Click here for AnswerPool.com Home page


Google

    AnswerPool.com  Hop To Forum Categories  Computers  Hop To Forums  Security Issues    Virus that keeps coming back!

Moderators: Dwight
Go
Post
Find
Notify
Tools
Reply
  
  Login/Join 
Platinum
Enthusiast
Posted
Yesterday our virus detector (called "Avast") detected a virus (I think it is a trojan?). We followed the directions and removed it. The computer was working fine until we clicked on internet Explorer. As soon as we opened explorer, the same virus came back! We removed it again, but every time we open explorer, the virus returns. What can we do?
 
Posts: 2241 | Location: In between | Registered: 06-03-02Reply With QuoteEdit or Delete MessageReport This Post
Diamond Enthusiast

Picture of bedstor
Posted Hide Post
Depending on what this could be there are lots of things to do..

I'm hoping this is a "False Positive" alert the scan has "thought" that something downloaded recently , temporary plug-in perhaps for a file ? The code matches a signature in the Virus programs list
A good pointer to it being a "Bogey" is if you have a 2nd A/V program running Such as AVG which stays silent
I had such a thing happen the other day to me
An old program file which was left by an uninstall started a Virus alert on AVG but NOT on Avast! Confused
No link to the " Program file" in Search No Idea of what was doing this Roll Eyes
So I wheeled out my Crap Cleaner Program (www.ccleaner.com) Ran it and gained a lot of Space as usual Cool And it removed all the files that were pointing to nowhere.Untick the check list box for (Cookies) before you run this.
Otherwise you'll have to log on everywhere again (and lose some "Save points") Frown
Do this offline then log on again you may have a small lag (pages loading) at first but will disappear when the Temp file cache starts filling up Smile
Any difference?
 
Posts: 13485 | Location: 6 miles west of Wigan UK | Registered: 06-05-02Reply With QuoteEdit or Delete MessageReport This Post
Platinum
Enthusiast
Posted Hide Post
Still there! Frown

My husband ran Norton AntiVirus and Norton detects it also. We get this message from Norton:

"Norton Antivirus detected a virus.

Object Name: C:/WINDOWS/System32/pnmd.dll
Name: Trojan.StartPage.M
Action taken: It is not possible to repair this file."

Note: The slashes (/) should be going the other way, but I don't know how to type that.

Also, if the wording doesn't sound like standard Norton wording, it's not because of a problem, it's just because of my translation (our Norton Antivirus is in Spanish).

Right now internet access on that computer is sketchy, so I'm typing on my work laptop.

What do you think, Bedstor (or other computer whizzes out there)? Are we in big trouble?
 
Posts: 2241 | Location: In between | Registered: 06-03-02Reply With QuoteEdit or Delete MessageReport This Post
Gold Enthusiast
Posted Hide Post
If you have Windows XP, disable System Restore, then delete the Trojan thru Avast, or move it to the virus chest, then delete it. To disable System Restore, right click on My Computer, click Properties, then click the System Restore tab at the top of the window that opens. Check the box that says "Turn off System Restore on all drives" , then click "Apply", then click "Ok" . Run your virus scan, get rid of what you find, and that Trojan might not come back this time. It could be that in System Restore, the Trojan is re-infecting your system after you delete it. Good luck, hope this helps!

chris
 
Posts: 822 | Location: Wytheville, va. USA | Registered: 09-03-02Reply With QuoteEdit or Delete MessageReport This Post
Diamond Enthusiast

Picture of bedstor
Posted Hide Post
Hi Sarai
I agree 100% with Vansrme (Chris's) Idea
I also think you should make up and submit a Hijackthis log to the forum on this link stating that you have problems with C:/WINDOWS/System32/pnmd.dll
Name: Trojan.StartPage.M

and you cannot delete it Frown
All the instructions for making one of these logs is on the top link in this section
and you'll have to register to post it OK?
Forum is very busy but you'll recieve an answer within an hour or 2
And do follow the instructions given. Normally its ticking boxes on the Hijack this Checklist
Don't be tempted to tick other boxes as you can do serious damage (It's an experts program)
The hijackthis log will look like this (no 2 are alike) this is mine(made recently) and its clean.
quote:
Logfile of HijackThis v1.98.2
Scan saved at 20:46:51, on 06/03/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\system32\cisvc.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\Program Files\BT Voyager 105 ADSL Modem\dslstat.exe
C:\Program Files\BT Voyager 105 ADSL Modem\dslagent.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\XP-PowerPack\Anti-Spam\AntiSpam.exe
C:\Program Files\SETI@home\SETI@home.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\Program Files\Yahoo!\Messenger\ypager.exe
C:\Program Files\LeechGet 2004\LeechGet.exe
C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
C:\Program Files\AOL 9.0\aoltray.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\AOL 9.0\waol.exe
C:\Program Files\AOL 9.0\shellmon.exe
C:\Program Files\Common Files\AOL\aoltpspd.exe
C:\WINDOWS\system32\cidaemon.exe
C:\handy file folder\hijackthis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboForm.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [%FP%Friendly fts.exe] "C:\Program Files\VoyagerTest\fts.exe"
O4 - HKLM\..\Run: [LogitechGalleryRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [DSLSTATEXE] C:\Program Files\BT Voyager 105 ADSL Modem\dslstat.exe icon
O4 - HKLM\..\Run: [DSLAGENTEXE] C:\Program Files\BT Voyager 105 ADSL Modem\dslagent.exe
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [AntiSpam] C:\Program Files\XP-PowerPack\Anti-Spam\AntiSpam.exe -TRAY
O4 - HKCU\..\Run: [seticlient] C:\Program Files\SETI@home\SETI@home.exe -min
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [LeechGet] "C:\Program Files\LeechGet 2004\LeechGet.exe" -intray
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - Global Startup: AOL 9.0 Tray Icon.lnk = C:\Program Files\AOL 9.0\aoltray.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms &] - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms &[ - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: Run DAP - {669695BC-A811-4A9D-8CDF-BA8C795F261C} - (no file)
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm &2 - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=34738&clcid=0x409
O16 - DPF: {2A32B14F-4D29-4EA3-AC54-E9B19F436CE7} (Scanner Class) - http://www.windowsecurity.com/trojanscan/TDECntrl.CAB
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - http://aolcc.aolsvc.aol.co.uk/computercheckup/qdiagcc.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Cont...te.cab?1095693852109
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall...ousecall/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/suite/yautocomplete.cab
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) - http://ax.phobos.apple.com.edgesuite.net/detection/ITDetector.cab
O16 - DPF: {E36C5562-C4E0-4220-BCB2-1C671E3A5916} - http://www.seagate.com/support/disc/asp/tools/en/bin/npseatools.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{DFA5C6CA-1534-4A38-83CB-FB283C9DD3E9}: NameServer = 205.188.146.145

