Reply

Join Date: Jul 2009
Posts: 5
Reputation: mike123421 is an unknown quantity at this point 
Solved Threads: 0
mike123421 mike123421 is offline Offline
Newbie Poster

virus remains

 
0
  #1
Jul 21st, 2009
today i got a nasty fake antivirus named "windows antivirus pro". i got rid of the virus but a few things still remain like i cannot open add or remove programs or display. here is my hyjack this: Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:16:25 PM, on 7/21/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\svchast.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\uTorrent\uTorrent.exe
C:\Program Files\Opera\opera.exe
C:\WINDOWS\explorer.exe
C:\Program Files\CCleaner\CCleaner.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R3 - URLSearchHook: DefaultSearchHook Class - {C94E154B-1459-4A47-966B-4B843BEFC7DB} - C:\Program Files\AskSearch\bin\DefaultSearch.dll
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: ICQSys (IE PlugIn) - {F54AF7DE-6038-4026-8433-CC30E3F17212} - C:\WINDOWS\system32\dddesot.dll
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - Startup: Xfire.lnk = C:\Program Files\Xfire\Xfire.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.systemrequirementslab.com...reqlab_srl.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - avgrsstx.dll (file missing)
O23 - Service: AntipyPro_12 (AntipPro2009_12) - Unknown owner - C:\WINDOWS\svchast.exe
O23 - Service: ASKUpgrade - Unknown owner - C:\Program Files\AskBarDis\bar\bin\ASKUpgrade.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe

--
End of file - 4571 bytes

if this report does not fix it, is there another way to unlock these 2 things
Reply With Quote Quick reply to this message  
Join Date: Jul 2008
Posts: 3,047
Reputation: jholland1964 is a name known to all jholland1964 is a name known to all jholland1964 is a name known to all jholland1964 is a name known to all jholland1964 is a name known to all jholland1964 is a name known to all 
Solved Threads: 173
Moderator
Featured Poster
jholland1964 jholland1964 is offline Offline
Posting Sensei

Re: virus remains

 
0
  #2
Jul 21st, 2009
How DID you remove the virus? That is one thing we need to know before we go forward.
You are running TWO anti-virus programs, Avast and AVG 8. That is an absolute No-No.
TOTALLY UNINSTALL one of them immediately. You will have to do this before other steps can be taken.
The infection is NOT removed by the way, it still shows in your HJT log.

Turn off that uTorrent program and leave it off.
Last edited by jholland1964; Jul 21st, 2009 at 5:52 pm.
Reply With Quote Quick reply to this message  
Join Date: Jul 2009
Posts: 5
Reputation: mike123421 is an unknown quantity at this point 
Solved Threads: 0
mike123421 mike123421 is offline Offline
Newbie Poster

Re: virus remains

 
0
  #3
Jul 21st, 2009
Originally Posted by jholland1964 View Post
How DID you remove the virus? That is one thing we need to know before we go forward.
You are running TWO anti-virus programs, Avast and AVG 8. That is an absolute No-No.
TOTALLY UNINSTALL one of them immediately. You will have to do this before other steps can be taken.
i used windows search and regedit, searched all files with the name windows anti virus and deleted everything that matched, the spot in program files, the spot in system and all matching registries
Reply With Quote Quick reply to this message  
Join Date: Jul 2009
Posts: 5
Reputation: mike123421 is an unknown quantity at this point 
Solved Threads: 0
mike123421 mike123421 is offline Offline
Newbie Poster

Re: virus remains

 
0
  #4
Jul 21st, 2009
utorrent is gone, although i did notice something weird while i was looking in regedit, i went in hkey current user and in control panel because that is where the locked things are and i notice a file that looks out of place, it is called don't load and the d is not capitalised like in all other folders, in it is 2 files named ncpa.cpl and odbccp32.cpl
Reply With Quote Quick reply to this message  
Join Date: Jul 2008
Posts: 3,047
Reputation: jholland1964 is a name known to all jholland1964 is a name known to all jholland1964 is a name known to all jholland1964 is a name known to all jholland1964 is a name known to all jholland1964 is a name known to all 
Solved Threads: 173
Moderator
Featured Poster
jholland1964 jholland1964 is offline Offline
Posting Sensei

Re: virus remains

 
0
  #5
Jul 21st, 2009
That was not the way to remove the infection. Removing the entire infection file by file manually is almost impossible. PLEASE leave the registry ALONE. Remove that extra Anti-virus program immediately. Then I will give you a program to remove the infection. But leave the registry alone.

Obviously you can't remove that extra AV program since you can't get into Add/Remove...that is a "duh" on my part. You will have to totally disable one of them using the program itself.
Last edited by jholland1964; Jul 21st, 2009 at 6:16 pm.
Reply With Quote Quick reply to this message  
Join Date: Jul 2009
Posts: 5
Reputation: mike123421 is an unknown quantity at this point 
Solved Threads: 0
mike123421 mike123421 is offline Offline
Newbie Poster

Re: virus remains

 
0
  #6
Jul 21st, 2009
ok, i dont need avast but i cant access the add or remove programs file so i will go with deleting avg until problem solved, sorry for my foolish attempt to erase the fake antivirus, i didnt know any other way.
Reply With Quote Quick reply to this message  
Join Date: Jul 2008
Posts: 3,047
Reputation: jholland1964 is a name known to all jholland1964 is a name known to all jholland1964 is a name known to all jholland1964 is a name known to all jholland1964 is a name known to all jholland1964 is a name known to all 
Solved Threads: 173
Moderator
Featured Poster
jholland1964 jholland1964 is offline Offline
Posting Sensei

Re: virus remains

 
0
  #7
Jul 21st, 2009
Avast is the better program really.
Do the following:
Please download Malwarebytes' Anti-Malware (MBA-M) to your Desktop.

* DoubleClick mbam-setup.exe and follow the prompts to install MBA-M.
* Be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
* If an update is found, it will download and install the latest version.
* Once the program has loaded, select Perform full scan, then click Scan.
* When the scan is complete, click OK, then Show Results to view the results.
* Be sure that everything is checked, and click Remove Selected.
* When MBA-M finishes, Notepad will open with the log. Please save it where you can find it easily. The log can also be opened by going to Start > All Programs > Malwarebytes' Anti-Malware > Logs > log-date.txt.

Reboot the computer.

Once rebooted, run a new HJT scan. Save the log. Post back here with the MBA-M log and the HJT log.
Judy
Reply With Quote Quick reply to this message  
Join Date: Jul 2009
Posts: 5
Reputation: mike123421 is an unknown quantity at this point 
Solved Threads: 0
mike123421 mike123421 is offline Offline
Newbie Poster

Re: virus remains

 
0
  #8
Jul 21st, 2009
totally disabled avg then, just need the remover then.
Reply With Quote Quick reply to this message  
Join Date: Jul 2008
Posts: 3,047
Reputation: jholland1964 is a name known to all jholland1964 is a name known to all jholland1964 is a name known to all jholland1964 is a name known to all jholland1964 is a name known to all jholland1964 is a name known to all 
Solved Threads: 173
Moderator
Featured Poster
jholland1964 jholland1964 is offline Offline
Posting Sensei

Re: virus remains

 
0
  #9
Jul 21st, 2009
Originally Posted by mike123421 View Post
totally disabled avg then, just need the remover then.
Just posted it. Follow the instructions and be sure you REMOVE all that is found. REBOOT the computer and post back with both logs.
Judy
Reply With Quote Quick reply to this message  
Reply

This thread is more than three months old.
Perhaps start a new thread instead?
Message:



Similar Threads
Other Threads in the Viruses, Spyware and other Nasties Forum
Thread Tools Search this Thread



About Us | Contact Us | Advertise | DaniWeb | Acceptable Use Policy | RSS Feed

©2003 - 2009 DaniWeb® LLC