Computer Support Forum

awola virus

Question: awola virus

I am running windows xp and believe I caught the awola virus probably bundled with a lot of other things.
Ok, all I really want to do is copy my files to my external hard drive so I can reformat my computer. But, the virus has taken away my administrator status. It has disabled copying files to my external hard drive or dragging and dropping files. I cannot install Norton antivirus. The error message is "Setup was unable to update the MSI system component. If this problem continues please contact Microsoft at www.microsoft.com". I try to open my network connections, and they won't open.

Is my best bet just paying for the phishing scheme and going along with awola? Will it give me back these capabilities after I have paid, so I can reformat my computer?

Please help. I am desperate.

Relevance 100%
Preferred Solution: awola virus

I recommend downloading and running Reimage. It's a computer repair tool that has been proven to identify and fix many Windows problems with a high level of success.

I've used it in the past to identify and fix everything from blue screens (BSOD's), ActiveX errors, corrupt files and processes, dll/exe/sys errors, recover lost memory, Windows update problems, defragging, malware removal etc.

You can download it direct from this link http://downloadreimage.com/download.php. (This link will automatically start a download of Reimage that you can save to your computer.)

Answer: awola virus

Oh, I am also considering buying XoftSpySE. I downloaded the program of the internet, and it did locate many corrupt files. However, I am worried if I purchase it, I will not be able to install it fully and use it as I wasnt able to install Nortan Antivirus from disk. Is this a legitimate fear, or did this program already install, and when I purchase the license key, it will simply remove the corrupt files?

I hope I explained this well. Please reply.

19 more replies
Relevance 59.45%
Question: Awola virus

How do I get rid of the awola virus?

Answer:Awola virus

Hi and welcome to TSF.

Please start here and follow the instructions.

http://www.techsupportforum.com/secu...sting-log.html

If you cannot complete any of the Steps, simply move on to the next one - remember to let the Analyst know about this when you post your logs.

Do not post your logs back in this thread - follow the guidance in the above link!

Please note that the Security Forum is always busy, so I would ask for your patience while waiting for a reply.

1 more replies
Relevance 59.04%

I have read that some others have gotten help on the Awola virus, can someone help guide me through removing this malware?

More replies
Relevance 59.04%

After reviewing the forums I have found that I have a common issue as others do. I have the same Windows balloon pop-up and when clicked it will install the fake AWOLA anti-spyware. I have already followed the steps required to generate logs and I am posting them now. Could someone please provide me with any additional help to remove this malware from my system and thank you in advance.
 

Answer:AWOLA virus removal help

Welcome to Major Geeks!

Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

Do you use MusicMatch Jukebox?

You need to go back and follow the instructions in step 1 of the READ ME for MSconfig. You must not use MSconfig to control any startups or services. Select Normal Startup mode and remain in that state.

Uninstall the below old versions of software:
J2SE Runtime Environment 5.0 Update 12
Java 2 Runtime Environment, SE v1.4.2
Viewpoint Media Player <-- should have been uninstalled in step 0 of the READ ME

Make sure you reboot after uninstalling the above!

After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [KernelDrv.exe] C:\WINDOWS\System32\KernelDrv.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_4\bin\jusched.exe"
O4 - Startup: PowerReg Scheduler V3.exe
O17 - HKLM\System\CS2\... Read more

3 more replies
Relevance 59.04%

I have a simular issue to other but I dont see a common fix - HELP!

I've ran all the programs you recommended. Here are the logs.

This virus puts a yellow bang in my tray and states i've been infected. After closing the message a few times it launches Awola.

I belive it hit me 2 weeks ago.
 

Answer:Awola virus has infected my pc

More files attached.
 

10 more replies
Relevance 58.22%

Hi there. I believe I contracted a virus / trojan through Awola 6.0 a few weeks back. I started a thread in the 'Am I Infected' section, here's the link for that full thread: http://www.bleepingcomputer.com/forums/t/143729/infected-by-awola-60-and-could-really-use-some-help-removing-it/Long story short, I believe this virus was contracted on Wednesday, April 23 around 745pm. My operating system is Windows XP. Whenever I double-click on any .exe file I get an all-black window, and a little window above it with an error message similar to this: "16-bit MS-DOS SubsystemC:\Documents and Settings\All Users\Desktop\Winamp.InkThe NTVDM CPU has encountered an illegal instruction.CS:054d IP: 013d OP: f0 85 38 90 3a Choose 'Close' to terminate the application." I can right-click certain programs and select "Run As" to use them, but can't double-click on anything. I also think this virus has taken over Administrator duties, changed my registry and is preventing me from properly installing programs. It was also preventing me from running anti-virus scans, but I believe we have found a way around this, and I was finally able to process a scan with DSS (and Hijack This). I also did a scan using the Kaspersky scanner. I will copy and paste all logs below. Thanks in advance for all your help. HIJACK THIS MAIN.TXTDeckard's System Scanner v20071014.68Run by Mania on 2008-05-19 22:51:49Computer is in Normal Mode.---------------------------------------------------------------------------------- ... Read more

Answer:Infected With Awola 6.0 Virus / Trojan

HelloApologize for the delay in response we get overwhelmed at times but we are trying our best to keep up.If you have since resolved the original problem you were having would appreciate you letting us know If not please perform the following below so I can have a look at the current condition of your machine.Thanks and again sorry for the delay.Please download Deckard's System Scanner (DSS) and save to your Desktop.alternate download siteDSS will do the following:Create a new System Restore point in Windows XP and Vista.Clean your Temporary Files, Downloaded Program Files, Internet Cache Files, and empty the Recycle Bin on all drives.Check some important areas of your system and produce a report for an analyst to review.Automatically run HijackThis. It will also install and place a shortcut to HijackThis on your desktop if you do not already have it installed. So if HijackThis is not installed and DSS prompts you to download it, please answer yes.You must be logged onto an account with administrator privileges when using.Close all applications and windows.Double-click on dss.exe to run it and follow the prompts.If your anti-virus or firewall complains, please allow this script to run as it is not
malicious.When the scan is complete, two text files will open in Notepad:main.txt <- this one will be maximizedextra.txt <- this one will be minimizedIf not, they both can be found in the C:\Deckard\System Scanner folder.Please copy (Ctrl+C) and paste (Ctrl+V) the c... Read more

18 more replies
Relevance 58.22%

This morning I had a little yellow triangle with a black exclamation mark appear in my toolbar . Upon doing some investigation and updating Spybot S&D and running it in the safe mode as well as searching files and deleting them from my program files , control panel and other locations , after re-booting , the yellow triangle continues to reappear as well as I can hear my pop-up blocker blocking tons of attempts . I need help getting rid of this cursed thing .I have included my HJT log which I just ran about 5 minutes ago .Thanks in advance for help . I look forward to hearing from anyone who can assist .

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:51:01 AM, on 3/16/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Bellsouth\HelpCenter40b\bin\sprtcmd.exe
C:\Program Files\ATT Internet Tools\blslo... Read more

Answer:AWOLA VIRUS - HJT log file included

Hello biddle1,

Infection is showing here, so assuming you have not made too made changes since posting this log let's work from what shows here for now.
To keep them from interfering with the repairs, be sure to temporarily disable all antivirus/anti-spyware softwares while these steps are being completed. This can usually be done through right clicking the software's Taskbar icons, or accessing each software through Start - Programs.
To keep them from interfering with the repairs, be sure to temporarily disable all antivirus/anti-spyware softwares while these steps are being completed. This can usually be done through right clicking the software's Taskbar icons, or accessing each software through Start - Programs.
Download ComboFix.exe from here to your desktop

Then disconnect from net access. Once you have done that, click the downloaded ComboFix.exe file to run the repair.
When starting ComboFix will cause your computer's internal speakers to produce two beeps, and during the start process display two warnings. These are intended to discourage people who are not getting help in the forum from just experimenting with tools they do not understand. Just to inform you so you will understand that the procedures are expected, and okay.

ComboFix will also change the drive autoplay settings there as it's own added security measure. When we have completed all repairs here we will return the default Windows settings.
A caution - do not touch you... Read more

3 more replies
Relevance 56.58%

I'm not exactly sure at what time it happened or what I was doing, but the "Awola Anti-spyware 6.0" program is installed on my computer and won't uninstall. A pop-up box is constantly at the bottom right-hand corner of the taskbar saying Your computer is infected! , recomending that I use the tool to prevent data loss.

Also - on another note - I'm unable to use any open-source internet browers (ie. Firefox, Opera, Bonjour...). When I attempt to use Firefox (for example) I'm given the message "Firefox can't establish a connection to the server at www.google.com." It won't open any site. I'm given a similar message when I try to any other browser other than IE. The browser suggests that if my computer or network is protected by a firewall or proxy, to make sure make sure that Firefox is permitted to access the Web. I don't think this is the problem - but I really can't be sure. I never did anything to change these settings - nor would I know where to go to do such a thing. I'm not sure if these two things are related as the internet problem happened a good 2 months after the Awola problem started.

I really appreciate any help. From viewing other members' responses, your help seems very effective.

Thanks!

Deckard's System Scanner v20071014.68
Run by Frankie on 2008-02-22 23:17:18
Computer is in Normal Mode.
--------------------------------------------------------------------------------

-- System Restore -------------------------... Read more

Answer:Awola Virus :( .... May also be messing with my open-source internet browsers

One more thing I forgot to mention! --- On step 4 of what to do before posting a log - Updating the Operating System - I was unable to update Is there anything I can to do fix this?

Thanks so much!

13 more replies
Relevance 44.69%
Question: AWOLA

Just picked up Awola on my computer.Please help, how do I get rid of it??
 

Answer:AWOLA

have you tried any of the google search links?
http://www.google.com/search?aq=t&oq=awola+re&hl=en&safe=active&q=atwola+removal&btnG=Search

i havent had specific experience with this one.
 

1 more replies
Relevance 44.69%
Question: Awola

Hi,

I've tried to clean Awola off of my system by piecing together what to do from the treads in this forum, and it appears to have removed the pop-ups. Can you guys take a look at my HJThis log and let me know if I missed anything? Also, please let me know if I should post anything else to be reviewed.

Thanks very much
 

Answer:Awola

Your HJT log is clean...although we recommend that the exe be renamed to analyse.

Are you still having problems? If you are:

Please follow the instructions in the below link and attach the requested logs when you finish these instructions.

READ & RUN ME FIRST. Malware Removal Guide
 

1 more replies
Relevance 44.69%

I searched previous threads about this pesky malware, but I think my problem might be a little different...
So my computer automatically shut down, and then after rebooting I noticed a popup (from the taskbar only) telling me that my computer is infected and that I should download "special antispyware"...

I haven't clicked it, and don't plan on it, BUT I'm wondering if my computer is already infected ( I ran spybot and AVG and both found no infections.) and if not how do I stop that pop up from well popping up.

Thanks
 

Answer:Not sure if I have awola yet...

Welcome to Major Geeks!

Please follow the instructions in the below link and attach the requested logs when you finish these instructions.


If something does not run, write down the info to explain to us later but keep on going.
Do not assume that because one step does not work that they all will not.
READ & RUN ME FIRST. Malware Removal Guide

Notes:

If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode. You can try running steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
Starting your computer in Safe mode

If you have problems downloading on the problem PC, download the tools on another PC and burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.


Plus a guide on HOW TO: Attach Items To Your Post
 

1 more replies
Relevance 44.69%
Question: Awola

Well I got the AWola bug and it's a killer. Dang "Your Computer is infected!" pops up every 5 seconds after closing it and that is the good news. I can't go anywhere without being redirected. I am not even sure how I have made it to this site. Anyway I have done a HIJACK THIS log and I am posting it if anyone knows what to do I am all EARS.Thanks!Logfile of Trend Micro HijackThis v2.0.2Scan saved at 2:58:00 PM, on 12/28/2007Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\csrss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\system32\spoolsv.exeC:\WINDOWS\system32\svchosts.exeC:\WINDOWS\UmVlc2UgQnJpZGdlcw\command.exeC:\WINDOWS\system32\drivers\KodakCCS.exeC:\Program Files\Common Files\LightScribe\LSSrvc.exeC:\Program Files\Network Monitor\netmon.exeC:\Program Files\PC Tools AntiVirus\PCTAVSvc.exeC:\WINDOWS\system32\lpcywinp.exeC:\WINDOWS�... Read more

Answer:Awola

Hi and welcome to Bleeping Computer! My name is Sam and I will be helping you. Please download ComboFix and save it to your desktop.Double click combofix.exe and follow the prompts.When it's done running it will produce a log for you. Please post that log in your next reply.Important Note - Do not mouseclick combofix's window whilst it's running. That may cause it to stall.

3 more replies
Relevance 44.69%
Question: Awola

thanks for your advice boopme.

i had so much trouble getting rid of awola and i finally did it thanks to your suggestions.
thanks alot!

Answer:Awola

You're welcome and welcome to BC. I split your post away into it's wn topic as that one is still working and you are further along. Always mke your own topic it is the better method and keeps things from being confused. As in The stpe for you to do is not the step for them,thanks. I would recommend you do this step now. Now you should Set a New Restore Point to prevent possible reinfection from an old one. Some of the malware you picked up could have been saved in System Restore. Since System Restore is a protected directory, your tools can not access it to delete these bad files which sometimes can reinfect your system. Setting a new restore point AFTER cleaning your system will help prevent this and enable your computer to "roll-back" to a clean working state. The easiest and safest way to do this is:Go to Start > Programs > Accessories > System Tools and click "System Restore".Choose the radio button marked "Create a Restore Point" on the first screen then click "Next". Give the R.P. a name then click "Create". The new point will be stamped with the current date and time. Keep a log of this so you can find it easily should you need to use System Restore.Then use Disk Cleanup to remove all but the most recently created Restore Point.Then go to Start > Run and type: CleanmgrClick "OK".Click the "More Options" Tab.Click "Clean Up" in the System Restore section to remove all ... Read more

3 more replies
Relevance 44.69%
Question: Awola Bug?

There's a little bubble on the right side of my screen, near the clock, that keeps popping up (and won't go away, which is very annoying), saying "Your computer is infected!" Unknowingly, I clicked it and it presented me with "Awola Anti-Spyware 6.0" or something to that effect. I Googled Awola and found out that it was a rogue anti-spyware program, or something. So, I checked out Add/Remove Programs, and it wasn't in there. So I went through the Start menu to Uninstall Awola, and it said it was removed successfully, but the bubble will still not go away.

I am completely computer-stupid and have no idea what to do. Any help?
 

More replies
Relevance 44.69%

I'm infected with Awola.

I don't know if that's what it's called exactly, and there could be more to my problem than that; but there are other threads on this very problem. As far as I could tell, netiquette on MajorGeeks says I should make my own thread rather than invade someone else's.

If I'm wrong, I'm very sorry for having made a redundant thread.

Symptoms:

- A yellow triangle with a black exclamation point in it sitting in my task bar. It spawns a large, intrusive word bubble telling me I'm infected with spyware and that Windows will download the Awola anti-spyware program if I click the bubble.

- My system will freeze for several seconds at a seemingly random frequency. It always unfreezes, and anything I've done during the 'frozen' period (words I've typed, things I've clicked on, etc.) eventually happens after things come unfrozen.

What I was doing when I first noticed the infection:

- I'd been gone for two days, and my computer had been left on. When I came back I noticed my internet browser was open, and the word bubble was staring at me. I don't believe anyone touched my computer while I was gone.

