System Alert! Message VIRUS HELP!! URGENT!!
reeceb New Member Date Joined Dec 2006 Total Posts : 3 Posted 12-26-2006 12:36 (GMT +1) Hi, I keep getting a message saying "Download the appropriate software to remove this virus" and it opens up with Anti Vermins site. I did a huge virus and trojan scan and i got rid of some nasty viruses and mysterious programs and folders in my C Drive, and im pretty confident the trojan is gone.. but i keep getting this "System Alert!" message. Please help me get rid of this, here is a log file Logfile of HijackThis v1.99.1 Scan saved at 8:29:24 PM, on 26/12/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.5730.0011) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe C:\WINDOWS\system32\spoolsv.exe C:\Progra~1\Altiris\AClient\AClient.exe C:\Program Files\Altiris\Altiris Agent\AeXNSAgent.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe C:\WINDOWS\system32\ccsrvc.exe C:\Program Files\Network Associates\Common Framework\FrameworkService.exe C:\Program Files\Altiris\Carbon Copy\shellker.exe C:\Program Files\Network Associates\VirusScan\mcshield.exe C:\Program Files\Network Associates\VirusScan\vstskmgr.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\wbem\wmiapsrv.exe C:\PROGRA~1\Altiris\CARBON~1\client.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\00THotkey.exe C:\WINDOWS\System32\taskswitch.exe C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe C:\Progra~1\Altiris\AClient\AClntUsr.EXE C:\WINDOWS\system32\hkcmd.exe C:\WINDOWS\system32\igfxpers.exe C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE C:\Program Files\Common Files\Network Associates\TalkBack\tbmon.exe C:\WINDOWS\system32\TPWRTRAY.EXE C:\WINDOWS\system32\TFNF5.exe C:\Program Files\TOSHIBA\Wireless Hotkey\TosHKCW.exe C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe C:\WINDOWS\system32\EZSP_PX.EXE C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe C:\Program Files\MessengerPlus! 3\MsgPlus.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\TGTSoft\StyleXP\StyleXP.exe C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\WinRAR\WinRAR.exe C:\DOCUME~1\bakerrf\LOCALS~1\Temp\Rar$EX00.061\HijackThis.exe C:\DOCUME~1\bakerrf\LOCALS~1\Temp\Rar$EX01.573\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Hale School R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://antares/proxy.dat O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O3 - Toolbar: Protection Bar - {0D045BAA-4BD3-4C94-BE8B-21536BD6BD9F} - (no file) O4 - HKLM\..\Run: [00THotkey] C:\WINDOWS\system32\00THotkey.exe O4 - HKLM\..\Run: [000StTHK] 000StTHK.exe O4 - HKLM\..\Run: [CoolSwitch] C:\WINDOWS\System32\taskswitch.exe O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey O4 - HKLM\..\Run: [AClntUsr] C:\Progra~1\Altiris\AClient\AClntUsr.EXE O4 - HKLM\..\Run: [AeXAgentLogon] "C:\Program Files\Altiris\Altiris Agent\AeXAgentActivate.exe" /logon O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\tbmon.exe" O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName O4 - HKLM\..\Run: [Tpwrtray] TPWRTRAY.EXE O4 - HKLM\..\Run: [TFNF5] TFNF5.exe O4 - HKLM\..\Run: [TosHKCW.exe] "C:\Program Files\TOSHIBA\Wireless Hotkey\TosHKCW.exe" O4 - HKLM\..\Run: [TFncKy] TFncKy.exe O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\system32\EZSP_PX.EXE O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [STYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide O4 - HKCU\..\Run: [SpywareBot] C:\Program Files\SpywareBot\SpywareBot.exe -boot O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: Bluetooth Manager.lnk = ? O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O11 - Options group: [INTERNATIONAL] International* O14 - IERESET.INF: START_PAGE_URL=http://intranet.hale.wa.edu.au/ O15 - Trusted Zone: http://antares.hale.wa.edu.au O15 - Trusted Zone: http://intranet.hale.wa.edu.au O15 - Trusted Zone: http://www.hale.wa.edu.au O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = students.hale.wa.edu.au O17 - HKLM\Software\..\Telephony: DomainName = students.hale.wa.edu.au O17 - HKLM\System\CCS\Services\Tcpip\..\{23AAF6CA-9E61-4E25-BA06-76D314BFEEE8}: Domain = students.hale.wa.edu.au O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = students.hale.wa.edu.au O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O20 - AppInit_DLLs: AMInit.dll O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O21 - SSODL: buprestidae - {b59f3ba4-98da-4b5f-8a2d-7b56fb11140b} - C:\WINDOWS\system32\cthkpcv.dll O23 - Service: Altiris Client Service (AClient) - Altiris, Inc. - C:\Progra~1\Altiris\AClient\AClient.exe O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: Altiris Agent (AeXNSClient) - Altiris, Inc. - C:\Program Files\Altiris\Altiris Agent\AeXNSAgent.exe O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe O23 - Service: Altiris Carbon Copy (CarbonCopy32) - Altiris - C:\WINDOWS\system32\ccsrvc.exe O23 - Service: Carbon Copy Scheduler (CarbonCopyScheduler) - Altiris - C:\WINDOWS\system32\schdsrvc.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\mcshield.exe O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\vstskmgr.exe O23 - Service: MySQL - Unknown owner - C:\Program.exe (file missing) O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\HPZipm12.exe O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe Back to Top
Tron Trusted Member Date Joined Oct 2006 Total Posts : 290 Posted 12-26-2006 3:20 (GMT +1)
Your Java is out of date.
o Please navigate to Control Panel.
o Double click Java icon, select 'update ' tab ( location - Top left of 'Java Control Panel' window )
o Click 'update now ', follow the the next set of prompts.
Re-open HiJackThis and scan. Check the boxes next to all the entries listed below (if present ):
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = O3 - Toolbar: Protection Bar - {0D045BAA-4BD3-4C94-BE8B-21536BD6BD9F} - (no file)O4 - HKCU\..\Run: [SpywareBot] C:\Program Files\SpywareBot\SpywareBot.exe -boot O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present O21 - SSODL: buprestidae - {b59f3ba4-98da-4b5f-8a2d-7b56fb11140b} - C:\WINDOWS\system32\cthkpcv.dll
O4 - HKCU\..\Run: - This entry is an optional clean. SpywareBot is a rouge Antispyware program that delivers false positives to goad the user into purchasing the program. You can either choose to clean or keep this program, but I would recommend cleaning it.
Now close all windows other than HiJackThis , then click Fix Checked. Close HiJackThis.
Boot into safe mode (you can do this by switching off your machine, and continually tap the F8 key at first blank screen ).
Please navigate to Add/Remove programs and uninstall the following programs:
SpywareBot
Using Windows Explorer (to get there right-click your Start button and go to "Explore "), please delete this file/s (if present ):
C:\Program Files\ SpywareBot
Boot to normal windows.
Download SmitfraudFix (by S!Ri ) to your Desktop.
Extract all the files to your Destop.
A folder named SmitfraudFix will be created on your Desktop.
o Reboot your computer in Safe Mode (before the Windows icon appears, tap the F8 key continuall y)
o Double-click smitfraudfix.cmd
o Select 2 and hit Enter to delete infect files.
o You will be prompted: Do you want to clean the 'Registry?'
answer Y (yes ) and hit Enter in order to remove the Desktop background and clean registry keys associated with the infection.
o The tool will now check if wininet.dll is infected. You may be prompted to replace the infected file (if found ):
Replace infected file ? answer Y (yes ) and hit Enter to restore a clean file.
o A reboot may be needed to finish the cleaning process.
The report can be found at the root of the system drive, usually at C:\rapport.txt
When installation has completed, click 'Scan your computer'.
Next, place a tick in the box of the drive you would like to scan eg. (A) (C) (D) (E)
Make sure 'Perform complete scan' is ticked, then click 'Next'.
When scanning has completed, place a tick next to all infections found, then click 'Next'.
If your machine requires a reboot, let it reboot.
After reboot, re-open Superantispyware.
Click 'Preferences' and then click 'statistics/logs' tab.
Click the dated log and click 'view log' a text file will appear.
Copy&Paste the results of the text file here, C:\rapport.txt logfile, and a fresh HijackThis logfile.
Kind Regards.
Tron.
NOTE: You may be asked to download various tools to aid with system repair.
These tools are essential in the clean up of your machine,
and can be removed after cleaning has transpired (Optional ).
Back to Top
reeceb New Member Date Joined Dec 2006 Total Posts : 3 Posted 12-26-2006 4:13 (GMT +1) I fixed all those files you told me too from Hijack this, and then rebooted my computer and now the message is gone. I also removed Spyware Bot from my C: drive. My school has restricted me from accessing safe mode, but do I need to now that I have got rid of the message? Back to Top
Tron Trusted Member Date Joined Oct 2006 Total Posts : 290 Posted 12-27-2006 7:24 (GMT +1) Hi Reeceb. Can you please follow all of the above instructions without entering into safe mode. I need to see the logs asked for to ascertain the infection. Tron.
NOTE: You may be asked to download various tools to aid with system repair.
These tools are essential in the clean up of your machine,
and can be removed after cleaning has transpired (Optional ).
Back to Top
reeceb New Member Date Joined Dec 2006 Total Posts : 3 Posted 12-28-2006 6:12 (GMT +1) Ok, here's the SUPERAntiSpyware log. SUPERAntiSpyware Scan Log Generated 12/27/2006 at 00:23 AM Application Version : 3.4.1000 Core Rules Database Version : 3143 Trace Rules Database Version: 1159 Scan type : Complete Scan Total Scan Time : 00:07:14 Memory items scanned : 555 Memory threats detected : 0 Registry items scanned : 7374 Registry threats detected : 0 File items scanned : 720 File threats detected : 0 Back to Top
Tron Trusted Member Date Joined Oct 2006 Total Posts : 290 Posted 12-28-2006 1:25 (GMT +1) Hi Reeceb. C:\rapport.txt logfile, and a fresh HijackThis logfile?? Tron.
NOTE: You may be asked to download various tools to aid with system repair.
These tools are essential in the clean up of your machine,
and can be removed after cleaning has transpired (Optional ).
Back to Top
Forum Information Currently it is Thursday, March 11, 2010 1:25 PM (GMT +1) There are a total of 76.111 posts in 17.589 threads. In the last 3 days there were 13 new threads and 75 reply posts. View Active Threads Who's Online This forum has 31118 registered members. Please welcome our newest member, Logz10 . 22 Guest(s), 1 Registered Member(s) are currently online. Details markusg 5 Latest Threads