PS Have you got Adaware and Spywareblaster installed? These are the best programs in preventing this from happening again in future (both Free) Cool
 
Posts: 13485 | Location: 6 miles west of Wigan UK | Registered: 06-05-02Reply With QuoteEdit or Delete MessageReport This Post
Platinum
Enthusiast
Posted Hide Post
Chris- I have disabled restore. However, I can't eliminate the virus. Norton says "The virus cannot be eleiminated. There is still one infection."

Bedstore- I can't get online on our home computer. Pop up ads are going nuts and I think being online helps the virus somehow. I'm currently working in Safemode on that computer. If I download the hijackthis log from my other work laptop, will it be useful to me? Or do I have to do it from the infected computer? If it has to be from the infected computer, I can't do it. What else could I try?
 
Posts: 2241 | Location: In between | Registered: 06-03-02Reply With QuoteEdit or Delete MessageReport This Post
Diamond Enthusiast

Picture of bedstor
Posted Hide Post
You said :"Pop-Ups going nuts" means only 2 things
1st You have no Popup prevention software (SpywareBlaster keeps these at bay)and do a weekly update check to keep up the Protection
2nd Windows Messenger is not disabled can do it in Windows security controls but there is an "add-on" for the Ad-Aware SE personal program(www.lavasoft.com)click on Download in Left column) which turns it off with 1 click Cool This is found in the right side of the download page the one Marked Messenger-Control The other OE-W Messengerctrl is for Outlook Express's Manager
Otherwise expect lots of XXX ad popups which seem to bypass the other pop-up stoppers ConfusedMad
And it also can be switched off if you have a Firewall installed?
Ps And you did not say if you were using Broadband? or XP?
With Broadband a Firewall is the first thing you need to have installed (even the Windows version) otherwise within a few minutes your machine will be under attack from all sorts of nasties Mad
Popups will be the least of your problems if this happens Frown Eek
Good News though,If you have XP you can go to www.microsoft.com/athome/security/spyware/product and Download the Microsoft Antispyware Program for free (have to register) This is very strong at keeping nasties away Cool

Back to now the Hijackthis Program is transferable.
Download on one machine(file is about 220K) save the file to floppy install on the other machine,make the log (its a text file)of about 6k upwards. Save that to floppy then load that to your other computer then send that to the Hijackthis Forum get the Instructions back then open the Log on your other computer and do what they say then they may ask you for a 2nd log to see what effect that has done?
Then they'll give you the all-clear or give more instructions.(they only do this if the machine is really choked Frown OK?) You'll have to keep an eye on the Forum answers (Note the Authorised readers have their screennames marked as such)anybody else's answer must NOT be trusted OK?
The whole job will take you about half an Hour?
But as you can see in the posting above there are some items that have lots of numbers Roll Eyes If you can get somebody to double check while you are ticking the boxes,
then it'll make things a lot easier(maybe they'll learn something as well? as well as making the time seem to go faster? Wink

This message has been edited. Last edited by: bedstor,
 
Posts: 13485 | Location: 6 miles west of Wigan UK | Registered: 06-05-02Reply With QuoteEdit or Delete MessageReport This Post
Posted Hide Post
OK I know this is an old thread but try looking up startpage.m and symantec in google and see what symantec security response has to say - may give you some joy? Can't say I've had much luck tracking down that particular .dll though. Good luck from all the threes
 
Posts: 1 | Location: Peckham, mate | Registered: 10-17-05Reply With QuoteEdit or Delete MessageReport This Post
Diamond
Enthusiast

Picture of Mozart
Posted Hide Post
Sarai never replied to let us know if her problems had been taken care of.I guess she's alright now. Complete removal instructions can be found here.
 
Posts: 6358 | Location: u.s.a, south Florida | Registered: 06-03-02Reply With QuoteEdit or Delete MessageReport This Post
Platinum
Enthusiast
Posted Hide Post
Sorry I never updated you! We weren't able to fix it ourselves. We ended up calling a computer guy who is a friend of ours. He wasn't able to fix it either, and we ended up erasing everything and re-installing the hard drive.

Thanks for your help, everyone!
 
Posts: 2241 | Location: In between | Registered: 06-03-02Reply With QuoteEdit or Delete MessageReport This Post
 Previous Topic | Next Topic powered by eve community  
 

    AnswerPool.com  Hop To Forum Categories  Computers  Hop To Forums  Security Issues    Virus that keeps coming back!

© 2002-2008 AnswerPool.com



Visit DiscussionPool.com!