| | #1 | ||
| (I Love Brackets) | virus Right i had this on my comp at home and now someone has it on a laptop at work i had to run a fix in safe mode but cant find it now. any ideas ![]() (running scans wiv avg spybot and all that doesnt sort it ![]() | ||
| |
|
| | #3 | ||
| (I Love Brackets) | Re: virus found my original way of doing it ![]() http://www.precisesecurity.com/tools.../smitfraudfix/ thank you anyway Stu | ||
| |
|
| | #4 | ||
| doM repuS | Re: virus Sorted then
__________________ Electroclash Panda 100HP ![]() Red brake calipers - done / Red highlights on engine cover - done Red GSR kit - done / Red badges - done / Cobra springs - done ![]() ![]() | ||
| |
|
| | #5 | ||
| (I Love Brackets) | Re: virus | ||
| |
|
| | #6 | ||
| (I Love Brackets) | Re: virus my fix didnt work. looked at the 1 you linked and am bit confused do i have to find all these file locations and fix it with Hijack this? | ||
| |
|
| | #7 | ||
| doM repuS | Re: virus Post up your Hijack this log then
__________________ Electroclash Panda 100HP ![]() Red brake calipers - done / Red highlights on engine cover - done Red GSR kit - done / Red badges - done / Cobra springs - done ![]() ![]() | ||
| |
|
| | #8 | ||
| (I Love Brackets) | Re: virus | ||
| |
|
| | #9 | ||
| (I Love Brackets) | Re: virus Logfile of HijackThis v1.97.7 Scan saved at 14:02:40, on 25/04/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16640) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Symantec AntiVirus\DefWatch.exe C:\Program Files\Intel\Wireless\Bin\EvtEng.exe C:\WINDOWS\system32\NMSSvc.exe C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe C:\Program Files\CheckPoint\SecuRemote\bin\SR_Service.exe C:\Program Files\CheckPoint\SecuRemote\bin\SR_WatchDog.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Symantec AntiVirus\Rtvscan.exe C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe C:\Program Files\Sony\VAIO Event Service\VESMgr.exe C:\Program Files\RealVNC\VNC4\WinVNC4.exe C:\WINDOWS\Explorer.EXE C:\Program Files\CheckPoint\SecuRemote\bin\SR_GUI.Exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Sony\ISB Utility\ISBMgr.exe C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe C:\Program Files\Protector Suite QL\psqltray.exe C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\PROGRA~1\SYMANT~1\VPTray.exe C:\Program Files\iTunes\iTunesHelper.exe C:\WINDOWS\system32\rundll32.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe C:\Program Files\Panasonic\LUMIXSimpleViewer\PhLeAutoRun.exe C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe C:\Program Files\iPod\bin\iPodService.exe E:\6. HijackThis 1.97.7.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://softwarereferral.com/jump.php...MjI6Ojg5&lid=2 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Virgin.net R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = 127.0.0.1 O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {3CAB59B4-55A3-4737-9FD5-B93C6430BF75} - C:\WINDOWS\system32\ttmvansi.dll O2 - BHO: (no name) - {51B0C2F6-3CB6-450A-ABF1-E60646D00F5E} - C:\WINDOWS\system32\ssqNFYQj.dll O2 - BHO: (no name) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll O2 - BHO: (no name) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\s wg.dll O2 - BHO: (no name) - {C3F37ECA-A8D9-4633-92C6-FE24C7D16ABA} - C:\WINDOWS\system32\urqNDUkj.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll O4 - HKLM\..\Run: [ISBMgr.exe] "C:\Program Files\Sony\ISB Utility\ISBMgr.exe" O4 - HKLM\..\Run: [PSQLLauncher] "C:\Program Files\Protector Suite QL\launcher.exe" /startup O4 - HKLM\..\Run: [VAIOCameraUtility] "C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe" O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [70f4e57c] rundll32.exe "C:\WINDOWS\system32\wevurxru.dll",b O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe O4 - HKCU\..\Run: [VirusIsolator.exe] C:\Program Files\VirusIsolator\VirusIsolator.exe O4 - Global Startup: Bluetooth Manager.lnk = ? O4 - Global Startup: hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe O4 - Global Startup: Intranet.lnk = C:\Program Files\Internet Explorer\iexplore.exe O4 - Global Startup: LUMIX Simple Viewer.lnk = ? O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE O4 - Global Startup: Symantec Fax Starter Edition Port.lnk = C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM) O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 (HKLM) O9 - Extra button: Messenger (HKLM) O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM) O11 - Options group: [INTERNATIONAL] International* O14 - IERESET.INF: START_PAGE_URL=http://www.virgin.net O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/s...sh/swflash.cab O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = allsop.co.uk O17 - HKLM\Software\..\Telephony: DomainName = allsop.co.uk O17 - HKLM\System\CCS\Services\Tcpip\..\{039765EE-AE18-4A51-981C-B380127CF699}: Domain = allsop.co.uk O17 - HKLM\System\CCS\Services\Tcpip\..\{039765EE-AE18-4A51-981C-B380127CF699}: NameServer = 192.168.10.24,192.168.11.3,192.168.12.4 Last edited by Mikeee : 25-04-2008 at 13:12. | ||
| |
|
| | #10 | ||
| (I Love Brackets) | Re: virus shall i just "fix" anything that seems suspicious? | ||
| |
|
| | #11 | ||
| doM repuS | Re: virus Looks like guy used Hijackthis and SuperAntiSpyware Scan No idea what combo fix is though ha.
__________________ Electroclash Panda 100HP ![]() Red brake calipers - done / Red highlights on engine cover - done Red GSR kit - done / Red badges - done / Cobra springs - done ![]() ![]() | ||
| |
|
| | #12 | |||
| The modfather | ![]()
__________________ Gone fishing | |||
| |
|
| | #13 | ||
| doM repuS | Re: virus Is that the end of the log?
__________________ Electroclash Panda 100HP ![]() Red brake calipers - done / Red highlights on engine cover - done Red GSR kit - done / Red badges - done / Cobra springs - done ![]() ![]() | ||
| |
|
| | #14 | ||
| (I Love Brackets) | Re: virus | ||
| |
|
| | #15 | ||
| doM repuS | Re: virus So why no 'end of file' - forum has a character limit.
__________________ Electroclash Panda 100HP ![]() Red brake calipers - done / Red highlights on engine cover - done Red GSR kit - done / Red badges - done / Cobra springs - done ![]() ![]() | ||
| |
|
![]() |
| Tags: virus |
| Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | |
| Thread Tools | Search this Thread |
|
|
Similar Threads | ||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| think i have a computer virus already | stilosporting | Computing | 11 | 21-09-2007 16:57 |
| best anti virus | chris_gray21 | Computing | 19 | 20-01-2007 17:53 |
| virus- help!! | beau | Leisure Lounge | 6 | 10-11-2006 20:58 |
| PC Virus, who knows about them? | Steven | Computing | 24 | 08-02-2006 20:45 |
| Virus checker? | black_cinq | Leisure Lounge | 51 | 10-12-2004 23:41 |