This thread's last reply is from February 14, 2007, 7:27 AM UTC. Software, malware, and removal-tool
advice below may be out of date — treat specific steps and download links with caution.
StilettoRed
Thought I had the AVG loaded, but I guess it was not the antivirus program. The newest AVG scan got this:
Trojan horse Collected.9.AN" "C:\Program Files\Common Files\System\d3ui32.dll" "2/11/2007 10:48:35 AM" "d3ui32.dll" "88 KB"
KASPERSKY ONLINE SCANNER REPORT
Sunday, February 11, 2007 1:55:57 PM
Operating System: Microsoft Windows 2000 Professional, Service Pack 4 (Build 2195)
Kaspersky Online Scanner version: 5.0.83.0
Kaspersky Anti-Virus database last update: 11/02/2007
Kaspersky Anti-Virus database records: 266806
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
D:\
E:\
F:\
Scan Statistics:
Total number of scanned objects: 38424
Number of viruses found: 5
Number of infected objects: 8 / 0
Number of suspicious objects: 6
Duration of the scan process: 02:27:33
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\avg7\Log\emc.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Comodo\Personal Firewall\Logs\cpf.lock Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DyFuCAInternetOptimizer10.zip/optimize.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DyFuCAInternetOptimizer10.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DyFuCAInternetOptimizer24.zip/optimize.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DyFuCAInternetOptimizer24.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DyFuCAInternetOptimizer3.zip/optimize.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DyFuCAInternetOptimizer3.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\Robert Cummins\.housecall6.6\Quarantine\flec006.exe.bac_a01664 Infected: Trojan-Downloader.Win32.Bagle.aw skipped
C:\Documents and Settings\Robert Cummins\.housecall6.6\Quarantine\temp.zip.bac_a01664 Infected: Email-Worm.Win32.Bagle.gen skipped
C:\Documents and Settings\Robert Cummins\.housecall6.6\Quarantine\wjrjzhcmsat.exe.bac_a01664 Infected: Email-Worm.Win32.Bagle.gl skipped
C:\Documents and Settings\Robert Cummins\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Robert Cummins\Desktop\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\Robert Cummins\Desktop\SmitfraudFix.exe/data.rar/SmitfraudFix/Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\Robert Cummins\Desktop\SmitfraudFix.exe/data.rar Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\Robert Cummins\Desktop\SmitfraudFix.exe RarSFX: infected - 2 skipped
C:\Documents and Settings\Robert Cummins\Desktop\SmitfraudFix.exe PE_Patch.UPX: infected - 2 skipped
C:\Documents and Settings\Robert Cummins\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Robert Cummins\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Robert Cummins\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Robert Cummins\Local Settings\Temp\~DFDF39.tmp Object is locked skipped
C:\Documents and Settings\Robert Cummins\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Robert Cummins\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Robert Cummins\NTUSER.DAT.LOG Object is locked skipped
C:\WINNT\CSC\00000001 Object is locked skipped
C:\WINNT\Debug\ipsecpa.log Object is locked skipped
C:\WINNT\Debug\oakley.log Object is locked skipped
C:\WINNT\Debug\PASSWD.LOG Object is locked skipped
C:\WINNT\ModemLog_HSP56 MicroModem.txt Object is locked skipped
C:\WINNT\SchedLgU.Txt Object is locked skipped
C:\WINNT\Sti_Trace.log Object is locked skipped
C:\WINNT\system32\config\AppEvent.Evt Object is locked skipped
C:\WINNT\system32\config\default Object is locked skipped
C:\WINNT\system32\config\default.LOG Object is locked skipped
C:\WINNT\system32\config\SAM Object is locked skipped
C:\WINNT\system32\config\SAM.LOG Object is locked skipped
C:\WINNT\system32\config\SecEvent.Evt Object is locked skipped
C:\WINNT\system32\config\SECURITY Object is locked skipped
C:\WINNT\system32\config\SECURITY.LOG Object is locked skipped
C:\WINNT\system32\config\software Object is locked skipped
C:\WINNT\system32\config\software.LOG Object is locked skipped
C:\WINNT\system32\config\SysEvent.Evt Object is locked skipped
C:\WINNT\system32\config\system Object is locked skipped
C:\WINNT\system32\config\SYSTEM.ALT Object is locked skipped
Scan process completed.
StilettoRed
AVG removed the file d3ui32.dll.
I have Spy-Bot running again and it found a few things. I also loaded SpyBlaster and have it running.
I haven't had any problems lately with returned emails from addresses that I never sent anything to, which I believe is an indicator that the computer was hijacked.
For a summary I am running Comodo firewall in a "learning mode." It has intercepted 35 "severe events" in the last three days.
AVG anti virus
AVG anti spy ware
SpyBlaster
Adaware installed
SpyBot Search and Destroy installed
Trojan Hunter installed
A Squared installed
Do I need anything else?
How do you remove the stuff that is in quarantine? I would rather have the files deleted completely.
Can you suggest a good Anti-Spam?
Thanks
StilettoRed
A few issues if you have the time.
FYI AVG now calls their quarantine the "Virus Vault"
I use CCleaner as it has a register utility. OK?
I understand what the intent of the MVP hosts file is for, but don't know what is to be done to install and use it. I assume you periodically have to go back and get updates?
When I went to the MSFT updates and tried to set up Automatic Updates I was not able to run the file: services.misc
I received a message that the file was not found or component missing - make sure the path and file name are correct....
Do these fall within your domain for fixes.
Thanks
StilettoRed
Hello Mr undersore JAk3,
I think I have completed everything that is to be done. I found the automatic updates in the system folder which I should have been able to find without asking you. It evidently worked OK...maybe.
Many thanks for all of your help. I really appreciate the time you have taken to work out all these virus issues. You perform an admirable service!!
I have one more request. Can you please recommend a good Windows repair site. After getting the updates and starting to reply to your post my computer locked up. Everything has slowed to a crawl and my CPU usage has maxed out at 100% just to make an internet connection and it literally took about 5 minutes after the computer took about 5 minutes to boot to get back on the internet. I have a dia-up connection which doesn't help matters, but it is still excessively slow. Evidently I have other problems now other thatn just viruses,
When will it all end? (rhetorical question NRE)
Later,
StilettoRed
Yes sir, I made the changes and everything appears to be back to normal. However, in my case "slow down" was a misnomer. The computer came to a screeching halt and fell on its side. I had to remove power to get it to reboot.
Again, thanks for your help.
Aside from all the BS we had to go through it has been my pleasure to meet you.
Best of luck to you Mr_JAk3.