This thread's last reply is from November 28, 2006, 5:06 AM UTC. Software, malware, and removal-tool
advice below may be out of date — treat specific steps and download links with caution.
Hi, i have spybot S&D, ad-aware se, spywareblaster, spywareguard and bidefender v10 installed.
i ran scans and detected that trojan name AstaKiller in spybot and bitdefender.
so both detected mezziacodec.chl. when i fix using spybot, mce showed an error 'specified cast is not valid' when i try to play music or video. after recover the registry, mce is good. (i'm using windows xp media center edition)
Logfile of HijackThis v1.99.1
Scan saved at 4:00:11 AM, on 11/11/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Sorry for the delay. You posted twice to your topic so helpers searching for 0 reply topics missed your topic...
What is the current state of the SpyBot S&D findings ?
Have you restored those ?
I'm thinking that this might be a false positive from Spybot S&D :
AstaKiller: Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{6BF52A52-394A-11D3-B153-00C04F79FAA6}
You seem to have disabled some of the startups. I need to see what is disabled in case there is some malware lurking there...
Go to Start >Run and type "Notepad" without the quotes
Copy the text from the quotebox to Notepad.
Go to the menu at the top of the Notepad file and Save as:
Name the file peek.bat
Save as Type: All files
Select the desktop icon on the left to save it on the desktop.
Double click on peek.bat and let it run.
When finished it will open a file in Notepad.
That file will be named startup.txt
Please post the contents of startup.txt into your next reply here.
if not exist Files MkDir Files
regedit /e peek1.txt "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg"
regedit /e peek2.txt "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder"
type peek1.txt >> startup.txt
type peek2.txt >> startup.txt
del peek*.txt
start notepad startup.txt
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\BigDog303]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="VM303_STI"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\VM303_STI.EXE VIMICRO USB PC Camera (ZC0301PLH)"
"inimapping"="0"
The following is a verified false positive from Spybot S&D (It shouldn't have been removed)
AstaKiller: Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{6BF52A52-394A-11D3-B153-00C04F79FAA6}
So if you have the entry in quarantine at the moment, restore it. Then update the latest definitions to Spybot S&D, the entry shouldn't be flagged again.
Your HijackThis log looks good but there is this one thing that I want to point out...
The unregistered version of FlashGet serves up Ads in Internet Explorer that are downloaded from Cydoor servers. I would suggest removing it if it is this version. The registered version supposedly does not... so it should be ok. You can find safer alternatives. Please uninstall FlashGet in the Control Panel /Add Remove programs.
Right click the running icon of Spywareguard in the system tray to open the program. Then go to Menu, File, and choose Exit. It will automatically restart at next boot. (otherwise it may interfere with our cleaning process)
These are the items to fix in HijackThis.
O2 - BHO: IeCatch5 Class - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\PROGRA~1\FlashGet\jccatch.dll
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
O8 - Extra context menu item: Download All by FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\Program Files\FlashGet\jc_link.htm
This is the folder to remove - C:\Program Files\FlashGet
I already remove the flashget and the flashget folder.
When you said fix items in HijackThis, do you mean fix the selected items using the HijackThis, or simply remove the flashget folder.
And this is the Kapersky scan report.
