help pavlsp.dll hijack

Discussion in 'Malware Help (A Specialist Will Reply)' started by rikki661, Jul 31, 2005.

  1. rikki661

    rikki661 Private E-2

    hi i have xp sp2 and panda antivirus i have a problem with PAVLSP.DLL file not sure if its a hijack but it is stopping the antivirus from working. i have uninstalled the antivirus and reinstalled it but this file still looks like the problem i have run hijack this and below are the results if anyone could help dont know to much so if you could explaine everything i have to do please
     

    Attached Files:

    • hjt.txt
      File size:
      8.7 KB
      Views:
      2
    Last edited by a moderator: Jul 31, 2005
  2. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Please follow standard cleanup procedures as given below:

    - Run ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal

    Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above and you still have a problem, make sure you have booted to normal mode and run the steps below:



    http://www.majorgeeks.com/images/grenade.gif Download HijackThis 1.99.1

    http://www.majorgeeks.com/images/grenade.gif Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    http://www.majorgeeks.com/images/grenade.gif Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the ZIP file as your backups will not be safely stored.

    http://www.majorgeeks.com/images/grenade.gifBefore running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    http://www.majorgeeks.com/images/grenade.gifRun HijackThis and save your log file.

    http://www.majorgeeks.com/images/grenade.gif Post your log as an ATTACHMENT to your next post. (Do NOT copy/paste the log into your post as it will be removed).

    http://www.majorgeeks.com/images/grenade.gifNeed help with HJT? See this thread: NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting
     
  3. rikki661

    rikki661 Private E-2

    ok thanks for replying it will take me a bit to get through all this the ad-ware program i have had on for a year or so but will not start or uninstall
     
  4. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Just follow as many steps in the READ ME as possible. Then reboot and attach a fresh HJT log.
     
  5. rikki661

    rikki661 Private E-2

    hi done as much of that as pos a few things to tell you about . the online scans wont work in safe mode so i ran them in normal start up NO PROBLEMS WERE FOUND.is this because i am on aol?
    SPYBOT ran this with a lot of hard work had to keep clicking hundreds of times on the cancel tab of the WINDOWS NO DISK box it found two things ;
    class id HKEY_LOCAL_MACHINE\Software\Classes\CLSID\CA.....
    and ROOT CLASS HKEY_LOCAL_MACHINE\Software\Classes\intrallaun
    fixed\removed the items


    AD-WARE COULD NOT RUN AT ALL it the same windows box came up whats that about
    also ran aol spyware scan and got two things up ; advanced key logger and shop at home

    now on starting up the computer i get up a box that says "WINDOWS-NO DISK"
    "X THERE IS NO DISK IN THE DRIVE. PLEASE INSERT A DISK INTO THE DRIVE "

    5 CLICKS ON CANCEL TO GET IT OFF

    THEN COMES UP " PROBLEM" "CENTINEL V X D: APVXDWIN.EXE-UNABLE TO LOCATE COMPONENT" " THIS APPLICATION HAS FAILED TO START BECAUSE SPORDER.DLL WAS NOT FOUND. RE-INSTALLING THE APPLICATION MAY FIX THIS PROBLEM"

    THEN THE WINDOWS BOX COMES UP AGAIN AS ABOVE 5 CLICKS AND WE ARE READY TO GO
    HAVE ATTACHED THE NEW HIJACK THIS SAVED LOG SHEET AND IT WAS RAN OUT OF A FOLDER IN C DRIVE
     

    Attached Files:

  6. rikki661

    rikki661 Private E-2

    Sorry But For Some Reason The Computer People Who Made My Computer Called The C Drive I It Has Always Been This Way
     
  7. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Download the following two files, create a folder on your desktop, call it TSC. Save these 2 files there!

    Sysclean Package

    Pattern.zip

    Once you have these downloaded into the folder you just created, REBOOT INTO SAFE MODE!

    Once in Safe Mode double click the file sysclean.com. When the system cleaner loads, click SCAN to start the scanner. After you complete the scan reboot and attach a fresh HJT log.
     
