Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Malware / virus issues [CLOSED]


  • This topic is locked This topic is locked

#1
kkqwel

kkqwel

    Member

  • Member
  • PipPip
  • 27 posts
Well not sure how I got infected but my computer running XP Pro has been hit by something. It seems to have disabled the following Windows features, Can not run Windows in safe mode, can not start up system restore and a lot of other nasty things are happening , plaese help me get rid of this malware.

here is my Hijackthis log.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:05:05 PM, on 07/09/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
c:\windows\system32\grr.exe
C:\DOCUME~1\Karl\LOCALS~1\Temp\svchost.exe
C:\WINDOWS\system32\oodag.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe
C:\Program Files\Intel\Intel® Active Monitor\imonnt.exe
C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
C:\WINDOWS\system32\userinit.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\devldr32.exe
C:\Program Files\MSNCS\data\dpnsvrm.exe
C:\Program Files\MSNCS\data\vssvcm.exe
C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe
C:\Program Files\BitDefender\BitDefender 2008\seccenter.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FPRECKA.EXE
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FPRECKA.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\drivers\services.exe,C:\WINDOWS\system32\oembios.exe,
O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll
O4 - HKLM\..\Run: [adsnwm] C:\WINDOWS\system32\adsnwm.exe
O4 - HKLM\..\Run: [bdmreg] C:\WINDOWS\system32\bdmreg.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [EPSON Stylus Photo R280 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICKA.EXE /FU "C:\WINDOWS\TEMP\E_S19F.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [Run] "C:\Documents and Settings\Karl\Application Data\Adobe\Manager.exe"
O4 - HKCU\..\Run: [[system]] C:\WINDOWS\system32\drivers\services.exe
O4 - HKCU\..\Run: [winlogon] C:\Documents and Settings\Karl\svchost.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [[system]] C:\WINDOWS\system32\drivers\services.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [winlogon] C:\Documents and Settings\LocalService\svchost.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O15 - Trusted Zone: http://www.transcendmagazine.com
O16 - DPF: {2E12FB00-546B-4EE3-9CC2-057BF02E1C17} (Webshots Multiple Media Uploader - Container) - http://community.web...wsaxcontrol.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akama...meInstaller.exe
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onec...lscbase5036.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebo...otoUploader.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.mi...b?1188475865671
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.mi...b?1188475840046
O16 - DPF: {AE9DCB17-F804-11D2-A44A-0020182C1446} - file://D:\Resources\IntraLaunch.CAB
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.m...ash/swflash.cab
O16 - DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} (DownloadManager Control) - http://dlm.tools.aka...vex-2.2.1.6.cab
O20 - Winlogon Notify: acpie - acpie.dll (file missing)
O22 - SharedTaskScheduler: lksdfj98w3rmsekfnaui3rgfdgf - {C5BF49A2-94F3-42BD-F434-3604812C897D} - C:\WINDOWS\system32\gjm86akm34.dll (file missing)
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Capture Device Service - InterVideo Inc. - C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Greyware Registry Rearguard - Greyware Automation Products, Inc. - c:\windows\system32\grr.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Intel® Active Monitor (imonNT) - Intel Corp. - C:\Program Files\Intel\Intel® Active Monitor\imonnt.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: Network Driver Interface - Unknown owner - C:\DOCUME~1\Karl\LOCALS~1\Temp\svchost.exe
O23 - Service: O&O Defrag - O&O Software GmbH - C:\WINDOWS\system32\oodag.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Task Scheduler (Schedule) - Unknown owner - C:\WINDOWS\system32\drivers\services.exe (file missing)
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
O23 - Service: BitDefender Communicator (XCOMM) - BitDefender - C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe

--
End of file - 8134 bytes
  • 0

Advertisements


#2
fenzodahl512

fenzodahl512

  • Malware Removal
  • 9,863 posts
Hello, my name is fenzodahl512 and welcome to Geekstogo.. Please do the following...

Please temporarily disable your BitDefender while proceed with our fix.. Don't forget to re-enable it back after performing all steps below.. Please visit HERE if you do not know how...


Please visit below webpage for instructions for downloading and running ComboFix. Make sure you download and save ComboFix DIRECTLY to your Desktop

http://www.bleepingc...to-use-combofix

This includes installing the Windows XP Recovery Console in case you have not installed it yet.

For more information on the Windows XP Recovery Console read http://support.microsoft.com/kb/314058.

Once you install the Recovery Console, when you reboot your computer, you'll see the option for the Recovery Console now as well. DO NOT select Recovery Console as we don't need it. By default, your main OS is selected there. The screen stays for 2 seconds and then it proceeds to load Windows. That is normal.

Post the log from ComboFix (located in C:\combofix.txt) when you've accomplished that, along with a new HijackThis log.

Edited by fenzodahl512, 07 September 2008 - 11:31 PM.

  • 0

#3
kkqwel

kkqwel

    Member

  • Topic Starter
  • Member
  • PipPip
  • 27 posts

Hello, my name is fenzodahl512 and welcome to Geekstogo.. Please do the following...

Please temporarily disable your BitDefender while proceed with our fix.. Don't forget to re-enable it back after performing all steps below.. Please visit HERE if you do not know how...


Please visit below webpage for instructions for downloading and running ComboFix. Make sure you download and save ComboFix DIRECTLY to your Desktop

http://www.bleepingc...to-use-combofix

This includes installing the Windows XP Recovery Console in case you have not installed it yet.

For more information on the Windows XP Recovery Console read http://support.microsoft.com/kb/314058.

Once you install the Recovery Console, when you reboot your computer, you'll see the option for the Recovery Console now as well. DO NOT select Recovery Console as we don't need it. By default, your main OS is selected there. The screen stays for 2 seconds and then it proceeds to load Windows. That is normal.

Post the log from ComboFix (located in C:\combofix.txt) when you've accomplished that, along with a new HijackThis log.


Hi, thanks for ypur help but I am not sure I can perform all of the tasks you have asked .

Not sure I can install the Windows recovery console, my RUN menu has been disabled as well by this virus ! I will try to run it from the desktop?
  • 0

#4
fenzodahl512

fenzodahl512

  • Malware Removal
  • 9,863 posts
Just download ComboFix >> Disable ALL your Antivirus/Antispyware/Firewall >> Double-click ComboFix >> Wait until finish (Do nothing on your computer) >> Post the log here :)
  • 0

#5
kkqwel

kkqwel

    Member

  • Topic Starter
  • Member
  • PipPip
  • 27 posts

Just download ComboFix >> Disable ALL your Antivirus/Antispyware/Firewall >> Double-click ComboFix >> Wait until finish (Do nothing on your computer) >> Post the log here :)


OK my situation is going downhill very fast, I am now communicating from my wife's computer, mine is all but unusable now.

After I disabled the antivirus it has become extremely unstable and locks up frequently , I tried to run Combofix but it stopped after a few seconds with the following error message

Attempting to create a restore point ' route.exe' is not recognized as an internal or external command or operable program.

Most of my programs like Hijackthis will also not run now and the computer will not let me boot into safe mode either !
  • 0

#6
fenzodahl512

fenzodahl512

  • Malware Removal
  • 9,863 posts
That's not good.. Lets do this..

Please download RSIT by random/random and save it to your Desktop.
  • Double click on RSIT.exe to run RSIT.
  • Click Continue at the disclaimer screen.
  • Once it has finished, two logs will open. Please post the contents of both log.txt and info.txt in your next reply.

  • 0

#7
kkqwel

kkqwel

    Member

  • Topic Starter
  • Member
  • PipPip
  • 27 posts

That's not good.. Lets do this..

Please download RSIT by random/random and save it to your Desktop.

  • Double click on RSIT.exe to run RSIT.
  • Click Continue at the disclaimer screen.
  • Once it has finished, two logs will open. Please post the contents of both log.txt and info.txt in your next reply.



I am unable to get past my login page.

When I start my computer a first page comes with a bright RED warning sign the reads "Warning your computer has been infected with Win32/adware virtumonde and Privacy Remover -64"
It then goes to the normal login page and as soon as I click on a user name to logon my computer reboots !
  • 0

#8
fenzodahl512

fenzodahl512

  • Malware Removal
  • 9,863 posts
Can you restart into Last Known Good Configuration?
  • 0

#9
kkqwel

kkqwel

    Member

  • Topic Starter
  • Member
  • PipPip
  • 27 posts

Can you restart into Last Known Good Configuration?



No, I can't access that either !

I also now get a blue screen with various errors that are noted as the system crashes after a login attempt
  • 0

#10
fenzodahl512

fenzodahl512

  • Malware Removal
  • 9,863 posts
Hi.. I need to set myself clear..

You still haven't run ComboFix yet aren't you?..

And can you get past your log on screen in any mode available?
  • 0

Advertisements


#11
kkqwel

kkqwel

    Member

  • Topic Starter
  • Member
  • PipPip
  • 27 posts

Hi.. I need to set myself clear..

You still haven't run ComboFix yet aren't you?..

And can you get past your log on screen in any mode available?



That is correct.
  • 0

#12
fenzodahl512

fenzodahl512

  • Malware Removal
  • 9,863 posts

Hi.. I need to set myself clear..

You still haven't run ComboFix yet aren't you?..

And can you get past your log on screen in any mode available?



That is correct.



Wait.. the last question.. Can you get past your logon screen at any mode?.. I mean that can you logon (without password) into Windows/Blue Screen..
  • 0

#13
kkqwel

kkqwel

    Member

  • Topic Starter
  • Member
  • PipPip
  • 27 posts

Hi.. I need to set myself clear..

You still haven't run ComboFix yet aren't you?..

And can you get past your log on screen in any mode available?



That is correct.



Wait.. the last question.. Can you get past your logon screen at any mode?.. I mean that can you logon (without password) into Windows/Blue Screen..



no I can not logon, as soon as I click on a user icon at the logon screen the system reboots. I do have acess to the BIOS though
  • 0

#14
fenzodahl512

fenzodahl512

  • Malware Removal
  • 9,863 posts
Sounds like your userinit.exe is corrupted.. We need to get your pc bootable first before we can attempt on cleaning the malware..

Please seek further assistance at our Windows XP forum (link below).. Tell them that I send you there, and your pc is still infected.. Tell them that your pc is unbootable even before proceed with any step.. Link them to this thread...

http://www.geekstogo...2003-NT-f5.html

After your pc is bootable, please come here for further assistance on cleaning your malware..
  • 0

#15
fenzodahl512

fenzodahl512

  • Malware Removal
  • 9,863 posts
Hello.. I received feedback from fellow Geekstogo colleagues, you have to perform a repair-install on your machine (not a reformat/reinstall Windows).. Do you have Windows CD? Or can you borrow anyone's Windows CD that have the same version as yours?

Please visit below webpage on instruction of how to do a Repair Install.. After you successfully get into Windows, please return here for further cleaning process..

http://www.geekstogo...;p=489#entry489
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP