Antivirus Protection
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
User Name:
Password:
Remember me
Go Back   Dev Shed ForumsSystem AdministrationAntivirus Protection

Closed Thread
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread Dev Shed Forums Sponsor:
  #1  
Old April 28th, 2005, 01:21 PM
SnowWhite's Avatar
SnowWhite SnowWhite is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Nov 2004
Posts: 79 SnowWhite User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 19 h 28 m 22 sec
Reputation Power: 4
Unhappy Drowning in Spyware!

Hi,

Here's my problem, and I am at my wits end, so I hope to find some suggestions on my favorite forum.

In a nutshell, my husband turned off our popup stopper. My teenager then got on the computer and hit some cheat code sites for his xbox, which of course are loaded with popups. So then Zone Alarm pops up with a zillion "Do you want blah, blah, blah to access the internet?". Which of course, he responds "yes" to every one, thereby loading up our once happy Windows XP with hundreds of lovely little spywares. {sigh}

We have tried everything to try and get this stuff off our PC. Obviously we've used Spybot and AdAware, but the stuff just keeps coming back. We've looked at the registry, reconfigured Zone Alarm and Norton, etc. etc.

We can't use the browser anymore (IE or Mozilla) because it just redirects us to some ad / porn site.

Am I at a point where I need to do a Windows re-install, reformat of the motherboard, or what??

Any suggestions would be GREATLY appreciated.

Thanks so much,
~Snow

Reply With Quote
  #2  
Old April 28th, 2005, 02:54 PM
megumi amatuka megumi amatuka is offline
Contributing User
Dev Shed Demi-God (4500 - 4999 posts)
 
Join Date: Jun 2004
Posts: 4,869 megumi amatuka User rank is Major (30000 - 40000 Reputation Level)megumi amatuka User rank is Major (30000 - 40000 Reputation Level)megumi amatuka User rank is Major (30000 - 40000 Reputation Level)megumi amatuka User rank is Major (30000 - 40000 Reputation Level)megumi amatuka User rank is Major (30000 - 40000 Reputation Level)megumi amatuka User rank is Major (30000 - 40000 Reputation Level)megumi amatuka User rank is Major (30000 - 40000 Reputation Level)megumi amatuka User rank is Major (30000 - 40000 Reputation Level)megumi amatuka User rank is Major (30000 - 40000 Reputation Level)megumi amatuka User rank is Major (30000 - 40000 Reputation Level) 
Time spent in forums: 2 Months 6 Days 21 h 24 m 42 sec
Reputation Power: 333
(^^;?(Clean installation highly recommended as purely as SnowWhite.)

Any anti-virus-spyware can be disabled by anti-anti-spyware-virus (=real Trojan) executed by administrator right.

Clean Install Windows and disable Automatic Update. Disable all scripts and activeX control. Use such a browser that can disable scripts with easy interface.

If you want to try to remove spywares by all means, post Hijackthis log to Antivirus Forum.

Reply With Quote
  #3  
Old April 28th, 2005, 02:56 PM
aitken325i's Avatar
aitken325i aitken325i is offline
At a NO MA'AM meeting . . . .
Dev Shed God 18th Plane (13500 - 13999 posts)
 
Join Date: Mar 2004
Location: nr Edinburgh, Scotland
Posts: 13,542 aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)  Folding Points: 10110 Folding Title: Novice Folder
Time spent in forums: 5 Months 2 Weeks 1 Day 7 h 2 m 26 sec
Reputation Power: 1952
Have you tried posting a HiJackThis log in the Anti-Virus forum ??

I'd give that a wee try first before you go re-formatting and re-installing windows again !
__________________
The No Ma'am commandments:

1.) It is O.K. to call hooters 'knockers' and sometimes snack trays
2.) It is wrong to be French
3.) It is O.K. to put all bad people in a giant meat grinder
4.) Lawyers, see rule 3
5.) It is O.K. to drive a gas guzzler if it helps you get babes
6.) Everyone should car pool but me
7.) Bring back the word 'stewardesses'
8.) Synchronized swimming is not a sport
9.) Mud wrestling is a sport

Reply With Quote
  #4  
Old April 28th, 2005, 03:23 PM
jharnois's Avatar
jharnois jharnois is offline
mod_dev_shed
Dev Shed God 19th Plane (14000 - 14499 posts)
 
