Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: THINKPOINT boot virus  (Read 37361 times)

0 Members and 1 Guest are viewing this topic.

Iwishiknew

    Topic Starter


    Beginner
    THINKPOINT boot virus
    « on: November 03, 2010, 06:43:12 AM »
    Hi, I'm not sure how it got infected but my computer is now infected with at least Thinkpoint hotfix.exe virus.

    When it boots up i get a warning message from the antivirus embedded in my Asus motherboard saying a boot virus is trying to install and i should boot from a bootable floppy disk but i don't have a floppy disk drive anymore. I then choose start anyway.

    I've followed the in instruction from "Computer viruses and spyware / Read this before requesting malware removal help" as best i could but after scanning with SUPERAntiSpyware Windows would start without a system restore, i lost the log because of this. I also couldn't find Java options in my browser IE8. I've scanned with CCleaner, AdAware, SUPERAntiSpyware, Malwarebytes and installed COMODO firewall.

    Thinkpoint does not automatically start up blocking the desktop anymore after using these programs but it is still on my computer in the start menu and on the desktop as a shortcut.

    I'm running XP, SP2, Pentium 4, 2.4 GHz

    I have logs for Hijackthis, Malwarebytes and in the process of trying to get a new SUPERAntiSpyware log.

    Any help will be greatly appreciated, thank you.

    harry 48



      Egghead

    • lay back , relax and chill out
    • Thanked: 129
      • Yes
      • Yes
      • Yes
      • Dribbling Pensioner
    • Certifications: List
    • Experience: Familiar
    • OS: Windows 7
    Re: THINKPOINT boot virus
    « Reply #1 on: November 03, 2010, 10:21:17 AM »
    please post what ever logs you have

    Iwishiknew

      Topic Starter


      Beginner
      Re: THINKPOINT boot virus
      « Reply #2 on: November 03, 2010, 10:59:31 AM »
      I can't seem to post the logs ... i get a server error message  ???

      Iwishiknew

        Topic Starter


        Beginner
        Re: THINKPOINT boot virus
        « Reply #3 on: November 03, 2010, 11:06:17 AM »

        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
        R3 - URLSearchHook: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\SearchSettings.dll
        O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
        O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
        O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
        O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
        O2 - BHO: BrowserHelper Class - {8A9D74F9-560B-4FE7-ABEB-3B2E638E5CD6} - C:\Program Files\SGPSA\SearchAssistant.dll (file missing)
        O2 - BHO: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
        O2 - BHO: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\SearchSettings.dll
        O3 - Toolbar: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
        O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
        O4 - HKLM\..\Run: [DeltTray] DeltTray.exe
        O4 - HKLM\..\Run: [RevHDD] C:\WINDOWS\SYSTEM\RevHDD.exe
        O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
        O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
        O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
        O4 - HKLM\..\Run: [SearchSettings] C:\Program Files\Search Settings\SearchSettings.exe
        O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
        O4 - HKLM\..\Run: [B2C_AGENT] C:\Documents and Settings\All Users\Application Data\LGMOBILEAX\B2C_Client\B2CNotiAgent.exe"
        O4 - HKLM\..\Run: [tsnp2std] C:\WINDOWS\tsnp2std.exe
        O4 - HKLM\..\Run: [snp2std] C:\WINDOWS\vsnp2std.exe
        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
        O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
        O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
        O4 - HKLM\..\Run: [ArcSoft MediaImpression Monitor] C:\Program Files\Kodak\MediaImpression\ArcMonitor.exe
        O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h
        O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
        O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
        O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
        O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
        O9 - Extra button: (no name) - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
        O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
        O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

        Iwishiknew

          Topic Starter


          Beginner
          Re: THINKPOINT boot virus
          « Reply #4 on: November 03, 2010, 11:08:49 AM »
          For some reason i can't post all of the log files at once, i guess it's a chracter max on this forum  ??? So i'm posting 10 entries at a time per post.

          harry 48



            Egghead

          • lay back , relax and chill out
          • Thanked: 129
            • Yes
            • Yes
            • Yes
            • Dribbling Pensioner
          • Certifications: List
          • Experience: Familiar
          • OS: Windows 7
          Re: THINKPOINT boot virus
          « Reply #5 on: November 03, 2010, 11:11:30 AM »
          there is no problem on the forum

          open the log and copy and paste it

          Iwishiknew

            Topic Starter


            Beginner
            Re: THINKPOINT boot virus
            « Reply #6 on: November 03, 2010, 11:15:56 AM »
            i can't seem to even post part of log... i don't undersand why .... when i copy and paste or try to attach the log file i get this error:

            Oops! This page appears broken. DNS Error - Server cannot be found.

            But i can post this message ... i don't get it  ???

            Could the virus be blocking this somehow?

            Iwishiknew

              Topic Starter


              Beginner
              Re: THINKPOINT boot virus
              « Reply #7 on: November 03, 2010, 11:17:14 AM »
              Malwarebytes' Anti-Malware 1.46
              www.malwarebytes.org

              Database version: 5030

              Windows 5.1.2600 Service Pack 2
              Internet Explorer 8.0.6001.18702

              11/3/2010 12:53:24 PM
              mbam-log-2010-11-03 (12-53-24).txt

              Scan type: Quick scan
              Objects scanned: 172608
              Time elapsed: 12 minute(s), 17 second(s)

              Memory Processes Infected: 0
              Memory Modules Infected: 0
              Registry Keys Infected: 4
              Registry Values Infected: 0
              Registry Data Items Infected: 0
              Folders Infected: 0
              Files Infected: 5

              Memory Processes Infected:
              (No malicious items detected)

              Memory Modules Infected:
              (No malicious items detected)

              Registry Keys Infected:
              HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{258c9770-1713-4021-8d7e-1f184a2bd754} (Adware.ShoppingReport2) -> Quarantined and deleted successfully.
              HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{bdea95cf-f0e6-41e0-bd3d-b00f39a4e939} (Adware.ShoppingReport2) -> Quarantined and deleted successfully.
              HKEY_CURRENT_USER\SOFTWARE\Microsoft\Handle (Malware.Trace) -> Quarantined and deleted successfully.

              Registry Values Infected:
              (No malicious items detected)

              Registry Data Items Infected:
              (No malicious items detected)

              Folders Infected:
              (No malicious items detected)

              Files Infected:
              C:\Documents and Settings\Rob\Application Data\dkfjasdfshd.bat (Malware.Trace) -> Quarantined and deleted successfully.
              C:\WINDOWS\Tasks\{BBAEAEAF-1275-40e2-BD6C-BC8F88BD114A}.job (Trojan.Downloader) -> Quarantined and deleted successfully.
              C:\Documents and Settings\All Users\Documents\Server\admin.txt (Malware.Trace) -> Quarantined and deleted successfully.
              C:\Documents and Settings\All Users\Documents\Server\server.dat (Malware.Trace) -> Quarantined and deleted successfully.
              C:\WINDOWS\Tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job (Trojan.Downloader) -> Quarantined and deleted successfully.

              Iwishiknew

                Topic Starter


                Beginner
                Re: THINKPOINT boot virus
                « Reply #8 on: November 03, 2010, 11:19:40 AM »
                The HJT log won't post for some reason but as you can see the MBAM log is posted and part of the HJT log ...

                harry 48



                  Egghead

                • lay back , relax and chill out
                • Thanked: 129
                  • Yes
                  • Yes
                  • Yes
                  • Dribbling Pensioner
                • Certifications: List
                • Experience: Familiar
                • OS: Windows 7
                Re: THINKPOINT boot virus
                « Reply #9 on: November 03, 2010, 11:42:09 AM »
                ok , i can't help you any more you will have to wait for a malware expert

                SuperDave

                • Malware Removal Specialist


                • Genius
                • Thanked: 1020
                • Certifications: List
                • Experience: Expert
                • OS: Windows 10
                Re: THINKPOINT boot virus
                « Reply #10 on: November 03, 2010, 12:30:56 PM »
                If you can't copy and paste the logs please try attaching them.
                Windows 8 and Windows 10 dual boot with two SSD's

                Iwishiknew

                  Topic Starter


                  Beginner
                  Re: THINKPOINT boot virus
                  « Reply #11 on: November 03, 2010, 01:07:57 PM »
                  I also can't attach the HJT log, when i try i get the same server error message.



                  i will try to copy and paste a little at a time starting with this:

                  Logfile of Trend Micro HijackThis v2.0.4
                  Scan saved at 1:07:34 PM, on 11/3/2010
                  Platform: Windows XP SP2 (WinNT 5.01.2600)
                  MSIE: Internet Explorer v8.00 (8.00.6001.18702)
                  Boot mode: Normal

                  Iwishiknew

                    Topic Starter


                    Beginner
                    Re: THINKPOINT boot virus
                    « Reply #12 on: November 03, 2010, 01:08:46 PM »
                    Running processes:
                    C:\WINDOWS\System32\smss.exe
                    C:\WINDOWS\system32\winlogon.exe
                    C:\WINDOWS\system32\services.exe
                    C:\WINDOWS\system32\lsass.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\Program Files\AVG\AVG9\avgchsvx.exe
                    C:\Program Files\AVG\AVG9\avgrsx.exe
                    C:\Program Files\AVG\AVG9\avgcsrvx.exe
                    C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
                    C:\WINDOWS\system32\spoolsv.exe
                    C:\WINDOWS\Explorer.EXE
                    C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
                    C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
                    C:\Program Files\Application Updater\ApplicationUpdater.exe
                    C:\Program Files\AVG\AVG9\avgwdsvc.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\system32\DeltTray.exe
                    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
                    C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                    C:\Program Files\Search Settings\SearchSettings.exe
                    C:\PROGRA~1\AVG\AVG9\avgtray.exe
                    C:\WINDOWS\tsnp2std.exe
                    C:\Program Files\AVG\AVG9\avgemc.exe
                    C:\WINDOWS\vsnp2std.exe
                    C:\Program Files\iTunes\iTunesHelper.exe
                    C:\Program Files\AVG\AVG9\avgnsx.exe
                    C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
                    C:\Program Files\AVG\AVG9\avgcsrvx.exe
                    C:\Program Files\Kodak\MediaImpression\ArcMonitor.exe
                    C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
                    C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac
                    C:\WINDOWS\system32\ctfmon.exe
                    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                    C:\WINDOWS\system32\wscntfy.exe
                    C:\Program Files\iPod\bin\iPodService.exe
                    C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
                    C:\Program Files\Internet Explorer\IEXPLORE.EXE
                    C:\Program Files\Internet Explorer\IEXPLORE.EXE
                    C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
                    C:\Documents and Settings\Rob\Desktop\war on spyware\sniper.exe.exe
                    C:\Program Files\Skype\Toolbars\Shared\SkypeNames.exe

                    Iwishiknew

                      Topic Starter


                      Beginner
                      Re: THINKPOINT boot virus
                      « Reply #13 on: November 03, 2010, 01:11:05 PM »
                      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
                      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
                      R3 - URLSearchHook: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\SearchSettings.dll
                      O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
                      O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
                      O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
                      O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
                      O2 - BHO: BrowserHelper Class - {8A9D74F9-560B-4FE7-ABEB-3B2E638E5CD6} - C:\Program Files\SGPSA\SearchAssistant.dll (file missing)
                      O2 - BHO: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
                      O2 - BHO: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\SearchSettings.dll
                      O3 - Toolbar: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
                      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
                      O4 - HKLM\..\Run: [DeltTray] DeltTray.exe
                      O4 - HKLM\..\Run: [RevHDD] C:\WINDOWS\SYSTEM\RevHDD.exe
                      O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
                      O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                      O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
                      O4 - HKLM\..\Run: [SearchSettings] C:\Program Files\Search Settings\SearchSettings.exe
                      O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
                      O4 - HKLM\..\Run: [B2C_AGENT] C:\Documents and Settings\All Users\Application Data\LGMOBILEAX\B2C_Client\B2CNotiAgent.exe"
                      O4 - HKLM\..\Run: [tsnp2std] C:\WINDOWS\tsnp2std.exe
                      O4 - HKLM\..\Run: [snp2std] C:\WINDOWS\vsnp2std.exe
                      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                      O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                      O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
                      O4 - HKLM\..\Run: [ArcSoft MediaImpression Monitor] C:\Program Files\Kodak\MediaImpression\ArcMonitor.exe
                      O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h
                      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                      O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
                      O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                      O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
                      O9 - Extra button: (no name) - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
                      O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
                      O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
                      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

                      Iwishiknew

                        Topic Starter


                        Beginner
                        Re: THINKPOINT boot virus
                        « Reply #14 on: November 03, 2010, 01:27:24 PM »
                        Attached is the last bit of the HJT log as a GIF file, sorry it's so messed up but it's the only way i could post it, it's all there now in the previous posts ....



                        [recovering disk space - old attachment deleted by admin]