Welcome Guest ( Log In | Click here to Register a free account now! )
Welcome to Bleeping Computer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.![]() ![]() |
Feb 16 2005, 11:24 AM
Post
#1
|
|
|
New Member ![]() Group: Members Posts: 7 Joined: 16-February 05 Member No.: 12,197 |
Anyway, I'm running Win2000 and my computer keeps re-booting during a scan with any/all of the following anti-virus/spyware programs (It's also running REALLY slow): * AVG (computer boots up with this one) * Ad-Aware * McAfee * NoAdware * SpyBot * BitDefender I'm able to download the updates for all the above. Internet works as well as all other applications. I also have KillBox which appears to function, HijackThis and CWShredder which work and I'm able to get logs from those. According to the previous help forum I visited, the HJT log looks clean. NOTE: No viruses/spyware are found by the programs prior to the re-boot. I shut off the auto-reboot, so I get a 'blue screen' error message. Just prior to logging on to this site I attempted a manual scan with AVG. Here's a fresh blue screen error message I wrote out by hand when the scan was interrupted: "*** STOP: 0x0000001E (0xC0000005,0xF7298459,0x00000000,0x007C8EF2) KMODE_EXCEPTION_NOT_HANDLED ***Address F7298459 base at F7298000, DateStamp 42068a5e - vdmt16.sys Beginning dump of physical memory Physical memory dump complete. Contact your system administrator or technical support group." The other forum seemed to think the problem was with vdmt16.sys being associated with Backdoor/Haxdoor/Horseserver.net. That's as far as they could help me. I did find the information about Horseserver on your Security/Spyware & Malware Self-Help and Reading Room forum. There were registry keys in your topic that weren't in my registry, and others I couldn't remove. Therefore, I still have this pest on my machine. What would you like me to do next? Any assistance is GREATLY appreciated! |
|
|
|
Feb 17 2005, 04:58 PM
Post
#2
|
|
![]() Bleep Bleep! ![]() ![]() ![]() ![]() ![]() ![]() Group: Admin Posts: 29,870 Joined: 24-January 04 From: USA Member No.: 3 |
What operating system are you?
-------------------- Lawrence
|
|
|
|
Feb 17 2005, 06:39 PM
Post
#3
|
|
|
New Member ![]() Group: Members Posts: 7 Joined: 16-February 05 Member No.: 12,197 |
I'm running Windows 2000.
|
|
|
|
Feb 18 2005, 01:02 PM
Post
#4
|
|
![]() Bleep Bleep! ![]() ![]() ![]() ![]() ![]() ![]() Group: Admin Posts: 29,870 Joined: 24-January 04 From: USA Member No.: 3 |
You have a Horseserver infection which requires some tools to get rid of.
-------------------- Lawrence
|
|
|
|
Feb 19 2005, 12:37 PM
Post
#5
|
|
|
New Member ![]() Group: Members Posts: 7 Joined: 16-February 05 Member No.: 12,197 |
Grinler,
Sorry it took so long. I've been working on your solution since last night. The scans took longer than I thought they would. (I ran all 3 you suggested). As you requested, 3 logs are pasted below in this order: HJT Pre-Scan, HS log and HJT Post-Scan: Logfile of HijackThis v1.98.2 Scan saved at 7:46:06 PM, on 2/18/2005 Platform: Windows 2000 SP4 (WinNT 5.00.2195) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINNT\System32\smss.exe C:\WINNT\system32\services.exe C:\WINNT\system32\lsass.exe C:\WINNT\system32\svchost.exe C:\WINNT\system32\spoolsv.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe C:\WINNT\System32\svchost.exe C:\WINNT\system32\regsvc.exe C:\WINNT\system32\MSTask.exe C:\WINNT\System32\WBEM\WinMgmt.exe C:\WINNT\system32\svchost.exe C:\Program Files\Microsoft Hardware\Mouse\point32.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe C:\Program Files\NoAdware3\NoAdware3.exe C:\Program Files\Naviscope\naviscope.exe C:\WINNT\explorer.exe C:\Program Files\Hijack This\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon O4 - HKLM\..\Run: [POINTER] point32.exe O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKCU\..\Run: [NoAdware3] "C:\Program Files\NoAdware3\NoAdware3.exe" O4 - Startup: naviscope.lnk = C:\Program Files\Naviscope\naviscope.exe O8 - Extra context menu item: Download using Download &Express - C:\Program Files\Download Express\Add_Url.htm O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/SSC/SharedCon...bin/AvSniff.cab O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC...n/bin/cabsa.cab ------- Horseserver Removal Tool v1.05 by Atri - - 1. Registry Fix Started - Registry fix complete - 2. Deleted Services - klo5 [SC] OpenService FAILED 1060: The specified service does not exist as an installed service. - 3. Finding files Located on system - klogini.dll p2.ini ps.a3d klo5.sys w32tm.exe - 4. Deleting files that were found. - - 5. Checking for and Removing Winupdate - - - --------------- Logfile of HijackThis v1.98.2 Scan saved at 11:17:34 AM, on 2/19/2005 Platform: Windows 2000 SP4 (WinNT 5.00.2195) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINNT\System32\smss.exe C:\WINNT\system32\winlogon.exe C:\WINNT\system32\services.exe C:\WINNT\system32\lsass.exe C:\WINNT\system32\svchost.exe C:\WINNT\system32\spoolsv.