Bullguard Antivirus Forum Download A Free Copy Of Bullguard Antivirus Software
Free Antivirus Forum - Learn about antivirus, firewalls and personal security Free Antivirus Forum - Learn about antivirus, firewalls and personal security
 HomeLog InRegisterCommunity CalendarSearch the ForumView The Member ListHelp
Help needed - redirecting virus
   
BullGuard Antivirus Forum > Virus Removal > Removal Help > Help needed - redirecting virus  
Forum Quick Jump
 
New Topic Post reply to : Help needed - redirecting virus Printable version of : Help needed - redirecting virus
62 posts in this thread.
Viewing Page :
 1  2  3 
[ << Previous Thread | Next Thread >> ]

Jintan
Senior Member




Date Joined Dec 2006
Total Posts : 1424
 
   Posted 9-9-2009 12:45 (GMT +1)    Quote: Help needed - redirecting virusAlert an admin about: Help needed - redirecting virus
The first scan located mostly infection already removed by ComboFix to it's Qoobox folder, and it looks like it mistook a Panda active scan file as malicious (one way to eliminate the competition). The second scan just show infection held harmless in System Restore, which we will be clearing out shortly anyway. Looks cleaned up at this point. Before we do some last steps to finish our work, post back how things are running now please.


Click here and help my friend help stop leukemia, lymphoma, Hodgkin lymphoma and myeloma from taking more lives.

Back to Top
 

grinaldo
New Member


Date Joined Aug 2009
Total Posts : 33
 
   Posted 9-9-2009 6:21 (GMT +1)    Quote: Help needed - redirecting virusAlert an admin about: Help needed - redirecting virus
Hi Jintan,

No noticeable issues at the moment with the orignal probelm of being re-directed when using search engines, system even running a little quicker.

The only known issue that remains is the RSIT.exe file that I cannot delete (and also a HiJackthis.exe file) from the desktop.

Do you need any more details?

Thanks
Back to Top
 

Jintan
Senior Member




Date Joined Dec 2006
Total Posts : 1424
 
   Posted 9-10-2009 12:47 (GMT +1)    Quote: Help needed - redirecting virusAlert an admin about: Help needed - redirecting virus
If you are being redirected, and the desktop is locked like that, we do have some additional checking to do here. We do need a scan that shows the HijackThis and running process entries, which seem to be blocked in other results so far.


Download subinacl.msi from here to your desktop, then click the file to start the installer.

Accept any agreements, and allow it to install SubInACL.exe to it's "C:\Program Files\Windows Resource Kits\Tools\" folder.


Once you have done that open Notepad (Start - Run, type notepad then press Enter) and copy the following text into a new file:
cd "%programfiles%\Windows Resource Kits\Tools"
subinacl /subdirectories %SystemDrive% /grant=everyone=f

Save the file to the desktop as "permdo.bat"

Make sure to use the quotes "" in the name.

Then double-click on permdo.bat. A window should open and you will see some procedures run --- this is normal. Once they have completed the changes the window should close.

------

Go to Start - Run, type cmd (and press OK). At the prompt type or copy/paste the following, pressing Enter after:

cd\
win32kdiag -r -f


Once that completes press any key to finish the scan. Post the new Win32kDiag.txt log with your next reply (it should be located on the desktop).

--------------

See if can now run a scan using HijackThis, and post that log. If you cannot get HijackThis to run go here and download HijackThis 1.99.1. Unzip that downloaded file, then click on that copy of HijackThis.exe to open HijackThis. Run a scan using that and post the log back here please.

--------------

And run a new ComboFix scan. Post that C:\ComboFix.txt log along with the Win32kDiag.txt log and the HijackThis log please.


Click here and help my friend help stop leukemia, lymphoma, Hodgkin lymphoma and myeloma from taking more lives.

Back to Top
 

grinaldo
New Member


Date Joined Aug 2009
Total Posts : 33
 
   Posted 9-10-2009 6:51 (GMT +1)    Quote: Help needed - redirecting virusAlert an admin about: Help needed - redirecting virus
Log file is located at: C:\Documents and Settings\David\Desktop\Win32kDiag.txt

Removing all found mount points.

Attempting to reset file permissions.

WARNING: Could not get backup privileges!

Searching 'C:\WINDOWS'...





Finished!
Back to Top
 

grinaldo
New Member


Date Joined Aug 2009
Total Posts : 33
 
   Posted 9-10-2009 6:52 (GMT +1)    Quote: Help needed - redirecting virusAlert an admin about: Help needed - redirecting virus
Logfile of HijackThis v1.99.1
Scan saved at 6:52:09 AM, on 9/10/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16876)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Kontiki\KService.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Linksys\Compact Wireless-G USB Adapter Wireless Network Monitor\WLService.exe
C:\Program Files\Linksys\Compact Wireless-G USB Adapter Wireless Network Monitor\WUSB54GC.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Mixer.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\DNA\btdna.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\David\Desktop\hijackthis1991\HijackThis.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.co.uk/0SEENGB/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 192.168.1.1:80
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O8 - Extra context menu item: Add to AMV Converter... - C:\Program Files\MP3 Player Utilities 4.03\AMVConverter\grab.html
O8 - Extra context menu item: Add to Media Manager... - C:\Program Files\MP3 Player Utilities 4.03\MediaManager\grab.html
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/FacebookPhotoUploader5.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/betapit/PCPitStop.CAB
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase1140.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/FacebookPhotoUploader.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1224800874562
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://dl8-cdn-03.sun.com/s/ESD5/JSCDL/jre/6u10-b92-b/jinstall-6u10-windows-i586-jc.cab?e=1227348943080&h=195074a9b2fc8109f49e85de0c7340f7/&filename=jinstall-6u10-windows-i586-jc.cab
O16 - DPF: {9122D757-5A4F-4768-82C5-B4171D8556A7} (PhotoPickConvert Class) - http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/PhotoSwap/PhtPkMSN.cab
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://89.213.64.14/activex/AxisCamControl.cab
O16 - DPF: {9732FB42-C321-11D1-836F-00A0C993F125} (mhLabel Class) - http://www.pcpitstop.com/mhLbl.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - C:\Program Files\Java\jre6\bin\jqs.exe" -service -config "C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf (file missing)
O23 - Service: KService - Kontiki Inc. - C:\Program Files\Kontiki\KService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\System32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: WUSB54GCSVC - Unknown owner - C:\Program Files\Linksys\Compact Wireless-G USB Adapter Wireless Network Monitor\WLService.exe" "WUSB54GC.exe (file missing)
Back to Top
 

grinaldo
New Member


Date Joined Aug 2009
Total Posts : 33
 
   Posted 9-10-2009 7:17 (GMT +1)    Quote: Help needed - redirecting virusAlert an admin about: Help needed - redirecting virus
ComboFix 09-09-09.04 - David 09/10/2009 6:58.3.1 - NTFSx86
Running from: c:\documents and settings\David\Desktop\456out.com
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
* Created a new restore point
.

((((((((((((((((((((((((( Files Created from 2009-08-10 to 2009-09-10 )))))))))))))))))))))))))))))))
.

2009-09-10 05:33 . 2009-09-10 05:33 105 ----a-w- c:\documents and settings\David\permdo.bat
2009-09-10 05:32 . 2009-09-10 05:32 -------- d-----w- c:\program files\Windows Resource Kits
2009-09-09 18:23 . 2009-06-21 22:04 153088 -c----w- c:\windows\system32\dllcache\triedit.dll
2009-09-04 06:09 . 2009-09-06 17:27 46080 ----a-w- C:\Win32kDiag.exe
2009-09-03 18:31 . 2009-09-03 18:52 -------- d-----w- c:\program files\Common Files\ParetoLogic
2009-09-03 06:07 . 2009-09-03 06:07 -------- d-----w- c:\documents and settings\David\Application Data\Malwarebytes
2009-09-03 06:07 . 2009-08-03 12:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-03 06:07 . 2009-09-03 06:07 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-09-03 06:07 . 2009-09-03 06:07 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-09-03 06:07 . 2009-08-03 12:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-09-01 06:11 . 2009-09-01 06:11 -------- d-----w- C:\rsit
2009-08-31 19:06 . 2009-09-01 06:13 -------- d-----w- c:\program files\Trend Micro
2009-08-31 18:45 . 2009-09-04 06:15 -------- d--h--w- c:\windows\PIF
2009-08-31 18:25 . 2009-08-31 18:25 -------- d-----w- c:\documents and settings\David\Application Data\Yahoo!
2009-08-31 18:25 . 2009-09-01 06:02 -------- d-----w- c:\program files\Yahoo!
2009-08-31 18:24 . 2009-08-31 18:25 -------- d-----w- c:\program files\CCleaner
2009-08-31 18:07 . 2009-09-01 06:02 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-08-31 18:07 . 2009-09-01 05:48 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-08-31 17:50 . 2009-08-31 17:50 -------- d-----w- C:\WINDOWS is valid
2009-08-31 12:35 . 2009-09-01 05:49 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-08-31 12:20 . 2009-08-31 12:21 -------- d-----w- c:\program files\Windows Live Safety Center
2009-08-31 12:03 . 2009-09-01 05:49 -------- d-----w- c:\program files\Windows Defender
2009-08-30 21:36 . 2009-08-30 21:36 -------- d-----w- c:\documents and settings\David\Application Data\Logs
2009-08-13 16:02 . 2009-07-10 13:42 1315328 -c----w- c:\windows\system32\dllcache\msoe.dll
2009-08-13 16:02 . 2009-06-05 07:42 655872 -c----w- c:\windows\system32\dllcache\mstscax.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-10 06:11 . 2007-11-11 11:14 -------- d-----w- c:\documents and settings\All Users\Application Data\Kontiki
2009-09-10 06:11 . 2008-12-27 03:08 -------- d-----w- c:\documents and settings\David\Application Data\DNA
2009-09-10 05:21 . 2008-12-27 03:08 -------- d-----w- c:\program files\DNA
2009-09-06 18:01 . 2009-05-24 13:32 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-09-02 17:26 . 2003-03-31 12:00 56320 ------w- c:\windows\system32\eventlog.dll
2009-08-30 07:58 . 2009-05-24 13:33 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-08-30 07:58 . 2007-05-12 19:29 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-08-30 07:58 . 2009-05-24 13:33 335240 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-08-10 12:46 . 2007-05-30 17:51 64072 ----a-w- c:\documents and settings\David\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-09 18:31 . 2009-08-09 18:31 -------- d-----w- c:\program files\MSBuild
2009-08-09 18:31 . 2009-08-09 18:31 -------- d-----w- c:\program files\Reference Assemblies
2009-08-09 18:24 . 2009-08-09 18:24 -------- d-----w- c:\program files\MSXML 6.0
2009-08-05 09:11 . 2008-03-28 10:52 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-07-30 21:21 . 2007-09-04 17:02 -------- d-----w- c:\program files\Roxio
2009-07-30 17:57 . 2009-07-17 11:51 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2009-07-30 17:57 . 2009-07-17 11:51 -------- d-----w- c:\program files\NOS
2009-07-27 06:14 . 2007-04-24 20:11 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-07-18 07:41 . 2009-07-18 07:41 -------- d-----w- c:\documents and settings\David\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2009-07-17 18:55 . 2003-03-31 12:00 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-17 11:54 . 2009-07-17 11:54 -------- d-----w- c:\program files\Common Files\Adobe AIR
2009-07-13 09:08 . 2005-01-28 12:44 286720 ----a-w- c:\windows\system32\wmpdxm.dll
2009-06-29 16:12 . 2006-06-23 10:33 827392 ------w- c:\windows\system32\wininet.dll
2009-06-29 16:12 . 2008-09-23 12:55 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-06-29 16:12 . 2003-03-31 12:00 17408 ------w- c:\windows\system32\corpol.dll
2009-06-25 08:44 . 2005-06-15 17:50 298496 ----a-w- c:\windows\system32\kerberos.dll
2009-06-25 08:44 . 2003-03-31 12:00 724480 ----a-w- c:\windows\system32\lsasrv.dll
2009-06-25 08:44 . 2003-03-31 12:00 59392 ----a-w- c:\windows\system32\wdigest.dll
2009-06-25 08:44 . 2003-03-31 12:00 56320 ----a-w- c:\windows\system32\secur32.dll
2009-06-25 08:44 . 2003-03-31 12:00 168448 ----a-w- c:\windows\system32\schannel.dll
2009-06-25 08:44 . 2003-03-31 12:00 133632 ----a-w- c:\windows\system32\msv1_0.dll
2009-06-22 11:34 . 2003-03-31 12:00 92544 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2009-06-16 14:55 . 2003-03-31 12:00 82432 ----a-w- c:\windows\system32\fontsub.dll
2009-06-16 14:55 . 2003-03-31 12:00 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-12 11:50 . 2003-03-31 12:00 76288 ----a-w- c:\windows\system32\telnet.exe
2007-11-18 10:44 . 2007-11-18 10:44 21216112 ----a-w- c:\program files\aaw2007.exe
2007-08-11 14:09 . 2007-08-11 14:09 271648 ----a-w- c:\program files\RealPlayer11BETA.exe
2007-08-04 09:23 . 2007-08-04 09:23 6890528 ----a-w- c:\program files\nvu-1.0-win32-installer-full.exe
2007-06-23 06:16 . 2007-06-23 06:16 25755448 ----a-w- c:\program files\wmp11-windowsxp-x86-enu.exe
2007-05-12 19:28 . 2007-05-12 19:28 21407888 ----a-w- c:\program files\avg75free_467a1008.exe
2007-05-02 19:16 . 2007-05-02 19:16 37873216 ----a-w- c:\program files\iTunesSetup.exe
2007-05-01 19:54 . 2007-05-01 19:54 18040176 ----a-w- c:\program files\Install_Messenger_nous.exe
2009-04-20 08:15 . 2009-04-20 08:15 8192 --sha-w- c:\windows\o2cLicStore.bin
.

------- Sigcheck -------

[-] 2009-09-02 . 6D4FEB43EE538FC5428CC7F0565AA656 . 56320 . . [5.1.2600.5512] . . c:\windows\system32\eventlog.dll
[-] 2008-04-14 . 6D4FEB43EE538FC5428CC7F0565AA656 . 56320 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\cf8ec753e88561d2ddb53e183dc05c3e\eventlog.dll
[7] 2004-08-04 . 82B24CB70E5944E6E34662205A2A5B78 . 55808 . . [5.1.2600.2180] . . c:\windows\ServicePackFiles\i386\eventlog.dll
[-] 2003-03-31 . BF3C8CF53C77B48206B39910B6D6CBCC . 49152 . . [5.1.2600.1106] . . c:\windows\$NtServicePackUninstall$\eventlog.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-09-02_17.41.52 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-09-10 05:20 . 2009-09-10 05:20 16384 c:\windows\temp\Perflib_Perfdata_73c.dat
+ 2008-01-06 17:40 . 2009-09-09 22:44 23040 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
- 2008-01-06 17:40 . 2009-08-14 02:11 23040 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
- 2008-01-06 17:40 . 2009-08-14 02:10 61440 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pubs.exe
+ 2008-01-06 17:40 . 2009-09-09 22:44 61440 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pubs.exe
+ 2008-01-06 17:40 . 2009-09-09 22:44 27136 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
- 2008-01-06 17:40 . 2009-08-14 02:11 27136 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
+ 2008-01-06 17:40 . 2009-09-09 22:44 11264 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
- 2008-01-06 17:40 . 2009-08-14 02:11 11264 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
- 2008-01-06 17:40 . 2009-08-14 02:11 86016 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\inficon.exe
+ 2008-01-06 17:40 . 2009-09-09 22:44 86016 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\inficon.exe
- 2008-01-06 17:40 . 2009-08-14 02:11 12288 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
+ 2008-01-06 17:40 . 2009-09-09 22:44 12288 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
+ 2008-01-06 17:40 . 2009-09-09 22:44 4096 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
- 2008-01-06 17:40 . 2009-08-14 02:11 4096 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
+ 2006-05-18 05:58 . 2009-08-13 15:16 512000 c:\windows\system32\jscript.dll
+ 2003-03-31 12:00 . 2009-08-13 15:16 512000 c:\windows\system32\dllcache\jscript.dll
+ 2009-09-10 05:32 . 2009-09-10 05:32 279040 c:\windows\Installer\ba843.msi
+ 2008-01-06 17:40 . 2009-09-09 22:44 409600 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
- 2008-01-06 17:40 . 2009-08-14 02:10 409600 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
- 2008-01-06 17:40 . 2009-08-14 02:10 286720 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
+ 2008-01-06 17:40 . 2009-09-09 22:44 286720 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
+ 2008-01-06 17:40 . 2009-09-09 22:44 249856 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pptico.exe
- 2008-01-06 17:40 . 2009-08-14 02:10 249856 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pptico.exe
- 2008-01-06 17:40 . 2009-08-14 02:11 794624 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\outicon.exe
+ 2008-01-06 17:40 . 2009-09-09 22:44 794624 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\outicon.exe
+ 2008-01-06 17:40 . 2009-09-09 22:44 135168 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\misc.exe
- 2008-01-06 17:40 . 2009-08-14 02:10 135168 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\misc.exe
- 2008-01-06 17:40 . 2009-08-14 02:11 593920 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\accicons.exe
+ 2008-01-06 17:40 . 2009-09-09 22:44 593920 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\accicons.exe
+ 2005-01-28 12:44 . 2009-05-20 11:24 2373504 c:\windows\system32\WMVCore.dll
+ 2005-01-28 12:44 . 2009-05-20 11:24 2373504 c:\windows\system32\dllcache\WMVCore.dll
+ 2009-08-25 13:57 . 2009-08-25 13:57 5518336 c:\windows\Installer\f4c237.msp
+ 2007-07-18 18:07 . 2009-08-28 21:38 24689600 c:\windows\system32\MRT.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
"BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2009-04-06 321344]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2007-04-19 484904]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-05-04 149040]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\System32\NvCpl.dll" [2004-10-29 4620288]
"NvMediaCenter"="c:\windows\System32\NvMcTray.dll" [2004-10-29 86016]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-11-22 136600]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-05-04 161328]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2005-05-11 49152]
"SpeedTouch USB Diagnostics"="c:\program files\Thomson\SpeedTouch USB\Dragdiag.exe" [2004-01-26 866816]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-04-02 342312]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-08-30 2007832]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"C-Media Mixer"="Mixer.exe" - c:\windows\mixer.exe [2002-07-12 1581056]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2004-10-29 921600]

c:\documents and settings\David\Start Menu\Programs\Startup\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-5-11 282624]
HP Image Zone Fast Start.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2005-5-12 73728]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-08-30 07:58 11952 ----a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\Electronic Arts\\Battlefield 2142\\BF2142.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\TVAnts\\Tvants.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=

