Infected by some virus/worm please HELP!
chiaopi
Mexico
Hi,
I'm in great need of help, since Internet Explorer doesn't load properly...
Since i believed was somenthing wrong with IE7 i uninstalled and enabled IE6 but that doesnt work too...
I have installed AVG Free edition 8.0 for my antyvirus and i have the Firewall that cames with Windows XP...
This virus even disabled the automatic updates from Windows and wont let me enable it again...
Even, when i was doing the scan with Ad-aware SE, AVG showed this threads:
Trojan Horse Generic10.BGXY
Win 32/Heur
and i moved them to virus vault...
I didn't have the chance to make the scans with Panda or Kapersky online since IE dont work... i have to install Firefox
but, i made a complete scan with ClamWin Portable...
so, here's my scan with ClamWin portable:
and heres my HijackThis log:
Thanks in advance..
I'm in great need of help, since Internet Explorer doesn't load properly...
Since i believed was somenthing wrong with IE7 i uninstalled and enabled IE6 but that doesnt work too...
I have installed AVG Free edition 8.0 for my antyvirus and i have the Firewall that cames with Windows XP...
This virus even disabled the automatic updates from Windows and wont let me enable it again...
Even, when i was doing the scan with Ad-aware SE, AVG showed this threads:
Trojan Horse Generic10.BGXY
Win 32/Heur
and i moved them to virus vault...
I didn't have the chance to make the scans with Panda or Kapersky online since IE dont work... i have to install Firefox
but, i made a complete scan with ClamWin Portable...
so, here's my scan with ClamWin portable:
Scan Started Thu Jul 24 00:12:14 2008
WARNING: Can't open file \\?\C:\Documents and Settings\All Users\Datos de programa\Microsoft\Dr Watson\user.dmp, Permission denied
WARNING: Can't open file \\?\C:\Documents and Settings\Veronica\Escritorio\Swish\Swish 2.01 Complete Suite (SwiSHmax + Templates + Crack\Swish 2.01 Complete Suite (SwiSHmax + Templates + Crack\SwiSH Templates\Premium Flasheasy\premium_t_kit_flasheasy\premium_flasheasy\premium\index.htindex.htgš¨O@@, No such file or directory
WARNING: Can't open file \\?\C:\Documents and Settings\Veronica\Escritorio\Swish\Swish 2.01 Complete Suite (SwiSHmax + Templates + Crack\Swish 2.01 Complete Suite (SwiSHmax + Templates + Crack\SwiSH Templates\Premium Flasheasy\premium_t_kit_flasheasy\premium_flasheasy\premium\premium.premium.gš¨O@@, No such file or directory
WARNING: Can't open file \\?\C:\Documents and Settings\Veronica\Escritorio\Swish\Swish 2.01 Complete Suite (SwiSHmax + Templates + Crack\Swish 2.01 Complete Suite (SwiSHmax + Templates + Crack\SwiSH Templates\Premium Flasheasy\premium_t_kit_flasheasy\premium_flasheasy\premium\sound1.ssound1.sgš¨O@@, No such file or directory
WARNING: Can't open file \\?\C:\Documents and Settings\Veronica\Escritorio\Swish\Swish 2.01 Complete Suite (SwiSHmax + Templates + Crack\Swish 2.01 Complete Suite (SwiSHmax + Templates + Crack\SwiSH Templates\Premium Flasheasy\premium_t_kit_flasheasy\premium_flasheasy\premium\sound2.ssound2.sgš¨O@@, No such file or directory
WARNING: Can't open file \\?\C:\Documents and Settings\Veronica\Escritorio\Swish\Swish 2.01 Complete Suite (SwiSHmax + Templates + Crack\Swish 2.01 Complete Suite (SwiSHmax + Templates + Crack\SwiSH Templates\Premium Flasheasy\premium_t_kit_flasheasy\premium_flasheasy\premium\sound3.ssound3.sgš¨O@@, No such file or directory
WARNING: Can't open file \\?\C:\Documents and Settings\Veronica\Escritorio\Swish\Swish 2.01 Complete Suite (SwiSHmax + Templates + Crack\Swish 2.01 Complete Suite (SwiSHmax + Templates + Crack\SwiSH Templates\Premium Flasheasy\premium_t_kit_flasheasy\premium_flasheasy\premium\sound4.ssound4.sgš¨O@@, No such file or directory
WARNING: Can't open file \\?\C:\Documents and Settings\Veronica\Escritorio\Swish\Swish 2.01 Complete Suite (SwiSHmax + Templates + Crack\Swish 2.01 Complete Suite (SwiSHmax + Templates + Crack\SwiSH Templates\Premium Flasheasy\premium_t_kit_flasheasy\premium_flasheasy\premium\sound5.ssound5.sgš¨O@@, No such file or directory
WARNING: Can't open file \\?\C:\Documents and Settings\Veronica\Escritorio\Swish\Swish 2.01 Complete Suite (SwiSHmax + Templates + Crack\Swish 2.01 Complete Suite (SwiSHmax + Templates + Crack\SwiSH Templates\Premium Flasheasy\premium_t_kit_flasheasy\premium_flasheasy\premium\sound6.ssound6.sgš¨O@@, No such file or directory
WARNING: Can't open file \\?\C:\Documents and Settings\Veronica\Escritorio\USB 4-01-07\Fairies\Fairy Art Erotic Flower Fairies; Contemporary Faerie Art ( Faery Art ) after the Victorian Fairy Art Tradition by Howard David* Johnson_archivos\The_Fairy_Paintings_of_Howard_David_Johnson.gohnson.g¯¢¨O@@, No such file or directory
WARNING: Can't open file \\?\C:\Documents and Settings\Veronica\Escritorio\USB 4-01-07\Fairies\Fairy Art Erotic Flower Fairies; Contemporary Faerie Art ( Faery Art ) after the Victorian Fairy Art Tradition by Howard David* Johnson_archivos\The_seven_wonders_of_the_ancient_world_btn.jpd_btn.jp¯¢¨O@@, No such file or directory
WARNING: Can't open file \\?\C:\pagefile.sys, Permission denied
WARNING: Can't open file \\?\C:\WINDOWS\system32\CatRoot2\tmp.edb, Permission denied
WARNING: Can't open file \\?\C:\WINDOWS\system32\ftps.exe, Permission denied
SCAN SUMMARY
Known viruses: 366175
Engine version: 0.92
Scanned directories: 9726
Scanned files: 115724
Skipped non-executable files: 1402
Infected files: 0
Data scanned: 27066.74 MB
Time: 24693.453 sec (411 m 33 s)
Completed
and heres my HijackThis log:
Logfile of HijackThis v1.99.1
Scan saved at 09:31:49 a.m., on 24/07/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Archivos de programa\Archivos comunes\Autodesk Shared\Service\AdskScSrv.exe
C:\ARCHIV~1\AVG\AVG8\avgwdsvc.exe
C:\Archivos de programa\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
C:\WINDOWS\system32\crypserv.exe
C:\Archivos de programa\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Archivos de programa\Archivos comunes\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Tablet.exe
C:\ARCHIV~1\AVG\AVG8\avgrsx.exe
C:\ARCHIV~1\AVG\AVG8\avgemc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\system32\pctspk.exe
C:\Archivos de programa\Java\jre1.5.0_06\bin\jusched.exe
C:\Archivos de programa\HP\HP Software Update\HPWuSchd2.exe
C:\Archivos de programa\IUSACELL\CDU680DORA\BIN\RDVCHG.EXE
C:\ARCHIV~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\Rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\svchost.exe
C:\Archivos de programa\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Archivos de programa\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Archivos de programa\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\system32\Wtablet\TabUserW.exe
C:\Archivos de programa\HP\Digital Imaging\bin\hpqimzone.exe
C:\Archivos de programa\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Archivos de programa\Hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Vínculos
O3 - Toolbar: StylerToolBar - {D2F8F919-690B-4EA2-9FA7-A203D1E04F75} - C:\Archivos de programa\styler\TB\StylerTB.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Archivos de programa\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Gana Buscando Toolbar - {FFFFFFFF-FFFF-FFFF-FFFF-FFFFFFFF2D1F} - C:\Archivos de programa\Toolbar GB\Gana Buscando Toolbar\gana_buscando.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\archivos de programa\google\googletoolbar1.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\ARCHIV~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Archivos de programa\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\system32\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HP Software Update] C:\Archivos de programa\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [IUSACELL_CDU680] C:\Archivos de programa\IUSACELL\CDU680DORA\BIN\RDVCHG.EXE
