• Navigation
Page 1 of 2 1 2 LastLast
Results 1 to 20 of 23
  1. #1
    :3
    Join Date
    Dec 2006
    Posts
    279
    BG Level
    4
    FFXI Server
    Caitsith
    WoW Realm
    Skywall

    I have a virus/worm, but I don't know what it is or how to get rid of it

    Every time I start up my computer, it seems like all of my drives (C:/, D:/ F:/ and even my external E:/) get a batch of files installed onto it, a folder and an AutoRun notepad file that is hidden. It causes me to not be able to left-click and open the actual drives, instead it does nothing (i'd imagine it actually executes) unless I right click and open.

    Now, with the external, it crashes, and ithe autoexec is this:

    (AutoRun)
    open=ϵͳÀ¬»øÇåÀí.exe
    shellexecute=ϵͳÀ¬»øÇåÀí.exe
    shell\Auto\command=ϵͳÀ¬»øÇåÀí.exe

    Note: the () are actually brackets, but that would just mess with the forum layout if i left brackets in.

    any clue what this could be, if it is hazardous or just a byproduct of some stupid download. And more importantly.. how I can go about getting rid of it? Erasing everything doesn't work, as I've already done this before. AVG does not pick it up as a virus, so the only other thing I can think of doing is running HijackThis, but it would simply show that the program listed above is probably running.

    So.. I'm stumped

  2. #2
    2600klub
    I donated 5 bucks and all I got was this shitty title from Zet

    Join Date
    Jun 2007
    Posts
    2,688
    BG Level
    7
    FFXI Server
    Ragnarok

    HijackThis does far more than just tell you the program is running ... it tells you all the vital startup information your PC uses to load stuff when it boots. Run HijackThis and remove any suspicious entries if you feel safe doing it, otherwise post the log file here and I'll try to help you.

    Warning though: using HijackThis is at your own risk. If you (or I) break your machine, it's on you.

  3. #3
    Campaign
    Join Date
    Mar 2006
    Posts
    6,192
    BG Level
    8

    Post a Hijackthis log please

  4. #4
    :3
    Join Date
    Dec 2006
    Posts
    279
    BG Level
    4
    FFXI Server
    Caitsith
    WoW Realm
    Skywall

    as requested:

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 1:33:47 PM, on 12/5/2008
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16735)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
    C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    C:\PROGRA~1\AVG\AVG8\avgtray.exe
    C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
    C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIA CA.EXE
    C:\PROGRA~1\AVG\AVG8\avgrsx.exe
    D:\Adobe\Reader 9.0\Reader\Reader_sl.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Unlocker\UnlockerAssistant.exe
    C:\Program Files\ATI Multimedia\main\launchpd.exe
    C:\Program Files\ATI Multimedia\main\ATIDtct.EXE
    C:\Program Files\ATI Multimedia\RemCtrl\ATIRW.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\WINDOWS\system32\PnkBstrA.exe
    C:\WINDOWS\system32\PnkBstrB.exe
    C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe
    C:\PROGRA~1\AVG\AVG8\avgemc.exe
    C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WMP54Gv4.exe
    C:\Program Files\iPod\bin\iPodService.exe
    D:\Trend Micro\HijackThis\HijackThis.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\wuauclt.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Live Search
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Live Search
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = MSN.com
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (file missing)
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
    O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
    O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime
    O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
    O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
    O4 - HKLM\..\Run: [EPSON Stylus CX3800 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIA CA.EXE /P26 "EPSON Stylus CX3800 Series" /O6 "USB001" /M "Stylus CX3800"
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
    O4 - HKCU\..\Run: [ATI Launchpad] "C:\Program Files\ATI Multimedia\main\launchpd.exe"
    O4 - HKCU\..\Run: [ATI DeviceDetect] C:\Program Files\ATI Multimedia\main\ATIDtct.EXE
    O4 - HKCU\..\Run: [ATI Remote Control] C:\Program Files\ATI Multimedia\RemCtrl\ATIRW.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKUS\S-1-5-18\..\Run: [] (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [] (User 'Default user')
    O4 - Global Startup: VPN Client.lnk = ?
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office12\EXCEL.EXE/3000
    O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll
    O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll
    O9 - Extra button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - C:\Program Files\ATI Multimedia\tv\EXPLBAR.DLL
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\Office12\REFIEBAR.DLL
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {27527D31-447B-11D5-A46E-0001023B4289} (CoGSManager Class) - http://gamingzone.ubisoft.com/dev/pa.../GSManager.cab
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/micr...?1218686475134
    O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
    O20 - AppInit_DLLs: avgrsstx.dll
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
    O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
    O23 - Service: getPlus(R) Helper - Unknown owner - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe (file missing)
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: kbsj - Unknown owner - C:\WINDOWS\system32\ϵͳÀ¬»øÇåÀí.exe
    O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
    O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
    O23 - Service: WMP54Gv4SVC - GEMTEKS - C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe
    O23 - Service: X10 Device Network Service (x10nets) - Unknown owner - C:\PROGRA~1\ATIMUL~1\RemCtrl\x10nets.exe (file missing)

    --
    End of file - 7326 bytes

  5. #5
    Campaign
    Join Date
    Mar 2006
    Posts
    6,192
    BG Level
    8

    O23 - Service: kbsj - Unknown owner - C:\WINDOWS\system32\ϵͳÀ¬»øÇåÀí.exe

    that's the only glaringly obvious thing, but google has no results for that garbage filename.

    Are you able to install stuff or is it fucking windows up too badly?

  6. #6
    Annihilation Banwave
    sprout sprout sprout
    2031 No.1 Draft Pick
    Pittsburgh Penguins

    Sweaty Dick Punching Enthusiast

    Join Date
    Aug 2006
    Posts
    19,830
    BG Level
    9
    FFXI Server
    Bismarck

    Could be worse buddy, my wife somehow managed to get that virus off of Facebook. So now I'm currently dealing with that. And I'm not the most computer literate person here.

  7. #7
    My Little Ixion
    Join Date
    Aug 2007
    Posts
    8,016
    BG Level
    8
    FFXIV Character
    Olorin Bustyoas
    FFXIV Server
    Sargatanas
    FFXI Server
    Ramuh

    Have you tried rebooting into safe mode? That should keep this thing from loading and allow you to delete it both from your HD and from your registry..

  8. #8
    Sea Torques
    Join Date
    Dec 2005
    Posts
    668
    BG Level
    5
    FFXI Server
    Valefor

    Rock some MalwareBytes Antimalware (MBAM) and some ComboFix on that noise.

  9. #9
    Annihilation Banwave
    sprout sprout sprout
    2031 No.1 Draft Pick
    Pittsburgh Penguins

    Sweaty Dick Punching Enthusiast

    Join Date
    Aug 2006
    Posts
    19,830
    BG Level
    9
    FFXI Server
    Bismarck

    Wait. Me or Shadowrunner? I'm lost lol. What I was going to try to do was hit up Facebook's security and use the one link for Kasparansky or whatever the fuck it's called and hope that does the trick.

  10. #10
    I Am, Who I Am.
    Join Date
    Nov 2005
    Posts
    15,657
    BG Level
    9
    FFXIV Character
    Trixi Sephyuyx
    FFXIV Server
    Excalibur
    FFXI Server
    Ragnarok

    Go to run, type restore, and click rstrui.exe
    Restore to a time before this started happening and see if that works.

  11. #11
    E. Body
    Join Date
    Jun 2005
    Posts
    2,226
    BG Level
    7
    FFXI Server
    Caitsith

    I would most definitly restart in safe mode and run malwarebytes. It's one of the better programs out there for nailing obscure random viruses.

  12. #12
    My Little Ixion
    Join Date
    Aug 2007
    Posts
    8,016
    BG Level
    8
    FFXIV Character
    Olorin Bustyoas
    FFXIV Server
    Sargatanas
    FFXI Server
    Ramuh

    I just had another thought - this could be a keylogger, in which case I would change your passwords as soon as you're done cleaning out your system.

  13. #13
    E. Body
    Join Date
    Jun 2007
    Posts
    2,285
    BG Level
    7
    FFXI Server
    Ragnarok
    WoW Realm
    Haomarush

    text looks korean. well it's the same as starcraft game texts which are korean people. so i wouldn't doubt a keylog

  14. #14
    :3
    Join Date
    Dec 2006
    Posts
    279
    BG Level
    4
    FFXI Server
    Caitsith
    WoW Realm
    Skywall

    The only thing it has successfully done has made it so I can't double left click any of the drive letters in My Computer to open them, I have to right click and select open. On the external, it crashes that program.

    I'm not entirely sure where in the registry it is, but in safe mode I have already gone through and deleted the files from each drive, and with the external, simply plugging it in re-installed all of the files. I'm not sure what's goin on. I'll give that Malware thinger a try and see what I come up with.

  15. #15
    :3
    Join Date
    Dec 2006
    Posts
    279
    BG Level
    4
    FFXI Server
    Caitsith
    WoW Realm
    Skywall

    I lied, I -am- having another problem where imgburn wont burn any information onto CD's, even though it's set up to. But I suspect that's something with my optical drive rather than this crud.

    Unless anyone else has had experiences where you set imgburn to write and it seems to do it's thing but the CD is still blank when done.

  16. #16
    Campaign
    Join Date
    Mar 2006
    Posts
    6,192
    BG Level
    8

    Quote Originally Posted by Shuemue View Post
    Are you able to install stuff or is it fucking windows up too badly?
    Did you answer this?

  17. #17
    :3
    Join Date
    Dec 2006
    Posts
    279
    BG Level
    4
    FFXI Server
    Caitsith
    WoW Realm
    Skywall

    Sorry, I didn't, but no, windows seems to let me install and do everything absolutely fine, the only changes to my system that i've noticed were listed above.

    Speaking of which:

    Running Malwarebytes and the only thing it picked up was some crap ebay thing.
    Combofix, on the other hand, immediately deleted the autoexec files on all 3 of my drives.. and it 'might' have fixed the problem. Combofix created a log, if that needs to be posted I can do that too.

    EDIT: I can't believe I did it again. I really did intend on answering your question

  18. #18
    Campaign
    Join Date
    Mar 2006
    Posts
    6,192
    BG Level
    8

    lol that's okay, I was just going to suggest sourcing a copy of something like Symantec Corporate.

    Let us know if it's fixed. You might want to consider a reformat anyway, I know I would.

  19. #19
    Sea Torques
    Join Date
    Dec 2005
    Posts
    668
    BG Level
    5
    FFXI Server
    Valefor

    ComboFix, even with it's amazing vague-ness ("Don't bother me, I'm working. I'll let you know when I'm done") is pretty good for catching stuff MBAM doesn't.

    At this point, I'd throw Ccleaner on the machine and delete everything it wants to from the main screen (temp files, leftover hotfix files, etc) and registry (clean the shit up).

    Then, I'd grab a copy of HijackThis and run a scan again. Throw it (resulting log) into HijackThis Logfileauswertung

    Your old log looks okay, don't freak out if something legit is classified as weird (it's a Euro site).

    Once you've done all that (especially the reg clean/other crap cleaning) hit up Windows/Microsoft update and download everything. Then rerun Ccleaner to pick up the bits again, lol.

    Then install Spybot, update, immunize, and periodically scan for problems. It's a cute little program.

    Reformating is giving in! Rawr!

  20. #20
    Campaign
    Join Date
    Mar 2006
    Posts
    6,192
    BG Level
    8

    Reformatting isn't giving in, it's the easiest way to be 100% clean.

Page 1 of 2 1 2 LastLast

Similar Threads

  1. Replies: 3
    Last Post: 2011-08-02, 13:39
  2. How do I get rid of this virus?
    By Waef in forum Tech
    Replies: 10
    Last Post: 2009-07-08, 14:46
  3. Replies: 5
    Last Post: 2008-10-10, 22:24