Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

I Think Ive Got A Deep Virus.


  • Please log in to reply
1 reply to this topic

#1 ibLah

ibLah

  • Members
  • 23 posts
  • OFFLINE
  •  
  • Location:United States of America
  • Local time:08:23 AM

Posted 16 February 2008 - 12:06 AM

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:05:55 PM, on 2/15/2008
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm

--
End of file - 1146 bytes




My first question;
Is it possible for a virus to survive a complete reformat?
I used the WidnowsXP install disk, deleted all partitions and installed windows on the unpartitioned space.
I'm correct that that does delete the entire HDD and does a completely fresh install of windows right?
Then why is the machine still acting up?


Here's the issues;
Lots of websites will not load and when i attemp to ping then in the command it times out.
Websites like www.yahoo.com, www.microsoft.com (I cant get to windowsupdate), msn.com, and many others.
Now the thing is, I was not going to post this because i did not think it was possible for a virus to still be on here untill a message poped up on me earlier.
While I was pinging www.microsoft.com a dialog poped up but i completely forgot what it said. All i know is that it was not supposed to be here and it said that my computer will be at wisk if i dont go to this website and download some crap.

All i did after refoprmatting was put in the Dell Resource CD and installed the network driver and my graphics card driver. Then attempted to go to windows update. Just like I do on all my computer and i never have these problems.


Maybe im not completely erasing the HDD?
I heard somewhere that if you take a magnet to your HDD it will take everything off it. Is that ok to do?



Please excuse my spelling mistakes, im extremly tired and im headed to bed now. Ill check this post in the morning. Thanks
EDIT:
That message i was talking about earlier it just poped up again now. Here is a screenshot: Remember, i have not downloaded anything after reformatting my computer, I only installed drivers off a DELL disk.
http://img211.imageshack.us/my.php?image=badtu6.jpg

Edited by ibLah, 16 February 2008 - 12:13 AM.

Posted Image
Signature #19 [+]


BC AdBot (Login to Remove)

 


#2 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:02:23 PM

Posted 26 February 2008 - 10:31 AM

Welcome to the BleepingComputer HijackThis Logs and Analysis forum.
My name is Richie and i'll be helping you to fix your problems.

Apologies for the late response,as i'm sure you can appreciate we are extremely busy.

If you've already recieved help at another forum and your issues have been resolved,or you're presently recieving help elsewhere then please let us know.

If you have not followed the info in the link below prior to posting your log then please do so now:
Preparation Guide for use before posting a HijackThis Log:
http://www.bleepingcomputer.com/forums/t/34773/preparation-guide-for-use-before-using-malware-removal-tools-and-requesting-help/

If you still require help,please post a new Hijackthis log into this topic in your next reply.

Also post a detailed description of the issues you're experiencing.

*Note*
Post all reports/logs directly into this topic,not as attachments or inside code boxes,thanks.
Posted Image
Posted Image




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users