I have searched your FAQs and not found any steps I have not yet tried, so I am posting a meticulously detailed explanation of my problem here so that maybe one of you can help me with it
Thursday -- my brother called for help because McAffee was giving him a message and he didn't understand exactly what it meant. The message was that a file had tried to use a "filemove" operation and that Mcaffee viewed this as high threat so I told McAffee to dissallow it. Shortly after, my PC began receiving about 20 to 30 popups per minute. I tried to use Cntrl+alt+del to close all iexplorer processes and turn off the computer, but cntrl+alt+del would not work. I opened Internet explorer and told my pop up blocker there to reject all popups (i'm a firefox user so I hadn't previously edited ie settings) and discovered that two sites had been added to the "allow list." Each time I re-opened ie they were re-added. I had to unplug my computer to turn it off. I rebooted in safe mode w/o networking and unplugged my computer from our network to ensure no other computers were infected. Cntrl+alt+del function now ONLY works in safe mode.
The first thing I did after this was to run a preliminary full ad-aware scan.
--------------------------------------------------------------
It found the following groups:
Adware.Look2me (2 objects total)
SurfSideKick (2 Objects Total)
VirtualBouncer (6 Objects Total)
Win32.Trojan.Downloader (2 Objects Total)
With the following individual files:
Adware.Look2Me Process Adware C:\Windows\system32\i4jq0e15eh.dll
SurfSideKick Regkey Data Miner HKEY_CLASSES_ROOT:clsid\{02ee5b04-f144-47bb-83fb-a60bd91b74a9
Virtual Bouncer Regkey Malware HEY_LOCAL_MACHINE:software\microsoft\windows nt\currentversion\winlogon\notify\policies\
Virtual Bouncer Regkey Malware HEY_LOCAL_MACHINE:software\microsoft\windows nt\currentversion\winlogon\notify\policies "DllName"
Virtual Bouncer Regkey Malware HEY_LOCAL_MACHINE:software\microsoft\windows nt\currentversion\winlogon\notify\policies "Impersonate"
Virtual Bouncer Regkey Malware HEY_LOCAL_MACHINE:software\microsoft\windows nt\currentversion\winlogon\notify\policies "Logon"
Virtual Bouncer Regkey Malware HEY_LOCAL_MACHINE:software\microsoft\windows nt\currentversion\winlogon\notify\policies "Logoff"
Virtual Bouncer Regkey Malware HEY_LOCAL_MACHINE:software\microsoft\windows nt\currentversion\winlogon\notify\policies "Shutdown"
Win32.Trojan.Downloader File Malware C:\System Volume Information\_restore{416CB326-BFB9-4525-A07D-2376D00F26F7}\RP280\A0031281.dll
Win32.Trojan.Downloader File Malware C:\System Volume Information\_restore{416CB326-BFB9-4525-A07D-2376D00F26F7}\RP280\A0031281.exe
Adware.Look2Me Regkey Adware HKEY_LOCAL_MACHINE:software\microsoft\windows nt\currentversion\winlogon\notify
SurfSideKick Folder Data Miner C:\program Files\SurfSideKick 3\
-----------------------------------------
However, I got the following message upon trying to delete them "Some objects could not be removed, try closing all open browser windows prior to the removal. If this does not help, reboot and run Ad-Aware again.
C:\Windows\System32\i4jq0e15eh.dll
Do you want to let Ad-Aware remove them after the next reboot?"
Whenever I receive this message, explorer encounters restarts. Keep in mind my computer doesn't restart, explorer just encounters an error and restarts inexplicably. If i'm not already IN explorer, explorer just starts on its own. Either way, I get the "windows is running in safe mode" message which is normal. After it starts, even the files which ad-aware was able to remove have returned. I cannot prevent it from starting. Even more interestingly, when it restarts, "My Documents" opens.
