Here is the story on what has happened. I was (stupidly) trying to download a TV show from LimeWire. It downloaded really quickly, which should have been my tip off. Doh! I don’t know why, but I opened it. AVG 7.0 caught that it was a Trojan and isolated it. But, it said it could not heal it. I scanned with a couple of other programs and nothing.

Here are the problems

1. No task manager

2. I noticed during the virus scan that there was a weird folder on the hard drive. It is called C:\Documents and Settings\Aaron and Kimberly\! . The file is full of AVI files that are exactly 38.6 KB that are named after TV shows and they were created at the date and time I downloaded the supposed TV show . Obviously these are not videos. This file was hidden in documents and settings. I had to uncheck hide protected operating system files in folder options, which is scary.

I tried to delete the file and it said it was in use by another program. Then I moved on to trying to delete the files that were in the folder. When I tried to do a mass shift delete, it froze (this is the only time it freezes is when I am trying to work with these files or LimeWire). So, I started doing single deletes. The deleted for a while, but then an adaptation occurred and they became read-only. I changed them back and then they froze as I tried to remove them individually.

3. I moved on to try to delete LimeWire. I followed the instructions from this site in a thread about deleting LimeWire on this thread:

http://www.daniweb.com/forums/thread31290.html

I got through the uninstall, but was still left with LimeWire.exe. I tried to delete it and failed. So I decided to move onto the step in the thread about typing regedit in the run box. It says that another program is using this file.

4. Next, I came to this forum and did what the instructions in the file that say please run this before posting. I go to download the newest AVG and it gets almost through the install and gives me a message:

Local machine: installation failed
Installation:
Error: Action failed for file avgssie.dll: file registration....
Error 0x80070020

Here is the error message:

LimeWire version 4.16.6
Java version 1.6.0_05 from Sun Microsystems Inc.
Windows XP v. 5.1 on x86
Free/total memory: 31411032/33357824

com.limegroup.gnutella.gui.GUILoader$StartupFailedException: .\lib\hashes (The system cannot find the file specified)
at com.limegroup.gnutella.gui.GUILoader.sanityCheck(GUILoader.java:286)
at com.limegroup.gnutella.gui.GUILoader.load(GUILoader.java:57)
at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)
at sun.reflect.NativeMethodAccessorImpl.invoke(Unknown Source)
at sun.reflect.DelegatingMethodAccessorImpl.invoke(Unknown Source)
at java.lang.reflect.Method.invoke(Unknown Source)
at com.limegroup.gnutella.gui.Main.main(Main.java:44)

STARTUP ERROR!

I have tried installing three times to no avail. I tried to rerun a scan on another program so I could post any info I get on here, but guess what? None of the work now.


I am getting so frustrated. This is freaking my out. I'm afraid my computer is being used to spread evil. I have always been able to get rid of the few buggies we have gotten. I am feeling like I will ultimately have to back-up our docs and photos to our back-up drive and just wipe the main hard drive clean to do a reinstall. I don’t want the Trojan horse to win though so I thought I would ask for any ideas.

I will be back to check the thread. I have it book marked.


Kimberly

Dani AI

Generated

described a classic persistence infection after a P2P download: security tools partially detect/quarantine items, core Windows utilities are disabled, tiny bogus media files appear and cannot be deleted, and installers fail. Those symptoms usually mean a trojan with startup persistence or a rootkit component that intercepts file and service operations.

Immediate triage (high priority): isolate the machine from the network and avoid using it for anything sensitive. Make a full image if possible; if not, collect personal files from a clean environment (boot a Linux live USB) and copy only data files (documents, photos, etc.). Do not copy executables, installers, or shortcut files. Scan that backup on a known-clean computer with up-to-date AV/malware tools before restoring anything.

Cleanup workflow (in roughly this order): boot Safe Mode (F8) or Safe Mode with Command Prompt; stop malicious processes (tools like RKill exist to do this safely); run a full scan with a reputable anti-malware product and a dedicated rootkit scanner; use Sysinternals Autoruns to remove suspicious startup entries and Process Explorer to identify which process holds file locks. If files are hidden/readonly, reset attributes from a command prompt (adjust the path before running):

attrib -s -h -r "C:\path\to\suspect\*.*" /S /D

After removing attributes, delete only the confirmed malicious files.

When to wipe: if AV installs still fail, system tools remain blocked, or a rootkit is confirmed, the safest course is a full wipe and reinstall from known-good media. After recovery, change all passwords from a different, clean device, restore only scanned data, enable automatic updates and modern endpoint protection, and avoid P2P networks for casual file sharing. For others troubleshooting similar symptoms, helpful diagnostics include exact detection names and quarantine logs (as asked) and Autoruns/Process Explorer listings; those make targeted removal possible.

Recommended Answers

All 10 Replies

I'm running trojan hunter right now. It seems to be scanning fine. DH seems to think that we will probably have to just wipe the HD clean though.

