for some help.

Before I found this forum, I initially went to the search bar in start menu to find mbam.exe since all the files were hidden, ran Malwarebytes once(full scan) and the system messages were gone.
However, after I've restarted the computer with the completion of the scan, the S.M.A.R.T program seems to still exist.
After I've found this forum and read a few other similar topics, I've downloaded unhide.exe and ran it, the icons on my desktop and in the start menu were back.
I've ran Malwarebytes again and it returned no infection but it seems my computer is still infected. I have no idea on what to do right now, if someone can help me here it will be greatly appreciated.

Answer:system infected: S.M.A.R.T and system messages

Hello, I moved this over to Am I Infected for now.Run RKill....Download and Run RKillPlease download RKill by Grinler from one of the 4 links below and save it to your desktop.

Link 1
Link 2
Link 3
Link 4

Before we begin, you should disable your anti-malware softwares you have installed so they do not interfere RKill running as some anti-malware softwares detect RKill as malicious. Please refer to this page if you are not sure how.
Double-click on Rkill on your desktop to run it. (If you are using Windows Vista, please right-click on it and select Run As Administrator)
A black screen will appear and then disappear. Please do not worry, that is normal. This means that the tool has been successfully executed.
If nothing happens or if the tool does not run, please let me know in your next replyDo not reboot your computer after running rkill as the malware programs will start again. Or if rebooting is required run it again.If you continue having problems running rkill.com, you can download iExplore.exe or eXplorer.exe, which are renamed copies of rkill.com, and try them instead.>>>>Please download TDSSKiller.zip and and extract it.Run TDSSKiller.exe. Click on Change Parameters Put a check in the box of Detect TDLFS file system Click Start scan.When it is finished the utility outputs a list of detected objects with description.
The utility automatically selects an action (Cure or Delete) for malicious objects.
The utility prompts the user to sel... Read more

1 more replies
Relevance 35.26%

Yesterday one of our employees got infected with the System Fix virus (I think from a email PDF attachment). I have read thru the "Remove System Fix (Uninstall Guide)" on here and the RKill process is always terminated. In the DOS window the RKill program says:
Preparing Rkill.
Terminating known malware process.
Please be patient.
Access is denied.
Then the log window opens and the dos window closes. I have ran this many times with the same result.

Thank you in advance for your help,
John

DDS.txt log file:
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.6001.18702
Run by abiller at 11:35:50 on 2011-12-02
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2014.1453 [GMT -8:00]
.
AV: Trend Micro Security Agent *Disabled/Updated* {7D2296BC-32CC-4519-917E-52E652474AF5}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
C:\WINDOWS\System32\svchost.exe -k eapsvcs
svchost.exe
C:\WINDOWS\System32\svchost.exe -k dot3svc
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Trend Micro\UniClient\UiFrmWrk\uiWatchDog.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Prog... Read more

Answer:Infected with System Fix

Hello and Welcome to the forums! My name is Gringo and I'll be glad to help you with your computer problems. Somethings to remember while we are working together.Do not run any other tool untill instructed to do so!please Do not Attach logs or put in code boxes.Tell me about any problems that have occurred during the fix.Tell me of any other symptoms you may be having as these can help also.Do not run anything while running a fix.Do not run any other tool untill instructed to do so!Click on the Watch Topic Button and select Immediate Notification and click on proceed, this will help you to get notified faster when I have replied and make the cleaning process faster.Please print out or make a copy in notpad of any instructions given, as sometimes it is necessary to go offline and you will lose access to them.Run Combofix:You may be asked to install or update the Recovery Console (Win XP Only) if this happens please allow it to do so (you will need to be connected to the internet for this)Before you run Combofix I will need you to turn off any security software you have running, If you do not know how to do this you can find out >here< or >here<Combofix may need to reboot your computer more than once to do its job this is normal.You can download Combofix from one of these links.Link 1Link 2Link 3 1. Close any open browsers or any other programs that are open.2. Close/disable all anti virus and anti malware programs so they do not interfere with the r... Read more

