Computer Hope

Software => Computer viruses and spyware => Topic started by: blu_smiley on December 28, 2007, 08:26:57 PM

Title: help with a virus
Post by: blu_smiley on December 28, 2007, 08:26:57 PM
my virus scanner(nod 32) keep detecting these viruses every so often but its not going away..
it affects my internet i.e...i can go on the internet for like 30 mins but then it suddenly stops working....
th only way to get the internet working is to restart...
when the internet stops working, it also affects the other computers in the house....
i know it has nothing to do with my internet connection and isp because it only happens to my computer (thats affected with the virus) because i can go on the internet all day on the other computers.
Also sometimes my applications dont close properly when i shut down....and when i shut down i get this thing saying "run time error 53-file not found ".
i think thats about it...sorry if i sound confusing
 
Ive attached the 1)SUPERantispyware log
                            2) eset online scanner log
                            3) hijackthis log

I'd appreciate anyone that can help me!
thanks in advance

[saving space - attachment deleted by admin]
Title: Re: help with a virus
Post by: Broni on December 28, 2007, 09:59:04 PM
I can't see any firewall running, unless you have Windows firewall up???

1. Print this post out, since you won't have an access to it, at some point.

2. Close all windows, except for HijackThis.

3. Put a checkmark next to the following HijackThis entries:

- R3 - URLSearchHook: (no name) - {B3FD786C-9985-B876-F5DC-96CB2B9E59E6} - C:\WINDOWS\system32\ukqg.dll (file missing)

- F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Config\lsass.exe

- F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,xpjava.exe

- O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

- O4 - HKLM\..\Run: [Microsoft Config 32] msconfigx32.exe

- O4 - HKLM\..\Run: [DRam prosessor] winupdate.exe

- O4 - HKLM\..\Run: [system] tskmgr.exe

- O4 - HKLM\..\Run: [MSUpdater] System32i.exe

- O4 - HKLM\..\RunServices: [Microsoft Config 32] msconfigx32.exe

- O4 - HKLM\..\RunServices: [system] tskmgr.exe

- O4 - HKLM\..\RunServices: [MSUpdater] System32i.exe

- O4 - HKCU\..\Run: [Microsoft Config 32] msconfigx32.exe

- O4 - HKCU\..\Policies\Explorer\Run: [digoun] C:\WINDOWS\System32\digoun.exe

- O4 - HKCU\..\Policies\Explorer\Run: [kbdsld] C:\WINDOWS\System32\kbdsld.exe

- O4 - HKCU\..\Policies\Explorer\Run: [regign] C:\WINDOWS\System32\regign.exe

- O4 - HKCU\..\Policies\Explorer\Run: [commv2] C:\WINDOWS\System32\commv2.exe

- O4 - HKCU\..\Policies\Explorer\Run: [mshuie] C:\WINDOWS\System32\mshuie.exe

- O4 - HKUS\S-1-5-18\..\Run: [Microsoft Config 32] msconfigx32.exe (User 'SYSTEM')

- O20 - Winlogon Notify: wintuh32 - wintuh32.dll (file missing)

- O23 - Service: winauthm (spdauth) - Unknown owner - C:\WINDOWS\spdauth.exe (file missing)

- O23 - Service: tsecure - Unknown owner - C:\WINDOWS\tsecure.exe (file missing)

4. Click on "Fix checked" button.

5. Restart your computer in Safe Mode (keep tapping F8 key, when your computer starts)

6. Open Windows Explorer. Go Tools>Folder Options>View tab, put a checkmark next to "Show hidden files, and folders".

7. Delete following files/folders (if present):

- from C:\WINDOWS\system32, files: digoun.exe, kbdsld.exe, regign.exe, commv2.exe, mshuie.exe

8. Turn off System Restore:

- Windows XP:
   1. Click Start.
   2. Right-click the My Computer icon, and then click Properties.
   3. Click the System Restore tab.
   4. Check "Turn off System Restore".
   5. Click Apply.   
   6.  When turning off System Restore, the existing restore points will be deleted. Click Yes to do this.
   7. Click OK.
- Windows Vista:
   1. Click Start.
   2. Right-click the Computer icon, and then click Properties.
   3. Click on System Protection under the Tasks column on the left side
   4. Click on Continue on the "User Account Control" window that pops up
   5. Under the System Protection tab, find Available Disks
   6. Uncheck the box for any drive you wish to disable system restore on (in most cases, drive "C:")
   7. When turning off System Restore, the existing restore points will be deleted. Click "Turn System Restore Off" on the popup window to do this.
   8. Click OK

9. Restart in Normal Mode.

10. Turn System Restore on.

11. Run HijackThis again, and post back its log back here.
Title: Re: help with a virus
Post by: blu_smiley on December 29, 2007, 04:33:26 PM
^ thanks for helping =D

but where am i suppose to begin step 3??.....ive opened hjt but i dont know what to do next as you described in step 3)
Title: Re: help with a virus
Post by: Broni on December 29, 2007, 05:47:20 PM
Oh, click on Scan.
Title: Re: help with a virus
Post by: blu_smiley on December 30, 2007, 12:42:45 AM
im on internet explorer (ver7) but i cant find "folder options" under tools
Title: Re: help with a virus
Post by: Deerpark on December 30, 2007, 07:17:02 AM
It's not Internet Explorer blu_smiley, it's Windows Explorer. This is the name of the program that lets you browser you folders and such.
Just double click "My Computer" and you'll launch it. :)
Title: Re: help with a virus
Post by: blu_smiley on December 30, 2007, 03:40:12 PM
Deerpark: thanks for that!!
------------------------

hjt log attached

[saving space - attachment deleted by admin]
Title: Re: help with a virus
Post by: evilfantasy on December 30, 2007, 06:19:03 PM
Please download Combofix by sUBs from either  here (http://download.bleepingcomputer.com/sUBs/Beta/ComboFix.exe) or  here (http://subs.geekstogo.com/ComboFix.exe)

Save Combofix.exe to your your Desktop.

Double click combofix.exe & follow the prompts. (from the keyboard select 1 and press enter)
When finished, it will produce a log for you.
Attach that log in your next reply.

Do not mouseclick combofix's window while it's running. That may cause your computer to stall
Title: Re: help with a virus
Post by: blu_smiley on December 30, 2007, 08:25:44 PM
combofix log attached

[saving space - attachment deleted by admin]
Title: Re: help with a virus
Post by: evilfantasy on December 30, 2007, 08:41:41 PM
Delete these files/folders, as follows:

* Open notepad and copy/paste the text in the quote box below into it (all except the word QUOTE):

Quote
File::
C:\WINDOWS\imsins.BAK
C:\WINDOWS\system32\temp.dat
C:\WINDOWS\system32\System32i.exe

Registry::
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ceb43567-9b98-11db-a316-000f3d300101}]
\Shell\AutoRun\command - ~tmp0.1st.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ceb43568-9b98-11db-a316-000f3d300101}]
\Shell\AutoRun\command - ~tmp0.1st.exe

* Save this as CFScript on the desktop.
* Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully!

(http://i154.photobucket.com/albums/s258/evilfantasy69/CFScript.gif)

* ComboFix will begin to execute, just follow the prompts. After reboot (in case it asks to reboot), it shall produce a log for you. Post that log (Combofix.txt) in your next reply.

Note: Do not mouseclick combofix's window while it is running. That may cause your system to hang

==========

Please run the  F-Secure Online Scanner (http://www.247fixes.com/forums/ipb_seo.php?url=http%3A%2F%2Fsupport.f-secure.com%2Fenu%2Fhome%2Fols.shtml)

Note: This Scanner works with Internet Explorer Only!
Cancel, then New Scan[/list]
[/list]

==========

Next post please attach
combofix log
f-secure online scan log
Title: Re: help with a virus
Post by: blu_smiley on December 31, 2007, 03:10:28 AM
combofix & fsecure logs attached

[saving space - attachment deleted by admin]
Title: Re: help with a virus
Post by: evilfantasy on December 31, 2007, 11:15:21 AM
Looking better. Still more to do though.


Please download ATF Cleaner by Atribune.  ATF Cleaner.exe (http://www.atribune.org/ccount/click.php?id=1)

Make sure that all browser windows are closed.
If you use Firefox browser
If you use Opera browser
Click Exit on the Main ATF Cleaner menu to close the program.

Restart the computer.

----------

Please download  DrWeb CureIt (http://fileforum.betanews.com/download/DrWeb_CureIt/1169129698/1) & save it to your desktop.

Scan with DrWeb-CureIt as follows:
----------

Run a new hijackthis scan and post that log along with the DR.Web log please.
Title: Re: help with a virus
Post by: blu_smiley on December 31, 2007, 04:51:08 PM
the linke you gave me to dl DrWeb-CureIt .exe doesnt work
Title: Re: help with a virus
Post by: evilfantasy on December 31, 2007, 05:07:18 PM
Sorry about that, it is fixed now.
Title: Re: help with a virus
Post by: blu_smiley on December 31, 2007, 06:18:03 PM
I downloaded drweb cure it but the express scan doesn't finish scanning

This happens:
(http://img341.imageshack.us/img341/7707/fvcvwn0.jpg)

and then this shows up:
(http://img247.imageshack.us/img247/989/fdeq7.jpg)
Title: Re: help with a virus
Post by: evilfantasy on December 31, 2007, 06:31:05 PM
OK, you can uninstall that. We will use AVG Antispyware instead. Sorry for that, I have not had any problems with it before....



Download and install   AVG Anti-Spyware Free (http://free.grisoft.com/doc/download-free-anti-spyware/us/frt/0) to your desktop.

    * Once you have downloaded AVG Anti-Spyware Free , locate the icon on the desktop and double-click it to launch the set up program.
    * Once the setup is complete you will need run AVG and update the definition files
    * On the main screen select the icon Update then select the Update now link.
    * Next select the Start Update button, the update will start and a progress bar will show the updates being installed.
    * Once the update has completed select the Scanner icon at the top of the screen, then select the Settings tab.
    * Once in the Settings screen click on Recommended actions and then select Quarantine <-- Dont forget this
    * Under Reports
    * Select Automatically generate report after every scan
    * Un-Select Only if threats were found
    * Under "What to scan"? "Select Scan every file".
   
    * Select the Scanner icon at the top and then the Scan tab then click on Complete System Scan
    * AVG will now begin the scanning process, be patient this may take a little time.
    * Once the scan is complete do the following:
    * If you have any infections you will prompted, then select Apply all actions <--be sure qaurantine is selected
    * Next select the Reports icon at the top.
    * Select the Save report as button in the lower left hand of the screen and save it to a text file on your system
    * Make sure to remember where you saved that file, this is important (usually the desktop)
    * Close AVG Anti-Spyware Free

    * Attach the AVG scan report in the next post.
Title: Re: help with a virus
Post by: blu_smiley on December 31, 2007, 07:06:49 PM
I have SUPER antispyware from  before. Do I need to uninstall that before I  install AVG antispyware?
Title: Re: help with a virus
Post by: evilfantasy on December 31, 2007, 07:53:28 PM
No it will not hurt to have both installed, they only run when you launch them so it is safe.
Title: Re: help with a virus
Post by: blu_smiley on January 01, 2008, 02:03:35 AM
AGV log attached

-----------

do i still need to post the hjt log?


[file cleanup - saving space - attachment deleted by admin]
Title: Re: help with a virus
Post by: evilfantasy on January 01, 2008, 02:10:23 AM
Yes, I will need to see a new HijackThis log.

The hjiackthis logs are how we can tell if the removal tools are working and if more work needs to be done.
Title: Re: help with a virus
Post by: blu_smiley on January 01, 2008, 05:06:02 AM
hijack this log attached

[file cleanup - saving space - attachment deleted by admin]
Title: Re: help with a virus
Post by: evilfantasy on January 01, 2008, 09:22:46 AM
Delete the copy of Combofix from the desktop and download a new one.

Download Combofix by sUBs from either  here (http://download.bleepingcomputer.com/sUBs/Beta/ComboFix.exe) or  here (http://subs.geekstogo.com/ComboFix.exe)

Save Combofix.exe to your your Desktop.

Double click combofix.exe & follow the prompts. (from the keyboard select 1 and press enter)
When finished, it will produce a log for you.
Attach that log in your next reply.

Do not mouseclick combofix's window while it's running. That may cause your computer to stall

Also post a fresh hijackthis log after combofix has completed.
Title: Re: help with a virus
Post by: blu_smiley on January 01, 2008, 05:37:42 PM
combo fix & hjt log attached

[file cleanup - saving space - attachment deleted by admin]
Title: Re: help with a virus
Post by: evilfantasy on January 01, 2008, 06:06:26 PM
Quote
Hardware Clock Driver (hwclock)
Quote
winauthm (spdauth)

---------------

Please download OTMoveIt2 by OldTimer  OTMoveIt2.exe (http://download.bleepingcomputer.com/oldtimer/OTMoveIt2.exe) and save it to your desktop.

Don't use it yet

---------------

Open HijackThis and select Do a system scan only then place a check mark next to:

O4 - HKUS\S-1-5-18\..\Run: [kimochiz.exe] C:\WINDOWS\temp\kimochiz.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [kimochiz.exe] C:\WINDOWS\temp\kimochiz.exe (User 'Default user')
O23 - Service: Hardware Clock Driver (hwclock) - Unknown owner - C:\WINDOWS\System32\hwclock.exe (file missing)
O23 - Service: winauthm (spdauth) - Unknown owner - C:\WINDOWS\spdauth.exe (file missing)


Close all windows except for HijackThis and click Fix checked

---------------

Double click OTMoveIt.exe to launch it.

Be sure there is a check mark next to Unregister Dll's and OCX's

Quote
C:\WINDOWS\temp\kimochiz.exe
C:\WINDOWS\System32\hwclock.exe
C:\WINDOWS\spdauth.exe

Title: Re: help with a virus
Post by: blu_smiley on January 01, 2008, 07:02:54 PM
I did the system scan only but when it finished i couldnt find:
O23 - Service: Hardware Clock Driver (hwclock) - Unknown owner - C:\WINDOWS\System32\hwclock.exe (file missing)
O23 - Service: winauthm (spdauth) - Unknown owner - C:\WINDOWS\spdauth.exe (file missing)
Title: Re: help with a virus
Post by: evilfantasy on January 01, 2008, 07:10:59 PM
We stopped them from running in services so they probably just didn't get picked up by the HJT scan.

Do the next step with OTMoveIt and we will see if they are removed by it.
Title: Re: help with a virus
Post by: blu_smiley on January 01, 2008, 07:13:05 PM
ok ^^

oh oh one thing...should i fix:
O4 - HKUS\S-1-5-18\..\Run: [kimochiz.exe] C:\WINDOWS\temp\kimochiz.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [kimochiz.exe] C:\WINDOWS\temp\kimochiz.exe (User 'Default user')
Title: Re: help with a virus
Post by: evilfantasy on January 01, 2008, 07:16:06 PM
ok ^^

oh oh one thing...should i fix:
O4 - HKUS\S-1-5-18\..\Run: [kimochiz.exe] C:\WINDOWS\temp\kimochiz.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [kimochiz.exe] C:\WINDOWS\temp\kimochiz.exe (User 'Default user')

Yes fix them in hijackthis and then continue with OTMoveIt.
Title: Re: help with a virus
Post by: blu_smiley on January 01, 2008, 07:19:55 PM
OTmoveIt:

File/Folder C:\WINDOWS\temp\kimochiz.exe not found.
File/Folder C:\WINDOWS\System32\hwclock.exe not found.
File/Folder C:\WINDOWS\spdauth.exe not found.
 
Created on 01022008_151824

---------------
hjt log attached

[file cleanup - saving space - attachment deleted by admin]
Title: Re: help with a virus
Post by: evilfantasy on January 01, 2008, 08:06:11 PM
Well that revealed a few more bad guys.


Run Combofix again and post the log.



Also run SDFix and post its log.

Download SDFix.exe (http://downloads.andymanchesta.com/RemovalTools/SDFix.exe) and save it to your Desktop.

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)

Please then reboot your computer in Safe Mode by doing the following:
* Restart your computer
* After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
* Instead of Windows loading as normal, the Advanced Options Menu should appear;
* Select the first option, to run Windows in Safe Mode, then press Enter.
* Choose your usual account.
* Open the extracted SDFix folder and double click RunThis.bat to start the script.
* Type Y to begin the cleanup process.
* It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
* Press any Key and it will restart the PC.
* When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
*] Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
(Report.txt will also be copied to Clipboard).
* Finally add the contents of the Report.txt in your next post as an Attachment with a new HijackThis log
Title: Re: help with a virus
Post by: blu_smiley on January 01, 2008, 09:20:31 PM
when i press F8 the 'advance options' menu doesnt appear..
instead it's  'boot device' and asks me to select a drive O__O
Title: Re: help with a virus
Post by: evilfantasy on January 01, 2008, 09:43:31 PM
OK, just do the combofix log.
Title: Re: help with a virus
Post by: blu_smiley on January 01, 2008, 11:17:56 PM
combofix log attached

[file cleanup - saving space - attachment deleted by admin]
Title: Re: help with a virus
Post by: evilfantasy on January 01, 2008, 11:33:19 PM
Now download  The Avenger By Swandog46 (http://swandog46.geekstogo.com/avenger.zip), and save it to your Desktop.

Quote
Files to delete:
C:\WINDOWS\temp\kimochiz.exe
C:\WINDOWS\System32\hwclock.exe
C:\WINDOWS\spdauth.exe

Note: the above quote was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system

The Avenger will automatically do the following:

Title: Re: help with a virus
Post by: blu_smiley on January 02, 2008, 04:26:00 PM
avenger, bdscan and hjt logs attached

[file cleanup - saving space - attachment deleted by admin]
Title: Re: help with a virus
Post by: evilfantasy on January 02, 2008, 05:30:33 PM
We need to do some work in the registry to get rid of the TELLCOMA.EXE.

Backup the registry

1. Click Start, click Run, type (or copy and then paste) %SystemRoot%\system32\restore\rstrui.exe, and then click OK.
2. On the Welcome to System Restore page, click Create a restore point, and then click Next .
3. On the Create a Restore Point page, type a name for the restore point and then click Create
4. After the restore point has been created, click Close.
* Remember or write down the name you give the restore point.

Kill the tellcoma process
Open Windows Task Manager by pressing CTRL+ALT+DELETE all at the same time and choose the processes tab.

In the list of running programs locate the process:
TELLCOMA.EXE and right click it then choose End task

Close Task Manager.

Remove tellcoma from the registry

1. Open Registry Editor. Click Start>Run, type REGEDIT, then press Enter.

2. In the left panel, double-click the following:
HKEY_LOCAL_MACHINE>SOFTWARE>Microsoft>
Windows>CurrentVersion>Run

3. In the right panel, locate and delete the entry:
Microsoft Telecoma Center = "tellcoma.exe"

4. In the left panel, double-click the following:
HKEY_LOCAL_MACHINE>SOFTWARE>Microsoft>
Windows>CurrentVersion>RunServices

5. In the right panel, locate and delete the entry:
Microsoft Telecoma Center = "tellcoma.exe"

6. In the left panel, double-click the following:
HKEY_CURRENT_USER>Software>Microsoft>
Windows>CurrentVersion>Run

7. In the right panel, locate and delete the entry:
Microsoft Telecoma Center = "tellcoma.exe"

8. Leave Registry Editor open.

Restoring EnableDCOM and RestrictAnonymous Registry Entries


1. In the left panel, double-click the following:
HKEY_LOCAL_MACHINE>SOFTWARE>Microsoft>Ole

2. In the right panel, locate the entry:
EnableDCOM = "N"

3. Right-click on this registry entry and choose Modify. Change the value of this entry to:
EnableDCOM = "Y"

4. Close Registry Editor.

Toggle System Restore to clear infected restore points

1. Turn off System Restore
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply, and then click OK.

2. Restart your computer

3. Turn ON System Restore
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
UN-Check Turn off System Restore.
Click Apply, and then click OK.

Run Housecall

Use the  Trend Micro Housecall Scan (http://housecall.trendmicro.com/us/index.html)

Title: Re: help with a virus
Post by: blu_smiley on January 02, 2008, 07:52:58 PM
I cant find TELLCOMA.EXE in task manager
Title: Re: help with a virus
Post by: evilfantasy on January 02, 2008, 08:07:44 PM
Open the registry and see if you can find the entries in there and follow those instructions.

Title: Re: help with a virus
Post by: blu_smiley on January 02, 2008, 08:14:02 PM
went to the registry but couldnt find the entries
Title: Re: help with a virus
Post by: evilfantasy on January 02, 2008, 08:22:15 PM
Post a fresh hijackthis log please.
Title: Re: help with a virus
Post by: blu_smiley on January 02, 2008, 08:26:11 PM
hjt log attached

[file cleanup - saving space - attachment deleted by admin]
Title: Re: help with a virus
Post by: evilfantasy on January 02, 2008, 08:33:12 PM
Post a fresh hijackthis log please.

Scan saved at 4:25:02 p.m., on 3/01/2008

I need a NEW hijackthis log.
Title: Re: help with a virus
Post by: blu_smiley on January 02, 2008, 08:40:36 PM
^ But that is a new one..
i scanned it only like 15 minutes ago
Title: Re: help with a virus
Post by: evilfantasy on January 02, 2008, 08:49:46 PM
Download  Deckard's System Scanner (DSS) (http://www.geekstogo.com/forum/index.php?automodule=downloads&req=download&code=confirm_download&id=19) to your Desktop. Note: You must be logged onto an account with administrator privileges.

What DSS will do:

Title: Re: help with a virus
Post by: blu_smiley on January 02, 2008, 09:01:02 PM
main and extra txt attached

[file cleanup - saving space - attachment deleted by admin]
Title: Re: help with a virus
Post by: evilfantasy on January 02, 2008, 11:16:38 PM
Open HijackThis and select Do a system scan only then place a check mark next to:

O4 - HKUS\S-1-5-18\..\Run: [Microsoft Telecoma Center] tellcoma.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Microsoft Telecoma Center] tellcoma.exe (User 'Default user')


Close all windows except for HijackThis and click Fix checked

Exit Hijackthis.

----------

1) Please download  Pocket Killbox (http://www.killbox.net/)


2) Please run Killbox.

3) Select "Delete on Reboot"

4) Open the text file with these instructions in it, and copy the file name in the quote box below to the clipboard by highlighting them and pressing Control-C:

Quote
C:\WINDOWS\System32\tellcoma.exe

5) Return to Killbox, go to the File menu, and choose "Paste from Clipboard"

6) Click the red-and-white "Delete File" button. Click "Yes" at the Delete on Reboot prompt Click "No" at the Pending Operations prompt

(http://i154.photobucket.com/albums/s258/evilfantasy69/killbox.jpg)

If you receive a message such as: "Component 'MsComCtl.ocx' or one of its dependencies not correctly registered: a file is missing or invalid." when trying to run Killbox, click  HERE (http://www.eudaemonia.me.uk/downloads/Files/missingfilesetup.exe) to download and run missingfilesetup.exe Then try Killbox again..

Let the system reboot.

Post a new HijackThis log.
Title: Re: help with a virus
Post by: blu_smiley on January 02, 2008, 11:57:37 PM
when i clicked "delete file" i got "pending file name operations registry data has been removed by external process"

and then it doesnt reboot by itself
Title: Re: help with a virus
Post by: evilfantasy on January 03, 2008, 12:26:31 AM
Reboot the computer.

After rebooting, open up Killbox again, click File -> Logs -> Actions History Log

Copy and paste the contents of kb.log and post it in your next reply.


If that doesn't work go to Start > Run and type: (or copy and paste)

notepad systemdrive%\!Killbox\Logs\kb.log

Copy and paste the contents of kb.log and post it in your next reply.


Also run a new hijackthis scan and post the log.
Title: Re: help with a virus
Post by: blu_smiley on January 03, 2008, 12:49:56 AM
kill box & hjt logs attached

[file cleanup - saving space - attachment deleted by admin]
Title: Re: help with a virus
Post by: evilfantasy on January 03, 2008, 01:22:36 AM
This is definitely a nasty one. They are renamed to something else now.

Open HijackThis and select Do a system scan only then place a check mark next to:

O4 - HKUS\S-1-5-18\..\Run: [Microsoft Config 32] msconfigx32.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Microsoft Config 32] msconfigx32.exe (User 'Default user')


Close all windows except for HijackThis and click Fix checked

Exit Hijackthis.



Open Killbox.

Click the button that says All Files

Copy the files in the quote box below.

Quote
C:\WINDOWS\System32\tellcoma.exe
C:\WINDOWS\System32\msconfigx32.exe

In Killbox click File > Paste from clipboard

Check the box to Replace On Reboot, then check the box under it Use Dummy.

Then click the red X and allow reboot.

Post the Killbox log i the next post along with a new hijackthis log please.


Title: Re: help with a virus
Post by: blu_smiley on January 03, 2008, 02:16:38 AM
i cant seem to get the new kb log?....i got to kb..click files...click logs then i click actions history log but it comes up with the previous kb log..
am i doing something wrong?
Title: Re: help with a virus
Post by: evilfantasy on January 03, 2008, 02:24:16 AM
Did it seem like it worked this time?

Title: Re: help with a virus
Post by: blu_smiley on January 03, 2008, 02:35:07 AM
what do you mean?
Title: Re: help with a virus
Post by: evilfantasy on January 03, 2008, 02:36:13 AM
Did killbox work with no errors?

Post a new hijackthis log please.
Title: Re: help with a virus
Post by: blu_smiley on January 03, 2008, 02:40:18 AM
it came up with the same message as before

---------

hjt log attched

[file cleanup - saving space - attachment deleted by admin]
Title: Re: help with a virus
Post by: evilfantasy on January 03, 2008, 02:56:15 AM
I have asked on the errors and it seems this is not uncommon for killbox to report this.


The log is finally clean. How is the computer now?


Let's clear out the programs we've been using to clean up your computer, they are not suitable for
general malware removal and could cause damage if launched accidentally.

Please download OTMoveIt2 by OldTimer  OTMoveIt2.exe (http://download.bleepingcomputer.com/oldtimer/OTMoveIt2.exe) and place it on your desktop.

1. Double click OTMoveIt2.exe to launch it.
2. Click on the CleanUp! button.
3. OTMoveIt2 will download a list from the Internet, if your firewall or other defensive programs alerts you, allow it access.
4. Click YES at the next prompt (list downloaded, Do you want to begin cleanup process?)
4. When finished exit out of OTMoveIt2


Download and install CleanUp! (http://cleanup.stevengould.org/)

Open Cleanup! by double-clicking the icon on your desktop (or from the Start > All Programs menu).
Set the program up as follows:

Title: Re: help with a virus
Post by: blu_smiley on January 03, 2008, 03:25:25 AM
I think everything is ok now!
I'll let you know if any of the symptoms appear again!!
thanks so much for this!! Im sorry if i ve bee a pain ^^
thank you thank you!!

btw..how come i have a antivirus on my pc but it still doesnt help instead we have to go through all thses steps?
Title: Re: help with a virus
Post by: evilfantasy on January 03, 2008, 03:41:35 AM
Quote
thanks so much for this!! Im sorry if i ve bee a pain ^^

No problem, glad you stuck it out also.

Quote
how come i have a antivirus on my pc but it still doesnt help instead we have to go through all thses steps?

Not sure how it got there. All it takes is one click and all sorts of stuff can get in. Antivirus can't always stop some of the well written virus out there.

Quote
I'll let you know if any of the symptoms appear again!!

Absolutely, we will be here.

Quote
I think everything is ok now!

Good, I hope it stays that way.


To learn more about how to protect yourself while on the internet read this article by Tony Klien:  So how did I get infected in the first place? (http://www.castlecops.com/postlite7736-.html)


Safe surfing........(http://andymanchesta.com/ICONS/1%20(6).gif)