The FIAT Forum

Go Back   The FIAT Forum > General > Leisure Lounge > Computing


Reply
 
Thread Tools Search this Thread
Old 25-04-2008   #1
(I Love Brackets)
 
Mikeee's Avatar
 
Join Date: Oct 2007
Posts: 3,732
Thanks: 166
Trader Rating: (0)
Mikeee has donated! United Kingdom 
virus

Right i had this on my comp at home and now someone has it on a laptop at work i had to run a fix in safe mode but cant find it now.

any ideas

(running scans wiv avg spybot and all that doesnt sort it please dnt tell me to do this.)

__________________
Mikeee is offline  
Reply With Quote
Old 25-04-2008   #2
doM repuS
 
Stu DemonD's Avatar
 
Join Date: Sep 2003
Location: N/A :p
Posts: 16,289
Thanks: 130
Trader Rating: (1)
Stu DemonD has donated! United Kingdom 
Re: virus

__________________
Electroclash Panda 100HP
Red brake calipers - done / Red highlights on engine cover - done
Red GSR kit - done / Red badges - done / Cobra springs - done
Stu DemonD is offline  
Reply With Quote
The following user says "Thank You!" to Stu DemonD for this useful post:
Mikeee (25-04-2008)
Old 25-04-2008   #3
(I Love Brackets)
 
Mikeee's Avatar
 
Join Date: Oct 2007
Posts: 3,732
Thanks: 166
Trader Rating: (0)
Mikeee has donated! United Kingdom 
Re: virus

found my original way of doing it


http://www.precisesecurity.com/tools.../smitfraudfix/

thank you anyway Stu
__________________
Mikeee is offline  
Reply With Quote
Old 25-04-2008   #4
doM repuS
 
Stu DemonD's Avatar
 
Join Date: Sep 2003
Location: N/A :p
Posts: 16,289
Thanks: 130
Trader Rating: (1)
Stu DemonD has donated! United Kingdom 
Re: virus

Sorted then Good old Google eh
__________________
Electroclash Panda 100HP
Red brake calipers - done / Red highlights on engine cover - done
Red GSR kit - done / Red badges - done / Cobra springs - done
Stu DemonD is offline  
Reply With Quote
Old 25-04-2008   #5
(I Love Brackets)
 
Mikeee's Avatar
 
Join Date: Oct 2007
Posts: 3,732
Thanks: 166
Trader Rating: (0)
Mikeee has donated! United Kingdom 
Re: virus

Originally Posted by Stu DemonD View Post
Sorted then Good old Google eh

yeah found milions of rubbish results of newbs getting stuck


gheeeeeeey


thank you Stu (rhymes)
__________________
Mikeee is offline  
Reply With Quote
Old 25-04-2008   #6
(I Love Brackets)
 
Mikeee's Avatar
 
Join Date: Oct 2007
Posts: 3,732
Thanks: 166
Trader Rating: (0)
Mikeee has donated! United Kingdom 
Re: virus

my fix didnt work.

looked at the 1 you linked and am bit confused

do i have to find all these file locations and fix it with Hijack this?

__________________
Mikeee is offline  
Reply With Quote
Old 25-04-2008   #7
doM repuS
 
Stu DemonD's Avatar
 
Join Date: Sep 2003
Location: N/A :p
Posts: 16,289
Thanks: 130
Trader Rating: (1)
Stu DemonD has donated! United Kingdom 
Re: virus

Post up your Hijack this log then
__________________
Electroclash Panda 100HP
Red brake calipers - done / Red highlights on engine cover - done
Red GSR kit - done / Red badges - done / Cobra springs - done
Stu DemonD is offline  
Reply With Quote
Old 25-04-2008   #8
(I Love Brackets)
 
Mikeee's Avatar
 
Join Date: Oct 2007
Posts: 3,732
Thanks: 166
Trader Rating: (0)
Mikeee has donated! United Kingdom 
Re: virus

Originally Posted by Stu DemonD View Post
Post up your Hijack this log then
give me 5 mins
__________________
Mikeee is offline  
Reply With Quote
Old 25-04-2008   #9
(I Love Brackets)
 
Mikeee's Avatar
 
Join Date: Oct 2007
Posts: 3,732
Thanks: 166
Trader Rating: (0)
Mikeee has donated! United Kingdom 
Re: virus

