i really don't like doing this... but I need virus help

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • Bahamut-X
    FFR Player
    FFR Simfile Author
    • Nov 2004
    • 3399

    #1

    i really don't like doing this... but I need virus help

    Since every "professional" site where you're supposed to post hijack this logs is usually swarmed with people and your post never gets answered, I'm forced to post it here (the only other place I really know of, and I've had success here before).

    Logfile of HijackThis v1.99.1
    Scan saved at 11:15:10 PM, on 9/15/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\csrss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\WINDOWS\VGhlIEZhbWlseQ\command.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Network Monitor\netmon.exe
    C:\WINDOWS\system32\HPZipm12.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\System32\alg.exe
    C:\WINDOWS\system32\pipmon.exe
    C:\d.exe
    C:\Program Files\Windows Media Player\WMPNSCFG.exe
    C:\Program Files\TuneUp Utilities 2007\MemOptimizer.exe
    C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
    C:\Program Files\uTorrent\utorrent.exe
    C:\WINDOWS\system32\pipmon.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\WINDOWS\system32\wbem\wmiprvse.exe
    C:\Program Files\Hijackthis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    O4 - HKLM\..\Run: [LTMSG] -LTMSG.exe 7
    O4 - HKLM\..\Run: [AlcxMonitor] -ALCXMNTR.EXE
    O4 - HKLM\..\Run: [VTTimer] -VTTimer.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] -"C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
    O4 - HKLM\..\Run: [HostManager] -C:\Program Files\Common Files\AOL\1141683113\ee\AOLSoftware.exe
    O4 - HKLM\..\Run: [IPHSend] -C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
    O4 - HKLM\..\Run: [HP Software Update] -C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [QuickTime Task] -"C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] -"C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [pipmon] pipmon.exe
    O4 - HKLM\..\Run: [E-Gold] C:\d.exe
    O4 - HKLM\..\Run: [au] C:\Program Files\Dealio\DealioAU.exe
    O4 - HKCU\..\Run: [ctfmon.exe] -C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
    O4 - HKCU\..\Run: [TuneUp MemOptimizer] "C:\Program Files\TuneUp Utilities 2007\MemOptimizer.exe" autostart
    O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
    O8 - Extra context menu item: Compare Prices with &Dealio - C:\Program Files\Dealio\kb106\res\DealioSearch.html
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
    O9 - Extra button: Dealio - {E908B145-C847-4e85-B315-07E2E70DECF8} - C:\Program Files\Dealio\kb106\Dealio.dll (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {BD08A9D5-0E5C-4F42-99A3-C0CB5E860557} (CSolidBrowserObj Object) - http://cdn1.acclaimdownloads.com/solidstateion.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{DB4103DE-1D13-4213-9B3D-5745914C0A1E}: NameServer = 24.159.193.40,68.115.71.53
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
    O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
    O23 - Service: Apple Mobile Device - Unknown owner - -"C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (file missing)
    O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Canon Camera Access Library 8 (CCALib8) - Unknown owner - -C:\Program Files\Canon\CAL\CALMAIN.exe (file missing)
    O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\VGhlIEZhbWlseQ\command.exe
    O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    O23 - Service: iPod Service - Unknown owner - -"C:\Program Files\iPod\bin\iPodService.exe (file missing)
    O23 - Service: McAfee Framework Service (McAfeeFramework) - Unknown owner - -C:\Program Files\Network Associates\Common Framework\FrameworkService.exe (file missing)
    O23 - Service: Machine Debug Manager (MDM) - Unknown owner - -"C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (file missing)
    O23 - Service: Network Monitor - Unknown owner - C:\Program Files\Network Monitor\netmon.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: Windows Media Player Network Sharing Service (WMPNetworkSvc) - Unknown owner - -"C:\Program Files\Windows Media Player\WMPNetwk.exe (file missing)

    what do I delete? gettin lots of IE popups
  • Bahamut-X
    FFR Player
    FFR Simfile Author
    • Nov 2004
    • 3399

    #2
    Re: i really don't like doing this... but I need virus help

    so apparently I can't edit the regsitry and can't access task manager, which means I can't delete certain things from hijack this..... ****

    what do I do =/

    Comment

    • silvercomet1525
      FFR Player
      • Sep 2005
      • 601

      #3
      Re: i really don't like doing this... but I need virus help

      I'm no computer expert, and I'm not sure if this would help but... have you tried system restore yet?
      Originally posted by Phynx
      BEDTIME FOR ME YAY!!! PILLOW SO SOFT!