At this point I did what I always do with trojans, I used the "regedit" command. However, I now receive the message "regedit is not a valid win32 application" so whatever this trojan is, it's disabled my ability to take it out manually in that way. Clamwin found that the virus had made copies of itself and placed them in multiple hidden directories. It created an invisible "C:\Documents and Settings\Captain\My Documents\Morpheus Shared\Shared" directory in my morpheus files and hid 50 versions of itself in compressed folders all with different names. I'm assuming that this is how it spreads. It also sent copies of itself to Outlook Express which I never use. The following is a copy of the results from my original clamwin scan:
------------------------------------------------------
Scan started: Mon Jul 3 03:50:06 2006
ERROR: Can't open file C:\WINDOWS\SoftwareDistribution\EventCache\4033692E-A2CC-4D44-AE4F-76633195FE0B.bin
ERROR: Can't open file C:\WINDOWS\system32\config\default
ERROR: Can't open file C:\WINDOWS\system32\config\SAM
ERROR: Can't open file C:\WINDOWS\system32\config\SECURITY
ERROR: Can't open file C:\WINDOWS\system32\config\software
ERROR: Can't open file C:\WINDOWS\system32\config\system
ERROR: Can't open file C:\WINDOWS\system32\drivers\dtscsi.sys
ERROR: Can't open file C:\WINDOWS\system32\drivers\sptd.sys
ERROR: Can't open file C:\WINDOWS\system32\drivers\sptd5565.sys
ERROR: Can't open file C:\WINDOWS\system32\fpn8035ue.dll
ERROR: Can't open file C:\WINDOWS\system32\jtju0719e.dll
C:\Documents and Settings\Captain\Local Settings\Temp\!update.exe: Trojan.PurityScan.BJ FOUND
C:\Documents and Settings\Captain\Local Settings\Temp\ac2_0004.exe: Trojan.Downloader.Small-1610 FOUND
C:\Documents and Settings\Captain\Local Settings\Temp\i23.tmp: Adware.SurfSide-2 FOUND
C:\Documents and Settings\Captain\Local Settings\Temp\NNCLXA638.EXE: Adware.NewDotNet.B FOUND
C:\Documents and Settings\Captain\Local Settings\Temp\pre.exe: Worm.Tenga.A FOUND
C:\Documents and Settings\Captain\Local Settings\Temp\temp.fr21BA: Adware.Lookme-26 FOUND
C:\Documents and Settings\Captain\Local Settings\Temp\temp.fr3C11: Trojan.Downloader.VB-104 FOUND
C:\Documents and Settings\Captain\Local Settings\Temp\temp.frAAA4: Adware.CommAd-2 FOUND
C:\Documents and Settings\Captain\Local Settings\Temp\temp.frEA19: Adware.Lookme-26 FOUND
C:\Documents and Settings\Captain\Local Settings\Temp\Temporary Internet Files\Content.IE5\CDIBSX2B\103[1].avi: Trojan.Downloader.TSUp-12 FOUND
C:\Documents and Settings\Captain\Local Settings\Temporary Internet Files\Content.IE5\IV1LPNEA\NNSCAA638[1].EXE: Adware.NewDotNet.B FOUND
C:\Documents and Settings\Captain\Local Settings\Temporary Internet Files\Content.IE5\JUOJN94D\104[1].avi: Trojan.Downloader.Small-945 FOUND
C:\Documents and Settings\Captain\Local Settings\Temporary Internet Files\Content.IE5\K08XWZAP\!update-4020[1].0000: Trojan.PurityScan.BJ FOUND
C:\Documents and Settings\Captain\Local Settings\Temporary Internet Files\Content.IE5\V5L13QQJ\numbsoft[1].exe: Worm.Tenga.A FOUND
C:\Documents and Settings\Captain\My Documents\Morpheus Shared\Downloads\Age Of Empires 3 Keygen Crack Key Code exe.zip: Trojan.VB-100 FOUND
C:\NNSCAA638.EXE: Adware.NewDotNet.B FOUND
C:\numbsoftnew.exe: Worm.Tenga.A FOUND
C:\Program Files\NewDotNet\newdotnet6_38.dll_tobedeleted: Adware.NewDotNet.B FOUND
C:\Program Files\NewDotNet\newdotnet7_22.dll: Adware.NewDotNet.I FOUND
C:\Program Files\outlook\outlook.exe: Trojan.VB-100 FOUND
C:\WINDOWS\system32\guard.tmp: Adware.Lookme-26 FOUND
