Computing.Net > Forums > Security and Virus > Crazy Virus

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

Crazy Virus

Reply to Message Icon

Name: goobafish
Date: February 24, 2006 at 22:54:44 Pacific
OS: Windows XP Home SP2
CPU/Ram: 2048
Product: homebrew
Comment:

Hey guys,
I got a or a number of viruses, i have tried about 6 differet virus check, scan and removal programs without success.
The virus does the following
No CTRL ALT DEL
No Task Manager
Java Window on bootup (sometimes)when closed causes freeze
Freezes, where my computer makes a beep sound and totally freezes
No restore
No safemode
No limewire

ectect
Any help is appreciated, Thanks



Sponsored Link
Ads by Google

Response Number 1
Name: jabuck
Date: February 25, 2006 at 07:59:01 Pacific
Reply:

If you can, please post a Hijack This log so that the files associated with the virus/spyware/hijacker might possibly be identified. You can download Hijack This at this link http://www.tomcoyote.org/hjt/ then place it into a folder of it's on, such as C:\HJT, so that back up copies can be made and not clutter your desktop or other folders and the backup copies of deleted items can be easily located if needed.

Once saved double click HijackThis.exe, and press "Scan". When the scan is finished, the "Scan" button will change into a "Save Log" button.
Press that, save the log, Ctrl-A to Select All, and copy its contents into the text editor at this forum.

Do not fix anything yet unless you know what you are doing. This is a powerful tool that can crash the computer if used improperly.


0

Response Number 2
Name: goobafish
Date: February 25, 2006 at 08:09:38 Pacific
Reply:

Logfile of HijackThis v1.99.1
Scan saved at 11:08:11 AM, on 2/25/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
G:\WINDOWS\System32\smss.exe
G:\WINDOWS\SYSTEM32\winlogon.exe
G:\WINDOWS\system32\services.exe
G:\WINDOWS\system32\lsass.exe
G:\WINDOWS\system32\svchost.exe
G:\WINDOWS\Explorer.exe
G:\Program Files\Mozilla Firefox\firefox.exe
H:\Hijack\HijackThis.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
F2 - REG:system.ini: UserInit=G:\WINDOWS\system32\Userinit.exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - G:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - G:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - G:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - G:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O4 - HKLM\..\Run: [MSConfig] G:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [csr] csrrs.exe
O4 - HKLM\..\RunServices: [csr] csrrs.exe
O4 - Global Startup: svchost.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://G:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - G:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - G:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - G:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - G:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - G:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - G:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1133909631983
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1133909737874
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Housecall ActiveX 6.5) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{797F5F5D-C068-4B61-AB7D-7E0D8BA9D3BD}: NameServer = 24.153.22.195,24.153.22.67
O17 - HKLM\System\CS1\Services\Tcpip\..\{797F5F5D-C068-4B61-AB7D-7E0D8BA9D3BD}: NameServer = 24.153.22.195,24.153.22.67
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "G:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)



0

Response Number 3
Name: jabuck
Date: February 25, 2006 at 08:37:16 Pacific
Reply:

You will need to disable any anti spyware with "real time protection" as suggested at this link for the fixes to work Castlecops Real Time Protection Tutorial

Download killbox from this link Killbox
Double-click on Killbox.exe to run it.
Put a tick by Standard File Kill.
In the "Full Path of File to Delete" box, copy and paste each of the following lines one at a time.

G:\WINDOWS\csrrs.exe

G:\WINDOWS\System32\csrrs.exe


Click on the button that has the red circle with the X in the middle after you enter each file.
It will ask for confimation to delete the file.
Click Yes.
Continue with that procedure until you have pasted all of these in the "Paste Full Path of File to Delete" box.

Run HT again, cloce all windows and browser except HT, place a check to the left of the following items and press "fix checked":

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm

O4 - HKLM\..\Run: [csr] csrrs.exe


O4 - HKLM\..\RunServices: [csr] csrrs.exe

Msconfig is runnig in "selective startup" and will need to be set to "normal startup" to finish the cleanup. Go to start>run>type "msconfig" without the quotes>ok>check the circle beside normal startup>apply>ok.

Then post a new HT log.


0

Response Number 4
Name: goobafish
Date: February 25, 2006 at 08:49:28 Pacific
Reply:

The file
G:\WINDOWS\csrrs.exe

did not exist...
Heres the newest HT log

Logfile of HijackThis v1.99.1
Scan saved at 11:47:50 AM, on 2/25/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
G:\WINDOWS\System32\smss.exe
G:\WINDOWS\system32\csrss.exe
G:\WINDOWS\SYSTEM32\winlogon.exe
G:\WINDOWS\system32\services.exe
G:\WINDOWS\system32\lsass.exe
G:\WINDOWS\system32\svchost.exe
G:\WINDOWS\system32\svchost.exe
G:\WINDOWS\System32\svchost.exe
G:\WINDOWS\System32\svchost.exe
G:\WINDOWS\System32\svchost.exe
G:\WINDOWS\system32\spoolsv.exe
G:\WINDOWS\Explorer.exe
G:\WINDOWS\System32\CTsvcCDA.exe
G:\Program Files\Network Associates\Common Framework\FrameworkService.exe
G:\Program Files\Network Associates\VirusScan\Mcshield.exe
G:\PROGRA~1\NETWOR~1\COMMON~1\naPrdMgr.exe
G:\WINDOWS\system32\wgp.exe
G:\Program Files\Winamp\winampa.exe
G:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
G:\Program Files\Network Associates\VirusScan\SHSTAT.exe
G:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
G:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe
G:\WINDOWS\system32\nvsvc32.exe
G:\WINDOWS\system32\RUNDLL32.exe
G:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
G:\Program Files\iTunes\iTunesHelper.exe
G:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe
G:\Program Files\Spyware Doctor\sdhelp.exe
G:\WINDOWS\system32\CTHELPER.exe
G:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDet.exe
G:\Program Files\Elaborate Bytes\CloneCD\CloneCDTray.exe
H:\program files\steam\steam.exe
G:\Program Files\Spyware Doctor\swdoctor.exe
G:\WINDOWS\system32\rundll32.exe
G:\WINDOWS\System32\svchost.exe
G:\Documents and Settings\All Users\Start Menu\Programs\Startup\svchost.exe
G:\WINDOWS\system32\wdfmgr.exe
G:\WINDOWS\System32\wbem\wmiprvse.exe
G:\Program Files\iPod\bin\iPodService.exe
G:\WINDOWS\System32\alg.exe
G:\WINDOWS\System32\svchost.exe
H:\Hijack\HijackThis.exe
G:\WINDOWS\system32\wuauclt.exe

F3 - REG:win.ini: load=???
?
F3 - REG:win.ini: run=???
?
F2 - REG:system.ini: UserInit=G:\WINDOWS\system32\Userinit.exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - G:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - G:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - G:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - G:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O4 - HKLM\..\Run: [WinGuard Pro] G:\WINDOWS\system32\wgp.exe
O4 - HKLM\..\Run: [WinampAgent] G:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [UpdReg] G:\WINDOWS\UpdReg.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] G:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [ShStatEXE] "G:\Program Files\Network Associates\VirusScan\SHSTAT.exe" /STANDALONE
O4 - HKLM\..\Run: [SBDrvDet] G:\Program Files\Creative\SB Drive Det\SBDrvDet.exe /r
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NVMixerTray] "G:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.exe G:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.exe G:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NeroFilterCheck] G:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "G:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [iTunesHelper] "G:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [CTSysVol] G:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [CTHelper] CTHELPER.exe
O4 - HKLM\..\Run: [CTDVDDET] G:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDet.exe
O4 - HKLM\..\Run: [csr] csrrs.exe
O4 - HKLM\..\Run: [CloneCDTray] "G:\Program Files\Elaborate Bytes\CloneCD\CloneCDTray.exe"
O4 - HKLM\..\Run: [CloneCDElbyCDFL] "G:\Program Files\Elaborate Bytes\CloneCD\ElbyCheck.exe" /L ElbyCDFL
O4 - HKLM\..\RunServices: [csr] csrrs.exe
O4 - HKCU\..\Run: [a-squared] "G:\Program Files\a-squared\a2guard.exe"
O4 - HKCU\..\Run: [Steam] "h:\program files\steam\steam.exe" -silent
O4 - HKCU\..\Run: [Spyware Doctor] "G:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O4 - HKCU\..\Run: [eMuleAutoStart] G:\Program Files\eMule\emule.exe -AutoStart
O4 - Global Startup: svchost.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://G:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - G:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - G:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - G:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - G:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - G:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - G:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1133909631983
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1133909737874
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Housecall ActiveX 6.5) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{797F5F5D-C068-4B61-AB7D-7E0D8BA9D3BD}: NameServer = 24.153.22.195,24.153.22.67
O17 - HKLM\System\CS1\Services\Tcpip\..\{797F5F5D-C068-4B61-AB7D-7E0D8BA9D3BD}: NameServer = 24.153.22.195,24.153.22.67
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "G:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - G:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - G:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - G:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - G:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - G:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - G:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - G:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - G:\Program Files\Spyware Doctor\sdhelp.exe



0

Response Number 5
Name: jabuck
Date: February 25, 2006 at 10:46:32 Pacific
Reply:

Reboot into safe mode, if you need instructions follow the directions Safe Mode

Use killbox and delete these files if found (it may say they do not exist but go through the process as if they do exist):

G:\WINDOWS\csrrs.exe

G:\WINDOWS\System32\csrrs.exe

G:\Documents and Settings\All Users\Start Menu\Programs\Startup\svchost.exe

Run HT again, close all browsers and windows except HT, place a check to the left of the following items and press "fix checked":

F3 - REG:win.ini: load=???
?

F3 - REG:win.ini: run=???
?

O4 - HKLM\..\Run: [csr] csrrs.exe

O4 - HKLM\..\RunServices: [csr] csrrs.exe

O4 - Global Startup: svchost.exe

Download Ewido Security Suite then set it up this way Ewido Setup Instructions reboot into safe mode and run Ewido.

When the scan has completed, Ewido will create a report.txt file. Click the "Save Report" button on the bottom of the screen and save the log to your desktop in case you need it later.

Please reboot into normal mode and post the ewido log and a new HT log.



0

Related Posts

See More



Response Number 6
Name: goobafish
Date: February 25, 2006 at 14:57:06 Pacific
Reply:

Ok well the ewido found about 3000 things, so I probably shouldnt post them :P il post the ht lopg in a sec


0

Response Number 7
Name: goobafish
Date: February 25, 2006 at 15:20:02 Pacific
Reply:

Running processes:
G:\WINDOWS\System32\smss.exe
G:\WINDOWS\system32\csrss.exe
G:\WINDOWS\SYSTEM32\winlogon.exe
G:\WINDOWS\system32\services.exe
G:\WINDOWS\system32\lsass.exe
G:\WINDOWS\system32\svchost.exe
G:\WINDOWS\system32\svchost.exe
G:\WINDOWS\System32\svchost.exe
G:\WINDOWS\System32\svchost.exe
G:\WINDOWS\System32\svchost.exe
G:\WINDOWS\system32\spoolsv.exe
G:\WINDOWS\Explorer.exe
G:\WINDOWS\system32\wgp.exe
G:\Program Files\Winamp\winampa.exe
G:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
G:\Program Files\Network Associates\VirusScan\SHSTAT.exe
G:\WINDOWS\System32\CTsvcCDA.exe
G:\Program Files\ewido anti-malware\ewidoctrl.exe
G:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe
G:\WINDOWS\system32\rundll32.exe
G:\WINDOWS\system32\RUNDLL32.exe
G:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
G:\Program Files\ewido anti-malware\ewidoguard.exe
G:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe
G:\WINDOWS\system32\CTHELPER.exe
G:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDet.exe
G:\Program Files\Elaborate Bytes\CloneCD\CloneCDTray.exe
G:\Program Files\a-squared\a2guard.exe
H:\program files\steam\steam.exe
G:\Program Files\Spyware Doctor\swdoctor.exe
G:\Program Files\eMule\emule.exe
G:\Program Files\Network Associates\Common Framework\FrameworkService.exe
G:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
G:\WINDOWS\system32\nvsvc32.exe
G:\PROGRA~1\NETWOR~1\COMMON~1\naPrdMgr.exe
G:\Program Files\Spyware Doctor\sdhelp.exe
G:\WINDOWS\System32\svchost.exe
G:\WINDOWS\system32\wdfmgr.exe
G:\WINDOWS\System32\wbem\wmiprvse.exe
G:\WINDOWS\system32\wuauclt.exe
H:\Hijack\HijackThis.exe

F2 - REG:system.ini: UserInit=G:\WINDOWS\system32\Userinit.exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - G:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - G:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - G:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - G:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O4 - HKLM\..\Run: [WinGuard Pro] G:\WINDOWS\system32\wgp.exe
O4 - HKLM\..\Run: [WinampAgent] G:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [UpdReg] G:\WINDOWS\UpdReg.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] G:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [ShStatEXE] "G:\Program Files\Network Associates\VirusScan\SHSTAT.exe" /STANDALONE
O4 - HKLM\..\Run: [SBDrvDet] G:\Program Files\Creative\SB Drive Det\SBDrvDet.exe /r
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NVMixerTray] "G:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.exe G:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.exe G:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NeroFilterCheck] G:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "G:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [iTunesHelper] "G:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [CTSysVol] G:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [CTHelper] CTHELPER.exe
O4 - HKLM\..\Run: [CTDVDDET] G:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDet.exe
O4 - HKLM\..\Run: [CloneCDTray] "G:\Program Files\Elaborate Bytes\CloneCD\CloneCDTray.exe"
O4 - HKLM\..\Run: [CloneCDElbyCDFL] "G:\Program Files\Elaborate Bytes\CloneCD\ElbyCheck.exe" /L ElbyCDFL
O4 - HKCU\..\Run: [a-squared] "G:\Program Files\a-squared\a2guard.exe"
O4 - HKCU\..\Run: [Steam] "h:\program files\steam\steam.exe" -silent
O4 - HKCU\..\Run: [Spyware Doctor] "G:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O4 - HKCU\..\Run: [eMuleAutoStart] G:\Program Files\eMule\emule.exe -AutoStart
O8 - Extra context menu item: E&xport to Microsoft Excel - res://G:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - G:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - G:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - G:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - G:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - G:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - G:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1133909631983
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1133909737874
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Housecall ActiveX 6.5) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{797F5F5D-C068-4B61-AB7D-7E0D8BA9D3BD}: NameServer = 24.153.22.195,24.153.22.67
O17 - HKLM\System\CS1\Services\Tcpip\..\{797F5F5D-C068-4B61-AB7D-7E0D8BA9D3BD}: NameServer = 24.153.22.195,24.153.22.67
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "G:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - G:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: ewido security suite control - ewido networks - G:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - G:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - G:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - G:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - G:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - G:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - G:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - G:\Program Files\Spyware Doctor\sdhelp.exe


0

Response Number 8
Name: jabuck
Date: February 25, 2006 at 15:30:04 Pacific
Reply:

Looks much better, is it running ok.I would like to see an Ewido scan if you have time.There should be much less in there in the second scan.


0

Response Number 9
Name: goobafish
Date: February 25, 2006 at 17:56:09 Pacific
Reply:

K i will post one tommorow morning,
Thanks a million for your help, its totally fixed


0

Response Number 10
Name: jabuck
Date: February 25, 2006 at 18:15:03 Pacific
Reply:

Ok goobafish, glad you are running ok.


