Virus problem.

By angelSLACKER
Aug 26, 2006
Topic Status:
Not open for further replies.
  1. i'm using avg and a trojan: downloader.generic2 wont be healed, move to virus vault or even delete...

    i tried it in safe mode but no luck
    scanned it using the following: Kaspersky, F-Secure and no virus was found!~
  2. howard_hopkinso

    howard_hopkinso Newcomer, in training Posts: 25,948   +19

  3. angelSLACKER

    angelSLACKER Newcomer, in training Topic Starter Posts: 48

    here's the hijackthis log~
  4. howard_hopkinso

    howard_hopkinso Newcomer, in training Posts: 25,948   +19

    Run HJT with no other programmes open. Click the scan button. Have HJT fix the following, by placing a tick in the little box next to(if there).

    O16 - DPF: {072039AB-2117-4ED5-A85F-9B9EB903E021} (NowStarter Control) - http://www.clubbox.co.kr/neo.fld/NowStarter.cab

    O16 - DPF: {09883431-7429-11D5-8B69-0050049F5256} (VBAuthentic.Authentic) - https://www.metrobankdirect.com/download/Authentic/VBAuthentic.cab

    O17 - HKLM\System\CCS\Services\Tcpip\..\{B1E3469A-2168-4469-996C-A06E1B367E3C}: NameServer = 58.69.254.6 58.69.254.8<Only fix this, if it doesn`t belong to your ISP.

    Click on the fix checked button.

    Close HJT.

    Other than the above, your HJT log is clean.

    It appears you`re not running any firewall software. You should consider getting some. The free Zonealarm or Kerio firewall programme are very good. Just Google for these.

    If you have any further virus/spyware problems, please post in this thread.

    Regards Howard :)

    This thread is for the use of angelSLACKER only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
  5. angelSLACKER

    angelSLACKER Newcomer, in training Topic Starter Posts: 48

    ah thank you for your reply, i managed to delete the "downloader.generic2" manually~~~

    uhm i didn't remove any of those above because i'm kind-of using them~

    thanks anyway! =)
  6. angelSLACKER

    angelSLACKER Newcomer, in training Topic Starter Posts: 48

    thecoolpics link (virus content) spreading in Yahoo! Messenger

    I opened a link from thecoolpics sent by a someone over at YM and since then, there's been a virus I can't seem to get rid of... It sends itself to people in my list, too (this is prob'ly how it got to me)! I have to log out to make sure it doesn't spread... I scanned using Ad-Aware and antivirus scanners. Ad-Aware detected something but the antivirus scanners didn't... I deleted it and I was able to run YM again... Each time I open the Internet Explorer, however, the home is set at the site where I got the virus! I can't change it! And I can't check the Task Manager coz it won't open... I tried the thread where it says how I can un-disable the Task Manager but I can't find the "Run" in my Start Menu...

    Please help. And thanks!
  7. howard_hopkinso

    howard_hopkinso Newcomer, in training Posts: 25,948   +19

    I have merged your new thread into this one.

    Go and read the Trojan Pakes and other nasties preliminary removal instructions. Follow all the instructions exactly.

    Post fresh HJT and AVG Antispyware logs as attachments into this thread, only after doing the above.


    Regards Howard :)


    This thread is for the use of angelSLACKER only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
  8. angelSLACKER

    angelSLACKER Newcomer, in training Topic Starter Posts: 48

    This is the only thing I can seem to do. =(

    I can't boot into Safe Mode. I can't use Run. And my PC goes into Blue Screen in the middle of my AVG scanning.

    And thank you!
  9. howard_hopkinso

    howard_hopkinso Newcomer, in training Posts: 25,948   +19

    Follow as many of the instructions below as you can. Don`t worry if you can`t boot into safe mode at this stage.

    You might want to copy and paste these instructions into a notepad file. Then you can have the file open in safe mode, so you can follow the instructions easier.

    Turn off system restore.(XP/ME only) See how here.> http://www.bleepingcomputer.com/forums/tutorial56.html

    Boot into safe mode, under your normal user name(NOT THE ADMINISTRATOR ACCOUNT). See how here.> http://www.bleepingcomputer.com/forums/tutorial61.html

    In Windows Explorer, turn on "Show all files and folders, including hidden and system". See how here.> http://www.bleepingcomputer.com/forums/tutorial62.html

    Open your task manager, by holding down the ctrl and alt keys and pressing the delete key.

    Click on the processes tab and end process for(if there).

    svchost32.exe<Not to be confused with svchost.exe
    svhost.exe<Not to be confused with svchost.exe

    Close task manager.

    Run HJT with no other programmes open(except notepad). Click the scan button. Have HJT fix the following, by placing a tick in the little box next to(if there).

    O4 - HKLM\..\Run: [Task Manager] C:\WINDOWS\system\svchost32.exe

    O4 - HKLM\..\Run: [SVCHOST] C:\WINDOWS\system\svhost.exe

    O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1

    Click on the fix checked button.

    Close HJT.

    Locate and delete the following bold files and/or directories(if there).

    C:\WINDOWS\system\svchost32.exe<not to be confused with svchost.exe
    C:\WINDOWS\system\svhost.exe<Not to be confused with svchost.exe

    Reboot into normal mode, turn system restore back on and rehide your protected OS files.

    Post a fresh HJT log and let me know how your system is running.

    Regards Howard :)

    This thread is for the use of angelSLACKER only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
  10. angelSLACKER

    angelSLACKER Newcomer, in training Topic Starter Posts: 48

    there is no task manager, it's disabled with right click:

    [​IMG]

    and even when i press ctrl+alt+delete: it just prompts me if i wanna lock computer, log-off, shutdown, change password, and cancel.. the task manager is disabled as well~

    but i managed to boot it in safemode here's the hjt for that~

    and thanks again XD

    EDIT;

    oh & btw, there's also no Run on Start:

    [​IMG]
  11. howard_hopkinso

    howard_hopkinso Newcomer, in training Posts: 25,948   +19

    Your HJT log apperas to be clean. Did you run the HJT scan from safe mode or normal mode?

    If it was from safe mode, I need to see a fresh HJT log from normal mode.

    Did you manage to delete the files I suggested?

    As for your task manager problems, please see this thread HERE.

    For your run problem, try the following.

    To add RUN to the menu.
    Right-click on the Start button and choose Properties from the menu
    Click the start menu tab.
    Then choose the "customize" button
    Then choose the "advanced" tab and check the box for the Run command.

    Click ok/apply/ok.

    Regards Howard :)

    This thread is for the use of angelSLACKER only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
     
  12. angelSLACKER

    angelSLACKER Newcomer, in training Topic Starter Posts: 48

    It says:

    Task Manager has been disabled by your administrator.

    there is only 1 computer account and it's already administrator~

    As for RUN:

    there is NO Run command in the Advanced Tab

    attached is the HJT log from normal mode.

    again, thanks
  13. howard_hopkinso

    howard_hopkinso Newcomer, in training Posts: 25,948   +19

    Your HJT log is clean.

    Once you`ve clicked the advanced tab you should see a panel named "start menu items"

    If you use the scroll bar to navigate though the list, you should see the run command box. It`s directly under the printers and faxes box. Make sure it`s ticked and click ok/apply/ok

    For your task manager problem, see HERE and follow the instructions.

    Regards Howard :)

    This thread is for the use of angelSLACKER only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
  14. angelSLACKER

    angelSLACKER Newcomer, in training Topic Starter Posts: 48

    i run ad-aware and i saw a disable task manager from there, now i can use the task manager, but as for the run there really is no run command, only the following:

    Control Panel
    Enable Dragging & Dropping
    Favorites Menu
    Help & Support
    My Computer
    My Documents
    My Music
    My Network Places
    My Pictures
    Network Connection
    Printer & Faxes
    Scroll Programs
    Search
    Set Program Access & Default
    System Administrative Tool
  15. howard_hopkinso

    howard_hopkinso Newcomer, in training Posts: 25,948   +19

    Yes, under network connections you should see the following three round radio buttons.

    Display as Connect to menu<not selected

    Don`t display this item<should be selected

    Link to network connection folder<Not selected

    Then directly under those, you should see some square little boxes starting with-

    Printers and faxes

    Run command <should be ticked

    Scroll programs

    Set programme access and defaults.

    Let me know if this helps.

    Regards Howard :)

    This thread is for the use of angelSLACKER only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
  16. angelSLACKER

    angelSLACKER Newcomer, in training Topic Starter Posts: 48

    here's the start menu items i have:

    [​IMG]
  17. howard_hopkinso

    howard_hopkinso Newcomer, in training Posts: 25,948   +19

    Go HERE and see if it helps.


    Regards Howard :)

    This thread is for the use of angelSLACKER only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
  18. angelSLACKER

    angelSLACKER Newcomer, in training Topic Starter Posts: 48

    How can I go to my registry editor without the Run command?
     
  19. howard_hopkinso

    howard_hopkinso Newcomer, in training Posts: 25,948   +19

    Open task manager, click file, new task and type regedit, click ok.

    Regards Howard :)

    This thread is for the use of angelSLACKER only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
Topic Status:
Not open for further replies.


Add New Comment

TechSpot Members
Login or sign up for free,
it takes about 30 seconds.
You may also...


Get complete access to the TechSpot community. Join thousands of technology enthusiasts that contribute and share knowledge in our forum. Get a private inbox, upload your own photo gallery and more.