Hopefully I've attached everything properly.

I did an AVG scan, but the log reads:





"[1/21/2008 15:03:15 PM] synchronize database and filecache"Click to expand...

I followed the directions in the "read me first and do these thi... Read more

Answer:Awola, maybe others.

Welcome to Major Geeks!

Is your copy of Spywar Doctor a paid version or free trial? If free, uninstall it now.

Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

Uninstall the below software:
J2SE Runtime Environment 5.0 Update 11
Java(TM) 6 Update 3
Viewpoint Media Player <-- should have been uninstalled in step 0 of the READ ME

Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
R3 - URLSearchHook: (no name) - <default> - (no file)
O2 - BHO: Toolbar Helper - {D44BBB61-E17F-4AE6-A502-8D7E0B29E616} - C:\WINDOWS\system32\s1940.dll
O3 - Toolbar: Stumble&Upon - {22D003CE-6952-46C5-80B9-D19B479620AB} - C:\WINDOWS\system32\s1940.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [Microsoft Windows Adapter 5.1.3214] C:\Documents and Settings\RICHARD\Application Data\pzruv.exe
O4 - HKCU\..\Run: [Awola] "C:\Documents and Settings\RICHARD\Application Data\Awola\Awola.exe" /MIN
O8 - Extra context menu item: StumbleUpon: &Blog This - res://C:\WIND... Read more

4 more replies
Relevance 44.28%
Question: Awola Malware

My computer has been infected with Awola. I am normally pretty good with computers but this has caused me to waste the last 6 hours on trying to removed it with no luck. From what I have read this is pretty common but extremly hard to remove. I really need help before me and my computer play fisty cuffs.Here is the log named main.txt:Deckard's System Scanner v20071014.68Run by Barry on 2008-04-22 22:52:31Computer is in Normal Mode.---------------------------------------------------------------------------------- System Restore --------------------------------------------------------------System Restore is disabled; attempting to re-enable...success.-- Last 1 Restore Point(s) --1: 2008-04-23 02:52:32 UTC - RP1 - System CheckpointBacked up registry hives.Performed disk cleanup.-- HijackThis (run as Barry.exe) -----------------------------------------------Logfile of Trend Micro HijackThis v2.0.2Scan saved at 10:57:25 PM, on 4/22/2008Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v7.00 (7.00.6000.16640)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\csrss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\Program Files\WIDCOMM\Bluetooth Software\... Read more

Answer:Awola Malware

Hello BarryCareyWelcome to BleepingComputer ========================If you are still in need of assistance please post a new Hijackthis log.

1 more replies
Relevance 44.28%
Question: Awola Removal!!!!

I got infected with Awola and cant get it off. Thanks for you help.

Incident Status Location

Spyware:Application/Awola Not disinfected c:\documents and settings\kris\application data\awola\awola.exe
Spyware:Application/Awola Not disinfected C:\Documents and Settings\Kris\load.exe
Potentially unwanted tool:Application/PRScheduler Not disinfected C:\Documents and Settings\Kris\Start Menu\Programs\Startup\PowerReg Scheduler V3.exe ... Read more

Answer:Awola Removal!!!!

Any suggestions on how to get rid of this. Plzzz my computer is crashing and i need help bad. Thanks

10 more replies
Relevance 44.28%
Question: Awola.... sigh

I'm embarrassed that I got "suckered" into this spyware, but I clicked too quickly after seeing the security alert (bogus, of course). I've searched and read everything, and can't believe I'm unable to get rid of it!



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:37:36 AM, on 1/14/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\acs.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\ISS\BlackICE\blackd.exe
c:\em\opt\Tivoli\lcf\bin\w32-ix86\mrt\lcfd.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\mcshield.exe
C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\TDS\tdssvc.exe
C:\WINNT\System32\mspmspsv.exe
C:\WINNT\system32\wscntfy.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\igfxtray.exe
C:\WINNT\system32\hkcmd.exe
C:\WINNT\AGRSMMSG.exe
C:\Program Files\Network Associates\Common Framework\UdaterUI.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Network Associates\Common Framework\McTray.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
... Read more

Answer:Awola.... sigh

Stupid spyware! Ran SDFIX and COMBOFIX with fingers crossed

Anyways....the Awola popup from the tray is still there!!


SDFix: Version 1.129

Run by LocalAdmin on Tue 01/22/2008 at 10:54 PM

Microsoft Windows XP [Version 5.1.2600]

Running From: C:\SDFix

Safe Mode:
Checking Services:


Restoring Windows Registry Values
Restoring Windows Default Hosts File

Rebooting...


Normal Mode:
Checking Files:

No Trojan Files Found






Removing Temp Files...

ADS Check:

C:\WINNT
No streams found.

C:\WINNT\system32
No streams found.

C:\WINNT\system32\svchost.exe
No streams found.

C:\WINNT\system32\ntoskrnl.exe
No streams found.



Final Check:

catchme 0.3.1344.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-22 23:00:49
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden services & system hive ...

scanning hidden registry entries ...

scanning hidden files ...

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


Remaining Services:
------------------



Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" ... Read more

4 more replies
Relevance 44.28%
Question: Awola hijack

My sister's computer has been hijacked, any help will be much appreciated. Here's the HJT log:
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Farstone Url Blocker - {316AEF8D-3C37-423E-9E6E-13820A9DC37A} - C:\PROGRA~1\PCSECU~1\THESHI~1\IrlOnIE.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O2 - BHO: BndShell3 BHO Class - {875A1348-7674-42aa-ADAC-B4F36A004A2D} - C:\Program Files\QdrDrive\QdrDrive8.dll (file missing)
O2 - BHO: Farstone Popup Blocker - {E22F9B9D-1A1F-473E-BED6-D8BC152441F4} - C:\PROGRA~1\PCSECU~1\THESHI~1\FARPOP~1.DLL
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - ... Read more

More replies
Relevance 44.28%
Question: Awola Invastion

Good Day Doctors, I'm helping another friend with their system. It looks like they got caught in one of those sites that pull you in and the next thing you know the software is on your system. I trying to uninstall a program called AWOLA. It states that it is an ANTI -SYPWARE and the system has been infected. I tried to uninstall it but no luck. It seems you have to buy the program to have the option available to uninstall it.

Has anyone heard of this program and how can I get it off my friend's system?
Thx in advance
Steve
 

More replies
Relevance 44.28%
Question: Awola Removal

dealt with AWOLA removal today. here are the following steps used to remove it:

0. DISABLE System Restore.

1. download, install and update Malwarebytes AntiMalware removal tool.
http://www.malwarebytes.org/

2. reboot your system into Safe Mode with networking.

3. verify that you have the latest update of Malwarebytes by performing the update again.

4. perform a FULL SCAN with Malwarebytes and, after the scan is complete, remove all items in the list.

5. perform a search on your computer for the following:
*awola*.*
this will search for ANY file in your system with the word 'awola' anywhere within its name, regardless of the file extension. DELETE any 'awola' files.

6. open the registry (ie. regedit) and do a search for 'awola' and remove any items you find.

7. perform another scan with Malwarebytes to be certain your system is clean.

8. restart your system.

if anyone has comments, please share them.
 

More replies
Relevance 44.28%

Howdy!

My computer seems to have been infected with this malware Awola. It is driving me bonkers. I cannot seem to rid my computer of this program. I've tried my antispyware programs and uninstalling and basic registry deletions, but it keeps regenerating.

Any help would be tremendously appreciated.

Thanks,
Andrew
 

More replies
Relevance 44.28%
Question: awola help needed

my sweet husband contracted awola and I am left to figure out how to get rid of it... any help is much appreciated - here is the HijackThis Log I just ran



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:01:50 PM, on 1/23/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPZIPM12.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\keyhook.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\WINDOWS\system32\kmw_run.exe
C:\WINDOWS\system32\KMW_SHOW.EXE
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\system32\hphmon05.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09... Read more

Answer:awola help needed

I have now also completed ComboFix but the popup "Your computer is infected!" is still there... log listed below but not sure if I did it correctly. It is also affecting other programs and now I cannot print. Please help before I divorce my husband or at least throw the computer at him!!!




WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons

19 more replies
Relevance 44.28%

Awola is driving me crazy!! And just about the time I get started on another paper, I get a pop-up. I can't tell you how many times I have had to re-connect to this site just to finish this thread.
I wasn't able to perform a Windows Update because the Windows Genuine Advantage Validation Tool wouldn't install. (KB892130).
Here is the log;

Deckard's System Scanner v20071014.68
Run by gc on 2008-01-18 13:44:27
Computer is in Normal Mode.
--------------------------------------------------------------------------------

-- System Restore --------------------------------------------------------------

System Restore is disabled; attempting to re-enable...success.


-- Last 1 Restore Point(s) --
1: 2008-01-18 19:44:32 UTC - RP1 - System Checkpoint


Backed up registry hives.
Performed disk cleanup.

Percentage of Memory in Use: 81% (more than 75%).
Total Physical Memory: 256 MiB (512 MiB recommended).


-- HijackThis (run as gc.exe) --------------------------------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:51:41 PM, on 1/18/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C... Read more

Answer:Awola & numerous pop-ups

Download SDFix from here and save it to your desktop.


Please then reboot your computer in Safe Mode by doing the following :
Restart your computer

After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
Instead of Windows loading as normal, a menu with options should appear;
Select the first option, to run Windows in Safe Mode, then press "Enter".
Choose your usual account.

In Safe Mode, right click the SDFix.zip folder and choose Extract All,
Open the extracted folder and double click RunThis.bat to start the script.
Type Y to begin the script.

It will remove the Trojan Services then make some repairs to the registry and prompt you to press any key to Reboot.
Press any Key and it will restart the PC.

Your system will take longer that normal to restart as the fixtool will be running and removing files.
When the desktop loads the Fixtool will complete the removal and display Finished, then press any key to end the script and load your desktop icons.

Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
(Report.txt will also be copied to Clipboard ready for posting back on the forum).

Finally paste the contents of the Report.txt back on the forum.


=========================================


Download Combofix from any of the links below, and save it to your desktop. For information regarding this d... Read more

3 more replies
Relevance 44.28%
Question: Awola Removal!!!!

I have Awola virus on my computer and i cannot get it off. i have deleted the registry values and everything. I ran spybot s&d and ad-aware. Please help in any way you can. Thanks.

Answer:Awola Removal!!!!

help plzzzz, i can barely use my computer with it this bad. thanks

2 more replies
Relevance 44.28%
Question: awola removal

My brother-in-law has managed to install awola and now I have to get rid of it. Any ideas? He lives 60miles away and is techno-phobic.

Answer:awola removal

click here

10 more replies
Relevance 44.28%

Hi can anyone assist me? I am trying to repair my cousin's computer which appears to have Awola installed on it.

I also unable to get the computer to detect any wireless signals even after manually entering the settings for my network. In addition, the user also installed SystemTech Spyware Cleaner. Is this is a good program to use? Am I better off using Windows Defender?

Below is a log file


Deckard's System Scanner v20071014.68
Run by RASHIDA XXXX on 2008-05-03 20:53:22
Computer is in Normal Mode.
--------------------------------------------------------------------------------

-- System Restore --------------------------------------------------------------

Failed to create restore point; System Restore is disabled (service is not running).


Backed up registry hives.
Performed disk cleanup.



-- HijackThis (run as RASHIDA ROACH.exe) ---------------------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:54:15 PM, on 5/3/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wirele... Read more

Answer:Please help Awola 6 on laptop

I am sorry to bump this thread. I was wondering if there was something that I left out or should have done before posting this thread.

I did complete steps 1-4. I was unable to connect to the internet to do an online scan.

I apologize if I incorrectly posted. Sorry for bumping this thread.

4 more replies
Relevance 44.28%
Question: Awola infection!

My computer is infected with Awola anti spyware. I searched Google for some solutions for this aggrevating problem. This website caught my eye. I hope that I can be helped for my problem. As of right now my computer crashes on normal mode within 5 min's of startup. The only way I can use the computer is on safe mode.
Once I entered the website I was reading a forum for Awola removal and downloaded the file SDfix (this was from a link on the thread. I decided that is would be best if I discontinue any attemp at correcting the problem myself because I am not extremely knowledgable. Thanks for any help I can get.

Answer:Awola infection!

why doesnt anyone want to help me with my issue?

1 more replies
Relevance 43.87%

Hi there, I believe my computer was recently infected by the Awola Virus / Trojan, and I could really use some assistance. I thank you in advance for any suggestions and help, they are appreciated. I'll put up a detailed description here of what's happened so far, and can certainly provide any additional information that may be required. My computer knowledge is okay, but very limited in terms of spyware and troubleshooting complex problems like this one.

Operating System = Windows XP

A couple of days ago I was doing some stuff online at 7:45pm, preoccupied and in somewhat of a rush. I got a popup menu that a trojan had been found, I assumed it was from my McAfee Security Centre (as this has happened several times before) but I didn't really look at it that closely, and selected okay (I think). I then started to receive a bunch of popups about Spyware, and Awola spyware removal program. I kept closing them because I was in a rush, didn't really look that closely, thought it was just ads and may very well have clicked something I shouldn't have. I did see the Awola Program box come up at one point and I thought I attempted to close it, but I may have clicked on something inadvertently.

Upon rebooting later, I realized that the computer was probably infected. I cannot click or open any application, by double-clicking an icon or program name I always receive the same error message (tailored to whatever application I attempted to open). A black empty box a... Read more

Answer:Infected By Awola 6.0 And Could Really Use Some Help Removing It

if you have not already done so you could try the superantispyware program?http://www.superantispyware.com/superantis...efreevspro.htmldownload it fromhttp://www.superantispyware.com/downloadfi...ANTISPYWAREFREErun the installation program and start the program from the desktop icon; fully update the definitions , reboot the computer into safe mode if it will let you , then run superantispyware from the desktop icon on a full computer scan when the scan is complete, reboot your computer into normal mode, and come back and post the log report you should find by opening the program and go to preferences/statistics.logsleft mouse click on the most recent entry, click on 'view log' and copy and paste that report into here for examination so folks can see what help you may need

30 more replies
Relevance 43.87%

hello guys/gals:



here with my computer again. it now has a phony anti-virus software on it "awola" the computer has been taken over, no task manager, no wallpaper, random shut downs, constant "warning" pop ups, i cant do anything anymore......


please help thanks


here are the logs:


DDS (Ver_09-03-16.01) - NTFSx86
Run by Owner at 18:02:31.03 on Mon 04/06/2009
Internet Explorer: 7.0.5730.11
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.894.500 [GMT -7:00]


============== Running Processes ===============

C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
svchost.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
svchost.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\awolaantispy.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\iTunes\iTune... Read more

Answer:AWOLA has infected my system

Hello and Welcome to TSF.

Please Subscribe to this Thread to get immediate notification of replies as soon as they are posted. To do this click Thread Tools, then click Subscribe to this Thread. Make sure it is set to Instant notification by email, then click Add Subscription.

Please note that the forum is very busy and if I don't hear from you within three days this thread will be closed.

------------------------------------------------------

Please explain why this computer has no antivirus program installed and running. This is an open invitation for infection.

It can take as little as eight seconds to infect an unprotected computer.

Please keep this computer offline except when downloading tools and posting in the forum until we get one installed. Let me know your intentions for an antivirus program.

