Virus message popup

Status
Not open for further replies.
I just realized that this thread has been hijacked. That's not fair. Here I was thinking that you started the thread. You should have started your own thread, but I guess it is too late for that.

In your first post you mentioned spyware 2009. Are you shure it isn't antivirus 2009?
 
Files were already unhidden and these two are not in system32.
Apologies, I didn't mean to hijack - happened by accident. I believe Karterfive and myself have an identical problem.
It was called AntispywareXP2009 I believe
Bratsk isn't there either as I deleted both of them. But it will be back in Windows and system32 if I re-boot - which I agree says it's something else - but I have no idea what or where to look. It would help if you could agree each process in the boot up one at a time and see which one causes the problem. I've posted all of the regedit "unusuals".
 
Did you try to see if you are able to download the programs mentioned earlier? If not please try and see if you are able to.
At this point a HJT log would be great. If you are still unable to download the programs I will email them to you.

Go to C:\Program Files and search for any suspicious entries.
 
I just realized that this thread has been hijacked. That's not fair. Here I was thinking that you started the thread. You should have started your own thread, but I guess it is too late for that.

Damn I missed that too :suspiciou

Karterfive if you are still out there, please reply back here, and let us know if you still require support. Apologies for the misunderstanding.
 
HJT Log

I have downloaded HJT but it won't allow it to run. If I click the icon it does nothing despite the fact it is downloaded and installed. Last night I tried to re-install Norton. It wouldn't let that happen either. I think it has knocked out windows installer. I followed the Norton instructions to re-install, but it still won't let it happen. All I have that is working is Spyhunter 3 security suite.
 
Can you try running it in safe mode? Also, see if it works by renaming HijackThis to something recognisable to us, like 'DoThis.exe' or something.
 
I have renamed Hijack This and it works - hurrah! I attach the log file. Hijack This is now "Do This" in the logfile!

The only reason I have spyhunter is because it was the only thing I could download and install having had AVG and Norton wiped out. AVG is my preferred choice.

Can't seem to start in Safe mode either because the keyboard entries will not accept. I suspect it has knocked this out too.
 
Wow. That's a pretty bad log.

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: (no name) - {D355DF51-1319-6ED2-6CB5-D46A940A619F} - Kargo.dll (file missing)
O1 - Hosts: localhost 127.0.0.1
O1 - Hosts: 1.1.1.1 ewido.net
O1 - Hosts: 1.1.1.1 www.bitdefender.com
O1 - Hosts: 1.1.1.1 download.bitdefender.com
O1 - Hosts: 1.1.1.1 sysinternals.com
O1 - Hosts: 1.1.1.1 www.sysinternals.com
O1 - Hosts: 1.1.1.1 onguardonline.gov
O1 - Hosts: 1.1.1.1 www.onguardonline.gov
O1 - Hosts: 1.1.1.1 avast.com
O1 - Hosts: 1.1.1.1 www.avast.com
O1 - Hosts: 1.1.1.1 safety.live.com
O1 - Hosts: 1.1.1.1 www.paretologic.com
O1 - Hosts: 1.1.1.1 paretologic.com
O1 - Hosts: 1.1.1.1 services.google.com
O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
O4 - HKLM\..\Run: [Limeshop0] "C:\Program Files\Lime_Shop\Limeshop0.exe"
O14 - IERESET.INF: START_PAGE_URL=http://www.tiny.com
O20 - AppInit_DLLs: karna.dat

Also, I'd like to check this entry with you, did you install this, and what do you use it for?
O4 - HKLM\..\Run: [SupaDial] C:\Program Files\SupaDial\SupaDial.exe /A

If you do not recognise it, fix the entry too. After you have fixed those entries, try running MBAM and SAS again. Then post back with a fresh HijackThis log.
 
It wasn't this bad last week! Damn infection.

Supadial was the original default dialler connection that came with all Tiny computers. It is disabled.

From the log file, what specifically should I get rid of and how please? Do I just select them in the HJ file and press "fix checked"?
 
Kimsland / Tw0rld?

Please could you advise which files from my logfile I should "fix" please? And presumably I fix them within HJT by selecting them and pressing "fix checked"?
 
After you have fixed those entries, try running MBAM and SAS again. Then post back with a fresh HijackThis log.

I do not want to interfere with momok's support to you (anyway he's better than me!)

Please do what he has suggested
 
Yes, but I don't understand his reply. Do I "fix" everything in the screenprint or everything that HJT comes up with in the logfile?
 
Oh!

