Reply

Join Date: Oct 2006
Posts: 1,311
Reputation: vishesh is on a distinguished road 
Solved Threads: 36
vishesh's Avatar
vishesh vishesh is offline Offline
Nearly a Posting Virtuoso

Virus attack

 
0
  #1
Feb 22nd, 2007
I have Windows XP SP1 with Norton Antivirus 2004 Pro installed.

Some virus has come into my computer, which has blocked my regedit, folder option, noton antivirus etc.. etc... That restarts my computer within few minutes i start my computer.

I am not able to see Folder Option in both control panel and explorer tool menu. also when i open regedit it gives a message "Registry Editing Has Been Diabled By Your administrator".

I manally deleted some files(which were infected by the virus) in system folder first by first killing process in task manager and then deleting.

But still computer is still affected and i am not able to reinstall norton. What should i do??
Reply With Quote Quick reply to this message  
Join Date: Feb 2007
Posts: 549
Reputation: eXceed69 is an unknown quantity at this point 
Solved Threads: 2
eXceed69's Avatar
eXceed69 eXceed69 is offline Offline
Posting Pro

Re: Virus attack

 
0
  #2
Feb 25th, 2007
Is your workstation is part of a LAN?if so the admin had been disable. And what is your account privileges
Reply With Quote Quick reply to this message  
Join Date: Feb 2004
Posts: 9,982
Reputation: crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold 
Solved Threads: 754
Moderator
Featured Poster
crunchie's Avatar
crunchie crunchie is offline Offline
Spyware Killer

Re: Virus attack

 
0
  #3
Feb 26th, 2007
What files did you delete?

Download HijackThis self-extracting zip version from here. Once downloaded, double click on the file & it will install into it's own, permanent folder.
Start HJT & press the "Do a system scan and save a log file" button. When the scan is finished a window will pop up giving you the option of where to save it. Save it to desktop where it is easy to access. Open the log file and copy the entire contents of the file & paste it into the body of your post. DO NOT FIX ANYTHING YET. Most of what is there is necessary for the running of your system.
Reply With Quote Quick reply to this message  
Join Date: Oct 2006
Posts: 1,311
Reputation: vishesh is on a distinguished road 
Solved Threads: 36
vishesh's Avatar
vishesh vishesh is offline Offline
Nearly a Posting Virtuoso

Re: Virus attack

 
0
  #4
Feb 26th, 2007
Well, i have got rid of those virus using HijackThis and AVG.

But the problem now is that

1. I am not able to open RegEdit. It gives a message
Registry Editor has been diabled by your administrator, even when i am administrator. And yes it is not on LAN or any server.

2. The Folder Options has in Tools menu and control panel is not visible.

3. Whenever i start my computer after hibernating, it asks for password, and i have not set any password.


Logfile of HijackThis v1.99.1
Scan saved at 3:03:05 PM, on 2/26/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Adobe\Adobe Photoshop Lightroom\apdproxy.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\PROGRA~1\Grisoft\AVG7\avgfwsrv.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\Grisoft\AVG7\avgw.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
D:\RegSeeker2\hijackthis\HijackThis.exe

O1 - Hosts: <!doctype html public "-//W3C//DTD HTML 4.01 Transitional//EN">
O1 - Hosts: <html>
O1 - Hosts: <head>
O1 - Hosts: <title> Songs, mp3 and lyrics db searches</title
O1 - Hosts: <meta name="Author" content="net4free.org">
O1 - Hosts: <meta name="Keywords" content="free web host, domain host, mp3 searchable database, lyrics searches, lyrics, mp3 discographi">
O1 - Hosts: </head>
O1 - Hosts: <STYLE type=text/css>
O1 - Hosts: <!--
O1 - Hosts: a {color: #3300CC; text-decoration: none}
O1 - Hosts: .bordata {border-bottom :solid #C0C0C0 1px;border-top :solid #C0C0C0 1px;border-left :solid #C0C0C0 1px;border-right :solid #C0C0C0 1px}
O1 - Hosts: h3{font-family: Arial;font-style : normal ;font-size : 12pt; font-weight :bold;text-align : center; color :#FFFFFF;background-color :#004f9d }
O1 - Hosts: body {FONT-SIZE: 4px; COLOR: #444444;}
O1 - Hosts: .small {BORDER-RIGHT: silver 1px solid; BORDER-TOP: silver 1px solid; FONT-SIZE: 7pt; BORDER-LEFT: silver 1px solid; COLOR: black; BORDER-BOTTOM: silver 1px solid; FONT-FAMILY: Verdana,Arial,sans-serif; HEIGHT: 14px; BACKGROUND-COLOR: white}
O1 - Hosts: .small1 {FONT-SIZE: 7pt; WIDTH: 75px; COLOR: black; FONT-FAMILY: Verdana,Arial,sans-serif; HEIGHT: 14px; }
O1 - Hosts: .small2 {FONT-SIZE: 9pt; FONT-FAMILY: Verdana,Arial;}
O1 - Hosts: .abuse {FONT-SIZE: 10pt; FONT-FAMILY: Verdana,Arial;}
O1 - Hosts: .HF {FONT-SIZE: 17pt; FONT-FAMILY: Verdana,Arial;}
O1 - Hosts: -->
O1 - Hosts: </STYLE>
O1 - Hosts: </head>
O1 - Hosts: <body leftmargin=0 rightmargin=0>
O1 - Hosts: <table class=bordata cellpadding=14 cellspacing=0 height=80 width=100% background="/images/sfondo1.gif" BORDER=0>
O1 - Hosts: <tr>
O1 - Hosts: <td valign=top><a href="http://www.net4free.org/"><img src="http://www.net4free.org/images/nff_l.gif" border=0 alt=""></a></td>
O1 - Hosts: <td valign=top>
O1 - Hosts: <p align=right>
O1 - Hosts: <table cellpadding=2 cellspacing=2 BORDER=0>
O1 - Hosts: <tr>
O1 - Hosts: <td class=small align=center><a href="http://www.net4free.org/free_web_hosting.php"><b>Join Now</a></b></td>
O1 - Hosts: <td class=small align=center><a href="/faq.html"><b>FAQ</a></b></td>
O1 - Hosts: <td class=small align=center><a href="/terms_of_service.html"><b>Terms Of Service</a></b></td>
O1 - Hosts: <td class=small align=center><a href="/free_utility.html"><b>Net4Free Utility</a></b></td>
O1 - Hosts: <td class=small align=center><a href="/welcome.php"><b>Forgot Password</a></b></td>
O1 - Hosts: </tr>
O1 - Hosts: </table>
O1 - Hosts: </p>
O1 - Hosts: </td>
O1 - Hosts: </tr>
O1 - Hosts: </table>
O1 - Hosts: <table><tr><td></td></tr></table>
O1 - Hosts: <table class=bordata cellpadding=14 cellspacing=0 height=180 width=100% background="/images/sfondog.gif" BORDER=0>
O1 - Hosts: <tr>
O1 - Hosts: <td align=center>
O1 - Hosts: <a href="http://www.top100lyrics.com/in/?id=997"><img src="/images/top100.gif" border=0></a><BR><BR>
O1 - Hosts: <table class=bordata>
O1 - Hosts: <tr>
O1 - Hosts: <td><a href="http://www.mp3qm.com/"><img src="http://www.mp3qm.com/images/logo.gif" border=0 alt="Mp3 lyrics database"><br>
O1 - Hosts: Mp3 search searchable database</a></td>
O1 - Hosts: </tr>
O1 - Hosts: </table>
O1 - Hosts: <BR>
O1 - Hosts: <table class=bordata>
O1 - Hosts: <tr>
O1 - Hosts: <td><a href="http://www.lyricsbook.net/"><img src="http://www.lyricsbook.net/images/lyrics_book1.gif" border=0 alt="Mp3 database"><br>
O1 - Hosts: <CENTER>Lyrics searchable database</CENTER></a></td>
O1 - Hosts: </tr>
O1 - Hosts: </table>
O1 - Hosts: </td>
O1 - Hosts: <td align="center">
O1 - Hosts: <table ><tr><td>
O1 - Hosts: <!--
O1 - Hosts: <a href="http://www.net4free.org/angelicastore.php" onMouseover="window.status='Angelica Store!'; return true">
O1 - Hosts: <img src="http://www.net4free.org/images/angel3.jpg" alt="Angelica Store!" border="0"/></a>
O1 - Hosts: -->
O1 - Hosts: </td>
O1 - Hosts: </tr>
O1 - Hosts: </table>
O1 - Hosts: </td>
O1 - Hosts: <td>
O1 - Hosts: <table class=bordata bgcolor=#FFFFFF>
O1 - Hosts: <tr>
O1 - Hosts: <td>
O1 - Hosts: <table>
O1 - Hosts: <tr>
O1 - Hosts: <td align=center><a href="http://www.findhostdir.com/"><img src="http://www.findhostdir.com/images/link2.gif" border=0><br>
O1 - Hosts: Free web Host, Free domain Host<br> and Cheap web Host Directory</a></td>
O1 - Hosts: </tr>
O1 - Hosts: </table>
O1 - Hosts: </td>
O1 - Hosts: </tr>
O1 - Hosts: </table>
O1 - Hosts: </td>
O1 - Hosts: </tr>
O1 - Hosts: <tr>
O1 - Hosts: <td></td>
O1 - Hosts: </tr>
O1 - Hosts: </table>
O1 - Hosts: </body>
O1 - Hosts: </html>
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Adobe Photoshop Lightroom\apdproxy.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: Download using LeechGet - file://C:\Program Files\LeechGet 2006\\AddUrl.html
O8 - Extra context menu item: Download using LeechGet Wizard - file://C:\Program Files\LeechGet 2006\\Wizard.html
O8 - Extra context menu item: Edit with Altova X&MLSpy - D:\Program Files\Altova\XMLSpy2006\spy.htm
O8 - Extra context menu item: Parse with LeechGet - file://C:\Program Files\LeechGet 2006\\Parser.html
O9 - Extra button: Edit with Altova X&MLSpy - {2222EF56-F49E-4d07-A14E-8D2B08766958} - D:\Program Files\Altova\XMLSpy2006\spy.htm
O9 - Extra 'Tools' menuitem: Edit with Altova X&MLSpy - {2222EF56-F49E-4d07-A14E-8D2B08766958} - D:\Program Files\Altova\XMLSpy2006\spy.htm
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{19D372AF-5BF1-4464-B1AE-ED5DDDA05340}: NameServer = 192.168.1.1,192.168.1.2
O17 - HKLM\System\CCS\Services\Tcpip\..\{1AD5B67B-CC2D-4B70-B97F-D2685C151B33}: NameServer = 192.1.1.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{9CF691B0-A6A6-4155-9EE0-7F007FC346BD}: NameServer = 218.248.255.193 218.248.255.145
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: AVG Firewall (AVGFwSrv) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgfwsrv.exe
O23 - Service: Client Disk Manager - Unknown owner - C:\WINDOWS\system32\spoolvc.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
Last edited by crunchie; Feb 26th, 2007 at 6:04 am.
Attached Files
File Type: txt hjt.txt (9.3 KB, 1 views)
Reply With Quote Quick reply to this message  
Join Date: Feb 2004
Posts: 9,982
Reputation: crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold 
Solved Threads: 754
Moderator
Featured Poster
crunchie's Avatar
crunchie crunchie is offline Offline
Spyware Killer