------------------------------------------------------

Please note that these fixes are not instantaneous. Most infections require more than one round to properly eradicate.

Please stay with me until given the 'all clear' even if symptoms seemingly abate.

Kindly follow my instructions and please do no fixing on your own or running of scanners unless requested by a helper.

------------------------------------------------------

Please visit this webpage for download links, and instructions for running ComboFix:

http://www.bleepingcomputer.com/comb...o-use-combofix

* Ensure you have disabled all antivirus and antimalware programs ... Read more

2 more replies
Relevance 43.87%

My machine has been infected with AntivirusXP 08 and Awola. Have cleaned out alot but now am left with random non-fatal BSOD's that I think are a trademark of these infections. Kaspersky scan of the critical areas is clean so there is no log to attach.I am including to two logs from the DSS scan.Deckard's System Scanner v20071014.68Run by Samantha on 2008-07-19 14:35:13Computer is in Normal Mode.--------------------------------------------------------------------------------Total Physical Memory: 480 MiB (512 MiB recommended).-- HijackThis (run as Samantha.exe) --------------------------------------------Logfile of Trend Micro HijackThis v2.0.2Scan saved at 2:35:42 PM, on 7/19/2008Platform: Windows XP SP3 (WinNT 5.01.2600)MSIE: Internet Explorer v7.00 (7.00.6000.16674)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\SYSTEM32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\spoolsv.exeC:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exeC:\Program Files\Bonjour\mDNSResponder.exeC:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exeC:\Program Files... Read more

Answer:Antivirusxp 08 And Awola Infection

Hello, my name is fenzodahl512 and welcome to BC.. Please do the following...]Please uninstall Viewpoint Media Player from your computer..Please download ATF Cleaner by Atribune.Double-click ATF-Cleaner.exe to run the program.Under Main choose: Select AllClick the Empty Selected button.If you use Firefox browserClick Firefox at the top and choose: Select AllClick the Empty Selected button.NOTE: If you would like to keep your saved passwords, please click No at the prompt.If you use Opera browserClick Opera at the top and choose: Select AllClick the Empty Selected button.NOTE: If you would like to keep your saved passwords, please click No at the prompt.Click Exit on the Main menu to close the program.------------------------Please download the OTMoveIt2 by OldTimer.Save it to your desktop.Please double-click OTMoveIt2.exe to run it. (Vista users, please right click on OTMoveit2.exe and select "Run as an Administrator")Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

[kill explorer]
C:\Documents and Settings\Samantha\Application Data\internaldb6334.dat
C:\Documents and Settings\Samantha\Application Data\internaldb41.dat
C:\Documents and Settings\Sam\Application Data\shc3ubj0enb9
C:\WINDOWS\system32\blphc5ubj0enb9.scr
C:\Program Files\Viewpoint
EmptyTemp
puri... Read more

2 more replies
Relevance 43.87%

Hi, my mother recently infected her PC with AWOLA, and ever since, everything has been running much worse. I've tried to use previous posts / fixes, but to no avail. I've included the DSS report below. Thank you so much.

Deckard's System Scanner v20071014.68
Run by sconstan on 2008-02-01 14:59:16
Computer is in Normal Mode.
--------------------------------------------------------------------------------



-- HijackThis Clone ------------------------------------------------------------


Emulating logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2008-02-01 14:59:34
Platform: Windows XP Service Pack 2 (5.01.2600)
MSIE: Internet Explorer (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\system32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\scardsvr.exe
C:\Progress\OpenEdge\bin\admsrvc.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Microsoft SQL ... Read more

Answer:Older PC Infected with AWOLA, Please Help

Bump. Thanks again.

8 more replies
Relevance 43.87%

Hi, yesterday I starte getting some really annoying Awola anti-spywear popups on my PC. I used the information in some of the threads on this forum, and thought that I had it beat, but today, I'm having the same problem. Here's the HijackThis log. Any help is much appreciated. This is a really annoying issue.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:49:55 PM, on 1/18/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\aspimgr.exe
C:\WINDOWS\system32\basfipm.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Dell\QuickSet\bak\quickset.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\iTunes\iTunes... Read more

Answer:Solved: Awola Malware

16 more replies
Relevance 43.87%

gettin tons of pop ups, mainly says "internet speed monitor" or "outerinfo" on em, also awola self downloaed dis now automatically coming on and what not, and of course comp running slow as heck. Thanks for help, im computer stupid, haha.Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\Ati2evxx.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\Ati2evxx.exeC:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exeC:\WINDOWS\system32\spoolsv.exeC:\WINDOWS\Explorer.EXEC:\Program Files\M-Audio\Fast Track USB\MAUSBFTInst.exeC:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exeC:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYSC:\WINDOWS\system32\svchost.exeC:\Program Files\VentSrv\ventrilo_svc.exeC:\Program Files\VentSrv\ventrilo_srv.exeC:\WINDOWS\system32\wscntfy.exeC:\Program Files\Java\jre1.6.0_02\bin\jusched.exeC:\Program Files\Common Files\Real\Update_OB\realsched.exeC:\WINDOWS\system32\Rundll32.exeC:\Program Files\Java\jr... Read more

Answer:Pop Ups, Awola, Sloooow Comp, Help!

already fixed it, didnt know how to just delete the topic, thanks.

2 more replies
Relevance 43.87%

My Bosses computer got hit with AWOLA before finding your site I tried to fix it. We run McaFee antivirus. His firewall was down, which has been fixed.

His computer runs XP Pro, he can do what he needs to do however, he still is getting the message poping up. Your computer is infected.

Yes, I deleted files and some registry stuff already. I ran spybot and found a few more files. On the last run of spybot there are not offending files showing. Is there any way of ridding that annoying message?

Thanks,
 

Answer:AWOLA- Continued Pop Up Message

Welcome to Major Geeks!

Please follow the instructions in the below link and attach the requested logs when you finish these instructions.

READ & RUN ME FIRST. Malware Removal Guide
 

3 more replies
Relevance 43.87%

Had a recent problem with malware. The main culprits seemed to be Awola, Security Toolbar, Kukkakreck taking over my home page with numerous pop-ups and slow performance. Followed your nine step program and am greatly appreciative for the concise advice. Most of my problems seemed to be solved but I will post the log and hope for the best. Thank you in advance.Logfile of Trend Micro HijackThis v2.0.2Scan saved at 3:24:34 PM, on 12/14/2007Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v7.00 (7.00.6000.16574)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\system32\LEXBCES.EXEC:\WINDOWS\system32\LEXPPS.EXEC:\WINDOWS\system32\spoolsv.exeC:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exeC:\Program Files\Network Associates\McAfee Desktop Firewall for Windows XP\FireSvc.exeC:\Program Files\Network Associates\Common Framework\FrameworkService.exeC:\Program Files\Network Associates\VirusScan\VsTskMgr.exeC:\Program Files\Sygate\SEA\smc.exeC:\WI... Read more

Answer:Awola, Kukkakreck, Etc. And Other Villains

Welcome to the BleepingComputer HijackThis Logs and Analysis forum Thom TMy name is Richie and i'll be helping you to fix your problems.Please disable Spybot S&D?s protection,or it will interfere.You can enable it after you're clean.Open Spybot and click on 'Mode' and check 'Advanced Mode'.Click on 'Tools' in bottom left hand corner.Click on the 'System Startup' icon.Uncheck 'Teatimer' box and/or uncheck 'Resident'.Click the 'Allow Change' box.Then, check next to the computer clock to see if the icon for Spybot is still there.If it is, right click it and choose 'exit Spybot-S&D Resident'.Restart the computer.If you find you're experiencing problems disabling Spybot's Tea-Timer,follow the info in the link below:http://www.russelltexas.com/malware/teatimer.htmViewpoint Manager is considered as foistware instead of malware since it is installed without users approval but doesn't spy or do anything "bad". This will change from what we know in 2006 read this article: http://www.clickz.com/news/article.php/3561546You are well advised to remove the program now. Go to Start > Settings > Control Panel > Add/Remove Programs and remove the following programs if present,then restart your pc:ViewpointViewpoint ManagerViewpoint Media PlayerYour version of Sun Java is out of date.Older versions have vulnerabilities that malware can use to infect your system.Please follow these steps to remove older versions of Sun Java,and then update.1. Download the latest versio... Read more

15 more replies
Relevance 43.87%

I keep getting pop-ups and a little notification at the bottom right of my screen saying: "Your computer is infected! Windows has detected spyware infection. It is recommended to use special antispyware tools to prevent data loss. Windows will now download and install the most up-to-date antispyware for you. Click here to protect your computer from spyware."

I clicked it and found that it was installing a program "Awola," which I later found to be some sort of spyware or something. I uninstalled and did some Ad Aware scans (both in normal and safe modes), but I keep getting this notification CONSTANTLY. It's really annoying. Can anyone help?

Thanks!!
 

Answer:Awola program--How do I remove it?

14 more replies
Relevance 43.87%

I have run the XP cleaning procedure with combofix, spybot, AVG and MG tools as suggeste by this great site, but I still have a nasty Awola bug on my computer. I will try to attach the logs, but AVG stated that it did not create one.

Please help, and thanks in advance!
 

Answer:awola still giving me fits

Welcome to Major Geeks!

Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

Uninstall the below old versions of software:
Spybot - Search & Destroy 1.3 <-- this has not been used for more than 2 years.
Viewpoint Media Player <-- should have been uninstalled in step 0 of the READ ME

Then install the proper version of Spybot as given in the READ ME. MAKE SURE to uncheck the option for using Teatimer.

Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

O4 - HKCU\..\Run: [Microsft Windows Adapter 5.1.3013] C:\Documents and Settings\Home\Application Data\zpbfwsb.exe
O4 - HKLM\..\Policies\Explorer\Run: [ngm] C:\WINDOWS\System32\ngm.exe
O4 - HKCU\..\Policies\Explorer\Run: [nhhp] C:\WINDOWS\System32\nhhp.exe
O15 - Trusted Zone: http://www.neededware.com
O16 - DPF: NDWCab - http://www.neededware.com/ndw4.cab
O20 - Winlogon Notify: khfdbxx - khfdbxx.dll (file missing)
O23 - Service: PLSRemote Service (PLSRemoteSvc) - Unknown owner - C:\WINDOWS\SYSTEM32\PLSRemote.exe (file missing)

After clicking Fix, exit HJT.

Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is ... Read more

9 more replies
Relevance 43.87%

Hello TechGuy users,
I am a new user to TechGuy after my friend had an encounter with... AWOLA.
They said they were getting pop-ups even if not on the internet and their whole Compaq Windows XP Laptop is slowing down. I told them to get Spybot Search & Destroy and update to the newest version and they did. They scanned their whole computer and they destroyed some AWOLA software, but it is still there.

What should they do?
Thanks,
Michael
 

Answer:AWOLA Spyware... AAAHHHHH!

More info:
I told my friend to do System Restore they said it didnt work, then also tried to uninstall it manually but they want them to pay for it...

 

1 more replies
Relevance 43.87%

Hi there I REALLY need help okay so first i got infected with awola its a flashy trojan virus that disguises itself as a antivirus spyware and i thought i removed it and then today i turn on my computer and i have 2 drives C and D and my D drive would not load like its would just show my background with no icons or side bars on it. Please if you know how to help would you please i would be forever grateful thank you
 

More replies
Relevance 43.46%

This is definitely not an anti-spyware program. It opens a window off the toolbar disguised as a Windows security update. It warns, "Your computer is infected! Click here to protect your computer...". The balloon does not go away. It worked its way onto the computer uninvited. I've followed all the procedures listed in the Preparation Guide but to no avail. Please help. Thanks for your time and expertise. Here's the hijack log:Logfile of Trend Micro HijackThis v2.0.2Scan saved at 10:35:13 PM, on 8/31/2007Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v7.00 (7.00.6000.16512)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\Ati2evxx.exeC:\WINDOWS\system32\svchost.exeC:\Program Files\Panda Security\Panda Antivirus 2008\pavsrv51.exeC:\Program Files\Panda Security\Panda Antivirus 2008\AVENGINE.EXEC:\WINDOWS\System32\svchost.exeC:\Program Files\Sygate\SPF\smc.exeC:\WINDOWS\system32\spoolsv.exeC:\WINDOWS\system32\acs.exeC:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exeC:\WINDOWS\system32\Ati2evxx.exeC:\WINDOWS\Explorer.EXEC:\Program Files\Common Files\Apple\M... Read more

Answer:Infected With "awola Anti-spyware 6.0"

Welcome to the BleepingComputer HijackThis Logs and Analysis forum rosevilledad My name is Richie and i'll be helping you to fix your problems.Your version of Sun Java is out of date.Older versions have vulnerabilities that malware can use to infect your system.Please follow these steps to remove older versions of Sun Java,and then update.1. Download the latest version of Java Runtime Environment (JRE)2. Scroll down to where it says 'Java Runtime Environment (JRE) 6u2'.3. Click the "Download" button to the right.4. Check the box that says: "Accept License Agreement".5. The page will refresh.6. Click on the link to download 'Windows Offline Installation, Multi-language' and save to your desktop.7. Close any programs you may have running - especially your web browser.8. Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.9. Check any item with Java Runtime Environment (JRE or J2SE) in the name.10. Click the Change/Remove button.11. Repeat as many times as necessary to remove each Java versions.12. Reboot your computer once all Java components are removed.13. Then from your desktop double-click on jre-6u2-windows-i586-p.exe to install the newest version.Download Combofix and save to your desktop:Note: It is important that it is saved directly to your desktop Close any open browsers. Double click on combofix.exe and follow the prompts. When it's finished it will produce a log. Post the entire contents of C:... Read more

7 more replies
Relevance 43.46%

Hi everyone-

I'm trying to help my younger brother get his computer functioning properly.

Within the last couple of weeks, he's acquired the AWOLA problem, the machine runs incredibly slow and also his home page starts out at something completely different even though we've changed it back many times.

I've gone through the 5 steps and this is what I have.
Thank you all for your help.




Deckard's System Scanner v20071014.68
Run by Adam on 2008-04-25 23:30:56
Computer is in Normal Mode.
--------------------------------------------------------------------------------

-- System Restore --------------------------------------------------------------

System Restore is disabled; attempting to re-enable...success.


-- Last 1 Restore Point(s) --
1: 2008-04-26 04:31:07 UTC - RP1005 - System Checkpoint


Backed up registry hives.
Performed disk cleanup.

Total Physical Memory: 255 MiB (512 MiB recommended).
System Drive C: has 4.34 GiB (less than 15%) free.


-- HijackThis Clone ------------------------------------------------------------


Emulating logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2008-04-25 23:35:32
Platform: Windows XP Service Pack 2 (5.01.2600)
MSIE: Internet Explorer (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\SYSTEM32\smss.exe
C:\WINDOWS\SYSTEM32\csrss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\SYSTEM32\services.exe
C:\WINDOWS\SYSTEM32\lsass.exe
C:\WINDOWS\SYSTEM32\svchost.exe... Read more

Answer:AWOLA + Hijacked IE Home Page + others...

Hello and welcome to TSF.

Scan with HijackThis and put a checkmark against the following entries:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\WINDOWS\system32/left.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir...r=7&ar=msnhome
R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll (file missing)
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: (no name) - _{1C78AB3F-A857-482e-80C0-3A1E5238A565} - (no file)
R3 - URLSearchHook: (no name) - _{20EC3D2D-33C1-4C9D-BC37-C2D500688DA2} - (no file)
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
O15 - Trusted Zone: about://internet (HKCU)
O16 - DPF: {99802379-7362-40E2-9D28-8A3B9AF880B7} () - http://hotsearchbar.com/toolbar2/winhot32.cab

Close all browsers and windows other than HijackThis and click on "fix checked".

I am not sure if you set this as your start page yourself or not... Read more

11 more replies
Relevance 43.46%

Hey guys, I'm working on a PC for a friend, and she has the constant "Your Computer is infected!" crap going on... Here's the HJT and SmitFraud logs:

Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 9:18:29 PM, on 1/9/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messen... Read more

Answer:HijackThis/SmitFraud logs - Awola!

Please see the new post below... the above scan was old...
 

2 more replies
Relevance 43.46%

Ive had this infection for sometime. Tried a bunch of methods from computerforum but still cant finish the virus off. I constantly get CID popups and on my moms guest account she has this annoying AWOLA popup that appears to say its an anto virus program. Logfile of Trend Micro HijackThis v2.0.2Scan saved at 5:31:45 PM, on 5/10/2008Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v7.00 (7.00.6000.16640)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\Program Files\Windows Defender\MsMpEng.exeC:\WINDOWS\System32\svchost.exeC:\Program Files\Common Files\Symantec Shared\ccSvcHst.exeC:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exeC:\WINDOWS\system32\spoolsv.exeC:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exeC:\Program Files\Bonjour\mDNSResponder.exeC:\Program Files\Common Files\LightScribe\LSSrvc.exeC:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exeC:\WINDOWS\system32\nvsvc32.exeC:\WINDOWS\system32\svchost.exeC:\Program Files\Common Files\Ulead Systems\D... Read more

Answer:Badly Infected With Cid Popups And Awola

also in my c: folder I have like 200 TMP files that look like pos1A2F.tmp what are these??

3 more replies
Relevance 43.46%

Have an AWOLA infection. was going to use info from this forum which suggested downloading a couple of files to help. But when I try to go to the sites, I get redirected to no page. Can't go anywhere.

Also, when doing a search now to locate and delete AWOLA files I get an error notice and Search shuts down.

Ad-Aware will run then stops about half way through.

Continuously get a little popup about infections. And there is a little yellow triangle on the startup menu bar (lower right) that, if clicked, will start Awola again.

Any suggestion, or do I just through the box away?

Thanks,

Pete

Answer:Awola - can't download fixes due to redirect

You should be able to download this tool. If not, use another machine, and a usb stick or CDR to carry it to the afflicted machine.

Please do this:

Download Deckard's System Scanner (DSS) to your Desktop. Note: You must be logged onto an account with administrator privileges.Close all applications and windows.
Double-click on dss.exe to run it, and follow the prompts.
When the scan is complete, two text files will open - main.txt <- this one will be maximized and extra.txt <-this one will be minimized
Copy (Ctrl+A then Ctrl+C) and paste (Ctrl+V) the contents of main.txt here.
Please attach extra.txt to your post.
To attach a file to a new post, simplyClick the[Manage Attachments] button under Additional Options > Attach Files on the post composition page, and
copy and paste the following into the "Upload File from your Computer" box:C:\Deckard\System Scanner\extra.txt

Click Upload.

What DSS will do: create a new System Restore point in Windows XP and Vista.
clean your Temporary Files, Downloaded Program Files, and Internet Cache Files, and also empty the Recycle Bin on all drives.
check some important areas of your system and produce a report for your analyst to review. DSS automatically runs HijackThis for you, but it will also install and place a shortcut to HijackThis on your desktop if you do not already have HijackThis installed.

------------------------------------------------------------------------------------... Read more

3 more replies
Relevance 43.46%

A big thanks in advance.Windows XP Professional SP2I am working on a friend's PC that was hit with Awola 6. He followed removal procedures described at http://www.spyware-techie.com/awola-or-awo...-removal-guide/He brought me the computer with no signs of the Awola 6 files or registry entries mentioned in the link above yet his network adapter stops receiving packets only about a minute after the Windows desktop has booted.I used system restore to take him back to before the attack but no help. Ran Smitfraud again and no help. I weeded through the running processes and ensured that there was no proxy set up in Internet options.Since the system has no available network connection I wasn't able to run the Kaspersky online scanner.I ran DSS and here is the log: Please note that I didn't have the computer hooked up to the router at the time of the DSS scan. If it is important I can hook the computer up and make a new log.Deckard's System Scanner v20071014.68Run by Santa B on 2008-06-20 04:50:22Computer is in Normal Mode.---------------------------------------------------------------------------------- System Restore --------------------------------------------------------------System Restore is disabled; attempting to re-enable...success.-- Last 1 Restore Point(s) --1: 2008-06-20 11:50:23 UTC - RP1 - System CheckpointBacked up registry hives.Performed disk cleanup.-- HijackThis (run as Santa B.exe) ---------------------------------------------Logfile of Trend Micro HijackThi... Read more

Answer:Awola 6 Removed But Packets Are Not Being Received.

I'm hoping somebody can get to solving this soon.

5 more replies
Relevance 43.46%

Here's my logfile. Is this the right thing to post?



Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 8:38:27 PM, on 5/21/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal

Running processes:
C:\WINXP\System32\smss.exe
C:\WINXP\system32\winlogon.exe
C:\WINXP\system32\services.exe
C:\WINXP\system32\lsass.exe
C:\WINXP\system32\svchost.exe
C:\WINXP\System32\svchost.exe
C:\WINXP\system32\spoolsv.exe
C:\WINXP\system32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINXP\Explorer.EXE
C:\WINXP\StartupMonitor.exe
C:\Program Files\Antivirus\Clamwin\bin\ClamTray.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINXP\system32\RDSHOST.exe
C:\WINXP\system32\sessmgr.exe
C:\WINXP\system32\winlogon.exe
C:\WINXP\system32\logonui.exe
C:\WINXP\system32\rdpclip.exe
C:\WINXP\system32\wuauclt.exe
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\WINXP\system32\logon.scr
C:\Program Files\Antivirus\HijackThis\HiJackThis_v2.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://runonce.msn.com/?v=msgrv75
R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareBlock Class - {0A87E45F-537A-40B4-B812-E2544C21A09F} - C:\Program Files\Antivirus\SpyCatcher\SCAc... Read more

Answer:Awola fake anti-spyware

Ok.We need to download ComboFix.exe. This will give a better view to the files running and also hidden on your computer.
Please visit this webpage for download links, and instructions for running ComboFix

When the tool is finished, it will produce a report for you. Please copy and paste the "C:\ComboFix.txt" along with a new 'HijackThis' log so that we can continue to do any further cleaning that your system may require.

Caution: Never run and remove files with Combofix unless supervised by a qualified security analyst who is experienced in the use of Combofix. Mal use can cause serious computer problems

NOTE: Combofix prevents autorun of all CDs, floppies and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you - please let me know.

=======================================

Please download SDFix from here and save it to your desktop

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)

Please then reboot your computer in Safe Mode by doing the following :
Restart your computer
After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
Instead of Windows loading as normal, the Advanced Options Menu should appear;
Select the first option, to run Windows in Safe Mode, then press Enter.
Choose your usual account.

Open the extra... Read more

1 more replies
Relevance 43.46%

Hi,

Earlier today I managed to get the Awola malware onto my computer. I have run Ad-Aware & Spybot S&D along with F-Prot anti-virus software. I have also ran Hijackthis! & removed the Awola line. I also ran a search of my computer files & removed all files relating to Awola. I have rebooted my computer & the annoying yellow triangle warning message continues to popup every 30 seconds. Could someone help to squash this pest?

Thanks in advance!
haroldff1082

Answer:Annoying "your Computer Is Infected!" Pop-up (awola)

Hello and welcome haroldff1082What antivirus procuct do you have installed and have you scanned with it in safe move.Please do this also Download Attribune's ATF Cleaner and then SUPERAntiSpyware , Free Home Version. Save both to desktop .. DO NOT run yet.Open SUPER from icon and install and Update itUnder Scanner Options make sure the following are checked (leave all others unchecked):Close browsers before scanning.Scan for tracking cookies.Terminate memory threats before quarantining.Click the "Close" button to leave the control center screen and exit the program. DO NOT run yet.Now reboot into Safe Mode: How to start Windows in Safe ModeDouble-click ATF-Cleaner.exe to run the program.Under Main "Select Files to Delete" choose: Select All.Click the Empty Selected button.If you use Firefox or Opera browser click it at the top and choose: Select AllClick the Empty Selected button.If you would like to keep your saved passwords, please click No at the prompt.Click Exit on the Main menu to close the program.NOW Scan with SUPEROpen from the desktop icon or the program Files listOn the left, make sure you check C:\Fixed Drive.Perform a Complete scan. After scan,Verify they are all checked.Click OK on the summary screen to quarantine all found items.If asked if you want to reboot, click "Yes" and reboot normally.To retrieve the removal information after reboot, launch SUPERAntispyware again.Click Preferences, then click the Statistics/Logs... Read more

3 more replies
Relevance 43.05%

Hello, new to the forum, think this is great learning for a novice like me and appreciate the help if I could get it here.

I have the AWOLA virus/scarewware on my system. My virus scan picks it up as Generic FakeAlert.b

A warning is posted on my right hand lower toolbar that says "Windows has detected syware infection. It is recommended to use a special antispyware to prevent data loss etc.."

I went through the 5 steps posted here and created this log, I hope I didn't screw this up.

Deckard's System Scanner v20071014.68
Run by Jeff on 2008-01-12 22:18:17
Computer is in Normal Mode.
--------------------------------------------------------------------------------

-- System Restore --------------------------------------------------------------

Successfully created a Deckard's System Scanner Restore Point.


-- Last 5 Restore Point(s) --
70: 2008-01-13 05:18:26 UTC - RP1052 - Deckard's System Scanner Restore Point
69: 2008-01-12 03:19:33 UTC - RP1051 - Removed QuickTime
68: 2008-01-12 03:08:02 UTC - RP1050 - Software Distribution Service 3.0
67: 2008-01-12 02:51:28 UTC - RP1049 - Spybot-S&D Spyware removal
66: 2008-01-11 03:57:49 UTC - RP1048 - Spybot-S&D Spyware removal


-- First Restore Point --
1: 2007-10-16 05:41:31 UTC - RP983 - System Checkpoint


Backed up registry hives.
Performed disk cleanup.



-- HijackThis Clone ------------------------------------------------------------


Emulating logfile of Trend Mic... Read more

Answer:AWOLA scareware help needed, Log posted inside.

Bump, any help would be appreciated. thx

- Installed Java 6.4

19 more replies
Relevance 42.64%

I am attempting to clean my in-laws computer but I have been unable to remove AWOLA spyware from their system. I have downloaded Ad-Aware and also followed the steps that you suggested and I am still seeing the yellow box pop-up and AWOLA will uninstall and then re-install itself. I have been unable to locate the original file only shortcuts. Also, I have not been able to do any Windows Updates on their system. PLEASE HELP!

Deckard's System Scanner v20071014.68
Run by Owner on 2008-05-16 17:15:41
Computer is in Normal Mode.
--------------------------------------------------------------------------------

Total Physical Memory: 383 MiB (512 MiB recommended).


-- HijackThis (run as Owner.exe) -----------------------------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:15:55 PM, on 5/16/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Documents and Settings\Owner\Applicati... Read more

Answer:AWOLA Removal and Your computer is infected! Popup continuous

Hi, welcome to TSF!

If you still need assistance, please post a fresh main.txt log

1 more replies
Relevance 37.72%

I'm in an identical situation to another post. I'm not sure though if the response to other post was based on the reports or not. So, like the other guy:

Ran all the "READ & RUN ME FIRST" (Win XP) steps. Still have popups from yield sign in tray that say "Your computer is infected!" Also still have Awola Anti-spyware that either Spybot S&D or AVG had detected, and I thought, deleted.

Thank you so much for this forum!! Just let me know if I should simply follow what the other thread described.
 

Answer:AWOLA antispy and "Your Computer is Infected"

Hi kilgore!
I'll take a look at your logs and get back to you. This takes some time, so thanks for your patience. Please don't use your computer too much until we're sure it's clean.
abri
 

14 more replies
Relevance 37.72%

Hello All,I placed this in the wrong forum last week, I home someone can help me.I seem to have a few problems on my PC, no Pop-ups but something has Hi-jacked both my active-desktop and IE 6. IE 6 is un-useable. I also have Awola Anti-spyware message in near the clock. Another that came up today which says it is Window's Security Center says you have been infected with Spyware.My active desktop has been hi-jacked again, it keeps bringing up a default.htm in the on my desktop. (what I have done for this is created a default.htm with a picture in it. So when the process calls up this default.htm it is something I want to look at.) Will explain more if it makes a difference.I also have a LoadLibrary Manager error???? It wants me to send an error report.Here are the steps that I have taken:1. Cleaned out Temporary internet files in IE6 and Cleared private data in Firefox.2. Ran Ad-Aware SE (Crashed several times)3. Ran Spy-Bot Search and Destroy selected all and clicked Fix and repair4. Rebooted and tried running Ad-Aware SE again and it crashed.5. Ran Spy-bot again and downloaded Ad-Aware SE and installed fresh copy.6. Rebooted and ran Ad-Aware SE selected all and quarantined.6. Reboot and ran Ad-Aware SE again. quarantined again.7. Ran Norton Anti-Virus cleaned everything.8. Ran House Call Anti-virus tried to clean.9. Attempted to run Panda and Bit defender to no avail, since IE has been hi-jacked.10. Ran McAfee AVERT Stinger. (really can't tell if it is cleaning anything sinc... Read more

Answer:Spyware That Has Taken Over My Active Desktop And Awola Anti-spyware

Hi,Your system is terribly infected. Problem with these infections nowadays is, it causes a lot of damage. Even if we clean the malware off your system, I can't guarantee that your system will be clean afterwards, because these infections/bundles leave a lot of leftovers behind that most scanners won't even recognise and logs won't show.Also, I can't promise you we can repair all the damage it caused... Even after cleaning the malware, you can still get errors afterwards because of the damage. Solving these is not always possible since it will be searching for a needle in a haystack to find the right cause and solution.So, we can try to clean this up and do what we can, but keep in mind that we can't solve ALL problems this malware already caused.In light of this it would be wise for you to back up any files and folders that you don't want to lose before we start. Reason I am telling this is because when a system is so terribly infected and we try to clean this up manually, the damage that is already present may interfere with our removal attempts. Before you proceed with the following steps, please do this first..Go to this page.Enter the url of this thread in the first field.Where it says, browse to the file that you want to submit, click the browse button next to it and browse to next file:C:\WINDOWS\system32\GE.dllSelect it and click ok:Then click the Send File button below.Then AFTER you did before...* Start HijackThis, close all open windows leaving only ... Read more

6 more replies
Relevance 36.9%

Ran all the "READ & RUN ME FIRST" (Win XP) steps. Still have popups from yield sign in tray that say "Your computer is infected!" Also still have Awola Anti-spyware that either Spybot S&D or AVG had detected, and I thought, deleted.

Attached Combofix and MGTools logs. AVG had no report to save even though I had "Automatically generate report after every scan" checked and "Only if threats are found" unchecked. The only thing AVG found was 9 cookies.

Thanks.
 

Answer:"Your computer is infected!" & Awola

Hi cee3!
Welcome to Major Geeks!

I'm looking at your logs.
abri
 

8 more replies
Relevance 25.83%

Conficker, also known as Downup, Downadup and Kido, is a computer worm targeting the Microsoft Windows operating system that was first detected in November 2008. The worm uses a combination of advanced malware techniques which has made it difficult to counter, and has since spread rapidly into what is now believed to be the largest computer worm infection since the 2003 SQL Slammer.
To start itself at system boot, the worm saves a copy of its DLL form to a random filename in the Windows system folder, then adds registry keys to have svchost.exe invoke that DLL as an invisible network service.
Once infected, it disables Windows Automatic Update, Windows Security Center, Windows Defender, Windows Error Reporting and installs more malware in your computer. It also collects personal information and attach to several processes like svchost.exe, explorer.exe and services.exe. So, How to Remove this Virus? 1. Right-click the Explorer.exe process and choose the option ?Properties?. 2. Click on the ?Threads? Tab, locate and highlight the Conficker DLL files listed below. 3. To kill Conficker DLL files, click the ?Kill? button. 4. Kill the following Conficker DLL files: %System%\[RANDOM FILE NAME].dll 5. Open Regedit 6. Find and Delete HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\{random}\Parameters\?ServiceDll? = ?[PATH OF WORM]? 7. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\{random}\?ImagePath? = %SystemRoot%\system32\svchost.exe -k netsvcs
Source : Tw... Read more

Answer:Learn How to Remove Conficker Virus / Downadup Virus without any Anti-Virus

Thank you Rahul964, I was just wondering how to avoid Conficker
Just kidding, you made a good work

4 more replies
Relevance 25.42%

Topic Title edited to show original Post Title ~KoanYorelHi I posted original post on the 6th July and have not had a replyThanks for any help that may come my wayCheers Johttp://www.bleepingcomputer.com/forums/t/98897/w32-alcra-f-virus-trojan-popper-virus-with-2-downloader-viruss/I am so sorry for double posting for some reason I cant post in the ' havent had a reply in 5 days ?'I have also tried to clean up my computer since the original post so I will put my new HiJack This log in this posting..... hope that isnt a problem.ThanksLogfile of HijackThis v1.99.1Scan saved at 6:22:43 PM, on 13/07/2007Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\csrss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\system32\svchost.exeC:\Program Files\Common Files\Symantec Shared\ccSvcHst.exeC:\WINDOWS\Explorer.EXEC:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exeC:\WINDOWS\system32\spoolsv.exeC:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exeC:\Program Files\Common Files\LightScribe\LSSrvc.exeC:\WINDOWS\system32\NMSAccess.exeC:\WINDOWS\system32\nvsvc32.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\system32\wdfmgr.exeC:\WINDOWS\System32\alg.exeC:\WINDOWS\RTHDCPL.EXEC:\Program Files\HP... Read more

Answer:W32 Alcra F. Virus + Trojan Popper Virus With 2 Downloader Virus's,

Welcome to the BleepingComputer HijackThis Logs and Analysis forum magic23My name is Richie and i'll be helping you to fix your problems.Please download Combofix and save to your desktop:Note: It is important that it is saved directly to your desktop Close any open browsers. Double click on combofix.exe and follow the prompts. When it's finished it will produce a log. Post the entire contents of C:\ComboFix.txt into your next reply. Note: Do not mouseclick combofix's window while it's running. That may cause the program to freeze/hang. Also post a new Hijackthis log please.

9 more replies
Relevance 25.42%

Hey!!! Please help me. About two days ago, my computer got infected with Vista Anti-virus 2011. I spent the whole day trying to remove it, I finally did with the help of Malwarebytes. Its seems to wipe it out until today when Vista Anti-virus emerged again. I ran Malwarebytes and removed it again. Rebooted and ran it again and came up clean. I also ran systematic antivirus and it also came up clean. The only problem now is that about every minute a commercial audio plays without anything else running. Nothing pops up or anything, just the audio file. Also when I try to go in the internet either with internet explorer or firefox, I get alot of redirects. Please help me!!!Please follow the instructions in ==>This Guide<==. If you cannot complete a step, skip it and continue.Then post your DDS and GMER logs as a reply to this topic. Once you have done that I will remove my reply and consolidate the posts so that you retain your correct place in the queue.If you can produce at least some of the logs, then please explain what happens when you try to create the log(s) that you couldn't get. If you cannot produce any of the logs, then still post the reply and explain that you followed the Prep. Guide, were unable to create the logs, and describe what happens when you try to create the logs..DDS (Ver_11-03-05.01) - NTFSx86 Run by Garrett N at 0:51:43.25 on Sat 05/07/2011Internet Explorer: 8.0.6001.19048 BrowserJavaVersion: 1.6.0_22Microsoft? Windo... Read more

Answer:Vista anti-virus (virus) and Commercial Audio virus

Hello and Welcome to the forums! My name is Gringo and I'll be glad to help you with your computer problems. Somethings to remember while we are working together.Do not run any other tool untill instructed to do so!Please Do not Attach logs or put in code boxes.Tell me about any problems that have occurred during the fix.Tell me of any other symptoms you may be having as these can help also.Do not run anything while running a fix.We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.Click on the Watch Topic Button and select Immediate Notification and click on proceed, this will help you to get notified faster when I have replied and make the cleaning process faster.In order for me to see the status of the infection I will need a new set of logs to start with.Please print out or make a copy in notpad of any instructions given, as sometimes it is necessary to go offline and you will lose access to them.DeFogger: Please download DeFogger to your desktop.

Double click DeFogger to run the tool.
The application window will appear Click the Disable button to disable your CD Emulation drivers Click Yes to continue A 'Finished!' message will ap... Read more

28 more replies
Relevance 24.6%

I have an HP running XP.All microsoft updates are current. Adobe Reader is the latest version.I have started in safe mode removed proxy and run both Malware and Super Anti Virus multiple times. Infections included multiple trojans and rogues.Some but not limited to AV, Wireshark, trojan dropper etc.I get pop ups that state "overstack" i also get other pop ups with 000000000000000000000.0000I also had redirect issues on google search but went away when i went in and cleared out the ip it was directing it to. Trojans and rogues keep coming back.Please help.Logfile of Trend Micro HijackThis v2.0.4Scan saved at 1:11:57 AM, on 8/9/2010Platform: Windows XP SP3 (WinNT 5.01.2600)MSIE: Internet Explorer v8.00 (8.00.6001.18702)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exec:\Program Files\Fingerprint Sensor\AtService.exeC:\WINDOWS\system32\svchost.exeC:\Program Files\Windows Defender\MsMpEng.exeC:\WINDOWS\System32\svchost.exeC:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exeC:\WINDOWS\system32\ZoneLabs\vsmon.exeC:\Program Files\CheckPoint\ZAForceField\IswSvc.exeC:\WINDOWS\system32\spoolsv.exeC:\Program Files\CheckPoint\ZAForceField\ForceField... Read more

Answer:AV Virus then WireShark Virus now Google redirect Virus

Hello, and to the Malware Removal forum! My online alias is Blade Zephon, or Blade for short, and I will be assisting you with your malware issues!If you have since resolved the original problem you were having, we would appreciate you letting us know.In the upper right hand corner of the topic you will see a button called Options. If you click on this in the drop-down menu you can choose Track this topic. By doing this and then choosing Immediate E-Mail notification and then clicking on Proceed you will be advised when we respond to your topic and facilitate the cleaning of your machine.Before we begin cleaning your machine, I'd like to lay out some guidelines for us to follow while we are working together.I will be assisting you with your malware issues. This may or may not resolve other problems you are having with your computer. If you are still having problems after your machine has been determined clean, I will be glad to direct you to the proper forum for assistance.Even if things appear better, that does not mean we are finished. Please continue to follow my instructions until I give you the all clean. Absence of symptoms does not mean that all the malware has been removed. If a piece of the infection is left, it can regenerate and reinfect your machine. Attention to detail is important! Since I cannot see or directly interact with your computer I am dependent on you to "be my eyes" and provide as much information as you can regarding the current state of your ... Read more

2 more replies
Relevance 24.6%

I have recently purchased a HP All-In-One computer running Windows 7. This past Friday I chose a link from Google news thinking I was going to a news article. Instead, I was taken to a website that appeared to be a virus scanner. I recognized that this was a scam and X'ed out of the screen. Now the computer is slow when navigating the web and periodically returns to the virus scan scam. The virus shows as AVG8 virus scan.

I've run both Avast virus scan and Malwarebytes malware scanner and both show up with 0 infections.

Can anyone provide me a direction that would eliminate this browsing re-direct problem?

(Ironically, I have an old dell laptop running Windows XP that has the same problem. Since it is old and I got so frustrated I just stopped using it. I bought the All-In-One for my wife for Christmas and now it's doing the same thing.)

Thanks

Answer:AVG Anti-Virus Virus or browser redirect virus

Hello,Please follow the instructions in ==>This Guide<==. If you cannot complete a step, skip it and continue.Once the proper logs are created, then make a NEW TOPIC and post it ==>HERE<== Please include a description of your computer issues and what you have done to resolve them.If you can produce at least some of the logs, then please create the new topic and explain what happens when you try to create the log(s) that you couldn't get. If you cannot produce any of the logs, then still post the topic and explain that you followed the Prep. Guide, were unable to create the logs, and describe what happens when you try to create the logs.Orange Blossom

1 more replies
Relevance 24.6%

Hello,

Well today my brother and his wife were using my computer and when I got on the first thing I was met with was this little problem. A black rectangular box in the middle of my desktop with red lettering stating:

YOUR SYSTEM IS INFECTED!

The program that suddenly showed up on my hard drive is called Advanced Virus Remover. The desktop background has been changed to a plain blue background and the task manager has been blocked by the so called "administrator" even though I am logged into the default admin account.

For an anti-virus on my system I currently use Avast Home Edition but it seems to have been unsuccessful at removing the entire virus and it just keeps coming back. I have not personally had a virus like this in some years now. I want to find a method that is going to COMPLETELY eliminate everything that has been placed onto my PC 100%.

I do have a complete backup of my system made. When I first installed windows XP on my machine I made a complete backup witch I can use if all else fails to completely wipe out this situation. However since I did a complete recovery to my system about a week ago just before I got internet hooked up to it again I really do not want to do everything all over yet again.

Any recommendations to completely rid myself of this garbage is much appreciated.

Answer:Virus alterting me of a virus - Advanced Virus Remover

I appears as if I have removed it completely, but I am always a bit worried whenever something like this happens even it seems to be gone. Any pointers would still be helpful.

2 more replies
Relevance 24.19%

Hello everyone.

I have tried my best to remove this virus on my laptop, but no success yet.

Here are all of the things the virus does:

-Prevents access to websites like spybot, instead of letting me see the site, it simply says "Internet Explorer cannot display the webpage", and there is a button to click that says "Diagnose Connection Problem" (no connection problem of course)

-When I click links from a google search, they most of the time take me to the wrong webpage and I am forced to copy/paste the original link into the web bar.

-Programs like Combofix, Spybot, and HJT do not work and a box comes up after starting them saying "Combofix has stopped working".

-I tried running the programs in Safe Mode, but no luck there.

If anyone knows a fix please reply.

Thanks,

Sean

Answer:Virus prevents access to Anti-Virus sites/anti-virus programs (combofix, etc.)

I renamed my Combofix to something else and I followed the instructions from a different post and here is the log I ended up with:

ComboFix 09-07-29.04 - Sean 07/31/2009 0:30.1.2 - NTFSx86
Microsoft? Windows Vista? Home Premium 6.0.6001.1.1252.1.1033.18.3070.2059 [GMT -7:00]
Running from: c:\users\Sean\Desktop\Music.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\progra~2\MICROS~1\Windows\STARTM~1\Programs\videosoft
c:\progra~2\MICROS~1\Windows\STARTM~1\Programs\videosoft\Uninstall.lnk
c:\program files\videosoft
c:\program files\videosoft\Uninstall.exe
C:\resycled
c:\resycled\boot.com
c:\windows\10057vir9sza2.cpl
c:\windows\1059zpamb5t5bd.exe
c:\windows\1069thi5fz912.bin
c:\windows\1075859zj467.exe
c:\windows\11297vzr5s51c.cpl
c:\windows\1132z5ru977d.cpl
c:\windows\11388troz4559.cpl
c:\windows\1179zs5y695.dll
c:\windows\11991szambo95d9.cpl
c:\windows\120355zoj6819.bin
c:\windows\12324tr9j7b5z.bin
c:\windows\1279zroj295.ocx
c:\windows\12a7d5wnloader999z.bin
c:\windows\132985pz2a0.cpl
c:\windows\133505i9us7z8.exe
c:\windows\13552hackt9ol37z.ocx
c:\windows\1355zw59m5d8.exe
c:\windows\13562vizus1059.cpl
c:\windows\135759orm5c5z.ocx
c:\windows\13599virus6cz5.dll
c:\windows\13614spamzo5990.cpl
c:\windows\13956trojz59.cpl
c:\windows\1502zspy169.ocx
c:\windows\15107zpa9bot54.cpl
c:\windo... Read more

1 more replies
Relevance 23.37%

I have a nasty if not multiple nasty virus's and have not been successful removing them. It started with the XP Anti-Virus 2011 Removal fake anti-virus popping up with all real anti-virus programs disabled and anytime I try to go to an antivirus website I'm redirected to a random site. This happens in all browsers not just Internet Explorer. I also had many of my files changed to hidden file folders and also the start/all programs button does not show any of my programs. I mananged to get both Malwarebytes and Superantispyware on my computer and was able to get rid of much of the problems by running these programs. Now it seems the XP Anti-Virus 2011 has been removed but I still have the issue with my webpages being redirected depending on which page I try to access. I also have many processes that should not be running in the task manager and when i close them out they just start back up again. This worm seems to be accessing my iexplorer because there are multiple iexplorer.exe open at all times and sometimes the CPU Usage gets very high which is not normal for my computer. The final symptom is that at random times I get a webpage pop up or if not a webpage an error that reads like the following example:

An error has occured in the script on this page.

line: 13
Char: 1
Error: Object doesnt support this property or method
Code: 0
URL: http:/www2a.glam.com/mobile/detect.act?affiliatedld=288743725

Do you want to continue scripts on this page?

I will get at ... Read more

Answer:XP Anti-Virus 2011 Fake Anti-VIrus and webpages being Redirected Virus

Hello and welcome to the forums!My secret agent name on the forums is SweetTech (you can call me ST for short), it's a pleasure to meet you. I am very sorry for the delay in responding, but as you can see we are at the moment being flooded with logs which, when paired with the never-ending shortage of helpers, resulted in the delayed responding to your thread.I would be glad to take a look at your log and help you with solving any malware problems.If you have since resolved the issues you were originally experiencing, or have received help elsewhere, please inform me so that this topic can be closed. If you have not, please adhere to the guidelines below and then follow instructions as outlined further below:Logs from malware removal programs (OTL is one of them) can take some time to analyze. I need you to be patient while I analyze any logs you post. Please remember, I am a volunteer, and I do have a life outside of these forums.
Please make sure to carefully read any instruction that I give you. Attention to detail is important! Since I cannot see or directly interact with your computer I am dependent on you to "be my eyes" and provide as much information as you can regarding the current state of your computer.
If you're not sure, or if something unexpected happens, do NOT continue! Stop and ask!
In Windows Vista and Windows 7, all tools need to be started by right clicking and selecting Run as Administrator!
Do not d... Read more

17 more replies
Relevance 23.37%

Antivirus vanished! Can't install ANY new one!Can't access microsoft and any anti virus sites (thus i cannot download or scan my computer from there)I tried to install a copy of avast pro but the set- up immediately close after opening, i also noticed a lot of programs behaving like this just like the bandmaster game from e games and Grand Theft Auto Vice City( once i opened it, it immediately closes)Tried to install that in safe mode, but the computer does not start and reboots back into normal mode.This is the content of DDS logDDS (Ver_10-11-26.01) - NTFSx86 Run by neopc10 at 19:47:12.65 on Fri 11/26/2010Internet Explorer: 6.0.2900.2180Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1023.353 [GMT -8:00]============== Running Processes ===============C:\WINDOWS\system32\svchost -k DcomLaunchsvchost.exeC:\WINDOWS\System32\svchost.exe -k netsvcssvchost.exeC:\WINDOWS\system32\spoolsv.exesvchost.exeC:\Program Files\Common Files\Acronis\Schedule2\schedul2.exeC:\WINDOWS\System32\svchost.exe -k AkamaiC:\WINDOWS\system32\svchost.exe -k imgsvcC:\WINDOWS\Explorer.EXEC:\Program Files\KGB\Mpk.exeC:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exeC:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exeC:\WINDOWS\PixArt\PAC7302\Monitor.exeC:\Program Files\... Read more

Answer:anti virus banished.can't install any anti virus programs, can't acces microsoft and anti virus sites!!!...

Hello and welcome to Bleeping ComputerWe apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.If you have since resolved the original problem you were having, we would appreciate you letting us know. If not please perform the following steps below so we can have a look at the current condition of your machine. If you have not done so, include a clear description of the problems you're having, along with any steps you may have performed so far.Upon completing the steps below another staff member will review and take the steps necessary with you to get your machine back in working order clean and free of malware.If you have already posted a DDS log, please do so again, as your situation may have changed.Use the 'Add Reply' and add the new log to this thread.Thanks and again sorry for the delay.We need to see some information about what is happening in your machine. Please perform the following scan:Download DDS by sUBs from one of the following links. Save it to your desktop.DDS.scrDDS.pifDouble click on the DDS icon, allow it to run.A small box will open, with an explaination about the tool. No input is needed, the scan is running.Notepad will open with the ... Read more

2 more replies
Relevance 22.96%

Hi,

Please help!

I have a Fake Virus Alert Visus on my PC.

When booting the machine it comes up as:
" Application cannot be started - the file wltuser is damaged. Do you want to activate Antivirus now?"

Internet Explorer will then be locked and will only link to the Fake AntiVirus software.

Can someone please help? I have ran Malewarebytes a few times but it has not worked. I am currently in Safemode and re-running once again.

Thank you very much!

Answer:Virus - false Virus Protection Virus

Lots of people have been getting this recently. Is it similar to Vista Internet Security 2011? Thats the one i got. Dunno if it matters if urs is windows 7 or xp. When it pops up and the the shield icon shows up in the taskbar tray, open task manager. Look for .exe's pw.exe and MSASCui.exe. For me it was uuj.exe.

Right click on it and then click open file location. If you cant see it, then go into folder options and click show hidden files and show system files too. Once u can see it, u can delete it.

The pop up should be gone now but you still wont be able to load you .exes. You can only use them by running as admin.

So click start and type in regedit. Right click on it and run as admin.

In regedit look for these entries;
HKEY_CURRENT_USER\Software\Classes\pezfile
HKEY_CLASSES_ROOT\pezfile
HKEY_CURRENT_USER\Software\Classes\.exe\shell\open\command "(Default)" = "%UserProfile%\Local Settings\Application Data\pw.exe" /START "%1" %*
HKEY_CURRENT_USER\Software\Classes\pezfile\shell\open\command "(Default)" = "%UserProfile%\Local Settings\Application Data\pw.exe" /START "%1" %*

For me, i could only find the third one. I deleted replaced it with "%1" %*

Then i downloaded and used that vista/windows7 exe fix from this site and fixed the problem
http://www.winhelponline.com/articles/105/1/Fil... Read more

2 more replies
Relevance 22.96%

so i have registry cleaner installed because ive been getting the blue screen of death and i heard it helps ( no help)
i have Malwarebytes' Anti-Malware and its pretty good,removes viruses and all
and i JUST installed Safereturner

ok so everytime i run MAM it says only 1 infected (torjan.bubnix) remove and restart. i restart and run again...still there! so i install safe Returner and it found viruses in dell and quicktime and stuff but no malware found no bubnix found....so i restart and run MAM AGAIN and still have Trojan.bubnix.
i think that has been the reason for my re-occuring blue screens of death and looooads of spam e-mail! i really am sick and tired and i need it installed fast,easy and free,pleeeeeeeeeeeeease help!

Answer:apparently i have a virus? one virus and two virus removers...help!

Please follow the instructions in ==>This Guide<==. If you cannot complete a step, skip it and continue.Once the proper logs are created, then make a NEW TOPIC and post it ==>HERE<== Please include a description of your computer issues and what you have done to resolve them.If you can produce at least some of the logs, then please create the new topic and explain what happens when you try to create the log(s) that you couldn't get. If you cannot produce any of the logs, then still post the topic and explain that you followed the Prep. Guide, were unable to create the logs, and describe what happens when you try to create the logs.

2 more replies
Relevance 22.55%

My anti-virus said it removed a trojan. When I restarted my computer my anti-virus was turned off and it won't turn back on. I ran MalwareBytes and I didn't find anything, so I need some help.

Answer:Anti-virus removed virus now anti-virus won't turn back on.

DownloadTDSSkillerLaunch it.Click on change parameters-Select TDLFS file systemClick on "Scan".Please post the LOG report(log file should be in your C drive) Do not change the default options on scan resultsDownloadaswMBRLaunch it, allow it to download latest Avast! virus definitionsClick the "Scan" button to start scan.After scan finishes,click on Save logPost the log results hereDownloadESET online scannerInstall itClick on START,it should download the virus definitionsWhen scan gets completed,click on LIST of found threatsExport the list to desktop,copy the contents of the text file in your reply

11 more replies
Relevance 22.14%

Hello
I have been experiencing some problems with my computer recently. Firstly, my virus scanner (AVG) keeps on finding a virus called 'not-a-virus:RemoteAdmin.Win32.WinVNC-based.f' and some trojans called 'Trojan.JavaClass'. I have also been getting random pop-ups whenever I have been browsing the internet, and my computer seems to be running very sluggish, especially at startup.

I also believe that, last week, someone gained remote access to my computer, as all of a sudden, my mouse wouldn't move properly and the computer became really slow. This only stopped when I engaged the internet lock on my Zonealarm firewall.

Today, I was asked by Zonealarm to give a program called spoolsv.exe "access to privileged rights" which I have never seen before for this program. When I looked at the properties of spoolsv.exe, it said that it was created in 2006 but modified in 2005 (???), and so therefore didn't allow the program access. (I don't know if that has anything to do with the problems that I am having but thought I would mention it)

I have done "the 5 things you need to do" before posting a blog; here are the files requested:

Panda Scan:

Incident Status Location ... Read more

Answer:[SOLVED] &quot;not-a-virus&quot; virus and &quot;javaclass&quot; trojan keep appearing on virus scans

Bump.

4 more replies
Relevance 22.14%

Logfile of Trend Micro HijackThis v2.0.2Scan saved at 1:57:03 PM, on 9/9/2009Platform: Windows XP SP3 (WinNT 5.01.2600)MSIE: Internet Explorer v7.00 (7.00.6000.16876)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\Program Files\Common Files\Symantec Shared\ccSetMgr.exeC:\WINDOWS\Explorer.EXEC:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exeC:\Program Files\Lavasoft\Ad-Aware\AAWService.exeC:\WINDOWS\system32\spoolsv.exeC:\WINDOWS\system32\Brmfrmps.exeC:\WINDOWS\System32\GEARSec.exeC:\Program Files\Java\jre6\bin\jqs.exeC:\Program Files\Dell Support Center\bin\sprtsvc.exeC:\WINDOWS\system32\svchost.exeC:\Program Files\Viewpoint\Common\ViewpointService.exeC:\WINDOWS\system32\SearchIndexer.exeC:\WINDOWS\system32\wscntfy.exeC:\WINDOWS\system32\BRMFRSMG.EXEC:\WINDOWS\system32\hkcmd.exeC:\WINDOWS\system32\igfxpers.exeC:\Program Files\Java\jre6\bin\jusched.exeC:\Program Files\Dell\Media Experience\DMXLauncher.... Read more

Answer:Please diagnose Hijackthis log: Personal Guard 2009 virus (fake anti-virus)

DDS (Ver_09-07-30.01) - NTFSx86
Run by Admin at 14:22:35.14 on Wed 09/09/2009
Internet Explorer: 7.0.5730.13
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1270.580 [GMT -4:00]
============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\WINDOWS\system32\Brmfrmps.exe
C:\WINDOWS\System32\GEARSec.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\BRMFRSMG.EXE
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Progra... Read more

3 more replies
Relevance 22.14%

I got this nasty virus but I have no idea how to get it out, I can't run into safe mode because it restarts my computer and it keeps doing that. Ill post up a HiJackThis log PLEASE HELP! I am still a beginner so please bare with it. The problems that I know/see on my computer is that, I have restricted admin rights so I cant use System Restore or the task manager, Also my anti-virus keeps disabling and its Macafee if you want to know.
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\Stardock\SDMCP.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\UPHClean\uphclean.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\AGRSMMSG.... Read more

More replies
Relevance 22.14%

Hi seem something got into my computer!!!
  Noticed yesterday my Norton’s popup said it caused an error and had to close. I rebooted the computer and ran a scan, came up fine? I notice my pointer would blink back and forth to the hourglass. I opened my task manager and it seems to be switching with the CSRSS.EXE & N360.EXE (CPU) counter jumping up and down, FAST! Never saw anything like it before, usually what just system idle, maybe Firefox??? I tried running Norton's again, I really forget if it crashed or didn't do anything. Tried the standard online virus scans and ran into all kinds of troubles. Some seem to start to load and then the popup window disappeared? Think it was Kasp., when I reloaded it, it ran and found nothing! Others froze or crashed, restarted the computer, without finishing. It seems to have gotten worse, the last few time I looked at the Task Manager and I see
 
CSRSS.exe       KSS.EXE       N360.EXE       AVG***.exe
 
All these (CPU) counts are jumping up and down I have never seen my task manager list jumping so much! It seems so much worse now that I tried all these scans, even with the computer freezing and crashing now. I rebooted in safe mode and came right here. You help me once so long ago and hope you can again! One thing, now when I look at the Task Manager, all those virus program names are gone, list is very short.  Plus (C... Read more

Answer:virus chk, no run! Task Manager show CSRSS.EXE & Virus prgs crazy switching??

Are you really surprised? You have kaspersky, norton, and AVG installed. There I was thinking that I like a bit of tin foil head gear. The executable CSRSS.exe as you typed it has reputation for being exploited, and although it should be a legit bit of XP, it could also be a trojan according to some of the webz? This support article from Micro$oft may be more practical/applicable use to you, and they suggest that it's caused by a corrupt user profile. The suggested remedy is to delete your user account after backing up stuff, and then restart followed by re-creating your user account.
 
PS
 
Being a Linux user I'd have to chip in as to why don't you try a linux live DVD/USB, there is no need to make changes to your hard drive or computer with the possible exception of changing the BIOS boot order. If you cannot afford a hardware/software upgrade then just boot into free linux, and try it out. There is no obligation to buy, and little/no risk of damage. Visit the BC linux forums, where people are very friendly and helpful.
 
windows XP ==
 
Linux ==

22 more replies
Relevance 22.14%

Please can anyone help me clear my laptop of whatever has hijacked it. It blue screens on me and will only access the internet with add ons disabled. It completely locked me out at first but used malware removal and found yura 94.exe I have tried using several malware removal tools since but think I need to leave it to you experts as it really seems to be in a mess and i can't fix it !!!!
Thank You in anticipation.
Here is the HJT log.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:31:12, on 27/09/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Acer\Empowering Technology\admServ.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\NCH Software\Fling\fling.exe
C:\Program Files\Kontiki\KService.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\lxdicoms.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Pro... Read more

More replies
Relevance 22.14%

Hello, i'm new to this site, so if i say something stupid please be understanding.
(i'm running vista to clarify)

I had a while ago gotten a virus which would play sounds randomly, and i was able to temporarily fix it by going to task manager and killing the process. after a while the virus stopped bugging me (i guess the antivirus software caught the culprit.)

recently i downloaded an installer, and it happened again. this time i hit ctrl alt del, and task manager had been removed from the list. i tried accessing it through control panel and it told me it had been blocked by the administrator (me) i then looked up how to re-enable it, and went to run REGEDIT and that was blocked too. i've tried several scripts to re-enable regedit, all to no avail.

whenever the sound stops playing i get a message saying:
"Host Process for Windows Services stopped working and was closed

A problem caused the application to stop working correctly. Windows will notify you if a solution is available."

i also found these 2 files in system configuration: BtwSrv (by Microsoft Corporation) and fastnetsrv Service (by Sigma Designs Inc)

I googled the second one, and found it to be a virus (yayy google!)
I am unsure about how to remove these, and i also found several remote applications which i would like to disable... help would be appreciated

McAfee identified a virus and removed it, however it keeps re-appearing

Detected: Artemis!F245638D7283 (Trojan),
Artemis... Read more

Answer:Random Sound Virus + Registry editor and task manager disabled by virus

Hello and Welcome.

We want all our members to perform the steps outlined in the link I'll give you below, before posting for malware removal assistance. There's a sticky at the top of this forum, and a
Quote:




Having problems with spyware and pop-ups? First Steps




link at the top of each page.

---------------------------------------------------------------------------------------------

Please follow our pre-posting process outlined here:

http://www.techsupportforum.com/f50/...lp-305963.html

After running through all the steps, you shall have a proper set of logs. Please post them in a new topic, as this one shall be closed. I currently have as many open topics as I can effectively handle; this will have you back in queue with the proper logs so an available helper would be able to assist.

If you have trouble with one of the steps, simply move on to the next one, and make note of it in your reply.

Please note that the Virus/Trojan/Spyware Help forum is extremely busy, and it may take a while to receive a reply.

1 more replies
Relevance 22.14%

Hi. I am new here. I have had constant problems with my computer crashing for over two weeks. Also I have noticed that I haven't been able to update my anti virus software...both ad aware se personal and avg 7 free have not been able to update for some 16 days now.
I have run your recommended online scanners, pandasoftware, housecall, and macafee. I believe macafee discovered the WIN32.ATAK.B and NEW POLYWIN 32 viruses, but said it could not remove them.
something seems to be eating up my ram, simple rendering tasks cause my computer to crash now.

I have updated to windows sp1a. I am running windows xp pro. I would appreciate any help.

here is my hijack this log.

