Author Topic: Trojan.Horse.Win32.PAV.64.a  (Read 4202 times)

0 Members and 1 Guest are viewing this topic.

Offline ScottishThistle

  • Newbie
  • *
  • Posts: 22
Trojan.Horse.Win32.PAV.64.a
« on: October 30, 2010, 03:17:14 PM »
Help! I believe Trojan.Horse.Win32.PAV.64.a is what is messing up my computer.  I found this out by way of Microsoft Security Essentials.  I have Windows XP as my OS.  I start up my computer and am only able to be on it for a couple of minutes before it stalls everything.  I was lucky enough to get MSE up and running long enough to get the information in the subject line.  I was asked to "scan online" for a solution, one was found, and I was asked if I wanted to download the solution and that's as far as I got.  Everything stalled.

Online Corrine

  • The Mystical Rose
  • Administrator
  • Hero Member
  • *****
  • Posts: 11542
  • "Stronger than the past, united in our goal."
    • Security Garden
Re: Trojan.Horse.Win32.PAV.64.a
« Reply #1 on: October 30, 2010, 07:50:08 PM »
Hi, ScottishThistle.  Welcome to LandzDown Forum.

We will do our best to assist you.  However, in order to do so, please follow all instructions provided in the sequence given.  Do not install/re-install any programs or run any fixes or scanners that you have not been instructed to use.  This may cause conflicts with the tools being used in the cleanup process.   

If you have questions regarding any of the instructions or problems running any tools, please let us know.

Please note that it is possible that the infection you are trying to remove will not allow you to download files on the infected computer. If this is the case, then you will need to download the files requested in this guide on another computer and then transfer them to the infected computer. You can transfer the files via a CD/DVD, external drive, or USB flash drive.

Just as well that everything stalled.  You have a nasty rogue installed on your computer.  The instructions are complicated but since they are so nicely illustrated at Bleeping Computer, I am asking that you carefully follow the instructions there:  http://www.bleepingcomputer.com/virus-removal/remove-thinkpoint

Please post the MBAM log here as a reply.  It is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.

Next, Please download random's system information tool (RSIT):
  • Download RSIT by random/random from here and save it to your desktop.
    Note:  If you have a 64-bit OS, please download random's system information tool (RSIT)from
  • Double-click RSIT.exe to run RSIT.
  • Click Continue at the disclaimer screen.
  • Once it has finished, two logs will open. Please post the contents of both log.txt (<<will be maximized) and info.txt (<<will be minimized).
,  

Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.

Offline ScottishThistle

  • Newbie
  • *
  • Posts: 22
Re: Trojan.Horse.Win32.PAV.64.a
« Reply #2 on: October 30, 2010, 09:27:28 PM »
Thank you so much for replying so quickly.  I will follow your instructions.  However, it may take me a couple of days (I have a few time constraints).  But I will definitely get back to you with results. 

Thank you again for your help.  It is greatly appreciated!

Kris (scottishthistle)

Offline ScottishThistle

  • Newbie
  • *
  • Posts: 22
Re: Trojan.Horse.Win32.PAV.64.a
« Reply #3 on: October 30, 2010, 09:59:23 PM »
I hope this is what you are needing. 

