I am currently receiving about 10 suspicious message alerts per minute, which, as you can imagine, is infuriating.
I have changed my system setting to show all hidden files and folders and then run an Avast boot scan, to no avail. I have also used Ccleaner and spybot search and destroy. All these programs found a few problems and ‘fixed’ them but I still get the suspicious messages.
I have done a hijack this scan and uploaded the results to virustotal.com which said eveything was fine. Hang on WTF! I just copied the results from virustotal.com, which appear exactly as below except with current status marked as finished, but when I paste it appears as:
File hijack_this_logfile.txt received on 03.24.2009 20:25:53 (CET)
Current status: Loading … queued waiting scanning finished NOT FOUND STOPPED
Result: 0/40 (0%)
That is defintley weird, no?
I was going to paste the full Hikackthis log file here as well but it will exceed the 10000 character limit so I will try and do it in a few parts. Anyone who can help me on this in anyway will be a hero.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:20:37, on 24/03/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal
We didn’t detect any active process of a firewall on your system. Reasons maybe:
(1.) You are using the windows firewall or a hardware firewall.
(2.) You are using a firewall of an unknown vendor.
(3.) You are using a firewall, but for unknown reasons it is disabled
(4.) You don’t use any firewall at all.
We recommend you to use a firewall.
The below entries were rated as questionable or unknown :
C:\Windows\System32\fslhjmr.exe
There were no search results for this entry. This makes it very suspicious.
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
Unnecessary (deactivated) entry that can be fixed. Belongs to Yahoo Companion.
O2 - BHO: Act.UI.InternetExplorer.Plugins.AttachFile.CAttachFile - {D5233FCD-D258-4903-89B8-FB1568E7413D} - mscoree.dll (file missing)
Unnecessary (deactivated) entry that can be fixed. Belongs to ACT! 2005
O4 - HKLM..\Run: [fslhjmr] C:\Windows\system32\fslhjmr.exe \u
There were no search results for this entry. This makes it very suspicious.
O9 - Extra button: Attach Web page to ACT! contact - {6F431AC3-364A-478b-BBDB-89C7CE1B18F6} - mscoree.dll (file missing)
Unnecessary (deactivated) entry that can be fixed.
O9 - Extra ‘Tools’ menuitem: Attach Web page to ACT! contact… - {6F431AC3-364A-478b-BBDB-89C7CE1B18F6} - mscoree.dll (file missing)
Unnecessary (deactivated) entry that can be fixed.
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
Belongs to OpenDNS and should be OK.
So, there are 2 entries that are very suspicious. I hope this info will give someone help to resolve your problem.
I have done a hijack this scan and uploaded the results to virustotal.com which said eveything was fine. Hang on WTF! I just copied the results from virustotal.com, which appear exactly as below except with current status marked as finished, but when I paste it appears as:
I don't know the specifics of why the file did not upload, producing the error message, but the virus total service is for suspicious or unknown file, not log file analysis. Any results would have been meaningless.
What you should do, in the light of CharleyO’s post, is to locate that C:\Windows\System32\fslhjmr.exe and upload that to virus total.
Any chance you could advise us the content of the suspicious alert messages, please? The content (what is flagged) is important for determining any needed course of action. (Which may include deleting the file mentioned, but don’t rush into that without a bit more research.)
They are not always in German and of course the sender, receiver and subject vary.
I have deleted all of the files suggested by Charley O and am still receiving the message. I have task manager open just now and noticed cwpylgc.exe running at around 21k. I just googles to find out what this is and the only result was this post, where it appears in my log file as F2 - REG:system.ini: UserInit=C:\Windows\system32\userinit.exe,C:\Users\Owner\cwpylgc.exe \s. Could this be the offender?
This message “There are too many identical e-mails in appointed time:” is an indication that you have an undetected/hidden trojan spambot on your system.
If you haven’t already got this software (freeware), download, install, update and run it, preferably in safe mode and report the findings (it should product a log file).
SUPERantispyware On-Demand only in free version. - 2. MalwareBytes Anti-Malware, On-Demand only in free version http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe, right click on the link and select Save As or Save File (As depending on your browser), save it to a location where you can find it easily later.
Thanks again for your pearls of wisdom. I have followed your advice and ran Malwarebytes and superantispyware and they seem to have done the trick (I will post my mbam log below). I am now looking for a new firewall to stop this from happening again as I feel the windows one is not sufficient so if anyone has any recommendations of a good freeware firewall then please let me know. Thanks Again!
Malwarebytes’ Anti-Malware 1.35
Database version: 1921
Windows 6.0.6001 Service Pack 1
There are many freeware firewalls such as, Comodo (care required now it is a suite not to install the anti-virus element), PCTools Firewall Plus, Jetico, etc. - Zone Alarm free works fine with avast and has a reasonably friendly user interface, however, the free version is becoming bloated with trial ware and is also crippled as far as outbound protection goes In the Program Control, configuration area, the slider will only goes as far as Medium protection, if you want more you have to buy the Pro version.
Many forum users are using all of the above:
PC Tools Firewall seems to have the least user headaches as it doesn’t seem to be constantly asking the user questions about this and that.
I think you can see by my comments on Zone Alarm free you have to be careful that you are not using the pro trial version.
Online Armor for the most parts fine but it has caused some users grief after avast program updates and that is something you have to watch out for.
Comodo is now a suite and you have to do a custom install so as not to install the antivirus element, of all the firewalls listed this seems to be the noisiest in asking questions, depending on settings and elements used, so it could be daunting for those not to familiar with firewalls or their systems.