Um.. First of all, my computer is indeed extremely slow. I don't know how long its had such and such "nasty" because it's pretty old. Before it went into my care, the computer was basically accessible to everyone.. But anyhow, I think it was when I was just trying to get some music when..I knew something was wrong 'cause I suddenly found a lot of zipped files in a folder. So I ran up a scan with a few different anti-spyware programs, but none of the free versions are willing to get rid of whatever is infecting the computer, so that makes me very unhappy. CounterSpy got rid of a few, but not everything, and AVG Anti-Spyware got rid of something.. And I followed a few of the links in one of the stickies, but as slow as this compuer is..I really don't feel like downloading and installing 20 different programs just to find out which one will make a log of what nasty trojans/viruses/etc stuff is on my computer.

I had a scan done by XoftSpySE, though, and it has found...well, a lot, but I can't get rid of any of it unless I pay $40 just for one stinkin run, so I really don't want to do that either. Apparently, I'm infected with:

Agent BLS Trojan
FlashGet
IPWins
Instant Acesss
ISTBar
Viewpont (a LOT of Viewpoint came up)
Xupiter.Orbitexplorer
CWS.Homepage / CWS.Msconfd

Rbot-WJ

..and I can't really get to any of it to see if I can get rid of it manually. It's all under something like "software\microsoft\ or software\classes" or "software\mozillapugins" (..? I don't even have mozilla..) and then a few other really weird looking stuff. ("interface\{9dbb28c-1925-11....}\proxystubclsid", "clsid\{100725b-c455-4de6-....}", "axmetastream.metasteamctlsecondary...")

One of the Agent BLS Trohans is under just plain "wr" too.. None of the other programs I've run seem to have picked any of that up--or not all of it--but it's there... I'm getting tired of this computer now-a-days... Also, a little earlier I kept getting a pop-up for some type of anti-spyware and it was getting really annoying. It froze up one of the pages I was on (I was trying to get registered so I could post this, but that pop up happened and it froze that page and the page I was on). I haven't been to many different pages since, but I made sure my pop-up blocker was on after that and so far haven't had any.

Also--
AVG Anti-Spyware has been running so I'm hoping that's the reason I'm having some difficulty getting everything I type out, but the point.. It found some stuff, again, like:

Trojan.Agent.anr
Not-A-Virus.Downloader.Win32.Win... (low threat, but meh)
Trogan.Agent.aoy
a bunch of tracking cookies..
Adware.something
Dropper.BV.lu
Dialer.V.lu

..I'm having it deleted and am scanning again. -Sigh- All the programs seem to come up with something different...

Dani AI

Generated

Quick summary for and follow-up to : the symptoms you describe — very slow system, multiple differing detections from several scanners, and persistent pop-ups — are classic signs of multiple layered infections (adware/PUAs plus at least one persistent trojan). The priority is containment, safe evidence collection for helpers, and then removal or a clean reinstall if the system is too compromised.

Practical next steps (in order):

  1. Unplug the PC from the network and stop doing any banking or password use on it.
  2. Copy only personal documents and media (no .exe, .msi, .zip installers) to an external drive. Do not run those files on the infected machine. Scan that external drive on a known-clean machine.
  3. Boot the machine into a non-standard environment (Safe Mode or a bootable AV rescue USB) and run full offline scans; these find persistent code that runs before the OS.
  4. Produce a startup/autorun log (startup services, scheduled tasks, browser helpers) and the recent AV scan log, then post those logs so helpers can diagnose. As @gerbil suggested, a startup log is the quickest way for others to be useful. Don’t edit the registry on guesswork — unknown CLSIDs and interfaces can break Windows.
  5. Disable System Restore during cleanup so the infection cannot hide there; re-enable it only after a confirmed clean.

If cleanup becomes unreliable or the PC is old, a full backup of personal files followed by a wipe and clean OS install is the safest route. After any cleanup or reinstall, update the OS, install a current AV, and change all passwords from a clean device. If help is needed, include the startup log and a short list of steps already taken.

Recommended Answers

All 2 Replies

I've changed my mind about the pop-ups. Now I keep getting a really annoying one. It says:

Wait! A live agent would like to talk to you about last minute savings. Please hit 'Cancel' on the next window to remain on this page...

(After hitting the x or OK..)

Are you sure you want to navigate away from this page?

Press 'CANCEL' below to chat...

Press OK to continue, or Cancel to stay on the current page.


..it's really annoying. Same thing everytime, and it pops up whether there's a browser open or not.

"And I followed a few of the links in one of the stickies, but as slow as this compuer is..I really don't feel like downloading and installing 20 different programs just to find out which one will make a log of what nasty trojans/viruses/etc stuff is on my computer."
If you don't give us a scan, we are blind, and we won't help. So. Your choice. You have run AVG AS [hope you set recommended actions to Quarantine], next do this:
HiJackThis:
==download hijackthis:
-install it to a new folder alongside your program files and then rename the Hijackthis.exe to imabunny.exe.
-in that folder start HijackThis by dclicking the .exe; now close ALL other applications and any open windows including the explorer window containing HijackThis.
-click the Scan and Save a Logfile button. Post the log here. Plus that AVG AS scan log if you kept it.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.