hi. anyone can help me clear some virus in my comp pls? thanks

View previous topic View next topic Go down

Solved hi. anyone can help me clear some virus in my comp pls? thanks

Post by dropleague on 24th January 2009, 3:16 am

knew my computer got infected by malware long long time ago. but i always cant be bothered to come here and post a log file.
so here it is...
hope someone could help me out. thanks alot

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:16:00 AM, on 1/24/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Unlocker\UnlockerAssistant.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
J:\J.C.T.H\Thumbdrive Backup\My Softwares\Internet Downloaded Softwares\HiJackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.singnet.com.sg:8080
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 10.0.0.5;
R3 - URLSearchHook: (no name) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - (no file)
O2 - BHO: GigagetIEHelper - {111CAA23-6F4F-42AC-8555-B48C1D87BBAB} - C:\WINDOWS\system32\gigagetbho_v10.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Media Codec Update Service] C:\Program Files\Essentials Codec Pack\update.exe -silent
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [EPSON Stylus C59 Series (Copy 1)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBHP.EXE /FU "C:\WINDOWS\TEMP\E_SEE.tmp" /EF "HKLM"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [UVS11 Preload] C:\Program Files\Ulead Systems\Ulead VideoStudio 11\uvPL.exe
O4 - HKLM\..\Run: [SearchSettings] C:\Program Files\Search Settings\SearchSettings.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
O4 - HKLM\..\Run: [AdVantage Setup] C:\DOCUME~1\Admin\LOCALS~1\Temp\is-2THCM.tmp\AdVantageSetup.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SystemShowInfo] C:\RECYCLER\S-1-5-21-3209337583-1119639346-775236423-9248\sysinfo.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: MagicDisc.lnk = C:\Program Files\MagicDisc\MagicDisc.exe
O8 - Extra context menu item: &Download All by Gigaget - C:\Program Files\Giganology\Gigaget\getallurl.htm
O8 - Extra context menu item: &Download by Gigaget - C:\Program Files\Giganology\Gigaget\geturl.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - [You must be registered and logged in to see this link.]
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - [You must be registered and logged in to see this link.]
O17 - HKLM\System\CCS\Services\Tcpip\..\{A1BAF0B2-A4BE-4E91-BBD5-E4678F441F35}: NameServer = 165.21.83.88,165.21.100.88
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Capture Device Service - InterVideo Inc. - C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe

--
End of file - 7882 bytes

dropleague
Intermediate
Intermediate

Posts Posts : 94
Joined Joined : 2008-07-08
Gender Gender : Male
OS OS : Windows 7
Protection Protection : Avast
Points Points : 30766
# Likes # Likes : 0

View user profile

Back to top Go down

Solved Re: hi. anyone can help me clear some virus in my comp pls? thanks

Post by Belahzur on 24th January 2009, 2:19 pm


  • Open HijackThis
  • Choose "Do a system scan only"
  • Check the boxes in front of these lines:


    R3 - URLSearchHook: (no name) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - (no file)
    O4 - HKLM\..\Run: [SearchSettings] C:\Program Files\Search Settings\SearchSettings.exe
    O4 - HKLM\..\Run: [AdVantage Setup] C:\DOCUME~1\Admin\LOCALS~1\Temp\is-2THCM.tmp\AdVantageSetup.exe
    O4 - HKCU\..\Run: [SystemShowInfo] C:\RECYCLER\S-1-5-21-3209337583-1119639346-775236423-9248\sysinfo.exe


  • Press "Fix Checked"
  • Close Hijack This.

Please download the [You must be registered and logged in to see this link.].

  • Save it to your desktop.
  • Please double-click OTMoveIt3.exe to run it.
  • Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose CopyCrying


    :files
    C:\Program Files\Search Settings
    C:\RECYCLER\S-1-5-21-3209337583-1119639346-775236423-9248

    :commands
    [purity]
    [emptytemp]
    [reboot]


  • Return to OTMoveIt3, right click in the "Paste instructions for items to be Moved" window (under the light blue bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.

Please post the OTMoveIt log.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34918
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : 7 Home Premium x64
Points Points : 245101
# Likes # Likes : 1

View user profile

Back to top Go down

Solved Log File for OTMoveIt3.exe

Post by dropleague on 25th January 2009, 4:32 am

here's the log file u asked for.
Sorry for the late reply.

========== FILES ==========
C:\Program Files\Search Settings\kb127 moved successfully.
C:\Program Files\Search Settings moved successfully.
C:\RECYCLER\S-1-5-21-3209337583-1119639346-775236423-9248 moved successfully.
========== COMMANDS ==========
File delete failed. C:\DOCUME~1\Admin\LOCALS~1\Temp\etilqs_Z0HyiVZ2LZ7iP6agCcfd scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Admin\LOCALS~1\Temp\~DF13C3.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Admin\LOCALS~1\Temp\~DF148B.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Admin\LOCALS~1\Temp\~DFDF5E.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Admin\LOCALS~1\Temp\~DFDF95.tmp scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
Local Service Temp folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
File delete failed. C:\WINDOWS\temp\_avast4_\Webshlock.txt scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_534.dat scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_730.dat scheduled to be deleted on reboot.
Windows Temp folder emptied.
Java cache emptied.
File delete failed. C:\Documents and Settings\Admin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zu14r28c.default\Cache\_CACHE_001_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Admin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zu14r28c.default\Cache\_CACHE_002_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Admin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zu14r28c.default\Cache\_CACHE_003_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Admin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zu14r28c.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Admin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zu14r28c.default\urlclassifier3.sqlite scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Admin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zu14r28c.default\XUL.mfl scheduled to be deleted on reboot.
FireFox cache emptied.
Temp folders emptied.

OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 01252009_121833

Files moved on Reboot...
File C:\DOCUME~1\Admin\LOCALS~1\Temp\etilqs_Z0HyiVZ2LZ7iP6agCcfd not found!
File C:\DOCUME~1\Admin\LOCALS~1\Temp\~DF13C3.tmp not found!
File C:\DOCUME~1\Admin\LOCALS~1\Temp\~DF148B.tmp not found!
File C:\DOCUME~1\Admin\LOCALS~1\Temp\~DFDF5E.tmp not found!
File C:\DOCUME~1\Admin\LOCALS~1\Temp\~DFDF95.tmp not found!
File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot.
File move failed. C:\WINDOWS\temp\_avast4_\Webshlock.txt scheduled to be moved on reboot.
C:\WINDOWS\temp\Perflib_Perfdata_534.dat moved successfully.
File C:\WINDOWS\temp\Perflib_Perfdata_730.dat not found!
C:\Documents and Settings\Admin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zu14r28c.default\Cache\_CACHE_001_ moved successfully.
C:\Documents and Settings\Admin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zu14r28c.default\Cache\_CACHE_002_ moved successfully.
C:\Documents and Settings\Admin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zu14r28c.default\Cache\_CACHE_003_ moved successfully.
C:\Documents and Settings\Admin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zu14r28c.default\Cache\_CACHE_MAP_ moved successfully.
C:\Documents and Settings\Admin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zu14r28c.default\urlclassifier3.sqlite moved successfully.
C:\Documents and Settings\Admin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zu14r28c.default\XUL.mfl moved successfully.

dropleague
Intermediate
Intermediate

Posts Posts : 94
Joined Joined : 2008-07-08
Gender Gender : Male
OS OS : Windows 7
Protection Protection : Avast
Points Points : 30766
# Likes # Likes : 0

View user profile

Back to top Go down

Solved Re: hi. anyone can help me clear some virus in my comp pls? thanks

Post by Belahzur on 25th January 2009, 12:50 pm

How is everything now?


  • Please download DDS by sUBs to your Desktop (Important!!) from one of these locations:
    [You must be registered and logged in to see this link.]
    [You must be registered and logged in to see this link.]
    [You must be registered and logged in to see this link.]
  • Double click DDS.scr to run
  • When complete, DDS.txt will open.
  • Click No for Optional Scan.
  • Save the report to your Desktop.
  • Copy and paste DDS.txt back here, I don't need to see attach.txt.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34918
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : 7 Home Premium x64
Points Points : 245101
# Likes # Likes : 1

View user profile

Back to top Go down

Solved Re: hi. anyone can help me clear some virus in my comp pls? thanks

Post by dropleague on 29th January 2009, 2:52 pm

sorry for the late reply.
Nothing abnormal in the computer these days.
maybe cos i seldom use the computer.. i cant confirm yet.

here's the log from dds.scr


DDS (Ver_09-01-19.01) - NTFSx86
Run by Admin at 22:48:29.46 on Thu 01/29/2009
Internet Explorer: 6.0.2900.2180 BrowserJavaVersion: 1.6.0_11
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.511.133 [GMT 8:00]