0

Response Number 11
Name: goobafish
Date: February 25, 2006 at 18:56:30 Pacific
Reply:

:mozilla.6:G:\Documents and Settings\David Caplan\Application Data\Mozilla\Firefox\Profiles\sd5ezu1c.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.7:G:\Documents and Settings\David Caplan\Application Data\Mozilla\Firefox\Profiles\sd5ezu1c.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.10:G:\Documents and Settings\David Caplan\Application Data\Mozilla\Firefox\Profiles\sd5ezu1c.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.11:G:\Documents and Settings\David Caplan\Application Data\Mozilla\Firefox\Profiles\sd5ezu1c.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.14:G:\Documents and Settings\David Caplan\Application Data\Mozilla\Firefox\Profiles\sd5ezu1c.default\cookies.txt -> TrackingCookie.Linksynergy : Cleaned with backup
:mozilla.16:G:\Documents and Settings\David Caplan\Application Data\Mozilla\Firefox\Profiles\sd5ezu1c.default\cookies.txt -> TrackingCookie.Bfast : Cleaned with backup
:mozilla.17:G:\Documents and Settings\David Caplan\Application Data\Mozilla\Firefox\Profiles\sd5ezu1c.default\cookies.txt -> TrackingCookie.Bfast : Cleaned with backup
:mozilla.20:G:\Documents and Settings\David Caplan\Application Data\Mozilla\Firefox\Profiles\sd5ezu1c.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.21:G:\Documents and Settings\David Caplan\Application Data\Mozilla\Firefox\Profiles\sd5ezu1c.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.24:G:\Documents and Settings\David Caplan\Application Data\Mozilla\Firefox\Profiles\sd5ezu1c.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.63:G:\Documents and Settings\David Caplan\Application Data\Mozilla\Firefox\Profiles\sd5ezu1c.default\cookies.txt -> TrackingCookie.Hitslink : Cleaned with backup
:mozilla.64:G:\Documents and Settings\David Caplan\Application Data\Mozilla\Firefox\Profiles\sd5ezu1c.default\cookies.txt -> TrackingCookie.Hitslink : Cleaned with backup
:mozilla.65:G:\Documents and Settings\David Caplan\Application Data\Mozilla\Firefox\Profiles\sd5ezu1c.default\cookies.txt -> TrackingCookie.Hitslink : Cleaned with backup
:mozilla.68:G:\Documents and Settings\David Caplan\Application Data\Mozilla\Firefox\Profiles\sd5ezu1c.default\cookies.txt -> TrackingCookie.Hitslink : Cleaned with backup
:mozilla.75:G:\Documents and Settings\David Caplan\Application Data\Mozilla\Firefox\Profiles\sd5ezu1c.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.76:G:\Documents and Settings\David Caplan\Application Data\Mozilla\Firefox\Profiles\sd5ezu1c.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.80:G:\Documents and Settings\David Caplan\Application Data\Mozilla\Firefox\Profiles\sd5ezu1c.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.81:G:\Documents and Settings\David Caplan\Application Data\Mozilla\Firefox\Profiles\sd5ezu1c.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup
:mozilla.82:G:\Documents and Settings\David Caplan\Application Data\Mozilla\Firefox\Profiles\sd5ezu1c.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.83:G:\Documents and Settings\David Caplan\Application Data\Mozilla\Firefox\Profiles\sd5ezu1c.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.84:G:\Documents and Settings\David Caplan\Application Data\Mozilla\Firefox\Profiles\sd5ezu1c.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.85:G:\Documents and Settings\David Caplan\Application Data\Mozilla\Firefox\Profiles\sd5ezu1c.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.89:G:\Documents and Settings\David Caplan\Application Data\Mozilla\Firefox\Profiles\sd5ezu1c.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup


0

Response Number 12
Name: jabuck
Date: February 25, 2006 at 18:59:58 Pacific
Reply:

Looks good, just cookies.


0

Sponsored Link
Ads by Google
Reply to Message Icon

UnSpyPC infection Is GData Anti Virus 2006 ...



Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home


Sponsored links

Ads by Google


Results for: Crazy Virus

Crazy Virus www.computing.net/answers/security/crazy-virus/26500.html

Crazy Virus www.computing.net/answers/security/crazy-virus/17421.html

crazy virus...please help www.computing.net/answers/security/crazy-virusplease-help/23108.html