R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2009-08-30 908056]
S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\Drivers\avgldx86.sys [2009-08-30 335240]
S1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\System32\Drivers\avgtdix.sys [2009-05-24 108552]
S2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-08-30 297752]


[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\program files\Common Files\LightScribe\LSRunOnce.exe"
.
Contents of the 'Scheduled Tasks' folder

2009-09-03 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.co.uk/
uSearchMigratedDefaultURL = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
uInternet Settings,ProxyServer = 192.168.1.1:80
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://g.msn.co.uk/0SEENGB/SAOS01?FORM=TOOLBR
IE: Add to AMV Converter... - c:\program files\MP3 Player Utilities 4.03\AMVConverter\grab.html
IE: Add to Media Manager... - c:\program files\MP3 Player Utilities 4.03\MediaManager\grab.html
IE: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-09-10 07:12
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'explorer.exe'(2636)
c:\windows\system32\WININET.dll
c:\program files\iTunes\iTunesMiniPlayer.dll
c:\program files\iTunes\iTunesMiniPlayer.Resources\en.lproj\iTunesMiniPlayerLocalized.dll
c:\program files\iTunes\iTunesMiniPlayer.Resources\iTunesMiniPlayer.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\msi.dll
.
Completion time: 2009-09-10 7:16
ComboFix-quarantined-files.txt 2009-09-10 06:16
ComboFix2.txt 2009-09-06 18:15
ComboFix3.txt 2009-09-02 17:51

Pre-Run: 91,213,275,136 bytes free
Post-Run: 91,370,786,816 bytes free

216 --- E O F --- 2009-09-09 22:46
Back to Top
 

grinaldo
New Member


Date Joined Aug 2009
Total Posts : 33
 
   Posted 9-10-2009 7:18 (GMT +1)    Quote: Help needed - redirecting virusAlert an admin about: Help needed - redirecting virus
Hello Jintan,

Above are the scans that you requested.

Thanks,
David
Back to Top
 

Jintan
Senior Member




Date Joined Dec 2006
Total Posts : 1424
 
   Posted 9-11-2009 1:07 (GMT +1)    Quote: Help needed - redirecting virusAlert an admin about: Help needed - redirecting virus
Good, that gives us any easier way to change unwanted proxy settings, and shows a suspect file as well.


Make a copy of the following list, then close Internet Explorer and all running programs and run a scan in HijackThis. Place a check next to all of the following lines, then select “Fix Checked” and close HijackThis.

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 192.168.1.1:80
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)


-----------------

To keep them from interfering with the repairs, be sure to temporarily disable all antivirus/anti-spyware softwares while these steps are being completed. This can usually be done through right clicking the software's Taskbar icons, or accessing each software through Start - Programs.



Download OTM.exe by OldTimer to your desktop.

Then click OTM.exe to run it (Vista users, please right click on OTM.exe and select "Run as an Administrator").

Copy the file path(s) below (inside the Code box) to the clipboard by highlighting ALL of them and pressing CTRL + C, or right-click and choose Copy):

:files
c:\windows\Installer\f4c237.msp
:commands
[purity]
[emptytemp]


Return to OTM, right click in the "Paste Instructions for Items to be Moved" window and select Paste. Then click the red MoveIt! button.

A log of files and folders moved will be created in the c:\_OTM\MovedFiles folder, in the form of Date and Time (mmddyyyy_hhmmss.log). Please open this log in Notepad and post its contents in your next reply.

If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose "Yes".

-----------

Disable your antivirus program and go here and run an online scan using ESET Online Scanner (you will need to use Internet Explorer for this scan, or download the installer to run it in a different browser). If you accept the Terms of Use, check the box and click Start. After the ActiveX Control has loaded, it will take a couple minutes for the scanner to get ready. Next, check the following boxes:

Remove found threats
Scan unwanted applications


Click Start. This scan may take a while, so please be patient. A log may open when the scan is complete (if not, go to C:\Program Files\EsetOnlineScanner\ and open the file log.txt). Click Edit - Select All then copy/paste that log back here please.


If you have any problems getting Eset started, one work-around is to have an open Internet connection, and then click here and download the esetsmartinstaller_enu.exe Eset installer. Then click that file, and follow the same previous steps to run the scan.

Post back that Eset log, the OTM log and a new RSIT log please.


Click here and help my friend help stop leukemia, lymphoma, Hodgkin lymphoma and myeloma from taking more lives.

Back to Top
 

grinaldo
New Member


Date Joined Aug 2009
Total Posts : 33
 
   Posted 9-11-2009 6:41 (GMT +1)    Quote: Help needed - redirecting virusAlert an admin about: Help needed - redirecting virus
All processes killed
========== FILES ==========
c:\windows\Installer\f4c237.msp moved successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes

User: All Users

User: David
->Temp folder emptied: 1571940 bytes
->Temporary Internet Files folder emptied: 40770142 bytes
->Java cache emptied: 65905 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes

User: LocalService
->Temp folder emptied: 0 bytes
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
->Temporary Internet Files folder emptied: 32969 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
File delete failed. C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
->Temporary Internet Files folder emptied: 32902 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 1119318 bytes
%systemroot%\System32 .tmp files removed: 23057 bytes
Windows Temp folder emptied: 12041 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 41.61 mb


OTM by OldTimer - Version 3.0.0.6 log created on 09112009_063754

Files moved on Reboot...

Registry entries deleted on Reboot...
Back to Top
 

Jintan
Senior Member




Date Joined Dec 2006
Total Posts : 1424
 
   Posted 9-11-2009 5:36 (GMT +1)    Quote: Help needed - redirecting virusAlert an admin about: Help needed - redirecting virus
Good - post the Eset scan log and the new RSIT log when ready and we'll review then.


Click here and help my friend help stop leukemia, lymphoma, Hodgkin lymphoma and myeloma from taking more lives.

Back to Top
 

grinaldo
New Member


Date Joined Aug 2009
Total Posts : 33
 
   Posted 9-13-2009 6:25 (GMT +1)    Quote: Help needed - redirecting virusAlert an admin about: Help needed - redirecting virus
ESETSmartInstaller@High as CAB hook log:
OnlineScanner.ocx - registred OK
# version=6
# iexplore.exe=7.00.6000.16876 (vista_gdr.090625-2339)
# OnlineScanner.ocx=1.0.0.6050
# api_version=3.0.2
# EOSSerial=77df09dc2c92c243ac04b1120cf436c9
# end=finished
# remove_checked=true
# archives_checked=false
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2009-09-13 05:12:04
# local_time=2009-09-13 06:12:04 (+0000, GMT Daylight Time)
# country="United States"
# lang=1033
# osver=5.1.2600 NT Service Pack 2
# compatibility_mode=1026 37 83 95 12427908441387
# scanned=68927
# found=0
# cleaned=0
# scan_time=2090
Back to Top
 

Jintan
Senior Member




Date Joined Dec 2006
Total Posts : 1424
 
   Posted 9-13-2009 10:23 (GMT +1)    Quote: Help needed - redirecting virusAlert an admin about: Help needed - redirecting virus
smile The new RSIT log too please.


Click here and help my friend help stop leukemia, lymphoma, Hodgkin lymphoma and myeloma from taking more lives.

Back to Top
 

grinaldo
New Member


Date Joined Aug 2009
Total Posts : 33
 
   Posted 9-13-2009 11:05 (GMT +1)    Quote: Help needed - redirecting virusAlert an admin about: Help needed - redirecting virus
Hi Jintan,

Thanks for sticking with me I have had trouble finding time to get online in the last couple of days.

I am still unable to run RSIT

When I try to re-download I get "Cannot copy RSIT:Access id denied. Make sure that the disk is not full or write-protected and that the file is not currently in use"

When I try to run without downloading to desktop I get "Autolt Error Error: Variable used without being declared"
Back to Top
 

Jintan
Senior Member




Date Joined Dec 2006
Total Posts : 1424
 
   Posted 9-15-2009 3:23 (GMT +1)    Quote: Help needed - redirecting virusAlert an admin about: Help needed - redirecting virus
Seems like an unseen rootkit there, or a similar issue. Let's see if we can locate and disable it when it is vulnerable.

I have not used the following method recently, so my steps may not quite match what you see there.

listsvc
dir c:\windows\system32\drivers


Open Notepad (Start - Run, type notepad and press Enter).

Copy/paste the above text (inside the Code box) into the open text box, then save this to your C:\Windows folder as "servcheck.bat"

It should then be C:\Windows\servcheck.bat (important)

-------------------

Reboot, and at the boot options screen select the following:

Microsoft Windows Recovery Console


If you are given the option, enter the number for the appropriate Windows installation (usually #1), Windows will then prompt you to enter the Administrator account password if one was created (if one was not created then just press Enter).

At the prompt type the following, pressing Enter after each:

cd C:\windows

batch servcheck.bat c:\windows\servicelook.txt

exit


When you hit Enter after typing exit your computer will reboot. Do Not press any key until the system has completely rebooted, then after the reboot be sure to remove your XP CD from the CD-ROM drive.