AV: avast! antivirus 4.8.1229 [VPS 090128-0] *On-access scanning enabled* (Updated)

============== Running Processes ===============

C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Unlocker\UnlockerAssistant.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MagicDisc\MagicDisc.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Admin\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = [You must be registered and logged in to see this link.]
uSearch Page = [You must be registered and logged in to see this link.]
uSearch Bar = [You must be registered and logged in to see this link.]
mDefault_Search_URL = [You must be registered and logged in to see this link.]
uInternet Settings,ProxyServer = proxy.singnet.com.sg:8080
uInternet Settings,ProxyOverride = 10.0.0.5;
uSearchAssistant = [You must be registered and logged in to see this link.]
uSearchURL,(Default) = [You must be registered and logged in to see this link.]
mSearchAssistant = [You must be registered and logged in to see this link.]
BHO: GigagetIEHelper Class: {111caa23-6f4f-42ac-8555-b48c1d87bbab} - c:\windows\system32\gigagetbho_v10.dll
BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.0.926.3450\swg.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar2.dll
uRun: [MsnMsgr] "c:\program files\msn messenger\MsnMsgr.Exe" /background
uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe
uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [IMJPMIG8.1] "c:\windows\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
mRun: [MSPY2002] c:\windows\system32\ime\pintlgnt\ImScInst.exe /SYNC
mRun: [PHIME2002ASync] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /SYNC
mRun: [PHIME2002A] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /IMEName
mRun: [SoundMan] SOUNDMAN.EXE
mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [Media Codec Update Service] c:\program files\essentials codec pack\update.exe -silent
mRun: [RemoteControl] "c:\program files\cyberlink dvd solution\powerdvd\PDVDServ.exe"
mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe
mRun: [EPSON Stylus C59 Series (Copy 1)] c:\windows\system32\spool\drivers\w32x86\3\e_fatibhp.exe /fu "c:\windows\temp\E_SEE.tmp" /EF "HKLM"
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [UVS11 Preload] c:\program files\ulead systems\ulead videostudio 11\uvPL.exe
mRun: [UnlockerAssistant] "c:\program files\unlocker\UnlockerAssistant.exe"
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
StartupFolder: c:\docume~1\admin\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
StartupFolder: c:\docume~1\admin\startm~1\programs\startup\magicd~1.lnk - c:\program files\magicdisc\MagicDisc.exe
IE: &Download All by Gigaget - c:\program files\giganology\gigaget\getallurl.htm
IE: &Download by Gigaget - c:\program files\giganology\gigaget\geturl.htm
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - [You must be registered and logged in to see this link.]
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - [You must be registered and logged in to see this link.]
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - [You must be registered and logged in to see this link.]
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - [You must be registered and logged in to see this link.]
DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - [You must be registered and logged in to see this link.]
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - [You must be registered and logged in to see this link.]
TCP: {A1BAF0B2-A4BE-4E91-BBD5-E4678F441F35} = 165.21.83.88,165.21.100.88
Handler: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - c:\program files\belarc\advisor\system\BAVoilaX.dll
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL
Notify: AtiExtEvent - Ati2evxx.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\admin\applic~1\mozilla\firefox\profiles\zu14r28c.default\
FF - prefs.js: browser.search.defaulturl - [You must be registered and logged in to see this link.]
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - [You must be registered and logged in to see this link.]
FF - component: c:\program files\nokia\nokia pc suite 7\bkmrksync\components\BkMrkExt.dll
FF - plugin: c:\windows\system32\c2mp\npdivx32.dll

============= SERVICES / DRIVERS ===============

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-10-3 78416]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2008-9-3 8944]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2008-9-3 55024]
R3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast4\ashMaiSv.exe [2008-10-3 250040]
R3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast4\ashWebSv.exe [2008-10-3 348344]
R3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2008-9-3 7408]
R4 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2008-10-3 20560]
R4 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast4\ashServ.exe [2008-10-3 147640]

