Jump to content

Recommended Posts

Posted

Hi guys i recently got the internet security 2010 virus i used rkill.exe and mbam.exe to remove this horendous infliction i have also used spybot s&d and a few other in a bid to get rid of it i think i have removed the internet security 2010 but im left with a totaly hijacked browser my pc is really laggin hard sometimes ive been stuck with this for days now plz help i will include my hijack this log and an uninstal log ok hurry guys im pulling my hair out im also considering getting a knew hard drive i feel ive tried everything

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 14:43:43, on 19/01/2010

Platform: Windows Vista SP2 (WinNT 6.00.1906)

MSIE: Internet Explorer v7.00 (7.00.6002.18005)

Boot mode: Normal

Running processes:

C:\Windows\system32\Dwm.exe

C:\Windows\Explorer.EXE

C:\Windows\system32\taskeng.exe

C:\Program Files\AVG\AVG8\avgtray.exe

C:\Windows\RtHDVCpl.exe

C:\Program Files\Java\jre6\bin\jusched.exe

C:\Windows\ehome\ehtray.exe

C:\Users\aaron\Desktop\Spybot - Search & Destroy\TeaTimer.exe

C:\Program Files\Windows Media Player\wmpnscfg.exe

C:\Windows\ehome\ehmsas.exe

C:\Users\aaron\Desktop\Spybot - Search & Destroy\SpybotSD.exe

C:\Program Files\Internet Explorer\ieuser.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\Program Files\Windows Live\Toolbar\wltuser.exe

C:\Windows\system32\Macromed\Flash\FlashUtil10c.exe

C:\Windows\system32\taskeng.exe

C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Bing

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Google

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = Hotmail, Messenger, Unterhaltung, Nachrichten, Sport, Jobs, Immobilien und mehr bei MSN AT

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = Games Fusion - PC Cheats, Saved Games, Trailers, Demos and Patches

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

F2 - REG:system.ini: UserInit=C:\Windows\system32\userinit.exe,C:\Users\aaron\AppData\Roaming\sdra64.exe,

O1 - Hosts: ::1 localhost

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Users\aaron\Desktop\SPYBOT~1\SDHelper.dll

O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)

O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll

O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll

O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll

O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"

O4 - HKLM\..\Run: [Video Accelerator] "C:\Program Files\Leawo\Video Accelerator\VideoAccelerator.exe" -auto

O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe

O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background

O4 - HKCU\..\Run: [u*******] "C:\Program Files\u*******\u*******.exe"

O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe

O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Users\aaron\Desktop\Spybot - Search & Destroy\TeaTimer.exe

O4 - HKCU\..\Run: [userinit] C:\Users\aaron\AppData\Roaming\sdra64.exe

O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'NETWORK SERVICE')

O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll

O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll

O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Users\aaron\Desktop\SPYBOT~1\SDHelper.dll

O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Users\aaron\Desktop\SPYBOT~1\SDHelper.dll

O16 - DPF: {138E6DC9-722B-4F4B-B09D-95D191869696} (Bebo Uploader Control) - http://www.bebo.com/files/BeboUploader.5.1.4.cab

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1257773195876

O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} - http://launch.gamespyarcade.com/software/launch/alaunch.cab

O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://icq.oberon-media.com/Gameshell/GameHost/1.0/OberonGameHost.cab

O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll

O20 - AppInit_DLLs: avgrsstx.dll

O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe

O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe

O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

O23 - Service: Google Update Service (gupdate1c9da1a8b3f465b) (gupdate1c9da1a8b3f465b) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe

O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\Windows\system32\GameMon.des.exe (file missing)

O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe

O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Users\aaron\Desktop\Spybot - Search & Destroy\SDWinSec.exe

--

End of file - 6790 bytes

 

and heres my uninstal list A.V.A

Acrobat.com

Actua Ice Hockey 2

Adobe AIR

Adobe AIR

Adobe Flash Player 10 ActiveX

Adobe Flash Player 10 Plugin

Adobe Reader 9.1

Adobe Shockwave Player 11.5

Advanced SystemCare 3

Apple Application Support

Apple Mobile Device Support

Apple Software Update

AVG 8.0

AviSynth 2.5

AVS Update Manager 1.0

AVS Video Converter 6

AVS4YOU Software Navigator 1.3

Bonjour

Championship Boxing

Cross Fire En

DivX Codec

DivX Converter

DivX Player

DivX Plus DirectShow Filters

DivX Plus Web Player

DVD Flick 1.3.0.7

Game Booster

Google Earth

Google Update Helper

HDReg

HijackThis 2.0.2

Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)

Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)

iTunes

Java 6 Update 17

Junk Mail filter update

K-Lite Codec Pack 5.5.1 (Full)

Leawo Free Video Accelerator Version: 3.0.1.0

******** PRO 5.0.11

Microsoft .NET Framework 3.5 SP1

Microsoft Choice Guard

Microsoft Search Enhancement Pack

Microsoft Silverlight

Microsoft SQL Server 2005 Compact Edition [ENU]

Microsoft Sync Framework Runtime Native v1.0 (x86)

Microsoft Sync Framework Services Native v1.0 (x86)

Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053

Microsoft Visual C++ 2005 Redistributable

Microsoft Visual C++ 2005 Redistributable

Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148

Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022

Microsoft Visual C++ Run Time Lib Setup

Mozilla Firefox (3.5.3)

MSVCRT

MSXML 4.0 SP2 (KB954430)

MSXML 4.0 SP2 (KB973688)

MSXML 4.0 SP2 P****r and SDK

NVIDIA Drivers

Photo Gadget Pro

Photo Gadget Viewer

PVSonyDll

QuickTime

Realtek HD Audio V6.0.1.5618

Realtek High Definition Audio Driver

Spybot - Search & Destroy

The Incredibles - When Danger Calls

Total Uninstall 5.4.2

Ultimate Extras sounds from Microsoft® Tinker™

Update for Microsoft .NET Framework 3.5 SP1 (KB963707)

VC80CRTRedist - 8.0.50727.4053

Ventrilo Client

Ventrilo Server

Video NVIDIA V163.96

Videora iPod nano Converter 4.06

Windows Live Call

Windows Live Communications Platform

Windows Live Essentials

Windows Live Essentials

Windows Live Mail

Windows Live Messenger

Windows Live Movie Maker

Windows Live Photo Gallery

Windows Live Sign-in Assistant

Windows Live Sync

Windows Live Toolbar

Windows Live Upload Tool

Windows Live Writer

Windows Sound Schemes

WinRAR archiver

World Championship Pool 2004

 

ty guys

  • Replies 5
  • Created
  • Last Reply

Top Posters In This Topic

Popular Days

Top Posters In This Topic

Posted

Hello and welcome.

 

Well we can see your problems stem from using torrented program software I see a few listed.

 

Could you uninstall them and then we can help you further.If we help you clean the infection and you still use these programs we are basicaly wasting our time.You will just reinfect yourself over and over again.

Rwy'n ceisio fy ngorau......................
Posted

Your computer appears to be infected with Malware. Malware is software designed to infiltrate or damage a computer system without the owner's informed consent. It is a combination of the words malicious and software. The expression is a general term used by computer professionals to mean a variety of forms of hostile, intrusive, or annoying software or program code.

 

It is in your best interest to note the following:

  1. Please disable your resident security applications (such as AVG, Spybot, WinPatrol, etc.) before performing the below procedure so that they do not interfere with the process.
  2. Perform all the steps in the order listed to avoid any conflicts.
  3. If unsure, please stop and voice your doubts.
  4. You might be required to go offline during the disinfection process. Therefore, it is recommended to print off the instructions below for ease of reference.

If you stick to the above guidelines, all should go smoothly.

 

 

 

================================================

STEP 1

  1. Download ATF-Cleaner by Atribune.
  2. Save the file to your Desktop.
  3. Double-click on the file to run the program.
  4. On the Main tab, check the Select All button.
  5. Next, click on the Firefox tab (if applicable) and check the Select All button.
     
    Note: If you would like to preserve your saved passwords in Firefox, then click No at the corresponding prompt.
  6. Now, click on the Opera tab (if applicable) and check the Select All button.
     
    Note: If you would like to preserve your saved passwords in Opera, then click No at the corresponding prompt.
  7. Press the Empty Selected button and click OK to acknowledge the corresponding prompt.
  8. Click on the Exit button to quit the program.

================================================

STEP 2

  1. Please click here to download Malwarebytes' Anti-Malware.
  2. Save the file to your Desktop.
  3. Double-click mbam-setup.exe and follow the prompts to install the program.
  4. At the end, make sure a check mark is placed next to:

    1. Update Malwarebytes' Anti-Malware
    2. Launch Malwarebytes' Anti-Malware

[*]Click Finish.

[*]The program will download and update itself if it finds the necessity to do so. Please allow this.

[*]Once the program has loaded, select Perform full scan, then click Scan.

 

 

Note: Depending on your computer specifications, the scan may take some time to complete. Please wait patiently and do not interrupt the process.

[*]When the scan is complete, click OK, and then Show Results to view the results.

[*]Make sure that every entry is selected, and click Remove Selected.

[*]Restart your computer.