I managed to access my Ad Aware log I can post it here, but it is SUPER long, and no Trojan. If anyone wants it, say so and I can post it.

Okay, this message just popped up:

Microsoft Visual C++ Runtime Library
Buffer Overrun Detected

A buffer over run has been detected which has corrupted the program's internal state. This program cannot safely continue execution and must now be terminated.

Okay, still no replies... I ran trojan hunter and it isolated 2 trojans and put them in the vault, but the program locked up before I could get the log. There is no log now when I go back. The files they found are in the vault though. I'm not sure it made any difference though as the computer is still having the same issues.

do you have a name of the trojans,see if you can get the names.get back to me and ill help you

We got it fixed. My husband's friend is an IT guy. He came over and karate chopped it for us. Our computer is back to normal.

if you're firmiliar with what the problem was and what he did to fix it please post it here for reference for the users in your shoes

I am having the EXACT same issue!!! I've purchased McAffee and they could not detect the trojan. I've deleted McAffee and purchased AVG. Can't seem to install AVG because i get an error message saying:
local machine: installation failed
Installation:
error: action failed for file AVGSSIE>DLL:file registration...
Error 0x80070020

AVG has not responded to my request for tech help. Apparantly you can only talk to them via email. Very POOR service!

ok, you all need to download SUPER Anti-Spyware PRO From downloads.com and run a full scan. it cleans out EVERYTHING.
oh, and don't open anything that downloads quickly. ;)

Hi!

I have developed exactly the same problem as you (although I downloaded a song from Limewire not a tv show, however I still ended up with the same AVI files as you did) and have also not had a reply from AVG or Limewire regarding support.

Have you managed to sort yours out yet? I would really appreciate your help if you have!

Many thanks!

Jane

Here is the story on what has happened. I was (stupidly) trying to download a TV show from LimeWire. It downloaded really quickly, which should have been my tip off. Doh! I don’t know why, but I opened it. AVG 7.0 caught that it was a Trojan and isolated it. But, it said it could not heal it. I scanned with a couple of other programs and nothing.

Here are the problems

1. No task manager

2. I noticed during the virus scan that there was a weird folder on the hard drive. It is called C:\Documents and Settings\Aaron and Kimberly\! . The file is full of AVI files that are exactly 38.6 KB that are named after TV shows and they were created at the date and time I downloaded the supposed TV show . Obviously these are not videos. This file was hidden in documents and settings. I had to uncheck hide protected operating system files in folder options, which is scary.

I tried to delete the file and it said it was in use by another program. Then I moved on to trying to delete the files that were in the folder. When I tried to do a mass shift delete, it froze (this is the only time it freezes is when I am trying to work with these files or LimeWire). So, I started doing single deletes. The deleted for a while, but then an adaptation occurred and they became read-only. I changed them back and then they froze as I tried to remove them individually.

3. I moved on to try to delete LimeWire. I followed the instructions from this site in a thread about deleting LimeWire on this thread:

http://www.daniweb.com/forums/thread31290.html

I got through the uninstall, but was still left with LimeWire.exe. I tried to delete it and failed. So I decided to move onto the step in the thread about typing regedit in the run box. It says that another program is using this file.

4. Next, I came to this forum and did what the instructions in the file that say please run this before posting. I go to download the newest AVG and it gets almost through the install and gives me a message:

Local machine: installation failed
Installation:
Error: Action failed for file avgssie.dll: file registration....
Error 0x80070020

Here is the error message:

LimeWire version 4.16.6
Java version 1.6.0_05 from Sun Microsystems Inc.
Windows XP v. 5.1 on x86
Free/total memory: 31411032/33357824

com.limegroup.gnutella.gui.GUILoader$StartupFailedException: .\lib\hashes (The system cannot find the file specified)
at com.limegroup.gnutella.gui.GUILoader.sanityCheck(GUILoader.java:286)
at com.limegroup.gnutella.gui.GUILoader.load(GUILoader.java:57)
at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)
at sun.reflect.NativeMethodAccessorImpl.invoke(Unknown Source)
at sun.reflect.DelegatingMethodAccessorImpl.invoke(Unknown Source)
at java.lang.reflect.Method.invoke(Unknown Source)
at com.limegroup.gnutella.gui.Main.main(Main.java:44)

STARTUP ERROR!

I have tried installing three times to no avail. I tried to rerun a scan on another program so I could post any info I get on here, but guess what? None of the work now.


I am getting so frustrated. This is freaking my out. I'm afraid my computer is being used to spread evil. I have always been able to get rid of the few buggies we have gotten. I am feeling like I will ultimately have to back-up our docs and photos to our back-up drive and just wipe the main hard drive clean to do a reinstall. I don’t want the Trojan horse to win though so I thought I would ask for any ideas.

I will be back to check the thread. I have it book marked.


Kimberly

follow my advice.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.