Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Virus/Trojan Expert advice needed...


  • Please log in to reply
3 replies to this topic

#1 llp

llp

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:12:22 AM

Posted 04 April 2005 - 01:24 PM

I don't know if anyone can help me, but here it goes... I have tried every virus/trojan scanner I could find and nothing finds it. I'm running Windows XP and SQL Server on my laptop. I have symptoms of a virus/trojan. I seem to have an extra services running (when I go to Admin Tools/Services I see an extra tab below called "Extended" right before the "Standard" tab. Also I found some files (using hijackThis) in the WINDOWS/security/database/ directory. Here's a file list:

mybot.log
mybot.state
services.exe
cygcrypt-0.dll
mybot.pid
mybot.txt
svchost.ini
WindowsServices.sys
cygwin1.dll
system32.dll

Also, when I startup I get a warning using RegRun Run Guard. The warning tells me that two files are dangerous for my computer. The 2 files are:

C:\\WINDOWS\System32\screengrace.vbs
c:\windows\system32\repl\import\scripts\logo.bat

Sorry for the long message. If anyone can lend their expertise I would be very grateful. Thanks for reading.

Lisa

BC AdBot (Login to Remove)

 


#2 Enthusiast

Enthusiast

  • Members
  • 5,898 posts
  • OFFLINE
  •  
  • Location:Florida, USA
  • Local time:12:22 AM

Posted 04 April 2005 - 02:22 PM

Freeware AntiSpyware and Security Programs

Software firewalls with freeware versions
Zone Alarm: http://www.zonealarm.com/
Sygate: http://www.sygate.com/

Antivirus programs - freeware

AVG: http://www.grisoft.com/us/us_index.php

Anti-malware freeware

AdAware: http://www.lavasoftusa.com/software/adaware/
Microsoft Antispyware Beta: http://www.microsoft.com/athome/security/s...re/default.mspx
SpywareBlaster: http://www.javacoolsoftware.com/spywareblaster.html
Spybot S&D: http://www.safer-networking.org/en/index.html
Microsoft Malicious Software Removal Tool (Win XP and Win 2000):
http://www.microsoft.com/security/malwareremove/default.mspx


Web based online Antivrius and anti-malware scans:

Panda Activescan (IE only)
http://www.pandasoftware.com/activescan/co...n_principal.htm

Trend Micro antivirus and malware scan:
http://housecall-beta.trendmicro.com/en/st...orp.asp?id=scan

Etrust Anti-virus web scanner
http://www3.ca.com/securityadvisor/virusinfo/scan.aspx


Start Menu Program Control:

StartUpMonitor: http://www.mlin.net/StartupMonitor.shtml

-------------------

The online scans now scan for all malware, so download, update and run them.

I would also suggest that you download and use the Microsoft Anti-spyware beta.

#3 Scarlett

Scarlett

    Bleeping Diva


  • Members
  • 7,479 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:As always I'm beside myself ;)
  • Local time:12:22 AM

Posted 04 April 2005 - 02:31 PM

Your log needs to be posted in the HijackThis Logs and Analysis Forum.

http://www.bleepingcomputer.com/forums/Hij...alysis-f22.html

I can move it for you, if you like. But first you should add some of the information that was in your initial post.
Posted Image

#4 LoLucky

LoLucky

  • Members
  • 331 posts
  • OFFLINE
  •  
  • Local time:01:22 AM

Posted 04 April 2005 - 03:29 PM

Hi i'm not an Expert and not Claiming to be.
But ...
VolumeControl.exe = BAD!

You also have traces of Alexa
But i would wait till the HJT Team looks into your Log

Also its unknown to me why userinit.exe is shown running on your computer its supposed to do its job and exit but you have it running twice! (Least from my knowledge)

Again i'm no Expert Do not Fix anything on your Own till you have a HJT Expert look at your Log and tell you to do so!
if they don't mention something wrong with VolumeControl.exe Mention it to them!




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users