Thanks!
Kris (scottishthistle)

~~~~~~~~~~~~~~~~~~~~~~~~~~~~


Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4938

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

10/24/2010 6:13:43 PM
mbam-log-2010-10-24 (18-13-43).txt

Scan type: Full scan (C:\|)
Objects scanned: 260568
Time elapsed: 1 hour(s), 4 minute(s), 7 second(s)

Memory Processes Infected: 1
Memory Modules Infected: 0
Registry Keys Infected: 15
Registry Values Infected: 3
Registry Data Items Infected: 0
Folders Infected: 11
Files Infected: 25

Memory Processes Infected:
C:\Program Files\Adparatus\Adparatus.exe (Adware.Adparatus) -> Unloaded
process successfully.

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\Interface\{d0b60438-57e7-44de-8f8e-6c3bf305d430}
(Adware.Adparatus) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{8b2c7c9d-716d-4e9e-9358-b9c80a81b7ed}
(Adware.Adparatus) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{a4bca928-b566-49c6-aef1-50bf8673f5cf}
(Adware.Adparatus) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{8b
2c7c9d-716d-4e9e-9358-b9c80a81b7ed} (Adware.Adparatus) -> Quarantined and
deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{8b2c7
c9d-716d-4e9e-9358-b9c80a81b7ed} (Adware.Adparatus) -> Quarantined and
deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\adpar
atus (Adware.Adparatus) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\space
query (Adware.SpaceQuery) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\AppDataLow\Software\MarketPrecision
(Adware.Adparatus) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\MarketPrecision\Adparatus (Adware.Adparatus) ->
Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\MarketPrecision\DuhikiToolbar (Malware.Trace) ->
Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\MarketPrecision\Adparatus (Adware.Adparatus) ->
Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\ESENT\Process\Adparatus
(Adware.Adparatus) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\SpaceQuery (Adware.SpaceQuery) -> Quarantined
and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SPACEQUERY_SERV
ICE (Adware.SpaceQuery) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SpaceQuery Service
(Adware.SpaceQuery) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\adparatus
(Adware.Adparatus) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\.exe\shell\open\command\(default) (Hijack.ExeFile) ->
Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\secfile\shell\open\command\(default) (Rogue.MultipleAV) ->
Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\Documents and Settings\All Users\Application Data\SpaceQuery
(Adware.SpaceQuery) -> Quarantined and deleted successfully.
C:\Program Files\Adparatus (Adware.Adparatus) -> Quarantined and deleted
successfully.
C:\Program Files\Adparatus\FF (Adware.Adparatus) -> Quarantined and deleted
successfully.
C:\Program Files\Adparatus\FF\2594 (Adware.Adparatus) -> Quarantined and
deleted successfully.
C:\Program Files\Adparatus\FF\2594\components (Adware.Adparatus) ->
Quarantined and deleted successfully.
C:\Program Files\Mozilla
Firefox\extensions\{0A328249-98DF-476C-9D25-3853C961DAB9} (Adware.Agent) ->
Quarantined and deleted successfully.
C:\Program Files\Mozilla
Firefox\extensions\{0A328249-98DF-476C-9D25-3853C961DAB9}\chrome
(Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Mozilla
Firefox\extensions\{0A328249-98DF-476C-9D25-3853C961DAB9}\defaults
(Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Mozilla
Firefox\extensions\{0A328249-98DF-476C-9D25-3853C961DAB9}\defaults\preferenc
es (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\SpaceQuery (Adware.SpaceQuery) -> Quarantined and deleted
successfully.
C:\Documents and Settings\HP_Administrator\Start Menu\Programs\Adparatus
(Adware.Adparatus) -> Quarantined and deleted successfully.

Files Infected:
C:\Program Files\Adparatus\Adparatus.exe (Adware.Adparatus) -> Quarantined
and deleted successfully.