      Tier Points: 537 (519 + 18 for 664 AAAs)
      (7/29/09)

      Comment

      • Bahamut-X
        FFR Player
        FFR Simfile Author
        • Nov 2004
        • 3399

        #4
        Re: i really don't like doing this... but I need virus help

        Yea.

        It didn't work.

        Comment

        • Tibs
          FFR Player
          • May 2006
          • 5235

          #5
          Re: i really don't like doing this... but I need virus help

          safe mode hijack this taka taka boom wasted

          Metal covers of vidya game songs

          Comment

          • Bahamut-X
            FFR Player
            FFR Simfile Author
            • Nov 2004
            • 3399

            #6
            Re: i really don't like doing this... but I need virus help

            holy crap i didnt think of that

            problem is i still need to know what to delete

            Comment

            • silvercomet1525
              FFR Player
              • Sep 2005
              • 601

              #7
              Re: i really don't like doing this... but I need virus help

              C:\WINDOWS\VGhlIEZhbWlseQ\command.exe
              C:\Program Files\Network Monitor\netmon.exe
              C:\d.exe

              Those three processes are worms and could be causing the problem. I guess I know what's wrong but now what to do with it.

              Edit: Oh, yeah. There you go then.

              Edit2: You might want to bookmark this page if something like this ever happens again.
              Last edited by silvercomet1525; 09-16-2007, 01:18 AM.
              Originally posted by Phynx
              BEDTIME FOR ME YAY!!! PILLOW SO SOFT!


              Tier Points: 537 (519 + 18 for 664 AAAs)
              (7/29/09)

              Comment

              • evilbutterfly
                FFR Player
                • Apr 2003
                • 5784

                #8
                Re: i really don't like doing this... but I need virus help

                I don't know why you keep getting viruses, but good lord Tyler, do you not have any anti-virus stuff? If you have Norton or some ****, or if you have nothing, go here:

                Join hundreds of millions of others & get free antivirus for PC, Mac, & Android. Surf safely with our VPN. Download Avast!


                It's free, it's awesome, it's fast. Won't slow your computer down, scans way faster than Norton but catches way more, checks code in real time in addition to using virus databases (I've had it block malicious programs I've written myself, it has to be scanning the actual code before it runs), and it's all completely 100% free. You should get it, everybody on this site should get it.
                So I've gone completely slack-ass and haven't done any work on creating games. =(

                In less-depressing news, I got a job for an online business (which sells non-electronic games, of all things!) which has taught me a lot about marketing online and all that jazz.

                So now I'm on Twitter @NoahWright.
                And I write the blog for their website.

                Plus I do cool programming in-house that you'll never see. =O

                Comment

                • nforcer06164
                  FFR Player
                  • Mar 2003
                  • 4772

                  #9
                  Re: i really don't like doing this... but I need virus help

                  I had my hijackthis log analyzed in less than an hour on geekstogo.com. Try posting it there and just be patient.

                  And eb, AVG works just as well. It does everything you just said (and checking malicious code that isn't in a virus database is "heuristics"). I had trouble removing a worm at my school that tied itself to the winlogon process, and Norton couldn't remove it. I tried everything and I still couldn't do anything. This was just about the time AVG upgraded to 7.5... BOOM. Gone.

                  PROUD OWNER OF TWO OMEGA FAVORS. YEAH, NICE TRY.
                  Giant NES Controller (4 FEET) progress: PAINT IS DONE!
                  Download my Wii Music Suite v1.0, and PM me with your input!

                  Originally posted by Squeek
                  My mind says "GOGOGOG" and my hands go "wut no scru u ***"

                  Comment

                  • Bahamut-X
                    FFR Player
                    FFR Simfile Author
                    • Nov 2004
                    • 3399

                    #10
                    Re: i really don't like doing this... but I need virus help

                    Well after around 2 hours or so I'm about 99.9% sure I've killed the problem.

                    And eb, I've been looking for a good antivirus program for awhile now. I guess I'll try this Avast thing since you say it's completely free and stuff.

                    I also got spybot which really helped I think. I

                    Comment

                    • Zageron
                      Zageron E. Tazaterra
                      FFR Administrator
                      • Apr 2007
                      • 6592

                      #11
                      Re: i really don't like doing this... but I need virus help

                      Install Panda Titanium AntiVirus + AntiSpyware.

                      Your troubles will be gone.

                      Comment

                      Working...