Join Date: Sep 2002
Location: Atlanta, GA
Posts: 14,424 jharnois User rank is Major General (70000 - 90000 Reputation Level)jharnois User rank is Major General (70000 - 90000 Reputation Level)jharnois User rank is Major General (70000 - 90000 Reputation Level)jharnois User rank is Major General (70000 - 90000 Reputation Level)jharnois User rank is Major General (70000 - 90000 Reputation Level)jharnois User rank is Major General (70000 - 90000 Reputation Level)jharnois User rank is Major General (70000 - 90000 Reputation Level)jharnois User rank is Major General (70000 - 90000 Reputation Level)jharnois User rank is Major General (70000 - 90000 Reputation Level)jharnois User rank is Major General (70000 - 90000 Reputation Level)jharnois User rank is Major General (70000 - 90000 Reputation Level)jharnois User rank is Major General (70000 - 90000 Reputation Level)jharnois User rank is Major General (70000 - 90000 Reputation Level)jharnois User rank is Major General (70000 - 90000 Reputation Level) 
Time spent in forums: 1 Month 1 Week 2 Days 12 h 58 m 27 sec
Reputation Power: 812
If you do end up with a fresh Windows install, look into different user groups to prevent others from doing things you don't want them to do w/o you knowing.
__________________
# Jeremy

Explain your problem instead of asking how to do what you decided was the solution.

Reply With Quote
  #5  
Old April 28th, 2005, 10:36 PM
Andrew80's Avatar
Andrew80 Andrew80 is offline
Advanced Programmer
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Dec 2004
Location: Malaysia
Posts: 445 Andrew80 User rank is Sergeant Major (2000 - 5000 Reputation Level)Andrew80 User rank is Sergeant Major (2000 - 5000 Reputation Level)Andrew80 User rank is Sergeant Major (2000 - 5000 Reputation Level)Andrew80 User rank is Sergeant Major (2000 - 5000 Reputation Level)Andrew80 User rank is Sergeant Major (2000 - 5000 Reputation Level)Andrew80 User rank is Sergeant Major (2000 - 5000 Reputation Level) 
Time spent in forums: 3 Days 11 h 28 m 46 sec
Reputation Power: 35
Send a message via MSN to Andrew80 Send a message via Yahoo to Andrew80
Run a few spyware removers. i recommend spybot search and destroy and lavasoft adaware.

Full scan and remove all the viruses, cookies and whatever it may find.

If still hijacked, Clean out all your browser caches,plugins and objects, then re-install your browsers.
__________________
"Computer games don't affect kids; I mean if Pac-Man affected us as kids, we'd all be running around in darkened rooms, munching magic pills and listening to repetitive electronic music."
- Kristin Wilson, Nintendo, Inc., 1989.

Reply With Quote
  #6  
Old April 29th, 2005, 01:18 AM
Doug G Doug G is offline
Grumpier Old Moderator
Dev Shed God 12th Plane (10500 - 10999 posts)
 
Join Date: Jun 2003
Posts: 10,957 Doug G User rank is Major General (70000 - 90000 Reputation Level)Doug G User rank is Major General (70000 - 90000 Reputation Level)Doug G User rank is Major General (70000 - 90000 Reputation Level)Doug G User rank is Major General (70000 - 90000 Reputation Level)Doug G User rank is Major General (70000 - 90000 Reputation Level)Doug G User rank is Major General (70000 - 90000 Reputation Level)Doug G User rank is Major General (70000 - 90000 Reputation Level)Doug G User rank is Major General (70000 - 90000 Reputation Level)Doug G User rank is Major General (70000 - 90000 Reputation Level)Doug G User rank is Major General (70000 - 90000 Reputation Level)Doug G User rank is Major General (70000 - 90000 Reputation Level)Doug G User rank is Major General (70000 - 90000 Reputation Level)Doug G User rank is Major General (70000 - 90000 Reputation Level)Doug G User rank is Major General (70000 - 90000 Reputation Level) 
Time spent in forums: 1 Month 1 Day 15 h 35 m 19 sec
Reputation Power: 802
Run a virus scan as well

Get the Microsoft antispyware program which seems to find stuff that spybot and adaware miss.
__________________
======
Doug G
======
I didn't attend the funeral, but I sent a nice letter saying I approved
of it. --Mark Twain

Reply With Quote
  #7  
Old April 29th, 2005, 12:56 PM
edwinbrains's Avatar
edwinbrains edwinbrains is offline
Retired Moderator
Dev Shed God 4th Plane (6500 - 6999 posts)
 
Join Date: Jan 2004
Location: London, UK
Posts: 6,670 edwinbrains User rank is Second Lieutenant (5000 - 10000 Reputation Level)edwinbrains User rank is Second Lieutenant (5000 - 10000 Reputation Level)edwinbrains User rank is Second Lieutenant (5000 - 10000 Reputation Level)edwinbrains User rank is Second Lieutenant (5000 - 10000 Reputation Level)edwinbrains User rank is Second Lieutenant (5000 - 10000 Reputation Level)edwinbrains User rank is Second Lieutenant (5000 - 10000 Reputation Level)edwinbrains User rank is Second Lieutenant (5000 - 10000 Reputation Level)  Folding Points: 85411 Folding Title: Advanced FolderFolding Points: 85411 Folding Title: Advanced FolderFolding Points: 85411 Folding Title: Advanced FolderFolding Points: 85411 Folding Title: Advanced FolderFolding Points: 85411 Folding Title: Advanced Folder
Time spent in forums: 1 Week 6 Days 23 h 39 m 19 sec
Reputation Power: 92
Thread moved from Windows Help to Antivirus Protection.
__________________
- Edwin -

The General Rules Thread | The General FAQ Thread

Reply With Quote
  #8  
Old May 6th, 2005, 12:47 PM
oneMSBi's Avatar
oneMSBi oneMSBi is offline
CAUTION: Loderator Moose
Dev Shed Loyal (3000 - 3499 posts)
 
Join Date: Nov 2004
Location: some starry place (india)
Posts: 3,431 oneMSBi User rank is First Lieutenant (10000 - 20000 Reputation Level)oneMSBi User rank is First Lieutenant (10000 - 20000 Reputation Level)oneMSBi User rank is First Lieutenant (10000 - 20000 Reputation Level)oneMSBi User rank is First Lieutenant (10000 - 20000 Reputation Level)oneMSBi User rank is First Lieutenant (10000 - 20000 Reputation Level)oneMSBi User rank is First Lieutenant (10000 - 20000 Reputation Level)oneMSBi User rank is First Lieutenant (10000 - 20000 Reputation Level)oneMSBi User rank is First Lieutenant (10000 - 20000 Reputation Level) 
Time spent in forums: 4 Weeks 1 Day 21 h 34 m 19 sec
Reputation Power: 156
whats your staus now ?
__________________
Nigel
..Seeking code free nirvana...
Nigel Fernandes Blog
Never argue with fools. They will bring you down to their level and beat you with experience.


Manchester United Forever

Reply With Quote
  #9  
Old May 9th, 2005, 04:24 PM
SnowWhite's Avatar
SnowWhite SnowWhite is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Nov 2004
Posts: 79 SnowWhite User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 19 h 28 m 22 sec
Reputation Power: 4
Unhappy Still hosed...

Hi, and thanks for your suggestions.

Status as of today:

Have run adaware, spybot, virus check, trojan remover, disabled scripts in browser. Haven't uninstalled/reinstalled anything yet. Things seem to be better after running all of these things, but if we have to restart or shut down - we're right back where we started. So, does this mean it's living in the registry somewhere??

I've only done one reinstall of Windows in my geek career - and that was Windows 98. So, after uninstalling Windows, I need to reformat the hard disk and then reinstall, correct? Is this a surefire way of killing any sneaky little bugs that may be deeply embedded? Want to make sure that I'm truly starting fresh.

Thanks so much - and thanks to edwinbrains for moving my post over to this Forum.

~Snow

Reply With Quote
  #10  
Old May 11th, 2005, 09:37 AM
Tom Myboy Tom Myboy is offline
Contributing User
Dev Shed Regular (2000 - 2499 posts)
 
Join Date: Aug 2003
Posts: 2,491 Tom Myboy User rank is Sergeant (500 - 2000 Reputation Level)Tom Myboy User rank is Sergeant (500 - 2000 Reputation Level)Tom Myboy User rank is Sergeant (500 - 2000 Reputation Level)Tom Myboy User rank is Sergeant (500 - 2000 Reputation Level)Tom Myboy User rank is Sergeant (500 - 2000 Reputation Level) 
Time spent in forums: 3 Days 20 h 13 m 41 sec
Reputation Power: 14
Hi SnowWhite,

Please download HijackThis. Make sure you install HijackThis to a permanent folder such as C:\HJT as it creates backups of what we will fix.

Run the program, click the button at the top "Do a system scan and save a logfile". Save the log to a convenient place such as C:\HJT Notepad will open, copy and paste the entire log into your post. Do not fix anything yet, most of what's in the log is needed!

http://www.majorgeeks.com/download3155.html

Tom
__________________
HijackThis
Ad-aware
Spybot Search & Destroy
SpywareBlaster
SpywareGuard
Housecall Online A/V Scan

Please read the stickys at the top of the forum before posting!

Reply With Quote
  #11  
Old May 23rd, 2005, 09:17 PM
SnowWhite's Avatar
SnowWhite SnowWhite is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Nov 2004
Posts: 79 SnowWhite User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 19 h 28 m 22 sec
Reputation Power: 4
Hi again ~

Here are the results of my HijackThis scan - I really appreciate the help!!

Logfile of HijackThis v1.99.1
Scan saved at 7:05:56 PM, on 5/23/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\unuzpr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\POP-UP~1\PSFree.exe
C:\Program Files\Messenger\MSMSGS.EXE
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\rundll32.exe
C:\HJT\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/yc...//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://red.clientapps.yahoo.com/cus...://my.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://red.clientapps.yahoo.com/cus...//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/cus...//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://red.clientapps.yahoo.com/cus...://my.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/cus...//www.yahoo.com
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll
O4 - HKLM\..\Run: [C-Media Mixer] NOT_Mixer.exe /startup
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
O4 - HKLM\..\Run: [TkBellExe] "NOT_C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [TrojanScanner] C:\Program Files\Trojan Remover\Trjscan.exe
O4 - HKLM\..\Run: [KavSvc] C:\WINDOWS\system32\unuzpr.exe reg_run
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\POP-UP~1\PSFree.exe"
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [audiodev] NOT_C:\WINDOWS\System32\audiodev.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Get It With Kontiki - res://C:\Program Files\Kontiki\bin\bh309190.dll/201
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_06\bin\npjpi142_06.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_06\bin\npjpi142_06.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\winlspak.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\winlspak.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\winlspak.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\dolsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\dolsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\dolsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\dolsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\winlspak.dll
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - http://us.dl1.yimg.com/download.yah.../ymmapi_416.dll
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/gam...aploader_v6.cab
O20 - Winlogon Notify: policies - C:\WINDOWS\system32\h84m0ih1e84.dll
O23 - Service: pcAnywhere Host Service (awhost32) - Symantec Corporation - C:\Program Files\Symantec\pcAnywhere\awhost32.exe
O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

Reply With Quote
  #12  
Old May 24th, 2005, 05:24 PM
Tom Myboy Tom Myboy is offline
Contributing User
Dev Shed Regular (2000 - 2499 posts)
 
Join Date: Aug 2003
Posts: 2,491 Tom Myboy User rank is Sergeant (500 - 2000 Reputation Level)Tom Myboy User rank is Sergeant (500 - 2000 Reputation Level)Tom Myboy User rank is Sergeant (500 - 2000 Reputation Level)Tom Myboy User rank is Sergeant (500 - 2000 Reputation Level)Tom Myboy User rank is Sergeant (500 - 2000 Reputation Level) 
Time spent in forums: 3 Days 20 h 13 m 41 sec
Reputation Power: 14
You appear to be infected with Virtumundo/VirtuMonde

If you have any questions, please don't hesitate to ask.

I'd like you to download and run Symantec's VirtuMonde Removal Tool:

http://securityresponse.symantec.co...er/FixVundo.exe

Follow these steps to download and run the tool:

1. Download the FixVundo.exe file
2. Save the file to a convenient location, such as your Desktop.
3. Close all the running programs.
4. If you are on a network or if you have a full-time connection to the Internet, disconnect the computer from the network and the Internet.
5. Double-click the FixVundo.exe file to start the removal tool.
6. Click Start to begin the process, and then allow the tool to run.

Do not launch any new applications while the tool is running!

7. Restart the computer.
8. Run the removal tool again to ensure that the system is clean.
9. Purge System Restore with the directions below:

1 Right-click My Computer, and then click Properties.
2 Click the System Restore tab.
3 Check the "Turn off System Restore" or "Turn off System Restore on all drives" check box.
4 Click Apply
5 this will delete all existing restore points. Click Yes to do this.
6 Click OK.

Reboot

1 Right-click My Computer, and then click Properties.
2 Click the System Restore tab.
3 Uncheck the "Turn off System Restore" or "Turn off System Restore on all drives" check box.
4 Click Apply
5 Click OK.

Create a new Restore Point:

Start > All Programs > Accessories > System Tools > System Restore > tick Create a Restore Point > Next > enter a name for the Restore Point Creation (Today, Removed Spyware, etc.) > Create > Close.

The date and time will automatically be added.

Next...

Let's do some more cleaning up:

Download Ad-Aware SE Personal Edition version 1.05 from:

http://www.lavasoft.de/support/download/

Run Adaware, click the "Check for Updates now" link. Install the latest reference file

Perform a full system scan with Adaware, allow it to remove anything it finds. It may ask if it can run the next time your computer boots, allow it to do so.

Then...

Download Spybot - Search & Destroy 1.3 from.

http://www.safer-networking.org/en/download/index.html

Make sure you are online, run Spybot - Search & Destroy, click the "Check for Updates now" link. Install the latest reference file

Scan and fix all items checked in RED.

Reboot and post a fresh HijackThis log.

Tom