C:\WINDOWS\system32\winlogon.dll: Trojan.PurityScan.EN FOUND
-- summary --
Known viruses: 60743
Engine version: 0.88
Scanned directories: 5811
Scanned files: 72868
Infected files: 109
Data scanned: 37470.22 MB
Time: 13949.199 sec (232 m 29 s)
-------------------
Completed
--------------------------------------------------------
I disabled system restore. I then manually went into a few of the hidden directories and deleted the copies it had made of itself. The next thing I did was run stinger. Stinger found 12 infections and claimed to have removed all of them. I ran a symantec sysclean which claimed to find the same 12 infections and remove them, followed finally by yet another clamwin. These were my results for the final clamwin run. As you can see, fewer files remain but they are all still in my registries which i CANNOT ACCESS because "regedit" has been somehow disabled. These are the same 12 Stinger and Sysclean both claimed to take care of. Ad-aware still encounters the same errors and gives me the same reports as before, explorer still restarts as before, even in safemode, even after all three scanners have been run. The final clamwin run produced these results:
--------------------------------------
Scan started: Mon Jul 3 21:27:45 2006
C:\Program Files\outlook\outlook.exe: Removed
C:\Program Files\outlook\p.zip: Removed
C:\Program Files\outlook\v.tmp: Removed
C:\WINDOWS\system32\ausmsext.dll: Removed
C:\WINDOWS\system32\cgbcatex.dll: Removed
ERROR: Can't open file C:\WINDOWS\system32\config\default
ERROR: Can't open file C:\WINDOWS\system32\config\SAM
ERROR: Can't open file C:\WINDOWS\system32\config\SECURITY
ERROR: Can't open file C:\WINDOWS\system32\config\software
ERROR: Can't open file C:\WINDOWS\system32\config\system
ERROR: Can't open file C:\WINDOWS\system32\drivers\dtscsi.sys
ERROR: Can't open file C:\WINDOWS\system32\drivers\sptd.sys
ERROR: Can't open file C:\WINDOWS\system32\drivers\sptd5565.sys
C:\WINDOWS\system32\dzdmo.dll: Removed
C:\WINDOWS\system32\guard.tmp: Removed
C:\WINDOWS\system32\guard.tmp_tobedeleted: Removed
C:\WINDOWS\system32\hrn4055qe.dll: Removed
ERROR: Can't open file C:\WINDOWS\system32\i4jq0e15eh.dll
ERROR: Can't open file C:\WINDOWS\system32\mv26l9fs1.dll
C:\WINDOWS\system32\nqtapi32.dll: Removed
C:\WINDOWS\system32\p6p6lg7s16.dll: Removed
ERROR: Can't open file C:\WINDOWS\system32\wmdconns.dll
C:\WINDOWS\system32\wyd_ci.dll: Removed
C:\Program Files\outlook\outlook.exe: Trojan.VB-100 FOUND
C:\Program Files\outlook\p.zip: Trojan.VB-100 FOUND
C:\Program Files\outlook\v.tmp: Trojan.VB-100 FOUND
C:\WINDOWS\system32\ausmsext.dll: Adware.Lookme-26 FOUND
C:\WINDOWS\system32\cgbcatex.dll: Adware.Lookme-26 FOUND
C:\WINDOWS\system32\dzdmo.dll: Adware.Lookme-26 FOUND
C:\WINDOWS\system32\guard.tmp: Adware.Lookme-26 FOUND
C:\WINDOWS\system32\guard.tmp_tobedeleted: Adware.Lookme-26 FOUND
C:\WINDOWS\system32\hrn4055qe.dll: Adware.Lookme-26 FOUND
C:\WINDOWS\system32\nqtapi32.dll: Adware.Lookme-26 FOUND
C:\WINDOWS\system32\p6p6lg7s16.dll: Adware.Lookme-26 FOUND
C:\WINDOWS\system32\wyd_ci.dll: Adware.Lookme-26 FOUND
-- summary --
Known viruses: 60743
Engine version: 0.88
Scanned directories: 5805
Scanned files: 73792
Infected files: 12
Data scanned: 39044.24 MB
Time: 27499.507 sec (458 m 19 s)
-------------------
Completed
-------------------
