I'm a bit new (brand new) to virus removal and it seems like I might have a couple lurking inside my computer... Can anyone suggest anything that could help? I have a free AVG at the moment that has come up with the below, but can't actually get rid of them!
"Infection";"Trojan horse PSW.Lineage.BVE";"C:\DOCUME~1\Rozi\LOCALS~1\Temp\E_N4\krnln.fnr";"";"28/08/2010, 12:27:56" "Infection";"Virus found Win32/Heur";"C:\DOCUME~1\Rozi\LOCALS~1\Temp\E_N4\eCompress.fne";"";"28/08/2010, 12:27:59" "Infection";"Virus found Win32/Heur";"C:\DOCUME~1\Rozi\LOCALS~1\Temp\E_N4\RegEx.fnr";"";"28/08/2010, 12:28:00" "Infection";"Virus found Win32/Heur";"C:\DOCUME~1\Rozi\LOCALS~1\Temp\E_N4\spec.fne";"";"28/08/2010, 12:28:00" "Infection";"Trojan horse PSW.Lineage.BVE";"C:\WINDOWS\system32\758E8C\krnln.fnr";"";"28/08/2010, 12:28:33" "Infection";"Virus found Win32/Heur";"C:\DOCUME~1\Rozi\LOCALS~1\Temp\E_N4\RegEx.fnr";"";"28/08/2010, 12:43:02" "Infection";"Virus found Win32/Heur";"C:\DOCUME~1\Rozi\LOCALS~1\Temp\E_N4\eCompress.fne";"";"28/08/2010, 13:16:34" "Infection";"Trojan horse PSW.Lineage.BVE";"C:\DOCUME~1\Rozi\LOCALS~1\Temp\E_N4\krnln.fnr";"";"28/08/2010, 13:16:40" "Infection";"Virus found Win32/Heur";"C:\DOCUME~1\Rozi\LOCALS~1\Temp\E_N4\spec.fne";"";"28/08/2010, 13:16:44" "Infection";"Trojan horse PSW.Lineage.BVE";"C:\WINDOWS\system32\457C85\74C6C2.EXE";"";"28/08/2010, 13:16:47" "Warning";"Found Tracking cookie.Revsci";"C:\Documents and Settings\Rozi\Application Data\Mozilla\Firefox\Profiles\c7fua2fi.default\cookies.sqlite";"";"28/08/2010, 13:17:14" "Infection";"Trojan horse PSW.Lineage.BVE";"C:\DOCUME~1\Rozi\LOCALS~1\Temp\E_N4\krnln.fnr";"";"01/09/2010, 23:09:57" "Infection";"Virus found Win32/Heur";"C:\DOCUME~1\Rozi\LOCALS~1\Temp\E_N4\eCompress.fne";"";"01/09/2010, 23:10:01" "Infection";"Trojan horse Generic2_c.BMHD";"c:\WINDOWS\system32\4FBC81\wif8ffe.exe";"";"06/09/2010, 19:19:27" "Infection";"Trojan horse Generic2_c.BMHD";"c:\WINDOWS\system32\4FBC81\wif8ffe.exe";"";"06/09/2010, 23:20:58"
Ahh, right ok, thanks Ive done that... Here's the info that you requested...
Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 22:30:58, on 08/09/2010 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v8.00 (8.00.6001.18702) Boot mode: Normal
Files\AVG\AVG9\avgwdsvc.exe O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth
Software\bin\btwdins.exe O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common
Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program
Memory Processes Infected: (No malicious items detected)
Memory Modules Infected: C:\Documents and Settings\Rozi\Local Settings\Temp\E_N4\krnln.fnr (Trojan.Agent) -> Delete on reboot. C:\Documents and Settings\Rozi\Local Settings\Temp\E_N4\HtmlView.fne (HackTool.Patcher) -> Delete on reboot. C:\Documents and Settings\Rozi\Local Settings\Temp\E_N4\internet.fne (HackTool.Patcher) -> Delete on reboot.
Registry Keys Infected: (No malicious items detected)
Registry Values Infected: (No malicious items detected)
Registry Data Items Infected: (No malicious items detected)
Folders Infected: C:\Documents and Settings\Rozi\Local Settings\Temp\E_N4 (Worm.Autorun) -> Delete on reboot.
Files Infected: C:\Documents and Settings\Rozi\Local Settings\Temp\E_N4\krnln.fnr (Trojan.Agent) -> Delete on reboot. C:\Documents and Settings\Rozi\Local Settings\Temp\E_N4\HtmlView.fne (HackTool.Patcher) -> Delete on reboot. C:\Documents and Settings\Rozi\Local Settings\Temp\E_N4\internet.fne (HackTool.Patcher) -> Delete on reboot. C:\Documents and Settings\Rozi\Local Settings\Temp\E_N4\cnvpe.fne (Worm.Autorun) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{0D0FB848-E68F-4A1D-9352-35082FC643ED}\RP239\A0050440.rbf (Adware.WidgiToolbar) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{0D0FB848-E68F-4A1D-9352-35082FC643ED}\RP239\A0050443.rbf (Adware.WidgiToolbar) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{0D0FB848-E68F-4A1D-9352-35082FC643ED}\RP239\A0050444.rbf (Adware.WidgiToolbar) -> Quarantined and deleted successfully. C:\WINDOWS\system32\17B65B\cnvpe.fne (Worm.Autorun) -> Quarantined and deleted successfully. C:\WINDOWS\system32\17B65B\HtmlView.fne (HackTool.Patcher) -> Quarantined and deleted successfully. C:\WINDOWS\system32\17B65B\internet.fne (HackTool.Patcher) -> Quarantined and deleted successfully. C:\WINDOWS\system32\17B65B\krnln.fnr (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\system32\4FBC81\cnvpe.fne (Worm.Autorun) -> Quarantined and deleted successfully. C:\WINDOWS\system32\4FBC81\HtmlView.fne (HackTool.Patcher) -> Quarantined and deleted successfully. C:\WINDOWS\system32\4FBC81\internet.fne (HackTool.Patcher) -> Quarantined and deleted successfully. C:\WINDOWS\system32\4FBC81\krnln.fnr (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\system32\758E8C\cnvpe.fne (Worm.Autorun) -> Quarantined and deleted successfully. C:\WINDOWS\system32\758E8C\HtmlView.fne (HackTool.Patcher) -> Quarantined and deleted successfully. C:\WINDOWS\system32\758E8C\internet.fne (HackTool.Patcher) -> Quarantined and deleted successfully. C:\WINDOWS\system32\758E8C\krnln.fnr (Trojan.Agent) -> Quarantined and deleted successfully. C:\Documents and Settings\Rozi\Local Settings\Temp\E_N4\dp1.fne (Worm.Autorun) -> Delete on reboot. C:\Documents and Settings\Rozi\Local Settings\Temp\E_N4\eAPI.fne (Worm.Autorun) -> Delete on reboot. C:\Documents and Settings\Rozi\Local Settings\Temp\E_N4\eCompress.fne (Worm.Autorun) -> Delete on reboot. C:\Documents and Settings\Rozi\Local Settings\Temp\E_N4\RegEx.fnr (Worm.Autorun) -> Delete on reboot. C:\Documents and Settings\Rozi\Local Settings\Temp\E_N4\shell.fne (Worm.Autorun) -> Delete on reboot. C:\Documents and Settings\Rozi\Local Settings\Temp\E_N4\spec.fne (Worm.Autorun) -> Delete on reboot.
DDS (Ver_10-03-17.01) - NTFSx86 Run by Rozi at 22:25:55.29 on 08/09/2010 Internet Explorer: 8.0.6001.18702 Microsoft Windows XP Professional 5.1.2600.3.1252.44.1033.18.1014.254 [GMT 8:00]
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_10-03-17.01)
Microsoft Windows XP Professional Boot Device: \Device\HarddiskVolume2 Install Date: 11/12/2009 23:04:04 System Uptime: 09/08/2010 22:13:54 (720 hours ago)
RP234: 11/06/2010 07:01:20 - System Checkpoint RP235: 11/06/2010 12:28:30 - Software Distribution Service 3.0 RP236: 11/06/2010 21:20:51 - Installed Java(TM) 6 Update 20 RP237: 16/06/2010 00:42:40 - Installed Rosetta Stone V3. RP238: 17/06/2010 01:53:06 - System Checkpoint RP239: 17/06/2010 23:08:44 - Removed Dealio Toolbar v4.0.2. RP240: 17/06/2010 23:56:53 - Removed Rosetta Stone V3. RP241: 18/06/2010 00:08:44 - Installed Rosetta Stone V3. RP242: 18/06/2010 00:29:01 - Removed Rosetta Stone V3. RP243: 18/06/2010 00:30:25 - Installed Rosetta Stone V3. RP244: 18/06/2010 00:30:52 - Installed Rosetta Stone V3. RP245: 18/06/2010 00:38:54 - Installed Rosetta Stone V3. RP246: 18/06/2010 01:10:23 - SPTD setup V1.69 RP247: 18/06/2010 01:28:30 - Removed Rosetta Stone V3. RP248: 18/06/2010 20:42:36 - Installed Rosetta Stone Version 3 RP249: 20/06/2010 08:15:47 - System Checkpoint RP250: 22/06/2010 03:04:02 - System Checkpoint RP251: 24/06/2010 16:00:25 - Software Distribution Service 3.0 RP252: 25/06/2010 07:47:56 - Avg Update RP253: 28/06/2010 01:10:29 - System Checkpoint RP254: 06/07/2010 06:50:41 - System Checkpoint RP255: 07/07/2010 07:15:49 - System Checkpoint RP256: 10/07/2010 08:32:51 - System Checkpoint RP257: 11/07/2010 09:25:02 - System Checkpoint RP258: 13/07/2010 03:58:20 - System Checkpoint RP259: 14/07/2010 23:39:08 - Software Distribution Service 3.0 RP260: 16/07/2010 21:25:46 - Avg Update RP261: 16/07/2010 21:27:02 - Avg Update RP262: 18/07/2010 22:58:55 - System Checkpoint RP263: 20/07/2010 12:10:31 - System Checkpoint RP264: 25/07/2010 10:00:37 - System Checkpoint RP265: 27/07/2010 18:05:59 - System Checkpoint RP266: 29/07/2010 06:16:52 - System Checkpoint RP267: 30/07/2010 07:35:08 - System Checkpoint RP268: 03/08/2010 01:59:26 - System Checkpoint RP269: 05/08/2010 15:01:08 - System Checkpoint RP270: 06/08/2010 16:39:44 - System Checkpoint RP271: 08/08/2010 01:57:33 - System Checkpoint RP272: 09/08/2010 22:47:56 - System Checkpoint RP273: 10/08/2010 21:44:36 - Software Distribution Service 3.0 RP274: 17/08/2010 22:10:39 - System Checkpoint RP275: 18/08/2010 22:13:45 - System Checkpoint RP276: 20/08/2010 15:58:14 - System Checkpoint RP277: 24/08/2010 17:44:28 - System Checkpoint RP278: 26/08/2010 00:11:20 - Avg Update RP279: 26/09/2010 11:06:21 - System Checkpoint RP280: 26/09/2010 11:38:17 - Software Distribution Service 3.0 RP281: 03/09/2010 04:29:56 - System Checkpoint RP282: 04/09/2010 05:20:29 - System Checkpoint RP283: 07/09/2010 01:13:59 - System Checkpoint RP284: 08/09/2010 01:29:14 - System Checkpoint RP285: 08/09/2010 19:25:59 - Removed Java(TM) 6 Update 16 RP286: 08/09/2010 22:11:28 - Removed Java(TM) 6 Update 17 RP287: 08/09/2010 22:27:01 - Installed Java(TM) 6 Update 21
==== Installed Programs ======================
Adobe Download Manager Adobe Flash Player 10 Plugin Adobe Flash Player ActiveX Adobe Reader 9.3.4 Alarm Clock v1.0 Apple Application Support Apple Mobile Device Support Apple Software Update Atheros WLAN Client µTorrent AVG Free 9.0 BatteryLifeExtender Bonjour CCleaner Easy Display Manager Easy Network Manager Easy Resolution Manager Facebook Plug-In Free Mp3 Wma Converter V 1.9 GOM Player Google Chrome Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) Hotfix for Windows Media Format 11 SDK (KB929399) Hotfix for Windows XP (KB952287) Hotfix for Windows XP (KB954550-v5) Hotfix for Windows XP (KB961118) Hotfix for Windows XP (KB976098-v2) Hotfix for Windows XP (KB979306) Hotfix for Windows XP (KB981793) imagine digital freedom - Samsung Intel(R) Graphics Media Accelerator Driver iTunes Java Auto Updater Java(TM) 6 Update 21 Magic FLAC to MP3 Converter 3.72 Magic Keyboard MagicDisc 2.7.106 Malwarebytes' Anti-Malware Marvell Miniport Driver Microsoft .NET Framework 2.0 Service Pack 2 Microsoft .NET Framework 3.0 Service Pack 2 Microsoft .NET Framework 3.5 SP1 Microsoft .NET Framework Client Profile Microsoft User-Mode Driver Framework Feature Pack 1.0 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Mozilla Firefox (3.6.9) MPEG2 Codec(libmpeg2/mad) MyDefrag v4.2.6 Namuga 1.3M Webcam OpenOffice.org 3.1 Paint.NET v3.5.3 proXPN 2.2.7 QuickTime Realtek High Definition Audio Driver Rosetta Stone Version 3 Samsung Battery Manager Samsung Magic Doctor Samsung Recovery Solution III Samsung Update Plus Search Settings v1.2.3 Security Update for Windows Internet Explorer 8 (KB2183461) Security Update for Windows Internet Explorer 8 (KB971961) Security Update for Windows Internet Explorer 8 (KB976325) Security Update for Windows Internet Explorer 8 (KB978207) Security Update for Windows Internet Explorer 8 (KB981332) Security Update for Windows Internet Explorer 8 (KB982381) Security Update for Windows Media Player (KB911564) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player (KB954155) Security Update for Windows Media Player (KB968816) Security Update for Windows Media Player (KB973540) Security Update for Windows Media Player (KB978695) Security Update for Windows Media Player (KB979402) Security Update for Windows Media Player 8 (KB917734) Security Update for Windows Media Player 9 (KB911565) Security Update for Windows XP (KB2079403) Security Update for Windows XP (KB2115168) Security Update for Windows XP (KB2160329) Security Update for Windows XP (KB2229593) Security Update for Windows XP (KB2286198) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951066) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956744) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB956844) Security Update for Windows XP (KB957097) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958687) Security Update for Windows XP (KB958869) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960225) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB960859) Security Update for Windows XP (KB961371-v2) Security Update for Windows XP (KB961501) Security Update for Windows XP (KB969059) Security Update for Windows XP (KB969947) Security Update for Windows XP (KB970238) Security Update for Windows XP (KB970430) Security Update for Windows XP (KB971468) Security Update for Windows XP (KB971486) Security Update for Windows XP (KB971557) Security Update for Windows XP (KB971633) Security Update for Windows XP (KB971657) Security Update for Windows XP (KB972270) Security Update for Windows XP (KB973354) Security Update for Windows XP (KB973507) Security Update for Windows XP (KB973525) Security Update for Windows XP (KB973869) Security Update for Windows XP (KB973904) Security Update for Windows XP (KB974112) Security Update for Windows XP (KB974318) Security Update for Windows XP (KB974392) Security Update for Windows XP (KB974571) Security Update for Windows XP (KB975025) Security Update for Windows XP (KB975467) Security Update for Windows XP (KB975560) Security Update for Windows XP (KB975561) Security Update for Windows XP (KB975562) Security Update for Windows XP (KB975713) Security Update for Windows XP (KB976325) Security Update for Windows XP (KB977165) Security Update for Windows XP (KB977816) Security Update for Windows XP (KB977914) Security Update for Windows XP (KB978037) Security Update for Windows XP (KB978251) Security Update for Windows XP (KB978262) Security Update for Windows XP (KB978338) Security Update for Windows XP (KB978542) Security Update for Windows XP (KB978601) Security Update for Windows XP (KB978706) Security Update for Windows XP (KB979309) Security Update for Windows XP (KB979482) Security Update for Windows XP (KB979559) Security Update for Windows XP (KB979683) Security Update for Windows XP (KB980195) Security Update for Windows XP (KB980218) Security Update for Windows XP (KB980232) Security Update for Windows XP (KB980436) Security Update for Windows XP (KB981852) Security Update for Windows XP (KB981997) Security Update for Windows XP (KB982214) Security Update for Windows XP (KB982665) Skype Toolbars Skype™ 4.2 SmartSync LT - Fix device error Synaptics Pointing Device Driver Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Windows Internet Explorer 8 (KB975364) Update for Windows Internet Explorer 8 (KB976662) Update for Windows Internet Explorer 8 (KB980182) Update for Windows XP (KB951978) Update for Windows XP (KB955759) Update for Windows XP (KB967715) Update for Windows XP (KB968389) Update for Windows XP (KB971737) Update for Windows XP (KB973687) Update for Windows XP (KB973815) User Guide VobSub v2.23 (Remove Only) WebFldrs XP WIDCOMM Bluetooth Software Windows Genuine Advantage Notifications (KB905474) Windows Genuine Advantage Validation Tool (KB892130) Windows Internet Explorer 8 Windows Media Format 11 runtime Windows Media Player Firefox Plugin Windows XP Service Pack 3 WinRAR archiver
==== Event Viewer Messages From Past Week ========
28/09/2010 12:11:27, error: MRxSmb [8003] - The master browser has received a server announcement from the computer MAC002332CA10FC that believes that it is the master browser for the domain on transport NetBT_Tcpip_{ECC4AD0A-D5F. The master browser is stopping or an election is being forced. 28/09/2010 12:05:52, error: BROWSER [8009] - The browser was unable to promote itself to master browser. The computer that currently believes it is the master browser is PC-200911201232. 28/09/2010 11:50:52, error: NetBT [4321] - The name "WORKGROUP :1d" could not be registered on the Interface with IP address 192.168.1.102. The machine with the IP address 192.168.1.127 did not allow the name to be claimed by this machine. 28/09/2010 00:33:52, error: Dhcp [1002] - The IP address lease 192.168.1.141 for the Network Card with network address 0026B6203DD0 has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message). 26/09/2010 11:53:43, error: W32Time [34] - The time service has detected that the system time needs to be changed by -2678397 seconds. The time service will not change the system time by more than -54000 seconds. Verify that your time and time zone are correct, and that the time source time.windows.com (ntp.m|0x1|192.168.1.141:123->207.46.197.32:123) is working properly. 26/09/2010 11:38:57, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)
Now, please make sure no other programs are running, close all other windows.
Please double click on the file you downloaded. Follow the onscreen prompts to start the scan. Once the scanning process has started please DO NOT click on the Combofix window or attempt to use your computer as this can cause the scanning process to stall. It may take a while to complete scanning and this is normal.
You will be disconnected from the internet and your desktop icons/toolbars will disappear during scanning, do not worry, this is normal and it will be restored after scanning has completed.
Combofix will create a logfile and display it after your computer has rebooted.
Usually located in c:\combofix.txt, please post it to your next reply
The logs will be reasonably large so you may have to divide them into sections and make several posts to post them.
ComboFix 10-09-07.01 - Rozi 09/09/2010 0:28.1.2 - x86 Microsoft Windows XP Professional 5.1.2600.3.1252.44.1033.18.1014.708 [GMT 8:00] Running from: c:\documents and settings\Rozi\My Documents\Downloads\ComboFix.exe AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D} .
((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) .
Currently it is Wednesday, June 19, 2013 8:05 PM (GMT +3) There are a total of 59,658 posts in 13,160 threads. In the last 3 days there were 4 new threads and 12 reply posts. View Active Threads
Who's Online
This forum has 34678 registered members. Please welcome our newest member, Davidhariston. 27 Guest(s), 0 Registered Member(s) are currently online. Details