Computer Hope

Software => Computer viruses and spyware => Topic started by: Andrea0769 on March 10, 2008, 10:55:15 PM

Title: Virus from Hades Please please help :-(
Post by: Andrea0769 on March 10, 2008, 10:55:15 PM
First let me just start by saying thank you!! Thank you for all you do to help fellow computer users in our darkest hour of need!!! :-)

I read and followed all evilfantsy's wonderfully long and thorough list of must do firsts... It seems to have made a difference at first, but this stupid virus just keeps coming back. :-( It has taken over my wallpaper with a red screen with a warning that my privacy is in danger and keeps trying to get me to download more wonderful things to protect my computer, it also seems to be engaging and turning off my wireless adapter. Sigh.. I have spent about 14 hours working on this so far, will attach logs as instructed. I have also run Zone alarm, and a new version of CA security suite to no avail.

Any assistance you can provide will be very much appreciated. I would really like to avoid formatting my hard drive if at all possible.

Thanks again for your time and efforts!!!

Logs to follow:


[recovering space - attachment deleted by admin]
Title: Re: Virus from Hades Please please help :-(
Post by: Spoiler on March 11, 2008, 08:05:25 AM
I hate to say this but I would reload the machine at this point. You say you spent 14 hours on this. You could have rebuilt the whole machine many times over by now.

I am sure someone here can help you but I would copy my data off the machine and than wipe it clean.

Thats just me. Again I am sure someone here can help you.
Title: Re: Virus from Hades Please please help :-(
Post by: neljan on March 11, 2008, 08:32:23 AM
I hate to say this but I would reload the machine at this point. You say you spent 14 hours on this. You could have rebuilt the whole machine many times over by now.

I am sure someone here can help you but I would copy my data off the machine and than wipe it clean.

Thats just me. Again I am sure someone here can help you.

Yes, I'm sure they will.

The reason you haven't had a response from one of the malware specialists thus far Andrea is probably due to time difference, please give it a little longer before you consider resorting to a total reinstallation.

I can see some problems, but it's best to wait for one of the specialists who will be along shortly...
Title: Re: Virus from Hades Please please help :-(
Post by: evilfantasy on March 11, 2008, 08:34:33 AM
Thanks Spoiler, that was very helpful information.

Thanks neljan, time difference can make things harder but we will get it worked out with a little patience.

Hi Andrea0769 welcome to Computer Hope.

Open Hijackthis and select Do a system scan only then place a check mark next to:

R3 - URLSearchHook: OLE (Part 1 of 5) - - (no file)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZUxdm265YYUS
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei/MyFunCardsFWBInitialS etup1.0.0.15.cab
O21 - SSODL: btrklfr - {0F87A531-94E0-4851-9656-FFDBEB6AE948} - (no file)
O21 - SSODL: apdqnxp - {E174E9BB-D286-43E7-BB51-4EB67EC9603F} - C:\WINDOWS\apdqnxp.dll

Now close all windows except for Hijackthis and click Fix checked.

----------

PLEASE READ ALL OF THESE INSTRUCTIONS FIRST BEFORE DOING ANYTHING. Ask any questions that you may have before starting.

Download  SmitfraudFix (by S!Ri) (http://siri.urz.free.fr/Fix/SmitfraudFix.zip) to your Desktop.
Extract all the files to your Destop.
A folder named SmitfraudFix will be created on your Desktop.

You may want print out these instructions or copy and paste them to notepad and save it to the desktop as you will not be able to see this page in safe modeA reboot may be needed to finish the cleaning process. The report can be found at the root of the system drive, usually at C:\rapport.txt

Suggested Step:
.
----------

Next post please add
Smitfraudfix log
Also a NEW Hijackthis log





Title: Re: Virus from Hades Please please help :-(
Post by: Andrea0769 on March 11, 2008, 02:18:10 PM
Sigh... Thanks I feel like there is light at the end of the tunnel :-)

I followed your latest instructions and upon reboot I could not get Internet Explorer.. grrrr. Soooooo I downloaded it from another computer and reinstalled it, so far so good on that one.

Here are the new logs...

[recovering space - attachment deleted by admin]
Title: Re: Virus from Hades Please please help :-(
Post by: evilfantasy on March 11, 2008, 05:17:31 PM
Looking better but still work to do.

You have Viewpoint installed.

Viewpoint Media Player/Manager/Toolbar is considered as foistware instead of malware since it is installed without users approval but doesn't spy or do anything "bad". See Viewpoint to Plunge Into Adware (http://www.clickz.com/showPage.html?page=3561546)

It is suggested to remove the program now.
Go to Start > Settings > Control Panel > Add/Remove Programs and remove the following programs if present.If you have trouble removing Viewpoint, I suggest that you use ViewpointKiller (http://"http://bellsouthpwp.net/p/r/prprogramsstudios/viewpointkiller.zip")

Once you have downloaded ViewpointKiller, unzip it to a convenient location such as your desktop.
Run ViewpointKiller, and select File > Do All Killings
Follow the prompts, selecting Yes or No, depending on which selection you are most comfortable with.

----------

Open Hijackthis and select Do a system scan only.

Place a check mark next to the following entries: (if there)

O24 - Desktop Component 0: Privacy Protection - file:///C:\WINDOWS\privacy_danger\index.htm
O24 - Desktop Component 1: (no name) - http://privacy.securepccleaner.com/MTY4ODE=/2/5993/ed=2/desctop/


Important: Close all windows except for Hijackthis and then click Fix checked.

Exit Hijackthis.

----------

Run CCleaner

----------

Do you know what this is? O23 - Service: RasMan - Unknown owner - c:\clXb.exe

----------

Scan Suspicious File(s)

Please visit one of the following:
(Multiple sites are given in case one is not working)
(If more than one file needs scanned they must be done separately and logs posted for each one)
Copy the file path in the code box below.
Code: [Select]
C:\WINDOWS\system32\mdmcls32.exe.
If you don't know what c:\clXb.exe is then run it through the file scanner also.

----------

Next post
Suspicious file scan results
NEW Hijackthis log

Title: Can't tell if its getting better or worse :-(
Post by: Andrea0769 on March 11, 2008, 09:58:33 PM
Ok... I will attach both logs.. I have had to reinstall IE again and am fighting for control of my wireless adapter :-(




[recovering space - attachment deleted by admin]
Title: Re: Virus from Hades Please please help :-(
Post by: orlandgalistejr on March 11, 2008, 10:44:37 PM
i dont think so but i want also to resolve how do viruses get lost.
Title: Re: Virus from Hades Please please help :-(
Post by: evilfantasy on March 12, 2008, 08:41:17 AM
orlandgalistejr you will need to start a new thread please.

----------

Have Hijackthis fix this entry R3 - URLSearchHook: OLE (Part 1 of 5) - - (no file)

How is the computer now?
Title: Re: Virus from Hades Please please help :-(
Post by: Andrea0769 on March 12, 2008, 09:39:36 AM
I will run hijack this again and let you know. It is better, but everytime I reboot I have to reinstall IE AND reset my wireless adapter.  :-(

Also, When IE does finally come up it seems set on go.microsoft.com/FWlink/?LinkId=74005 even though I have yahoo.com listed as my chosen home page....
Title: Re: Virus from Hades Please please help :-(
Post by: Andrea0769 on March 12, 2008, 09:42:04 AM
On a side note, I have to reinstall IE because it just wont connect. I am definitely connected as I Can get and send email, and when I run IE diagnostic it says it cant find anything wrong... but it still cannot find the server.... Most frustrating >:(
Title: Re: Virus from Hades Please please help :-(
Post by: evilfantasy on March 13, 2008, 08:06:34 PM
Sorry it has taken me a while to respond, been busy.............

Try Dial a fix

Please download Dial-a-Fix (http://wiki.djlizard.net/Dial-a-fix#Mirrors.2Fdownload_locations.2C_and_articles) by djlizard, save it to the desktop then extract it to it's own folder.Let me know if IE behaves properly.

If that doesn't work try this method.

Open Dial-a-fix and click the hammer icon. Select Flush DNS and click Go
When complete, select Repair Permissions and click Go
When complete, select Repair/reinstall IE and click Go

If at any time you are prompted for the XP cd, insert it
Make note of any error messages and post them here
Reboot when complete and let me know if there's any change