Symantec and Clamwin and Stinger each appear to be finding these exact same 12 infections. Each time they claim to remove them but the files have returned by the next scan. I cannot fix this manually. Now, "Surfsidekick 3" (one of the recurring programs which ad-aware removes and which returns after explorer restarts) IS detected and removed by Blacklist but it is the only program affected by Blacklist and as you can see here, the exe file for it CANNOT be deleted, only the registry values. any attempt at manually removes it results in a typical "bla bla bla being used by another person or program." The next time blacklist is run, the registry values have returned and it has to delete them again. They are being automatically replaced. I get the following every single time I run blacklist:
------------------------------
Detected: C:\Program Files\SurfSideKick 3\Ssk.exe
Could not delete file: C:\Program Files\SurfSideKick 3\Ssk.exe
Deleted Registry value: HKCU\...\Run SurfSideKick 3
Deleted Registry value: HKLM\...\Run SurfSideKick 3
--------------------------------
Jay Loden's aimfix has found no viruses applicable to aim.
I have run winsock after running all three virus scanners and this has made no difference.
My McAffee virus scan is about a year out of date
I mainly use the default windows firewall
Stinger/Clamwin/Symantec were all up-to-date as of late this april
Please keep in mind any solutions involving the command "regedit" are not on the table, as this trojan has somehow managed to shut down that system32 application. Winsock does not restore my ability to use "regedit." I should also note that spybot encounters the same problems as ad-aware (not surprisingly).
I clamwin scanned a fourth time and this time, out of the blue:
-----------------------------------------
Infected files: 0
Data scanned: 39044.60 MB
Time: 27746.470 sec (462 m 26 s)
-----------------------------------------
Which is even more troubling because when I run ad-aware i STILL get the same results except for:
-----------------------------------
Win32.Trojan.Downloader File Malware C:\System Volume Information\_restore{416CB326-BFB9-4525-A07D-2376D00F26F7}\RP280\A0031281.dll
Win32.Trojan.Downloader File Malware C:\System Volume Information\_restore{416CB326-BFB9-4525-A07D-2376D00F26F7}\RP280\A0031281.exe
-----------------------------------
These two are now mysteriously gone. I again got the same message "Some objects could not be removed, try closing all open browser windows prior to the removal. If this does not help, reboot and run Ad-Aware again.
C:\Windows\System32\i4jq0e15eh.dll
Do you want to let Ad-Aware remove them after the next reboot?"
And explorer itself restarted -- as usual. Keep in mind my computer is not restarting, only explorer itself. It inexplicably closes and up pops the "Windows is running in safemode message" as it restarts. And as usual, "My Documents" mysteriously opened. I ran adaware AGAIN and the results were exactly the same. Stinger and sysclean have now both cleared me of any trojan infections. I should also note that my computer now freezes each time i turn it off from normal mode and it now encounters errors opening bizzarrely named ".dll" files each time windows starts.
My computer is useless with this thing on it -- I can't do anything while closing 30 pop ups per minute. Please help!I should also note that it drastically slows down my computer even beyond the drag of normal browser-opening. It has also turned my clock to "military" time (eg 23:58 instead of 11:58 pm). I should also note that restarting after running adaware does not help because adaware fails to open upon restarting and thus doesn't take care of anything.