1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Virus-something taking over the whole system

Discussion in 'Malware and Virus Removal Archive' started by Sangofe, 2008/09/11.

  1. 2008/09/11
    Sangofe

    Sangofe Inactive Thread Starter

    Joined:
    2008/09/11
    Messages:
    4
    Likes Received:
    0
    Ok, so I'll admit it, I was tempted and tried to download a recent version of office from mininova, and that was my biggest error ever.
    What's happened is that I cannot use my task manager, I can't do system restore, and I'm spammed all over trying to do any sort of surfing at all.
    Of course I can't access to programs from the start menu either.

    Anyway, here's the hijack log:
    PLEASE help:
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 20:28: VIRUS ALERT!, on 11.09.2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    J:\WINDOWS\System32\smss.exe
    J:\WINDOWS\system32\winlogon.exe
    J:\WINDOWS\system32\services.exe
    J:\WINDOWS\system32\lsass.exe
    J:\WINDOWS\system32\svchost.exe
    J:\WINDOWS\System32\svchost.exe
    J:\WINDOWS\system32\svchost.exe
    J:\WINDOWS\Explorer.EXE
    J:\WINDOWS\system32\spoolsv.exe
    J:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    J:\PROGRA~1\Grisoft\AVG7\avgemc.exe
    J:\WINDOWS\system32\cisvc.exe
    J:\WINDOWS\system32\nvsvc32.exe
    J:\WINDOWS\system32\oodag.exe
    J:\Program Files\CyberLink\Shared files\RichVideo.exe
    J:\WINDOWS\System32\snmp.exe
    J:\WINDOWS\system32\svchost.exe
    J:\Program Files\Viewpoint\Common\ViewpointService.exe
    J:\WINDOWS\system32\wscntfy.exe
    J:\Program Files\D-Tools\daemon.exe
    J:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
    J:\Program Files\Unlocker\UnlockerAssistant.exe
    J:\Program Files\PowerISO\PWRISOVM.EXE
    J:\WINDOWS\SOUNDMAN.EXE
    J:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe
    J:\PROGRA~1\Grisoft\AVG7\avgcc.exe
    J:\Program Files\Winamp\winampa.exe
    J:\Program Files\Java\jre1.6.0_04\bin\jusched.exe
    J:\WINDOWS\system32\rundll32.exe
    J:\WINDOWS\system32\ctfmon.exe
    J:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe
    J:\Program Files\iolo\System Mechanic Professional 6\SMSystemAnalyzer.exe
    J:\Program Files\MSN Messenger\msnmsgr.exe
    J:\Program Files\PeerCast\PeerCast.exe
    J:\Program Files\TortoiseSVN\bin\TSVNCache.exe
    J:\WINDOWS\System32\svchost.exe
    J:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
    J:\Program Files\MSN Messenger\usnsvc.exe
    J:\Program Files\Java\jre1.6.0_04\bin\jucheck.exe
    J:\WINDOWS\system32\cidaemon.exe
    J:\Program Files\Mozilla Firefox\firefox.exe
    J:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://softwarereferral.com/jump.php?wmid=6010&mid=MjI6Ojg5&lid=2
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://www.online.no/proxy.pac
    O1 - Hosts: 208.97.174.194 forum.saizen-fansubs.com
    O1 - Hosts: 208.97.173.156 www.saizen-fansubs.com
    O1 - Hosts: 208.97.173.156 saizen-fansubs.com too
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - j:\program files\google\googletoolbar1.dll
    O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - J:\PROGRA~1\FlashGet\fgiebar.dll (file missing)
    O3 - Toolbar: fqbewlna - {94E952A4-FAE1-40E5-BBE1-8199D8CF7FD0} - J:\WINDOWS\fqbewlna.dll
    O4 - HKLM\..\Run: [NeroFilterCheck] J:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [DAEMON Tools-1033] "J:\Program Files\D-Tools\daemon.exe" -lang 1033
    O4 - HKLM\..\Run: [RemoteControl] "J:\Program Files\CyberLink\PowerDVD\PDVDServ.exe "
    O4 - HKLM\..\Run: [LanguageShortcut] "J:\Program Files\CyberLink\PowerDVD\Language\Language.exe "
    O4 - HKLM\..\Run: [UnlockerAssistant] "J:\Program Files\Unlocker\UnlockerAssistant.exe "
    O4 - HKLM\..\Run: [PWRISOVM.EXE] "J:\Program Files\PowerISO\PWRISOVM.EXE "
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE J:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [NVMixerTray] "J:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe "
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [AVG7_CC] J:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE J:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [WinampAgent] "J:\Program Files\Winamp\winampa.exe "
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "J:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe "
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "J:\Program Files\Java\jre1.6.0_04\bin\jusched.exe "
    O4 - HKLM\..\Run: [gcasServ] "J:\Program Files\Microsoft AntiSpyware\gcasServ.exe "
    O4 - HKLM\..\Run: [dcb62926] rundll32.exe "J:\WINDOWS\system32\ojdsjyse.dll ",b
    O4 - HKLM\..\RunServices: [MSN] mssnmsgr.exe
    O4 - HKCU\..\Run: [ctfmon.exe] J:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "J:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe "
    O4 - HKCU\..\Run: [SMSystemAnalyzer] "J:\Program Files\iolo\System Mechanic Professional 6\SMSystemAnalyzer.exe "
    O4 - HKCU\..\Run: [msnmsgr] "J:\Program Files\MSN Messenger\msnmsgr.exe" /background
    O4 - HKCU\..\Run: [Skype] "J:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
    O4 - HKCU\..\Run: [Telio Phone Client] "J:\Program Files\Telio Phone\TelioPhone.exe "
    O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] J:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] J:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] J:\WINDOWS\system32\ctfmon.exe (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [ctfmon.exe] J:\WINDOWS\system32\ctfmon.exe (User 'Default user')
    O4 - Startup: PeerCast.lnk = J:\Program Files\PeerCast\PeerCast.exe
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
    O8 - Extra context menu item: &Google Search - res://J:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
    O8 - Extra context menu item: &Translate English Word - res://J:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
    O8 - Extra context menu item: Backward Links - res://J:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
    O8 - Extra context menu item: Cached Snapshot of Page - res://J:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
    O8 - Extra context menu item: Last ned alle med FlashGet - J:\Program Files\FlashGet\jc_all.htm
    O8 - Extra context menu item: Last ned med FlashGet - J:\Program Files\FlashGet\jc_link.htm
    O8 - Extra context menu item: Similar Pages - res://J:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
    O8 - Extra context menu item: Translate Page into English - res://J:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - J:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - J:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
    O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - J:\PROGRA~1\FlashGet\flashget.exe (file missing)
    O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - J:\PROGRA~1\FlashGet\flashget.exe (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - J:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - J:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{91F04DFF-03B2-4D19-B05C-23B60CA56C30}: NameServer = 208.67.220.220,208.67.222.222
    O17 - HKLM\System\CCS\Services\Tcpip\..\{E54DE78F-C3BD-410B-A509-2EF704E37873}: NameServer = 208.67.220.220,208.67.222.222
    O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
    O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - J:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
    O20 - AppInit_DLLs: gtqgbv.dll
    O21 - SSODL: mgxfebsq - {7FC5BE4A-08CA-4D5B-A80B-A002CD2D0AA1} - J:\WINDOWS\mgxfebsq.dll
    O21 - SSODL: dtseqrxk - {5A301F42-12ED-4042-B8F6-1687D6CFD790} - J:\WINDOWS\dtseqrxk.dll
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - J:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - J:\PROGRA~1\Grisoft\AVG7\avgemc.exe
    O23 - Service: MSDOCFILE - Unknown owner - C:\RECYCLER\pri008\Service.exe
    O23 - Service: MSErrorloger - Unknown owner - C:\RECYCLER\pri008\Service.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - J:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: O&O Defrag - O&O Software GmbH - J:\WINDOWS\system32\oodag.exe
    O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - J:\Program Files\CyberLink\Shared files\RichVideo.exe
    O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - J:\Program Files\WinPcap\rpcapd.exe
    O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - J:\Program Files\Viewpoint\Common\ViewpointService.exe
    O24 - Desktop Component 0: Privacy Protection - file:///J:\WINDOWS\privacy_danger\index.htm

    --
    End of file - 9045 bytes
     
  2. 2008/09/11
    Sangofe

    Sangofe Inactive Thread Starter

    Joined:
    2008/09/11
    Messages:
    4
    Likes Received:
    0
    Nobody that can help? I really need to use my pc for school related work this weekend...
     