Logfile of HijackThis v1.99.1
Scan saved at 18:47:14, on 19/06/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\system32\AvidSDMService.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\WINDOWS\System32\sv... Read more

Answer:virus WIN32.ATAK.B, NEW POLYWIN 32 viruses, can't update anti-virus software

HijackThis!
Open Hijack This and click on Scan. Check the following entries (make sure you do not miss any)
F3 - REG:win.ini: load=???
??? ???
?
? ?????
F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe
O16 - DPF: {FF3F0F03-0F01-131A-A3F9-08F02B23E0CC} - http://66.117.37.13/dba1402.exe

Please remember to close all other windows, including browsers then click Fix checked.

Online Scans
Perform an online scan with Internet Explorer with Panda ActiveScan
** click on "Free use ActiveScan" located on the top right hand corner Click Scan your PC & a 'pop up' window shall appear. *ensure that your pop up blocker doesn't block it
Click Scan Now
Enter your e-mail address & click Scan Now ...begins downloading 8 MB Panda's ActiveX controls
Begin the scan by selecting My Computer If it finds any malware, it may ask you to purchase the program, this is not necessary we will take care of the entries manually.
At the end of the scan click on see report. Then click Save report
Please post that log in your next reply.

In your next post please include:Panda Activescan Log
A new Hijackthis! Log

19 more replies
Relevance 22.14%

Operating System: Windows XP

I'm hoping that someone can help me! I am also getting three pop-up messages on my system. One is to download anti-virus software, another is a warning about the Blackworm virus, and the third is an Adult Friend Finder pop-up. My hijack this log:
Logfile of HijackThis v1.99.1
Scan saved at 5:05:45 PM, on 4/4/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\windows\system\hpsysdrv.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\System32\VTTimer.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe
C:\Program Files\Lexmark X74-X75\lxbbbmon.exe
C:\Program Files\Support.com\bin\tgcmd.exe
C:\Program Files\Charter High-Speed Security Suite\Common\FSM32.EXE
C:\Program Files\Clarisys\Claritel-i750\Ipnappgw.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\KODAK\Kodak EasyShare software\bin\EasyShare.exe
C:\PROGRA~1\CHARTE~1\backweb\3528733\Program\SERVIC~1.EXE
C:\WINDOWS\system32\drivers\dcfssvc.exe
C:\Program Files\Charter High-Speed Security Suite\backweb\3528733\Program\fspex.exe
C:\Program Files\Charter High-Speed Security Suite... Read more

Answer:Solved: Blackworm virus, anti-virus software and Adult Friend Finder pop ups

9 more replies
Relevance 22.14%

Hello,I'm usually good enough with my computer to avoid and/or repair these kinds of things on my own, but have never had this.It changed my desktop background from a picture to text warning me about malicious content, and at the same time my Windows Update icon flashed red, and my AVG anti-virus warned me about the bugs.Ad-Aware found and removed/quarantined some of them. AVG found and removed others.My task manager still runs properly and found a few programs that looked suspicious "fff.exe", "msctrl.exe", "16627184.exe", & "EtEngineU.exe".I run daily scans for all of my anti-virus and ad-aware, and nothing has come up previous to this stuff today, so I know it's new.One pop-up that looked like it came with a new Windows XP update I downloaded claimed it was "Windows Total Security" and that it would clean up malicious content, but that I'd have to pay.Thankfully I wasn't stupid enough to fall for that, just stupid enough to get it on my computer.I deleted a bunch of those programs from my task manager (ended the process tree completely), removed the programs from the control panel, searched out the files in "My computer" > "C:" > "System", etc.However, there are items in "startup" when I run "MSCONFIG" with the same names that claim they're going to run as soon as I start the program up again.I ran HJT, and the other scans this site recommends before posting a new ... Read more

Answer:Total Security virus - FFF.exe virus, 16627184.exe, EtEngineU.exe, perdm32.exe, msctrl.exe, & other viruses

Hello and welcome to Bleeping ComputerWe apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.If you have since resolved the original problem you were having, we would appreciate you letting us know. If not please perform the following steps below so we can have a look at the current condition of your machine. If you have not done so, include a clear description of the problems you're having, along with any steps you may have performed so far.Upon completing the steps below another staff member will review and take the steps necessary with you to get your machine back in working order clean and free of malware.If you have already posted a DDS log, please do so again, as your situation may have changed.Use the 'Add Reply' and add the new log to this thread.Thanks and again sorry for the delay.We need to see some information about what is happening in your machine. Please perform the following scan:Download DDS by sUBs from one of the following links. Save it to your desktop.DDS.scrDDS.pifDouble click on the DDS icon, allow it to run.A small box will open, with an explaination about the tool. No input is needed, the scan is running.Notepad will open with the results.Foll... Read more

2 more replies
Relevance 22.14%

hi all,

please help me solve my computer problem, because i have this so called trojan horse virus, tracking cookie. adbrite etc...i already do the scanning using my anti virus software called symantec anti virus corporate edition...i scan my pc in safe mode, and i turn off system re store..my anti virus software doesnt detect the virus, but the avg anti spyware detect it, i already deleted it all but when i go back to noramal window, my symantec antivirus auto protect is still disabled, iaso tried uninstalling the anti vius software and install it again but still cannot, the virus is still there ..what should i do? bec if my anti virus auto protect is disabled, my computer is at risk because i often connect to the internet and i might get so many viruses that will destroy my pc.. PLease help me...
 

Answer:trojan horse virus has disabled my symantec anti virus auto protect

Welcome to Major Geeks!

Cookies are not problems and cookies would also not be able to disable your antivirus.

Please work thru the below procedure and attach the requested logs when you finish:

Read & RUN ME FIRST Before Asking for Support
 

1 more replies
Relevance 22.14%

I hope that this is in the right section but I am having a problem with my computer. I can constantly hear programs running in the background. I currently have two anti spyware/malware installed on my computer. One is SpyHunter and the other is CyberDefender. They both are picking up on some virus called Vundo and everytime I delete it, it just comes right back. It is so frustrating surfing the internet because it freezes or moves extra slowly. Figured I'd ask you guys before I take a hammer to it lol.

Thanks

Answer:Windows XP SP2 running slow, virus protection catches it but the virus keeps coming back

Hello,i am moving yjis to the Am I Infected forum from XP.Please disable those apps while we do this.Next run MBAM (MalwareBytes):NOTE: Before saving MBAM please rename it to zztoy.exe....now save it to your desktop.Please download Malwarebytes Anti-Malware and save it to your desktop.alternate download link MBAM may "make changes to your registry" as part of its disinfection routine. If using other security programs that detect registry changes (ie Spybot's Teatimer), they may interfere or alert you. Temporarily disable such programs or permit them to allow the changes.Make sure you are connected to the Internet.Double-click on mbam-setup.exe to install the application.When the installation begins, follow the prompts and do not make any changes to default settings.When installation has finished, make sure you leave both of these checked:Update Malwarebytes' Anti-MalwareLaunch Malwarebytes' Anti-MalwareThen click Finish.MBAM will automatically start and you will be asked to update the program before performing a scan.If an update is found, the program will automatically update itself. Press the OK button to close that box and continue.If you encounter any problems while downloading the definition updates, manually download them from here and just double-click on mbam-rules.exe to install.On the Scanner tab:Make sure the "Perform Quick Scan" option is selected.Then click on the Scan button.If asked to select the drives to scan, leave all the drives selected and click on the St... Read more

9 more replies
Relevance 22.14%

Hi,

Virus doesn't allow me to startup my computer, apparently even if safe mode.

Symptoms were:
- Pseudo-anti virus program launched itself, and gave spurious results
- Messages were displayed in red over the screen background
- I rebooted, and could no longer run browsers or other programs, including Norton
- Rebooted again, and no screen display
- Tried to reboot in safe mode, but that appears not to work also
Help!
 

More replies
Relevance 22.14%

Windows XP Machine IE 7
Noticed a few days ago that whenever I was doing google searches I would find my item, click the hyperlink and was supposed to go to the intended website, but instead would hit a variety of Porn, Healthcare, Pharmacy etc website having nothing to do with my search criteria.

I had McAfee installed at the time but found that it had not updated itself in a few days and when I tried to run it for virus scans it wouldnt work. Finally removed the program and tried a number of others: Kasperia, Ad Aware, etc. The same problem exists in all of them.....I install it, I try to start a scan and either it starts scanning and then just disappears from my screen a few seconds later (program stopped and is gone from screen - try to restart and either it crashes instantly or does the same each time) or I cannot even click the scan button (it just doesnt do anything when you press it over and over again).

Have been for last few days reading through website help forums and downloading various programs to ID, fix etc...with little results.

Hijack installs and when I click the .exe file it gives me a popup error saying:

Windows cannot access the specific device, path, or file. You may not have the appropriate permissions to access the item.
I have managed to get Win32kDiag.exe to work with a log.....I currently have Erunt, HijackThis, SysRestorePoint, TFC, MGADiag, and Malware Bytes programs on my desktop.

Maleware is doing same as all other scanners....Either star... Read more

More replies
Relevance 22.14%

Accidental double post.  Here is the link to my real thread: http://www.bleepingcomputer.com/forums/t/524143/virus-possibly-paladin-virus-avoids-all-scanners-and-crashes-desktop-on-start/Edit: Merged two topics for continuity of context and MR Team topic management.~ Animal

Answer:Virus (possibly Paladin virus) avoids all scanners and crashes desktop on start

Computer: Windows Vista 64 bit / / Dell XPS 420
 
Problems started occurring out of the blue when I tried to resume my computer from sleep mode and it froze. I had not downloaded anything recently, not anything I was aware of anyway. My computer has had several corrupted files that contained error messages on start up. I have been able to fix these but my computer freezes soon after I start up. I am only able to access safe mode. 
 
I have been able to remove 42 entries of malware via Spybot. And 1 virus via Avast. The virus was called Paladin. However, in my virus chest there are multiple entries each named unknown, all with the same date of quarantine. Despite my quarantining of this virus, a [Paladin] program still pops up very briefly in normal mode in my start-up tray. 
 
I have been able to install and update a number of anti-virus and malware removal programs despite being infected. Although initially, the virus had somehow removed Adwcleaner, I was able to reinstall it and scan my registry. The problem, however, was not fixed. For some reason, despite downloading them, I have been unable to fully install Avira Anti-virus and am unable to get AVG to run.
 
Everything else comes up with zero results despite continuing problems. MRT says I have 1 infected file on a Full Scan, however, it always locks up when attempting to scan: D:\dell\Image\Factory.wim\Windows\Help\Windows\en-US\mail.wmv
Custom and quick scans yield no results.
 
... Read more

41 more replies
Relevance 22.14%

Here is teh log, I think I have a redirect virus, it seems like every uyahoo or google search I do the links take me to random places, I also cannot access my virus scanner or its update. Also teh computer is running very slow. Logfile of Trend Micro HijackThis v2.0.2Scan saved at 11:40:28 AM, on 4/22/2009Platform: Windows XP SP3 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)Boot mode: NormalRunning processes:E:\WINDOWS\System32\smss.exeE:\WINDOWS\system32\winlogon.exeE:\WINDOWS\system32\services.exeE:\WINDOWS\system32\lsass.exeE:\WINDOWS\system32\svchost.exeE:\WINDOWS\System32\svchost.exeE:\WINDOWS\system32\spoolsv.exeE:\Program Files\Java\jre6\bin\jqs.exeE:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exeE:\WINDOWS\system32\nvsvc32.exeE:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exeE:\WINDOWS\system32\HPZipm12.exeE:\WINDOWS\system32\svchost.exeE:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exeE:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exeE:\PROGRA~1\TRENDM~1\INTERN~1\PcScnSrv.exeE:\WINDOWS\Explorer.EXEE:\Program Files\HP\ToolBoxFX\bin\HPTLBXFX.exeE:\Program Files\Java\jre6\bin\jusched.exeE:\Program Files\Sharp\Shar... Read more

Answer:Hijackthis log I have a redirecting virus that wont allow virus scanners or internet explorer to work

Hello and welcome to Bleeping ComputerWe apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.If you have since resolved the original problem you were having, we would appreciate you letting us know. If not please perform the following steps below so we can have a look at the current condition of your machine. If you have not done so, include a clear description of the problems you're having, along with any steps you may have performed so far.Upon completing the steps below another staff member will review and take the steps necessary with you to get your machine back in working order clean and free of malware.If you have already posted a DDS log, please do so again, as your situation may have changed.Use the 'Add Reply' and add the new log to this thread.Thanks and again sorry for the delay.We need to see some information about what is happening in your machine. Please perform the following scan:Download DDS by sUBs from one of the following links. Save it to your desktop.DDS.comDDS.scrDDS.pifDouble click on the DDS icon, allow it to run.A small box will open, with an explaination about the tool. No input is needed, the scan is running.Notepad will open with the resul... Read more

2 more replies
Relevance 22.14%

Hi, my computer was struck with that hideous virus AntiMalware and its various forms such as Trojan-Downloader.JS.Multi.ca and Virus.Win32.Gpcode.ak. I kept getting frequent messages or Security Center alerts whenever I used my computer saying those trojans were present and I had to install their program. I managed to stop getting those alerts by deleting some entries from a HijackThis scan such as -ex_08.exe and others stored in the temp folder in the scan that seemed suspicious and those that I verified on Google as trojans. But I still can't use system restore, malwarebytes antimalware program or super anti spyware. I went into safe mode and everything I described above as well trying to install Malware bytes but it's stuck at finishing installation. It just doesn't work so I cant remove all the malware. Im posting a Hijackthis log. Please help.

Answer:AntiMalware program infection and virus disabled all antispyware/virus/malware programs

Hello , And to the Bleeping Computer Malware Removal Forum. My name is Elise and I'll be glad to help you with your computer problems.I will be working on your malware issues, this may or may not solve other issues you may have with your machine.Please note that whatever repairs we make, are for fixing your computer problems only and by no means should be used on another computer.You may want to keep the link to this topic in your favorites. Alternatively, you can click the button at the top bar of this topic and Track this Topic, where you can choose email notifications. The topics you are tracking are shown here.-----------------------------------------------------------If you have since resolved the original problem you were having, we would appreciate you letting us know. If not please perform the following steps below so we can have a look at the current condition of your machine. If you have not done so, include a clear description of the problems you're having, along with any steps you may have performed so far.If you have already posted a DDS log, please do so again, as your situation may have changed.Use the 'Add Reply' and add the new log to this thread.We need to see some information about what is happening in your machine. Please perform the following scan:Download DDS by sUBs from one of the following links. Save it to your desktop.DDS.scrDDS.pifDouble click on the DDS icon, allow it to run.A small box will open, with an explanation about the tool. No inp... Read more

2 more replies
Relevance 22.14%

My computer: Dell Inspiron 15inch Windows 8 64bit 500gb hardisk
 
 
I have this virus that will established connection to remote hacker and download virus etc. Currently Im using Sterjo Netstalker to block suspicous connection and its many. I believe its a rootkit virus that hide inside hard disk if not anything else. I have only 1 harddisk attach and I even flash bios and format hardisk. I use to format using DBAN nuke despite not finish (it takes 20 hour) though have gone 1 round and 2 pass but the virus is back after fresh Windows 8 install.
 
Its annoying as it slow down internet and keep use up my hard disk and its getting hot. I wish to remove this virus or had to buy new PC. I attach GMER scan here
 
Too bad though I take prevention step by using AVG and disabled my laptop wireless device and using external usb wireless instead. In the attachment you cant see the real original virus before like its infected svchost and create "auxiliaryseed..." inside the value something like that. But now maybe just ignore the AVG and see around if you can find anything in the attachment. Help much appreciated.
 