Re: Virus attack

 
0
  #5
Feb 26th, 2007
Download the Hoster.
Run it and press "Restore Original Hosts" and press "OK". Exit Program.
Note that if you have a custom host file, this will remove it. You can edit the host file with this program too.

-------

Can you please do the following.


===============

Scan with HijackThis and then place a check next to all the following, if present:


O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
...(Unless you've restricted the use of registry editing, have HiJackThis fix this.)

O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm

O23 - Service: Client Disk Manager - Unknown owner - C:\WINDOWS\system32\spoolvc.exe


Now, close all instances of Internet Explorer and any other windows you have open except HiJackThis, click "Fix checked".

===============

Locate and delete the following item(s), if present. Make sure you are able to view system and hidden files/ folders:

files...

C:\WINDOWS\system32\spoolvc.exe

-

Note that some of these file(s)/folder(s) may or may not be present. If present, and cannot be deleted because they're 'in use', try deleting them in Safe Mode by doing the following:
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
  • Instead of Windows loading as normal, a menu should appear.
Select the first option to run Windows in Safe Mode hit enter.

-

Reboot.

===============

After rebooting, rename hijackthis.exe to analyse.exe and post back the new log.
Reply With Quote Quick reply to this message  
Join Date: Oct 2006
Posts: 1,311
Reputation: vishesh is on a distinguished road 
Solved Threads: 36
vishesh's Avatar
vishesh vishesh is offline Offline
Nearly a Posting Virtuoso

Re: Virus attack

 
0
  #6
Feb 26th, 2007
I had already deleted spoolvc.exe. I have fixed the problems using HijackThis as per your instruction....and registry editor is now working perfectly fine, but i am still not able to see Folder Options under Tools menu. Here's the latest log.