C:\Documents and Settings\All Users\Application
Data\SpaceQuery\spacequery135.exe (Adware.SpaceQuery) -> Quarantined and
deleted successfully.
C:\Program Files\Adparatus\AdparatusResources.dll (Adware.Adparatus) ->
Quarantined and deleted successfully.
C:\Program Files\Adparatus\Uninstall.exe (Adware.Adparatus) -> Quarantined
and deleted successfully.
C:\Program Files\Adparatus\FF\2594\components\Adparatus2594.dll
(Adware.Adparatus) -> Quarantined and deleted successfully.
C:\Program Files\SpaceQuery\spacequery.exe (Adware.SpaceQuery) ->
Quarantined and deleted successfully.
C:\System Volume
Information\_restore{D7BD54B8-C977-4903-8CE7-9415B851EC71}\RP1310\A0365865.d
ll (Adware.Adparatus) -> Quarantined and deleted successfully.
C:\WINDOWS\temp\SPA1F.tmp\upgrade.exe (Adware.Dropper.Gen) -> Quarantined
and deleted successfully.
C:\WINDOWS\temp\SPA4.tmp\upgrade.exe (Adware.Zwangi) -> Quarantined and
deleted successfully.
C:\WINDOWS\temp\SPA5.tmp\upgrade.exe (Adware.Dropper.Gen) -> Quarantined and
deleted successfully.
C:\WINDOWS\temp\SPA7.tmp\upgrade.exe (Adware.Dropper.Gen) -> Quarantined and
deleted successfully.
C:\WINDOWS\temp\SPA9.tmp\upgrade.exe (Adware.Dropper.Gen) -> Quarantined and
deleted successfully.
C:\WINDOWS\temp\SPAE.tmp\upgrade.exe (Adware.Dropper.Gen) -> Quarantined and
deleted successfully.
C:\Program Files\Adparatus\Adparatus.ico (Adware.Adparatus) -> Quarantined
and deleted successfully.
C:\Program Files\Adparatus\Support.url (Adware.Adparatus) -> Quarantined and
deleted successfully.
C:\Program Files\Adparatus\FF\2594\chrome.manifest (Adware.Adparatus) ->
Quarantined and deleted successfully.
C:\Program Files\Adparatus\FF\2594\install.rdf (Adware.Adparatus) ->
Quarantined and deleted successfully.
C:\Program Files\Mozilla
Firefox\extensions\{0A328249-98DF-476C-9D25-3853C961DAB9}\chrome.manifest
(Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Mozilla
Firefox\extensions\{0A328249-98DF-476C-9D25-3853C961DAB9}\install.rdf
(Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Mozilla
Firefox\extensions\{0A328249-98DF-476C-9D25-3853C961DAB9}\chrome\spacequery.
jar (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Mozilla
Firefox\extensions\{0A328249-98DF-476C-9D25-3853C961DAB9}\defaults\preferenc
es\prefs.js (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\SpaceQuery\uninstall.exe (Adware.SpaceQuery) -> Quarantined
and deleted successfully.
C:\Documents and Settings\HP_Administrator\Start
Menu\Programs\Adparatus\About Adparatus.lnk (Adware.Adparatus) ->
Quarantined and deleted successfully.
C:\Documents and Settings\HP_Administrator\Start
Menu\Programs\Adparatus\Adparatus Support.lnk (Adware.Adparatus) ->
Quarantined and deleted successfully.
C:\Documents and Settings\HP_Administrator\Start
Menu\Programs\Adparatus\Uninstall Adparatus.lnk (Adware.Adparatus) ->
Quarantined and deleted successfully.


Online Corrine

  • The Mystical Rose
  • Administrator
  • Hero Member
  • *****
  • Posts: 11542
  • "Stronger than the past, united in our goal."
    • Security Garden
Re: Trojan.Horse.Win32.PAV.64.a
« Reply #4 on: October 30, 2010, 11:13:45 PM »
Good job, Kris! Now let's take a look at an RSIT log.  Please refer to the instructions above.

,  

Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.

Offline ScottishThistle

  • Newbie
  • *
  • Posts: 22
Re: Trojan.Horse.Win32.PAV.64.a
« Reply #5 on: October 31, 2010, 04:09:29 PM »
Ok, that will take me a while, but I'll get back with it. 

Thanks!!!
Kris

Offline ScottishThistle

  • Newbie
  • *
  • Posts: 22
Re: Trojan.Horse.Win32.PAV.64.a
« Reply #6 on: October 31, 2010, 05:29:06 PM »

I'm working on the instructions to get rid of ThinkPoint.  I got to this step:

8.When the Create New Task prompt appears, type explorer.exe into the Open: field and press the OK button. After a minute or so you should be back at your Windows desktop.

I did exactly as is said then after a few minutes I got two messages:

1.  Generic Host Process for Win32 Services has encountered a problem and needs to close (with the "send error report" and the "Don't send" buttons).
2.  svchost.exe - Application Error:  The instruction at 0x7c923845 referenced memory at 0x00000000.  The memory could not be read.  OK to terminate program or CANCEL to debug the program


Online Corrine

  • The Mystical Rose
  • Administrator
  • Hero Member
  • *****
  • Posts: 11542
  • "Stronger than the past, united in our goal."
    • Security Garden
Re: Trojan.Horse.Win32.PAV.64.a
« Reply #7 on: October 31, 2010, 06:29:09 PM »
Hi, Kris.

I'm a bit confused.  When you posted the MBAM log, I was of the understanding (misunderstanding?) that you had gone through the instructions at Bleeping Computer already.

So we can see where things stand, please download random's system information tool (RSIT):
  • Download RSIT by random/random from here and save it to your desktop.
    Note:  For users with 64-bit systems, please download RSIT from here
  • Double-click RSIT.exe to run RSIT.
  • Click Continue at the disclaimer screen.
  • Once it has finished, two logs will open. Please post the contents of both log.txt (<<will be maximized) and info.txt (<<will be minimized).


,  

Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.

Offline ScottishThistle

  • Newbie
  • *
  • Posts: 22
Re: Trojan.Horse.Win32.PAV.64.a
« Reply #8 on: October 31, 2010, 06:40:57 PM »
Sorry, I actually already had MBAM on the computer and had run it.  That's the log I posted.  I'll follow your newest instructions and post those logs.

Thanks!
Kris

Offline ScottishThistle

  • Newbie
  • *
  • Posts: 22
Re: Trojan.Horse.Win32.PAV.64.a
« Reply #9 on: October 31, 2010, 06:47:09 PM »
One question. . . . . I've downloaded RSIT to a flashdrive because my computer stalls after just a few minutes.  Should I run RSIT on my computer in safe mode?

Online Corrine

  • The Mystical Rose
  • Administrator
  • Hero Member
  • *****
  • Posts: 11542
  • "Stronger than the past, united in our goal."
    • Security Garden
Re: Trojan.Horse.Win32.PAV.64.a
« Reply #10 on: October 31, 2010, 07:36:00 PM »
I should have looked closer and seen that you hadn't updated MBAM to the latest defs 5005.

Have you restarted the computer since receiving the above error message? 

Do you get your regular desktop or is hotfix.exe running?

Let's first see if RKill helps. Please download rkill from one of the following links and transport it to your Desktop:

One, Two,Three or Four
  • Double-click rkill to run.
  • A command window will open then disappear upon completion, this is normal.
  • Please leave rkill on the Desktop until otherwise advised.
  • Do NOT restart your computer after running rkill as the malware program(s) will start again.
Notes:

If you you receive security warnings about rkill, please ignore and allow the download to continue.

Now see if you can update MBAM and run a fresh scan.  Follow that with RSIT in normal mode.

In the event you cannot do the above, yes, please run RSIT in safe mode.
,  

Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.

Offline ScottishThistle

  • Newbie
  • *
  • Posts: 22
Re: Trojan.Horse.Win32.PAV.64.a
« Reply #11 on: October 31, 2010, 09:59:44 PM »
Have you restarted the computer since receiving the above error message?  Yes, I have a couple of times.  And I have just restarted it.  This time I got a window saying that CHKDSK is verifying files.  Then the computer started.  I got the THINKPOINT screen up again.  So I am following those directions once again. 

Do you get your regular desktop or is hotfix.exe running? I don't think it's hotfix.exe since I'm having to follow those directions again. 


Offline ScottishThistle

  • Newbie
  • *
  • Posts: 22
Re: Trojan.Horse.Win32.PAV.64.a
« Reply #12 on: October 31, 2010, 10:18:52 PM »