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Thursday, November 23, 2006 11:10:10 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.83.0
Kaspersky Anti-Virus database last update: 23/11/2006
Kaspersky Anti-Virus database records: 244818
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
C:\
D:\
E:\
Scan Statistics:
Total number of scanned objects: 45256
Number of viruses found: 0
Number of infected objects: 0 / 0
Number of suspicious objects: 0
Duration of the scan process: 00:27:52
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Microsoft\eHome\logs\ehRecvr.log Object is locked skipped
C:\Documents and Settings\All Users\DRM\drmstore.hds Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Mohd Khairul\Application Data\Mozilla\Firefox\Profiles\mq8bvv1z.default\cert8.db Object is locked skipped
C:\Documents and Settings\Mohd Khairul\Application Data\Mozilla\Firefox\Profiles\mq8bvv1z.default\flashgot.log Object is locked skipped
C:\Documents and Settings\Mohd Khairul\Application Data\Mozilla\Firefox\Profiles\mq8bvv1z.default\history.dat Object is locked skipped
C:\Documents and Settings\Mohd Khairul\Application Data\Mozilla\Firefox\Profiles\mq8bvv1z.default\key3.db Object is locked skipped
C:\Documents and Settings\Mohd Khairul\Application Data\Mozilla\Firefox\Profiles\mq8bvv1z.default\parent.lock Object is locked skipped
C:\Documents and Settings\Mohd Khairul\Application Data\Mozilla\Firefox\Profiles\mq8bvv1z.default\search.sqlite Object is locked skipped
C:\Documents and Settings\Mohd Khairul\Application Data\Mozilla\Firefox\Profiles\mq8bvv1z.default\urlclassifier2.sqlite Object is locked skipped
C:\Documents and Settings\Mohd Khairul\Application Data\Skype\umah.mohd.nor\call256.dbb Object is locked skipped
C:\Documents and Settings\Mohd Khairul\Application Data\Skype\umah.mohd.nor\callmember256.dbb Object is locked skipped
C:\Documents and Settings\Mohd Khairul\Application Data\Skype\umah.mohd.nor\chat512.dbb Object is locked skipped
C:\Documents and Settings\Mohd Khairul\Application Data\Skype\umah.mohd.nor\contactgroup256.dbb Object is locked skipped
C:\Documents and Settings\Mohd Khairul\Application Data\Skype\umah.mohd.nor\index2.dat Object is locked skipped
C:\Documents and Settings\Mohd Khairul\Application Data\Skype\umah.mohd.nor\profile16384.dbb Object is locked skipped
C:\Documents and Settings\Mohd Khairul\Application Data\Skype\umah.mohd.nor\transfer256.dbb Object is locked skipped
C:\Documents and Settings\Mohd Khairul\Application Data\Skype\umah.mohd.nor\user1024.dbb Object is locked skipped
C:\Documents and Settings\Mohd Khairul\Application Data\Skype\umah.mohd.nor\voicemail256.dbb Object is locked skipped
C:\Documents and Settings\Mohd Khairul\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Mohd Khairul\Local Settings\Application Data\ApplicationHistory\CLI.EXE.c88dbd71.ini.inuse Object is locked skipped
C:\Documents and Settings\Mohd Khairul\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Mohd Khairul\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Mohd Khairul\Local Settings\Application Data\Mozilla\Firefox\Profiles\mq8bvv1z.default\Cache\_CACHE_001_ Object is locked skipped
C:\Documents and Settings\Mohd Khairul\Local Settings\Application Data\Mozilla\Firefox\Profiles\mq8bvv1z.default\Cache\_CACHE_002_ Object is locked skipped
C:\Documents and Settings\Mohd Khairul\Local Settings\Application Data\Mozilla\Firefox\Profiles\mq8bvv1z.default\Cache\_CACHE_003_ Object is locked skipped
C:\Documents and Settings\Mohd Khairul\Local Settings\Application Data\Mozilla\Firefox\Profiles\mq8bvv1z.default\Cache\_CACHE_MAP_ Object is locked skipped
C:\Documents and Settings\Mohd Khairul\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Mohd Khairul\Local Settings\History\History.IE5\MSHist012006112320061124\index.dat Object is locked skipped
C:\Documents and Settings\Mohd Khairul\Local Settings\Temp\Perflib_Perfdata_19c.dat Object is locked skipped
C:\Documents and Settings\Mohd Khairul\Local Settings\Temp\Perflib_Perfdata_fb0.dat Object is locked skipped
C:\Documents and Settings\Mohd Khairul\Local Settings\Temp\~DF273.tmp Object is locked skipped
C:\Documents and Settings\Mohd Khairul\Local Settings\Temp\~DF9DE3.tmp Object is locked skipped
C:\Documents and Settings\Mohd Khairul\Local Settings\Temp\~DFF7E5.tmp Object is locked skipped