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe C:\WINNT\System32\svchost.exe C:\WINNT\system32\regsvc.exe C:\WINNT\system32\MSTask.exe C:\WINNT\System32\WBEM\WinMgmt.exe C:\WINNT\system32\svchost.exe C:\WINNT\Explorer.EXE C:\Program Files\Microsoft Hardware\Mouse\point32.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe C:\Program Files\NoAdware3\NoAdware3.exe C:\Program Files\Naviscope\naviscope.exe C:\Program Files\Hijack This\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon O4 - HKLM\..\Run: [POINTER] point32.exe O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKCU\..\Run: [NoAdware3] "C:\Program Files\NoAdware3\NoAdware3.exe" O4 - Startup: naviscope.lnk = C:\Program Files\Naviscope\naviscope.exe O8 - Extra context menu item: Download using Download &Express - C:\Program Files\Download Express\Add_Url.htm O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/SSC/SharedCon...bin/AvSniff.cab O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC...n/bin/cabsa.cab O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061...all/xscan53.cab O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab Everything's working great ! YOU ROCK !! |
|
|
|
Feb 19 2005, 11:24 PM
Post
#6
|
|
![]() Bleep Bleep! ![]() ![]() ![]() ![]() ![]() ![]() Group: Admin Posts: 29,870 Joined: 24-January 04 From: USA Member No.: 3 |
Fix this:
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm O4 - HKCU\..\Run: [NoAdware3] "C:\Program Files\NoAdware3\NoAdware3.exe" Can you do a full scan with avg now? -------------------- Lawrence
|
|
|
|
Feb 20 2005, 07:07 AM
Post
#7
|
|
|
New Member ![]() Group: Members Posts: 7 Joined: 16-February 05 Member No.: 12,197 |
Hi Grinler !
I fixed the 2 items in HJT...new log pasted below. Yes, AVG and all other applications are working great ! Once again, YOU ROCK ! THANKS ! As a sidebar, I know I'm supposed to go to another discussion board for this (which I will do shortly), but I wanted the opinion of a tech person. What do you think of the new XP Pro x64 Edition? I'm shopping around for a new PC and the sales guy I talked to yesterday said I should wait for it to come out, rather than get a system with XP Pro now, as I'm going to be getting into radio-control plane flight sims. R/C flight sims are more high-end than Microsoft flight sim. The sales guy has been using the beta version, and said he's had no problems with it. The reason I'm asking is that I get a more than a little nervous about buying Microsoft products in an early version. HJT log: Logfile of HijackThis v1.98.2 Scan saved at 5:28:59 AM, on 2/20/2005 Platform: Windows 2000 SP4 (WinNT 5.00.2195) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINNT\System32\smss.exe C:\WINNT\system32\winlogon.exe C:\WINNT\system32\services.exe C:\WINNT\system32\lsass.exe C:\WINNT\system32\svchost.exe C:\WINNT\system32\spoolsv.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe C:\WINNT\System32\svchost.exe C:\WINNT\system32\regsvc.exe C:\WINNT\system32\MSTask.exe C:\WINNT\System32\WBEM\WinMgmt.exe C:\WINNT\system32\svchost.exe C:\WINNT\Explorer.EXE C:\Program Files\Microsoft Hardware\Mouse\point32.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe C:\Program Files\Naviscope\naviscope.exe C:\Program Files\Hijack This\HijackThis.exe O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon O4 - HKLM\..\Run: [POINTER] point32.exe O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - Startup: naviscope.lnk = C:\Program Files\Naviscope\naviscope.exe O8 - Extra context menu item: Download using Download &Express - C:\Program Files\Download Express\Add_Url.htm O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/SSC/SharedCon...bin/AvSniff.cab O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC...n/bin/cabsa.cab O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061...all/xscan53.cab O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab |
|
|
|
Feb 20 2005, 01:15 PM
Post
#8
|
|
![]() Bleep Bleep! ![]() ![]() ![]() ![]() ![]() ![]() Group: Admin Posts: 29,870 Joined: 24-January 04 From: USA Member No.: 3 |
Its nice to have the 64bit, but there is hardly any software that really takes advantage of it. May be better off in waiting for now
Log looks clean...great job! Now that you are clean, please follow these simple steps in order to keep your computer clean and secure:
Glad I was able to help. -------------------- Lawrence
|
|
|
|
Feb 20 2005, 04:10 PM
Post
#9
|
|
|
New Member ![]() Group: Members Posts: 7 Joined: 16-February 05 Member No.: 12,197 |
Grinler,
I'll be using your info to keep my computer clean. Thanks ! |
|
|
|
![]() ![]() |
| Lo-Fi Version | Time is now: 8th January 2009 - 08:18 PM |