O4 - HKLM\..\Run: [AVG8_TRAY] C:\ARCHIV~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [882a5cf5] rundll32.exe "C:\WINDOWS\system32\rndxyplu.dll",b
O4 - HKLM\..\Run: [BM8b196f69] Rundll32.exe "C:\WINDOWS\system32\ggqopfob.dll",s
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [TuneUp MemOptimizer] "C:\Archivos de programa\TuneUp Utilities 2007\MemOptimizer.exe" autostart
O4 - HKCU\..\Run: [swg] C:\Archivos de programa\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - Startup: Adobe Gamma.lnk = C:\Archivos de programa\Archivos comunes\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Archivos de programa\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\Archivos de programa\Archivos comunes\Autodesk Shared\acstart16.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Archivos de programa\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Inicio rápido de HP Photosmart Premier.lnk = C:\Archivos de programa\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: TabUserW.exe.lnk = C:\WINDOWS\system32\Wtablet\TabUserW.exe
O8 - Extra context menu item: E&xportar a Microsoft Excel - res://C:\ARCHIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O10 - Unknown file in Winsock LSP: c:\archivos de programa\bonjour\mdnsnsp.dll
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {8731163E-77B9-4F91-9122-F112521C28AF} (MMSPlayerX Class) - http://mmbox.itelcel.com/mmawap/jsp/composer/player/mmsPlayer.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{58D9E86D-D4D3-4191-A95F-53E369FA4B21}: NameServer = 200.33.146.193,200.33.146.201
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Archivos de programa\AVG\AVG8\avgpp.dll
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARCHIV~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARCHIV~1\MSNMES~1\MSGRAP~1.DLL
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Archivos de programa\Archivos comunes\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Archivos de programa\Archivos comunes\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\ARCHIV~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\ARCHIV~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Archivos de programa\Bonjour\mDNSResponder.exe
O23 - Service: C-DillaSrv - C-Dilla Ltd - C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
O23 - Service: Crypkey License - Kenonic Controls Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Archivos de programa\Archivos comunes\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Archivos de programa\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: ServiceLayer - Nokia. - C:\Archivos de programa\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\system32\Tablet.exe
Thanks in advance..
0
Comments
My name is Jay and I will be helping you to remove any infection(s) that you may have.
Please observe these rules while we work:
1. If you don't know, stop and ask! Don't keep going on.
2. Please reply to this thread. Do not start a new topic.
3. Please continue to respond until I give you the "All Clear"
(Just because you can't see a problem doesn't mean it isn't there)
If you can do those three things, everything should go smoothly
I apologize for the delay in responding, but as you can probably see the forums are quite busy
and sometimes a post manages to slip by us.
Unfortunately there are far more people needing help than there are helpers, so be patient if reply comes late
Download latest HijackThis (http://www.trendsecure.com/portal/en-US/tools/security_tools/hijackthis) to your Desktop.
• Doubleclick HJTInstall.exe to install it.
• By default it will install to C:\Program Files\Trend Micro\HijackThis .
• Click on Install.
• It will create a HijackThis icon on the desktop.
• Once installed, it will launch Hijackthis.
change the name of hijackthis to scanner and then open it
• Click on the Do a system scan and save a logfile button. It will scan and the log should open in notepad.