  8. rikki661

    rikki661 Private E-2

    ok no problems doing that in safe mode i have attached the log file off sysclean.com too just in case it helps
     

    Attached Files:

  9. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Scan with HijackThis and Check the Boxes for the following:

    Make sure All Browser Windows are Closed when you Click FIX.

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ycomp_wave/defaults/sb/*http://www.yah oo.com/search/ie.html
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1

    O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)

    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)

    O16 - DPF: {AE9DCB17-F804-11D2-A44A-0020182C1446} - file://G:\SuperCD\IntraLaunch.CAB

    Again, make sure All Browser Windows are Closed when you Click FIX.

    NEXT:
    Run CCleaner to clean up cookies and temp files.

    Then, as an added precaution, Go to Start > Run and type: cleanmgr and then click OK. Make sure the boxes for these are checked:
    Temporary Files
    Temporary Internet Files
    Recycle Bin


    And Click OK.


    After you complete the above REBOOT and attach a fresh HJT log. Also let me know if any problems remain.
     
  10. rikki661

    rikki661 Private E-2

    hi just got two problems the no windows disk message and the centinel vxd: aovxdwin.exe-unable to locate component as one of the messages below i have attached a new log and by the way thanks for all your help
     

    Attached Files:

  11. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Scan with HijackThis and Check the Boxes for the following:

    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)

    Make sure All Browser Windows are Closed when you Click FIX.

    NEXT:
    Run CCleaner to clean up cookies and temp files.

    Run full scans with Ad-Aware SE & Spybot S&D and have both programs fix what they find.
    Note: Remember to get all updates before doing the scans.


    After you complete the above, reboot and let me know what problems if any remain.
     
  12. rikki661

    rikki661 Private E-2

    still cant run ad-aware because of no windows disk message still the same two problems and spybot didnt find anything at all also ran aol spyware
     

    Attached Files:

  13. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Your HJT log is clean, when you get the aovxdwin.exe-unable to locate component error?
     
  14. rikki661

    rikki661 Private E-2

    on start up first i get the windows no disk error the the centinel vxd: apvxdwin.exe -unable to locate component then the no windows disk error again
     
    Last edited by a moderator: Aug 10, 2005
  15. rikki661

    rikki661 Private E-2

    also the anti virus is only sometimes working
     
  16. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Generate a StartupList log using HijackThis.
    Run HJT and on the first screen, click the button that says "Open the Misc Tools section". In the next window first select "List also minor sections (full)" and then click the button that says "Generate StartupList log". CLick Yes to the Do you want to continue prompt. Now a notepad window will come up with the Startuplist.txt file. It is already saved in the the directory HJT is running from. So just come back here and upload the file as an attachment to your next message.
     
  17. rikki661

    rikki661 Private E-2

    what do you mean the first screen
     
  18. rikki661

    rikki661 Private E-2

    think i have got it first screen of hijack thisi have attached
     

    Attached Files:

  19. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Please download "StartDreck", from here: http://www.niksoft.at/php/dl.php?f=startdreck.zip

    Unzip to its own folder and start the program,
    Press 'Config'
    Press 'Unmark All'
    Check the following boxes only:
    Registry -> Run Keys
    System/drivers> Running processes
    Press 'Ok'
    Press 'Save' and select the location to save the log file
    (default is the same folder as the application)

    Please attach the log in this thread.
     
  20. rikki661

    rikki661 Private E-2

    hi done that i hope
     

    Attached Files:

  21. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    The only thing I see is the file "apvxdwin.exe" which is part of Panda. If you are still getting the error I would uninstall Panda and then see if still comes up.
     
  22. rikki661

    rikki661 Private E-2

    there is not much time left to go on panda so which antivirus would you recommend i buy next i might buy a new one then uninstall in what do you think? they have a crap tec support and never get back to you
     
  23. rikki661

    rikki661 Private E-2

    today we had a power cut when i was on the computer and the no windows disk and the other think has now stoped coming up why i dont know the antivirus is still only sometimes working so i think it is sorted still would like to keep this thread open for a week to make sure and would like to know which antivirus to buy
     
  24. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Personally, I would never buy antivirus software. There are many free ones that do the same if not better.

    I would personally recommend AVG Free Edition, I use this and it does a great job.

    You should see this article on How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds