Malware and Virus RemovalProblems removing malware/viruses? Get help from our Malware removal experts.
Mission Statement
WindowsBBS is an online community dedicated to easily accessible technical support for those using Microsoft operating systems and other Windows software.
Our goal is to become the leading resource for computer users that require assistance with their day-to-day computer usage, including full support for networking PC's, virus & malware removal, system upgrades and general support questions.
Hi, I'm new here. And my knowledge of computer also is basic. English is my third language, so I want to apology for wrong uses of words and grammar. I can't update my anti virus and cannot opened anti virus website.I've receive this virus from one of my member's flash drive. I have read many threads that have similar problem as me,and all the threads are post with savefile log. So,using Trend Micro Hijack this, I've save a log file here. My question here, what is the next thing I have to do?
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:33:16, on 4/29/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
DDS (Ver_09-03-16.01) - NTFSx86
Run by User at 15:48:02.01 on Fri 05/01/2009
Internet Explorer: 6.0.2900.2180 BrowserJavaVersion: 1.6.0_11
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.766.300 [GMT 8:00]
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_09-03-16.01)
Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 9/3/2008 01:36:48
System Uptime: 5/1/2009 15:01:05 (0 hours ago)
Motherboard: Acer, Inc. | | Grasmoor
Processor: AMD Turion(tm) X2 Dual-Core Mobile RM-70 | Socket M2/S1G1 | 2000/133mhz
Processor: AMD Turion(tm) X2 Dual-Core Mobile RM-70 | Socket M2/S1G1 | 2000/133mhz
==== Disk Partitions =========================
C: is FIXED (NTFS) - 51 GiB total, 41.484 GiB free.
D: is FIXED (NTFS) - 98 GiB total, 80.323 GiB free.
E: is CDROM ()
F: is CDROM ()
G: is Removable
==== Disabled Device Manager Items =============
Class GUID: {EEC5AD98-8080-425F-922A-DABF3DE3F69A}
Description: DinKacak
Device ID: ROOT\WPD\0000
Manufacturer: Nokia
Name: DinKacak
PNP Device ID: ROOT\WPD\0000
Service: WUDFRd
==== System Restore Points ===================
No restore point in system.
==== Installed Programs ======================
7-Zip 4.57
ABC 3GP/MP4 Converter 3.00
Acer Crystal Eye Webcam
Acer Crystal Eye Webcam Video Class Camera
Adobe AIR
Adobe Flash Player ActiveX
Adobe Flash Player Plugin
Adobe Reader 9.1
Air Force Missions
Any Video Converter 2.7.2
Ares 2.1.0
Atheros for Acer Driver 5.3.0.67_Foxconn Installation Program
Audacity 1.2.6
Azteca
BitDefender Antivirus 2008
Canon MP160
CCleaner (remove only)
Crazy Birds
Defraggler (remove only)
Fish Tales ver 1.0
Folder Access 2.0.0 Free Version
Google Earth
Google Update Helper
Google Updater
Guitar Pro 5.2
HDAUDIO Soft Data Fax Modem with SmartCP
HijackThis 2.0.2
Hotfix for Windows XP (KB915865)
Java(TM) 6 Update 11
Jigsaw Puzzle Mania
K-Lite Mega Codec Pack 4.0.0
Launch Manager
Linguist
Magic Jigsaw
Microsoft .NET Framework 2.0
Microsoft .NET Framework 3.0
Microsoft Games for Windows - LIVE Redistributable
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office Professional Edition 2003
Microsoft User-Mode Driver Framework Feature Pack 1.5
Microsoft Visual C++ 2005 Redistributable
Mini Golf Pro
Mozilla Firefox (3.0.10)
MSVC80_x86
MSXML 4.0 SP2 Parser and SDK
MSXML 6.0 Parser (KB925673)
Mummy's Curse
MyPlayCity Toolbar
Nero 7 Premium
Nokia Connectivity Cable Driver
Nokia PC Suite
NVIDIA Drivers
Orbit Downloader
PC Connectivity Solution
PhotoScape
Pirates: Battle for the Caribbean
Pos Free Photo Editor
PowerDVD
RadarSync
Rainbow Web 2
Real Backgammon
Real Checkers
Real Chess
Real Dominoes
Realtek High Definition Audio Driver
Shark Attack
SodaBush Windowpaper XP v1.01
Software Update for Web Folders
Spyware Terminator
Synaptics Pointing Device Driver
VBA (3821b)
WallMaster
WIDCOMM Bluetooth Software
Winamp
Windows Communication Foundation
Windows Driver Package - Nokia Modem (10/27/2008 3.9)
Windows Driver Package - Nokia Modem (10/27/2008 7.01.0.1)
Windows Driver Package - Nokia pccsmcfd (08/22/2008 7.0.0.0)
Windows Imaging Component
Windows Installer 3.1 (KB893803)
Windows Media Format Runtime
Windows Presentation Foundation
Windows Workflow Foundation
WinRAR archiver
Xbox 360 Controller for Windows
XML Paper Specification Shared Components Pack 1.0
Yahoo! Browser Services
Yahoo! Install Manager
Yahoo! Internet Mail
Yahoo! Messenger
Yahoo! Toolbar
Yahoo! Widgets
==== Event Viewer Messages From Past Week ========
4/27/2009 11:33:29, error: Service Control Manager [7023] - The Installer Server service terminated with the following error: A dynamic link library (DLL) initialization routine failed.
4/27/2009 11:32:18, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service BITS with arguments "" in order to run the server: {4991D34B-80A1-4291-83B6-3328366B9097}
4/27/2009 05:58:06, error: Service Control Manager [7000] - The bdfsfltr service failed to start due to the following error: The system cannot find the file specified.
At the end of this post will be an attachment I want you to download to your desktop first to run and follow the instructions for it's use.
Download Flash_Disinfector.exe by sUBs from >here<
or from >here< and save it to your desktop.
Double-click Flash_Disinfector.exe to run it and follow any prompts that may appear.
The utility may ask you to insert your flash drive and/or other removable drives including your mobile phone. Please do so and allow the utility to clean up those drives as well.
Your desktop will vanish for a while, and then reappear. This is normal.
Wait until it has finished scanning and then exit the program. If you use more than 1 flash drive, run the tool with each plugged in.
Reboot your computer when done.
Note: Flash_Disinfector will create a hidden folder named autorun.inf in each partition and every USB drive plugged in when you ran it. Don't delete this folder...it will help protect your drives from future infection.
Please leave the flash drive plugged in while completing the following.
Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools.
Quote:
BIT DEFENDER
Move mouse arrow to the Bitdefender icon in the bottom right of the desktop. (The little pictures in the lower right corner. When the arrow is placed on the little picture, a caption appears that tells what it is.)
Double click the icon for Bit Defender.
When the Bit Defender window appears, move mouse arrow to the left side and click >> Virus Shield.
Move mouse arrow to the black check by Virus Shield is enabled and click.
The black works will change to red, >> Virus Shield is disabled.
Move mouse arrow to the top right corner and click the down arrows.
Bit Defender is now inactive.
To enable Bit Defender, do the same steps except click to enable.
Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : Protective Programs
Double click on worksnow & follow the prompts.
Note:worksnow will run without the Recovery Console installed.
As part of it's process, combofix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
"copy/paste" a new HijackThis log file into this thread as well.
Notes:
1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you -- please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Give it atleast 20-30 minutes to finish if needed.