Logfile of HijackThis v1.99.1
Scan saved at 8:31:24 PM, on 2/26/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\PROGRA~1\Grisoft\AVG7\avgfwsrv.exe
C:\Program Files\Adobe\Adobe Photoshop Lightroom\apdproxy.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
D:\RegSeeker2\hijackthis\analyse.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {8E5A2506-A3B7-4219-8ED2-BCEB8FCA968E} - C:\WINDOWS\System32\urqqqoo.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: (no name) - {E03C740E-BB24-4d3c-B92A-6F84DE1DD99C} - C:\WINDOWS\System32\bbckiwak.dll
O2 - BHO: (no name) - {EA409924-1ACA-448E-B4F9-A8D733590F9C} - C:\WINDOWS\System32\khhee.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Adobe Photoshop Lightroom\apdproxy.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: Download using LeechGet - file://C:\Program Files\LeechGet 2006\\AddUrl.html
O8 - Extra context menu item: Download using LeechGet Wizard - file://C:\Program Files\LeechGet 2006\\Wizard.html
O8 - Extra context menu item: Edit with Altova X&MLSpy - D:\Program Files\Altova\XMLSpy2006\spy.htm
O8 - Extra context menu item: Parse with LeechGet - file://C:\Program Files\LeechGet 2006\\Parser.html
O9 - Extra button: Edit with Altova X&MLSpy - {2222EF56-F49E-4d07-A14E-8D2B08766958} - D:\Program Files\Altova\XMLSpy2006\spy.htm
O9 - Extra 'Tools' menuitem: Edit with Altova X&MLSpy - {2222EF56-F49E-4d07-A14E-8D2B08766958} - D:\Program Files\Altova\XMLSpy2006\spy.htm
O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{19D372AF-5BF1-4464-B1AE-ED5DDDA05340}: NameServer = 192.168.1.1,192.168.1.2
O17 - HKLM\System\CCS\Services\Tcpip\..\{1AD5B67B-CC2D-4B70-B97F-D2685C151B33}: NameServer = 192.1.1.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{9CF691B0-A6A6-4155-9EE0-7F007FC346BD}: NameServer = 218.248.255.193 218.248.255.145
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O20 - Winlogon Notify: khhee - C:\WINDOWS\System32\khhee.dll
O20 - Winlogon Notify: urqqqoo - C:\WINDOWS\SYSTEM32\urqqqoo.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: AVG Firewall (AVGFwSrv) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgfwsrv.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
Reply With Quote Quick reply to this message  
Join Date: Feb 2004
Posts: 9,982
Reputation: crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold 
Solved Threads: 754
Moderator
Featured Poster
crunchie's Avatar
crunchie crunchie is offline Offline
Spyware Killer

Re: Virus attack

 
0
  #7
Feb 26th, 2007
Right click on the following link and select 'Save As.' http://www.kellys-korner-xp.com/regs...deroptions.reg Save the file to your desktop. Close ALL your browser windows and then double click the file to merge it with your registry. If you get a pop up asking if you should merge it, click yes. Reboot.

--

Please download VundoFix.exe
to your desktop.
  • Double-click VundoFix.exe to run it.
  • Click the Scan for Vundo button.
  • Once it's done scanning, click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click YES
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will reboot your computer, click OK.
  • Please post the contents of C:\vundofix.txt and a new HiJackThis log.
Note: It is possible that VundoFix encountered a file it could not remove.
In this case, VundoFix will run on reboot, simply follow the above
instructions starting from "Click the Scan for Vundo button." when
VundoFix appears at reboot.
Last edited by crunchie; Feb 26th, 2007 at 3:56 pm.
Reply With Quote Quick reply to this message  
Join Date: Oct 2006
Posts: 1,311
Reputation: vishesh is on a distinguished road 
Solved Threads: 36
vishesh's Avatar
vishesh vishesh is offline Offline
Nearly a Posting Virtuoso

Re: Virus attack

 
0
  #8
Feb 28th, 2007
Yes, I could now see Folder Options under tools menu and control panel, after the registry fix.


Here's the vundo report...It found 6 crap dll files.

VundoFix V6.3.9

Checking Java version...

Sun Java not detected
Scan started at 2:45:50 PM 2/28/2007

Listing files found while scanning....

C:\WINDOWS\System32\bbckiwak.dll
C:\WINDOWS\system32\bevdxmbs.dll
C:\WINDOWS\System32\eehhk.bak1
C:\WINDOWS\System32\eehhk.bak2
C:\WINDOWS\System32\eehhk.ini
C:\WINDOWS\System32\khhee.dll

Beginning removal...

 Attempting to delete C:\WINDOWS\System32\bbckiwak.dll
C:\WINDOWS\System32\bbckiwak.dll Has been deleted!

 Attempting to delete C:\WINDOWS\system32\bevdxmbs.dll
C:\WINDOWS\system32\bevdxmbs.dll Has been deleted!

 Attempting to delete C:\WINDOWS\System32\eehhk.bak1
C:\WINDOWS\System32\eehhk.bak1 Has been deleted!

