Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Win32/Heur [Solved]


  • This topic is locked This topic is locked

#1
Narcey

Narcey

    New Member

  • Member
  • Pip
  • 7 posts
Hello!

Few days ago, my AVG 8.0 started reporting Win32/Heur virus. At the same time this started happening - when I turned on my computer, Log On window appeared (usually it never appears). After that, the background wallpaper appeared, but the Windows Explorer doesn't start. I had to start it through Windows Task Manager. When I start Windows Explorer, this two massages appear:

/idlist,:0:1840,C:\Documents
Windows cannot find '/idlist,:0:1840,C:\Documents'. Make sure you typed the name correctly, and then try again. To search for a file, click Start button, and the click Search.

imapi.exe - Application Error
The instruction at "0x007a0671" referenced memory at "0x007a671". The memory could not be "written".
Click on OK to terminate the program
Click on CANCEL to debug the program

Actually, this second message has been appearing every now and then for the last few months, but I just kept ignoring it.

When I close these two, a ne window called Data Execution Prevention appears saying that a program called API Image Mastering (which I don't remember installing) has been closed by Windows to help protect my computer against damage from viruses and other security threats. I click Close Message, and after that appears the windows that I usually get when I close some non responding program - it says that "API Image Mastering has encountered a problem and needs to close".

Since AVG kept reporting Win32/Heur, I tried a bunch of different programs to scan and clean my computer. Some of them didn't find anything, some of them found Win32/Heur. But no matter how many reported viruses I deleted, AVG kept reporting. So yesterday I started taking those steps from the You Must Read This Before Posting A Hijackthis Log, Malware Cleaning Guide topic. I managed to do all the steps, except when I tried starting SysRestorePoint, I got message "The application failed to initialize properly (0xc000007b). Click on OK to terminate application." Also, Malware-Byte's Anti-Malware didn't find anything.

OK, all I have described has been happening until yesterday evening. When I restarted the computer today morning, instead of the Data Execution Prevention message for API Image Mastering, the same message appeared for Windows Explorer. So right now I have to do everything through Windows Task Menager. Also, ever since I can't start Windows Explorer, AVG didn't report anything.

And when I turned computer again half an hour ago, Data Execution Prevention message appeared for the program called "Run a DLL as an App".

There are also problems with a lot of other programs - for example, when I try to start Notepad nothing happens, some programs can't be started because of the Data Execution Prevention and for some programs I get message similiar to the one a got for SysRestorePoint ("The application failed to initialize properly (0xc000007b). Click on OK to terminate application."). Actually, for Paint.NET, this message has been appearing from the first day when AVG started reporting Win32/Heur (there are problems with Microsoft .NET Framework 3.0 as well - I can't install it because at the end of setup it keeps reporting an error).

Uh, this post came out much bigger than I planned it :) Sory about that! Thanks in advance for your help!

Here are the HiJackThis log and Uninstall List:

HIJACKTHIS LOG
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:52:36, on 6.3.2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\WINDOWS\system32\taskmgr.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\TASKMAN.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.hr
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.hr
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\MY PROGRAMS\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\MY PROGRAMS\Real Player\rpbrowserrecordplugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\MYPROG~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [D-Link AirPlus G] C:\Program Files\D-Link\AirPlus G\AirGCFG.exe
O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\MY PROGRAMS\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\MY PROGRAMS\Unlocker\UnlockerAssistant.exe" -H
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\MY PROGRAMS\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [FreeRAM XP] "C:\Program Files\MY PROGRAMS\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe" -win
O4 - HKCU\..\Run: [MAXadsl - Provjera prometa] C:\Program Files\Relja\MAXadsl - Provjera prometa\MAXadslPP.exe
O4 - HKCU\..\Run: [Iconize2] "C:\Program Files\MY PROGRAMS\Iconize\Iconize.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\MY PROGRAMS\uTorrent\uTorrent.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User '?')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\MY PROGRAMS\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: I&zvoz u Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Istraživanje - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\MYPROG~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\MYPROG~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file:///C:/Program%20Files/Little%20Shop%20of%20Treasures%202/Images/stg_drm.ocx
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1236369553359
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file:///C:/Program%20Files/Little%20Shop%20of%20Treasures%202/Images/armhelper.ocx
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.m...ash/swflash.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Alpha Networks Inc. - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe

--
End of file - 8472 bytes


UNINSTALL LIST
"GARFIELD:Ucimo od pocetka"
A Series of Unfortunate Events 1.00
Absolute Mastermind v1.4
ACDSee
Acrobat.com
Adobe AIR
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Flash Player Plugin
Adobe Photoshop 7.0
Adobe Reader 7.0.7
Adobe Shockwave Player 11
AirPlus G
Alex Gordon
Alice Greenfingers 2
Allok MPEG4 Converter 5.1.0626
AMP Font Viewer
ANIO Service
ANIWZCS2 Service
AVG Free 8.0
Bishoujo Senshi Sailor Moon
Blood Ties
Bubble Struggle 1.2
BUGS
Cartoonist 1.2
CDDC-Mahjongg (Supprimer uniquement)
CDisplay 1.8
Coloring Book - SHAREWARE
Convert AVI to MP4 1.2
Cooking Dash
Crazy Fishing v.2.0
Crazy Puzzle Special Edition
Dangerous High School Girls version 1.0.3.2
Dirk Dashing: Secret Agent
Discover Painting for Kids Special Edition
Dream Chronicles 2
eGames GOG Red
E-H rječnik
ERUNT 1.1j
Escape Artist
Europe!
Extreme Bugs Special Edition
Fishdom
Fitness Dash
Free FLV to AVI MP4 3GP WMV MP3 Converter v2.2
Free M4a to MP3 Converter 6.0
Freeride Thrash
Ginkgo Paint!
GOM Player
Google Toolbar for Internet Explorer
Google Video Player
HaCKeR
High Definition Audio Driver Package - KB888111
HijackThis 2.0.2
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows XP (KB915865)
Hotfix for Windows XP (KB926239)
Hotfix for Windows XP (KB935448)
Hotfix for Windows XP (KB952287)
Iconize 2.0
Icy Tower v1.3
iDailyDiary 3.20
Kea Coloring Book 3.6.0
Last Egg Standing
Magic Crystals
Malwarebytes' Anti-Malware
MAXadsl - Provjera prometa
MediaCoder 0.6.0
Memory Match
Microsoft .NET Framework 2.0
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office Professional Edition 2003
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
Mind Medley Free
Mindgames
MobileVideo For iPod 3.6
MotoAce 1.19
Mp3tag V.2.34a
MPEG2 Codec(libmpeg2/mad)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
Nero 8
neroxml
NoteTab Light
OpenMG Secure Module 4.7.00
Paint Shop Pro 7 Try And Buy
Paint.NET v3.36
PC Health Optimizer Free Edition
Pivot Stickfigure Animator
Playground Special Edition
QuickTime
RealPlayer
REALTEK GbE & FE Ethernet PCI NIC Driver
Realtek High Definition Audio Driver
Santa Claus in trouble ...again! - Demo
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950749)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB960715)
Shapes
Shockwave
SkyTracks 1.03
Solitary Confinement
Sony Ericsson PC Suite 1.20.173
SpongeBob SquarePants Diner Dash (remove only)
Spybot - Search & Destroy
Starcars Demo - Version 1.4
Strike Ball 2
The Hidden Object Show
The MagicBook V3
Tux Paint 0.9.15
Unlocker 1.8.3
Update for Windows XP (KB898461)
Update for Windows XP (KB932823-v3)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
VCRedistSetup
Video mp3 Extractor
VideoLAN VLC media player 0.8.2
VSO Image Resizer 1.3.3
WinBrick2000
Windows Imaging Component
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 7
Windows Live Messenger
Windows Media Format 11 runtime
Windows Media Format 11 runtime
Windows Media Player 11
Windows Media Player 11
WinFast® Display Driver
WinRAR archiver
WinSnap
WordWeb

Edited by Narcey, 10 March 2009 - 01:30 PM.

  • 0

Advertisements


#2
IndiGenus

IndiGenus

    Anti-Malware Buddha

  • Member
  • PipPipPipPip
  • 1,617 posts
Hi Narcey and welcome to the forums here at G2G. Sorry for the delay in getting to your post. You have quite a few issues going on here. I suspect you either have some serious Windows corruptions, or, Virut. Virut is a file infector that can cause these types of issues. I would like to see if it's present first so we'll run a Kaspersky scan.

The below scan can take up to an hour or longer, please be patient.

*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so no conflicts and to speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once scan is finished remember to re-enable resident antivirus protection along with whatever antispyware app you use.


Please do a scan with Kaspersky Online Scanner or from here
http://www.kaspersky.com/virusscanner

Note: If you are using Windows Vista, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.

  • Click on the Accept button and install any components it needs.
  • The program will install and then begin downloading the latest definition
    files.
  • After the files have been downloaded on the left side of the page in the Scan section select My Computer.
  • This will start the program and scan your system.
  • The scan will take a while, so be patient and let it run. (At times it may appear to stall)
    * Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
    * Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
    * Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Once the scan is complete, click on View scan report To obtain the report:
Click on: Save Report As
Next, in the Save as prompt, Save in area, select: Desktop
In the File name area, use KScan, or something similar In Save as type, click the drop arrow and select:
Text file [*.txt]
Then, click: Save
Please post the Kaspersky Online Scanner Report in
your reply.

Animated tutorial
http://i275.photobuc...ng/KAS/KAS9.gif

(Note.. for Internet Explorer 7 users:
If at any time you have trouble with the "Accept" button of the license, click on the "Zoom" tool located at the bottom right of the IE window and set the zoom to 75 %. Once the license has been accepted, reset to 100%
.)
Or use Firefox with IE-Tab plugin
https://addons.mozil...efox/addon/1419

In your next reply post:
Kaspersky log
New HJT log taken after the above scan has run

  • 0

#3
Narcey

Narcey

    New Member

  • Topic Starter
  • Member
  • Pip
  • 7 posts
Hi IndiGenus, thanks for replying! I am afraid there are problems at the very beginning...

First, I have AVG installed on my computer, but I am not sure how to gain access to it. Usually I do it either through Start Menu or the icon on the Task Bar, but now my Windows Explorer doesn't work. I don't have any shortcut to AVG on my desktop. I went into the AVG folder in program Files, but there are many files (such asavgdumpx, avgtray, setup...), so I don't know which one to start.
I am actually not even sure if AVG is running right now. In the "Processes" tab in Task manager, there are processes avgemc, avgrsx and avgwdsvc, but I don't get any kind of reports from AVG (before, it used to report win32 almost every 30 minutes).

Second, I tried running Kaspersky Online Scanner, but I am having trouble with the "Accept" button of the license (I have tried changing zoom, but that didn't help). Also, about 10 seconds after coming to the Kaspersky site, I get message saying I need to install Java version 1.5 or later. I tried installing it from java.com, but I still keep getting the same message (even after I restarted Internet Explorer).
Internet Explorer also blocks ActiveX Control, but I don't know if this is important.

Edited by Narcey, 11 March 2009 - 02:19 PM.

  • 0

#4
IndiGenus

IndiGenus

    Anti-Malware Buddha

  • Member
  • PipPipPipPip
  • 1,617 posts
Can you start explorer using Task Manager?

To start EXPLORER.EXE manually:

1. Open Windows Task Manager. Press CTRL+SHIFT+ESC.
2. On Windows Task Manager, Click File>New Task (Run..)
3. In Create New Task, type %WinDir%\EXPLORER.EXE and click OK.
4. Close Task Manager.

That should get you running.

Download Dr.Web CureIt to the desktop:
ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe
  • Doubleclick the drweb-cureit.exe file and Allow to run the express scan
  • This will scan the files currently running in memory and when something is found, click the yes button when it asks you if you want to cure it. This is only a short scan.
  • Once the short scan has finished, mark the drives that you want to scan.
  • Select all drives. A red dot shows which drives have been chosen.
  • Click the green arrow at the right, and the scan will start.
  • Click 'Yes to all' if it asks if you want to cure/move the file.
  • When the scan has finished, in the menu, click file and choose save report list
  • Save the report to your desktop. The report will be called DrWeb.csv
  • Close Dr.Web Cureit.
Post the report in your next reply.
  • 0

#5
Narcey

Narcey

    New Member

  • Topic Starter
  • Member
  • Pip
  • 7 posts
I couldn't start explorer even using Task Manager, but after running DrWeb, it starts itself automatically again.

I had to scan with Dr Web twice. When I started scan for the first time, scan of files currently running in memory went OK (it found 48 objects infected with Win32.Virut and cured them all), but at the beginning of the scan of the drives, the computer completely froze so I had to restart it. After restarting it, I ran DrWeb again and I posted the report from that scan.

Dr Web report
capabilitymanager.exe c:\program files\common files\teleca shared Win32.Virut.56 Cured.
generic.exe c:\program files\common files\teleca shared Win32.Virut.56 Cured.
epmworker.exe c:\program files\my programs\sony ericsson\mobile2\mobile phone monitor Win32.Virut.56 Cured.
RegUBP2b-DUNJA.reg C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2 Trojan.StartPage.1505 Deleted.
reader_s.exe C:\Documents and Settings\DUNJA Trojan.DownLoad.29459 Deleted.
GrLauncher.exe C:\Documents and Settings\DUNJA\Application Data\GRETECH\GomPlayer Win32.Virut.56 Cured.
NewShortcut1_81830F749785497EA8E887D1790D2331.exe C:\Documents and Settings\DUNJA\Application Data\Microsoft\Installer\{81830F74-9785-497E-A8E8-87D1790D2331} Win32.Virut.56 Cured.
NewShortcut5_46D44717548D4409893CB5AC299E43FA_1.exe C:\Documents and Settings\DUNJA\Application Data\Microsoft\Installer\{81830F74-9785-497E-A8E8-87D1790D2331} Win32.Virut.56 Cured.
NewShortcut6_46D44717548D4409893CB5AC299E43FA_1.exe C:\Documents and Settings\DUNJA\Application Data\Microsoft\Installer\{81830F74-9785-497E-A8E8-87D1790D2331} Win32.Virut.56 Cured.
TOMB2.EXE C:\Documents and Settings\DUNJA\Desktop\Dunja\Useless Stuff\Tomb Raider Update Files\TR2 Win32.Virut.56 Cured.
tomb3.exe C:\Documents and Settings\DUNJA\Desktop\Dunja\Useless Stuff\Tomb Raider Update Files\TR3 Win32.Virut.56 Cured.
tomb4.exe C:\Documents and Settings\DUNJA\Desktop\Dunja\Useless Stuff\Tomb Raider Update Files\TR4 Win32.Virut.56 Cured.
TRAOD.exe C:\Documents and Settings\DUNJA\Desktop\Dunja\Useless Stuff\Tomb Raider Update Files\TRAOD\bin Win32.Virut.56 Cured.
TRAOD_P3.exe C:\Documents and Settings\DUNJA\Desktop\Dunja\Useless Stuff\Tomb Raider Update Files\TRAOD\bin Win32.Virut.56 Cured.
TRAOD_P4.exe C:\Documents and Settings\DUNJA\Desktop\Dunja\Useless Stuff\Tomb Raider Update Files\TRAOD\bin Win32.Virut.56 Cured.
tr3gold.exe C:\Documents and Settings\DUNJA\Desktop\Dunja\Useless Stuff\Tomb Raider Update Files\TRLA Win32.Virut.56 Cured.
tomb4.exe C:\Documents and Settings\DUNJA\Desktop\Dunja\Useless Stuff\Tomb Raider Update Files\TRLE Win32.Virut.56 Cured.
10_3.exe C:\Documents and Settings\DUNJA\Desktop\Dunja\Škola\Informatika\Grafika\Test\Niko\info zad\Klaritaaa Win32.Virut.56 Cured.
VisualBoyAdvance.exe C:\Documents and Settings\DUNJA\Desktop\Games\Game Boy Advance Win32.Virut.56 Cured.
VisualBoyAdvance.exe C:\Documents and Settings\DUNJA\Desktop\Games\Game Boy Advance\Leaf Green Win32.Virut.56 Cured.
Roll On.exe C:\Documents and Settings\DUNJA\Desktop\Games\Igrice Win32.Virut.56 Cured.
TowerOfGooUnlimited.exe C:\Documents and Settings\DUNJA\Desktop\Games\Igrice Win32.Virut.56 Cured.
Cooking Dash.exe C:\Documents and Settings\DUNJA\Desktop\Games\Igrice\Setup Win32.Virut.56 Cured.
Mystery Case Files Ravenhearst.exe\data009 C:\Documents and Settings\DUNJA\Desktop\Games\Igrice\Setup\Mystery Case Files Ravenhearst.exe Trojan.Virtumod.based.11
Mystery Case Files Ravenhearst.exe C:\Documents and Settings\DUNJA\Desktop\Games\Igrice\Setup Archive contains infected objects Moved.
Mystery_Case_Files_Prime_Suspects_setup.exe\data005 C:\Documents and Settings\DUNJA\Desktop\Games\Igrice\Setup\Mystery_Case_Files_Prime_Suspects_setup.exe Trojan.Virtumod.based.11
Mystery_Case_Files_Prime_Suspects_setup.exe C:\Documents and Settings\DUNJA\Desktop\Games\Igrice\Setup Archive contains infected objects Moved.
