I got a virus and need help to get rid of it

By TimeParadoX
Oct 9, 2006
Topic Status:
Not open for further replies.
  1. I got a virus that steals my info like saved passwords and stuff, I disabled my restore feature so it would not be able to get into my restored computer because my friend told me to do that.

    It's a Downloader thing so it keeps giving me pop-ups about anti-virus and automaticly downloads this crap on my computer.. how can I get rid of it?

    Just post help because im ganna delete all my saved passwords and stuff so Im not ganna respond just put notes and stuff
  2. howard_hopkinso

    howard_hopkinso Newcomer, in training Posts: 25,948   +19

    Go and read the Trojan Pakes and other nasties preliminary removal instructions. Follow all the instructions exactly.

    Post fresh HJT and AVG Antispyware logs as an attachments into this thread, only after doing the above.

    Regards Howard :)

    This thread is for the use of TimeParadoX only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
  3. TimeParadoX

    TimeParadoX Newcomer, in training Topic Starter Posts: 2,438

    Thanks!

    Thanks howard I cleared all the viruses on my computer..
    Seems that I had like 70 after the Trojan appeared.

    I Forgot to get a HJT log but I got a AVG report after all the scans I did
  4. howard_hopkinso

    howard_hopkinso Newcomer, in training Posts: 25,948   +19

    I need to see a fresh HJT log.

    Regards Howard :)

    This thread is for the use of TimeParadoX only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
  5. TimeParadoX

    TimeParadoX Newcomer, in training Topic Starter Posts: 2,438

    Sorry

    Sorry for the wait had to do another scan to get a fresh report..
    Hope this is what you want, Also there are alot of stuff in the log but I dont know which to fix / delete with HJT check the log and tell me which files to delete or something
  6. howard_hopkinso

    howard_hopkinso Newcomer, in training Posts: 25,948   +19

    Download the Pocket Killbox programme from HERE. Extract it but don`t run it yet.

    You might want to copy and paste these instructions into a notepad file. Then you can have the file open in safe mode, so you can follow the instructions easier.

    Turn off system restore.(XP/ME only) See how here.> http://www.bleepingcomputer.com/forums/tutorial56.html

    Boot into safe mode, under your normal user name(NOT THE ADMINISTRATOR ACCOUNT). See how here.> http://www.bleepingcomputer.com/forums/tutorial61.html

    In Windows Explorer, turn on "Show all files and folders, including hidden and system". See how here.> http://www.bleepingcomputer.com/forums/tutorial62.html

    Open your task manager, by holding down the ctrl and alt keys and pressing the delete key.

    Click on the processes tab and end process for(if there).

    ALCXMNTR.EXE
    iiorm.exe

    Close task manager.

    Run HJT with no other programmes open(except notepad). Click the scan button. Have HJT fix the following, by placing a tick in the little box next to(if there).

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

    F2 - REG:system.ini: UserInit=userinit.exe

    O2 - BHO: (no name) - {4F0FD647-3DAB-40B7-84C9-3626F2BF584A} - C:\WINDOWS\system32\vturr.dll

    O2 - BHO: (no name) - {849B9523-785F-4014-9CAF-079FB4A74C61} - C:\WINDOWS\system32\fwysekil.dll (file missing)

    O2 - BHO: (no name) - {a43385f0-7113-496d-96d7-b9b550e3fcca} - C:\WINDOWS\system32\ixt4.dll (file missing)

    O3 - Toolbar: (no name) - {C004DEC2-2623-438e-9CA2-C9043AB28508} - (no file)

    O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE

    O4 - HKCU\..\Run: [iior] C:\PROGRA~1\COMMON~1\iior\iiorm.exe

    O8 - Extra context menu item: Add To Compaq Organize... - C:\PROGRA~1\HEWLET~1\COMPAQ~1\bin/module.main/favorites\ie_add_to.html

    O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEB utton\support.htm (file missing)

    O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEB utton\support.htm (file missing)

    O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEB utton\support.htm (file missing) (HKCU)

    O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEB utton\support.htm (file missing) (HKCU)

    Fix all 018-Protocol entries.

    O20 - Winlogon Notify: vturr - C:\WINDOWS\system32\vturr.dll

    O20 - Winlogon Notify: wintuh32 - wintuh32.dll (file missing)

    Click on the fix checked button.

    Close HJT.

    Locate and delete the following bold files and/or directories(if there).