19 more replies
Relevance 35.26%

Hi,I've started with the Prep Guide Before Removing Malware and Requesting Help but I'm having trouble completing all the steps.Here are the the popups and windows I see that swamp my screen:System Fix/Scan PC for errors window superimposes itself and can't be minimized so I hide it in the corner.Warning windows pop up that say:"Windows-delayed Write Failed. Failed to wave all the components for the file "sys32"00004f25.File corruptible or unreadable. This error may be caused by a PC hard drive prob."Warnings from my tray flash up frequently saying:"RAM memory reliability is extremely low. Prob. may cause system failure" "Hard Drive Critical error. Start sys diagnostic app to scan hardrive""Windows OS can't detect a free hard drive space. Hard drive error""Hard Drive clusters error.."A history of what's happened with the computer since infection:When all the popups first showed up I'm pretty sure that it reduced my once swollen desktop to about a quarter of it's original icons. I don't recall what panicked, feeble efforts I made to figure out what was going on but at some point the computer restarted and my desktop went from sparse to completely blank (black without my desktop image) and my start button only showed the Toshiba Direct Store link and everything else was empty.I tried to open my control panel with CTL+C and that wouldn't work nor would CTL+ALT+DEL do anything. ... Read more

Answer:Infected with System Fix

Hello and welcome to Bleeping Computer! I am HelpBot: an automated program designed to help the Bleeping Computer Staff better assist you! This message contains very important information, so please read through all of it before doing anything. We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here. To help Bleeping Computer better assist you please perform the following steps:*************************************************** In order to continue receiving help at BleepingComputer.com, YOU MUST tell me if you still need help or if your issue has already been resolved on your own or through another resource! To tell me this, please click on the following link and follow the instructions there.CLICK THIS LINK >>> http://www.bleepingcomputer.com/logreply/430251 <<< CLICK THIS LINK If you no longer need help, then all you needed to do was the previous instructions of telling me so. You can skip the rest of this post. If you do need help please continue with Step 2 below.*************************************************** If you still need help, I would like you to post a Reply to this topic (click the "Add Reply" button in the lo... Read more

3 more replies
Relevance 35.26%

I am infected with System Fix, I can stop it with RKILL, and i have unhidden all of my files, but nothing is recognizing it and removing it. I have tried Malwarebytes anti-malware, sybot, and McAfee. The System fix icon is still on my desktop, and it starts everytime i start the computer, i have to kill it every time with RKILL.

.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.6001.18702
Run by kondert at 20:19:42 on 2011-12-05
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.502.93 [GMT -6:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
AV: *Disabled/Updated* {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: *Disabled*
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
svchost.exe
C:\Program Files\Google\Google Desktop Search\Google... Read more

Answer:Infected with System fix

Hello and welcome to Bleeping Computer! I am HelpBot: an automated program designed to help the Bleeping Computer Staff better assist you! This message contains very important information, so please read through all of it before doing anything. We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here. To help Bleeping Computer better assist you please perform the following steps:*************************************************** In order to continue receiving help at BleepingComputer.com, YOU MUST tell me if you still need help or if your issue has already been resolved on your own or through another resource! To tell me this, please click on the following link and follow the instructions there.CLICK THIS LINK >>> http://www.bleepingcomputer.com/logreply/431006 <<< CLICK THIS LINK If you no longer need help, then all you needed to do was the previous instructions of telling me so. You can skip the rest of this post. If you do need help please continue with Step 2 below.*************************************************** If you still need help, I would like you to post a Reply to this topic (click the "Add Reply" button in the lo... Read more

3 more replies
Relevance 35.26%

When i turned on the computer, a screen shows up on my desktop saying "YOUR SYSTEM IS INFECTED! System has been stopped due to a serious malfunction.  Spyware activity has been detected.  It is recommended to use spyware removal tool to prevent...".  I ran AVG, malware, etc... and nothing works.  Should I reformat the hard drive and start all over with Windows XP?  Any help would be greatly appreciated?Thanks,pjchi704

Answer:YOUR SYSTEM IS INFECTED!