DangerousHSGirls_setup.exe C:\Documents and Settings\DUNJA\Desktop\Games\Igrice\Setup\DangerousHSGirls Win32.Virut.56 Cured.
brigiton.exe C:\Documents and Settings\DUNJA\Desktop\Games\Igrice\Setup\DangerousHSGirls\cracked\prog Win32.Virut.56 Cured.
dream2.exe C:\Documents and Settings\DUNJA\Desktop\Games\Igrice\Setup\Dream Chronicles 2\Crack Win32.Virut.56 Cured.
dream2.exe C:\Documents and Settings\DUNJA\Desktop\Games\Igrice\Setup\Dream Chronicles 2\Crack\game Win32.Virut.56 Cured.
Hospital Hustle.exe C:\Documents and Settings\DUNJA\Desktop\Games\Igrice\Setup\Hospital Hustle Win32.Virut.56 Cured.
gobpack.exe C:\Documents and Settings\DUNJA\Desktop\Games\Igrice\Setup\Jump 'n Bump Win32.Virut.56 Cured.
jnbpack.exe C:\Documents and Settings\DUNJA\Desktop\Games\Igrice\Setup\Jump 'n Bump Win32.Virut.56 Cured.
jnbunpack.exe C:\Documents and Settings\DUNJA\Desktop\Games\Igrice\Setup\Jump 'n Bump Modification of Win32.Virut.56 Moved.
jumpnbump.exe C:\Documents and Settings\DUNJA\Desktop\Games\Igrice\Setup\Jump 'n Bump Win32.Virut.56 Cured.
MysteryCaseFiles.exe C:\Documents and Settings\DUNJA\Desktop\Games\Igrice\Setup\Mystery Case Files Huntsville\Cracked Win32.Virut.56 Cured.
en_spongebobsquarepdd_inst.exe C:\Documents and Settings\DUNJA\Desktop\Games\Igrice\Setup\SpongeBob SquarePants Diner Dash Win32.Virut.56 Cured.
en_spongebobsquarepdd_inst.exe/data002\data001 C:\Documents and Settings\DUNJA\Desktop\Games\Igrice\Setup\SpongeBob SquarePants Diner Dash\en_spongebobsquarepdd_inst.exe/data Trojan.Click.23666
data002 C:\Documents and Settings\DUNJA\Desktop\Games\Igrice\Setup\SpongeBob SquarePants Diner Dash Container contains infected objects
en_spongebobsquarepdd_inst.exe C:\Documents and Settings\DUNJA\Desktop\Games\Igrice\Setup\SpongeBob SquarePants Diner Dash Container contains infected objects Moved.
ATF_Cleaner.exe C:\Documents and Settings\DUNJA\Desktop\Programs Win32.Virut.56 Cured.
Christmas Tree Collection.exe C:\Documents and Settings\DUNJA\Desktop\Programs Win32.Virut.56 Cured.
Unstoppable Copier 3.56.exe C:\Documents and Settings\DUNJA\Desktop\Programs Win32.Virut.56 Cured.
Auto Insult.EXE C:\Documents and Settings\DUNJA\Desktop\Programs\Funny Win32.Virut.56 Cured.
BinaryToys.exe C:\Documents and Settings\DUNJA\Desktop\Programs\Funny Win32.Virut.56 Cured.
Intelligent WordPad.EXE C:\Documents and Settings\DUNJA\Desktop\Programs\Funny Win32.Virut.56 Cured.
kamikazekat.exe C:\Documents and Settings\DUNJA\Desktop\Programs\Funny Win32.Virut.56 Cured.
Neko98.exe C:\Documents and Settings\DUNJA\Desktop\Programs\Funny\neko the cat Win32.Virut.56 Cured.
NekoCFG.exe C:\Documents and Settings\DUNJA\Desktop\Programs\Funny\neko the cat Win32.Virut.56 Cured.
Media Player Classic.exe C:\Documents and Settings\DUNJA\Desktop\Programs\Players Win32.Virut.56 Cured.
Install FreeRAM XP Pro 1.50.exe C:\Documents and Settings\DUNJA\Desktop\Programs\SETUP Win32.Virut.56 Cured.
MAXadsl Provjera Prometa.exe C:\Documents and Settings\DUNJA\Desktop\Programs\SETUP Win32.Virut.56 Cured.
MAXadslPP078.exe C:\Documents and Settings\DUNJA\Desktop\Programs\SETUP Win32.Virut.56 Cured.
abrViewer.NET.exe C:\Documents and Settings\DUNJA\Desktop\Programs\SETUP\abr viewer Win32.Virut.56 Cured.
SysRestorePoint.exe C:\Documents and Settings\DUNJA\Desktop\Programs\SETUP\PC Protection\SysRestorePoint_v13 Win32.Virut.56 Cured.

