Computing.Net > Forums > Security and Virus > Mapson.d I can't get rid of it

Computing.Net: Over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to sign up now, it's free!

Mapson.d I can't get rid of it

Reply to Message Icon

Original Message
Name: edulozada
Date: November 11, 2003 at 05:56:07 Pacific
Subject: Mapson.d I can't get rid of it
OS: Windows XP Professional S
CPU/Ram: 512 MB
Comment:

I recieve mails from my own mail address edulozada@hotmail.com (the last one I received was: subject:Blaster Remover. Size:248k), I have scanned my pc with norton, panda online, ad-aware6, RAV Antivirus Online... all updated, but nothing.. I can't find anything. I follow the instructions for removal i downloaded from symantec... nothing, I don't even find the files that this virus is supposed to have installed in my pc. I'm completely lost, I don't know what to do.

Here is my log (hijackthis)

Logfile of HijackThis v1.97.3
Scan saved at 9:42:24 AM, on 11/11/2003
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\inetsrv\inetinfo.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Winamp\Winamp.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Eduardo\My Documents\Bajado\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.autoavisos.com/
N2 - Netscape 6: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%206%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\Eduardo\Application Data\Mozilla\Profiles\default\be3vlr2s.slt\prefs.js)
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xportar a Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Si&milar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {A3009861-330C-4E10-822B-39D16EC8829D} (CRAVOnline Object) - http://www.ravantivirus.com/scan/ravonline.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{1E9BEAD5-A8E7-494E-A1E5-A08195C92330}: NameServer = 200.58.160.25 200.58.161.25
O17 - HKLM\System\CS1\Services\Tcpip\..\{1E9BEAD5-A8E7-494E-A1E5-A08195C92330}: NameServer = 200.58.160.25 200.58.161.25

Help me please!


Report Offensive Message For Removal


Response Number 1
Name: blender
Date: November 11, 2003 at 06:20:06 Pacific
Reply:

Hi

I don't see any signs of virus infection in your log...
What is likely happening..why you are recieving emails supposedly from yourself is probably because someone with your address in their address book has the virus.
The worm will spoof (fake) the from field making it look like it came from yourself.
Just keep deleting those emails as you seem to have been doing.
Whatever you do....dont open the attachments.

Good luck


Report Offensive Follow Up For Removal

Response Number 2
Name: Tom41
Date: November 11, 2003 at 06:22:44 Pacific
Reply:

There is no sign of a virus running on your machine.
More than likely, someone who has you in their address book is infected and are unknowingly sending the emails with your addy spoofed in the 'From' field.


Report Offensive Follow Up For Removal

Response Number 3
Name: edulozada
Date: November 13, 2003 at 11:05:02 Pacific
Reply:

Thank you for your responses...
I guess what you said is what may be happening, but... other people also receive those mails from my account, and I also receive mails from
postmaster@mail.hotmail.com (I can't block those mails because they are from hotmail staff): i did not open the attached file but this is what the mail says:

-----------
This is an automatically generated Delivery Status Notification.

Delivery to the following recipients failed.

lorgio_guapo2003@hotmail.com
raspapinchete@hotmail.com
faisalaramayo@hotmail.com
marceloaguilera@hotmail.com
gparada@hotmail.com
alejandro5pesos@hotmail.com
walter_sarazos@hotmail.com
lachok_@hotmail.com
gabrielacl9@hotmail.com
morochita_s@hotmail.com
mfernandez82@hotmail.com
patricia_roca1984@hotmail.com
pakuchi67@hotmail.com
daniela_tellez@hotmail.com
tamara_cristina@hotmail.com



Reporting-MTA: dns;mc6-s6.hotmail.com
Received-From-MTA: dns;mc6-f21.hotmail.com
Arrival-Date: Tue, 11 Nov 2003 14:04:30 -0800

Original-Recipient:
Final-Recipient: rfc822;lorgio_guapo2003@hotmail.com
Action: failed
Status: 5.2.3

Original-Recipient:
Final-Recipient: rfc822;raspapinchete@hotmail.com
Action: failed
Status: 5.2.3

Original-Recipient:
Final-Recipient: rfc822;faisalaramayo@hotmail.com
Action: failed
Status: 5.2.3

Original-Recipient:
Final-Recipient: rfc822;marceloaguilera@hotmail.com
Action: failed
Status: 5.2.3

