Author Topic: [Resolved] Coupla Virus problems (Hijack log attached)  (Read 3528 times)

0 Members and 1 Guest are viewing this topic.

Online Hoov

  • Malware Removal Mentors
  • Global Moderator
  • Diamond Member
  • Posts: 22685
  • Unwilling part owner of Gov't. Motors and Chrysler
    • Hoov's Personal Site
Re: [In Progress] Coupla Virus problems (Hijack log attached)
« Reply #45 on: February 21, 2011, 02:15:54 PM »
The only other thing I can think of trying, is plugging the thumbdrive into each of the other USB ports and see if you can boot to it from them. If that doesn't work, we will drop this and try something else.

Consumer Security

If I am helping you and you don't hear from me for 24Hrs, send me a PM Please!

Offline bushka

  • Bronze Member
  • Posts: 134
Re: [In Progress] Coupla Virus problems (Hijack log attached)
« Reply #46 on: February 21, 2011, 03:51:13 PM »
No such luck.  It's really frustrating because I can see how powerful booting up from the thumb drive can be.

What do you think about plan B?  I'm not having the same problems I had before I ran TDSSKiller.  Would a new hijackthis log or other be of any help at this point?

Online Hoov

  • Malware Removal Mentors
  • Global Moderator
  • Diamond Member
  • Posts: 22685
  • Unwilling part owner of Gov't. Motors and Chrysler
    • Hoov's Personal Site
Re: [In Progress] Coupla Virus problems (Hijack log attached)
« Reply #47 on: February 21, 2011, 04:32:45 PM »
Lets start from scratch. We start from right now. What problems are you having right now?

Consumer Security

If I am helping you and you don't hear from me for 24Hrs, send me a PM Please!

Offline bushka

  • Bronze Member
  • Posts: 134
Re: [In Progress] Coupla Virus problems (Hijack log attached)
« Reply #48 on: February 21, 2011, 04:57:42 PM »
Actually I'm not having any problem, except very sporadically I'm getting a message from Avira about the Uploader virus.  It seemed to occur when Malwarebytes was running, but it didn't occur the last time I ran it.  If you prefer, we can close this thread and I can report back the next time something happens.  Whatever you prefer.  It's just too bad the flash drive thing didn't work.  It would have been nice to have that option in the future.

Online Hoov

  • Malware Removal Mentors
  • Global Moderator
  • Diamond Member
  • Posts: 22685
  • Unwilling part owner of Gov't. Motors and Chrysler
    • Hoov's Personal Site
Re: [In Progress] Coupla Virus problems (Hijack log attached)
« Reply #49 on: February 21, 2011, 06:02:06 PM »
Do you have a log from Avira showing the message?

Consumer Security

If I am helping you and you don't hear from me for 24Hrs, send me a PM Please!

Offline bushka

  • Bronze Member
  • Posts: 134
Re: [In Progress] Coupla Virus problems (Hijack log attached)
« Reply #50 on: February 22, 2011, 08:44:48 AM »
I just ran an Avira scan and it doesn't look like it found anything.  Maybe one of the ccleaner or TDSS scans got rid of it and I didn't realize?  Here's the report:



Avira AntiVir Personal
Report file date: Tuesday, February 22, 2011  09:03

Scanning for 2418306 virus strains and unwanted programs.

The program is running as an unrestricted full version.
Online services are available:

Licensee        : Avira AntiVir Personal - FREE Antivirus
Serial number   : 0000149996-ADJIE-0000001
Platform        : Windows XP
Windows version : (Service Pack 3)  [5.1.2600]
Boot mode       : Normally booted
Username        : SYSTEM
Computer name   : TOSHIBA-USER