• Save the log to a convenient location as you'll need to post it soon.
• Don't use the Analyse This button, its findings are dangerous if misinterpreted.
• Don't have Hijackthis fix anything yet. Most of what it finds will be harmless or even required.
Post the HijackThis log back here.
sorry for the late reply, but the computer is getting more and more slow and opening a lot of pop-up windows (some of them are porn sites, btw..)
I couldn't did the online antivirus scan, because thenever i tried to install kaspersky online, the browser (IE & Firefox) started to have troubles...
btw, i think i got XP antivirus 2009 due the gray pop-up showing.. but i installed Rogue Remover free edition and couldn't find anything in my computer...
here's my new HijackThis log:
Please do the following...
1. Please download Malwarebytes' Anti-Malware to your desktop.
2. I need to see another log from HijackThis.
3. Please post the following...
MalwareBytes log
Uninstall list
New HijackThis log
i had to do the Malwarebyte's scan in 2 steps, due the first time running the full scan started lot of errors and the program at last crashed...
so i rebooted the coputer and started with the quick scan and later the full scan..
and here's the uninstall list:
and finally the new HijackThis log:
i can delete it if necessary...
Thanks
Please do the following...
1. Uninstall the following:
J2SE Runtime Environment 5.0 Update 4
J2SE Runtime Environment 5.0 Update 6
2. Open HijackThis
- Click the Do a system scan only button
- Check the following entries (below)
O2 - BHO: (no name) - {0FFE8B9B-0D48-4D47-8325-BE6D00F9F69D} - (no file)
O2 - BHO: (no name) - {550AD2E5-4DC1-48A4-96E7-36BC224CEA68} - C:\WINDOWS\system32\jkkijJBs.dll (file missing)
O2 - BHO: (no name) - {C6A085EA-03F5-43D9-8F63-D7C7E2A66303} - (no file)
- Close ALL open windows (especially Internet Explorer!)
- Click Fix Checked
Close HiajckThis
3. I'd like a file scanned...
4. Please post the following...
VirusTotal results.
i deleted the folder of Swish Max... and fixed with HijackThis,
but the next step.. when i tried to submit to Virus Total the ftps.exe file that you pointed out... i couldn't find it my computer.. seems that simply "dissapeared"
ok, here's my new HijackThis log:
Please visit this webpage for download links, and instructions for running ComboFix:
http://www.bleepingcomputer.com/combofix/how-to-use-combofix
Please ensure you read this guide carefully and install the Recovery Console first.
The Windows Recovery Console will allow you to boot up into a special recovery (repair) mode. This allows us to more easily help you should your computer have a problem after an attempted removal of malware. It is a simple procedure that will only take a few moments of your time.
Once installed, you should see a blue screen prompt that says:
The Recovery Console was successfully installed.
Please continue as follows:
When the tool is finished, it will produce a report for you.
Please include the following reports for further review, and so we may continue cleansing the system:
C:\ComboFix.txt
New HijackThis log.
Important: When Notepad opens, click Format and uncheck Word Wrap. Do this before posting ComboFix and HijackThis.
sorry for the late reply...
i installed Combo Fix and the Windows XP SP2 installation and here's my logfiles:
Combo Fix log:
HijackThis log:
Thanks
Please do the following...
1. You have had a USB infection it seems. So lets clean this...
2. Please do an online scan with Kaspersky WebScanner
Click on Kaspersky Online Scanner
You will be promted to install an ActiveX component from Kaspersky, Click Yes.
Note for Internet Explorer 7 users: If at any time you have trouble with the accept button of the licence, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75 %. Once the license accepted, reset to 100%.
Scan Mail Bases
3. Please post the Kaspersky report back here.
If it has been 7 days or more since your last post, and the helper assisting you posted a response to that post to which you did not reply, this topic will not be reopened. If you still require help, please start a new topic and include a fresh HijackThis log and a link to this thread in your new topic.
If you are not the user who started this thread, you must start your own Thread instead (grin)