Thank you

Answer:rootkit virus csrss, svchost spyware virus hidden in hardisk even reformat

Hi there,my name is Marius and I will assist you with your malware related problems.Before we move on, please read the following points carefully. First, read my instructions completely. If there is anything that you do not understand kindly ask before proceeding. Perform everything in the correct order. Sometimes one step requires the previous one. If you have any problems while following my instructions, Stop there and tell me the exact nature of your problem. Do not run any other scans without instruction or add/remove software unless I tell you to do so. This would change the output of our tools and could be confusing for me. Post all logfiles as a reply rather than as an attachment unless I specifically ask you. If you can not post all logfiles in one reply, feel free to use more posts. If I don't hear from you within 3 days from this initial or any subsequent post, then this thread will be closed. Stay with me. I will give you some advice about prevention after the cleanup process. Absence of symptoms does not always mean the computer is clean. My first language is not english. So please do not use slang or idioms. It could be hard for me to read. Thanks for your understanding.   Scan with aswMBRPlease download aswMBR ( 4.5MB ) to your desktop.Double click the aswMBR.exe icon, and click Run.There will be a short delay before the next dialog box comes up. Please just wait a minute or two.When asked if you'd like to "download the latest Avast! virus definit... Read more

16 more replies
Relevance 22.14%

OK i just got into the Econo Lodge hotel i got my computer and i started to realize it would keep getting hot. So sometimes it would crash or go into hibernation. But now its worse the computer keeps shutting down like in sleep mode where the screen dims and the wireless button becomes red accept now it shuts off is my harddrive shot or is there a remote accesser or worm in this. Let me note i do download ROMS and emulators but are these the cause. Even when my computer is just 34 or 48 degrees Faranheit it will do shall i call it a "sleep-mode shutdown" is this my BIOS doing a fail-safe worm by someone or is my hard-drive shot or is someone invading my computer and infecting it or remotely hacking and shutting it off with a .BAT i should also tell you i am in Safe Mode with Networking while i post this and my computer is Windows 7 Ultimate bought in 2007 and upgraded to Win7 2009.

Thank you. Ryan

- I will post a log as soon as i get a reply with what to do.

EDIT: I also get my ROMs from Emuparadise.com and since i use a hotel wireless access point i get a lot of pop-ups.

Answer:Weird virus??? (Remote access/WIN32.Worm/file virus/SHUTDOWN.exe PLEASE HELP)

My guess is your computer is getting to hot and being shutdown to protect it.

1 more replies
Relevance 22.14%

Hello,I've been figthing with this for some time now, with no joy. I found that somebody has an identical problem here: http://www.bleepingcomputer.com/forums/topic279534.html So in any broswer (MSIE8, Firefox, Chrome etc), google search results are hijacked to searchwebnet.info, and then redirected to various other locations - e.g. it seems the first point is searchwebnet.info, and then my browser makes a couple of other hops, before it eventually lands on some dodgy site. Results from search engines other than Google (e.g. Yahoo! or Bing), are not hijacked.Also, same as described in the topic above, MSIE sometimes doesn't start, or sometimes bluescreens my machine when I attempt to run it.One thing I noticed, whether is relevant or not, when the redirection happens, in windows task manager I see SearchProtocolHost.exe process starting up. And staying there, running..Interestingly, my problem also started happening around 17th Dec 2009, which is the date when the above topic was posted. Any help is greatly appreciated!

Answer:Unknown redirect virus(es?), A virus that often redirects to searchwebnet.info from google results 2

Please find my DDS.txt pasted below (created with AV & AS software off, and with network off). I've attached DDS' Attach.txt zipped, and NT Boot Log, if it's of any help.Many thanks!DDS (Ver_09-12-01.01) - NTFSx86 Run by Owner at 23:32:13.41 on 29/12/2009Internet Explorer: 8.0.6001.18865 BrowserJavaVersion: 1.6.0_15Microsoft? Windows Vista? Business 6.0.6002.2.1252.1.1033.18.1021.296 [GMT 0:00]SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}============== Running Processes ===============C:\Windows\system32\wininit.exeC:\Windows\system32\lsm.exeC:\Windows\system32\svchost.exe -k DcomLaunchC:\Windows\system32\svchost.exe -k rpcssC:\Windows\system32\Ati2evxx.exeC:\Windows\System32\svchost.exe -k LocalServiceNetworkRestrictedC:\Windows\System32\svchost.exe -k LocalSystemNetworkRestrictedC:\Windows\system32\svchost.exe -k netsvcsC:\Windows\system32\svchost.exe -k GPSvcGroupC:\Windows\system32\SLsvc.exeC:\Windows\system32\Ati2evxx.exeC:\Windows\system32\svchost.exe -k LocalServiceC:\Windows\system32\svchost.exe -k NetworkServiceC:\Windows\System32\spoolsv.exeC:\Windows\system32\svchost.exe -k LocalServiceNoNetworkC:\Windows\syste... Read more

3 more replies
Relevance 22.14%

hello guys/gals. this is my first post here. wonderful helpful site you have here ! thanks !
alright i may provide too much info, but i figure too much is better than not enough.
for starters, my wife's cousin was using my laptop to do online school work when the screen went blank, then changed to a solid red screen. all of those fake "windows restore" type error messages started popping up saying things such as failed hard drive, etc. then it started doing this scan and showed all of these problems that it detected. it prompted you to purchase their "bogus" program. luckily i was home and told her that was not legit and to avoid that. i grabbed the laptop from her, closed all of these 60 or so error messages, closed out this fake scan screen, and rebooted my pc. after reboot, everything appeared to be gone. my desktop icons were gone, my desktop image was gone and replaced with a solid red screen, everything in my start menu was gone.

i quickly realized that everything was not gone, but whatever had infected my computer had "hid" everything. i shut down again and hit my f8 key to reboot into safe mode. i have windows xp professional (5.1,build 2600) 32-bit. after hitting my f8 key, it pulled up the "windows advanced options menu" where i selected "safe mode with networking" so that i could troubleshoot and research the internet from the safety of safe mode. after selecting "safe mode with networking", i... Read more

Answer:possibly had / have root kit virus or restore / recovery virus that hid EVERYTHING and would not allow me access to safe mode

adding update. following your "remove system restore (uninstall guide)" in the exact order it was listed, after posting my initial post as suggested, i continued on to the next steps. i downloaded malwarebytes and ran a full system scan. here is a copy of the notepad txt file created with threats detected placed here as an attachment. i removed these threats as directed and restarted pc when malwarebytes prompted me to. my question is do i still need to run your step 19 which is to run the unhide.exe program ? i'm asking that because it APPEARS that everything is working like it should after me running the "pc recovery". i am now going to leave safe mode and reboot into normal mode without running unhide.exe, hopefully that will be ok. thanks again.

17 more replies
Relevance 22.14%

Received a link to clik from business colleague. I started receiving messages from friends on my Facebook buddy list asking me why I would send them a link to clik on. Apparently, the links are different but my McAfee said it blocked it when I tried to download whatever he sent me. I started getting virus alerts to download programs to clean it, which I knew was not from McAfee. I performed a manual scan and it found 6 virus and malwares which were quarantined. One of my friends said that her McAfee didn't even detect anything and had to pay them to get deep into her computer to get rid of it. Today, I awoke to find a similiar ploy to download a virus and malware program to rid my problems. I print screened and am posting that. I again ran a McAfee virus scan and it found 4 which again were quarantined.

How can we get rid of whatever is causing this?

I ran a Lavasoft Ad Aware scan which detected 2 cookies and were removed. I also ran Spybot Search & Destroy which found 25 Ask toolbar which I removed. It is 1 day after rerunning the McAfee scan above and so far no recurrence of the virus. But is it still in my computer?
 

More replies
Relevance 22.14%

Hello, I have some weird chinese "anti-virus" virus that I cannot delete, also Malwarebytes Quarantine doesnt let me press the finish button.
Some weird chinese programs tend to appear out of nowhere.
Please help.

Answer:Weird chinese "anti-virus" virus + malwarebytes quarantine doesnt let me finish

Hi Snajpi My name is Aura and I'll be assisting you with this issue. Please give me a few hours to review your logs and prepare a reply.Thank you!

15 more replies
Relevance 22.14%

Hi,

My desktop PC running on Windows XP Professional with SP3 is infected with some kind of virus/spyware that prevents access to anti virus sites.

The virus has also corrupted McAfee virus scan binary and prevents access to sites which clean spyware/malware. I have Malwarebytes' Anti-Malware and SuperAnti Spyware installed. But they cannot update their definitions since the virus attack started about 1 week ago.

I have tried several attempts to clean the virus/malware using the above anti spyware (McAfee scan is corrupted and won't start). The anti spyware finds a few worms and trojans and says that it cleaned them, but they keep coming back. I ran the scan in Safe mode with/without internet connection but that didn't help.

I have Zone Alarm installed but think that it is also infected.

Following are the main symptoms I see

1. No visible error messages/pop ups during bootup.

2. After booting I see quite a few new programs, mainly from the "C:/windows/system32/temp" dir trying to access the internet. Zone Alarm blocks them.

3. After doing a Google search in IE, if I click any website link, it is redirected to another random site. Sometimes opening the link in another IE window helps. (right click -> "open in new window")
Cannot access Microsoft or any anti virus/spyware related website.

4. Many times a pop up message saying "my computer may be infected with spyware" shows up and asks for running a scan. Initial... Read more

Answer:Virus/Spyware preventing access to Anti-Virus/Microsoft files

Hi there,

* Go here to run an online scanner from ESET.Tick the box next to YES, I accept the Terms of Use.
Click Start
Make sure that the option Remove found threats is UNchecked.
Click Scan
Wait for the scan to finish
Copy and paste report as a reply to this topic.

10 more replies
Relevance 22.14%

Hello Bleepingcomputer! I am a long time user of PCHelpForum that has been reffered to this forum as a better alternative and I decided to check it out. There is definitely something funky going on with my computer, as I recieve virus infection pop ups occasionally, my computer will randomly say it has encountered an issue and needs to restart, and has had internet connectivity issues. I used to frequently use HijackThis! logs as a means of analysis, but it seems that this FRST application has taken over that niche. Please let me know what additional information you may need for your analysis. If there are any unneccessary files or programs installed that may be an issue as well, please let me know, as I am trying to do as much of a deep clean as possible. Thank you in advance for taking time to check out these problems.
 
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 27-07-2016
Ran by Stellakinetic (administrator) on BLUEBALLOON (01-08-2016 10:32:31)
Running from C:\Users\Christian\Documents\AntiVirus
Loaded Profiles: Stellakinetic &  (Available Profiles: Stellakinetic)
Platform: Windows 8.1 (Update) (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included... Read more

Answer:Virus analysis and removal. Random virus pop-ups and internet connectivity issue

Thank you for deleting the extra copy of this post. Once I hit post, my internet connection was lost and it must have double posted when I reconnected. Also, it may be worth noting that normally when I run antivirus software, there is generally a little bit of malware or spyware that is found, but recently when I run a multitude of different scan programs absolutely nothing shows up. Either my computer is squeaky clean after nearly 6 months without scans, or something is blocking/hiding from the scanners. It seems to be the latter, as I have mentioned that I am having issues with my laptop shutting down intermittently, virus warning popups, and internet connectivity issues stemming from something altering my connection preferences.

0 more replies
Relevance 22.14%

Mod edit: Moved from the XP forum--PKHelp me. My computer restarts all the time. Windows come with this message to me: Virus alert: Microsoft detected the Win32/Nuwar.N!sys virus on your computer.Can someone help me, please. Here is my log: Logfile of Trend Micro HijackThis v2.0.0 (BETA)Scan saved at 17:49:07, on 16-06-2007Platform: Windows XP SP2 (WinNT 5.01.2600)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\Programmer\Windows Defender\MsMpEng.exeC:\WINDOWS\System32\svchost.exeC:\Programmer\F?lles filer\Symantec Shared\CCPD-LC\symlcsvc.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\system32\spoolsv.exeC:\WINDOWS\system32\CTHELPER.EXEC:\Programmer\QuickTime\qttask.exeC:\WINDOWS\MXOALDR.EXEC:\Programmer\F?lles filer\Real\Update_OB\realsched.exeC:\Programmer\CyberLink\PowerDVD\PDVDServ.exeC:\WINDOWS\system32\LVCOMSX.EXEC:\Programmer\Logitech\Video\LogiTray.exeC:\WINDOWS\system32\rundll32.exeC:\Programmer\Winamp\winampa.exeC:\Programmer\Java\jre1.6.0_01\bin\jusched.exeC:\PROGRA~1\Nokia\NOKIAP~1\LAUN... Read more

Answer:Virus Alert: Microsoft Detected The Win32/nuwar.n!sys Virus On Your Computer

Hi Jens B and welcome to Bleeping Computer.I will be handling your log and helping you to get cleaned up.Your current Hjt log is from the new beta version, please use the 1.99.1 version until the new version is out of beta.Please download the self-extracting version of HijackThis from here:HijackThis_sfx downloadSave HijackThis_sfx to your desktop.Double-click the file then click the Unzip button. Then close the Self-Extractor window.Using My Computer/Windows Explorer, navigate to C:\Program Files\HijackThis and double click on HijackThis.exe to run it. If you would like to make a shortcut for your Desktop so it's more easily accessable, right click HijackThis.exe and choose Send To > Desktop (create shortcut).Please run the extracted HijackThis.exe from now on. Delete any other copies of HijackThis that you have.Open HijackThis and click Do a system scan and save a log file. Copy the entire contents of that log and post it here by clicking the Add Reply button.Thanks,Starbuck

2 more replies
Relevance 22.14%

Hi
 
I've been having troubles with my PC for a while now. But now it is worse than ever!
 
Let me give you a back story - 
 
For the past few months I have had the problem where svchost.exe takes up a huge amount of memory and brings your computer to a crawl. With the help of this forum I finally fixed it. However, a month or so later it was back - It wasn't anywhere near as bad this time, but it still slowed me down.
So what I did was do a factory re-install of my whole computer. Everything was now fresh. However, the svchost problem remained.
 
I looked on google for some solutions and stumbled across one that looked promising. I tried to download the file the person suggested and save to my desktop, but I got an access denied message. So I went to google again. to find out why I was getting access denied. I read that I should go in to my C: drive folder, right click - properties - security - advanced ( something along those lines) and disable administrator access, then enable it again. Yes looking back this was very stupid, but I wasn't thinking. So I did this, and now I have access to nothing. I can't download anything, I can't transfer files from a USB to my computer even in safe mode, I can't do a system restore.
 
On top of this AVG and the built in windows defender have both somehow been disabled, and I can't turn them back on (I have been told this is probably because I have a virus on my system, but I don't know if this is true or not)... Read more

Answer:PC is a MESS - Virus disabled anti-virus, Access Denied, svchost etc.ws

Ok so PART 1 IS SOLVED
 
I fixed the 'access denied' issue by booting up safe mode with networking, from there going into the security options of my C Drive, and managed to enable access that way. 
 
Still got problems with svchost and antivirus being disabled though. I have just downloaded malwarebytes and am currently scanning with it.

15 more replies