Please follow the instructions in the following link and post your logs: http://www.computerhope.com/forum/index.php/topic,46313.0.html

2 more replies
Relevance 35.26%

Hi,

I have XP professional with Service Pack 2 Installed. And from 5-6 months since i have installed my windows....the Windows Firewall that comes with SP2 is always on and I am using NOD32 anti-virus system which is always upto-date.

I have been made sure on BleepingComputer's forum(official forums of the software HijackThis) that the log file of my system saved by HijackThis scan that was posted on there forum
shows nothing suspicious and its clean. As written in there steps , I scanned my pc with NOD32 latest anti-virus system, AVG Anti-spyware latest, BitDefender Online scanner, Spyware Doctor, HijackThis, Registry Mechanic and Nothing was found. Still my gutt feeling say that some data is logged and is been sent to a remote computer, (may be undetectable trojan).

And also I am NOT experiencing any type of problem with my system.

How shld i confirm this that my system is free of any spyware/virus/worm/trojan??

Thanx

Answer:HELP: Infected System

Post a log and I will take a look

6 more replies
Relevance 35.26%
Question: System Infected?

My PC was recently attacked by an unknown source. My Norton anti-virus said that certain system files were modified, so I'm leaning towards that being the cause. Specifically, my background is stuck on a black message with a colored background that reads like this:


Quote:




Your System is Infected

System has been stopped due to a serious malfunction
Spyware activity has been detected

It is recommended to use spyware removal tool to prevent data loss
Do not use the computer before all spyware removed




In addition to my background being stuck, I cannot use Task Manager and my speakers don't work. I've done several virus scans and am unable to pick anything up besides what I already mentioned and that it is a trojan.

Answer:System Infected?

Hi,

Download DDS and save it to your desktop from here or here or here.
Disable any script blocker, and then double click dds.scr to run the tool.When done, DDS will open two (2) logs: DDS.txt
Attach.txt

Save both reports to your desktop. Post them back to your topic.


Download GMER here by clicking download exe -button and then saving it your desktop:Double-click .exe that you downloaded
Click rootkit-tab and then scan.
Don't check
Show All
box while scanning in progress!
When scanning is ready, click Copy.
This copies log to clipboard
Post log in your reply.

2 more replies
Relevance 35.26%

My computer was recently infected with that nasty 'System Fix' scareware program and I've been able to restore computer functions and apparently remove it but I can tell it's still in here somewhere. Malwarebytes isn't catching any problems but I frequently get pop-ups from Internet Explorer saying 'a program has corrupted your default provider setting for Internet Explorer...etc'. I also sometimes get re-directs when using the internet but TDSSKiller will either A, not run despite renaming it or B, not detect anything if it runs. The final straw (kind of amusing in retrospect) was that Windows Media Player opened by itself and began playing Evangelical Sermons at about 12 am last night, which is a sign of a virus if I've ever seen one (I disconnected my internet and it stopped so it must have been streaming from somewhere).

I've tried to get rid of this but clearly it is too stubborn for me to handle. I've attached logs and any help would be very appreciated, thanks!

Answer:Infected with 'System Fix' and it will not die!

Hello and Welcome to the forums! My name is Gringo and I'll be glad to help you with your computer problems. Somethings to remember while we are working together.Do not run any other tool untill instructed to do so!Please Do not Attach logs or put in code boxes.Tell me about any problems that have occurred during the fix.Tell me of any other symptoms you may be having as these can help also.Do not run anything while running a fix.We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.Click on the Watch Topic Button and select Immediate Notification and click on proceed, this will help you to get notified faster when I have replied and make the cleaning process faster.In order for me to see the status of the infection I will need a new set of logs to start with.Please print out or make a copy in notpad of any instructions given, as sometimes it is necessary to go offline and you will lose access to them.DeFogger: Please download DeFogger to your desktop.

Double click DeFogger to run the tool.
The application window will appear Click the Disable button to disable your CD Emulation drivers Click Yes to continue A 'Finished!' message will ap... Read more

22 more replies
Relevance 35.26%
Question: infected system

hi
when i install avira on it , avir try delete his file !!
that means i infected badly !
plz help


this is dds.txt

DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 7.0.6000.20583
Run by Dear-User at 17:40:44 on 2014-08-16
Microsoft Windows XP Professional 5.1.2600.3.1256.981.1033.18.1938.868 [GMT 4.5:30]
.
AV: Avira Desktop *Enabled/Outdated* {AD166499-45F9-482A-A743-FDD3350758C7}
AV: Sheed AntiVirus *Enabled/Updated* {1B2C78D0-7F17-4587-8F75-554CCC260541}
.
============== Running Processes ================
.
C:\WINXPSP3\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\WINXPSP3\Explorer.EXE
C:\WINXPSP3\RTHDCPL.EXE
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe
C:\WINXPSP3\system32\ctfmon.exe
C:\Program Files\Internet Download Manager\IDMan.exe
C:\Program Files\Internet Download Manager\IEMonitor.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\Program Files\Sheed AntiVirus\shgrprot.exe
C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe
C:\WINXPSP3\system32\wbem\wmiprvse.exe
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
C:\WINXPSP3\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\ch... Read more

Answer:infected system

smohsen,

Hi and welcome to TSF.

I am currently reviewing your logs. Please note that this is under the supervision of an expert analyst, and I will be back with a fix for your problem as soon as possible.

Please Read! "Who is Helping you?"

You may wish to Subscribe to this Thread to get immediate notification of replies as soon as they are posted. To do this click Thread Tools (near the top), then click Subscribe to this Thread. Make sure it is set to Instant Notification by email, then click Add Subscription.

Please be patient with me during this time.

2 more replies
Relevance 35.26%

hi,
system got infected with a few virus that i ve been able to deal with but
a few remain virtumonde, dial_gif.e ,troj_renos.dl among others.
Could you take some time to take a look, would appre. merci

Answer:system infected, help please

hi again,
sorry, new to all this, opened a thread already whith same title but didn t include the log so here it is:
Logfile of HijackThis v1.99.1
Scan saved at 22:32:00, on 24/06/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\SPOOLSV.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\WINDOWS\SYSTEM32\DABSQCMK.EXE
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PCCTLCOM.EXE
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TMPROXY.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\TEMP\win37.tmp.exe
C:\WINDOWS\MGRS.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TMPFW.EXE
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\dllhost.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PccGuide.exe
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\Documents and Settings\dave\Local Settings\Temporary Internet Files\Content.IE5\LE7A6GY3\HijackThis[1].exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/... Read more

4 more replies
Relevance 35.26%

Hi, McAfee firewall is not working. I have malware bytes and system mechanic in my system and they are not finding any issues. I am facing issues while audio recordings and web browsing. My recent audio recordings missing some parts of it. My browser on my first click (some times) takes me to some other unwanted site.
I have searched the forum before I join the forum and launched the below registry files on my machine and they sounded like fixing the problem (only mcafee firewall) but with insallation of new security center version the problem returned to its original state.
windows firewall
base filtering engine
security center

Please help.
Thanks,
Atchutram

Answer:My system infected. What do I do?

Hello,I will be helping you with your problems. Please be patient while I assist you.Some points for you to keep in mind while I am helping you to make things go easier and faster for both of us Please do NOT run, install or uninstall any programs, unless instructed to do so.
We ask you to run different tools in a specific order to ensure the malware is completely removed from your machine, and running any additional tools may detect false positives, interfere with our tools, or cause unforeseen damage or system instability. Please do not attach logs or use code boxes, just copy and paste the text.
Due to the high volume of logs we receive it helps to receive everything in the same format, and code boxes make the logs very difficult to read. Also, attachments require us to download and open the reports when it is easier to just read the reports in your post. Please read every post completely before doing anything.
Pay special attention to the NOTE: lines, these entries identify an individual issue or important step in the cleanup process. Please provide feedback about your experience as we go.
A short statement describing how the computer is working helps us understand where to go next, for example: I am still getting redirected, the computer is running normally, etc. Please do not describe the computer as "the same", this requires the extra step of looking back at your previous post.NOTE: At the top of your post, click on the Watch Topic Butt... Read more

1 more replies
Relevance 35.26%

Hello. Recently our family computer has started behaving strangely. It will run ok after starting for a few minutes but if anybody tries to use the internet or after maybe 10 minutes it will get really slow. My 14yr old said he thinks it's a virus because some file named svchost.exe gets really high memory and cpu use like almost 70-100%. I let him try to fix it but I think he made it worse. Now when I go on the internet it sometimes makes a blank page open and the address is always something weird like recepies or for law etc. I finally decided to look on the internet for help and out of the places I saw your's looked the most professional. I read the instructions for getting help and did my best to follow them. I have the DDS\Attach\Gmer txt files if you need them. So I'm going to post them here now. I'm sorry if I did anything wrong I'm new at this.

This is the DDS file;

.
DDS (Ver_2011-06-12.02) - NTFSx86
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_20
Run by Lord Kain at 16:34:19 on 2011-06-22
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2046.1316 [GMT -4:00]
.
AV: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Firewall *Enabled*
.
============== Running Processes ===============
.
E:\WINDOWS\system32\Ati2evxx.exe
E:\WINDOWS\system32\svchost.exe -k DcomLaunch
svchost.exe
E:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
E:\WINDOWS\system32\Ati2evxx.exe
E:\WINDOWS\system32\spo... Read more

Answer:System is infected with something. Plz help.

Hello, Welcome to TSF.
I'm nasdaq and will be helping you.

You may wish to Subscribe to this thread (Thread Tools > Subscribe to this thread) so that you are notified when you receive a reply.

Please read these instructions carefully and then print out or copy this page to Notepad in order to assist you when carrying out the fix.

Note that the fix may take several posts. Please continue to respond to my instructions until I confirm that your logs are clean. Remember that although your symptoms may vanish, this does NOT mean that your system is clean.

If there is anything you don't understand, please ask BEFORE proceeding with the fixes.

Please ensure that you follow the instructions in the order I have them listed.

Please do not install or uninstall any programs, or run any other scanners or software, unless I specifically ask you to do so. Also please copy and paste logs into the thread, rather than add them as attachments.
===

Please Download
TDSSKiller.zip

>>> Double-click on TDSSKiller.exe to run the application.Click on the Start Scan button and wait for the scan and disinfection process to be over.
If an infected file is detected, the default action will be Cure, click on Continue

If a suspicious file is detected, the default action will be Skip, click on Continue

If you are asked to reboot the computer to complete the process, click on the Reboot Now button. A report will be automatically saved at the root of the Syste... Read more

15 more replies
Relevance 35.26%

So my background is now a big blue screen that tells me I have spyware that I need to get rid of. I ran Ad-Aware Plus AE and Spybot S&D (both normally and on startup) but the screen still won't go away.


DDS (Ver_09-06-26.01) - NTFSx86
Run by 11cummingsal at 17:42:46.17 on Wed 07/08/2009

============== Running Processes ===============


============== Pseudo HJT Report ===============

StartupFolder: c:\docume~1\11cumm~1\startm~1\programs\startup\impuls~1.lnk - c:\program files\stardock\impulse\now\ImpulseNow.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\audibl~1.lnk - c:\program files\audible\bin\AudibleDownloadHelper.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\paspor~1.lnk - c:\windows\installer\{fd50d88b-4eaf-4d58-9b49-9df99da2e8da}\NewShortcut1.exe

============= SERVICES / DRIVERS ===============


=============== Created Last 30 ================

2009-07-08 14:19 <DIR> --d----- c:\program files\Trend Micro
2009-07-08 11:28 0 a------- C:\KBOT.LOGON.LAUNCH
2009-07-07 20:38 15,688 a------- c:\windows\system32\lsdelete.exe
2009-07-07 17:09 64,160 a------- c:\windows\system32\drivers\Lbd.sys
2009-07-07 17:05 <DIR> -cd-h--- c:\docume~1\alluse~1\applic~1\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
2009-07-07 16:45 <DIR> --d----- c:\program files\Spybot - Search... Read more

Answer:Your System is Infected! joy

Hello, and Welcome to TSF.

Please subscribe to this thread to get immediate notification of replies as soon as they are posted. To do this click Thread Tools, then click Subscribe to this Thread. Make sure it is set to Instant Notification, then click Subscribe.

Before beginning the fix, read this post completely. If there's anything that you do not understand, kindly ask your questions before proceeding. Ensure that there aren't any opened browsers when you are carrying out the procedures below. Save the following instructions in Notepad as this webpage would not be available when you're carrying out the fix.

It is IMPORTANT that you don't miss a step & perform everything in the correct order/sequence.

---------------------------------------------------------------------------------------------

Please note that these fixes are not instantaneous. Most infections require more than one round to properly eradicate.

Stay with me until given the 'all clear' even if symptoms diminish. Lack of symptoms does not always mean the job is complete.

Kindly follow my instructions and please do no fixing on your own or running of scanners unless requested by me or another helper at this forum.

---------------------------------------------------------------------------------------------

Download ComboFix from this location:

Link 1

* IMPORTANT !!! Place combofix.exe on your Desktop
Disable your AntiVirus and AntiSpyware applications, usually via a ri... Read more

10 more replies
Relevance 35.26%

So Im running Windows Xp Pro.
My desktop has been changed to a blue one with a black box with red text that states YOUR SYSTEM IS INFECTED! blah blah blah blah... It wont let me change the desktop background, and now my internet doesn't work on that computer. In an avg scan it finds files, but they are still there when i restart:

\globalroot\systemroot\system32\gasfg....... .dll
C:\Windows\explorer.exe (200) <--- diff number every time i start computer

My computer refuses to let me go into safe mode. whenever i try via f8 it just restarts the computer and brings me to the "safe mode/las good config/etc." screen. When i tried setting it to autostart in safe mode it started BSODing...
Thanks for your help!

Answer:YOUR SYSTEM IS INFECTED!

When i tried setting it to autostart in safe mode it started BSODing.If you are referring to using MSConfig to access (force) safe mode, that is not advisable if you suspect malware on your system. Doing so could could have disastrous results and render your computer unbootable. The Safeboot option modifies the Boot.ini file by adding the /safeboot:minimal argument to your operating systems startup line. Some types of malware can delete or alter the safeboot key in the registry resulting in the inability to reboot fully into safe mode or back to normal mode. When this occurs, you may be locked in a continuous reboot loop afterwards where you cannot get back to MSConfig and undo your selection until the /safeboot argument is removed from the boot.ini. See "Booting into Safe Mode safely". Please download Malwarebytes Anti-Malware (v1.41) and save it to your desktop.alternate download link 1alternate download link 2MBAM may "make changes to your registry" as part of its disinfection routine. If using other security programs that detect registry changes (ie Spybot's Teatimer), they may interfere or alert you. Temporarily disable such programs or permit them to allow the changes.Make sure you are connected to the Internet.Double-click on mbam-setup.exe to install the application.When the installation begins, follow the prompts and do not make any changes to default settings.When installation has finished, make sure you leave both of these checked:Update Malwarebytes' Anti-MalwareL... Read more

16 more replies
Relevance 35.26%

Not sure what's going on.  I had Powelik!s on my other machine, that is now better, thanks to nasdaq, but I think I may have accidently infected my laptop by moving files via a thumb drive.  It is running Windows 7 and Norton 360.
 
Unfortunately, I used a thumb drive to move a document from my desktop machine to my this machine a couple weeks ago before I contacted you but after the desktop was infected.  Could I have infected my laptop?  It seems to be acting weird.  The other day it's IP address had been changed to 169.254.103.93 which is not in my network.  In addition, I could not seem to change it back.  I left it running that night and the IP has been changed back to where it should be. 
 
Norton keeps blocking hits from program files that are trying to change the Norton files.  This is a brief list of the log:
 
Category: Norton Product Tamper Protection
Date & Time,Risk,Activity,Status,Recommended Action,Date,Actor,Actor PID,Target,Target PID,Action,Reaction
11/23/2014 10:49:00 AM,Medium,Unauthorized access blocked (Access Process Data),Blocked,No Action Required,11/23/2014 10:49:00 AM,C:\WINDOWS\SYSTEM32\CONHOST.EXE,6676,C:\Program Files (x86)\Norton 360\Engine\21.6.0.32\cltlmh.exe,6352,Access Process Data,Unauthorized access blocked
11/22/2014 10:30:50 PM,Medium,Unauthorized access blocked (Open File),Blocked,No Action Required,11/22/2014 10:30:50 PM,C:\WINDOWS\SYSTEM32\SVCHOST... Read more

Answer:System may be infected

 
 
Also, I made a backup of it after it was infected.  What can/should I do with it?
I would not trust it. So when all is well I would delete it.
===
 
Norton is advising you of all the attemp by blocking it.
There is a setting in the Norton control to stop being advised.
===
 
Open notepad (Start =>All Programs => Accessories => Notepad). Please copy the entire contents of the code box below.

start
 
HKLM-x32\...\Run: [] => [X]
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre6\bin\jp2ssv.dll No File
Toolbar: HKU\S-1-5-21-778233862-3958696847-3620319111-1001 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin HKU\S-1-5-21-778233862-3958696847-3620319111-1001: @nds.com/PCShowPlugin -> C:\Users\Jean\AppData\Local\DIRECTV Player\npPCShowPlugin.dll No File
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\DigitalPersona\Bin\FirefoxExt
FF Extension: DigitalPersona Extension - C:\Program Files (x86)\DigitalPersona\Bin\FirefoxExt [2011-07-21]
CHR Plugin: (Shockwave Flash) - C:\Users\Jean\AppData\Local\Google\Chrome\Application\37.0.2062.120\gcswf32.dll No File
CHR Plugin: (Java™ Platform SE 6 U29) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.d... Read more

8 more replies
Relevance 35.26%
Question: Infected System

On a home network, can one infected computer spread that spyware/virus to others on that same network that share a common cable connection or is it limited to the one computer ?

Answer:Infected System

Depends on the sophistication of the worm.Edit: Edited to remove unnecessary quote. ~ tg

1 more replies
Relevance 35.26%

I had posted a question over the weekend about some infected systems that I had been given and had a difficult time 'cleaning' them. Well after using the 'PC Health Advisor' and 'Spyware Doctor' software to 'clean' them up and then feeling confident that they were fixed I returned them to my friend. This morning I get an email from the secretary saying that her pc had an error message pop up stating that Windows XP had to shut down because of a 'DELR1SVC.EXE' error. Now I had ran a sfc /scannow functiong to make sure that Windows' files were intact and did not have to replace any files. They had some business software installed that I could not run simply because I wasn't familiar with it. But I felt confident that the system was clean and performing as it should. Should I have performed a repair anyway? Help. All replies and opinions are greatly appreciated and respected. Loretta

Answer:System still infected?

Okay, after doing some research (sorry I didn't do that first before posting), it looks like a simple reinstall of the Dell 1600n printer driver. Still, any replies will be greatly appreciated. Loretta

2 more replies
Relevance 35.26%
Question: System Infected

Last Friday evening (10th October 2009), my computer was infected by Trojan viruses and Keyloggers. The keyloggers gained access to a gaming account and a forum account. I thought I had cleaned my system with Malwarebytes' Anti-Malware program (which removed 11 infections (Keyloggers/Trojans)). I changed all passwords after these infections were removed, believing that my system was clean, but the next day my gaming account was then re-hacked.I tried asking a few friends for help but none could offer any, and then I was advised to this website.Here are the logs:DDS (Ver_09-10-13.01) - NTFSx86Run by Heavyy at 16:31:17.75 on 17/10/2009Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_15Microsoft Windows XP Home Edition 5.1.2600.2.1252.44.1033.18.2495.1578 [GMT 1:00]AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}============== Running Processes ===============C:\WINDOWS\system32\nvsvc32.exeC:\WINDOWS\system32\svchost -k DcomLaunchsvchost.exeC:\WINDOWS\System32\svchost.exe -k netsvcsC:\WINDOWS\system32\svchost.exe -k WudfServiceGroupsvchost.exesvchost.exeC:\Program Files\Lavasoft\Ad-Aware\AAWService.exeC:\WINDOWS\system32\spoolsv.exesvchost.exeC:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exeC:\Program Files\Common Files\Autodesk Shared\Service�... Read more

Answer:System Infected

Hello and welcome to Bleeping ComputerWe apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.If you have since resolved the original problem you were having, we would appreciate you letting us know. If not please perform the following steps below so we can have a look at the current condition of your machine. Please include a clear description of the problems you're having, along with any steps you may have performed so far.Please refrain from running tools or applying updates other than those we suggest while we are cleaning up your computer. The reason for this is so we know what is going on with the machine at any time. Some programs can interfere with others and hamper the recovery process.Even if you have already provided information about your PC, we need a new log to see what has changed since you originally posted your problem.Please download OTL from following mirror:This is THE MirrorSave it to your desktop.Double click on the icon on your desktop.Click the "Scan All Users" checkbox.Push the button.Two reports will open, copy and paste them in a reply here:OTL.txt <-- Will be openedExtra.txt <-- Will be minimizedIn the upper right hand corner ... Read more

2 more replies
Relevance 35.26%

I believe I have a virus or other malware problem because my browser, Firefox, has begun to hang when it starts up and now also will redirect to other pages I have recently viewed without prompting, or will redirect to a Word document that is open on my system and so forth. My system is hanging and freezing, mostly when my browser is open but not always. . It runs very slow quite frequently and then suddenly is fine. Today I received an alert that my firewall was turned off and it took some time for me to turn it back on. My laptop system information is posted below. I have Avast free antivirus and also free Ad-Aware. I recently re-registered Ad-Aware and got a 30 day free trial of the Ad-Aware Pro Security which I am currently using.
I have tried to follow the instructions for posting a request for assistance. I was able to obtain a log file from Hijack This which I have posted below. I was not able to proceed with the second step. I downloaded and attempted to run the DDS.scr but it ran for over ten minutes without completing. I donít know if I have a script blocker that may have interfered. I will need help to locate and disable this feature. Finally, I have not proceeded to the third step because I do not know if I have a CD Emulation Program. I will also require help with this requirement.
I have been using a computer since 1994 but I have mostly been doing so in an office environment with full tech support. I am 70 years old but should be able to follow your instr... Read more

Answer:Need Help with Infected System

16 more replies
Relevance 35.26%

Black background Red writing Message says

system jas been stopped due to a serious malfunction.
Spyware activity has been detected. It is recommended
to use spyware removal tool to prevent data loss.
Do not use the computer before all spyware is removed.
what do I do I can't open up my online services to get to the
program to remove the problem I can't even use my mouse it is not even
detected nor is my modem.

what must I do...

Jan
 

Answer:Your System is infected

This "message" is from a nasty adware infection trying to get you to buy their product.

Its not a real Windows error message, but it does indicate that you perhaps are not running any adware or spyware programs that clean this up?

The infection is probably from a nasty called "spysherrif".

You need to download and run the full range of corrective programs and then run HiJackThis and post a log of the results back here.

The info for these is found on the security forum in this area.
http://forums.techguy.org/t376692.html
 

3 more replies
Relevance 35.26%

My desktop background has turned green with a black box that reads, "YOUR SYSTEM IS INFECTED! System has stopped due to a serious malfunction. Spyware activity has been detected. It is recommended to use spyware removal tool to prevent data loss. Do not use the computer before all spyware removed." My task manager has also been disabled. Can anyone help me? Windows XP Media Center Edition

Answer:YOUR SYSTEM IS INFECTED!

Do any programs pop up that you don't recognize that state they are trying to help or protect you? If so, what's the name of the program? A good place to look for this program is down in the taskbar by your clock. Let me know what you find there and maybe I can post a link to the best to remove it. You could also try this.

5 more replies