Edited by Narcey, 13 March 2009 - 02:49 AM.

  • 0

#6
IndiGenus

IndiGenus

    Anti-Malware Buddha

  • Member
  • PipPipPipPip
  • 1,617 posts
As you can see from the report, it is Virut.

Virut is a file infector which infects executables (.exe's or program files), .scr's, .htm, .html, .xml, .zip, and .rar files. The problem with Virut is that it is a buggy file infector and that's why scanners may not disinfect them properly either. The results of this, files are corrupted and won't work anymore.

This unfortunately means that the best course of action now is formatting and reinstalling Windows. You can back up your personal files such as documents, pictures, music, ect.... Just not any of the files with the extensions mentioned above.

Let me know if you need some guidance with the re-install.

Good luck,
Dave
  • 0

#7
Narcey

Narcey

    New Member

  • Topic Starter
  • Member
  • Pip
  • 7 posts
OK, I will format and reinstall Windows then. I just have few questions. If I unzip files from .zp and .rar files, are they still infected? Also, does this mean that there is no danger of infecting another comupter through USB, unless if I copy .exe, .scr's, .htm... files to USB? I just want to be 100% sure before I star with copying.

I don't think I'll need guidance with reinstalling, I have a friend who already helped me once with reinstalling. Thank you for helping me so far and taking your time to look into my problem :)

Edited by Narcey, 13 March 2009 - 12:25 PM.

  • 0

#8
IndiGenus

IndiGenus

    Anti-Malware Buddha

  • Member
  • PipPipPipPip
  • 1,617 posts

If I unzip files from .zp and .rar files, are they still infected?

Yes, they will likely still be infected. Avoid if you can.

Also, does this mean that there is no danger of infecting another comupter through USB, unless if I copy .exe, .scr's, .htm... files to USB? I just want to be 100% sure before I star with copying.

You should be okay as long as you avoid those files.

To help prevent the spread of any potential malware run this tool on your drive.

Download Flash_Disinfector.exe by sUBs from here and save it to your desktop.
  • Double-click Flash_Disinfector.exe to run it and follow any prompts that may appear.
  • The utility may ask you to insert your flash drive and/or other removable drives including your mobile phone. Please do so and allow the utility to clean up those drives as well.
  • Wait until it has finished scanning and then exit the program.
  • Reboot your computer when done.

    Note: Flash_Disinfector will create a hidden folder named autorun.inf in each partition and every USB drive plugged in when you run it. Don't delete this folder...it will help protect your drives from future infection.

  • 0

#9
Narcey

Narcey

    New Member

  • Topic Starter
  • Member
  • Pip
  • 7 posts
I have reinstalled Windows today and used Flash Disinfector according to your instructions. Just one last question - should I keep using AVG or can you recommend a better antivirus, and which firewall would you recommend?

P.S. Sorry about the delay, it took me some time to do the reinstalling.
  • 0

#10
IndiGenus

IndiGenus

    Anti-Malware Buddha

  • Member
  • PipPipPipPip
  • 1,617 posts
Great, glad you got it going again.

On the Antivirus, there are basically the big 3 free "A's" (for free solutions):

AVG
Avast
Avira Antivir

I've been leaning more towards Antivir recently and think it is more aggressive and on top of the newer infections. I recently had a couple of Virut sample files and of the 3 Avira was the only one to pick it up at that time (now all 3 have the definitions). Were only talking a matter of a few days or a week but that can mean the difference between stopping, or not stopping, this from happening to you in the future.

Hope that helps,
Dave
  • 0

#11
Narcey

Narcey

    New Member

  • Topic Starter
  • Member
  • Pip
  • 7 posts
I will probably go with Avira then, thank you for the recommendations.
  • 0

#12
IndiGenus

IndiGenus

    Anti-Malware Buddha

  • Member
  • PipPipPipPip
  • 1,617 posts
Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. :)

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP