Submit Your Article Forum Rules FAQ About Us
Search the forums:

Tech Support Team


Hello and Welcome to Tech Support Team! Before you can start posting and answering questions, you'll have to register. Registration is fast, simple and absolutely free! Feel free to browse through existing questions by choosing the forum you want to visit below.



Notices

Closed Thread
  #1 (permalink)   Top
Old 4th February 2008, 09:35 AM
DarkVisor's Avatar
Newcomer
 
Join Date: Feb 2008, 11 posts.
Reputation: DarkVisor is on a distinguished road
Strange virus infecting me! Pls help!

Hey everyone, I have been unlucky to be infected with a virus and so this is my first post!
I sook help on www.techspot.com but they were not informative and as a result not much has changed. My thread was here: http://www.techspot.com/vb/topic94985.html

I got infected about a month ago but I have been overseas and so could not do much about the virus. As you can see on the other thread, the computer generally booted extremely slowly and ads for spyware removal kept popping up. Nearly no background programs would load as well. I followed the preliminary removal instructions, but it showed a lot of the system files were infected- LSASS.exe etc.. but I still removed them. That was before I went overseas, and now when I came back it has gotten only marginally better. The blue screen at startup no longer shows. But for some reason when using internet browsers the computer now hangs every few seconds for about 3 seconds. This makes browsing and watching videos annoying to the point of smashing the box :frown: None of my background programs load, and popups keep on telling me that files in the registry are corrupt, or system files are broken.. But this hasnt had any effects that I know of. Here they are: http://img137.imageshack.us/img137/9719/popup1yg3.jpg
and http://img208.imageshack.us/img208/7443/popup2ps2.jpg

I have also included the old malware logs before I left and the one I have done now. thanks all!
Attached Thumbnails
strange-virus-infecting-me-pls-help-avg-report.jpg  
Attached Files
File Type: txt old ComboFix.txt (14.5 KB, 15 views)
File Type: txt old rapport.txt (1.6 KB, 13 views)
File Type: txt old VundoFix.txt (2.3 KB, 13 views)
File Type: log hijackthis.log (8.8 KB, 22 views)
  #2 (permalink)   Top
Old 4th February 2008, 02:43 PM
Howard's Avatar
TST Master
 
Join Date: Dec 2007, 3,366 posts.
Reputation: Howard has a spectacular aura aboutHoward has a spectacular aura about
Hello and welcome to

Click start/run and type services.msc into the run box and press the enter key.

When the window appears, maximise it. Double click on the following services(if there) and select stop if they are running. Set the startup type to disabled. Click apply/ok for each service you disable.

DomainService

Close the services window.

Step 1
  • Download RenV.exe by sUBs to your desktop.
  • Double click RenV.exe to run it.
  • It will search your system drive looking for any modified .exe files
  • When done it will produce a log for you.
  • Please add this log to your reply.
Step 2
  • Go to Start > Run > type Notepad.exe > click OK.
  • Copy the entire contents of the quote Box below to Notepad.
    • It must be Notepad.
  • Name the file as Log.txt (Overwrite any existing one)
  • Change the Save as Type to All Files
  • and Save it on the desktop
  • Refering to the picture below.
  • Drag Log.txt into RenV.exe
  • Add the resulting log to your reply.

Quote:
C:\WINDOWS\lsass .exe
C:\WINDOWS\lsass .exe
=========================================


Open notepad and copy/paste the text in the code box below into it:
NOTE* make sure to only highlight and copy what is inside the quote box nothing out side of it.
Also ..

Pay particular attention to this :-

Make sure the word File:: is on the first line of the text file you save (no blank line above it, & no space in front of it)
Code:
Quote:

File::
C:\WINDOWS\system32\sstqn.exe
C:\WINDOWS\system32\rjjrbpqw.dll
C:\WINDOWS\system32\utazimju.dll
C:\WINDOWS\system32\sstqn.dll
C:\WINDOWS\system32\efnytbeq.dll
C:\WINDOWS\system32\xtvedfhu.exe
C:\sqmnoopt19.sqm
C:\sqmdata19.sqm
C:\WINDOWS\system32\VundoFixSVC.exe
C:\WINDOWS\DiabUnin.exe
C:\sqmnoopt18.sqm
C:\sqmdata18.sqm
C:\sqmnoopt17.sqm
C:\sqmdata17.sqm
C:\sqmnoopt16.sqm
C:\sqmdata16.sqm
C:\sqmnoopt15.sqm
C:\sqmdata15.sqm
C:\WINDOWS\system32\SBFC.dat
C:\sqmnoopt14.sqm
C:\sqmdata14.sqm
C:\WINDOWS\QTFont.qfn
C:\WINDOWS\system32\SBRC.dat
C:\WINDOWS\system32\SBSP.dat

Folder::
C:\VundoFix Backups


Save this as CFScript.txt

Then drag the CFScript.txt into ComboFix.exe as you see in the screenshot below.



This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply together with a fresh HJT log.

===================================

Run HJT with no other programmes open(except notepad). Click the scan button. Have HJT fix the following, by placing a tick in the little box next to(if there).

F3 - REG:win.ini: load=C:\WINDOWS\system32\sstqn.exe

O2 - BHO: {553b35d3-0c51-f7d8-fc84-f7626376b435} - {534b6736-267f-48cf-8d7f-15c03d53b355} - C:\WINDOWS\system32\rjjrbpqw.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: (no name) - {A95B2816-1D7E-4561-A202-68C0DE02353A} - C:\WINDOWS\system32\utazimju.dll

O2 - BHO: (no name) - {B49F15EC-39C9-4180-9913-3557D807D344} - C:\WINDOWS\system32\sstqn.dll

O4 - HKLM\..\Run: [380babaf] rundll32.exe "C:\WINDOWS\system32\efnytbeq.dll",b

O4 - Global Startup: CO2 Saver.lnk = C:\Program Files\CO2 Saver\CO2Saver.exe

O20 - Winlogon Notify: utazimju - C:\WINDOWS\SYSTEM32\utazimju.dll

O23 - Service: DomainService - Unknown owner - C:\WINDOWS\system32\xtvedfhu.exe (file missing)

Click on the fix checked button.

Close HJT.

==============================================

Post the RenV log, the Combofix log and a fresh HJT log.

Regards Howard

This thread is for the use of DarkVisor only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our malware Removal forum.

Last edited by Howard; 4th February 2008 at 06:14 PM.
  #3 (permalink)   Top
Old 6th February 2008, 05:41 AM
DarkVisor's Avatar
Newcomer
 
Join Date: Feb 2008, 11 posts.
Reputation: DarkVisor is on a distinguished road
Hey thankyou very much for the reply Howard!!
I have attached the logs you requested, but because i didnt quite understand, 1Hijackthis.log is the one I did before the removal, and 2hijackthis.log is the one I did after what you instructed me to check. Just out of interest though, what was the point of deleting Co2saver.exe?
Attached Files
File Type: log 1hijackthis.log (8.4 KB, 22 views)
File Type: log 2hijackthis.log (8.1 KB, 20 views)
File Type: txt ComboFix.txt (921 Bytes, 12 views)
File Type: txt Log.txt (4.9 KB, 14 views)
  #4 (permalink)   Top
Old 6th February 2008, 06:19 AM
Howard's Avatar
TST Master
 
Join Date: Dec 2007, 3,366 posts.
Reputation: Howard has a spectacular aura aboutHoward has a spectacular aura about
CO2Saver.exe Doesn`t need to be run on startup and we didn`t actually delete it.

Run HJT with no other programmes open(except notepad). Click the scan button. Have HJT fix the following, by placing a tick in the little box next to(if there).

O2 - BHO: (no name) - {D309E9EC-2C8D-4C24-B517-31195199493D} - C:\WINDOWS\system32\sstqn.dll (file missing)

Click on the fix checked button.

Close HJT.

Apart from the above inactive entry, your HJT log is clean.

Unfortunately you`ve posted the CFScript, rather than a Combofix log. Please run Combofix again and post the log file.

Regards Howard

This thread is for the use of DarkVisor only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our malware Removal forum.
  #5 (permalink)   Top
Old 7th February 2008, 06:41 AM
DarkVisor's Avatar
Newcomer
 
Join Date: Feb 2008, 11 posts.
Reputation: DarkVisor is on a distinguished road
thanks again for your reply Howard!
Hmm I was sure it was the correct log, but I have just done another scan to make sure, here is the new log!
Hmm everything seems to be fixed except that extremely annoying lag when browsing the internet! Do you get what I mean? maybe I could post a video or something lol. Every about 15 seconds it would just freeze for about 2 seconds, everyhting except the mouse.. I might have been typing, and nothing would come up but after 2 seconds that whole sentence just pops up like it was on fast forward! Its happened about 15 times while I was typing this message.
I have checked the processes tab on taskmanager, but there seems to be nothing hogging the cpu, just system idle process and firefox, although the cpu fan seems to speed up and the slow down when the freeze happens. I checked the error report in services.msc but their time does not have much to do witht them!
Attached Files
File Type: log hijackthis.log (8.1 KB, 17 views)
  #6 (permalink)   Top
Old 7th February 2008, 08:19 AM
Albert Lionheart's Avatar
TST Oracle
 
Join Date: Dec 2007, 8,001 posts.
Location: Market Haemorrhoids, Middle England
Reputation: Albert Lionheart is on a distinguished road
Maybe there is a clue in the symptom you mention about the fan speed changing. This happens all the time to a small degree but it might indicate your PSU is not working properly.
You could download Everest from majorgeeks.com and run computer - sensor to see what the voltages are - if you report them we can check for you.
__________________
Confuse and Prosper.
  #7 (permalink)   Top
Old 7th February 2008, 12:15 PM
Howard's Avatar
TST Master
 
Join Date: Dec 2007, 3,366 posts.
Reputation: Howard has a spectacular aura aboutHoward has a spectacular aura about
I asked you to post a fresh Combofix log, not a HJT log.

Regards Howard

This thread is for the use of DarkVisor only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our malware Removal forum.
  #8 (permalink)   Top
Old 8th February 2008, 01:18 AM
DarkVisor's Avatar
Newcomer
 
Join Date: Feb 2008, 11 posts.
Reputation: DarkVisor is on a distinguished road
hehe I already have Everest! Ill post voltages when I get home

Sorry howard, dont know what I was thinking! Ill post the combofix also in about 3 hours!

About the psu thing, I also found this thread: http://www.techspot.com/vb/showthrea...457#post573457

But they are using a laptop and seem to think that its overheating.
  #9 (permalink)   Top
Old 8th February 2008, 01:31 AM
Howard's Avatar
TST Master
 
Join Date: Dec 2007, 3,366 posts.
Reputation: Howard has a spectacular aura aboutHoward has a spectacular aura about
Ok, no problem mate.

Regards Howard

This thread is for the use of DarkVisor only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our malware Removal forum.
  #10 (permalink)   Top
Old 8th February 2008, 06:56 AM
DarkVisor's Avatar
Newcomer
 
Join Date: Feb 2008, 11 posts.
Reputation: DarkVisor is on a distinguished road
Here i've included combofix.txt and the computer voltages from everest. Is the CPU supposed to have this voltage? lol
Attached Files
File Type: txt voltages.txt (140 Bytes, 16 views)
File Type: txt ComboFix.txt (921 Bytes, 16 views)
  #11 (permalink)   Top
Old 8th February 2008, 07:53 AM
Albert Lionheart's Avatar
TST Oracle
 
Join Date: Dec 2007, 8,001 posts.
Location: Market Haemorrhoids, Middle England
Reputation: Albert Lionheart is on a distinguished road
Voltages look OK to me.
I look forward to what Howard has to say about the other log.
cheers
__________________
Confuse and Prosper.
  #12 (permalink)   Top
Old 8th February 2008, 09:12 AM
DarkVisor's Avatar
Newcomer
 
Join Date: Feb 2008, 11 posts.
Reputation: DarkVisor is on a distinguished road
Hey Lionheart, lol thats good and bad to hear, good that my PSU isnt broken but bad that I still havent found the source of this stupid problem! Hmm I just tried running MSN messenger, and it does the exact same thing to that.. I dont know maybe its the .Net framework or something.. What do firefox IE and masn messenger all have in common?

Still looking forward to your reply about the log Howard!
  #13 (permalink)   Top
Old 8th February 2008, 09:24 AM
Albert Lionheart's Avatar
TST Oracle
 
Join Date: Dec 2007, 8,001 posts.
Location: Market Haemorrhoids, Middle England
Reputation: Albert Lionheart is on a distinguished road
If this only happens when accessing the net from any of the browsers or msn then perhaps it is a firewall issue.
If you have a firewall in the modem router, turn off any other
firewall(s) in windows.
If this doesn't make a difference, try turning off the antivirus software temporarily to see if this improves?
I have not heard of a problem running firefox and IE side by side but you could try uninstalling Firefox.
__________________
Confuse and Prosper.
  #14 (permalink)   Top
Old 8th February 2008, 12:34 PM
Howard's Avatar
TST Master
 
Join Date: Dec 2007, 3,366 posts.
Reputation: Howard has a spectacular aura aboutHoward has a spectacular aura about
For whatever reason, that still isn`t a full combofix log. Let`s do this instead.

Download Deckard's System Scanner and save it to your desktop. Note: You must be logged onto an account with administrator privileges. Save all your work and close all opened programs. Double click on dss.exe to run it. Follow the prompts. When the scan is complete, two log files will be produced. The first one, main.txt, will be maximized, the second one, extra.txt, will be minimized. Please post the contents of the 2 log files in your next reply.

Regards Howard

This thread is for the use of DarkVisor only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our malware Removal forum.
  #15 (permalink)   Top
Old 8th February 2008, 11:09 PM
DarkVisor's Avatar
Newcomer
 
Join Date: Feb 2008, 11 posts.
Reputation: DarkVisor is on a distinguished road
Hmm I dont know why they weren't the full logs, but at the end of the combofix scan after the computer restarts, the little box that loads onto the desktop freezes for some reason, so I have to close it manually. Maybe it was supposed to save the logs after this? It stays like that for an abnormal amount of time (I had it there for half an hour before I closed it)
But I have included the system scanner logs!
Hmm I dont know if its a firewall issue, the virus disabled all of my startup programs except for sound manager, so I don't have the firewall or antivirus up!

Also, the virus seems to have disabled autoplay support, any idea on how to turn this back on?
  #16 (permalink)   Top
Old 9th February 2008, 09:27 AM
Howard's Avatar
TST Master
 
Join Date: Dec 2007, 3,366 posts.
Reputation: Howard has a spectacular aura aboutHoward has a spectacular aura about
Please post the DSS logs.

Until such time as we can get rid of whatever infections you have, we`re going to struggle to fix this.

Regards Howard

This thread is for the use of DarkVisor only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our malware Removal forum.
  #17 (permalink)   Top
Old 9th February 2008, 10:12 PM
DarkVisor's Avatar
Newcomer
 
Join Date: Feb 2008, 11 posts.
Reputation: DarkVisor is on a distinguished road
here they are
Attached Files
File Type: txt main.txt (15.3 KB, 16 views)
File Type: txt extra.txt (18.5 KB, 32 views)
  #18 (permalink)   Top
Old 10th February 2008, 06:52 AM
Howard's Avatar
TST Master
 
Join Date: Dec 2007, 3,366 posts.
Reputation: Howard has a spectacular aura aboutHoward has a spectacular aura about
Your system still has the RenV infection.


Step 1
  • Download RenV.exe by sUBs to your desktop.
  • Double click RenV.exe to run it.
  • It will search your system drive looking for any modified .exe files
  • When done it will produce a log for you.
  • Please add this log to your reply.
Step 2
  • Go to Start > Run > type Notepad.exe > click OK.
  • Copy the entire contents of the quote Box below to Notepad.
    • It must be Notepad.
  • Name the file as Log.txt (Overwrite any existing one)
  • Change the Save as Type to All Files
  • and Save it on the desktop
  • Refering to the picture below.
  • Drag Log.txt into RenV.exe
  • Add the resulting log to your reply.

Quote:
C:\WINDOWS\system32\spoolvs .exe
C:\WINDOWS\system32\printer .exe
C:\WINDOWS\system32\spoolvs .exe
C:\WINDOWS\system32\printer .exe
C:\Program Files\BitTorrent\bittorrent .exe
C:\Program Files\MSN Messenger\MsnMsgr .exe
Once done, run a fresh DSS scan and post the DSS Main.txt as well as the RenV log.

Regards Howard

This thread is for the use of DarkVisor only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our malware Removal forum.
  #19 (permalink)   Top
Old 11th February 2008, 06:18 AM
DarkVisor's Avatar
Newcomer
 
Join Date: Feb 2008, 11 posts.
Reputation: DarkVisor is on a distinguished road
Hey everyone! Here are the logs you requested Howard, the log2 is the one after I did removal of those files, the other one is before.

By the way, do you know what
C:\Program Files\Bonjour\mDNSResponder.exe
is? It keeps trying to access the internet, and \i don't know if it is a Microsoft file!
Attached Files
File Type: txt Log2.txt (4.6 KB, 11 views)
File Type: txt Log.txt (4.7 KB, 12 views)
File Type: txt main.txt (13.0 KB, 15 views)
  #20 (permalink)   Top
Old 11th February 2008, 10:55 AM
Daveskater's Avatar
Community Moderator
 
Join Date: Dec 2007, 4,345 posts.
Location: Oxford, UK
Reputation: Daveskater will become famous soon enoughDaveskater will become famous soon enough
That file is a part of iTunes, so it's ok.

Howard will advise you on the next steps to take when he comes back online
__________________
Numberwang!

A little air on the earth.
Closed Thread

Only registered members can participate in forum threads. You must register or log in to contribute.


Thread Tools

Forum Jump


All times are GMT. The time now is 11:43 PM.






Post A Question!
Useful Links
Main Menu
Home
Forum Rules
FAQ
About Us
Welcome Pack
Search the forums
TST Mobile
Contact Us
Send Message

These are the 8 most used thread tags
Tag Cloud
geforce modem monitor no ring response no signal nvidia soft modem win7