Then locate and post back here the contents of c:\windows\servicelook.txt please.


Click here and help my friend help stop leukemia, lymphoma, Hodgkin lymphoma and myeloma from taking more lives.

Back to Top
 

mat3150
New Member


Date Joined Sep 2009
Total Posts : 8
 
   Posted 9-15-2009 4:27 (GMT +1)    Quote: Help needed - redirecting virusAlert an admin about: Help needed - redirecting virus
i am not very good with computer. computer has a redirecting virus. how do i get rid of it. remember i'm not to good on computer. could you take me step to step
Back to Top
 

Jintan
Senior Member




Date Joined Dec 2006
Total Posts : 1424
 
   Posted 9-16-2009 12:55 (GMT +1)    Quote: Help needed - redirecting virusAlert an admin about: Help needed - redirecting virus
Welcome to BullGuard forums mat3150. You need to wait for a response in the new thread you posted, so please no posting in other people's requests. Interrupts the flow of things. Post the log when ready grinaldo and we will review then.


Click here and help my friend help stop leukemia, lymphoma, Hodgkin lymphoma and myeloma from taking more lives.

Back to Top
 

grinaldo
New Member


Date Joined Aug 2009
Total Posts : 33
 
   Posted 9-19-2009 7:00 (GMT +1)    Quote: Help needed - redirecting virusAlert an admin about: Help needed - redirecting virus
Hi Jintan,

I tried going through the windows recovery console but when I do that all I get is a blank screen with flashing cursor. Did a little digging and I though I had an issue in as much as my Windows CD is SP1 I am now on SP2? I did a little more googling and tried to follow the advice to ugrade but cannot get away from the blank screen and flashing cursor.

I do not know what is more frustrating, this darn virus or my lack of knowledge!!!

Any help you can give me is (as always) appreciated.

Thanks, David
Back to Top
 

Jintan
Senior Member




Date Joined Dec 2006
Total Posts : 1424
 
   Posted 9-19-2009 11:58 (GMT +1)    Quote: Help needed - redirecting virusAlert an admin about: Help needed - redirecting virus
I sense it is an issue with either the disk, or the CD drive itself. Time to redirect our energies then. FYI - it has been my experience that, for access to the Recovery Console for just the use of the Windows commands, like we were intending, different Service Pack disks can be used.


See if you can click and get the Win32kDiag.exe to run, then follow the prompts from that and post back the Win32kDiag.txt log it creates on the desktop please.


Click here and help my friend help stop leukemia, lymphoma, Hodgkin lymphoma and myeloma from taking more lives.

Back to Top
 

grinaldo
New Member


Date Joined Aug 2009
Total Posts : 33
 
   Posted 9-21-2009 11:26 (GMT +1)    Quote: Help needed - redirecting virusAlert an admin about: Help needed - redirecting virus
Hello Jintan,

I ran the Win32kDiag as requested but all that was retuned was the below....should there be more than this?

Thanks



Log file is located at: C:\Documents and Settings\David\Desktop\Win32kDiag.txt

WARNING: Could not get backup privileges!

Searching 'C:\WINDOWS'...





Finished!
Back to Top
 

Jintan
Senior Member




Date Joined Dec 2006
Total Posts : 1424
 
   Posted 9-22-2009 2:14 (GMT +1)    Quote: Help needed - redirecting virusAlert an admin about: Help needed - redirecting virus
Have the RSIT.exe file on your desktop. Click here and download Inherit.exe to your desktop. Then for now just drag RSIT.exe into the Inherit.exe file. Once it completes the permissions changes it makes, a "Finish" popup showing "OK" should appear. Just click the OK button to close that.

Then try to run the RSIT scan again please.


Click here and help my friend help stop leukemia, lymphoma, Hodgkin lymphoma and myeloma from taking more lives.

Back to Top
 

Jintan
Senior Member




Date Joined Dec 2006
Total Posts : 1424
 
   Posted 9-22-2009 2:15 (GMT +1)    Quote: Help needed - redirecting virusAlert an admin about: Help needed - redirecting virus
Forgot to answer your question. Yes, if no malware folder "junction" tricks remain, the Win32kDiag log will be very short like that.


Click here and help my friend help stop leukemia, lymphoma, Hodgkin lymphoma and myeloma from taking more lives.

Back to Top
 

grinaldo
New Member


Date Joined Aug 2009
Total Posts : 33
 
   Posted 9-23-2009 12:33 (GMT +1)    Quote: Help needed - redirecting virusAlert an admin about: Help needed - redirecting virus
Hi Jintan,

Inherit.exe downloaded as requested and RSIT dragged. I am still unable to run RSIT though (Error message about line -1 variable used without being declared). I am able to delete the file from desktop though but when I re-save the RSIT file I receive the same error message.
Back to Top
 

Jintan
Senior Member




Date Joined Dec 2006
Total Posts : 1424
 
   Posted 9-23-2009 2:40 (GMT +1)    Quote: Help needed - redirecting virusAlert an admin about: Help needed - redirecting virus
smile I read back through some of the posts and see I really misread what you had posted - I had read the redirects are still occurring. And so tied that with Desktop issues there, and started seeking malware afresh. RSIT, and I think HijackThis, but are compiled using an AutoIt software, and it's that software's script that shows that variable error. Let's just check to make sure no access is being blocked that AutoIt or RSIT requires to run.

Download MS Sysinternal's Junction.zip from here to your desktop, then unzip that. Then in that folder locate the Junction.exe file, and place a copy of that directly on your desktop.

Go to Start - Run, and copy/paste the following command line, and then press OK:

cmd /c "%userprofile%\desktop\junction.exe" -s c:\ >log.txt&log.txt

Once that completes a log.txt will open in Notepad. Paste those contents back here please.


Click here and help my friend help stop leukemia, lymphoma, Hodgkin lymphoma and myeloma from taking more lives.

Back to Top
 

grinaldo
New Member


Date Joined Aug 2009
Total Posts : 33
 
   Posted 9-23-2009 7:31 (GMT +1)    Quote: Help needed - redirecting virusAlert an admin about: Help needed - redirecting virus

Junction v1.05 - Windows junction creator and reparse point viewer
Copyright (C) 2000-2007 Mark Russinovich
Systems Internals - http://www.sysinternals.com

Failed to open \\?\c:\\pagefile.sys: The process cannot access the file because it is being used by another process.

...
    
.
Failed to open \\?\c:\\Documents and Settings\David\Desktop\hijackthis\HijackThis.exe: Access is denied.


    
...
Failed to open \\?\c:\\Program Files\AVG\AVG8\avgcsrvx.exe: Access is denied.
 
    
...

...
Failed to open \\?\c:\\Program Files\Trend Micro\David.exe: Access is denied.
 
Failed to open \\?\c:\\Program Files\Trend Micro\HijackThis\HijackThis.exe: Access is denied.
 
Failed to open \\?\c:\\Program Files\Windows Defender\MsMpEng.exe: Access is denied.
 
    
...
    
.
Failed to open \\?\c:\\System Volume Information\MountPointManagerRemoteDatabase: Access is denied.

..
    
...
    
.\\?\c:\\WINDOWS\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a: JUNCTION
   Print Name     : C:\WINDOWS\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790
   Substitute Name: C:\WINDOWS\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790
\\?\c:\\WINDOWS\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a: JUNCTION
   Print Name     : C:\WINDOWS\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e
   Substitute Name: C:\WINDOWS\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e
..
Back to Top
 

Jintan
Senior Member




Date Joined Dec 2006
Total Posts : 1424
 
   Posted 9-23-2009 1:21 (GMT +1)    Quote: Help needed - redirecting virusAlert an admin about: Help needed - redirecting virus
That shows why things weren't work right there. I can't quite tell how that log should be, with the forum hyperlinking. And no RSIT example. If one is not there place a copy of RSIT.exe on the desktop, then run that same scan step again.

Then email the log from that as an attachment to jintan AT malwarecrypt.com (replace the "AT" with @). Please place "Submitted Files - grinaldo/bg/junctions" as the email Subject.


Click here and help my friend help stop leukemia, lymphoma, Hodgkin lymphoma and myeloma from taking more lives.

Back to Top
 
New Topic Post reply to : Help needed - redirecting virus Printable version of : Help needed - redirecting virus
62 posts in this thread.
Viewing Page :
 1  2  3 
 
Forum Information
Currently it is Sunday, March 14, 2010 1:43 AM (GMT +1)
There are a total of 76.176 posts in 17.594 threads.
In the last 3 days there were 5 new threads and 68 reply posts. View Active Threads
Who's Online
This forum has 31130 registered members. Please welcome our newest member, Ibot.
29 Guest(s), 1 Registered Member(s) are currently online.  Details
Ibot
5 Latest Threads
I also have a Re-direct Virus (3)13-03-2010 23:59:10 (baronv)
Unable to download adobe updates (3)13-03-2010 22:18:00 (LANEYM)
Firewall bullguard 9 (1)13-03-2010 21:10:39 (Dickens)
Redirect Virus (33)13-03-2010 16:29:10 (markusg)
How to remove a redirect virus that also stops my Antivirus for updating (5)13-03-2010 15:11:01 (markusg)