Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: please help ? virus or what?  (Read 13695 times)

0 Members and 1 Guest are viewing this topic.

computeridiot

    Topic Starter


    Rookie

    please help ? virus or what?
    « on: October 01, 2008, 06:36:42 AM »
    I recently was on here as I had puter problems. A kind person did every scan possible and checked my logs and I thought everything was ok.

    Since then however I have come on my puter today and everytime I put in a website I am re-directed to another, I can't get on to any website I want and the only reason I can get on this one is cus it was bookmarked.

    I have run an avast scan and it came up with nothing I have also done a trogen and malware scan which came up with one thing but it has not solved the problem.

    I can't download anything not even from avast to update as it redirects to another site. Any advice before I just go and pay for a new puter is appreciated.

    I do have hijack this and c.c. cleaner from when I was asked to download them before. 

    Carbon Dudeoxide

    • Global Moderator

    • Mastermind
    • Thanked: 169
      • Yes
      • Yes
      • Yes
    • Certifications: List
    • Experience: Guru
    • OS: Mac OS
    Re: please help ? virus or what?
    « Reply #1 on: October 01, 2008, 06:44:18 AM »
    Run a HijackThis Scan again and post your findings.

    computeridiot

      Topic Starter


      Rookie

      Re: please help ? virus or what?
      « Reply #2 on: October 01, 2008, 06:48:35 AM »
      Just to update you when I did a scan with avast before it kept coming up with some files that could not be scanned, but another of your helpers having checked everything out said that it was ok. However going into avast log I see none of the updates have downloaded since the 28th.



      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 13:47:02, on 01/10/2008
      Platform: Windows XP SP3 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.6000.16705)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Ahead\InCD\InCDsrv.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      C:\Program Files\Alwil Software\Avast4\ashServ.exe
      C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
      C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
      C:\Program Files\Voyager 105 ADSL Modem\dslstat.exe
      C:\Program Files\Voyager 105 ADSL Modem\dslagent.exe
      C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
      C:\Program Files\Ahead\InCD\InCD.exe
      C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
      C:\Program Files\QuickTime\qttask.exe
      C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      C:\PROGRA~1\Comodo\CBOClean\BOC427.exe
      C:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\OLYMPUS\OLYMPUS Master\Monitor.exe
      C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
      C:\Program Files\Samsung\Digimax Viewer 2.1\STImgBrowser.exe
      C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
      C:\Program Files\Google\Google Updater\GoogleUpdater.exe
      C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
      C:\WINDOWS\system32\sistray.exe
      C:\Program Files\Comodo\CBOClean\BOCORE.exe
      C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      C:\Program Files\PC Tools Firewall Plus\FWService.exe
      C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      C:\WINDOWS\system32\wuauclt.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ebay.co.uk/
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
      F3 - REG:win.ini: load=
      F3 - REG:win.ini: run=
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
      O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
      O2 - BHO: SpoofStick BHO - {CBA74CDA-DF78-4AD9-954E-3B15D0A993DE} - C:\Program Files\CoreStreet\SpoofStick\SpoofStickBHO.dll
      O3 - Toolbar: SpoofStick - {4D46ED77-1429-4CF6-8F63-C84B5D710BAF} - C:\Program Files\CoreStreet\SpoofStick\SpoofStick.dll
      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
      O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
      O4 - HKLM\..\Run: [Omnipage] C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
      O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
      O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
      O4 - HKLM\..\Run: [DSLSTATEXE] C:\Program Files\Voyager 105 ADSL Modem\dslstat.exe icon
      O4 - HKLM\..\Run: [DSLAGENTEXE] C:\Program Files\Voyager 105 ADSL Modem\dslagent.exe
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
      O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
      O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
      O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKLM\..\Run: [OM_Monitor] C:\Program Files\OLYMPUS\OLYMPUS Master\FirstStart.exe
      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      O4 - HKLM\..\Run: [BOC-427] C:\PROGRA~1\Comodo\CBOClean\BOC427.exe
      O4 - HKLM\..\Run: [00PCTFW] "C:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe" -s
      O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [OM_Monitor] C:\Program Files\OLYMPUS\OLYMPUS Master\Monitor.exe
      O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
      O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
      O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
      O4 - Global Startup: Digimax Viewer 2.1.lnk = ?
      O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
      O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
      O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
      O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
      O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
      O16 - DPF: {266B9238-31A5-4B53-9039-272FE846DF9D} (DiameterTransfer Control) - http://www.sis.com/download/SISTransfer.cab
      O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/FacebookPhotoUploader.cab
      O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/webplayer/stage6/windows/DivXBrowserPlugin.cab
      O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1164234819625
      O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
      O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab
      O17 - HKLM\System\CCS\Services\Tcpip\..\{3E839371-2795-4956-BB28-8A7ACB106382}: NameServer = 217.72.162.2,217.72.163.3
      O17 - HKLM\System\CCS\Services\Tcpip\..\{C2B5F731-0548-452B-8891-80B10F733E87}: NameServer = 212.159.6.10 212.159.6.9
      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
      O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      O23 - Service: BOCore - COMODO - C:\Program Files\Comodo\CBOClean\BOCORE.exe
      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
      O23 - Service: PC Tools Firewall Plus (PCToolsFirewallPlus) - PC Tools - C:\Program Files\PC Tools Firewall Plus\FWService.exe
      O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

      --
      End of file - 8813 bytes

      computeridiot

        Topic Starter


        Rookie

        Re: please help ? virus or what?
        « Reply #3 on: October 01, 2008, 08:09:14 AM »
        Anyone there please????

        Carbon Dudeoxide

        • Global Moderator

        • Mastermind
        • Thanked: 169
          • Yes
          • Yes
          • Yes
        • Certifications: List
        • Experience: Guru
        • OS: Mac OS
        Re: please help ? virus or what?
        « Reply #4 on: October 01, 2008, 08:10:43 AM »
        Anyone there please????

        I am afraid only our Malware Specialists can help you with the log. Unfortunately there aren't online now, but they will be soon. ;)

        computeridiot

          Topic Starter


          Rookie

          Re: please help ? virus or what?
          « Reply #5 on: October 01, 2008, 08:50:04 AM »
          Thanks for that. I am thinking it may be more than just malware as I just tried to do a system restore to a few days ago when my updates and puter was working normally and when I selected a restore point and clicked next nothing happened.

          So I am thinking unless a genius can sort me out I will need to get a new puter, so anyones help much appreciated.

          alyoob



            Intermediate

            Thanked: 1
            • Experience: Experienced
            • OS: Windows 8
            Re: please help ? virus or what?
            « Reply #6 on: October 01, 2008, 08:59:53 AM »
            Computeridiot what are your computer specifics are you using an hp, dell, gateway or another brand of computer

            Carbon Dudeoxide

            • Global Moderator

            • Mastermind
            • Thanked: 169
              • Yes
              • Yes
              • Yes
            • Certifications: List
            • Experience: Guru
            • OS: Mac OS
            Re: please help ? virus or what?
            « Reply #7 on: October 01, 2008, 09:01:42 AM »
            So I am thinking unless a genius can sort me out I will need to get a new puter,
            Don't worry, we have many geniuses here. :D

            Carbon Dudeoxide

            • Global Moderator

            • Mastermind
            • Thanked: 169
              • Yes
              • Yes
              • Yes
            • Certifications: List
            • Experience: Guru
            • OS: Mac OS
            Re: please help ? virus or what?
            « Reply #8 on: October 01, 2008, 09:02:23 AM »
            Computeridiot what are your computer specifics are you using an hp, dell, gateway or another brand of computer


            Alyoob, please leave the Computer Virus and Spyware section for the Malware Specialists.
            Do not try to diagnose the problem yourself as we have professionals who know exactly what they are doing.

            Would you like to learn to fight Malware?
            http://www.computerhope.com/forum/index.php/topic,57605.0.html

            computeridiot

              Topic Starter


              Rookie

              Re: please help ? virus or what?
              « Reply #9 on: October 01, 2008, 10:07:15 AM »
              Can someone help me? Its been hours and others are getting help but no one is replying to me?   :'(

              evilfantasy

              • Malware Removal Specialist
              • Moderator


              • Genius
              • Calm like a bomb
              • Thanked: 493
              • Experience: Experienced
              • OS: Windows 11
              Re: please help ? virus or what?
              « Reply #10 on: October 01, 2008, 10:33:12 AM »
              Post the other two logs from here http://www.computerhope.com/forum/index.php/topic,46313.0.html

              Then a new HijackThis scan.

              computeridiot

                Topic Starter


                Rookie

                Re: please help ? virus or what?
                « Reply #11 on: October 01, 2008, 10:46:59 AM »
                BUT that is my whole problem....I can't. When I click to access a site it either comes up as page can't be displayed or it re-directs me to a completely different site. That is why I can't even up date my antivirus as it can't connect to the site cus I guess its been redirected.

                evilfantasy

                • Malware Removal Specialist
                • Moderator


                • Genius
                • Calm like a bomb
                • Thanked: 493
                • Experience: Experienced
                • OS: Windows 11
                Re: please help ? virus or what?
                « Reply #12 on: October 01, 2008, 11:34:35 AM »
                Please print these instructions as they will be needed later when Internet access is not available.
                 
                Download SDFix by AndyManchesta and save it to your desktop. http://rapidshare.com/files/149534018/SDFix.exe.html
                 
                When using this tool, you must use the Administrator's account or an account with Administrative rights
                • Double click SDFix.exe and it will extract the files to %systemdrive%
                • (this is the drive that contains the Windows Directory, typically C:\SDFix).
                • DO NOT use it just yet.
                Reboot your computer in Safe Mode using the F8 method. To do this, restart your computer and after hearing your computer beep once during startup (but before the Windows icon appears) press the F8 key repeatedly. A menu will appear with several options. Use the arrow keys to navigate and select the option to run Windows in "Safe Mode".
                 
                Open the SDFix folder and double click RunThis.bat to start the script.
                • Type Y to begin the cleanup process.
                • It will remove any Trojan Services or Registry Entries found then prompt you to press any key to Reboot.
                • Press any Key and it will restart the PC.
                • When the PC restarts, the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
                • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt.
                • Copy and paste the contents of the results file Report.txt in your next reply along with a new HijackThis log.

                computeridiot

                  Topic Starter


                  Rookie

                  Re: please help ? virus or what?
                  « Reply #13 on: October 01, 2008, 11:42:01 AM »
                  I can't seem to do system restore and whilst I can get on some sites others come up as can't be displayed. Do you think its my browser? I tried firefox as well but its the same.

                  But my avast was up to date and it did not find anything neither did a trogan scan.

                  I did c.c. clean and got it to fix things on that with a back up.

                  What does this other scan do as I have never had to do safe mode and a bit nervous about doing it.

                  evilfantasy

                  • Malware Removal Specialist
                  • Moderator


                  • Genius
                  • Calm like a bomb
                  • Thanked: 493
                  • Experience: Experienced
                  • OS: Windows 11
                  Re: please help ? virus or what?
                  « Reply #14 on: October 01, 2008, 11:44:21 AM »
                  It will fix the problems you are having. I need logs, it is impossible to guess at the multitude of problems without seeing logs.