go to trendmicro.com go to feetools and download the Rootkit buster, removed the rootkits. After the reboot, use Malwarebytes to remove the other infected files.
Still having problem:
http://siri.geekstogo.com/
Main Topics
Browse All TopicsI had the windows antivirus pro and believed I removed it by the following steps.
First I ran my Symantec Antivirus software, it didn't find anything.
Then I found these directions and followed them:
Find and Remove Windows Antivirus Pro registry values:
HKEY_CURRENT_USER\Software
HKEY_CURRENT_USER\Software
HKEY_CLASSES_ROOT\CLSID\{4
HKEY_CLASSES_ROOT\CLSID\{F
HKEY_LOCAL_MACHINE\SOFTWAR
HKEY_LOCAL_MACHINE\SOFTWAR
HKEY_LOCAL_MACHINE\SYSTEM\
HKEY_LOCAL_MACHINE\SYSTEM\
Find and Delete Windows Antivirus Pro Files:
%UserProfile%\Desktop\Wind
%UserProfile%\Start Menu\Programs\Windows Antivirus Pro
%UserProfile%\Start Menu\Programs\Windows Antivirus Pro\Windows Antivirus Pro.lnk
c:\Program Files\Windows Antivirus Pro\
c:\Program Files\Windows Antivirus Pro\ANTI_files.exe
c:\Program Files\Windows Antivirus Pro\msvcm80.dll
c:\Program Files\Windows Antivirus Pro\msvcp80.dll
c:\Program Files\Windows Antivirus Pro\msvcr80.dll
c:\Program Files\Windows Antivirus Pro\Windows Antivirus Pro.exe
C:\Program Files\Windows Antivirus Pro\tmp\
C:\Program Files\Windows Antivirus Pro\tmp\dbsinit.exe
C:\Program Files\Windows Antivirus Pro\tmp\wispex.html
C:\Program Files\Windows Antivirus Pro\tmp\images\
C:\Program Files\Windows Antivirus Pro\tmp\images\i1.gif
C:\Program Files\Windows Antivirus Pro\tmp\images\i2.gif
C:\Program Files\Windows Antivirus Pro\tmp\images\i3.gif
C:\Program Files\Windows Antivirus Pro\tmp\images\j1.gif
C:\Program Files\Windows Antivirus Pro\tmp\images\j2.gif
C:\Program Files\Windows Antivirus Pro\tmp\images\j3.gif
C:\Program Files\Windows Antivirus Pro\tmp\images\jj1.gif
C:\Program Files\Windows Antivirus Pro\tmp\images\jj2.gif
C:\Program Files\Windows Antivirus Pro\tmp\images\jj3.gif
C:\Program Files\Windows Antivirus Pro\tmp\images\l1.gif
C:\Program Files\Windows Antivirus Pro\tmp\images\l2.gif
C:\Program Files\Windows Antivirus Pro\tmp\images\l3.gif
C:\Program Files\Windows Antivirus Pro\tmp\images\pix.gif
C:\Program Files\Windows Antivirus Pro\tmp\images\t1.gif
C:\Program Files\Windows Antivirus Pro\tmp\images\t2.gif
C:\Program Files\Windows Antivirus Pro\tmp\images\up1.gif
C:\Program Files\Windows Antivirus Pro\tmp\images\up2.gif
C:\Program Files\Windows Antivirus Pro\tmp\images\w1.gif
C:\Program Files\Windows Antivirus Pro\tmp\images\w11.gif
C:\Program Files\Windows Antivirus Pro\tmp\images\w2.gif
C:\Program Files\Windows Antivirus Pro\tmp\images\w3.gif
C:\Program Files\Windows Antivirus Pro\tmp\images\w3.jpg
C:\Program Files\Windows Antivirus Pro\tmp\images\wt1.gif
C:\Program Files\Windows Antivirus Pro\tmp\images\wt2.gif
C:\Program Files\Windows Antivirus Pro\tmp\images\wt3.gif
c:\WINDOWS\ppp3.dat
c:\WINDOWS\ppp4.dat
c:\WINDOWS\svchast.exe
c:\WINDOWS\system32\bennua
c:\WINDOWS\system32\dddeso
c:\WINDOWS\system32\desot.