C:\Documents and Settings\Mohd Khairul\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Mohd Khairul\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Mohd Khairul\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{6CDA4837-37D1-47D8-A8BC-DC3B8248ECC2}\RP34\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\Registration\{02D4B3F1-FD88-11D1-960D-00805FC79235}.{07E94163-DB21-4F49-BFF2-58E818C5DBF5}.crmlog Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{57AC998A-7D83-4C9F-8F89-12F16F0FD766}.bin Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\ACEEvent.evt Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\IntelDH.evt Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\Media Ce.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\Temp\tmp0000158a\tmp00000000 Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
D:\Recorded TV\TempRec\TempSBE\MSDVRMM_841055089_131072_1034 Object is locked skipped
D:\Recorded TV\TempRec\TempSBE\SBE1.tmp Object is locked skipped
D:\Recorded TV\TempRec\{1D93A7F4-0218-4EDD-836F-7F4EA192D69D}.TmpSBE Object is locked skipped
D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
D:\System Volume Information\_restore{6CDA4837-37D1-47D8-A8BC-DC3B8248ECC2}\RP34\change.log Object is locked skipped
Scan process completed.
I would like to thank you again for guiding me through this. Thanks a lot.
Sorry for the inconvenience. So you have now removed Flashget and it's folder. There might be some leftovers so run HijackThis, click Do a system scan only, and check the box next to each of these entries if still present. You have to disable SpywareGuard from it's icon before fixing any items. Close all other windows and press Fix checked. If something isn't there, please continue with the next entry in the list.
O2 - BHO: IeCatch5 Class - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\PROGRA~1\FlashGet\jccatch.dll
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
O8 - Extra context menu item: Download All by FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\Program Files\FlashGet\jc_link.htm
Seems to me that your BitDefender doesn't include a firewall. You don't seem to a firewall running, you must install one firewall. NOTE: If you're using Windows XP firewall, I recommend that you install a better firewall. Windows firewall doesn't really provide enough protection.
Disable Windows firewall after installing a new firewall.
Use Firefox browser
Firefox is faster, safer and better browser than Internet Explorer.
Keep your systen up-to-date
Visit Windows Update regularly.
Keep your antivirus and firewall up-to-date
Scan your computer regularly with your antivirus.
Read this article by TonyKlein
So how did I get infected in the first place?
Stand Up and Be Counted !
The site offers people who have been (or are) victims of malware the opportunity to document their story and, in that way, launch a complaint against the malware and the makers of the malware.
I followed all the instructions and installed all the recommended softwares.
I checked for update in SSD, but no update available. When i ran a scan in SSD again, the astakiller threat still exist.
What should I do.
Would you mind take a look this new HijackThis log.
Thanks a lot.
Logfile of HijackThis v1.99.1
Scan saved at 6:03:03 PM, on 11/24/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Nice to hear that you're interested in learning to help others. I can't solve every problem
Here are instructions how to enroll in the Malware Removal University
I forgot to ask. The MVPS Hosts file that you recommend to have, do I need to update it. I think it need to be updated, and doing it is by downloading the new version of the host file. Am I correct?
If it is need to be updated, could you tell me how?
Hi again and yes, you need to keep the hosts file updated.
The easy way is to just download and extract the latest version of hosts.zip file to your desktop. Then just run the mvps.bat file and it will replace the old hosts file with the new one.
There are also tools for managing hosts file, eg Hostsman is a very easy to use tool...
✨ Ask AI about this thread
No ads, no affiliate links — generated on request from this thread's own
archived content, not written by forum staff. Never run a scan/removal tool
as a self-service step if the original thread describes it being done under
a helper's direct supervision, and don't include your name, email, or other
personal details in a follow-up question. See our privacy page
for details on how this works.