Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: serious virus  (Read 15150 times)

0 Members and 1 Guest are viewing this topic.

only_lonely

    Topic Starter


    Intermediate
    Re: serious virus
    « Reply #15 on: August 25, 2008, 12:00:53 AM »
    I'm not sure,maybe i could try to remove them.
    O4 - HKCU\..\Run: [\VIE11.exe] C:\Windows\System32\VIE11.exe
    O8 - Extra context menu item: Add to QQ Customized Panel - C:\Program Files\Tencent\QQ\AddPanel.htm

    evilfantasy

    • Malware Removal Specialist
    • Moderator


    • Genius
    • Calm like a bomb
    • Thanked: 493
    • Experience: Experienced
    • OS: Windows 11
    Re: serious virus
    « Reply #16 on: August 25, 2008, 12:02:33 AM »
    We can remove them if you don't know what they are. There are so many I would think it is a leftover from the virus.

    Let me work up a fix real quick while you are doing the other steps.

    only_lonely

      Topic Starter


      Intermediate
      Re: serious virus
      « Reply #17 on: August 25, 2008, 12:10:51 AM »
      i notice that the porn sign and ms antivirus icon always at my desktop.
      but i couldn't find the program at add/remove program
      and the html balck scrren window always pop up

      only_lonely

        Topic Starter


        Intermediate
        Re: serious virus
        « Reply #18 on: August 25, 2008, 12:15:26 AM »
        ok.after remove all VIE and QQ related key
        it seems ok after reboot.
        here is the updated:
        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 2:14:19 PM, on 25-Aug-08
        Platform: Windows XP SP2 (WinNT 5.01.2600)
        MSIE: Internet Explorer v7.00 (7.00.5730.0011)
        Boot mode: Normal

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\ibmpmsvc.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\Program Files\ESET\ESET Smart Security\ekrn.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\SolidDocuments\SolidConverterPDF\SCPDF\SolidPdfService.exe
        C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
        C:\WINDOWS\system32\nipalsm.exe
        C:\WINDOWS\Explorer.EXE
        C:\WINDOWS\system32\wscntfy.exe
        C:\WINDOWS\system32\igfxtray.exe
        C:\WINDOWS\system32\hkcmd.exe
        C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
        C:\Program Files\ESET\ESET Smart Security\egui.exe
        C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
        C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
        C:\Program Files\RK Launcher\RKLauncher.exe
        C:\WINDOWS\FlyakiteOSX\Software\Alt+Q Hotkey.exe
        C:\WINDOWS\system32\conime.exe
        C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
        C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcrobatInfo.exe
        C:\WINDOWS\system32\wuauclt.exe
        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

        O2 - BHO: IE7pro - {00011268-E188-40DF-A514-835FCD78B1BF} - C:\Program Files\IE7pro\IE7pro.dll
        O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
        O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
        O2 - BHO: Solid Converter PDF - {259F616C-A300-44F5-B04A-ED001A26C85C} - C:\Program Files\SolidDocuments\SolidConverterPDF\SCPDF\ExploreExtPDF.dll
        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
        O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
        O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
        O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
        O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
        O3 - Toolbar: Solid Converter PDF - {259F616C-A300-44F5-B04A-ED001A26C85C} - C:\Program Files\SolidDocuments\SolidConverterPDF\SCPDF\ExploreExtPDF.dll
        O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
        O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
        O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
        O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
        O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
        O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
        O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
        O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
        O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
        O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
        O4 - HKLM\..\Run: [System Files Updater] C:\WINDOWS\FlyakiteOSX\System Files Updater.exe /S
        O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
        O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
        O4 - HKCU\..\Run: [RK Launcher] C:\Program Files\RK Launcher\RKLauncher.exe
        O4 - HKCU\..\Run: [Alt+Q Hotkey Tool] C:\WINDOWS\FlyakiteOSX\Software\Alt+Q Hotkey.exe
        O4 - HKCU\..\Run: [MSCalsClocks] C:\Program Files\Microsoft Chinese Date & Time\ICalClk.exe
        O4 - Startup: eCentral.lnk = C:\Program Files\Eshasoft\Calendar and Day Planner (USA Edition)\eCentral.exe
        O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
        O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
        O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
        O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
        O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
        O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
        O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
        O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
        O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
        O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
        O9 - Extra button: IE7pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program Files\IE7pro\IE7pro.dll
        O9 - Extra 'Tools' menuitem: IE7pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program Files\IE7pro\IE7pro.dll
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
        O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
        O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
        O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O15 - Trusted Zone: http://www.sheepshow.com.tw
        O15 - ESC Trusted Zone: http://*.update.microsoft.com
        O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} (iNotes6 Class) - http://webmail.ges.com.sg/iNotes6W.cab
        O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
        O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1207181156285
        O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1207185880443
        O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl.sun.com/webapps/download/AutoDL?BundleId=19588
        O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
        O16 - DPF: {EE884C7D-21A0-49EA-B6F2-61ACF4E226F6} (Microsoft Office Live Workspace Upload Tool) - http://workspace.office.live.com/Misc/Microsoft.OfficeLive.Workspace.RichUpload.cab
        O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
        O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
        O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
        O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
        O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
        O23 - Service: ThinkPad PM Service (IBMPMSVC) - Lenovo - C:\WINDOWS\system32\ibmpmsvc.exe
        O23 - Service: nipxirmu - National Instruments Corporation - C:\WINDOWS\system32\nipalsm.exe
        O23 - Service: SolidPDFConverterReadSpool (ScReadSpool) - VoyagerSoft, LLC - C:\Program Files\SolidDocuments\SolidConverterPDF\SCPDF\SolidPdfService.exe
        O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
        O23 - Service: Windows_IE7.0 - Unknown owner - C:\WINDOWS\IE7.0.exe (file missing)

        --
        End of file - 9373 bytes

        evilfantasy

        • Malware Removal Specialist
        • Moderator


        • Genius
        • Calm like a bomb
        • Thanked: 493
        • Experience: Experienced
        • OS: Windows 11
        Re: serious virus
        « Reply #19 on: August 25, 2008, 12:29:35 AM »
        OK I found another one.

        Name IE7.0.exe http://isc.sans.org/diary.html?storyid=2537

        ----------

        Go to Start > Run, and copy/paste the following blue text into the Open box:

        sc stop Windows_IE7.0

        Now click OK then enter the next line:

        sc delete Windows_IE7.0

        Now click OK

        ----------

        Your Java is out of date.

        Older versions have vulnerabilities that malicious sites can use to infect your system.

        Download JavaRa and unzip it to your desktop.

        • Double-click on JavaRa.exe to start the program.
        • Click on Remove Older Versions to remove the older versions of Java installed on your computer.
        • Click Yes when prompted. When JavaRa is done, a notice will appear that a logfile has been produced. Click OK.
        • A logfile will pop up. You can close it, you won't need to post it.
        • Delete the JavaRa .zip .exe and .html files from the Desktop
        .
        Follow this link to download and install Java Runtime Environment (JRE) 6 Update 7

        ----------

        What problems still remain?


        only_lonely

          Topic Starter


          Intermediate
          Re: serious virus
          « Reply #20 on: August 25, 2008, 12:36:10 AM »
          ya,update the java.
          everthings is fine now.
          thank you so much.
          luckly i met you,else i will reinstall my OS.
          thanks a lots

          evilfantasy

          • Malware Removal Specialist
          • Moderator


          • Genius
          • Calm like a bomb
          • Thanked: 493
          • Experience: Experienced
          • OS: Windows 11
          Re: serious virus
          « Reply #21 on: August 25, 2008, 12:51:05 AM »
          Just a few more things.

          Download OTCleanIt.exe and save it to your Desktop.
          • Double-click OTCleanIt.exe.
          • Click the CleanUp! button.
          • Select Yes when the "Begin cleanup Process?" prompt appears.
          • If you are prompted to Reboot during the cleanup, select Yes.
          • The tool will delete itself once it finishes, if not delete it yourself.
          .
          ----------

          Set a New Restore Point to prevent possible reinfection from an old one
          Setting a new restore point AFTER cleaning your system will enable your computer to roll-back to a clean working state if needed.
          • Go to Start > Programs > Accessories > System Tools and click System Restore
          • Choose the radio button marked Create a Restore Point on the first screen then click Next Give the Restore Point a name then click Create.
          • The new restore point will be stamped with the current date and time. Keep a log of this so you can find it easily should you need to use System Restore.
          • Next go to Start > Run and type Cleanmgr
          • Click OK
          • Click the More Options Tab.
          • Click Clean Up in the System Restore section to remove all previous restore points except the newly created clean one.
          You can find instructions on how to enable and re-enable system restore here:

          Windows XP System Restore Guide or Windows Vista System Restore Guide
          .
          ----------

          Use the Secunia Software Inspector to check for out of date software.
          • Click Start Now
          • Check the box next to Enable thorough system inspection.
          • Click Start
          • Allow the scan to finish and scroll down to see if any updates are needed.
          • Update anything listed.
          .
          ----------

          Let us know if anything else comes up.

          only_lonely

            Topic Starter


            Intermediate
            Re: serious virus
            « Reply #22 on: August 25, 2008, 02:03:48 AM »
            alots of windows updates need to install,
            thanks.will update it soon

            only_lonely

              Topic Starter


              Intermediate
              Re: serious virus
              « Reply #23 on: August 26, 2008, 12:33:13 AM »
              scan using ESET today.found 13 threats..
              name MSA.exe,VIE.exe (Win32 Adware)
              suspect my pc is not full clean..
              what should i do?
              are them cause any serious problem?

              evilfantasy

              • Malware Removal Specialist
              • Moderator


              • Genius
              • Calm like a bomb
              • Thanked: 493
              • Experience: Experienced
              • OS: Windows 11
              Re: serious virus
              « Reply #24 on: August 26, 2008, 12:43:27 AM »
              Yes those are bad. MSA.exe is s worm.

              This scan will take a while but the log from it will be very important.

              Run the Kaspersky Online Scanner

              In Microsoft Windows Vista, you must open the Web browser using the Run as Administrator command. From the Desktop right click the icon to open the browser and choose Run as Administrator.

              • Click on SCAN NOW
              • Click Accept.
              • The program will then begin downloading the latest definition files.
              • Once the files have been downloaded locate the Scan Settings and have it scan My Computer.
              • The scan will take a while, so be patient and let it finish.
              When the scan is done, in the Scan is complete window, any infection is displayed.
              There is no option to clean/disinfect, however, we need to analyze the information on the report.

              To obtain the report:
              Click on: Save Report As
              • Next, in the Save as prompt, Save in area, select: Desktop.
              • In the File name area use KScan, or something similar.
              • In Save as type: click the drop arrow and select: Text file [*.txt]
              • Then, click: Save


              Copy and paste the Kaspersky Online Scanner Report in your next reply.

              Note for Internet Explorer 7 users: If at any time you have trouble viewing the accept button of the license, click on the Zoom tool located at the bottom right of the IE window and set the zoom to 75%. Once the license is accepted, reset to 100%.

              only_lonely

                Topic Starter


                Intermediate
                Re: serious virus
                « Reply #25 on: August 26, 2008, 01:04:23 AM »
                ok.will post the report later.
                the database update is very slow.
                scanning cannot run right now.

                evilfantasy

                • Malware Removal Specialist
                • Moderator


                • Genius
                • Calm like a bomb
                • Thanked: 493
                • Experience: Experienced
                • OS: Windows 11
                Re: serious virus
                « Reply #26 on: August 26, 2008, 01:09:18 AM »
                The scan will take a while as well. But it is very thorough and should find anything that may be left. It won't have an option to clean what's found but we will be able to do that manually once we have the file locations.

                We will run another diagnostic scan once Kaspersky is done. It will contain a huge amount of information and not take long to run. I will be sure to leave no stone unturned this time ;)