Jump to content


Photo

Hooray for viruses!


  • Please log in to reply
22 replies to this topic

#1 Jagged

Jagged

    Lurker

  • Member
  • Pip
  • 32 posts

Posted 05 January 2009 - 10:39 PM

I somehow managed to get a program installed, and run a .mp3 file while making a playlist. The .mp3 file was the same size as all my music files, it was called Prodigy - Spitfire, the same name as one of my files, so i had no idea it wasn't a song.

After running this Prodigy file, my PC started going nuts, windows defender picked up aload of threats and Spyware Guard 2008 was running telling me it had threats. Spyware Guard 2008 was the program installed. I quickly installed AVG and Spybot and ran them. AVG hasn't finished and so far has picked up 34 threats. Spyware Guard 2008 listed the same threats as AVG so i thought nothing of it, then i realised alot of the Threats were located in this programs directory so i hastily removed the program off my system after my brother told me that it wasn't a default windows program. Very f*cking clever program if you ask me, because windows defender was picking it up as virus protection and keeps telling me it isn't enabled.

Why im posting is this, if the virus has infected the Master Boot record, that ultimatly means the threats won't go away, Correct? If that is the case, does that mean the files on there have a high chance to be infected? And would i need new hard drives or is there away to get rid of the threat?

The other thing is, i have 3 hard drives, what are the chances it has infected all 3? I recently backed up all my Pictures, Music and Movies onto an external HDD, and i only reformatted my PC and installed Vista last week. The fact the threats are coming up now says to me they are new, but is there a possibility my files on my external HDD (before the PC alerted me about threats) are infected aswell?

I am usually VERY careful about what i download, and this is the first time in a couple of years that i have managed to get a virus..

Edited by Jagged, 05 January 2009 - 10:40 PM.

  • 0

#2 Scroll_Lock88

Scroll_Lock88

    Internetz.

  • Banned
  • 1,291 posts

Posted 05 January 2009 - 10:47 PM

Steps to clean that sh*t off:


1. Boot to safe mode immediately, longer you leave it running in standard windows the more it spreads

2. Uninstall any unwanted programs like that spyware guard 2008, and any other malware that was installed, obviously not all will willingly uninstall

3. Run your cleanup tools, antivirus, anti-malware, etc. all in safe mode May want to do a quick scan with hijackthis and scan the log entries and remove any traces of it that is left

4. Do a ccleaner after all is said and done, chances are it has done some changes to your registry and you need to fix the issues uninstalling, cleaning etc.
  • 0

#3 AssHattery

AssHattery

    Combine Zombie

  • Dedicated Member
  • PipPipPipPip
  • 333 posts

Posted 05 January 2009 - 11:04 PM

mine caught aids recently too.... was searching for another torrent site other than pirate bay and clicked on one and poof.... avg doesn't seen to be able to get rid of it one of these days i'll have to break down and get kaspersky and reformat i guess
  • 0

#4 Jagged

Jagged

    Lurker

  • Member
  • Pip
  • 32 posts

Posted 05 January 2009 - 11:12 PM

Steps to clean that sh*t off:


1. Boot to safe mode immediately, longer you leave it running in standard windows the more it spreads

2. Uninstall any unwanted programs like that spyware guard 2008, and any other malware that was installed, obviously not all will willingly uninstall

3. Run your cleanup tools, antivirus, anti-malware, etc. all in safe mode May want to do a quick scan with hijackthis and scan the log entries and remove any traces of it that is left

4. Do a ccleaner after all is said and done, chances are it has done some changes to your registry and you need to fix the issues uninstalling, cleaning etc.


How do i manually uninstall the malware? And removing the traces? I'm not good with this kinda crap lol
  • 0

#5 Scroll_Lock88

Scroll_Lock88

    Internetz.

  • Banned
  • 1,291 posts

Posted 05 January 2009 - 11:37 PM

How do i manually uninstall the malware? And removing the traces? I'm not good with this kinda crap lol



Go into add/remove programs and uninstall the unwanted ones, some uninstall, some dont, obviously they come back but it's the first step in cleanup.



When you download and install hijackthis and you analyze, it will give you a large list of items on it. Copy and paste that log into here and I can tell you which ones to remove, do not go crazy with it because it picks up things that windows requires to run. It's a very powerful program but it gets the job done. Just make sure you run spybot first and use hijackthis for the end cleanup.
  • 0

#6 Sniprwulf

Sniprwulf

    demolition expert

  • Dedicated Member
  • PipPipPipPipPipPipPipPip
  • 2,479 posts

Posted 06 January 2009 - 12:15 AM

yeah, scroll's a nerd.
  • 0

#7 AssHattery

AssHattery

    Combine Zombie

  • Dedicated Member
  • PipPipPipPip
  • 333 posts

Posted 06 January 2009 - 12:34 AM

sounds like he's got lots of experience with the aids haha
  • 0

#8 Jagged

Jagged

    Lurker

  • Member
  • Pip
  • 32 posts

Posted 06 January 2009 - 02:48 AM

Heres the log file scroll

Logfile of HijackThis v1.99.1
Scan saved at 07:46:52, on 06/01/2009
Platform: Unknown Windows (WinNT 6.00.1905 SP1)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)

Running processes:
C:\Program Files\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O1 - Hosts: ::1 localhost
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG8\avgssie.dll
O2 - BHO: C:\Windows\SysWow64\rwhbfb873unjdfdg.dll - {C5BF49A2-94F3-42BD-F434-3604812C8955} - C:\Windows\SysWow64\rwhbfb873unjdfdg.dll (file missing)
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~2\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [jsf8uiw3jnjgffght] C:\Users\Rob\AppData\Local\Temp\winlogin.exe
O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
O4 - HKCU\..\Run: [Steam] "E:\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Speech Recognition] "C:\Windows\Speech\Common\sapisvr.exe" -SpeechUX -Startup
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files (x86)\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Windows Logon Applicationedc] C:\Users\Rob\winlogon.exe
O4 - HKCU\..\Run: [jsf8uiw3jnjgffght] C:\Users\Rob\AppData\Local\Temp\winlogin.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nlaapi.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\napinsp.dll
O11 - Options group: [INTERNATIONAL] International*
O13 - Gopher Prefix:
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG8\avgpp.dll
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O21 - SSODL: ieModule - {B7BCEB3C-4C53-4E1B-938A-B2FAC65854A6} - C:\ProgramData\Application Data\Microsoft\Internet Explorer\DLLs\ieModule.dll
O21 - SSODL: InternetConnection - {24A2FD17-7EE6-433C-A547-B02CE3B4E2B7} - C:\ProgramData\Application Data\Microsoft\Internet Explorer\DLLs\dcokagmpmg.dll
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~2\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~2\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
O23 - Service: @%SystemRoot%\ehome\ehstart.dll,-101 (ehstart) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Firebird Guardian - DefaultInstance (FirebirdGuardianDefaultInstance) - FirebirdSQL Project - C:\Program Files (x86)\Firebird\Firebird_2_1\bin\fbguard.exe
O23 - Service: Firebird Server - DefaultInstance (FirebirdServerDefaultInstance) - FirebirdSQL Project - C:\Program Files (x86)\Firebird\Firebird_2_1\bin\fbserver.exe
O23 - Service: GEST Service for program management. (GEST Service) - Unknown owner - C:\Program Files (x86)\GIGABYTE\EnergySaver\GSvr.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files (x86)\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\Windows\system32\PnkBstrB.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: TVersityMediaServer - Unknown owner - C:\Program Files (x86)\TVersity\Media Server\MediaServer.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - %ProgramFiles%\Windows Media Player\wmpnetwk.exe (file missing)
  • 0

#9 DarkShadow

DarkShadow

    Elitist Fuck

  • Gods
  • PipPipPipPipPipPipPipPip
  • 4,746 posts

Posted 06 January 2009 - 03:13 AM

Heres the log file scroll

Logfile of HijackThis v1.99.1
Scan saved at 07:46:52, on 06/01/2009
Platform: Unknown Windows (WinNT 6.00.1905 SP1)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)

Running processes:
C:\Program Files\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O1 - Hosts: ::1 localhost
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG8\avgssie.dll
O2 - BHO: C:\Windows\SysWow64\rwhbfb873unjdfdg.dll - {C5BF49A2-94F3-42BD-F434-3604812C8955} - C:\Windows\SysWow64\rwhbfb873unjdfdg.dll (file missing)
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~2\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [jsf8uiw3jnjgffght] C:\Users\Rob\AppData\Local\Temp\winlogin.exe
O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
O4 - HKCU\..\Run: [Steam] "E:\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Speech Recognition] "C:\Windows\Speech\Common\sapisvr.exe" -SpeechUX -Startup
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files (x86)\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Windows Logon Applicationedc] C:\Users\Rob\winlogon.exe
O4 - HKCU\..\Run: [jsf8uiw3jnjgffght] C:\Users\Rob\AppData\Local\Temp\winlogin.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nlaapi.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\napinsp.dll

O11 - Options group: [INTERNATIONAL] International*
O13 - Gopher Prefix:

O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG8\avgpp.dll
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WI1F86~1\MESSEN~1\MSGRAP~1.DLL

O21 - SSODL: ieModule - {B7BCEB3C-4C53-4E1B-938A-B2FAC65854A6} - C:\ProgramData\Application Data\Microsoft\Internet Explorer\DLLs\ieModule.dll
O21 - SSODL: InternetConnection - {24A2FD17-7EE6-433C-A547-B02CE3B4E2B7} - C:\ProgramData\Application Data\Microsoft\Internet Explorer\DLLs\dcokagmpmg.dll
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~2\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~2\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
O23 - Service: @%SystemRoot%\ehome\ehstart.dll,-101 (ehstart) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)

O23 - Service: Firebird Guardian - DefaultInstance (FirebirdGuardianDefaultInstance) - FirebirdSQL Project - C:\Program Files (x86)\Firebird\Firebird_2_1\bin\fbguard.exe
O23 - Service: Firebird Server - DefaultInstance (FirebirdServerDefaultInstance) - FirebirdSQL Project - C:\Program Files (x86)\Firebird\Firebird_2_1\bin\fbserver.exe
O23 - Service: GEST Service for program management. (GEST Service) - Unknown owner - C:\Program Files (x86)\GIGABYTE\EnergySaver\GSvr.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files (x86)\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)

O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\Windows\system32\PnkBstrB.exe

O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)

O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: TVersityMediaServer - Unknown owner - C:\Program Files (x86)\TVersity\Media Server\MediaServer.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - %ProgramFiles%\Windows Media Player\wmpnetwk.exe (file missing)


Those stand out a bit, fuck with them as you want, also some others, but tbh anything marked as file missing = bad/delete

Lot of the viruses came from C:\Users\Rob btw, so that'll also give some of an idea
  • 0

#10 Jagged

Jagged

    Lurker

  • Member
  • Pip
  • 32 posts

Posted 06 January 2009 - 02:42 PM

Ok cool, thanks for the help everyone.



After fixing the items, highjackthis said "Hijhackthis cannot repair 010 Winsock LSP entries. You should use LSPFix for that, which is available from [url="http://www.cexx.org/lspfix""]http://www.cexx.org/lspfix"[/url] But it is another program i don't know about. Has anyone used this before?

Edited by Jagged, 06 January 2009 - 02:51 PM.

  • 0

#11 Scroll_Lock88

Scroll_Lock88

    Internetz.

  • Banned
  • 1,291 posts

Posted 06 January 2009 - 03:10 PM

Ok cool, thanks for the help everyone.



After fixing the items, highjackthis said "Hijhackthis cannot repair 010 Winsock LSP entries. You should use LSPFix for that, which is available from [url="http://www.cexx.org/lspfix""]http://www.cexx.org/lspfix"[/url] But it is another program i don't know about. Has anyone used this before?



That is a program to use, used it myself and it fixed all winsock LSP entries i've encountered.

http://www.cexx.org/lspfix.htm

Correct link btw
  • 0

#12 Jagged

Jagged

    Lurker

  • Member
  • Pip
  • 32 posts

Posted 06 January 2009 - 03:42 PM

Right, AVG and Spybot don't appear to have picked up anymore threats so thank youto everyone who helped :D
  • 0

#13 wondergod

wondergod

    i'm colored

  • Dedicated Member
  • PipPipPipPipPipPip
  • 1,241 posts

Posted 06 January 2009 - 04:12 PM

Don't forget to install Weatherbug right after so you can tell the weather.
  • 0

#14 Unlikely

Unlikely

    Combine Soldier

  • Dedicated Member
  • PipPipPip
  • 125 posts

Posted 06 January 2009 - 04:24 PM

i loved avg until avg8. i use avast now. i think someone mentioned it earlier, but pick up CCleaner as well.

http://www.ccleaner.com/
  • 0

#15 Jagged

Jagged

    Lurker

  • Member
  • Pip
  • 32 posts

Posted 08 January 2009 - 09:21 AM

Since i removed those things with Highjackthis, IE no longer displays pictures. They all come up with a box and a red X :( I use Firefox mainly, but when i check my emails i do it through MSN so it automatically loads IE, and if i need to download a .PDF i have to do it in IE cos firefox was being gay about it.
  • 0

#16 Scroll_Lock88

Scroll_Lock88

    Internetz.

  • Banned
  • 1,291 posts

Posted 08 January 2009 - 06:27 PM

Disregard the crap I put up on here, when vista first came out you werent able to uninstall IE (hotfix fixed this)

It will show up if you click on show updates in your add/remove programs. Redownload it using the integrated windows updater :D
  • 0

#17 DarkShadow

DarkShadow

    Elitist Fuck

  • Gods
  • PipPipPipPipPipPipPipPip
  • 4,746 posts

Posted 08 January 2009 - 06:31 PM

Since i removed those things with Highjackthis, IE no longer displays pictures. They all come up with a box and a red X :( I use Firefox mainly, but when i check my emails i do it through MSN so it automatically loads IE, and if i need to download a .PDF i have to do it in IE cos firefox was being gay about it.


Stop using IE completely for fuck sake!

Firefox, the end to your problems.
  • 0

#18 wondergod

wondergod

    i'm colored

  • Dedicated Member
  • PipPipPipPipPipPip
  • 1,241 posts

Posted 08 January 2009 - 07:25 PM

Stop using IE completely for fuck sake!

Firefox, the end to your problems.



Ahem,

Firefox + Foxit PDF Reader

shoot even IE + Foxit Reader

Adobe PDF Viewer is utter garbage IMHO. I hate the fact its browser integrated it slows down your browser 10000000 fold.
  • 0

#19 Jagged

Jagged

    Lurker

  • Member
  • Pip
  • 32 posts

Posted 10 January 2009 - 02:33 PM

Stop using IE completely for f*ck sake!

Firefox, the end to your problems.


I do! But when i select inbox on msn, it uses IE, if i can completely remove it, i will.
  • 0

#20 PinkPanther

PinkPanther

    Lurker

  • Member
  • Pip
  • 28 posts

Posted 10 January 2009 - 06:20 PM

Just go under your Internet options and make firefox your default browser
  • 0


0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users