Logfile of HijackThis v1.97.7
Scan saved at 14:02:40, on 25/04/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\WINDOWS\system32\NMSSvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\CheckPoint\SecuRemote\bin\SR_Service.exe
C:\Program Files\CheckPoint\SecuRemote\bin\SR_WatchDog.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
C:\Program Files\RealVNC\VNC4\WinVNC4.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\CheckPoint\SecuRemote\bin\SR_GUI.Exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Sony\ISB Utility\ISBMgr.exe
C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Protector Suite QL\psqltray.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe
C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
C:\Program Files\Panasonic\LUMIXSimpleViewer\PhLeAutoRun.exe
C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\Program Files\iPod\bin\iPodService.exe
E:\6. HijackThis 1.97.7.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://softwarereferral.com/jump.php...MjI6Ojg5&lid=2
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Virgin.net
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {3CAB59B4-55A3-4737-9FD5-B93C6430BF75} - C:\WINDOWS\system32\ttmvansi.dll
O2 - BHO: (no name) - {51B0C2F6-3CB6-450A-ABF1-E60646D00F5E} - C:\WINDOWS\system32\ssqNFYQj.dll
O2 - BHO: (no name) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: (no name) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\s wg.dll
O2 - BHO: (no name) - {C3F37ECA-A8D9-4633-92C6-FE24C7D16ABA} - C:\WINDOWS\system32\urqNDUkj.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [ISBMgr.exe] "C:\Program Files\Sony\ISB Utility\ISBMgr.exe"
O4 - HKLM\..\Run: [PSQLLauncher] "C:\Program Files\Protector Suite QL\launcher.exe" /startup
O4 - HKLM\..\Run: [VAIOCameraUtility] "C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [70f4e57c] rundll32.exe "C:\WINDOWS\system32\wevurxru.dll",b
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe
O4 - HKCU\..\Run: [VirusIsolator.exe] C:\Program Files\VirusIsolator\VirusIsolator.exe
O4 - Global Startup: Bluetooth Manager.lnk = ?
O4 - Global Startup: hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
O4 - Global Startup: Intranet.lnk = C:\Program Files\Internet Explorer\iexplore.exe
O4 - Global Startup: LUMIX Simple Viewer.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Symantec Fax Starter Edition Port.lnk = C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O11 - Options group: [INTERNATIONAL] International*
O14 - IERESET.INF: START_PAGE_URL=http://www.virgin.net
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/s...sh/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = allsop.co.uk
O17 - HKLM\Software\..\Telephony: DomainName = allsop.co.uk
O17 - HKLM\System\CCS\Services\Tcpip\..\{039765EE-AE18-4A51-981C-B380127CF699}: Domain = allsop.co.uk
O17 - HKLM\System\CCS\Services\Tcpip\..\{039765EE-AE18-4A51-981C-B380127CF699}: NameServer = 192.168.10.24,192.168.11.3,192.168.12.4
__________________

Last edited by Mikeee : 25-04-2008 at 13:12.
Mikeee is offline  
Reply With Quote
Old 25-04-2008   #10
(I Love Brackets)
 
Mikeee's Avatar
 
Join Date: Oct 2007
Posts: 3,732
Thanks: 166
Trader Rating: (0)
Mikeee has donated! United Kingdom 
Re: virus

shall i just "fix" anything that seems suspicious?
__________________
Mikeee is offline  
Reply With Quote
Old 25-04-2008   #11
doM repuS
 
Stu DemonD's Avatar
 
Join Date: Sep 2003
Location: N/A :p
Posts: 16,289
Thanks: 130
Trader Rating: (1)
Stu DemonD has donated! United Kingdom 
Re: virus

Looks like guy used Hijackthis and SuperAntiSpyware Scan

No idea what combo fix is though ha.
__________________
Electroclash Panda 100HP
Red brake calipers - done / Red highlights on engine cover - done
Red GSR kit - done / Red badges - done / Cobra springs - done
Stu DemonD is offline  
Reply With Quote
Old 25-04-2008   #12
PNL
The modfather
 
PNL's Avatar
 
Join Date: Nov 2005
Location: Sunny S.Wales
Posts: 11,689
Thanks: 73
Trader Rating: (0)
PNL has donated! United Kingdom 
Cool Re: virus

Originally Posted by Stu DemonD View Post
Super stoggle to the rescue..
__________________
Gone fishing
PNL is offline  
Reply With Quote
Old 25-04-2008   #13
doM repuS
 
Stu DemonD's Avatar
 
Join Date: Sep 2003
Location: N/A :p
Posts: 16,289
Thanks: 130
Trader Rating: (1)
Stu DemonD has donated! United Kingdom 
Re: virus

Is that the end of the log?
__________________
Electroclash Panda 100HP
Red brake calipers - done / Red highlights on engine cover - done
Red GSR kit - done / Red badges - done / Cobra springs - done
Stu DemonD is offline  
Reply With Quote
Old 25-04-2008   #14
(I Love Brackets)
 
Mikeee's Avatar
 
Join Date: Oct 2007
Posts: 3,732
Thanks: 166
Trader Rating: (0)
Mikeee has donated! United Kingdom 
Re: virus

Originally Posted by Stu DemonD View Post
Is that the end of the log?
yes i didnt lay a very big log
__________________
Mikeee is offline  
Reply With Quote
Old 25-04-2008   #15
doM repuS
 
Stu DemonD's Avatar
 
Join Date: Sep 2003
Location: N/A :p
Posts: 16,289
Thanks: 130
Trader Rating: (1)
Stu DemonD has donated! United Kingdom 
Re: virus

So why no 'end of file' - forum has a character limit.
__________________
Electroclash Panda 100HP
Red brake calipers - done / Red highlights on engine cover - done
Red GSR kit - done / Red badges - done / Cobra springs - done
Stu DemonD is offline  
Reply With Quote
Reply
Tags:



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
think i have a computer virus already stilosporting Computing 11 21-09-2007 16:57
best anti virus chris_gray21 Computing 19 20-01-2007 17:53
virus- help!! beau Leisure Lounge 6 10-11-2006 20:58
PC Virus, who knows about them? Steven Computing 24 08-02-2006 20:45
Virus checker? black_cinq Leisure Lounge 51 10-12-2004 23:41


All times are GMT +1. The time now is 11:12.

Copyright ©2002 - 2008 FIAT Forum
Proudly hosted by iNETFX Message Boards and Forums Directory