HardwareLogic

Go Back   HardwareLogic > General Discussions > General Computing > Troubleshooting
Home Forums Rules All AlbumsBlogs Subscriptions Register Mark Forums Read

Troubleshooting Need help figuring out what went wrong? Wanna know where you screwed up?

Reply
 
LinkBack Thread Tools
Old October 3rd, 2007   #1
Fields
 
Elysium's Avatar
 
Join Date: Mar 2007
Location: Pacific Grove, CA
Posts: 4,394
Default Help with virus... Can't get rid of it!

OK, so it seems like I have a virus of some kind... It's an icon in the system tool bar (the one in the bottom right of Windows) and every so often it pops this up: AntispyGolden :: Cutting-Edge Anti-Spyware Protection <--***NOT LEGIT SITE***

I scanned my PC with AVG's scanner, SpyBot S&D, and with HijackThis!, And both AVG and SpyBot detected something bad, but they couldn't get rid of it. Here's the log from HijackThis!:

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Online Image Add-on\icthis.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Online Image Add-on\icmntr.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\OpenOffice.org 2.3\program\soffice.exe
C:\Program Files\OpenOffice.org 2.3\program\soffice.BIN
C:\Program Files\iPod\bin\iPodService.exe
C:\Documents and Settings\yellowhello\Desktop\Core Temp.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\yellowhello\Desktop\HiJackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Live Search
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Live Search
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = MSN.com
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKLM\..\Policies\Explorer\Run: [some] C:\Program Files\Online Image Add-on\icthis.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Startup: OpenOffice.org 2.3.lnk = C:\Program Files\OpenOffice.org 2.3\program\quickstart.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsu...?1189286829234
O22 - SharedTaskScheduler: hydria - {79cdca21-5055-4cae-b609-e1685ef55cf7} - C:\WINDOWS\system32\hymww.dll (file missing)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

...So I need to know how to get rid of this annoying thing!

Any help appreciated!

-Nate



E8400
DFI Blood Iron P35-T2RL
4GB G.Skill 800MHz
Sapphire Radeon HD3870 512MB
Silverstone DA650W
WD 250GB + Seagate 320GB
Elysium is offline   Reply With Quote
Old October 3rd, 2007   #2
Modder-ator
 
gvblake22's Avatar
 
Join Date: Dec 2005
Location: Tempe Desert
Posts: 6,474
Blog Entries: 1
Default Re: Help with virus... Can't get rid of it!

What is the "something bad" that Spybot and AVG's scanner detected? If it gave you a filename, you can just do a search on your machine for that file and try and delete it yourself. I've found it is better to remove these files in Safe Mode (especially if it is a worm).



gvblake22 is offline   Reply With Quote
Old October 3rd, 2007   #3
With a pinch of insane!
 
qazwsx's Avatar
 
Join Date: Apr 2007
Location: England, 127.0.0.1
Posts: 643
Default Re: Help with virus... Can't get rid of it!

I looked through and did some research and found
O4 - HKLM\..\Policies\Explorer\Run: [some] C:\Program Files\Online Image Add-on\icthis.exe

I think thats the guilty exe




qazwsx is online now   Reply With Quote
Old October 3rd, 2007   #4
ako the pinoy
 
halutzparilla's Avatar
 
Join Date: Jul 2006
Location: by the beach
Posts: 1,698
Default Re: Help with virus... Can't get rid of it!

check you control panel add/remove program if its installed there uninstall it and check
C:\WINDOWS\system32\drivers\etc\, use a text editor to remove the following entries from the hosts file that is related to this *.exe / file ...



Abit IP35-E
C2D E6750 G0 @ 2.66ghz [TR Ultra120EX]
EVAG 8800GTS [TR HR03]
Corsair [2gbDual@800]
820GB HDD[120/200/500]
Antec TP 550W
Silverstone Temjin 09
Saitek Eclipse1 & Razer DeathAdder
Windows Vista Ultimate 32bit
halutzparilla is offline   Reply With Quote
Old October 3rd, 2007   #5
I don't know how to put this, but, I'm kind of a big deal.
 
One4yu2c's Avatar
 
Join Date: Jan 2006
Location: Land of the Lounge Lizards
Posts: 2,725
Blog Entries: 3
Default Re: Help with virus... Can't get rid of it!

Safe mode, safe mode, safe mode.