    ALCXMNTR.EXE Search your system for this file and delete all instances of it.

    C:\PROGRA~1\COMMON~1\iior\iiorm.exe

    Run the killbox.exe file. When it loads type the full path to the file you would like to delete in the field and check the delete file on reboot button. press the Delete File button (looks like a red circle with a white X). It will prompt you to reboot, select no until you have finished inputting the files you want to delete, only then allow it to reboot and hopefully your files will now be deleted.

    This is the filepath you need to enter into killbox.

    C:\WINDOWS\system32\vturr.dll

    Once your system has rebooted, turn system restore back on and rehide your protected OS files.

    Post a fresh HJT log and let me know how your system is running.

    Regards Howard :)

    This thread is for the use of TimeParadoX only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
  7. TimeParadoX

    TimeParadoX Newcomer, in training Topic Starter Posts: 2,438

    OK howard, i'll be back after I do all this.. hope it works =)


    -Edit- added HJT log
  8. TimeParadoX

    TimeParadoX Newcomer, in training Topic Starter Posts: 2,438

    HJT logs

    I ran HJT just now and wanted to see if everything was clean =)

    Also.. O23 - Service: Symantec Core LC - Symantec Corporation is that apart of stupid norton? if it is can I delete it? =D
  9. Rik

    Rik Banned Posts: 4,985

    Do you have norton ghost perhaps? If so its a good bit of software and the entry will be for that!!!!!
  10. TimeParadoX

    TimeParadoX Newcomer, in training Topic Starter Posts: 2,438

    Lol I hate norton so much it's not funny... I was playing World of Warcraft and running naxx then out of no where norton came up with a stupid pop-up that made me crash WoW so I couldnt get any good loot from Kel'thuz ='(
  11. howard_hopkinso

    howard_hopkinso Newcomer, in training Posts: 25,948   +19

    You`re not running any antivirus software. This is a huge security risk.

    Do the following.

    Click start/run and type services.msc into the run box and press the enter key.

    When the window appears, maximise it. Double click on the following services(if there) and select stop if they are running. Set the startup type to disabled. Click apply/ok for each service you disable.

    Automatic LiveUpdate Scheduler

    Close the services window.

    Locate and delete the following bold files and/or directories(if there).

    C:\Program Files\Symantec

    Reboot your system.

    Go HERE and follow the links for installing AVG or Avast antivirus programmes.

    Regards Howard :)
     
  12. TimeParadoX

    TimeParadoX Newcomer, in training Topic Starter Posts: 2,438

    Im not running any security programs? What!? Im running kerio and AVG right now with the shield and all that stuff... maybe because I was in Safe Boot?
  13. howard_hopkinso

    howard_hopkinso Newcomer, in training Posts: 25,948   +19

    HJT logs should be posted from normal mode, not safe mode. You should still disable the service I told you about in my post above. It`s part of Symantec/Norton crapware.

    Post a fresh HJT log.

    Regards Howard :)

    This thread is for the use of TimeParadoX only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
  14. TimeParadoX

    TimeParadoX Newcomer, in training Topic Starter Posts: 2,438

    Oh... I run HJT from normal mode? ( sorry about that =P ) I remember running all those fancy programs in Safe Mode when I had virus... ok well i'll post another one then =) Also I removed that updater thing but I cant find C:\Program Files\Symantec anywhere.. not even the search thing could find it

    Here is the log
  15. howard_hopkinso

    howard_hopkinso Newcomer, in training Posts: 25,948   +19

    I have merged your new thread into this one. Please use this thread for all your virus/spyware problems. Thanks.

    Ok, no problem.

    Post the fresh HJT log and I`ll take a look.

    Regards Howard :)

    This thread is for the use of TimeParadoX only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
  16. TimeParadoX

    TimeParadoX Newcomer, in training Topic Starter Posts: 2,438

    I posted it already ( think you posted your Answer when I posted my attachment xD )

    Oh and sorry.. forgot to only post in this one but i'll do that for now on =D
  17. howard_hopkinso

    howard_hopkinso Newcomer, in training Posts: 25,948   +19

    There is absolutely no sign of the AVG Antivirus programme on your system. Only the AVG Antispyware programme. Also Symantc Norton hasn`t been properly uninstalled. Go to add remove programmes in your control panel and uninstall anything to do with Symantec or Norton. Then go and read this thread HERE.

