Welcome Guest ( Log In | Click here to Register a free account now! )
Welcome to Bleeping Computer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.When posting your problem, do not run and post a ComboFix logs. ComboFix is a tool that should only be run under the supervision of someone who has been trained in its use. Using it on your own can cause problems with your computer. Any posts containing CF Logs will be ignored.
To receive help, you should instead provide a detailed description of your problem, detailed word-for-word error messages that you are receiving, screenshots of strange behaviour, and your operating system. This information is much more useful to our helpers than a ComboFix log.
![]() ![]() |
Jul 5 2009, 01:59 PM
Post
#1
|
|
|
New Member ![]() Group: Members Posts: 8 Joined: 5-July 09 From: bodrum Member No.: 348,550 |
-------------------- the computer defines all life . then holds it up and leaves us dangling..
|
|
|
|
Jul 5 2009, 03:23 PM
Post
#2
|
|
![]() To INSANITY and BEYOND !! ![]() ![]() ![]() ![]() ![]() ![]() Group: Moderator Posts: 21,869 Joined: 10-September 04 From: NJ USA Member No.: 2,608 |
Welcome to BC... Let's get an MBAM log.
Next run MBAM (MalwareBytes): NOTE: Before saving MBAM please rename it to zztoy.exe....now save it to your desktop. Please download Malwarebytes Anti-Malware and save it to your desktop. alternate download link 1 alternate download link 2 MBAM may "make changes to your registry" as part of its disinfection routine. If using other security programs that detect registry changes (ie Spybot's Teatimer), they may interfere or alert you. Temporarily disable such programs or permit them to allow the changes.
-------------------- Can you spare some PC cycles to help FIND A CURE .. BC FOLDING TEAM Click me /info..
ThoughtVent a goodplace to discuss.<<>>>Staying Updated Calendar of Updates. For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear.... Become a BleepingComputer fan: Facebook |
|
|
|
Jul 6 2009, 04:57 AM
Post
#3
|
|
|
New Member ![]() Group: Members Posts: 8 Joined: 5-July 09 From: bodrum Member No.: 348,550 |
hi thanks for getting back to me . well eventually i managed to do as you said as explorer wouldnt let me download what i needed . but eventually got there . well the log you asked for is now done , intresting but frightning reading .. hope you will be able to advise me further as to the best course of action .....
Malwarebytes' Anti-Malware 1.36 Database version: 1945 Windows 5.1.2600 Service Pack 3 7/6/2009 12:31:54 PM mbam-log-2009-07-06 (12-31-54).txt Scan type: Quick Scan Objects scanned: 78640 Time elapsed: 1 minute(s), 55 second(s) Memory Processes Infected: 3 Memory Modules Infected: 0 Registry Keys Infected: 11 Registry Values Infected: 8 Registry Data Items Infected: 3 Folders Infected: 1 Files Infected: 24 Memory Processes Infected: C:\WINDOWS\services.exe (Trojan.Agent) -> Unloaded process successfully. C:\WINDOWS\system32\reader_s.exe (Trojan.Agent) -> Unloaded process successfully. C:\Documents and Settings\STEVE\reader_s.exe (Trojan.Agent) -> Unloaded process successfully. Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CLASSES_ROOT\CLSID\{d9c9a8c9-460d-4343-888e-ae02bcc3ce57} (Adware.SpeedApps) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{d9c9a8c9-460d-4343-888e-ae02bcc3ce57} (Adware.SpeedApps) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{35cfe9b1-81c2-4d01-a350-a759292ad7fc} (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Protect (Rootkit.Agent) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\dslcnnct (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\IProxyProvider (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\AGprotect (Malware.Trace) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Speedapps (Adware.Speedapps) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Speedapps (Adware.Speedapps) -> Quarantined and deleted successfully. Registry Values Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\reader_s (Trojan.FakeAlert.H) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\services (Trojan.FakeAlert.H) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\reader_s (Trojan.FakeAlert.H) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{d9c9a8c9-460d-4343-888e-ae02bcc3ce57} (Adware.SpeedApps) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{d9c9a8c9-460d-4343-888e-ae02bcc3ce57} (Adware.SpeedApps) -> Quarantined and deleted successfully. HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\reader_s (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\taskman (Backdoor.Bot) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\services\del (Malware.Trace) -> Quarantined and deleted successfully. Registry Data Items Infected: HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\Internet Explorer\Control Panel\Homepage (Hijack.Homepage) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL\CheckedValue (Hijack.System.Hidden) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. Folders Infected: C:\Program Files\speedapps (Adware.SpeedApps) -> Quarantined and deleted successfully. Files Infected: C:\Documents and Settings\STEVE\reader_s.exe (Trojan.FakeAlert.H) -> Quarantined and deleted successfully. C:\WINDOWS\services.exe (Trojan.FakeAlert.H) -> Delete on reboot. C:\WINDOWS\system32\reader_s.exe (Trojan.FakeAlert.H) -> Quarantined and deleted successfully. C:\Program Files\speedapps\tbspee.dll (Adware.SpeedApps) -> Quarantined and deleted successfully. C:\WINDOWS\system32\drivers\protect.sys (Rootkit.Agent) -> Quarantined and deleted successfully. C:\Program Files\speedapps\tbspee.zip (Adware.SpeedApps) -> Quarantined and deleted successfully. C:\WINDOWS\system32\mcrh.tmp (Malware.Trace) -> Quarantined and deleted successfully. C:\WINDOWS\cookies.ini (Malware.Trace) -> Quarantined and deleted successfully. C:\WINDOWS\system32\comsa32.sys (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\system32\2.tmp (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\system32\3.tmp (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\system32\4.tmp (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\system32\5.tmp (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\system32\6.tmp (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\system32\7.tmp (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\system32\8.tmp (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\system32\9.tmp (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\system32\C.tmp (Trojan.Agent) -> Quarantined and deleted successfully. C:\Documents and Settings\Administrator\reader_s.exe (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\system32\FInstall.sys (Backdoor.Bot) -> Quarantined and deleted successfully. C:\WINDOWS\pskt.ini (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\BM734e5e41.xml (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\BM734e5e41.txt (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\msxml71.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully. im now not touching anything until i here back from you ... best wishes for the day , and thankyou sooo much again ..... -------------------- the computer defines all life . then holds it up and leaves us dangling..
|
|
|
|
Jul 6 2009, 08:15 AM
Post
#4
|
|
![]() Visiting Alien ![]() ![]() ![]() ![]() ![]() ![]() Group: BC Advisor Posts: 9,346 Joined: 20-May 07 From: millenium falcon and rockytop Member No.: 131,963 |
Sorry to butt in but you are fighting a lost cause with this infection, you have virut.
The sooner you turn off that computer the better, use another to read up on the infection. Your system is infected with a nasty variant of Virut, a polymorphic file infector with IRCBot functionality which infects .exe, .scr files, downloads more malicious files to your system, and opens a back door that compromises your computer. According to this Norman White Paper Assessment of W32/Virut, some variants can infect the HOSTS file and block access to security related web sites. URL=http://blog.trendmicro.com/virux-cases-escalate/]Virux[/URL] is an even more complex file infector which can embed an iframe into the body of web-related files and infect script files (.php, .asp, and .html). When Virut creates infected files, it also creates non-functional files that are corrupted beyond repair. In many cases the infected files cannot be disinfected properly by your anti-virus. When disinfection is attempted, the files become corrupted and the system may become irreparable. QUOTE The virus has a number of bugs in its code, and as a result it may misinfect a proportion of executable files....some W32/Virut.h infections are corrupted beyond repair. McAfee Risk Assessment and Overview of W32/VirutQUOTE There are bugs in the viral code. When the virus produces infected files, it also creates non-functional files that also contain the virus...Due to the damaged caused to files by virut it's possible to find repaired but corrupted files. They became corrupted by the incorrect writing of the viral code during the process of infection. undetected, corrupted files (possibly still containing part of the viral code) can also be found. this is caused by incorrectly written and non-function viral code present in these files. AVG Overview of W32/VirutThis kind of infection is contracted and spread by visiting remote, crack and keygen sites. These type of sites are infested with a smörgåsbord of malware and an increasing source of system infection. However, the CA Security Advisor Research Blog says they have found MySpace user pages carrying the malicious Virut URL. Either way you can end up with a computer system so badly damaged that recovery is not possible and it cannot be repaired. When that happens there is nothing you can do besides reformatting and reinstalling the OS.QUOTE ...warez and crack web pages are being used by cybercriminals as download sites for malware related to VIRUT and VIRUX. Searches for serial numbers, cracks, and even antivirus products like Trend Micro yield malcodes that come in the form of executables or self-extracting files...quick links in these sites also lead to malicious files. Ads and banners are also infection vectors... Keygen and Crack Sites Distribute VIRUX and FakeAVIf your computer was used for online banking, has credit card information or other sensitive data on it, you should disconnect from the Internet until your system is cleaned. All passwords should be changed immediately to include those used for banking, email, eBay, paypal and online forums. You should consider them to be compromised. You should change each password using a clean computer and not the infected one. If not, an attacker may get the new passwords and transaction information. If using a router, you need to reset it with a strong logon/password so the malware cannot gain control before connect again. Banking and credit card institutions should be notified of the possible security breach. Because your computer was compromised please read:
-------------------- Chewy
|
|
|
|
Jul 6 2009, 09:52 AM
Post
#5
|
|
|
New Member ![]() Group: Members Posts: 8 Joined: 5-July 09 From: bodrum Member No.: 348,550 |
i cant turn of my computer as it is contolling my cctv .. thanks for the honest but gloomy answer though . so where from here if anywhere , can it be repaired or do i just have to grin and bear it till it dies ????????
-------------------- the computer defines all life . then holds it up and leaves us dangling..
|
|
|
|
Jul 6 2009, 10:36 AM
Post
#6
|
|
![]() Visiting Alien ![]() ![]() ![]() ![]() ![]() ![]() Group: BC Advisor Posts: 9,346 Joined: 20-May 07 From: millenium falcon and rockytop Member No.: 131,963 |
It would be a lot less trouble to wipe the computer and reinstall, if you don't read about the infection you may end up doing the reinstall several times.
Hopefully you have saved videos on a seperate partition -------------------- Chewy
|
|
|
|
Jul 6 2009, 10:41 AM
Post
#7
|
|
|
New Member ![]() Group: Members Posts: 8 Joined: 5-July 09 From: bodrum Member No.: 348,550 |
most of music and dvds and security vidios are all on the d drive . . the one thing i dont yet know is if i burn these to disk if i will take the virus with them ... the other question is about my security software .. its not avaliable very easy and can i save that from my system also ... loads of questions . sorry to be such an idiot when it comes to computers ....
-------------------- the computer defines all life . then holds it up and leaves us dangling..
|
|
|
|
Jul 6 2009, 10:47 AM
Post
#8
|
|
![]() Visiting Alien ![]() ![]() ![]() ![]() ![]() ![]() Group: BC Advisor Posts: 9,346 Joined: 20-May 07 From: millenium falcon and rockytop Member No.: 131,963 |
Music and video are not infected by virut but should be scanned by a good antivirus for other infections.
Software will be infected and cannot be saved. -------------------- Chewy
|
|
|
|
Jul 6 2009, 10:59 AM
Post
#9
|
|
|
New Member ![]() Group: Members Posts: 8 Joined: 5-July 09 From: bodrum Member No.: 348,550 |
well im taking your advice and reading up on it . ive now learnt which parts are virus and which are false ids .. gonna give norman malware cleaner ago . and run it the same time as malware bytes . see what we come up with now . thankyou sooo much for the help and advice you have given ....
-------------------- the computer defines all life . then holds it up and leaves us dangling..
|
|
|
|
Jul 6 2009, 11:02 AM
Post
#10
|
|
![]() Visiting Alien ![]() ![]() ![]() ![]() ![]() ![]() Group: BC Advisor Posts: 9,346 Joined: 20-May 07 From: millenium falcon and rockytop Member No.: 131,963 |
If you insist on trying to fix this infection instead of following our advice to reformat and reinstall your operating system, there are various rescue disks available from major anti-virus vendors which you can try. Keep in mind, even the vendors like Kaspersky say there is no quarantee that some files will not get corrupted during the disinfection process. In the end most folks end up reformatting out of frustration after spending hours attempting to repair and remove infected files. IMO the safest and easiest thing to do is just reformat and reinstall Windows.
Bleeping Computer DOES NOT assume any responsibility for your attempt to repair this infection using any of the following tools. You do this at your own risk and against our advice. These are links to Anti-virus vendors that offer free LiveCD or Rescue CD files that are used to boot from for repair of unbootable and damaged systems, rescue data, scan the system for virus infections. Burn it as an image to a disk to get a bootable CD. All (except Avira) are in the ISO Image file format. Avira uses an EXE that has built-in CD burning capability.
-------------------- Chewy
|
|
|
|
Jul 6 2009, 11:13 AM
Post
#11
|
|
|
New Member ![]() Group: Members Posts: 8 Joined: 5-July 09 From: bodrum Member No.: 348,550 |
its not so much an insistance but more of a nicesety for me at the mo as i said before i have a shop which the computer runs the cctv for and while that is still working its a must for me .. to be without cctv for a week here is just not an option (its a jewellery shop) . so im not trying to remove the problems but just limit them .. and try and get through the rest of the summer season . a rebuild then can happen in the winter months . the other problem is that im english and living in turkey and had this system custom built .. but i reallly do thankyou for your excellent help and advice .. if you have any further sugestions im always gratefull ..
-------------------- the computer defines all life . then holds it up and leaves us dangling..
|
|
|
|
Jul 11 2009, 09:58 AM
Post
#12
|
|
|
New Member ![]() Group: Members Posts: 8 Joined: 5-July 09 From: bodrum Member No.: 348,550 |
after thinking about it . you are right . im going for the rebuild approach ,please if you dont mind i have a couple of more questions . i thought of trying out the xp black version , are there any programs i can download to sort out the problem of missing drivers i will undoubtably have . i do have some of the origional disks for asus and hp but as im only very very average at this wondering if you have any further helpfull hints please .. and ty for your time once again . its appreciated.....
-------------------- the computer defines all life . then holds it up and leaves us dangling..
|
|
|
|
Jul 11 2009, 06:41 PM
Post
#13
|
|
![]() To INSANITY and BEYOND !! ![]() ![]() ![]() ![]() ![]() ![]() Group: Moderator Posts: 21,869 Joined: 10-September 04 From: NJ USA Member No.: 2,608 |
Hi donkeyboy, You should now ask those questions from a new topic in the XP forum, so the OS people can answer you better than I.
-------------------- Can you spare some PC cycles to help FIND A CURE .. BC FOLDING TEAM Click me /info..
ThoughtVent a goodplace to discuss.<<>>>Staying Updated Calendar of Updates. For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear.... Become a BleepingComputer fan: Facebook |
|
|
|
Jul 12 2009, 04:23 AM
Post
#14
|
|
|
New Member ![]() Group: Members Posts: 8 Joined: 5-July 09 From: bodrum Member No.: 348,550 |
ok thnaks for the tip . have a nice day .....
-------------------- the computer defines all life . then holds it up and leaves us dangling..
|
|
|
|
![]() ![]() |
| Lo-Fi Version | Time is now: 22nd November 2009 - 12:46 AM |