Welcome to the TechSpot OpenBoards. Please read the FAQ if you have any questions. Login to participate.
|
|||||||
I just conquered a virus, but...
![]() |
| Thread Tools |
|
#1
|
|||
|
|||
|
I just conquered a virus, but...
There are still bits left that I don't know where to begin removing. Some admin rights are locked by the virus, firefox and opera won't load, nor will smitfraudtfix. Superantispyware runs, and the computer restarts at the registry scan. Arrrrgh. Hijack this log is thus:
Logfile of HijackThis v1.99.1 Scan saved at 12:17: VIRUS ALERT!, on 7/5/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\System32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\LEXPPS.EXE C:\WINDOWS\system32\spoolsv.exe C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe C:\Program Files\Lexmark 1200 Series\lxczbmon.exe C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe C:\PROGRA~1\AVG\AVG8\avgtray.exe C:\PROGRA~1\AVG\AVG8\avgrsx.exe C:\Program Files\PeerGuardian2\pg2.exe C:\Program Files\Vidalia Bundle\Privoxy\privoxy.exe C:\PROGRA~1\AVG\AVG8\avgemc.exe C:\Program Files\MSN\MSNCoreFiles\MSN6.EXE C:\Program Files\Messenger\msmsgs.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\system32\mmc.exe C:\DOCUME~1\ADAMAN~1\LOCALS~1\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe O2 - BHO: (no name) - {28220052-D9A9-44B1-AB98-EDC594D238B6} - C:\WINDOWS\system32\yayyYPjk.dll (file missing) O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll O2 - BHO: (no name) - {9AC86257-A5DC-42A9-B216-951F78C3B861} - C:\WINDOWS\system32\urqQiFXR.dll (file missing) O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL O4 - HKLM\..\Run: [Lexmark 1200 Series] "C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe" O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKLM\..\Run: [PCTAVApp] "C:\Program Files\PC Tools AntiVirus\PCTAV.exe" /MONITORSCAN O4 - HKLM\..\Run: [24e26ca0] rundll32.exe "C:\WINDOWS\system32\vqxmoiqv.dll",b O4 - HKLM\..\Run: [Sys4.exe] C:\Windows\Sys4.exe O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe O4 - HKCU\..\Run: [Vidalia] "C:\Program Files\Vidalia Bundle\Vidalia\vidalia.exe" O4 - HKCU\..\Run: [PeerGuardian] C:\Program Files\PeerGuardian2\pg2.exe O4 - HKCU\..\Run: [Sys4.exe] C:\Windows\Sys4.exe O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe O4 - Global Startup: HOTSYNCSHORTCUTNAME.lnk = C:\Program Files\Palm\Hotsync.exe O4 - Global Startup: Privoxy.lnk = C:\Program Files\Vidalia Bundle\Privoxy\privoxy.exe O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dll O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O20 - Winlogon Notify: yayyYPjk - yayyYPjk.dll (file missing) O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (file missing) O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe (file missing) O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing) O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing) O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE O23 - Service: PC Tools AntiVirus Engine (PCTAVSvc) - Unknown owner - C:\Program Files\PC Tools AntiVirus\PCTAVSvc.exe (file missing) |
|
#2
|
||||
|
||||
|
first go to add/remove programs and uninstall that version of HJT
then... Highjackthis Instructions
|
|
|
|
#3
|
|||
|
|||
|
Round 2...
Here it is. Thank you for the guidance... ht log is attached...
|
|
#4
|
||||
|
||||
|
Multiple Anti Virus programs:
It looks like you are operating your computer with multiple Anti Virus programs running in memory at once: PC Tools AV AVG8 Avast! Anti-virus programs take up an enormous amount of your computer's resources when they are actively scanning your computer. Having two or more anti-virus programs running at the same time can cause your computer to run very slow, become unstable and even, in rare cases, crash. Please remove all except one that you would like to keep. -------------------------------------------------------------------------------------- Remove bad HijackThis entries
---------------------------------------------------------------------------------------- Please download the Killbox by Option^Explicit. Note: In the event you already have Killbox, this is a new version that I need you to download.
If your computer does not restart automatically, please restart it manually. If you receive a message such as: "Component 'MsComCtl.ocx' or one of its dependencies not correctly registered: a file is missing or invalid." when trying to run Killbox, click here to download and run missingfilesetup.exe. Then try Killbox again. ---------------------------------------------------------------------------------- Malwarebytes' Anti-Malware
--------------------------------------------------------------------------------- Combofix
Combofix will automatically save the log file to C:\combofix.txt Attach here: 1) MBAM 2) Combofix.txt 3) Hijackthis log ran after everything else |
|
#5
|
|||
|
|||
|
At last
Everything seems to work now... Thank you.
The log files, just in case there's something that needs to be addressed: |
|
#6
|
||||
|
||||
|
it looks like you kept AVG so you need to delete this folder
C:\Program Files\PC Tools AntiVirus ---------------------------------------------------------------- Run Kaspersky Online AV Scanner Order to use it you have to use Internet Explorer. Go to Kaspersky and click the Accept button at the end of the page. Note for Internet Explorer 7 users: If at any time you have trouble with the accept button of the licence, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75 %. Once the license accepted, reset to 100%.
|
|
#7
|
|||
|
|||
|
Here it is
The text file for the kas scan.
|
|
#8
|
||||
|
||||
|
Good job - just one false positive which we will remove now
Uninstall Combofix * Click START then RUN * Now type Combofix /u in the runbox * Make sure there's a space between Combofix and /u * Then hit Enter. * The above procedure will: * Delete the following: * ComboFix and its associated files and folders. * Reset the clock settings. * Hide file extensions, if required. * Hide System/Hidden files, if required. * Set a new, clean Restore Point. ----------------------------------------------------------------------- OTCleanit! by Oldtimer
--------------------------------------------------------------------------- Now that you are clean, please follow these simple steps in order to keep your computer clean and secure:
here are some additional utilities that will enhance your safety
|
|
#9
|
|||
|
|||
|
Thank you very much!. That was intense, but... awesome!
|
|
|
|
#10
|
||||
|
||||
|
Your welcome anytime!
|
![]() |
«
Previous Thread
|
Next Thread
»
| Thread Tools | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Keyboard Virus? BIOS Virus? | Mad Bad Monk | Security and the Web | 1 | 11-16-2007 08:47 AM |
| Myzor virus, networm-i virus on my computer | faticar | Security and the Web | 3 | 11-06-2007 04:13 PM |
| AIM Virus...Facebook Message caused virus please help!!!! | X05TiburonX | Security and the Web | 3 | 02-17-2007 06:19 PM |
| Spyware or Virus disabled my anti-virus and ad-aware - HJT log included | idontknowwww | Security and the Web | 11 | 10-31-2006 12:03 PM |
| Greek virus collector - virus.gr/english | Pazuzu | Security and the Web | 1 | 11-22-2005 09:56 PM |
All times are GMT -4. The time now is 12:19 AM.