Original-Recipient:
Final-Recipient: rfc822;gparada@hotmail.com
Action: failed
Status: 5.2.3

Original-Recipient:
Final-Recipient: rfc822;alejandro5pesos@hotmail.com
Action: failed
Status: 5.2.3

Original-Recipient:
Final-Recipient: rfc822;walter_sarazos@hotmail.com
Action: failed
Status: 5.2.3

Original-Recipient:
Final-Recipient: rfc822;lachok_@hotmail.com
Action: failed
Status: 5.2.3

Original-Recipient:
Final-Recipient: rfc822;gabrielacl9@hotmail.com
Action: failed
Status: 5.2.3

Original-Recipient:
Final-Recipient: rfc822;morochita_s@hotmail.com
Action: failed
Status: 5.2.3

Original-Recipient:
Final-Recipient: rfc822;mfernandez82@hotmail.com
Action: failed
Status: 5.2.3

Original-Recipient:
Final-Recipient: rfc822;patricia_roca1984@hotmail.com
Action: failed
Status: 5.2.3

Original-Recipient:
Final-Recipient: rfc822;pakuchi67@hotmail.com
Action: failed
Status: 5.2.3

Original-Recipient:
Final-Recipient: rfc822;daniela_tellez@hotmail.com
Action: failed
Status: 5.2.3

Original-Recipient:
Final-Recipient: rfc822;tamara_cristina@hotmail.com
Action: failed
Status: 5.2.3

-------------

(I don't have any of this e-mail addresses in my contact list)

Thanks again.


Report Offensive Follow Up For Removal

Response Number 4
Name: edulozada
Date: November 13, 2003 at 11:13:41 Pacific
Reply:

I forgot to write the question in my last post... do you still think that my pc is not infected????

-Other people receive e-mails supposedly from my account
- I receive e-mails like the one i posted before (from hotmail staff), and I don't have any of those mentioned e-mail address in my adress book


Report Offensive Follow Up For Removal

Response Number 5
Name: Tom41
Date: November 14, 2003 at 10:15:33 Pacific
Reply:

Go here and run an online virus scan and post the results:

RAV


Report Offensive Follow Up For Removal


Response Number 6
Name: edulozada
Date: November 14, 2003 at 11:07:32 Pacific
Reply:

I've scanned my pc with RAV, here are the results:

Scan started at 11/14/2003 2:44:33 PM

Scanning memory...
Scanning boot sectors...
Scanning files...

Scanned
============================
Objects: 27378
Directories: 2215
Archives: 670
Size(Kb): -10030
Infected files: 0

Found
============================
Viruses found: 0
Suspicious files: 0
Disinfected files: 0
Mail files: 71


RAV Engine: 8.11
Virus Signatures: 84243
Last Update: Thursday, November 13, 2003 13:44:50



Report Offensive Follow Up For Removal

Response Number 7
Name: edulozada
Date: November 17, 2003 at 13:55:14 Pacific
Reply:

so???? am I clean???
Help!!!!!!!!!!!!


Report Offensive Follow Up For Removal






Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home



Results for: Mapson.d I can't get rid of it

Can't get rid of RUN entry/Service
    Summary: My sister-in-law asked me to take a look at her PC which was barely working. It was overrun with spyware and crap (she has four kids and no conception of safe computing). I have gotten rid of most o...
www.computing.net/answers/security/cant-get-rid-of-run-entryservice/17409.html

Can't get rid of cws.searchx
    Summary: Hi, I can't get rid of cws.searchx. I clear it up with cwshredder but it comes back. Everything's up to date... Norton, just installed and run Spybot, microsoft patches etc etc. Don't know what I'm...
www.computing.net/answers/security/cant-get-rid-of-cwssearchx/12067.html

VIRUS that I can't get rid ofPLEASE help
    Summary: I have a virus I can't get rid of. It spreads through instant messages. It shows up as an instant message but it sends itself. It shows up as a link, but its a virus. I've tried to use Norton Antiviru...
www.computing.net/answers/security/virus-that-i-cant-get-rid-ofplease-help/469.html








Which MP3 player do you have?

iPod/iPhone
Zune
Something Else
None


View Results

Poll Finishes Today.
Discuss in The Lounge
Poll History






Data Recovery Software