Please help me with a virus problem!

Status
Not open for further replies.
I got this virus a while ago while trying to download a no-CD crack for the sims 2.(I own it i just lost the CD). At first, it would constantly interrupt and minimize any programs i was running and bring up ads. I removed what i thought was the virus, and it stopped minimizing programs, but apparently traces of the virus still remain, and its seriously dragging down my computer speed. Here is a Hijackthis log, with the programs that i suspect to be the virus in red:

UPDATE:

it brought up this site in Mozilla:

Actually, i find that pathetic attempt to trick me very amusing.
 
Hello and welcome to Techspot.

Your system is infected with malware.

Very Important: Before deciding whether you should clean or reformat your system, go and read this thread HERE and decide what it is you want to do.

If after reading the above, you wish to clean your system, do the following.

Go and read the Viruses/Spyware/Malware, preliminary removal instructions. Follow all the instructions exactly.

Post fresh HJT, AVG Antispyware and Combofix logs as attachments into this thread, only after doing the above.

Also, let me know the results of the AVG Antirootkit scan.

Regards Howard :wave: :wave:

This thread is for the use of Phasmaster only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
 
I completed all steps, and i had no problems. the virus apears to be gone, but i attached the hjt and combofix logs. the rootkit scan came up clean.

thanks!

::UPDATE::

added the avg log.

When i ran AVG, a few items showed up that werent there before:
Downloader.Alphabet
Downloader.Alphabet.b
Downloader.Alphabet.c
Downloader.LoadADV
Trojan.WOW.rg
Adware.Trymedia
Adware.VirtueMonde
 
Hi,

I noticed that your AVG log displays 'Ignored' for all the files detected.
I require you to run AVG again and quarantine the files. Pictorial instructions HERE.

You may wish to copy and paste these instructions on notepad for easier reference later.

Download the attached "Combofix-Do.txt" (from my attachment) and save it to the same folder as Combofix.

Boot into safe mode under your normal user name. See how HERE

Next turn on "Show all files and folders, including hidden and system". See how HERE

Go to start > run and type services.msc. Press the enter key.
Search for the following services. Double click to select stop if they are running. Set the startup type to disabled. Click apply/ok for each service you disable.

WildTangent CDA

Go to start > Control Panel > Add and Remove Programs.
Remove anything related to the following:

WildTangent CDA

After that, run HijackThis and fix the following entries, if found (do this by placing a tick in the check boxes beside these entries and clicking "Fix checked"):

O2 - BHO: (no name) - {50CB6A24-179C-4E77-AEAD-D0A3792FB468} - C:\WINDOWS\system32\vtsqn.dll (file missing)
O4 - HKLM\..\Run: [WildTangent CDA] "C:\Program Files\WildTangent\Apps\CDA\GameDrvr.exe" /startup "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0500.dll"

Close HJT.

Drag the Combofix-Do.txt that you downloaded earlier over on to Combofix.exe and release.

This will ask Combofix to execute the instructions within my file. Let Combofix run normally and do its job. Attach the resultant log in your reply.

Reboot into normal mode and rehide your protected OS files.

Thereafter, please post fresh HJT, ComboFix and AVG Antispyware logs from normal mode as attachments into this thread.


Regards,
Your friendly momok =)

This thread is for the use of Phasmaster only. Please don't post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
 
I did quarentine them, i just made the log before i did. i did not choose ignore.

are you sure i should remove WildTangent? It is a company that I have bought games form before, paticularly "Fate".
 
Hi,

With regards to WildTangent, it is a highly controversial as several anti-spyware programs classify it as rogue/spyware because it monitors certain user activity and machine specifications and sends it back to the the game servers. Although the company asserts that its software bundle is safe, its "spyware/adware" classification remains.

I wouldn't recommend keeping it since it has dubious repute; at least wait until things are fully clarified.

Please post the required logs in your next reply.


Regards,
Your friendly momok =)

This thread is for the use of Phasmaster only. Please don't post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
 
Status
Not open for further replies.
Back