c:\WINDOWS\system32\sysnet
Then I tried running Spy Doctor setup and Adaware setup, but they wouldn't work. Anytime I try to run an executable file I now get the "Open With" window, I found a reference to Pretty Park virus on the Microsoft site, but they tell me to rename regedit.exe to regedit.com so I can run it, but I don't see the .exe extension so I can't rename it or run it to edit the registry values. So I assume I have more than one issue.
Please help.
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
go to trendmicro.com go to feetools and download the Rootkit buster, removed the rootkits. After the reboot, use Malwarebytes to remove the other infected files.
Still having problem:
http://siri.geekstogo.com/
Another good rootkit removal tool is UnHackMe (http://www.greatis.com/un
The reason we suspect rootkit, is the inability of your antivirus program to locate the culprit (I am assuming you have some version other than 2009). I had a similar problem when I had 2008 installed. Symantec Antivirus 2009 or Symantec Internet Security 2009 has it all over the older versions. Lower overhead, faster scans and rootkit protection. <--shameless plug---> http://www.compresq.com/sy
Sorry Admin3k, but that file is unverified and not really to be trusted. Why throw a reghack into the mix, when obviously there is something seriously wrong in the registry. I do not trust a link that only lets me download with reading about what it fixes. Educated guess?
PriceD is right on it
Well this seems to have worked. I had done it before I read the other suggestions, so maybe I got lucky. It took me so long because I was waiting for the Symantec to update and run again and I also installed Adaware and ran that too. The last update when I ran Symantec before was in June. It still did not find anything even after the live update today. I am grateful since the only other solutions I had found for people with similar problems were much more complicated, one even had to reinstall Windows!
I think I spoke too soon. Although I can now use some software, there still seems to be other issues.
1. Audio commercials randomly start playing on the computer. (seem to be the same commercials, so maybe they are just audio files that reside on the computer? I did a search for audio files and didn't find anything unusual.
2. When I do a browser search using IE 6 (maybe I should upgrade?, the computer I'm currently on has v7.) If I click on a link from the list it gives me an ad instead of going to the page it should. I can copy and paste the address and get where I want to.
3. I downloaded lavasoft adaware and was able to run it. I also downloaded spyware doctor and the malewarebytes. I was able to install malewarebytes, but it won't run. It won't install spyware doctor at all.
So I have run the most updated symantec virus scan and it found nothing and I ran adaware and it found some things I had it delete, but I still have the above problems.
I also just downloaded and ran hijack this - here is the log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:53:48 AM, on 8/22/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.e
C:\WINDOWS\system32\winlog
C:\WINDOWS\system32\servic
C:\WINDOWS\system32\lsass.
C:\WINDOWS\system32\Ati2ev
C:\WINDOWS\system32\svchos
C:\WINDOWS\System32\svchos
C:\WINDOWS\system32\Ati2ev
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Lavasoft\Ad-Aware\AA
C:\WINDOWS\system32\spools
C:\WINDOWS\system32\wdnpsv
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTra
C:\Program Files\Microsoft Office\Office12\GrooveMoni
C:\WINDOWS\system32\NWTRAY
C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe
C:\WINDOWS\system32\ctfmon
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\Program Files\Novell\ZENworks\NALD
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
C:\Program Files\Novell\ZENworks\naln
C:\Program Files\Novell\ZENworks\Remo
C:\Program Files\Novell\ZENworks\Remo
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Novell\ZENworks\wm.e
C:\Program Files\Lavasoft\Ad-Aware\AA
C:\Program Files\Novell\ZENworks\WMRU
C:\Program Files\Internet Explorer\Iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThi
R0 - HKCU\Software\Microsoft\In
R1 - HKLM\Software\Microsoft\In
R1 - HKCU\Software\Microsoft\In
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-7
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTra
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMoni
O4 - HKLM\..\Run: [ZENRC Tray Icon] C:\WINDOWS\system32\zentra
O4 - HKLM\..\Run: [NWTRAY] NWTRAY.EXE
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: Application Explorer.lnk = C:\Program Files\Novell\ZENworks\NALD
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-0
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-0
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3
O9 - Extra button: Novell delivered applications - {C1994287-422F-47aa-8E5E-6
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-0
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-0
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.
O14 - IERESET.INF: START_PAGE_URL=http://coll
O15 - Trusted Zone: *.video.ccps (HKLM)
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3
O18 - Filter: application/xhtml+xml; charset=iso-8859-1 - {32F66A26-7614-11D4-BD11-0
O18 - Filter: application/xhtml+xml; charset=utf-8 - {32F66A26-7614-11D4-BD11-0
O18 - Filter: text/xml; charset=iso-8859-1 - {32F66A26-7614-11D4-BD11-0
O18 - Filter: text/xml; charset=utf-8 - {32F66A26-7614-11D4-BD11-0
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2ev
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Client Update Service for Novell (cusrvc) - Novell, Inc. - C:\WINDOWS\system32\cusrvc
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AA
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEU
O23 - Service: Novell Application Launcher (NALNTSERVICE) - Novell, Inc. - C:\Program Files\Novell\ZENworks\naln
O23 - Service: Novell ZfD Wake on LAN Status Agent (Prometheus Wake-On-LAN Status Agent) - Novell Inc. - C:\Program Files\Novell\ZENworks\Remo
O23 - Service: Novell ZfD Remote Management (Remote Management Agent) - Novell Inc. - C:\Program Files\Novell\ZENworks\Remo
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: RUMBA AS/400 Shared Folders (Wdworkstation) - NetManage Incorporated - C:\WINDOWS\system32\wdnpsv
O23 - Service: Workstation Manager (ZFDWM) - Novell, INC. - C:\Program Files\Novell\ZENworks\wm.e
Thanks again for your help
-upgrade to IE7 or IE8 , both offer much better security, you may also wish to upgrade to XP Service pack 3 from windows update website
- if there is still an infection that wont let you run Malwarebytes or other, you should try combofix
download & rename first before running
http://www.bleepin
you should be able to run MBAM or other tools afterwards, show us the log of Combofix if the problem persists.
how do you rename, if I don't see the extensions? I found that when I try it must retain the original extension, because yesterday I tried to rename regedit which is how it shows up on my computer and it just created an additional regedit.com that also wouldn't start.
I assume that may be a setting on the computer?
From what I read through google searching, aummsgwndname.exe is associated with Adobe Reader. Try uninstalling Adobe, run a free registry scanner like pctools - Registry Mechanic and clean the registry. Reboot and see if you get the error again. If not, download and install again Adobe Reader. If you are familiar enough with regedit (create a system restore point first) go to HKLM\Software\Microsoft\Wi
or get the .exe from this from here
http://www.winhelponline.c
Note:No need to rename just run it exefix_xp.com
So far I have updated to IE8, and downloaded the combofix, but it would not run. . . So I went back to the second comment from PriceD ID #25157015 and downloaded the rootkitbuster from Trendmicro - after that loaded, scanned, deleted and restarted, I was able to run the malwarbytes. So far so good, the search links are working, all software seems to be working, so far no audio playing on its own.
I tried to start a new question, but I don't have enough points to do so? Sorry PriceD, next time I will wait 24 hrs before I assume the problem is solved.
I should mention that when it restarted it did a check disk? I assume since it did actually start that it is ok.
Thank you ALL for your time and expertise!
Business Accounts
Answer for Membership
by: Admin3kPosted on 2009-08-21 at 17:30:50ID: 25156908
Try this fix for XP
http://filext.com/WinXP_ EXE_Fix.re g
you can also try running Command.com
then copy regedit.exe regedit.com
& use that to edit registry as nereded.
you should follow that up with a full antivirus scan.