Version information:
BUILD.DAT       : 10.0.0.611     31824 Bytes   1/14/2011 13:42:00
AVSCAN.EXE      : 10.0.3.5      435368 Bytes   1/10/2011 19:23:31
AVSCAN.DLL      : 10.0.3.0       46440 Bytes    4/1/2010 17:57:04
LUKE.DLL        : 10.0.3.2      104296 Bytes   1/10/2011 19:23:40
LUKERES.DLL     : 10.0.0.1       12648 Bytes   2/11/2010 04:40:49
VBASE000.VDF    : 7.10.0.0    19875328 Bytes   11/6/2009 14:05:36
VBASE001.VDF    : 7.11.0.0    13342208 Bytes  12/14/2010 19:23:50
VBASE002.VDF    : 7.11.3.0     1950720 Bytes    2/9/2011 21:21:48
VBASE003.VDF    : 7.11.3.1        2048 Bytes    2/9/2011 21:21:48
VBASE004.VDF    : 7.11.3.2        2048 Bytes    2/9/2011 21:21:48
VBASE005.VDF    : 7.11.3.3        2048 Bytes    2/9/2011 21:21:48
VBASE006.VDF    : 7.11.3.4        2048 Bytes    2/9/2011 21:21:48
VBASE007.VDF    : 7.11.3.5        2048 Bytes    2/9/2011 21:21:48
VBASE008.VDF    : 7.11.3.6        2048 Bytes    2/9/2011 21:21:48
VBASE009.VDF    : 7.11.3.7        2048 Bytes    2/9/2011 21:21:49
VBASE010.VDF    : 7.11.3.8        2048 Bytes    2/9/2011 21:21:49
VBASE011.VDF    : 7.11.3.9        2048 Bytes    2/9/2011 21:21:49
VBASE012.VDF    : 7.11.3.10       2048 Bytes    2/9/2011 21:21:49
VBASE013.VDF    : 7.11.3.59     157184 Bytes   2/14/2011 21:21:50
VBASE014.VDF    : 7.11.3.97     120320 Bytes   2/16/2011 21:21:50
VBASE015.VDF    : 7.11.3.148    128000 Bytes   2/19/2011 15:07:03
VBASE016.VDF    : 7.11.3.149      2048 Bytes   2/19/2011 15:07:03
VBASE017.VDF    : 7.11.3.150      2048 Bytes   2/19/2011 15:07:03
VBASE018.VDF    : 7.11.3.151      2048 Bytes   2/19/2011 15:07:03
VBASE019.VDF    : 7.11.3.152      2048 Bytes   2/19/2011 15:07:03
VBASE020.VDF    : 7.11.3.153      2048 Bytes   2/19/2011 15:07:04
VBASE021.VDF    : 7.11.3.154      2048 Bytes   2/19/2011 15:07:04
VBASE022.VDF    : 7.11.3.155      2048 Bytes   2/19/2011 15:07:04
VBASE023.VDF    : 7.11.3.156      2048 Bytes   2/19/2011 15:07:04
VBASE024.VDF    : 7.11.3.157      2048 Bytes   2/19/2011 15:07:04
VBASE025.VDF    : 7.11.3.158      2048 Bytes   2/19/2011 15:07:04
VBASE026.VDF    : 7.11.3.159      2048 Bytes   2/19/2011 15:07:04
VBASE027.VDF    : 7.11.3.160      2048 Bytes   2/19/2011 15:07:05
VBASE028.VDF    : 7.11.3.161      2048 Bytes   2/19/2011 15:07:05
VBASE029.VDF    : 7.11.3.162      2048 Bytes   2/19/2011 15:07:05
VBASE030.VDF    : 7.11.3.163      2048 Bytes   2/19/2011 15:07:05
VBASE031.VDF    : 7.11.3.169     40960 Bytes   2/21/2011 15:07:05
Engineversion   : 8.2.4.170
AEVDF.DLL       : 8.1.2.1       106868 Bytes   1/10/2011 19:23:26
AESCRIPT.DLL    : 8.1.3.53     1282427 Bytes   2/16/2011 21:22:02
AESCN.DLL       : 8.1.7.2       127349 Bytes   1/10/2011 19:23:26
AESBX.DLL       : 8.1.3.2       254324 Bytes   1/10/2011 19:23:26
AERDL.DLL       : 8.1.9.2       635252 Bytes   1/10/2011 19:23:25
AEPACK.DLL      : 8.2.4.9       512374 Bytes   2/16/2011 21:22:01
AEOFFICE.DLL    : 8.1.1.16      205179 Bytes   2/16/2011 21:22:00
AEHEUR.DLL      : 8.1.2.78     3277175 Bytes   2/21/2011 15:07:10
AEHELP.DLL      : 8.1.16.1      246134 Bytes   2/16/2011 21:21:55
AEGEN.DLL       : 8.1.5.2       397683 Bytes   2/16/2011 21:21:55
AEEMU.DLL       : 8.1.3.0       393589 Bytes   1/10/2011 19:23:18
AECORE.DLL      : 8.1.19.2      196983 Bytes   2/16/2011 21:21:54
AEBB.DLL        : 8.1.1.0        53618 Bytes   1/10/2011 19:23:18
AVWINLL.DLL     : 10.0.0.0       19304 Bytes   1/10/2011 19:23:32
AVPREF.DLL      : 10.0.0.0       44904 Bytes   1/10/2011 19:23:30
AVREP.DLL       : 10.0.0.8       62209 Bytes   6/17/2010 19:27:13
AVREG.DLL       : 10.0.3.2       53096 Bytes   1/10/2011 19:23:31
AVSCPLR.DLL     : 10.0.3.2       84328 Bytes   1/10/2011 19:23:31
AVARKT.DLL      : 10.0.22.6     231784 Bytes   1/10/2011 19:23:27
AVEVTLOG.DLL    : 10.0.0.8      203112 Bytes   1/10/2011 19:23:28
SQLITE3.DLL     : 3.6.19.0      355688 Bytes   6/17/2010 19:27:22
AVSMTP.DLL      : 10.0.0.17      63848 Bytes   1/10/2011 19:23:31
NETNT.DLL       : 10.0.0.0       11624 Bytes   6/17/2010 19:27:21
RCIMAGE.DLL     : 10.0.0.26    2550120 Bytes   1/28/2010 18:10:20
RCTEXT.DLL      : 10.0.58.0      97128 Bytes   1/10/2011 19:23:52

Configuration settings for the scan:
Jobname.............................: Complete system scan
Configuration file..................: C:\Program Files\Avira\AntiVir Desktop\sysscan.avp
Logging.............................: low
Primary action......................: interactive
Secondary action....................: ignore
Scan master boot sector.............: on
Scan boot sector....................: on
Boot sectors........................: C:,
Process scan........................: on
Extended process scan...............: on
Scan registry.......................: on
Search for rootkits.................: on
Integrity checking of system files..: off
Scan all files......................: All files
Scan archives.......................: on
Recursion depth.....................: 20
Smart extensions....................: on
Macro heuristic.....................: on
File heuristic......................: medium

Start of the scan: Tuesday, February 22, 2011  09:03

Starting search for hidden objects.

The scan of running processes will be started
Scan process 'msdtc.exe' - '40' Module(s) have been scanned
Scan process 'dllhost.exe' - '59' Module(s) have been scanned
Scan process 'dllhost.exe' - '45' Module(s) have been scanned
Scan process 'vssvc.exe' - '48' Module(s) have been scanned
Scan process 'avscan.exe' - '70' Module(s) have been scanned
Scan process 'avcenter.exe' - '63' Module(s) have been scanned
Scan process 'alg.exe' - '33' Module(s) have been scanned
Scan process 'wdfmgr.exe' - '15' Module(s) have been scanned
Scan process 'TAPPSRV.exe' - '14' Module(s) have been scanned
Scan process 'swupdtmr.exe' - '10' Module(s) have been scanned
Scan process 'avshadow.exe' - '26' Module(s) have been scanned
Scan process 'RegSrvc.exe' - '25' Module(s) have been scanned
Scan process 'mctskshd.exe' - '25' Module(s) have been scanned
Scan process 'mcdetect.exe' - '28' Module(s) have been scanned
Scan process 'DVDRAMSV.exe' - '13' Module(s) have been scanned
Scan process 'aoltpspd.exe' - '22' Module(s) have been scanned
Scan process 'CFSvcs.exe' - '42' Module(s) have been scanned
Scan process 'aoltsmon.exe' - '20' Module(s) have been scanned
Scan process 'AOLAcsd.exe' - '34' Module(s) have been scanned
Scan process 'avguard.exe' - '53' Module(s) have been scanned
Scan process 'RAMASST.exe' - '20' Module(s) have been scanned
Scan process 'toscdspd.exe' - '18' Module(s) have been scanned
Scan process 'ctfmon.exe' - '26' Module(s) have been scanned
Scan process 'avgnt.exe' - '46' Module(s) have been scanned
Scan process 'winpatrol.exe' - '43' Module(s) have been scanned
Scan process 'DLACTRLW.EXE' - '30' Module(s) have been scanned
Scan process 'pinger.exe' - '24' Module(s) have been scanned
Scan process 'AGRSMMSG.exe' - '19' Module(s) have been scanned
Scan process 'igfxpers.exe' - '23' Module(s) have been scanned
Scan process 'hkcmd.exe' - '22' Module(s) have been scanned
Scan process 'igfxtray.exe' - '27' Module(s) have been scanned
Scan process 'Explorer.EXE' - '90' Module(s) have been scanned
Scan process 'svchost.exe' - '34' Module(s) have been scanned
Scan process 'sched.exe' - '45' Module(s) have been scanned
Scan process 'spoolsv.exe' - '66' Module(s) have been scanned
Scan process 'svchost.exe' - '38' Module(s) have been scanned
Scan process 'svchost.exe' - '32' Module(s) have been scanned
Scan process 'S24EvMon.exe' - '39' Module(s) have been scanned
Scan process 'EvtEng.exe' - '55' Module(s) have been scanned
Scan process 'svchost.exe' - '162' Module(s) have been scanned
Scan process 'svchost.exe' - '38' Module(s) have been scanned
Scan process 'svchost.exe' - '51' Module(s) have been scanned
Scan process 'lsass.exe' - '63' Module(s) have been scanned
Scan process 'services.exe' - '27' Module(s) have been scanned
Scan process 'winlogon.exe' - '85' Module(s) have been scanned
Scan process 'csrss.exe' - '12' Module(s) have been scanned
Scan process 'smss.exe' - '2' Module(s) have been scanned

Starting master boot sector scan:
Master boot sector HD0
    [INFO]      No virus was found!

Start scanning boot sectors:
Boot sector 'C:\'
    [INFO]      No virus was found!

Starting to scan executable files (registry).
The registry was scanned ( '1726' files ).


Starting the file scan:

Begin scan in 'C:\' <SQ004092P01>


End of the scan: Tuesday, February 22, 2011  09:42
Used time: 38:36 Minute(s)

The scan has been done completely.

   5304 Scanned directories
 280868 Files were scanned
      0 Viruses and/or unwanted programs were found
      0 Files were classified as suspicious
      0 files were deleted
      0 Viruses and unwanted programs were repaired
      0 Files were moved to quarantine
      0 Files were renamed
      0 Files cannot be scanned
 280868 Files not concerned
   7446 Archives were scanned
      0 Warnings
      0 Notes
 349703 Objects were scanned with rootkit scan
      0 Hidden objects were found


Online Hoov

  • Malware Removal Mentors
  • Global Moderator
  • Diamond Member
  • Posts: 22685
  • Unwilling part owner of Gov't. Motors and Chrysler
    • Hoov's Personal Site
Re: [In Progress] Coupla Virus problems (Hijack log attached)
« Reply #51 on: February 22, 2011, 10:13:56 AM »
OK, lets do some cleanup, and then I will leave this thread open for a while in case something comes back.


Now  there are a few thing's you need to do to fully clean your system and keep it secure.

Run OTC
Download OTC to your desktop and run it
Click Yes to beginning the Cleanup process and remove these components, including this application.
You will be asked to reboot the machine to finish the Cleanup process. Choose Yes.

Cleaning out Temporary Files etc. There are several different products that you can use for this. You can go thru the Internet Options in the windows Control Panel. There are several programs that also do the job better than windows does it, in my opinion. There is System Security Suite, EasyCleaner, Ccleaner. Also sometimes other program sometimes do it as well as what you originally got it for like ZoneAlarm Security Suite. Just make sure to keep them updated and use them regularly.

Disable and Enable System Restore.
I recommend you turn off System restore, and then turn it back on so that you will not be able to restore your problems to a clean computer.
For Vista use these instructions, Windows Vista Restore Guide
For XP use these instructions, Windows XP System Restore Guide
Reboot
Re-enable system restore with instructions from tutorial above
Create a System Restore Point
Go to all programs, then to accessories, then to system tools, then to system restore. Check the box for create restore point (not select a restore point), then click next and follow the instructions.

Make your Internet Explorer more secure - This can be done by following these simple instructions: (unless you are using ZoneAlarm Security Suite or something similar, then you would secure the browser thru the firewall). There are some good basic instructions for that here.

Use a different browser other than  IE (most exploits are pointed towards IE). One of them is
Firefox.
It is also worth trying Thunderbird for controlling spam in your e-mail.

Always use an UPDATED anti-virus program Make sure you update this at least weekly, if not more often. This is one thing that may save you more than anything else.

Run malware scanners. Three free ones are Spybot Search and Destroy, and AdAware and Malwarebytes' Anti-Malware

Always use a firewall.
Any firewall is better than none, and you should pick a firewall that you will use, as even the best firewall is worthless if you turn it off.
 
Learn how to use your firewall Only programs that need it should have access to the net. But these are specific to the firewall you use, so you will need to learn how. Several firewalls have support forums here. My page will help you with ZoneAlarm if that is what you choose. 


Never run two Antivirus programs or two Firewalls  at the same time. They can interfere with each other and cause problems. Some people swear that more protection is provided, but the reverse is true. They tend to argue amongst themselves and end up leaving holes. Now I have more than 1 AV installed on my computer, and I keep them up to date. I only run one at a time, but each program has weakness's, so I keep a backup in case my computer starts acting up.


 MOST IMPORTANT : Windows and IE, and whatever other software that you have that connects to the net, needs to be kept updated. The reason is, these programs connect to the net, and if there is an internal security problem, you have already told your firewall to allow the communication, and thus you will have allowed a hole. UPDATES are important. I suggest that you make sure that Windows Updates and the updates for your antivirus and antimalware programs are set for automatic updates. I also suggest running Secunia PSI. It will monitor the software you have installed and let you know when something needs to be updated.

Don't ever use P2P or filesharing software Even the safest P2P file sharing programs that do not contain bundled spyware, still expose you to risks because of the very nature of the P2P file sharing process. By default, most P2P file sharing programs are configured to automatically launch at startup. They are also configured to allow other P2P users on the same network open access to a shared directory on your computer. The reason for this is simple. File sharing relies on its members giving and gaining unfettered access to computers across the P2P network. However, this practice can make you vulnerable to data and identity theft. Even if you change those risky default settings to a safer configuration, the act of downloading files from an anonymous source greatly increases your exposure to infection. That is because the files you are downloading may actually contain a disguised threat. Many very malicious worms and trojans, such as the Storm Worm, target and spread across P2P files sharing networks because of their known vulnerabilities.

Before using any malware detection / removal software Check with Rogue/Suspect Spyware List and Rogue Applications List That way you will know if the program you are looking at is on the up and up. If you want to know how it stacks up against other programs check out SpywareWarrior

We have a good guide here at Spyware Hammer on how to prevent Malware in the Future. You might want to peruse this and follow the recommendations in there.
PLEASE READ IT AND FOLLOW THE RECOMMENDATIONS TO PROTECT YOURSELF.

Let us know if you have any more problems, either new or old.
Have a good time surfing the net, but stay safe.
If you have more questions, ask away, that is why I am here.

Consumer Security

If I am helping you and you don't hear from me for 24Hrs, send me a PM Please!

Offline bushka

  • Bronze Member
  • Posts: 134
Re: [In Progress] Coupla Virus problems (Hijack log attached)
« Reply #52 on: February 22, 2011, 04:37:58 PM »
OK, I took care of all that and will report back if I have anything come up.  Thanks again for your help.  If it is gone, I think it was that TDSSKiller that did the trick.

 :t

Offline bushka

  • Bronze Member
  • Posts: 134
Re: [In Progress] Coupla Virus problems (Hijack log attached)
« Reply #53 on: February 27, 2011, 03:18:06 PM »
Thanks in advance, Hoov.  I think you can call this one complete.  I've had no further problems.  If you ever come across why I wasn't able to boot up with a flash drive, I'd love to know how to do it in the future.

Thanks again!

Online Hoov

  • Malware Removal Mentors
  • Global Moderator
  • Diamond Member
  • Posts: 22685
  • Unwilling part owner of Gov't. Motors and Chrysler
    • Hoov's Personal Site
Re: [In Progress] Coupla Virus problems (Hijack log attached)
« Reply #54 on: February 27, 2011, 03:25:30 PM »
You are welcome!

Consumer Security

If I am helping you and you don't hear from me for 24Hrs, send me a PM Please!