================================================

STEP 3

  1. Please click here to download SUPERAntiSpyware (Free Version).
  2. Save the file to your Desktop.
  3. Double-click SUPERAntiSpyware.exe and follow the prompts to install the program.
  4. Open SUPERAntiSpyware.
  5. Under Configuration and Preferences, click the Preferences button.
  6. Click the Scanning Control tab.
  7. Under Scanner Options make sure the following fields checked:

    [*]Click the Close button to leave the control center screen.

    [*]On the main screen, under Scan for Harmful Software click Scan your computer.

    [*]On the left, make sure you check mark All the Fixed Drives.

    [*]On the right, under Complete Scan, choose Perform Complete Scan.

    [*]Click Next to start the scan. Please be patient while it scans your computer.

    [*]After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click OK.

    [*]Make sure every entry has a check mark next to it and click Next.

    [*]A notification will appear that Quarantine and Removal is Complete. Click OK and then Finish to return to the main menu.

    [*]Restart your computer.

    ================================================

    STEP 4

    1. Please visit the ESET Online Scanner, using Internet Explorer to initiate the scan.
       
      Note: If you are running Windows Vista, then you will need Administrative privileges to complete the latter part of the procedure. To do so, right-click on the Internet Explorer icon in the Start Menu and select the Run As Administrator option in the shell context menu.
    2. Check mark the YES, I accept the Terms of Use box.
    3. Click the Start button.
    4. Click the Install button on the following screen.
    5. Click Start. This will will initialize and update the scanner engine.
    6. Check mark the box beside Remove found threats.
    7. Click the Scan button. This will start the scan. Please be patient while it is in progress.
    8. Restart your computer.

    ================================================

    STEP 5

    1. Click on Start > Programs > Accessories > System Tools and select System Restore.
    2. Choose the radio button marked Create a Restore Point on the first screen and click Next. Give the restore point a name then click Create. The new point will be stamped with the current date and time. Keep a note of this so you can find it easily should you need to use System Restore.
    3. Next, click on Start > Run, type Cleanmgr and click on OK.
    4. Click on the More Options tab.
    5. Click the Clean Up button in the System Restore section to remove all previous restore points except the most recent one.

    This will remove any infected files that have been backed up by Windows. The files in "System Restore" are protected to prevent any programs changing those files. This is the only foolproof way to ensure the deletion of those files.

     

    Note: Do not clear restore points on a regular basis as doing so will clear all previous restore points even those that you may need. System Restore is a useful tool to revert your computer back to a working condition if something goes wrong.

     

    Re-enable all your security applications and please return here and tell us how the computer seems to be operating.


Close browsers before scanning
Scan for tracking cookies
Terminate memory threats before quarantining
Rwy'n ceisio fy ngorau......................
Posted

OK so u think i have this due to utorrent or limewire i have done all the steps above many times over the past few days but to no avail i have followed all the step i have even ran combo fix there dosent seem to be any avg warnings anymore but how will i know im in the clear ?

i have uninstalled these programs u asked do u have any suggestions of safe ones i can use and can u tell me if it woz uttorent or limewire which cozed this nightmare oh btw ty for helping me i appreciate it

Posted

It could be a number of things that can cause an infection,sharware software is the usal culprit.But clicking a bad link or inserting lets say a friends infected USB pen drive or other means can cause your infections.

 

Download free version of this and tun it tell me if it comes up clean.If it dont please copy and paste results in your next post.

 

Malwarebytes.org

 

You are most welcome.

Rwy'n ceisio fy ngorau......................
Posted

ok i ran it and i got this

 

Malwarebytes' Anti-Malware 1.44

Database version: 3600

Windows 6.0.6002 Service Pack 2

Internet Explorer 7.0.6002.18005

19/01/2010 21:24:59

mbam-log-2010-01-19 (21-24-59).txt

Scan type: Quick Scan

Objects scanned: 107818

Time elapsed: 12 minute(s), 59 second(s)

Memory Processes Infected: 0

Memory Modules Infected: 0

Registry Keys Infected: 1

Registry Values Infected: 0

Registry Data Items Infected: 0

Folders Infected: 0

Files Infected: 0

Memory Processes Infected:

(No malicious items detected)

Memory Modules Infected:

(No malicious items detected)

Registry Keys Infected:

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{19127ad2-394b-70f5-c650-b97867baa1f7} (Backdoor.Bot) -> Quarantined and deleted successfully.

Registry Values Infected:

(No malicious items detected)

Registry Data Items Infected:

(No malicious items detected)

Folders Infected:

(No malicious items detected)

Files Infected:

(No malicious items detected)

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.


×
×
  • Create New...