I have 3 questions then I will follow up with a chronology of everything I have done and logs:
- How can I get rid of this thing?
- Why won’t Ad Aware work?
- Once we determine that my computer is clean, what other things can I do to protect myself that won’t conflict with AVG and Ad Aware, especially when on the Internet?
PLEASE talk to me like I know nothing, because … I know nothing. I really don’t know why or how I am doing the things I have done. I have just read instruction pages on several forums and tried to figure it out myself. I hope I haven’t messed things up more!
I have been messing with this for 3 days now and I am at my wits end. Thank you to anyone who has the guts, charity and patience to help me with this.
I do a lot of digging at Digg.com. I am pretty political these days and I am sure I got whatever this is by clicking on a link in Digg. At the time the problem started I was running:
- Windows XP Svc Pk 3 fully updated
- AVG Free
- Spybot
- Spy Doctor
- IE7
I knew I had a problem because an AVG warning window popped up which said I had been infected with a trojan horse.
I ran scans on AVG, Spybot and SpyDoctor. None picked up anything.
Rebooted and couldn’t open any Word or PDF documents. Files appeared in my folders, but when I clicked on them I got an error which said “file not available”
Then I tried all kinds of things:
I tried AVAST virus cleaner tool.
It found nothing, but there were several files it identified as “unable to scan.” Here is the log from one of those scans:
10/5/2008, 2:38:05 PM
Memory scanning started…
No virus body found in memory.
Memory scanning finished (7.0s).
Files scanning started…
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\MSS.log… file could not be scanned!
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\tmp.edb… file could not be scanned!
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Windows.edb… file could not be scanned!
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Temp\usgthrsvc\Perflib_Perfdata_c70.dat… file could not be scanned!
C:\Documents and Settings\NetworkService\Local Settings\Temp\Perflib_Perfdata_154.dat… file could not be scanned!
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Data\master.mdf… file could not be scanned!
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Data\mastlog.ldf… file could not be scanned!
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Data\model.mdf… file could not be scanned!
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Data\modellog.ldf… file could not be scanned!
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Data\msdbdata.mdf… file could not be scanned!
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Data\msdblog.ldf… file could not be scanned!
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Data\tempdb.mdf… file could not be scanned!
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Data\templog.ldf… file could not be scanned!
No virus body found.
I tried a number of things and nothing detected the Trojan horse or a virus:
Spybot
SUPERantispyware
MBAM
Spyware Terminator
Kaspersky Online Scanner
I found a DLoader.Trojan removal tool, but it didn’t find anything
FINALLY:
Dr. Web Cureit detected 2 files which it identified as “probably DLoader.Trojan.”
Dr. Web Cureit also detected 2 or 3 files which it identified as “probably Script.virus”
I had Cureit delete these files, but when I rebooted it was back
I had Cureit move the files, but when I rebooted it was back.
I uninstalled AVG and installed AVAST
I then had only AVAST and Ad Adware installed but Ad Aware locks up about 3 minutes into the scan
I turned off automatic recovery then I deleted all of my temporary internet files, my java cache and all of the temp files in my documents and settings.
Then I rebooted with AVAST set to do a full boot scan (with archiving). It took almost 3 hours, but finally got done. The scan didn’t find any infected files but it did find some corrupt files. These files are old and haven’t been opened in years. I backed them up when I got my new computer about 4 months ago so I just deleted them altogether. Here is the results of the scan (I am just pasting on of the lines identifying the corrupt files since I have deleted them and they were similar):
10/06/2008 14:11
Scan of C:\
File C:\Documents and Settings**[my full name]**\My Documents\Personal\Genealogy\SuitsTreen Full.FBK\CHUNK00004 Error 42145 {OLE archive is corrupted.}
Number of searched folders: 9854
Number of tested files: 483067
Number of infected files: 0
When it finished booting up I could open Word and PDF documents again.
I uninstalled AVAST and reinstalled AVG doesn’t find anything other than tracking cookies
All I have installed now is AVG and Ad Aware.
Ad Aware freezes up at the deep registry scan (about 1 minute into it). Actually, it doesn’t freeze up, but it won’t move forward even after about an hour of letting it go. When I do a ctrl+alt+del to stop Ad Aware it closes out the Ad Aware window but apparently, it keeps running.
Here is what Dr Web Cureit finds (I have tried deleting and moving these files, but they come back, sometimes with the files marked SCRIPT.virus and sometimes without finding them)
rpcnet.dll c:\windows32 Probably DLoader.Trojan incurable deleted
rpcnet.exe c:\system32 Probably DLoader.Trojan incurable deleted
Then I ran the Avast virus cleaning tool again to see if those same files still couldn’t be scanned and they were different (not much) this time. Might they have
renamed themselves? Here is the latest log:
10/7/2008, 4:57:29 PM
Memory scanning started…
No virus body found in memory.
Memory scanning finished (49.0s).
Files scanning started…
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\MSS.log… file could not be scanned!
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\MSStmp.log… file could not be scanned!
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\tmp.edb… file could not be scanned!
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Windows.edb… file could not be scanned!
C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Temp\usgthrsvc\Perflib_Perfdata_e48.dat… file could not be scanned!
C:\Documents and Settings\NetworkService\Local Settings\Temp\Perflib_Perfdata_b70.dat… file could not be scanned!
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Data\master.mdf… file could not be scanned!
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Data\mastlog.ldf… file could not be scanned!
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Data\model.mdf… file could not be scanned!
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Data\modellog.ldf… file could not be scanned!
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Data\msdbdata.mdf… file could not be scanned!
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Data\msdblog.ldf… file could not be scanned!
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Data\tempdb.mdf… file could not be scanned!
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Data\templog.ldf… file could not be scanned!
C:\WINDOWS\system32\CatRoot2\edb.log… file could not be scanned!
C:\WINDOWS\system32\CatRoot2\tmp.edb… file could not be scanned!
C:\WINDOWS\Temp\hsperfdata_SYSTEM\676… file could not be scanned!
No virus body found.
Files scanning finished (75781 files, 0 infected, 1608.6s).
Drives scanned: C:
Hijack This Log in reply (not enough room here)