No you just fix (tick and fix) only the ones in the quotes above

You need most of what's in the HJT log to run your computer

He forgot to say "place a checkmark against the following.......and fix them"
 
1, I do not see a functioning antivirus program.
2. I see you are also using SpyHunter3. This program has a checkered past. It was listed as a rogue program, eventually de-listed, but ti is still not a recommended program
3. You use the file sharing program Limeware, which is a know contributor to adware, spyware and other malware.
4. It appears that you may have attempted to set up Host files, but they are not setup correctly.
You need to deal with this immediately>> already mentioned by momok.
5. You have a plug-in for Norton Confidential
6. You have an AVG v8 Toolbar entry with file missing
7. IEreset.INF: When you click reset Internet Explorer reads it's default settings from a file called iereset.inf. ... You's is set ti tiny.com
8. the O20 - AppInit_DLLs: karna.dat>> this entry loads from th Regisrty>> Added by the Troj/FakeVir-GL Trojan
9. You have a Symantec Service running for Norton Internet Security Suite. but no other entries are seen

After you have fixed those entries, try running MBAM and SAS again. Then post back with a fresh HijackThis log.
I check the log. There are so many bad entries that you can only hope that running Malwarebytes and SuperAntispyware will clean some of it out.

I concur with exactly the same entries monok told you to remove, then follow up with those two programs and ending with a fresh logs from all 3 programs..

It is amazing at how many entries there are with the missing CLSID and URL. There is no way to verify these entries. Please proceed as requested if you want to make any progress.
 
Fixed I think

I have managed to load and run MBAM which cleared a lot of the problems. I then downloaded and ran SAS which seemed to clear the rest.

I was then able to re-load AVG (Hurrah) - haven't bothered with Norton, so there will still be refwerences to this.

I have run scan after scan after scan and currently I don't see any problems. The Antivirus 2009 / Bratsk problem has gone.

Please find attached my HJT log and - well you tell me - is it much better?

Many thanks for your help

Steve
 
There is still an older version of Java loading. Check these two entries for HijackThis to remove:
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll

Uninstall Java v6u7 in the Control Panel. If you did NOT update, please go here and update to v6u10:
https://www.techspot.com/downloads/6463-java-se.html

Otherwise the log looks fine.
If speed is an issue for you, there are several processes loading at startup that do not need to. The programs or applications can then be started manually when needed: Have HijackThis remove the following 04 entries:
1. PDVDServ.exe>>> CyberLink\PowerDVD
2. CARPService>>>Associated with Zoltrix modems - enables the internal modem speaker, allowing you to listen to the dial-up sounds for example
3. NeroCheck.exe>>> [NeroFilterCheck] CAMTRAY.EXE>>> Creative WebCam Tray
4. mm_tray.exe>>> tray icon for Musicmatch Jukebox
5. mimboot.exe>>> eMusicmatch Jukebox.
6. QTTask.exe>>> QickTime
7. jusched.exe>>> updates for Java:
8. realsched.exe>>> updater for real Player:
9. CTSyncU.exe">>> Related to Creative_Sync_Manager synchronizes music tracks on your computer with your player.
10. PCSuite.exe" -onlytray>>> tray icon for Nokia_PC_Suite lets you edit, synchronize and back up many of your phone's files on a compatible PC through a cable or wireless connection.
12. WZQKPICK.EXE>>> or WinZip System Tray Application. Did you know that Wondows XP has a built in 'unzipper' (uncompress)?

To disabled Java auto-updates:
1. Click on the Control Panel
2. Click on Java
3. Select 'Update tab'
4. Uncheck the box next to Check for updates Automatically
5. Answer Yes when asked to Verify.
6. Click on Apply

To disabled Real Player updates: All Programs> Open Real Player:
1. Launch RealPlayer > Tools menu. (Tip: If you only see File and View, click on the double greater-than icon (>>) to access the rest of the menus.)
2. Choose Preferences. In the Categories list on the left side, find Automatic Services. Click the plus icon to the left to reveal AutoUpdate. Select AutoUpdate.
3. Uncheck the box next to Automatically Download and Install Important Updates.
(NOTE: may be slight difference in versions)

To disable Adobe Reader updates:
1. All Programs> Adobe Reader
2. Choose 'Check for Updates'
3. Preferences
4. UNCHECK 'Automatically check for updates'> OK
(NOTE: you need to check for updates at least one time in-order to access the Adobe Auto Updater preference dialog box.

New versions should be checked for at intervals, downloaded and installed. Old versions should then be uninstalled from Add/Remove Programs in the Control Panel as these updates do not usually overwrite.
If the system is not stable, you can remove the cleaning tools:

* Download OTCleanIt (http://download.bleepingcomputer.com/oldtimer/OTCleanIt.exe)
* Click the CleanUp! button.
* It will go thorough the list and remove all of the tools it finds and then delete itself (requiring a reboot).

Clear your existing System Restore points and establish a new clean restore point:
Go to Start > All Programs > Accessories > System Tools > System Restore> Select Create a restore point> OK.
Next, go to Start > Run and type in cleanmgr> Select the More options tab> Choose the option to clean up System Restore and OK it.
This will remove all restore points except the new one you just created.
 
Status
Not open for further replies.
Back