 Attempting to delete C:\WINDOWS\System32\eehhk.bak2
C:\WINDOWS\System32\eehhk.bak2 Has been deleted!

 Attempting to delete C:\WINDOWS\System32\eehhk.ini
C:\WINDOWS\System32\eehhk.ini Has been deleted!

 Attempting to delete C:\WINDOWS\System32\khhee.dll
C:\WINDOWS\System32\khhee.dll Has been deleted!

Performing Repairs to the registry.
Done!
Last edited by vishesh; Feb 28th, 2007 at 5:39 am.
Reply With Quote Quick reply to this message  
Join Date: Feb 2004
Posts: 9,982
Reputation: crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold 
Solved Threads: 754
Moderator
Featured Poster
crunchie's Avatar
crunchie crunchie is offline Offline
Spyware Killer

Re: Virus attack

 
1
  #9
Feb 28th, 2007
Originally Posted by crunchie View Post
...and a new HiJackThis log.
You forgot this .
Reply With Quote Quick reply to this message  
Join Date: Oct 2006
Posts: 1,311
Reputation: vishesh is on a distinguished road 
Solved Threads: 36
vishesh's Avatar
vishesh vishesh is offline Offline
Nearly a Posting Virtuoso

Re: Virus attack

 
0
  #10
Feb 28th, 2007
Err...sorry just forgot....after two reboots:eek:

Uh...let me see....just bolded the one which i suspect.....i oughta learn something.....tell me if i am right. Havn't fixed em yet.

Logfile of HijackThis v1.99.1
Scan saved at 3:28:37 PM, on 2/28/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\PROGRA~1\Grisoft\AVG7\avgfwsrv.exe
C:\Program Files\Adobe\Adobe Photoshop Lightroom\apdproxy.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\spoolvc.exe
D:\RegSeeker2\hijackthis\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
 O2 - BHO: (no name) - {381B9E30-3E03-4976-9FD2-7A45AFAE3270} - C:\WINDOWS\System32\khhee.dll (file missing)
 O2 - BHO: (no name) - {8E5A2506-A3B7-4219-8ED2-BCEB8FCA968E} - C:\WINDOWS\System32\urqqqoo.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: (no name) - {E03C740E-BB24-4d3c-B92A-6F84DE1DD99C} - C:\WINDOWS\System32\bbckiwak.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Adobe Photoshop Lightroom\apdproxy.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: Download using LeechGet - file://C:\Program Files\LeechGet 2006\\AddUrl.html
O8 - Extra context menu item: Download using LeechGet Wizard - file://C:\Program Files\LeechGet 2006\\Wizard.html
O8 - Extra context menu item: Edit with Altova X&MLSpy - D:\Program Files\Altova\XMLSpy2006\spy.htm
O8 - Extra context menu item: Parse with LeechGet - file://C:\Program Files\LeechGet 2006\\Parser.html
O9 - Extra button: Edit with Altova X&MLSpy - {2222EF56-F49E-4d07-A14E-8D2B08766958} - D:\Program Files\Altova\XMLSpy2006\spy.htm
O9 - Extra 'Tools' menuitem: Edit with Altova X&MLSpy - {2222EF56-F49E-4d07-A14E-8D2B08766958} - D:\Program Files\Altova\XMLSpy2006\spy.htm
O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{19D372AF-5BF1-4464-B1AE-ED5DDDA05340}: NameServer = 192.168.1.1,192.168.1.2
O17 - HKLM\System\CCS\Services\Tcpip\..\{1AD5B67B-CC2D-4B70-B97F-D2685C151B33}: NameServer = 192.1.1.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{9CF691B0-A6A6-4155-9EE0-7F007FC346BD}: NameServer = 218.248.255.193 218.248.255.145
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O20 - Winlogon Notify: ljjkh - C:\WINDOWS\System32\ljjkh.dll
O20 - Winlogon Notify: urqqqoo - C:\WINDOWS\SYSTEM32\urqqqoo.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: AVG Firewall (AVGFwSrv) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgfwsrv.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Remote Process Manager - Unknown owner - C:\WINDOWS\system32\spoolvc.exe
Last edited by vishesh; Feb 28th, 2007 at 6:06 am.
Reply With Quote Quick reply to this message  
Reply

This thread is more than three months old.
Perhaps start a new thread instead?
Message:



Similar Threads
Other Threads in the Viruses, Spyware and other Nasties Forum
Thread Tools Search this Thread



About Us | Contact Us | Advertise | DaniWeb | Acceptable Use Policy | RSS Feed

©2003 - 2009 DaniWeb® LLC