    Once you`ve done that, go HERE and follow the links for downloading and installing either AVG free or Avast antivirus.

    Post a fresh HJT log into this thread, only after doing the above.

    Regards Howard :)

    This thread is for the use of TimeParadoX only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
  18. TimeParadoX

    TimeParadoX Newcomer, in training Topic Starter Posts: 2,438

    Sorry for the long waited reply... I had that thing with the Avast! scan when you reboot so it took like 30 minutes because I didnt want to bypass it..

    well here is a new HJT log ( Also to tell you the truth.. I could not find any signs of Norten on my computer or anything related to it, not anywhere on my system )
  19. howard_hopkinso

    howard_hopkinso Newcomer, in training Posts: 25,948   +19

    Your HJT log is clean.

    Lets get rid of the Symantec/Norton remnants.

    You might want to copy and paste these instructions into a notepad file. Then you can have the file open in safe mode, so you can follow the instructions easier.

    Turn off system restore.(XP/ME only) See how here.> http://www.bleepingcomputer.com/forums/tutorial56.html

    Boot into safe mode, under your normal user name(NOT THE ADMINISTRATOR ACCOUNT). See how here.> http://www.bleepingcomputer.com/forums/tutorial61.html

    In Windows Explorer, turn on "Show all files and folders, including hidden and system". See how here.> http://www.bleepingcomputer.com/forums/tutorial62.html

    Click start/run and type services.msc into the run box and press the enter key.

    When the window appears, maximise it. Double click on the following services(if there) and select stop if they are running. Set the startup type to disabled. Click apply/ok for each service you disable.

    Symantec Core LC

    Close the services window.

    Open your task manager, by holding down the ctrl and alt keys and pressing the delete key.

    Click on the processes tab and end process for(if there).

    symlcsvc.exe

    Close task manager.

    Run HJT with no other programmes open(except notepad). Click the scan button. Have HJT fix the following, by placing a tick in the little box next to(if there).

    O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe


    Click on the fix checked button.

    Close HJT.

    Locate and delete the following bold files and/or directories(if there).

    C:\Program Files\Common Files\Symantec Shared

    Reboot into normal mode, turn system restore back on and rehide your protected OS files.


    Regards Howard :)

    This thread is for the use of TimeParadoX only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
  20. TimeParadoX

    TimeParadoX Newcomer, in training Topic Starter Posts: 2,438

    Here is the log Howard!

    Thanks for your time, without you my computer will still have Norten crap =D

    Also.. do you mind if I post fresh HJT logs every now and then to see if my computer is infected? I got abit paranoid when I got that last virus =P
  21. howard_hopkinso

    howard_hopkinso Newcomer, in training Posts: 25,948   +19

    Your HJT log is clean.

    You might want to take a look at this thread HERE. It`ll show you how you can keep your system more secure.

    As for posting HJT logs for me to check, I have no problem with that, providing you don`t post them too often as I`m very busy and you post them in this thread.

    Obviously, if you start to have problems, then that`s different and you should post a HJT log immediately.

    Regards Howard :)

    This thread is for the use of TimeParadoX only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
  22. TimeParadoX

    TimeParadoX Newcomer, in training Topic Starter Posts: 2,438

    Yeah I know, I wont post every day or something like that but once every few months or so and if I have a virus then i'll post that =D

    Also thanks for the link to the windows protection thing I'll be sure to follow it =D
  23. TimeParadoX

    TimeParadoX Newcomer, in training Topic Starter Posts: 2,438

    Today my computer was acting really weird and when I went to check the processes to make sure nothing else was running to make my computer act weird and I noticed there was like 80 processes running ( Usualy I have like 40 )

    After I restarted computer I did a hijackthis scan and wanted to make sure I had no viruses
  24. howard_hopkinso

    howard_hopkinso Newcomer, in training Posts: 25,948   +19

    Your HJT log is clean mate.

    Regards Howard :)

    This thread is for the use of TimeParadoX only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
  25. TimeParadoX

    TimeParadoX Newcomer, in training Topic Starter Posts: 2,438

    Oh ok thanks howard ;)
Topic Status:
Not open for further replies.


Add New Comment

TechSpot Members
Login or sign up for free,
it takes about 30 seconds.
You may also...


Get complete access to the TechSpot community. Join thousands of technology enthusiasts that contribute and share knowledge in our forum. Get a private inbox, upload your own photo gallery and more.