SoftwareTipsandTricks Forum

Go Back   SoftwareTipsandTricks Forum > Software > Software Problems and Useful Utilities
User Name
Password


Please help!!! Virus troubles

Reply
 
Thread Tools Search this Thread Rate Thread Display Modes

  #1  
Old 08-14-2005, 07:10 PM
eege20 Offline
Registered User
 
Join Date: Aug 2005
Posts: 1
Please help!!! Virus troubles

I have been trying to get rid of a virus or two and have spent weeks trying. Nothing has solved the problem, but much has helped. I am posting my HJT log in hopes that somebody will help me know what to remove to take care of this problem once and for all. I would appreciate any and all help. Thanx,
Garrett




Logfile of HijackThis v1.99.1
Scan saved at 5:44:32 PM, on 8/14/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\Program Files\Softex\OmniPass\Omniserv.exe
C:\Program Files\Softex\OmniPass\OPXPApp.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINDOWS\system32\crwr.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe
C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe
C:\Program Files\Softwin\BitDefender8\bdmcon.exe
C:\Program Files\Softwin\BitDefender8\bdswitch.exe
C:\Program Files\Softwin\BitDefender8\bdnagent.exe
C:\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\qsdnn.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\qsdnn.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\qsdnn.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\hlpec.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyServer = :0
R3 - Default URLSearchHook is missing
O2 - BHO: Class - {1EA24A20-0EFF-C5A8-2CDB-39ABB3F27A0F} - C:\WINDOWS\system32\addqg32.dll
O2 - BHO: Class - {F573A15E-4E08-2CE8-1F75-3F0D794E2E42} - C:\WINDOWS\system32\sdkqj32.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [IEXPLORE.EXE] C:\Program Files\Internet Explorer\IEXPLORE.EXE
O4 - HKLM\..\Run: [SpyFighterMonitor] "C:\Program Files\SpyFighter\SpyFighter.exe" monitor
O4 - HKLM\..\Run: [SpyFighterUpdate] "C:\Program Files\SpyFighter\AutoUpdate.exe" silent
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [crwr.exe] C:\WINDOWS\system32\crwr.exe
O4 - HKLM\..\Run: [BDMCon] "C:\Program Files\Softwin\BitDefender8\bdmcon.exe"
O4 - HKLM\..\Run: [BDNewsAgent] "C:\Program Files\Softwin\BitDefender8\bdnagent.exe"
O4 - HKLM\..\RunServices: [WINS] WINS.exe
O4 - HKLM\..\RunOnce: [windj32.exe] C:\WINDOWS\windj32.exe
O4 - HKLM\..\RunOnce: [d3eo.exe] C:\WINDOWS\system32\d3eo.exe
O4 - HKLM\..\RunOnce: [netsr.exe] C:\WINDOWS\netsr.exe
O4 - HKLM\..\RunOnce: [netjm32.exe] C:\WINDOWS\netjm32.exe
O4 - HKLM\..\RunOnce: [iehm.exe] C:\WINDOWS\iehm.exe
O4 - HKLM\..\RunOnce: [javajn32.exe] C:\WINDOWS\system32\javajn32.exe
O4 - HKLM\..\RunOnce: [d3ua32.exe] C:\WINDOWS\d3ua32.exe
O4 - HKLM\..\RunOnce: [systq32.exe] C:\WINDOWS\system32\systq32.exe
O4 - HKLM\..\RunOnce: [msws.exe] C:\WINDOWS\msws.exe
O4 - HKLM\..\RunOnce: [crxq.exe] C:\WINDOWS\system32\crxq.exe
O4 - HKLM\..\RunOnce: [addki.exe] C:\WINDOWS\system32\addki.exe
O4 - HKLM\..\RunOnce: [msax.exe] C:\WINDOWS\msax.exe
O4 - HKLM\..\RunOnce: [appyi.exe] C:\WINDOWS\system32\appyi.exe
O4 - HKLM\..\RunOnce: [ipjz32.exe] C:\WINDOWS\system32\ipjz32.exe
O4 - HKLM\..\RunOnce: [crkl32.exe] C:\WINDOWS\crkl32.exe
O4 - HKLM\..\RunOnce: [javafj.exe] C:\WINDOWS\javafj.exe
O4 - HKLM\..\RunOnce: [ipzp.exe] C:\WINDOWS\system32\ipzp.exe
O4 - HKLM\..\RunOnce: [netin.exe] C:\WINDOWS\netin.exe
O4 - HKLM\..\RunOnce: [iedx32.exe] C:\WINDOWS\iedx32.exe
O4 - HKCU\..\Run: [a-squared] "C:\Program Files\a2\a2guard.exe"
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {01118400-3E00-11D2-8470-0060089874ED} (SdcNetCheckCtl Class) - http://activex.microsoft.com/objects/ocget.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.co...?1104389154666
O16 - DPF: {9294206B-A9B2-4F73-938E-89F694F48101} (MoveMinute Browser Object) - http://xlonhcld.xlontech.net/100348/.../ldsdlprod.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: OPXPGina - C:\Program Files\Softex\OmniPass\opxpgina.dll
O23 - Service: Workstation NetLogon Service ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\windj32.exe" /s (file missing)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe" /service (file missing)
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: CWShredder Service - InterMute, Inc. - c:\program files\InterMute\SpySubtract\CWShredder.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: InCD File System Service (InCDsrv) - Unknown owner - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod Service (iPodService) - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing)
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Softex OmniPass Service (omniserv) - Unknown owner - C:\Program Files\Softex\OmniPass\Omniserv.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: SmartFinder Uninstall (SmartFinder_Uninstall) - Unknown owner - C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\CBYJA5OF\SFUninstaller[1].exe" service (file missing)
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: BitDefender Communicator (XCOMM) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe" /service (file missing)
Reply With Quote

  #2  
Old 08-14-2005, 09:15 PM
Flyfsh's Avatar
Flyfsh Offline
Registered User
 
Join Date: Apr 2003
Location: Tulsa OK
Posts: 411
Did you shut off your restore points after doing a scan? Your logfile shows Norton and AVG. You could give them a dirty phone call and they may help.I am guessing you ran a scan at Housecalls and AVAST already?


http://www.avast.com/eng/avast_4_home.html


http://housecall.antivirus.com/house...tart_frame.asp
__________________
XP Home AMD2700+
Epox 8rda mobo
2x512 pc 2700 ram
ATI 256 9800XT
2X40 gig maxtor HD
onboard sound

Last edited by Flyfsh : 08-14-2005 at 09:18 PM.
Reply With Quote

  #3  
Old 08-15-2005, 06:18 AM
Jazz's Avatar
Jazz Offline
Registered User
 
Join Date: May 2004
Location: London, England
Posts: 1,658
Go throught the following, exactly, and then report back with your findings: -

Falcon's Crap Cleaner Routine

Incidentally, using two anti-virus products invariably leads to conflicts. Dump one or the other. Personally, I would keep AVG, as it's a far superior product, IMO, and far less of a resourse hog than Snortin' Norton.
__________________
An ounce of prevention is worth more than a pound of cure

Proud Member of the Alliance of Security Analysis Professionals (ASAP) 2006

Last edited by Jazz : 08-15-2005 at 06:21 AM.
Reply With Quote

  #4  
Old 08-17-2005, 06:20 PM
HoboConductor Offline
Registered User
 
Join Date: Aug 2005
Posts: 5
For virus scanners, go take a look at clamwin, just google it I don't know the url at the moment.

For internet, stop using Internet Explorer, go for something that is safer and a lot better such as FireFox or you can use the whole mozilla package by download the Mozilla Suite.
Reply With Quote
Reply




Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Blaster virus help request - thanks! owenhbrown Windows XP 8 04-30-2005 09:08 PM
virus from hell HELP! Felman Windows XP 3 02-12-2005 04:02 PM
Virus Win32/Hantaner!!! Plz help zile Internet 22 06-19-2003 03:31 AM
Virus Help- NAV Isnt Helping antivirus99 Windows XP 3 03-10-2003 05:20 PM
Trillian Pro Virus high6ix Internet 14 02-18-2003 12:32 PM



All times are GMT -5. The time now is 12:45 AM.


Designed by eXtremepixels. Powered by vBulletin Version 3.5.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 2.3.2 © 2005, Crawlability, Inc.