  3. to hide this advert.

  4. 2008/09/12
    MitchellCooley Lifetime Subscription

    MitchellCooley Inactive

    Joined:
    2006/12/02
    Messages:
    1,090
    Likes Received:
    20
    I know it can be frustrating, but please be patient. Someone will be along to help you soon. They are all volunteers and do this in their spare time.

    I did google these items:

    O3 - Toolbar: fqbewlna - {94E952A4-FAE1-40E5-BBE1-8199D8CF7FD0} - J:\WINDOWS\fqbewlna.dll
    O21 - SSODL: mgxfebsq - {7FC5BE4A-08CA-4D5B-A80B-A002CD2D0AA1} - J:\WINDOWS\mgxfebsq.dll
    O21 - SSODL: dtseqrxk - {5A301F42-12ED-4042-B8F6-1687D6CFD790} - J:\WINDOWS\dtseqrxk.dll

    and they appear to be problematic files. Mind you, i am no expert, not even a novice at virus/spyware removal - just thought they looked suspicious.

    Mitch
     
    Last edited: 2008/09/12
  5. 2008/09/12
    Sangofe

    Sangofe Inactive Thread Starter

    Joined:
    2008/09/11
    Messages:
    4
    Likes Received:
    0
    Thanks for your answer. I am aware it was a selfish demand to ask for replies so fast, but I'm in a kind of pressed situation. I'll see if I can find some other computer I can work from.

    As for those that are curious, I can tell that Windows Ultimate Boot CD did not boot either, so that possibility's gone too.
    Trying to disable the drive my current windows is on now, to have a fresh windows installation on another drive, so that I can boot up a healthy windows and wipe the infected partition...
     
  6. 2008/09/12
    MitchellCooley Lifetime Subscription

    MitchellCooley Inactive

    Joined:
    2006/12/02
    Messages:
    1,090
    Likes Received:
    20
    I don't think I'd wipe it quite yet. Give the experts here a chance to help you clean it up. It's much easier to clean it up than to lose data.

    Mitch
     
  7. 2008/09/13
    Sangofe

    Sangofe Inactive Thread Starter

    Joined:
    2008/09/11
    Messages:
    4
    Likes Received:
    0
    Maybe so, but I don't have the time waiting because my "paper" is due on monday so I did format one parition, and managed to get "NTDLR is missing" probably due to I just cutting power when windows setup did not want to load files from HDD (the virus seemed to stop any cd`s from loading after a fresh or re-start). So now I am left with the only option of formatting the system drive from another PC, which I am currently in progress of doing. This thread can be locked, unless there are people who have had similar problems.
     
  8. 2008/09/24
    TRICKYMUZZA

    TRICKYMUZZA Inactive

    Joined:
    2008/09/24
    Messages:
    3
    Likes Received:
    0
    i am having the exact same problem i tried to D/L an Antivirus and it seemed all normal then the computer froze i turned it off then on and everything was different next to the time it said virus alert the background was diff with all sorts of spam on it and i didnt have n e of my programs i went to my computer and my C:/ Drive wasnt there i really need the computer for school work if there is any help it would be much appreshiated also if u need anything ask :)
     
  9. 2008/09/24
    MitchellCooley Lifetime Subscription

    MitchellCooley Inactive

    Joined:
    2006/12/02
    Messages:
    1,090
    Likes Received:
    20
    Trickmuzza,

    Refer to this post http://www.windowsbbs.com/malware-virus-removal/announcements.html and post the logs requested in a NEW thread.

    Mitch
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.