Adblock breaks this site

Spyware - XP Anti-Virus 2011

Discussion in 'Help & Requests' started by Celestial Bow, Mar 20, 2011.

  1. Celestial Bow

    Celestial Bow Apprentice

    Joined:
    Jan 25, 2007
    Posts:
    716
    Referrals:
    1
    Sythe Gold:
    0
    Spyware - XP Anti-Virus 2011

    This program is raping my main computer. I tried downloading Malwarebytes in safemode but it will not let me run the .exe. I managed to get HighjackThis installed and I have the log for that, if it is of any use.

    Any advice as to what I can do, or which log entries I should "fix"?

    Logfile of Trend Micro HijackThis v2.0.4
    Scan saved at 1:44:18 PM, on 3/20/2011
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
    Boot mode: Safe mode

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\Documents and Settings\Owner\Local Settings\Application Data\sts.exe
    G:\Malwarebytes' Anti-Malware\lala.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gateway.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.gatewaybiz.com
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gatewaybiz.com
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://www.gatewaybiz.com
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
    O2 - BHO: uTorrentBar Toolbar - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files\uTorrentBar\tbuTor.dll
    O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O3 - Toolbar: uTorrentBar Toolbar - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files\uTorrentBar\tbuTor.dll
    O3 - Toolbar: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll
    O3 - Toolbar: FrostWire Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
    O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
    O4 - HKLM\..\Run: [SunKistEM] C:\Program Files\Digital Media Reader\shwiconem.exe
    O4 - HKLM\..\Run: [CHotkey] zHotkey.exe
    O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe
    O4 - HKLM\..\Run: [IntelAudioStudio] "C:\Program Files\Intel Audio Studio\IntelAudioStudio.exe" BOOT
    O4 - HKLM\..\Run: [Reminder] %WINDIR%\Creator\Remind_XP.exe
    O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
    O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
    O4 - HKLM\..\Run: [HPHUPD05] C:\Program Files\Hewlett-Packard\\{5372B9A6-6E51-4f90-9B40-E0A3B8475C4E}\hphupd05.exe
    O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
    O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
    O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\system32\hphmon05.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [Jdiqohovojamaze] rundll32.exe "C:\WINDOWS\ezoqajacuqe.dll",Startup
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
    O4 - HKLM\..\Run: [Corel Photo Downloader] C:\Program Files\CVS\CVS Photo Editor Plus\Corel Photo Downloader.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Install Pending Files.LNK = C:\Program Files\SIFXINST\SIFXINST.EXE
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
    O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
    O9 - Extra 'Tools' menuitem: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
    O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
    O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
    O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe
    O23 - Service: WUSB54Gv42SVC - GEMTEKS - C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe

    --
    End of file - 7101 bytes
     
  2. Divine blob

    Divine blob Guru

    Joined:
    Mar 14, 2007
    Posts:
    1,289
    Referrals:
    2
    Sythe Gold:
    0
    Spyware - XP Anti-Virus 2011

    Bleh, a simple thing to do is this:

    Restart and boot into safe mode again

    Download Blink Endpoint Security (30 day trial then no updates forever) or MalwareBytes.

    Scan

    ???

    Profit as you see the list of the viruses clump up.

    if not I'll come up with something more advanced

    also try msconfig and looking through your start menu and stop the evil processes
     
  3. Celestial Bow

    Celestial Bow Apprentice

    Joined:
    Jan 25, 2007
    Posts:
    716
    Referrals:
    1
    Sythe Gold:
    0
    Spyware - XP Anti-Virus 2011

    I can't open malwarebytes, it doesn't let me start the .exe.
     
  4. Marine Clark

    Marine Clark Grand Master
    Banned

    Joined:
    May 25, 2010
    Posts:
    2,430
    Referrals:
    0
    Sythe Gold:
    0
    Spyware - XP Anti-Virus 2011

    If you have nothing critical on the computer completely re-format the computer, and the viruses will be gone.
     
  5. Divine blob

    Divine blob Guru

    Joined:
    Mar 14, 2007
    Posts:
    1,289
    Referrals:
    2
    Sythe Gold:
    0
    Spyware - XP Anti-Virus 2011

    Please try the following routine to see if you can get Malwarebytes to run.

    Click on Start, click Run, and then type devmgmt.msc and click OK
    On the View menu click on Show hidden devices
    Browse to Non-Plug and Play Drivers and you should see something like TDSSserv.sys
    Highlight that driver and right click on it and select DISABLE
    Now RESTART your computer.
    Download a copy of Malwarebytes but DO NOT run it yet.
    Rename the downloaded installer file to any generic name such as your own name but keep the .EXE extension on the file and run it.
    Once the program is installed go to the UPDATE tab and try to update the program if you can.
    Then go to the SCANNER tab and run a Quick Scan and allow MBAM to fix anything found.
     
  6. Divine blob

    Divine blob Guru

    Joined:
    Mar 14, 2007
    Posts:
    1,289
    Referrals:
    2
    Sythe Gold:
    0
    Spyware - XP Anti-Virus 2011

    please just leave now
     
  7. Celestial Bow

    Celestial Bow Apprentice

    Joined:
    Jan 25, 2007
    Posts:
    716
    Referrals:
    1
    Sythe Gold:
    0
    Spyware - XP Anti-Virus 2011

    Thank you for the help - I don't see anything like TDSSserv.sys under Non-plug, and I did click show hidden.

    Just to let you know I put my HijackThis log into a program that analyzes it for you and I removed the ones it said were clear threats. I also ran a defogger to disable my CD emulation drives.
     
  8. Divine blob

    Divine blob Guru

    Joined:
    Mar 14, 2007
    Posts:
    1,289
    Referrals:
    2
    Sythe Gold:
    0
    Spyware - XP Anti-Virus 2011

    oh and this

    Jdiqohovojamaze

    dunno about it, but sadly I'm not sure what OTS commands are so I can't tell you if its bad or not.
     
  9. Divine blob

    Divine blob Guru

    Joined:
    Mar 14, 2007
    Posts:
    1,289
    Referrals:
    2
    Sythe Gold:
    0
    Spyware - XP Anti-Virus 2011

    Alright, try running Malwarebytes and install Blink Endpoint if possible. Its an amazing anti-virus.
     
  10. Skillers FTW

    Skillers FTW Guest

    Referrals:
    0
    Spyware - XP Anti-Virus 2011

    Nothing wrong with what he suggested.

    I occassionally wipe and start again because my computer is old and dying. (But then again, I run Linux so it's 1000x easier)
     
  11. Celestial Bow

    Celestial Bow Apprentice

    Joined:
    Jan 25, 2007
    Posts:
    716
    Referrals:
    1
    Sythe Gold:
    0
    Spyware - XP Anti-Virus 2011

    Still cant download Malwarebytes, and I think that it would be the biggest help to me. I did download avast, which is scanning now, and ccleaner, which I used to wipe a lot of stuff and clean out my registry.

    Just need to figure out how to get malwarebytes on.
     
  12. Celestial Bow

    Celestial Bow Apprentice

    Joined:
    Jan 25, 2007
    Posts:
    716
    Referrals:
    1
    Sythe Gold:
    0
    Spyware - XP Anti-Virus 2011

    I could wipe, but I'd prefer to use that as a last ditch move.
     
  13. Divine blob

    Divine blob Guru

    Joined:
    Mar 14, 2007
    Posts:
    1,289
    Referrals:
    2
    Sythe Gold:
    0
    Spyware - XP Anti-Virus 2011

    Yeah, but its Windows and its hell re-formating. And reformating to XP Anti-virus is not worth it.
     
  14. Divine blob

    Divine blob Guru

    Joined:
    Mar 14, 2007
    Posts:
    1,289
    Referrals:
    2
    Sythe Gold:
    0
    Spyware - XP Anti-Virus 2011

    Try the MSCONFIG thing I suggested earlier. And if you can manage to run HJT again in regular, I may have found the virus.
     
  15. Divine blob

    Divine blob Guru

    Joined:
    Mar 14, 2007
    Posts:
    1,289
    Referrals:
    2
    Sythe Gold:
    0
    Spyware - XP Anti-Virus 2011

  16. Celestial Bow

    Celestial Bow Apprentice

    Joined:
    Jan 25, 2007
    Posts:
    716
    Referrals:
    1
    Sythe Gold:
    0
    Spyware - XP Anti-Virus 2011

    I tried the MSCONFIC thing again after rebooting, still no file that looks like that. I can run Hijackthis. I deleted the file "O4 - HKLM\..\Run: [Jdiqohovojamaze] rundll32.exe "C:\WINDOWS\ezoqajacuqe.dll",Startup
    " because I was told it had something to do with it on the malwarebytes site. Should I have restarted after I deleted? Still, nothing seems to have changed.
     
  17. Divine blob

    Divine blob Guru

    Joined:
    Mar 14, 2007
    Posts:
    1,289
    Referrals:
    2
    Sythe Gold:
    0
    Spyware - XP Anti-Virus 2011

    Yeah, and its fine now. I already posted he had a reply, but what I wanted you to do was go to run then type in msconfig and I would have gotten you to cancel the jdiqohovo junk from starting up
     
  18. Celestial Bow

    Celestial Bow Apprentice

    Joined:
    Jan 25, 2007
    Posts:
    716
    Referrals:
    1
    Sythe Gold:
    0
    Spyware - XP Anti-Virus 2011

    I restarted. I think it may be gone?!
     
  19. Divine blob

    Divine blob Guru

    Joined:
    Mar 14, 2007
    Posts:
    1,289
    Referrals:
    2
    Sythe Gold:
    0
    Spyware - XP Anti-Virus 2011

  20. Celestial Bow

    Celestial Bow Apprentice

    Joined:
    Jan 25, 2007
    Posts:
    716
    Referrals:
    1
    Sythe Gold:
    0
    Spyware - XP Anti-Virus 2011

    I am running malewarebytes now. Downloaded and is scanning and all. Took me like 3 hours to remove this damn virus, I hope I didn't fuck too much of my computer up in the process, I did so many different things...Thanks a lot for your help, and I'll check out that antivirus too.
     
< I need some help! | Laptop keeps overheating :\ [NEED HELP] >


 
 
Adblock breaks this site