Help - Search - Members - Calendar
Full Version: SysProtect, DriveCleaner, WinAntivirus etc
Lavasoft Support Forums > Archived Topics > Archives: Resolved/Inactive Topics > Resolved/Inactive General Support Issues
connman
Hi Guys,
First of all please forgive me if this is the wrong place for this post, as this is my first time on the forum.

I do not know how the developers at Lavasoft operate but I would like to report a group of malicious Adware programs that I have not been able to remove from my PC in atleast 3 months.

The pop ups I get are for things including but not limited to: SysProtect, DriveCleaner, WinAntivirus
SysProtect has a knack for installing itself without my permission, the others are just annoying pop ups. I also get a lot of viruses now and system crashes and I think it is all related. Probably the worst thing is whenever I logon to WinXP I get a blue screen of death (dumping physical memory etc) and the PC reboots. The only work around I can find is to hold down shift to block startup applications.

Just yesterday I was with one of my customers and they asked me how to make word logos and I told them about a website I know about, www.flamingtext.com
DO NOT GO THERE. After my customer went to this site (and prodcued some nice looking logos) their computer started doing the same things mine is (DriveCleaner, WinAntivirus). You could imagine how happy with me they are and my great suggestions.

Anyway since I have pointed out a source for the malware, perhaps the experts can now figure out the fix for it and include in a future adaware update (is there a more official way of reporting newly discovered malware?)

I"ll also attach a hijack this log which shows some of the crap that installs itself. I routinely remove lines from the registry using hijack this but they always come back, without me having to visit the source of the malware a second time. However I have never asked for help before - if anyone can point out the things I need to fix I'll be most grateful. The protection I currently use is AVG, Adaware Personal SE, Spyblaster and Spybot S&D. I routinely update all these software, scan and remove malware in safe mode, but within minutes all problems are back again.

Possibly unrelated to the adware is my Windows Blue screen on log on that I mentioned earlier. My msconfig startup contains: qttask, avgcc, NvCpl, iTunesHelper, NvMcTray, nwiz, MsnMsgr, Adobe Reader Speed Launch, Microsoft Office, WallMaster (something I have beeen using for years - its ok), isuspm (I have disabled this - should i have?), USYP (SysProtect adware, also disabled)

Thankyou firstly to Lavasoft for reading about this malware; and secondly
Thankyou to anyone who can help me with my immediate problems

P.S. I would format and reinstall Windows in a heartbeat if that was an option. I'm on a VPN for work and the settings seem to be very complicated, we have to pay some guy hundreds every time he has to set one up from scratch.
connman
Sorry the attachment didn't seem to come out for some reason. Didn't really want to do this but I'll now paste in my full hijack this log:

Logfile of HijackThis v1.99.1
Scan saved at 11:57:15 AM, on 18/10/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\WINDOWS\CTHELPER.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\iexplore.exe
F:\Downloads\anti adware spyware\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - - (no file)
O1 - Hosts: 137.111.66.33 w2000server
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [IntelliType] "C:\Program Files\Microsoft Hardware\Keyboard\type32.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [SBDrvDet] C:\Program Files\Creative\SB Drive Det\SBDrvDet.exe /r
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Startup: WallMaster.lnk = C:\Program Files\WallMaster\wallmast.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://locator.cdn.imageservr.com
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/eB...l_v1-0-3-48.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://joelsboyland.spaces.msn.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co...b?1115279504971
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse...pDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O16 - DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} (JuniperSetup Control) - https://morpheus.freedom.com.au/dana-cached...uniperSetup.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: pcAnywhere Host Service (awhost32) - Symantec Corporation - C:\Program Files\Symantec\pcAnywhere\awhost32.exe
O23 - Service: Juniper Network Connect Service (dsNcService) - Juniper Networks - C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
O23 - Service: GhostStartService - Symantec Corporation - C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
spike-nz
Hi connman,

To help the expert log-readers, could you also post your latest Ad-Aware scan-log. Please make sure that you are using Ad-aware SE Build 106r1


Note: If your version is 6.0 and not the SE, you need to uninstall the older version first and get the latest version from the above link, then install SE.


Then use the WebUpDate to get the latest Definition file SE1R128 18.10.2006
To do this Open Ad-aware - Click the WebUpDate
button at the top right hand side of the Ad-aware screen (The world globe).
Click "Connect" Ad-aware will then download the latest Definition file for you.
To make sure it is updated , look at the main Ad-aware screen, and look under "Initialization Status"
It should say the Latest Definition file.
Then scan doing a "Full Scan"
and then post your logfile here by using the Add-Reply Feature.

Click to view attachment

By default, Logs are stored in: C:\Documents and Settings\USERNAME\Application Data\Lavasoft\Ad-aware\Logs\.
An easy way to get there is to click Start, click Run And type in and press ENTER: %appdata%
then click Lavasoft, then Ad-Aware and then Logs.
Scroll down to find the latest one that you have (by date & time)
and open it, right Click, select all, copy and then paste the contents of it here.
(Make sure that all of your Logfile has been posted, sometimes it will require two post's to get it all)

-Configuring Ad-Aware Full-Scan
1) Start Ad-Aware SE
2) Click on the link "Check for updates now" press the connect button and follow the prompts to ensure you are up to date.
3) Press the start button and in the Preparing System Scan window select the option "Perform full system scan", click on "Search for negligible risk entries" so that it shows a red cross i.e. is deselected and click on "Search for low-risk threats" so that is shows green tick i.e. is selected.
4) Click the next button to start the full scan, when the scan finishes click on the show logfile button. In the log window right mouse click and select "Select all..." then right mouse click again and select "Copy to clipboard" then paste in a reply to this thread.

Due to the number of requests for help, it may take a few days for the expert log-readers to get to you - please be patient and don't "bump" your Topic (ie: add extra posts to it), as logs are answered from oldest to newest smile.gif

Regards,

Spike
Tristian
Hello connman, I am now monitoring this topic so I can respond to you a lot quicker.

I need you to rename Hijackthis because I suspect that you may have the Vundo infection that can hide some entries in your log.
  • Please go to the folder where you saved Hijackthis.exe:
    F:\Downloads\anti adware spyware\HijackThis.exe
  • Right-click on it, then select Rename.
  • Name it something like: 321.exe (or whatever you want)
  • Then double-click 321.exe to scan and then post the new logfile.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2010 Invision Power Services, Inc.