=============== Created Last 30 ================

2009-01-29 22:48 --d-h--- c:\windows\PIF
2009-01-25 13:05 --d----- c:\program files\Real Alternative
2009-01-25 12:18 --d----- C:\_OTMoveIt
2009-01-21 17:42 161,209 a------- c:\windows\Expstudio Audio Editor FREE Uninstaller.exe
2009-01-21 17:42 --d----- c:\windows\system32\EXP
2009-01-21 17:42 --d----- c:\program files\Expstudio
2009-01-14 15:46 0 a------- c:\windows\ativpsrm.bin
2009-01-14 15:43 --d----- c:\program files\ATI
2009-01-14 15:40 593,920 -------- c:\windows\system32\ati2sgag.exe
2009-01-14 15:39 --d----- c:\program files\ATI Technologies
2009-01-14 15:38 --d----- C:\ATI
2009-01-14 15:32 10 a------- c:\windows\WININIT.INI
2009-01-14 04:29 268 a---h--- C:\sqmdata05.sqm
2009-01-14 04:29 244 a---h--- C:\sqmnoopt05.sqm
2009-01-13 16:50 0 a---h--- c:\windows\system32\drivers\Msft_Kernel_ccdcmb_01007.Wdf
2009-01-13 16:50 0 a---h--- c:\windows\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
2009-01-13 16:49 14,640 -------- c:\windows\system32\spmsgXP_2k3.dll
2009-01-12 16:40 --d----- c:\program files\common files\PCSuite
2009-01-12 16:40 --d----- c:\program files\common files\Nokia
2009-01-12 16:38 18,816 a------- c:\windows\system32\drivers\pccsmcfd.sys
2009-01-12 16:37 --d----- c:\program files\PC Connectivity Solution
2009-01-12 16:36 8,064 a------- c:\windows\system32\drivers\usbser_lowerfltj.sys
2009-01-12 16:36 8,064 a------- c:\windows\system32\drivers\usbser_lowerflt.sys
2009-01-12 16:36 22,016 a------- c:\windows\system32\drivers\ccdcmbo.sys
2009-01-12 16:36 1,112,288 a------- c:\windows\system32\wdfcoinstaller01007.dll
2009-01-12 16:36 659,968 a------- c:\windows\system32\nmwcdcocls.dll
2009-01-12 16:36 17,664 a------- c:\windows\system32\drivers\ccdcmb.sys
2009-01-10 01:56 --d----- c:\program files\netGangsters
2009-01-10 01:48 77,824 a------- c:\windows\iRODUninstall.exe
2009-01-10 01:48 --d----- c:\program files\ydt
2009-01-10 01:07 --d----- c:\program files\Hacker Evolution Untold
2009-01-03 21:04 --d----- c:\program files\Rockstar Games
2009-01-02 03:33 2,297,552 a------- c:\windows\system32\d3dx9_26.dll

==================== Find3M ====================

2008-12-26 00:37 20,480 a------- c:\windows\system32\H@tKeysH@@k.DLL
2008-12-12 12:36 410,984 a------- c:\windows\system32\deploytk.dll
2008-12-02 06:13 3,452,928 a------- c:\windows\system32\drivers\ati2mtag.sys
2008-12-02 04:52 425,984 a------- c:\windows\system32\ATIDEMGX.dll
2008-12-02 04:51 318,464 a------- c:\windows\system32\ati2dvag.dll
2008-12-02 04:46 11,304,960 a------- c:\windows\system32\atioglxx.dll
2008-12-02 04:41 188,416 a------- c:\windows\system32\atipdlxx.dll
2008-12-02 04:40 147,456 a------- c:\windows\system32\Oemdspif.dll
2008-12-02 04:40 26,112 a------- c:\windows\system32\Ati2mdxx.exe
2008-12-02 04:40 43,520 a------- c:\windows\system32\ati2edxx.dll
2008-12-02 04:40 143,360 a------- c:\windows\system32\ati2evxx.dll
2008-12-02 04:38 598,016 a------- c:\windows\system32\ati2evxx.exe
2008-12-02 04:37 53,248 a------- c:\windows\system32\ATIDDC.DLL
2008-12-02 04:27 4,120,384 a------- c:\windows\system32\ati3duag.dll
2008-12-02 04:19 307,200 a------- c:\windows\system32\atiiiexx.dll
2008-12-02 04:11 2,495,360 a------- c:\windows\system32\ativvaxx.dll
2008-12-02 04:11 3,107,788 a------- c:\windows\system32\ativvaxx.dat
2008-12-02 04:11 3,107,788 a------- c:\windows\system32\ativva5x.dat
2008-12-02 04:11 887,724 a------- c:\windows\system32\ativva6x.dat
2008-12-02 03:57 48,640 a------- c:\windows\system32\amdpcom32.dll
2008-12-02 03:53 401,408 a------- c:\windows\system32\atikvmag.dll
2008-12-02 03:53 45,056 a------- c:\windows\system32\amdcalrt.dll
2008-12-02 03:53 45,056 a------- c:\windows\system32\amdcalcl.dll
2008-12-02 03:52 86,016 a------- c:\windows\system32\atiadlxx.dll
2008-12-02 03:52 17,408 a------- c:\windows\system32\atitvo32.dll
2008-12-02 03:51 53,248 a------- c:\windows\system32\drivers\ati2erec.dll
2008-12-02 03:50 286,720 a------- c:\windows\system32\atiok3x2.dll
2008-12-02 03:50 3,252,224 a------- c:\windows\system32\Amdcaldd.dll
2008-12-02 03:45 577,536 a------- c:\windows\system32\ati2cqag.dll
2008-11-07 00:24 30,601 a------- c:\documents and settings\admin\x.exe
2004-10-01 15:00 40,960 a------- c:\program files\Uninstall_CDS.exe
2006-05-03 17:06 163,328 ---shr-- c:\windows\system32\flvDX.dll
2007-02-21 18:47 31,232 ---shr-- c:\windows\system32\msfDX.dll
2007-12-17 20:43 27,648 ---sh--- c:\windows\system32\Smab0.dll

