SoftwareTipsandTricks Forum

Go Back   SoftwareTipsandTricks Forum > Operating Systems > Windows XP
User Name
Password


Virus!!! Anyone know how to remove?

Reply
 
Thread Tools Search this Thread Rate Thread Display Modes

  #1  
Old 08-18-2006, 02:40 PM
tracebusta32 Offline
Registered User
 
Join Date: Aug 2006
Posts: 2
Virus!!! Anyone know how to remove?

I have Windows XP PE..I recently was invaded with a virus that I have been trying to remove for 3 days now. I have ran Ad-aware,ewido, avg scanners and although it has cleaned out some of the items I was infected with it doesn't seem to get the one that is causing all the hassel.

I am unable to access any site such as ebay,symantec,mcafee I don't know why but it gives me a blank page. When I run ewido it says "error while quarantining" Proxy.Xorpix.ai and Proxy.small.bo and Proxy.Agent.ji

Any help would be greatly appreciated.
Reply With Quote

  #2  
Old 08-18-2006, 02:42 PM
tracebusta32 Offline
Registered User
 
Join Date: Aug 2006
Posts: 2
Here is a copy of my most recent ewido log:




Created at: 3:40:02 PM 8/18/2006

+ Scan result:



C:\WINDOWS\Temp\~486330.tmp -> Downloader.Wintool.a : Error during cleaning.
C:\WINDOWS\Temp\~515938.tmp -> Downloader.Wintool.a : Error during cleaning.
C:\WINDOWS\Temp\~582418.tmp -> Downloader.Wintool.a : Error during cleaning.
C:\WINDOWS\Temp\~601030.tmp -> Downloader.Wintool.a : Error during cleaning.
C:\WINDOWS\Temp\~666224.tmp -> Downloader.Wintool.a : Error during cleaning.
C:\WINDOWS\Temp\art2115.tmp -> Proxy.Agent.ji : Error during cleaning.
C:\WINDOWS\Temp\art4C76.tmp -> Proxy.Agent.ji : Error during cleaning.
C:\WINDOWS\SYSTEM32\stonedrv.exe -> Proxy.Small.bo : Cleaned with backup (quarantined).
C:\WINDOWS\Temp\art8400.tmp -> Proxy.Xorpix.ai : Error during cleaning.
C:\WINDOWS\Temp\art8681.tmp -> Proxy.Xorpix.ai : Error during cleaning.
[448] C:\Documents and Settings\All Users\Documents\Settings\artm_new.dll -> Proxy.Xorpix.ai : Error during cleaning.
C:\Documents and Settings\PreVue\Cookies\prevue@cbs.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\PreVue\Cookies\prevue@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\PreVue\Cookies\prevue@com[1].txt -> TrackingCookie.Com : Cleaned.
C:\Documents and Settings\PreVue\Cookies\prevue@doubleclick[2].txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\PreVue\Cookies\prevue@e-2dj6wgl4snazmho.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\PreVue\Cookies\prevue@e-2dj6wjl4slczckp.stats.esomniture[1].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\PreVue\Cookies\prevue@e-2dj6wjliencjmgo.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\PreVue\Cookies\prevue@e-2dj6wjnycodpscp.stats.esomniture[1].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\PreVue\Cookies\prevue@linksynergy[2].txt -> TrackingCookie.Linksynergy : Cleaned.
C:\Documents and Settings\PreVue\Cookies\prevue@image.masterstats[1].txt -> TrackingCookie.Masterstats : Cleaned.
C:\Documents and Settings\PreVue\Cookies\prevue@mediaplex[2].txt -> TrackingCookie.Mediaplex : Cleaned.
C:\Documents and Settings\PreVue\Cookies\prevue@tribalfusion[2].txt -> TrackingCookie.Tribalfusion : Cleaned.


::Report end
Reply With Quote

  #3  
Old 08-18-2006, 03:16 PM
tones_ie's Avatar
tones_ie Offline
Registered User
 
Join Date: Jul 2006
Posts: 208
You could try running the scan in safe mode......as u have trojans that edit the host file to stop u trying to get to sites that can fix ure prob...like antivirus sites...

You need to get rid of this C:\WINDOWS\System32\stonedrv.exe click start > run > type in taskmgr.exe

Go to the process tab then end this processes if you see them:
stonedrv.exe to allow u to be able to delete it...

Also need to get this one off C:\Documents and Settings\All Users\Documents\Settings\artm_new.dll

Suggest u delete ALL ure temp files....And open ure Host file and see if its added blocked sites to it...

In XP its found here....
C:\WINDOWS\SYSTEM32\DRIVERS\ETC

look for Hosts file and open in Notepad..
Heres a copy of what a normal host file looks like to give u an idea of anything extra u might see in ures....

Code:
# Copyright (c) 1993-1999 Microsoft Corp. # # This is a sample HOSTS file used by Microsoft TCP/IP for Windows. # # This file contains the mappings of IP addresses to host names. Each # entry should be kept on an individual line. The IP address should # be placed in the first column followed by the corresponding host name. # The IP address and the host name should be separated by at least one # space. # # Additionally, comments (such as these) may be inserted on individual # lines or following the machine name denoted by a '#' symbol. # # For example: # # 102.54.94.97 rhino.acme.com # source server # 38.25.63.10 x.acme.com # x client host 127.0.0.1 localhost

If after assuming u do have xtra comments in ure host file and u are able to delete them...i suggest u do an online scan at the links in my sig below...

**just out of curiousity can u post what u find ( if anything ) in ure host file....

*ps. In case ewido is unable to get latest definitions for watever reason heres a direct link to a manual Update
Code:
http://download.ewido.net/ewido-signatures4-full-current.exe
__________________
Ad-Aware >> http://www.lavasoftusa.com/software/adaware/
SpyBot - Search and Destroy >> http://www.safer-networking.org/en/spybotsd/index.html

Online Antivirus Scan >> http://housecall.trendmicro.com/
Online Spyware Scan >> http://www.trendmicro.com/spyware-scan/

Last edited by tones_ie : 08-18-2006 at 03:33 PM.
Reply With Quote
Reply




Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
annoying virus cable Windows XP 12 05-24-2005 11:55 AM
Blaster virus help request - thanks! owenhbrown Windows XP 8 04-30-2005 09:08 PM
virus from hell HELP! Felman Windows XP 3 02-12-2005 04:02 PM
Virus Found--How to Remove gerette Windows XP 21 09-21-2004 08:11 AM
Can't get on to antivirus/spyware remove site..HLP Gunstarr Internet 2 07-18-2004 12:34 PM



All times are GMT -5. The time now is 04:18 PM.


Designed by eXtremepixels. Powered by vBulletin Version 3.5.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 2.3.2 © 2005, Crawlability, Inc.