Computer Hope

Software => Computer viruses and spyware => Topic started by: The Bubba on April 02, 2008, 06:18:57 PM

Title: I Have a virus
Post by: The Bubba on April 02, 2008, 06:18:57 PM
I've recently found that I have a virus called win32qhost.mg and was trying to find a program to remove it. I found one called CyberDefender and It says it out performs all of the well known others and lists them. Is it safe to use?
__________________
Title: Re: I Have a virus
Post by: evilfantasy on April 02, 2008, 06:36:30 PM
Not familiar with it.

Trusted method  HERE (http://www.computerhope.com/forum/index.php/topic,46313.0.html)
Title: Re: I Have a virus
Post by: The Bubba on April 02, 2008, 08:50:29 PM
I have AVG and it doesn't know it's there. I found it using Kaspersky's on line scan. My AVG is always updated as well and it still didn't catch it. I guess I'll bite and use this CyberDefender program that says it can remove it.
Title: Re: I Have a virus
Post by: evilfantasy on April 02, 2008, 09:40:47 PM
Cyberdefender is a rouge tool. See  HERE (http://www.siteadvisor.com/sites/cyberdefender.com?ref=safesearch&client_ver=FF_26.5_6258&locale=en-US&premium=false&aff_id=0) If you downloaded it then you have just infected your computer even further. All the tools we suggest are free and don't contain even more malware.

Do you still have the Kaspersky scan log? Kaspersky finds things but unless you know exactly what you are looking at in the log then it can be misleading.

You can follow the guide from my previous post or go for it on your own. Your choice.
Title: Re: I Have a virus
Post by: The Bubba on April 03, 2008, 09:27:37 AM
Looks like there are mixed feelings about it. My AVG doesn't detect the win32qhost Trojan and my computer is still acting very slow and won't even open pages on the first or second try. What to do except put down some bucks for a good program that can remove it.
Title: Re: I Have a virus
Post by: evilfantasy on April 03, 2008, 10:05:35 AM

Trusted method  HERE (http://www.computerhope.com/forum/index.php/topic,46313.0.html)

You can either do our guide which has helped hundreds fix their malware problems for free or as I said in the previous post you can go it alone. Your choice.
Title: Re: I Have a virus
Post by: The Bubba on April 03, 2008, 10:37:58 AM
OK, I had already done the first 3 steps and will get back to you after I'm through with the rest. I had gone over your list before but got distracted somehow.
Title: Re: I Have a virus
Post by: The Bubba on April 04, 2008, 11:49:56 PM
I'm about to give up, I've done all the steps and now when I try to add 3 attachments, it say either I can't add 4 attachments, no body or you've already posted that. What's a guy to do?
Title: Re: I Have a virus
Post by: The Bubba on April 04, 2008, 11:51:55 PM
I'm going to try each attachment in 3 different posts.

[recovering space - attachment deleted by admin]
Title: Re: I Have a virus
Post by: The Bubba on April 04, 2008, 11:52:56 PM
Another

Dr Web didn't want to do right, here is the log.


CFD.exe;C:\Program Files\BroadJump\Client Foundation;Adware.Cfd;;
00688484.FIL;D:\$VAULT$.AVG;Trojan.Fakealert.406;Deleted.;
00710875.FIL;D:\$VAULT$.AVG;Trojan.Fakealert.406;Deleted.;
00733187.FIL;D:\$VAULT$.AVG;Trojan.Fakealert.406;Deleted.;
nutils.dll;D:\Program Files\NoAdware5.0;Trojan.NtRootKit.103;Deleted.;
A0018115.dll;D:\System Volume Information\_restore{84ED5C82-C100-4A9C-A172-5240B436D570}\RP186;Trojan.NtRootKit.103;Deleted.;
A0019384.dll;D:\System Volume Information\_restore{84ED5C82-C100-4A9C-A172-5240B436D570}\RP190;Trojan.NtRootKit.103;Deleted.;




[recovering space - attachment deleted by admin]
Title: Re: I Have a virus
Post by: The Bubba on April 04, 2008, 11:53:41 PM
And the last


[recovering space - attachment deleted by admin]
Title: Re: I Have a virus
Post by: The Bubba on April 04, 2008, 11:54:27 PM
Success maybe? ::)
Title: Re: I Have a virus
Post by: evilfantasy on April 05, 2008, 12:22:58 AM
Having two antivirus programs running at the same time causes your computer to run very slowly and also causes random lockups.

Please uninstall one antivirus program and then run a new Hijackthis scan and post the log. You can just copy and pase it directly into the post instead of attaching it.

Let me know how things are now.
Title: Re: I Have a virus
Post by: The Bubba on April 05, 2008, 06:18:32 AM
I removed one of the anti virus programs. Did you remove my attachments? Here is the Hijack this log you asked for. BTW, my computer is doing much better but still acting up just a tad.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:13:34 AM, on 4/5/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
D:\WINDOWS\system32\spoolsv.exe
D:\WINDOWS\Explorer.EXE
D:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
D:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
D:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
D:\Program Files\IE New Window Maximizer\iemaximizer.exe
D:\WINDOWS\system32\ctfmon.exe
D:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
D:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
D:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
D:\PROGRA~1\Grisoft\AVG7\avgemc.exe
D:\WINDOWS\system32\wuauclt.exe
D:\Documents and Settings\John Matthews\My Documents\Hijack this\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://bigblueheaven.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - D:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O4 - HKLM\..\Run: [AVG7_CC] D:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "D:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKCU\..\Run: [IE New Window Maximizer] D:\Program Files\IE New Window Maximizer\iemaximizer.exe
O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] D:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] D:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] D:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] D:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] D:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: Microsoft Office.lnk = D:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &ieSpell Options - res://D:\Program Files\ieSpell\iespell.dll/SPELLOPTION.HTM
O8 - Extra context menu item: Check &Spelling - res://D:\Program Files\ieSpell\iespell.dll/SPELLCHECK.HTM
O8 - Extra context menu item: Lookup on Merriam Webster - file://D:\Program Files\ieSpell\Merriam Webster.HTM
O8 - Extra context menu item: Lookup on Wikipedia - file://D:\Program Files\ieSpell\wikipedia.HTM
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - D:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - D:\Program Files\ieSpell\iespell.dll
O9 - Extra button: (no name) - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - D:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - D:\Program Files\ieSpell\iespell.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/us/kavwebscan_unicode.cab
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://driveragent.com/files/driveragent.cab
O20 - Winlogon Notify: !SASWinLogon - D:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - D:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - D:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - D:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - D:\PROGRA~1\Grisoft\AVG7\avgemc.exe

--
End of file - 6016 bytes

Title: Re: I Have a virus
Post by: The Bubba on April 05, 2008, 10:31:26 AM
Well I saw the proceedure that you suggested remove some viruses, but I ran another Kaspersky online scan and it says I still have 6 viruses.
Title: Re: I Have a virus
Post by: patio on April 05, 2008, 11:01:55 AM
I suggest starting over following the Guideline from start to finish...there's a reason it was written the way it was and has been successful in the past.
Keep in mind a lot of work was put into this method and is done by volunteers...
If i'm off target on this i apologise but try it anyways.
Title: Re: I Have a virus
Post by: evilfantasy on April 05, 2008, 01:19:26 PM
Since you ran Kaspersky you could have posted the log. It would be a big help and I may need you to run it again so I can see the log.


Open Hijackthis and select Do a system scan only.

Place a check mark next to the following entries: (if there)

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm

Important: Close all windows except for Hijackthis and then click Fix checked.

Exit Hijackthis.

----------

Please download ATF Cleaner by Atribune.  ATF Cleaner.exe (http://www.atribune.org/ccount/click.php?id=1)

Make sure that all browser windows are closed.
.
Important: Restart the computer before continuing.

----------

This scanner works with Internet Explorer only
Go to the  BitDefender Online Scanner (http://www.bitdefender.com/scan8/ie.html)
Click I Agree to the license and then install the ActiveX control.
Please DO NOT change the Scanning Options.
That will make your logs huge and we don't need to see clean files.

Select Start Scan to begin.
This scan can take a while so please be patient and let it complete.

 Once Bitdefender completes the scan:
 Click-on the Detected Problems tab.
 Then select Click here to export the scan report

(http://i154.photobucket.com/albums/s258/evilfantasy69/Tutorials/bit.jpg)
 
 When the window comes up to save the report, change the Save as type: box to:
 Text (Tab Delimited) (*.txt) and then in the File name box enter change to bdscan then click Save

(http://i154.photobucket.com/albums/s258/evilfantasy69/Tutorials/bit2.jpg)
 
 This will save a file named bdscan.txt. I would suggest saving it to the Desktop so you can easily find it. (take notice of where you save it so you can find it later)
 
 This bdcan.txt file will actually contain HTML code that we can easily view later while reviewing your log. All we have to do is rename the file to bdscan.html.
 
 If you do not follow these step, you will have an incorrect log or worse a log summary which is useless to us
 
 Post the bdscan.txt in the next post.
Title: Re: I Have a virus
Post by: The Bubba on April 05, 2008, 01:47:54 PM
I'm at work right now but will tear into it when I get home later tonight. Thanks for all the help so far, it is much appreciated.
Title: Re: I Have a virus
Post by: evilfantasy on April 05, 2008, 01:49:05 PM
No problem, I should be around.
Title: Re: I Have a virus
Post by: The Bubba on April 06, 2008, 09:56:46 AM
I had to break up the Kaspersky log (too big for an attachment). I'm sending the top and the parts showing all infections.

Saturday, April 05, 2008 11:25:12 AM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 5/04/2008
Kaspersky Anti-Virus database records: 684126
 
 
Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true
 
Scan Target My Computer
A:\
C:\
D:\
E:\
F:\
G:\ 
 
Scan Statistics
Total number of scanned objects 105330
Number of viruses found 6
Number of infected objects 8
Number of suspicious objects 0
Duration of the scan process 01:52:06

C:\Documents and Settings\john\.housecall6.6\Quarantine\SeekmoTB.dll.bac_a03132  Infected: not-a-virus:AdWare.Win32.Agent.c  skipped 
 
C:\Documents and Settings\john\My Documents\ww2rescue.exe/file451  Infected: not-a-virus:AdTool.Win32.WhenU.a  skipped 
 
C:\Documents and Settings\john\My Documents\ww2rescue.exe/file452  Infected: not-a-virus:Server-Proxy.Win32.MarketScore.k  skipped 
 
C:\Documents and Settings\john\My Documents\ww2rescue.exe/file453  Infected: not-a-virus:AdWare.Win32.NewDotNet  skipped 
 
C:\Documents and Settings\john\My Documents\ww2rescue.exe  Inno: infected - 3  skipped 
 
C:\System Volume Information\MountPointManagerRemoteDatabase  Object is locked  skipped 
 
C:\WINDOWS\system32\drivers\etc\hosts.20070828-214029.backup  Infected: Trojan.Win32.Qhost.mg  skipped 
 
C:\WINDOWS\system32\drivers\etc\hosts.20070828-214030.backup  Infected: Trojan.Win32.Qhost.mg  skipped 
 
D:\25bbe8f1d2e98ae45a383005147b\ffastun.ffo  Object is locked  skipped 
 
D:\25bbe8f1d2e98ae45a383005147b\ffastun0.ffx  Object is locked  skipped 
 
D:\Documents and Settings\All Users\Application Data\avg7\Log\emc.log  Object is locked  skipped 
 
D:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log  Object is locked  skipped 
 
D:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log.lck  Object is locked  skipped 
 
D:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat  Object is locked  skipped 
 
D:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat  Object is locked  skipped 
 
D:\Documents and Settings\\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\AppLogs\SUPERANTISPYWARE-4-5-2008( 8-12-1 ).LOG  Object is locked  skipped 
 
D:\Documents and Settings\\Cookies\index.dat  Object is locked  skipped 
 
D:\Documents and Settings\\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat  Object is locked  skipped 
 
D:\Documents and Settings\\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat  Object is locked  skipped 
 
D:\Documents and Settings\\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG  Object is locked  skipped 
 
D:\Documents and Settings\\Local Settings\History\History.IE5\index.dat  Object is locked  skipped 
 
D:\Documents and Settings\\Local Settings\History\History.IE5\MSHist012008040520080406\index.dat  Object is locked  skipped 
 
D:\Documents and Settings\\Local Settings\Temp\~DF3D01.tmp  Object is locked 
Title: Re: I Have a virus
Post by: evilfantasy on April 06, 2008, 10:20:09 AM
Please download Combofix by sUBs from one of the below links.
(Try all three if necessary)Important! Combofix.exe MUST be saved to and ran from the Desktop.Warning: Do not mouseclick combofix's window while it is running. That may cause it to stall
Title: Re: I Have a virus
Post by: The Bubba on April 06, 2008, 02:48:33 PM
I haven't had time to go through the approved procedures because of some things that came up. I don't have anything planned tonight when I get home and should be able to devote my full attention to my computer. Do you want me to do the other steps posted first or just go straight to the Combofix?
Title: Re: I Have a virus
Post by: evilfantasy on April 06, 2008, 03:16:31 PM
We will do the combofix first, according to the Kaspersky log it is needed.
Title: Re: I Have a virus
Post by: The Bubba on April 06, 2008, 03:40:45 PM
Will do, which will be in about 5 hours when I get home.
Title: Re: I Have a virus
Post by: The Bubba on April 06, 2008, 10:15:13 PM
Here is the Combofix log:



[recovering space - attachment deleted by admin]
Title: Re: I Have a virus
Post by: evilfantasy on April 07, 2008, 12:45:39 AM
Delete these files/folders, as follows:

1. Go to Start > Run > type Notepad.exe and click OK to open Notepad.
It must be Notepad, not Wordpad.
2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C

Code: [Select]
Killall::

Folder::
D:\Program Files\CyberDefender
D:\Program Files\NoAdware5.0
File::
D:\WINDOWS\st_affiliate.ini

3. Go to the Notepad window and click Edit > Paste
4. Then click File > Save
5. Name the file CFScript.txt - Save the file to your Desktop
6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully!

(http://i154.photobucket.com/albums/s258/evilfantasy69/CFScript.gif)

ComboFix will begin to execute, just follow the prompts.
After reboot (in case it asks to reboot), it will produce a log for you.
Post that log (Combofix.txt) in your next reply.

Note: Do not mouseclick combofix's window while it is running. That may cause your system to freeze


After posting that log run the BitDefender scan from  HERE (http://www.computerhope.com/forum/index.php/topic,54395.msg341715.html#msg341715) and post the log from it.
Title: Re: I Have a virus
Post by: The Bubba on April 07, 2008, 11:33:15 AM
Will do. While I was waiting for your reply last night, I began doing the other procedure. I fell asleep during AVG's scan, man these scans are long. It found a virus though and deleted it. I'll your other procedure when I get home tonight. The way this is going, I might get this accomplished in about a week. ;D
Title: Re: I Have a virus
Post by: evilfantasy on April 07, 2008, 11:42:19 AM
Quote
man these scans are long.

The alternative is manually looking at each file. ;)

We will get through it all. Might take some time but it's worth it.
Title: Re: I Have a virus
Post by: The Bubba on April 07, 2008, 04:08:10 PM
There's no doubt it's worth it, you guys amaze me with your staying power. I've been to other computer sites and they're pretty good but you guys are the pick of the litter. ;D
Title: Re: I Have a virus
Post by: The Bubba on April 07, 2008, 09:49:26 PM
Here is the Combofix log, now off to bitdefender. I don't know how I double entered the attachment? ???

[recovering space - attachment deleted by admin]
Title: Re: I Have a virus
Post by: evilfantasy on April 07, 2008, 09:55:25 PM
Looks good. Combofix took care of what I was hoping it would. Hopefully BitDefender will be good news as well.
Title: Re: I Have a virus
Post by: The Bubba on April 07, 2008, 10:10:30 PM
Bitdefender giving me trouble, it won't comply. I went to my security options but they were set in accordance with Defender's specs.
Title: Re: I Have a virus
Post by: evilfantasy on April 07, 2008, 10:15:26 PM
Try this one instead.

Use the  Trend Micro Housecall Scan (http://housecall.trendmicro.com/us/index.html)

Title: Re: I Have a virus
Post by: The Bubba on April 07, 2008, 11:49:47 PM
I tried another site and got it to take, here is it's scan:



[recovering space - attachment deleted by admin]
Title: Re: I Have a virus
Post by: The Bubba on April 07, 2008, 11:50:21 PM
I will do housecall as well.
Title: Re: I Have a virus
Post by: evilfantasy on April 07, 2008, 11:54:26 PM
Was this the Bitdefender online scan?

Please post a new Hijackthis log.

Let me know how things are now.

Title: Re: I Have a virus
Post by: The Bubba on April 08, 2008, 10:44:06 AM
I'm afraid not, it has an icon in my startup bar or task menu. Here is the Hijack this log.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:43:13 AM, on 4/8/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
D:\WINDOWS\system32\spoolsv.exe
D:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
D:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
D:\PROGRA~1\Grisoft\AVG7\avgemc.exe
D:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe
D:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe
D:\WINDOWS\Explorer.EXE
D:\WINDOWS\system32\ctfmon.exe
D:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
D:\Program Files\IE New Window Maximizer\iemaximizer.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe
D:\Program Files\Softwin\BitDefender10\vsserv.exe
D:\Program Files\Softwin\BitDefender10\bdmcon.exe
D:\Documents and Settings\John Matthews\My Documents\Hijack this\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://bigblueheaven.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - D:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O4 - HKLM\..\Run: [AVG7_CC] D:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "D:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKCU\..\Run: [IE New Window Maximizer] D:\Program Files\IE New Window Maximizer\iemaximizer.exe
O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] D:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] D:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] D:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] D:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] D:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: Microsoft Office.lnk = D:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &ieSpell Options - res://D:\Program Files\ieSpell\iespell.dll/SPELLOPTION.HTM
O8 - Extra context menu item: Check &Spelling - res://D:\Program Files\ieSpell\iespell.dll/SPELLCHECK.HTM
O8 - Extra context menu item: Lookup on Merriam Webster - file://D:\Program Files\ieSpell\Merriam Webster.HTM
O8 - Extra context menu item: Lookup on Wikipedia - file://D:\Program Files\ieSpell\wikipedia.HTM
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - D:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - D:\Program Files\ieSpell\iespell.dll
O9 - Extra button: (no name) - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - D:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - D:\Program Files\ieSpell\iespell.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/us/kavwebscan_unicode.cab
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://driveragent.com/files/driveragent.cab
O20 - Winlogon Notify: !SASWinLogon - D:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - D:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - D:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - D:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - D:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - D:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - SOFTWIN S.R.L. - D:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - SOFTWIN S.R.L. - D:\Program Files\Softwin\BitDefender10\vsserv.exe
O23 - Service: BitDefender Communicator (XCOMM) - SOFTWIN S.R.L - D:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe

--
End of file - 6713 bytes
Title: Re: I Have a virus
Post by: The Bubba on April 08, 2008, 11:33:42 AM
I was able to go in and make a few security changes to allow the online bitdefender to work and will post it when I get home tonight. They're sooo long.
Title: Re: I Have a virus
Post by: evilfantasy on April 08, 2008, 11:46:49 AM
OK, if needed go to www.savefile.com and upload the log there. There is no need to sign up, just post the link to the file back here so I can go to it.

You can uninstall the BitDefender standalone that you used earlier. We are done with it.
Title: Re: I Have a virus
Post by: The Bubba on April 08, 2008, 03:26:43 PM
Thanks, will do. I assume the Hijackthis log was OK?
Title: Re: I Have a virus
Post by: evilfantasy on April 08, 2008, 03:36:43 PM
Yes it looked good, this will hopefully be the last scan.
Title: Re: I Have a virus
Post by: The Bubba on April 08, 2008, 09:59:39 PM
I don't think my computer is clean, it's still acting up. Here's the bitdefender log:

http://www.savefile.com/files/1492924
Title: Re: I Have a virus
Post by: The Bubba on April 08, 2008, 11:17:05 PM
I have a question, How long does it take for Housecall to initiate the scan? I called it up and it's taking a small lifetime to begin it's scan.
Title: Re: I Have a virus
Post by: evilfantasy on April 09, 2008, 12:07:11 AM
The housecall definitions can take a while.

What do you mean by acting up?
Title: Re: I Have a virus
Post by: The Bubba on April 09, 2008, 06:37:12 AM
It's still giving some of the old symptoms, sluggish, doesn't load the pages on the first try, takes a long time loading detail stuff like banners or icons like login and register. I run a website too as you may have noticed and when I call it up, it sometimes doesn't load all the way and I have to hit refresh.
Title: Re: I Have a virus
Post by: The Bubba on April 09, 2008, 08:55:43 AM
Here is my latest Kaspersky, it still says I have 5 viruses.

 http://www.savefile.com/files/1493802
Title: Re: I Have a virus
Post by: evilfantasy on April 09, 2008, 09:32:23 AM
Go in and delete this file ww2rescue.exe and any others with the name in it.

Found in C:\Documents and Settings\john\My Documents\ww2rescue.exe

Now lets do some cleanup.

Let's clear out the programs we've been using to clean up your computer, they are not suitable for
general malware removal and could cause damage if launched accidentally and will help secure the work you have done.
.
.
(http://i154.photobucket.com/albums/s258/evilfantasy69/combofixu-1.jpg)
.
The above procedure will:.
Download OTMoveIt2 by OldTimer  OTMoveIt2.exe (http://download.bleepingcomputer.com/oldtimer/OTMoveIt2.exe) and place it on your desktop. (unless you already have it installed)

1. Double click OTMoveIt2.exe to launch it.
Vista users right click and choose Run As Administrator
2. Click on the CleanUp! button.
3. OTMoveIt2 will download a list from the Internet, if your firewall or other defensive programs alerts you, allow it access.
4. Click YES at the next prompt (list downloaded, Do you want to begin cleanup process?)
5. Once complete exit out of OTMoveIt2

Set a New Restore Point to prevent possible reinfection from an old one
Setting a new restore point AFTER cleaning your system will enable your computer to roll-back to a clean working state if needed.
.
Use the  Secunia Software Inspector (http://secunia.com/software_inspector) to check for out of date software.
.
Here are some great tools to help you keep from getting infected again.

To prevent unknown applications from being installed on your computer install WinPatrol 2007 (http://"http://www.winpatrol.com/winpatrol.html")

Another thing I would suggest installing SiteAdvisor (http://www.siteadvisor.com/). SiteAdvisor rates sites on business practices and spam.

 Spybot Search & Destroy (http://fileforum.betanews.com/detail/Spybot_Search_and_Destroy/1043809773/1) - A safe and effective spyware scanner.
*  (http://www.safer-networking.org/en/tutorial/index.html)Using Spybot - Search & Destroy to remove Spyware , Malware, and Hijackers (http://www.bleepingcomputer.com/forums/tutorial43.html)

 AVG Anti-Spyware Free Edition (http://free.grisoft.com/doc/download-free-anti-spyware/us/frt/0) - Very reliable with a high detection rate.
*  AVG Anti-Spyware User Manual (http://free.grisoft.com/doc/5390/us/frt/0?prd=asf)

 SpywareBlaster (http://www.javacoolsoftware.com/spywareblaster.html) - Secure your Internet Explorer to make it harder for these ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
*  (http://www.bleepingcomputer.com/tutorials/tutorial49.html)Using SpywareBlaster to protect your computer from Spyware and Malware (http://www.bleepingcomputer.com/forums/tutorial49.html)

 Comodo BOClean (http://www.comodo.com/boclean/CBO_download.html) - Stops trojans and many more malicious attacks.

Use a Firewall - It can not be stressed enough how important it is that you use a Firewall on your computer. Without a firewall your computer is susceptible to being hacked and taken over.
*  Click here (http://www.freebyte.com/antivirus/#freefirewalls) for a list of free firewalls.
*  Why would I consider a third party firewall? (http://www.microsoft.com/windowsxp/using/security/learnmore/atkin_firewall.mspx#EGF)
* Understanding and Using Firewalls (http://www.bleepingcomputer.com/forums/tutorial60.html)

 UPDATE!!! UPDATE!!! UPDATE!!! - If you do not have automatic updates enabled then visit http://www.windowsupdate.com[/b]]http://www.windowsupdate.com (http://[b) regularly. This will ensure your computer has always the latest security updates available installed on your computer.
*  Help with Windows updates (http://support.microsoft.com/?scid=ph;en-us;6527)

Learn more about how to protect yourself while on the internet read this article by Tony Klien:  So how did I get infected in the first place? (http://www.castlecops.com/postlite7736-.html)

Let us know how things are now.
Title: Re: I Have a virus
Post by: The Bubba on April 09, 2008, 03:23:09 PM
Back at work again, I have tomorrow off and hopefully will be able to devote the whole day to my computer. I finally got Housecall to run and it cleaned up some stuff. I will try to get as much done tonight as I can on your to do list.
Title: Re: I Have a virus
Post by: The Bubba on April 09, 2008, 09:29:42 PM
I did the combofix /u in the run box and it didn't remove Combofix, it gave me a run box which I clicked and then acted like it ran Combofix.
Title: Re: I Have a virus
Post by: evilfantasy on April 09, 2008, 09:32:00 PM
OTMoveIt2 should remove anything left over that combofix /u didn't get so that is OK if it didn't work right.
Title: Re: I Have a virus
Post by: The Bubba on April 09, 2008, 10:07:26 PM
OK, we'll give it a try.
Title: Re: I Have a virus
Post by: The Bubba on April 09, 2008, 10:36:52 PM
I ran OTMoveIt2.exe and it removed combofix. I then created a new restore point and then tried to run Cleanmgr, it didn't give me the more options you mentioned, it just wanted to know which drive I wanted to clean, C or E.
Title: Re: I Have a virus
Post by: evilfantasy on April 09, 2008, 10:42:41 PM
Try it this way.

Reset and Re-enable your System Restore to remove any infected files that have been backed up by Windows. The files in System Restore are protected to prevent any programs from changing those files. This is the only way to clean these files: (You will lose all previous restore points which are infected, but that's good news)

Turn OFF System RestoreRestart your computer

Turn ON System Restore
System Restore will now be active again


Now set a new restore point
Title: Re: I Have a virus
Post by: The Bubba on April 09, 2008, 10:46:27 PM
OK, be right back.
Title: Re: I Have a virus
Post by: The Bubba on April 09, 2008, 10:54:55 PM
All done, do I do the aforemention proceedure now?
Title: Re: I Have a virus
Post by: evilfantasy on April 09, 2008, 11:13:09 PM
 Secunia Software Inspector would be advised. then check through the rest and see if there is anything you may use to tighten up your security.
Title: Re: I Have a virus
Post by: The Bubba on April 09, 2008, 11:18:57 PM
I already have most of what you've listed but will install what I don't have. I'm venturing to guess that I'm still infected. That's not a slam by any means but my computer is still not right.
Title: Re: I Have a virus
Post by: evilfantasy on April 09, 2008, 11:22:33 PM
I don't think that an infection is causing the problem. You can run a new Kaspersky scan and post the log for a double check.

You don't need everything in the list. I try to give more than one option for the software I advise to use so it doesn't seem like I am promoting any one product - which I don't.
Title: Re: I Have a virus
Post by: The Bubba on April 09, 2008, 11:44:25 PM
After I install everything and do scans, I'll do a Kaspersky and post it. See you tomorrow.
Title: Re: I Have a virus
Post by: The Bubba on April 10, 2008, 08:35:06 AM
Well, after running another Kaspersky scan, I can now say that my computer is clean. I now need to know how many of these new found security programs do I need on my start up menu or task bar and which ones can be ran every so often? I now have Window Patrol (have always had) AVG..ditto, new stuff is Comodo Boclean, spybot, Superantispyware, Omniquad total security and last but not least, a Kerio firewall. I want to thank you (Evilfantasy) for taking the time to help me struggle through these cleansing processes. Off topic, how's the weather there, we are due east of you and are expecting the same severe weather.
Title: Re: I Have a virus
Post by: The Bubba on April 10, 2008, 10:03:00 AM
While I am heaping praises, my computer is still having trouble opening web pages in a timely manner. Sometimes it fails completely. I guess the chase is still on.
Title: Re: I Have a virus
Post by: evilfantasy on April 10, 2008, 12:08:03 PM
Keep everything but Omniquad total security.

Do you have an XP CD?

If so, place it in your CD ROM drive and follow the instructions below:SFC - Which stands for System File Checker, retrieves the correct version of the file from %Systemroot%\System32\Dllcache or the Windows installation source files, and then replaces the incorrect file.

If you want to see what was replaced, right-click My Computer and click on Manage.
In the new window that appears, expand the Event Viewer (by clicking on the + symbol next to it) and then click on System.


The rain finally stopped today. First night we were getting large golfball size hail and then heavy rain for what seemed like 48 hours. Could be another flood riddled season in the midwest. Hope not.....
Title: Re: I Have a virus
Post by: The Bubba on April 10, 2008, 02:09:44 PM
Hmmm, the last time I was asked to place my XP cd in my drive, I accidentally reinstalled it and lost valuable personal files. Let's hope it doesn't happen again, it's a long drive to OK.
Title: Re: I Have a virus
Post by: evilfantasy on April 10, 2008, 02:18:22 PM
That method won't delete anything. Just don't restart the computer with the CD in the drive and you won't chance loosing anything.
Title: Re: I Have a virus
Post by: The Bubba on April 10, 2008, 03:28:45 PM
Mission accomplished but computer still sluggish. Some sites had to be refreshed to get them to load. I defraged today as well.
Title: Re: I Have a virus
Post by: evilfantasy on April 10, 2008, 03:44:21 PM
Let's try a few things with dial a fix.

First

Please download Dial-a-Fix (http://wiki.djlizard.net/Dial-a-fix#Mirrors.2Fdownload_locations.2C_and_articles) by djlizard, save it to the desktop then extract it to it's own folder..

Next

Open Dial-a-fix and click the hammer icon. Select Flush DNS and click Go
When complete, select Repair Permissions and click Go
When complete, select Repair/reinstall IE and click Go

If at any time you are prompted for the XP cd, insert it
Make note of any error messages and post them here
Reboot when complete and let me know if there's any change
Title: Re: I Have a virus
Post by: The Bubba on April 10, 2008, 05:34:15 PM
OK, but first I'm going to do some checks that dial-a-fix recommends first.
Title: Re: I Have a virus
Post by: The Bubba on April 10, 2008, 06:40:04 PM
Just concluded Dial a fix and had no problems. Computer is still slightly sluggish and some pages still have to be refreshed. Even on my own website, things like chat room boxes and stat counters are way slow to load. Any other suggestions?
Title: Re: I Have a virus
Post by: The Bubba on April 10, 2008, 06:45:39 PM
Just for grins, click on my website and scroll the whole page and time how long it takes. The last thing to load is the search engine boxes at the very bottom of the page. If your computer takes very long for it to load then I won't gripe but I know that in the past, mine use to load it in about 5 seconds.
Title: Re: I Have a virus
Post by: evilfantasy on April 10, 2008, 07:03:51 PM
Pretty much instantly.

Do you think it is the browser or your connection?

Title: Re: I Have a virus
Post by: The Bubba on April 10, 2008, 07:50:36 PM
It's possible, Insight has recently changed over to Comcast. As far as browsers, I've been using the same all a long. I installed Foxfire and tried it but it didn't do justice to some of the graphics on my site.

I really appreciate your help and even recommended the site on my site, thanks again.
Title: Re: I Have a virus
Post by: evilfantasy on April 10, 2008, 08:07:55 PM
Could be the connection. You could try re-installing IE7.

[/list]
Title: Re: I Have a virus
Post by: The Bubba on April 11, 2008, 09:03:24 AM
I downloaded, uninstalled and reinstalled IE7. I can't tell any difference so far. What is your opinion on the IE7 add ons that they offer?
Title: Re: I Have a virus
Post by: evilfantasy on April 11, 2008, 10:50:29 AM
Which add-ons, and from where?
Title: Re: I Have a virus
Post by: The Bubba on April 11, 2008, 02:52:52 PM
They are the addons that you can choose after installing IE7. They come with it, one of them is ispell. BTW, my computer is getting a bit perkier.
Title: Re: I Have a virus
Post by: evilfantasy on April 11, 2008, 03:23:07 PM
Hopefully it will come all the way around.

I am not real fammiliar with the add ons in ie7, I use Firefox. I did a google and found some interesting ones  HERE (http://www.ghacks.net/2007/03/16/10-must-see-internet-explorer-7-addons/). I suppose as long as they come from a reliable source then they would be great to use.
Title: Re: I Have a virus
Post by: The Bubba on April 11, 2008, 03:36:50 PM
Thanks and thanks again for all the work involved in helping clean up my computer.
Title: Re: I Have a virus
Post by: evilfantasy on April 11, 2008, 03:40:18 PM
No problem, safe surfing.........
Title: Re: I Have a virus
Post by: The Bubba on April 11, 2008, 04:04:48 PM
And safe surfing to you as well.
Title: Re: I Have a virus
Post by: The Bubba on April 12, 2008, 06:06:04 AM
Sorry to keep hanging on but my computer is still pretty sluggish. What do you think of the idea that the problem may be stemming from my modem (cable) or my router? I can bypass the router but how do you check a modem other than look at it's lights?
Title: Re: I Have a virus
Post by: evilfantasy on April 12, 2008, 10:16:16 AM
Not sure how to check a modem.

Try this.  PC Pitstop Full Tests (http://pcpitstop.com/pcpitstop/default.asp). It's a free set of tests. Might lead on to something that can be looked into.
Title: Re: I Have a virus
Post by: The Bubba on April 12, 2008, 02:26:48 PM
After running the tests, I have 3 areas that brought up yellow flags.

1) Memory 480 MB ram

2) Drives C,D

3) Internet: MSIE 7.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.04506.30

I looked over some of the options to try but decided to show the test results to you first. I'm thinking there might be room for improvement in these areas but they have been the same since I purchased the computer about 3 years ago. Obviously something has changed.
Title: Re: I Have a virus
Post by: evilfantasy on April 12, 2008, 05:39:10 PM
Adding new programs/software. Some windows updates can take up alot of space and add to system resources. Hardware isn't my strong suit but more RAM wouldn't hurt. 1gig is usually the recommended amount and does seem to be the "sweet spot" for XP as well as Vista.

I'm not sure what to think about 2) and 3).
Title: Re: I Have a virus
Post by: The Bubba on April 12, 2008, 11:38:45 PM
I thought about the ram myself and will get some soon and plug it in. I went ahead and did some of the cleanup part of Pitstop but haven't noticed any change. I drop a line after I get some more ram.
Title: Re: I Have a virus
Post by: The Bubba on April 16, 2008, 11:46:19 PM
Should get the ram tomorrow but in the meantime I have developed another problem. When I login to my site, it shows my name but still shows the word login (should show admin). I also can't post a message either. I also can't on the support forum that runs my site (message board). I went back a bit with system restore, back to where I reported I was clean. Still no luck. I ran Kaspersky again just to be safe and am still showing clean. At work I can login to my site an everything is fine. Any ideas?
Title: Re: I Have a virus
Post by: evilfantasy on April 18, 2008, 12:51:34 PM
Hello, sorry it has taken so long for me to get back to this.

I really don't know what might be going on.
Title: Re: I Have a virus
Post by: The Bubba on April 18, 2008, 02:01:21 PM
Well I got the ram installed, even did a reinstall of IE7 but the problem I mentioned still persists still persists. You would think Kaspersky would catch something with it's scan if there was anything and it didn't. This is darn aggravating and everything would be OK if I could get my website to allow a proper login. I would think it would have to be some kind of registry change, that's why I did a system restore. I do have another question though, I've reinstalled IE7 twice now, the first time it asked to insert my XP disc but this last time it didn't? Should I be asking these questions in another forum, it would appear that this is not virus/spyware related?
Title: Re: I Have a virus
Post by: evilfantasy on April 18, 2008, 02:07:43 PM
You may get a better response in another forum. (not many are willing to read the 6 pages we have here)

I am stumped. It could be something simple and then again it could be a reinstall that is needed.
Title: Re: I Have a virus
Post by: The Bubba on April 18, 2008, 03:09:59 PM
As far as a reinstall, are you referring to IE7? As far as reading the 6 pages we've created, the amount of views shown seem to indicate that there were several that were interested. You have a great deal of knowledge that you are willing to give for free in order to aid in solving certain computer problems and I hope that I haven't offended you by stating that I might need to ask certain questions in another forum. I more than appreciate your time and interest in helping me.
Title: Re: I Have a virus
Post by: evilfantasy on April 18, 2008, 03:15:14 PM
No offense taken at all :) . I am always open to "knowledgeable" input from others.

By a reinstall I meant Windows. I don't think that is the case and I normally never recommend it as I would rather see the problem fixed. I just don't know where to look for the fix. We have tried everything that normally works and it seems to have the opposite results. A new thread will be more likely to get new views on what to try.
Title: Re: I Have a virus
Post by: The Bubba on April 18, 2008, 03:19:16 PM
I was thinking the same thing but will exhaust all means possible before doing that because it's such a pain. Thanks again for your time in getting my computer cleaned up.