Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

W32/CodeCru-based!Maximus NASTYYYYYYSS!


  • Please log in to reply

#1
SpicyNHot

SpicyNHot

    Member

  • Member
  • PipPip
  • 54 posts
:) :help:
This is the list of the viruses shows up everytime I scan my disk defragmenter on my presario (c:) drive
my freedom anti virual detected all of this so I save the names to a notepad and paste it here.

This virus include for the whole listing of files

NASTY FILES!!!!!!!!!!! :whistling:

Virus name: W32/CodeCru-based!Maximus


D:\PROGRAM FILES\NORTON ANTIVIRUS\QUARANTINE\111B3147.EXE

D:\PROGRAM FILES\NORTON ANTIVIRUS\QUARANTINE\1118074B.EXE

D:\PROGRAM FILES\NORTON ANTIVIRUS\QUARANTINE\11145D4E.EXE

D:\PROGRAM FILES\NORTON ANTIVIRUS\QUARANTINE\11113352.EXE

D:\PROGRAM FILES\NORTON ANTIVIRUS\QUARANTINE\74490740.EXE

D:\PROGRAM FILES\NORTON ANTIVIRUS\QUARANTINE\110E0955.EXE

D:\PROGRAM FILES\NORTON ANTIVIRUS\QUARANTINE\110B5F59.EXE

D:\PROGRAM FILES\NORTON ANTIVIRUS\QUARANTINE\68B94B41.EXE

D:\PROGRAM FILES\NORTON ANTIVIRUS\QUARANTINE\1107355D.EXE

D:\PROGRAM FILES\NORTON ANTIVIRUS\QUARANTINE\11040B60.EXE

D:\PROGRAM FILES\NORTON ANTIVIRUS\QUARANTINE\11016164.EXE

D:\PROGRAM FILES\NORTON ANTIVIRUS\QUARANTINE\17603143.EXE

D:\PROGRAM FILES\NORTON ANTIVIRUS\QUARANTINE\10FE3767.EXE

D:\PROGRAM FILES\NORTON ANTIVIRUS\QUARANTINE\10FA0D6B.EXE

D:\PROGRAM FILES\NORTON ANTIVIRUS\QUARANTINE\10F7636F.EXE

D:\PROGRAM FILES\NORTON ANTIVIRUS\QUARANTINE\46081745.EXE

D:\PROGRAM FILES\NORTON ANTIVIRUS\QUARANTINE\10F43972.EXE

D:\PROGRAM FILES\MICROSOFT ANTISPYWARE\QUARANTINE\D51EF26A-6FA7-4339-A073-D0DB3D\4991D053-1C30-4727-AC14-F1E37F

D:\PROGRAM FILES\NORTON ANTIVIRUS\QUARANTINE\10F10F76.EXE

D:\PROGRAM FILES\NORTON ANTIVIRUS\QUARANTINE\126C7571.EXE

Another virus name for these last 3 files

NASTY FILES!!!!!!!

Virus name: Unknown

D:\PROGRAM FILES\NORTON ANTIVIRUS\QUARANTINE\524A1397.EXE

D:\PROGRAM FILES\NORTON ANTIVIRUS\QUARANTINE\5C5C2334.EXE

D:\PROGRAM FILES\NORTON ANTIVIRUS\QUARANTINE\1135012A.EXE

:blink:

My HijackThis log

Logfile of HijackThis v1.99.1
Scan saved at 2:46:53 AM, on 2/14/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
C:\windows\system\hpsysdrv.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Compaq Connections\6750491\Program\Compaq Connections.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Zero Knowledge\Freedom\Freedom.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\Command Software\dvpapi.exe
C:\Documents and Settings\Compaq_Owner\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.h...a...&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.h...a...&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.h...a...&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.h...a...&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.adelphia.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.h...a...&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: PopKill Class - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - C:\Program Files\Zero Knowledge\Freedom\pkR.dll
O2 - BHO: ZKBho Class - {56071E0D-C61B-11D3-B41C-00E02927A304} - C:\Program Files\Zero Knowledge\Freedom\FreeBHOR.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\RunOnce: [IndexCleaner] "C:\Program Files\Zero Knowledge\Freedom\IndexCleanerR.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\ccleaner.exe" /AUTO
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\RunOnce: [IndexCleaner] "C:\Program Files\Zero Knowledge\Freedom\IndexCleanerR.exe"
O4 - HKCU\..\RunOnce: [ypagerps] cmd.exe /C del "C:\Program Files\Yahoo!\Messenger\ypagerps.dll"
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\6750491\Program\Compaq Connections.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.micros...b?1170913350718
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1170913487281
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: DvpApi (dvpapi) - Command Software Systems, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe

My add/unistall programs log from HiJackThis

Adobe Flash Player 9 ActiveX
Adobe Reader 8
Adobe Shockwave Player
Agere Systems PCI Soft Modem
Apple Software Update
Canon Camera Support Core Library
Canon Camera Window DS for ZoomBrowser EX
Canon Camera Window DVC for ZoomBrowser EX
Canon Camera Window for ZoomBrowser EX
Canon MovieEdit Task for ZoomBrowser EX
Canon PhotoRecord
Canon RAW Image Task for ZoomBrowser EX
Canon RemoteCapture Task for ZoomBrowser EX
Canon Utilities PhotoStitch 3.1
Canon ZoomBrowser EX
CCleaner (remove only)
CleanUp!
Compaq Connections
Easy Internet Sign-up
Freedom Security & Privacy
Help and Support Additions
HijackThis 1.99.1
iTunes
J2SE Runtime Environment 5.0 Update 10
J2SE Runtime Environment 5.0 Update 11
Java 2 Runtime Environment, SE v1.4.2_03
KBD
Microsoft .NET Framework 1.1
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Works
MP3 Rocket
MSXML 4.0 SP2 (KB927978)
PC-Doctor for Windows
PS2
Python 2.2 combined Win32 extensions
Python 2.2.1
QuickTime
RealPlayer
Rhapsody Player Engine
S3 S3Display
S3 S3Gamma2
S3 S3Info2
S3 S3Overlay
Security Update for Windows Internet Explorer 7 (KB929969)
Sonic RecordNow!
VIA Rhine-Family Fast Ethernet Adapter
VIA/S3G Display Driver
Windows Internet Explorer 7
Windows Media Format 11 runtime
Windows Media Format 11 runtime
Windows Media Player 11
Windows Media Player 11
Yahoo! Browser Services
Yahoo! Mail
Yahoo! Messenger

Also what's those green lines in the volume of disk defragmenter on my presario (c:) drive
everytime I scan defrag it, it won't move??? I look at the below bottom box it's says unremovable files
But I have 4 of them green lines I understand one of them are a page file. I believe it has something to do with these viruses. Those nasty files shows on that volume I do believe. Also I think all these files could be listed all in C:\Program Files\Norton AntiVirus\Quarantine :Size on disk 5.78 MB The date it was created
8/19/2005 3:56 am for all the files included in that department. The whole Norton AntiVirus folder still exist even though I unistall it.

Here are my drives
my presario_rp (D:) drive: File system FAT 32: Capacity Total 4.18GB: Free Space 1.01GB
my presario (C:) drive: File system NTFS: Capacity Total 51.71 GB: Free Space 44.19GB

About a week ago I put my system in partial recovery. I was scared to do advance full recovery BECAUSE MY Computer didn't come with a xp disk I think it's built on my D drive including the recovery partition on the D: drive. I made a copy of my D: drive all 5 cd's..

:) !Please Help! :help:

Edited by SpicyNHot, 14 February 2007 - 03:28 AM.

  • 0

Advertisements


#2
SpicyNHot

SpicyNHot

    Member

  • Topic Starter
  • Member
  • PipPip
  • 54 posts
Someone please help! I need some emergency computer assistence??? I have several viruses I :whistling: don't want my hard drive to go.. :blink:

Edited by SpicyNHot, 14 February 2007 - 06:16 PM.

  • 0

#3
SpicyNHot

SpicyNHot

    Member

  • Topic Starter
  • Member
  • PipPip
  • 54 posts
Hey never mind don't need no help.. Someone can come along and close this thread! I just went along and put my system in destructive recovery formated the hard drive and got rid of everything.. Now my computer is running like it's new again..
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP