MSCONFIG and Task Manager

Thread Solved

Join Date: Feb 2004
Posts: 39
Reputation: raa4 is an unknown quantity at this point 
Solved Threads: 0
raa4 raa4 is offline Offline
Light Poster

Re: MSCONFIG and Task Manager

 
0
  #31
Apr 22nd, 2005
I've done what you said to do on this thread but i also scanned with spydoctor and the trojans still there, Here's my hijack log

Logfile of HijackThis v1.99.1
Scan saved at 20:07:27, on 22/04/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\WINDOWS\System32\VTTimer.exe
C:\Program Files\VIAudioi\SBADeck\ADeck.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\System32\ZoneLabs\isafe.exe
C:\Program Files\Messenger\MSMSGS.EXE
C:\Program Files\Spyware Doctor\swdoctor.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\WINDOWS\system32\ZONELABS\vsmon.exe
C:\Documents and Settings\Ruth Ankrah\My Documents\Computer Programs\hijackthis\HijackThis.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.timecomputers.com
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [AudioDeck] C:\Program Files\VIAudioi\SBADeck\ADeck.exe 1
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O14 - IERESET.INF: START_PAGE_URL=http://www.timecomputers.com
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall-beta.trendmicro.com...ll/xscan60.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2...ll/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {9B03C5F1-F5AB-47EE-937D-A8EDA626F876} (Anonymizer Anti-Spyware Scanner) - http://download.zonelabs.com/bin/pro...tor/WebAAS.cab
O16 - DPF: {A3009861-330C-4E10-822B-39D16EC8829D} (CRAVOnline Object) - http://www.ravantivirus.com/scan/ravonline.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/ms...downloader.cab
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: CA ISafe (CAISafe) - Computer Associates International, Inc. - C:\WINDOWS\System32\ZoneLabs\isafe.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs LLC - C:\WINDOWS\system32\ZONELABS\vsmon.exe
Reply With Quote Quick reply to this message  
Join Date: Jul 2004
Posts: 2,964
Reputation: dlh6213 is on a distinguished road 
Solved Threads: 210
Team Colleague
dlh6213 dlh6213 is offline Offline
Posting Maven

Re: MSCONFIG and Task Manager

 
0
  #32
Apr 22nd, 2005
Can you tell us where Spyware Doctor says the trojan is located?
Links to help you help yourself :

Protect Your PC & Avoid Infections -- http://www.daniweb.com/techtalkforums/thread27519.html

Cleanup Procedures & Tools -- http://www.daniweb.com/techtalkforums/thread27570.html

Infection Removal & HijackThis Use -- http://www.daniweb.com/techtalkforums/thread28196.html
Reply With Quote Quick reply to this message  
Join Date: Dec 2003
Posts: 6,439
Reputation: DMR will become famous soon enough DMR will become famous soon enough 
Solved Threads: 362
Team Colleague
DMR's Avatar
DMR DMR is offline Offline
Wombat At Large

Re: MSCONFIG and Task Manager

 
0
  #33
Apr 22nd, 2005
Originally Posted by dlh6213
Can you tell us where Spyware Doctor says the trojan is located?
Yes, do that if you can please. Your latest log looks clean, but HijackThis isn't designed to detect all types of infections, so you may still have something lurking in your system.

Also install the latest updates for your AVG anti-virus program and run a full scan with that. If AVG finds infections, give us the info on that from AVG's scan report.
"May the Wombat of Happiness snuffle through your underbrush."
- Ancient Aborigine blessing


Please do not contact me by email or PM for help. We're all volunteers here, and only have so much free time to dedicate to our efforts.

However, if I've been working on a thread with you already, and seem to have "forgotten" your thread, please do send me a message. I try not to let things slip through the cracks, but it does happen sometimes.
Reply With Quote Quick reply to this message  
Join Date: Feb 2004
Posts: 39
Reputation: raa4 is an unknown quantity at this point 
Solved Threads: 0
raa4 raa4 is offline Offline
Light Poster

Re: MSCONFIG and Task Manager

 
0
  #34
Apr 24th, 2005
AVG also finds the infections but it wouldn't delete nor heal it as in evertime i put in in quarantine and tunn off my computer, when i switched it off then it would detect that i have the virus again.

spyware doctor says:
INFECTION LOCATION
trojan.hacktool.rootkit multiple
trojan.hacktool.rootkit HKLM\SYSTEM\ControlSet001\Services\msdirectx
trojan.hacktool.rootkit HKLM\SYSTEM\ControlSet001\Services\msdirectx\Security
trojan.hacktool.rootkit HKLM\SYSTEM\ControlSet002\Services\msdirectx
trojan.hacktool.rootkit HKLM\SYSTEM\ControlSet002\Services\msdirectx\Security
trojan.hacktool.rootkit HKLM\SYSTEM\CurrentControlSet\Services\msdirectx
trojan.hacktool.rootkit HKLM\SYSTEM\CurrentControlSet\Services\msdirectx\security
and it says:
A worm/trojan which is installed onto the user's P.C unknowingly through a unsecured SQL server TCP port 1433

AVG says: Path
Trojan horse Collected.5.L C:\Documents and Settings\Ruth Ankrah\msdirectx.sys

I have located that folder but everytime i delete it it re-installs when i turn on my computer.
Reply With Quote Quick reply to this message  
Join Date: Dec 2003
Posts: 6,439
Reputation: DMR will become famous soon enough DMR will become famous soon enough 
Solved Threads: 362
Team Colleague
DMR's Avatar
DMR DMR is offline Offline
Wombat At Large

Re: MSCONFIG and Task Manager

 
0
  #35
Apr 24th, 2005
1. Turn off System Restore; instructions and explanation are here.

2. Follow the trojan removal instructions given in this Microsoft article:

http://support.microsoft.com/?scid=kb;en-us;897079

3. Run the AVG and Spyware Doctor scans again. If they no longer detect the trojan, re-enable System Restore. If they still detect the trojan, let us know.
"May the Wombat of Happiness snuffle through your underbrush."
- Ancient Aborigine blessing


Please do not contact me by email or PM for help. We're all volunteers here, and only have so much free time to dedicate to our efforts.

However, if I've been working on a thread with you already, and seem to have "forgotten" your thread, please do send me a message. I try not to let things slip through the cracks, but it does happen sometimes.
Reply With Quote Quick reply to this message  
Join Date: Feb 2004
Posts: 39
Reputation: raa4 is an unknown quantity at this point 
Solved Threads: 0
raa4 raa4 is offline Offline
Light Poster

Re: MSCONFIG and Task Manager

 
0
  #36
Apr 24th, 2005
I did what the instructions asked and ran spy doctor and it didn't detect anything and AVG also.

I followed instructions like those before (turning off system restore in normal mode and then deleting the files from the registery using regedit) but when you open safe mode it asks you to decide whther you want system restore to runor not even though you turned it off in normal mode, which i accidentally ticked yes (like a fool) anyway,:cheesy:

Thank you soooooooooooo much!
You guy's are stars!!!!
Reply With Quote Quick reply to this message  
Join Date: Dec 2003
Posts: 6,439
Reputation: DMR will become famous soon enough DMR will become famous soon enough 
Solved Threads: 362
Team Colleague
DMR's Avatar
DMR DMR is offline Offline
Wombat At Large

Re: MSCONFIG and Task Manager

 
0
  #37
May 18th, 2005
Glad we could help you get it sorted
"May the Wombat of Happiness snuffle through your underbrush."
- Ancient Aborigine blessing


Please do not contact me by email or PM for help. We're all volunteers here, and only have so much free time to dedicate to our efforts.

However, if I've been working on a thread with you already, and seem to have "forgotten" your thread, please do send me a message. I try not to let things slip through the cracks, but it does happen sometimes.
Reply With Quote Quick reply to this message  
Join Date: Jun 2005
Posts: 1
Reputation: stretch85 is an unknown quantity at this point 
Solved Threads: 1
stretch85 stretch85 is offline Offline
Newbie Poster

Re: MSCONFIG and Task Manager

 
0
  #38
Jun 24th, 2005
Hi, I've been having the same problem with that virus, and I followed your directions, and the virus is still there. It's a persistant little thing. Here are the stats on it:

Scan type: Realtime Protection Scan
Event: Virus Found!
Virus name: Hacktool.Rootkit
File: C:\Documents and Settings\Jeff\msdirectx.sys
Location: Quarantine
Computer: HOME
User: Jeff
Action taken: Clean failed : Quarantine succeeded : Access denied
Date found: Fri Jun 24 19:05:38 2005

I guess I'll try microsoft's 'automatic' way of ridding of it next; but if you have any more idea's, I sure would like to hear them.
Reply With Quote Quick reply to this message  
Join Date: Dec 2003
Posts: 6,439
Reputation: DMR will become famous soon enough DMR will become famous soon enough 
Solved Threads: 362
Team Colleague
DMR's Avatar
DMR DMR is offline Offline
Wombat At Large

Re: MSCONFIG and Task Manager

 
0
  #39
Jun 24th, 2005
Hi stretch85 ,

First of all- welcome to TechTalk!

We ask that members not tag their questions on to a thread previously started by another member (regardless of how similar your problem might seem). Not only does it divert the focus of the thread away from the original poster's problem, but it also makes it less likely that you yourself will get the individual attention that you need.

If you would like us to help you with your particular problem, please start your own thread in this forum and we'll take it from there. In your post, please include as much information as possible about the infection and what you've done so far to try to remove it.

For a full description of our posting guidelines and general rules of conduct, please see this page:

http://www.daniweb.com/techtalkforum..._faq#faq_rules


Thanks for understanding.
"May the Wombat of Happiness snuffle through your underbrush."
- Ancient Aborigine blessing


Please do not contact me by email or PM for help. We're all volunteers here, and only have so much free time to dedicate to our efforts.

However, if I've been working on a thread with you already, and seem to have "forgotten" your thread, please do send me a message. I try not to let things slip through the cracks, but it does happen sometimes.
Reply With Quote Quick reply to this message  
Reply

This thread has been marked solved.
Perhaps start a new thread instead?
Message:



Similar Threads
Other Threads in the Viruses, Spyware and other Nasties Forum


Views: 12251 | Replies: 38
Thread Tools Search this Thread



Tag cloud for Viruses, Spyware and other Nasties
About Us | Contact Us | Advertise | DaniWeb | Acceptable Use Policy | RSS Feed

©2003 - 2009 DaniWeb® LLC