For your HiJackThis log, there are some handy online auto-analyzers, including THIS ONE. IN short:

C:\Program Files\Online Image Add-on\icthis.exe
C:\Program Files\Online Image Add-on\icmntr.exe
O4 - HKLM\..\Policies\Explorer\Run: [some] C:\Program Files\Online Image Add-on\icthis.exe



One4yu2c is offline   Reply With Quote
Old October 3rd, 2007   #6
 
Join Date: Jul 2007
Location: Oregon, USA
Posts: 80
Default Re: Help with virus... Can't get rid of it!

Yeah definitely if your going to remove it do it in Safe Mode. Once you find out exactly what the virus is called Google it and see what they say about removing it. Seems to work for me every time.



C2D E8400 3.0GHz
Gigabyte GA-P35-DS3L Rev.2
Samsung 20x Burner
Samsung 500GB

Seagate 160GB
ASUS HD 3870 512mb

4GB Corsair XMS2 DDR2 800 mhz
PC Power and Cooling Silencer 610w
Samsung 226BW 22"

insomnia is online now   Reply With Quote
Old October 3rd, 2007   #7
T-Rex
 
polobunny's Avatar
 
Join Date: May 2006
Posts: 5,058
Blog Entries: 6
Default Re: Help with virus... Can't get rid of it!

Download SmitfraudFix
http://siri.urz.free.fr/Fix/SmitfraudFix.exe

Reboot into safe mode and follow instructions.



polobunny is online now   Reply With Quote
Old October 3rd, 2007   #8
Fields
 
Elysium's Avatar
 
Join Date: Mar 2007
Location: Pacific Grove, CA
Posts: 4,394
Default Re: Help with virus... Can't get rid of it!

Quote:
Originally Posted by gvblake22 View Post
What is the "something bad" that Spybot and AVG's scanner detected? If it gave you a filename, you can just do a search on your machine for that file and try and delete it yourself. I've found it is better to remove these files in Safe Mode (especially if it is a worm).
Well, thats just it, they tell me the name of them (and the location) but when I go to manually delete them they're not where AVG or SpyBot says they are... Strange, huh?

...I'll try in Safe Mode and report back.



E8400
DFI Blood Iron P35-T2RL
4GB G.Skill 800MHz
Sapphire Radeon HD3870 512MB
Silverstone DA650W
WD 250GB + Seagate 320GB
Elysium is offline   Reply With Quote
Old October 3rd, 2007   #9
Fields
 
Elysium's Avatar
 
Join Date: Mar 2007
Location: Pacific Grove, CA
Posts: 4,394
Default Re: Help with virus... Can't get rid of it!

OK, so I'm pretty sure I fixed it... I booted into Windows in Safe Mode and manually deleted the files that One4 said were the problem and I haven't gotten a pop-up in the last few minutes (usually a pop-up would have popped-up by now) so I think I can safely say this virus is busted.

Thanks all who contributed to this thread and helped me with my problem.



E8400
DFI Blood Iron P35-T2RL
4GB G.Skill 800MHz
Sapphire Radeon HD3870 512MB
Silverstone DA650W
WD 250GB + Seagate 320GB
Elysium is offline   Reply With Quote
Old October 3rd, 2007   #10
I don't know how to put this, but, I'm kind of a big deal.
 
One4yu2c's Avatar
 
Join Date: Jan 2006
Location: Land of the Lounge Lizards
Posts: 2,725
Blog Entries: 3
Default Re: Help with virus... Can't get rid of it!

Run your virus and spyware scans in safe mode too, just in case there are any hidden remnants lurking around.



One4yu2c is offline   Reply With Quote
Reply

  HardwareLogic > General Discussions > General Computing > Troubleshooting

Tags
rid, virus


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
UPS Virus Warning!!! stinger608 HL Lounge 5 July 24th, 2008 06:37
VIRUS in old PC no boot oldman_gamer HL Lounge 21 January 5th, 2008 14:27
virus? manisare Troubleshooting 1 August 22nd, 2007 15:53
Virus Help! manisare Troubleshooting 2 August 17th, 2007 14:22
The Joseph Virus Hitman HL Lounge 6 November 6th, 2006 16:57


All times are GMT -8. The time now is 02:35.


Powered by vBulletin® Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0
© HardwareLogic 2005 - 2008. All Rights Reserved


1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52