I went back over the instructions again after receiving the ThinkPoint screen again:  task manager; hotfix.exe and end process; then new task with explorer.exe and I got my desktop back.  I plugged in my flashdrive and ran Shell and merged the data.  Then I clicked on Rkill.  I now have a screen saying "Processes terminated by Rkill or while it was running: Rkill completed on 10/31/2010 at 17:03:18. However, the next step is to download MBAM and I no longer have my destop, it's just my background picture.  And the instructions say that I shouldn't reboot my computer.




Online Corrine

  • The Mystical Rose
  • Administrator
  • Hero Member
  • *****
  • Posts: 11542
  • "Stronger than the past, united in our goal."
    • Security Garden
Re: Trojan.Horse.Win32.PAV.64.a
« Reply #13 on: October 31, 2010, 10:39:30 PM »
Hi, Kris.

Ok, let's use the MBAM command lines to update and scan:

Click Start, Type Run.  In the run box, enter the following (note the space before the backslash):  mbam.exe /update
Following the update, open the run box again and enter the following:  mbam.exe /update

Note:  If you ended restarting the computer, just run RKill again.
,  

Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.

Offline ScottishThistle

  • Newbie
  • *
  • Posts: 22
Re: Trojan.Horse.Win32.PAV.64.a
« Reply #14 on: November 03, 2010, 10:52:48 PM »
Sorry it took so long to do this, but I made a little progress.  So here's where I'm at -
1.  Was able to run the computer long enough to update MBAM then it stalled.
2.  Opened the computer in safe mode and ran Rkill.
3.  Did a new scan with MBAM.  Here is the log from that scan:
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 5026

Windows 5.1.2600 Service Pack 3 (Safe Mode)
Internet Explorer 8.0.6001.18702

11/2/2010 9:44:28 PM
mbam-log-2010-11-02 (21-44-28).txt

Scan type: Full scan (C:\|D:\|E:\|F:\|G:\|H:\|I:\|J:\|)
Objects scanned: 279253
Time elapsed: 1 hour(s), 46 minute(s), 57 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 19

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\iqajahigafekuteg (Trojan.Hiloti.Gen) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\HPZi32.dll (Trojan.Hiloti.Gen) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Administrator\Application Data\hotfix.exe (Trojan.FakeAV) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Administrator\Local Settings\temp\glsdeeoq.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Administrator\Local Settings\temp\kxtkd.exe (Trojan.FakeAV) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Administrator\Local Settings\temp\orrm.exe (Trojan.Hiloti.Gen) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Administrator\Local Settings\temp\qbxwd.exe (Trojan.Clicker.IF) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\069Y1102\aaick[1].htm (Trojan.Clicker.IF) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\1LWCATM3\imdysnucxe[1].htm (Rootkit.MBR) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\1LWCATM3\tkbvqkfdls[1].htm (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\1LWCATM3\xbsnusnvp[1].htm (Trojan.Hiloti.Gen) -> Quarantined and deleted successfully.

C:\Documents and Settings\HP_Administrator\Local Settings\Temporary Internet Files\Content.IE5\ECQWEWPF\rhlgoidbwq[1].htm (Trojan.FakeAV) -> Quarantined and deleted successfully.
C:\Documents and Settings\NetworkService\Application Data\hotfix.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{D7BD54B8-C977-4903-8CE7-9415B851EC71}\RP1313\A0376290.dll (Trojan.Lukicsel) -> Quarantined and deleted successfully.
C:\WINDOWS\temp\b3wt05s2.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\temp\D.tmp (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\temp\_1F1.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\temp\_1F2.tmp (Trojan.Lukicsel) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\crt.dat (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\shimg.dll (Trojan.Agent) -> Quarantined and deleted successfully.