============= FINISH: 22:49:53.00 ===============

dropleague
Intermediate
Intermediate

Posts Posts : 94
Joined Joined : 2008-07-08
Gender Gender : Male
OS OS : Windows 7
Protection Protection : Avast
Points Points : 30766
# Likes # Likes : 0

View user profile

Back to top Go down

Solved Re: hi. anyone can help me clear some virus in my comp pls? thanks

Post by Belahzur on 29th January 2009, 4:10 pm

Looks good to me.

I see you have Adobe Reader version 8 installed on this machine, this is old and has holes malware can use to abuse to re-infect you, so we need to close these holes.

Go to Start > Control Panel > Add/Remove Programs and remove the following programs if present.

  • Adobe Reader 8
Then download and install version 9 from here:
[You must be registered and logged in to see this link.]


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34918
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : 7 Home Premium x64
Points Points : 245101
# Likes # Likes : 1

View user profile

Back to top Go down

Solved Re: hi. anyone can help me clear some virus in my comp pls? thanks

Post by dropleague on 30th January 2009, 9:50 am

oh okay okay. Thanks alot Belahzur for your help!
Appreciate it!

i always knew my adobe reader is out of date. i just couldn't be bothered to update it. LOL

dropleague
Intermediate
Intermediate

Posts Posts : 94
Joined Joined : 2008-07-08
Gender Gender : Male
OS OS : Windows 7
Protection Protection : Avast
Points Points : 30766
# Likes # Likes : 0

View user profile

Back to top Go down

Solved Re: hi. anyone can help me clear some virus in my comp pls? thanks

Post by Doctor Inferno on 9th May 2009, 10:00 am

Since this issue has been addressed, a "solved" tag will be added and this topic will be closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter.

Everyone else, please open a [You must be registered and logged in to see this link.] for your questions.


Please be a GeekPolice fan on [You must be registered and logged in to see this link.]



Have we helped you? [You must be registered and logged in to see this link.] | Doctor by day, ninja by night.

Doctor Inferno
Administrator
Administrator

Posts Posts : 11976
Joined Joined : 2007-12-26
Gender Gender : Male
OS OS : Windows 7 Home Premium and Ultimate X64
Protection Protection : Kaspersky PURE and Malwarebytes' Anti-Malware
Points Points : 104630
# Likes # Likes : 0

View user profile

Back to top Go down

Solved Re: hi. anyone can help me clear some virus in my comp pls? thanks

Post by Doctor Inferno on 9th May 2009, 10:00 am

Since this issue has been addressed, a "solved" tag will be added and this topic will be closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter.

Everyone else, please open a [You must be registered and logged in to see this link.] for your questions.


Please be a GeekPolice fan on [You must be registered and logged in to see this link.]



Have we helped you? [You must be registered and logged in to see this link.] | Doctor by day, ninja by night.

Doctor Inferno
Administrator
Administrator

Posts Posts : 11976
Joined Joined : 2007-12-26
Gender Gender : Male
OS OS : Windows 7 Home Premium and Ultimate X64
Protection Protection : Kaspersky PURE and Malwarebytes' Anti-Malware
Points Points : 104630
# Likes # Likes : 0

View user profile

Back to top Go down

View previous topic View next topic Back to top

- Similar topics

 
Permissions in this forum:
You cannot reply to topics in this forum