Results 1 to 13 of 13

Thread: Virus Problem     submit to reddit submit to twitter

  1. #1
    Pens win! Pens Win!!! PENS WIN!!!!!
    Sweaty Dick Punching Enthusiast

    Join Date
    Oct 2007
    Posts
    2,187
    BG Level
    7

    Virus Problem

    Recently aquired a virus of some sort, tried a few things to get rid of it but nothings working. Figure it's some kind of Spyware, but never really had too much experience with virus'.

    What it does: It plays adds through my headset, I'll be on vent and I'll start hearing adds for the stupidest shit ever. Some are personals, some are for movies, some are like home vidoes, one was an interview with the PussyCat Dolls, and just random other shit. It's annoying as hell to say the least, sometimes it repeats after 5 min, sometimes it's like 2 hrs in between playing, it's very random.

    I've DL'd and paid for SpyWare Doctor, didn't work. I have AVG running full time, yet it never caught it or hasn't found it. I tried STOPzilla, never worked. I've done CRTL+ALT+DEL looked at system processes, wrote down each process and researched each one, didn't see anything fishy or out of the blue when I did this.

    So, any experience with this problems or advice for me would be greatly appreciated.

  2. #2
    Sea Torques
    Join Date
    Nov 2005
    Posts
    504
    BG Level
    5

    Download Hijackthis and post a log here, I'm sure someone will be able to root out the problem.

    If all else fails, I'd try Malwarebytes.

    Someone else who seems to have your same problem: http://forum.nuklearpower.com/showthread.php?t=21543

  3. #3
    Sea Torques
    Join Date
    Dec 2005
    Posts
    668
    BG Level
    5
    FFXI Server
    Valefor

    As Rockstaru said, use MalwareBytes.

    Then use ComboFix

    MalwareBytes will find the stupid stuff, but ComboFix is gonna find the really nasty stuff. I've only seen audio viruses a few times, they are definitely my favorite though.

  4. #4
    Pens win! Pens Win!!! PENS WIN!!!!!
    Sweaty Dick Punching Enthusiast

    Join Date
    Oct 2007
    Posts
    2,187
    BG Level
    7

    Spoiler: show
    C:\Program Files\Linksys\Wireless-G Notebook Adapter with SRX Utility\lcu.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Ventrilo\Ventrilo.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\Iexplore.exe
    C:\DOCUME~1\oemuser1\LOCALS~1\Temp\Temporary Directory 1 for HiJackThis[1].zip\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Google
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
    O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\s wg.dll
    O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
    O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
    O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
    O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
    O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe
    O4 - HKCU\..\Run: [RegistryMechanic] C:\Program Files\Registry Mechanic\RegMech.exe /H
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-21-1844237615-839522115-854245398-500\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe (User 'Administrator')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
    O4 - Startup: Wireless-G Notebook Adapter with SRX Utility.lnk = C:\Program Files\Linksys\Wireless-G Notebook Adapter with SRX Utility\lcu.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: Yahoo! Euchre - http://download.games.yahoo.com/game...ts/y/et1_x.cab
    O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} (Citrix ICA Client) - http://a516.g.akamai.net/f/516/25175...at-no-eula.cab
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsu...?1117850906292
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1117851087031
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
    O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
    O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
    O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
    O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
    O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
    O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe

    --
    End of file - 6399 bytes


    Gonna try running that other program you suggested now.

  5. #5
    Pens win! Pens Win!!! PENS WIN!!!!!
    Sweaty Dick Punching Enthusiast

    Join Date
    Oct 2007
    Posts
    2,187
    BG Level
    7

    Out of all 3 programs I DL'd(Combofix, Malwarebytes, Highjackthis) none of them are executing, for Highjack this the file DL was offered in a Zip form so that one worked but I've been unable to find it for the other 2 programs.

  6. #6
    Nidhogg
    Join Date
    Jun 2007
    Posts
    3,528
    BG Level
    7
    FFXI Server
    Odin
    WoW Realm
    Lightbringer

    format c: <Enter>

  7. #7
    CoP Dynamis
    Join Date
    Jul 2007
    Posts
    262
    BG Level
    4
    FFXI Server
    Siren

    .

  8. #8
    Relic Shield
    Join Date
    Jan 2007
    Posts
    1,743
    BG Level
    6

    use dban, start fresh

  9. #9
    Sea Torques
    Join Date
    Dec 2005
    Posts
    668
    BG Level
    5
    FFXI Server
    Valefor

    Quote Originally Posted by Aragon of Odin View Post
    Out of all 3 programs I DL'd(Combofix, Malwarebytes, Highjackthis) none of them are executing, for Highjack this the file DL was offered in a Zip form so that one worked but I've been unable to find it for the other 2 programs.
    Rename ComboFix to something like CF123.exe

    Most bad viruses auto-kill programs with names that are AV related.

    Navigate to Program Files/MalwareBytes and rename mbam.exe to something like lol.exe

    Best of luck

  10. #10
    Pandemonium
    Join Date
    Oct 2005
    Posts
    7,839
    BG Level
    8
    WoW Realm
    Cho'gall

    Quote Originally Posted by Aragon of Odin View Post
    Out of all 3 programs I DL'd(Combofix, Malwarebytes, Highjackthis) none of them are executing, for Highjack this the file DL was offered in a Zip form so that one worked but I've been unable to find it for the other 2 programs.
    In addition to what Kriz said, make sure you're running them in safe mode with networking so you give it the best chance to clear out the virus.

  11. #11
    Sea Torques
    Join Date
    Nov 2005
    Posts
    504
    BG Level
    5

    Though not directly related to the topic, quick question about ComboFix - what makes it so dangerous to where they plaster "Do not use without supervision" on the guide for it? I've never had to use it myself (just heard from this and other websites that it's one of the best malware/spyware removal tools out there), so I'm curious as to why they stress that particular point.

  12. #12
    Pandemonium
    Join Date
    Oct 2005
    Posts
    7,839
    BG Level
    8
    WoW Realm
    Cho'gall

    So you can't sue/complain if it fucks up your shit. It stops and resets almost every service on the computer, and some anti-virus programs can flag Combofix as malware because of how it scans and unhooks DLL files.

    Also it's been known to just delete all the system files if it finds really bad rootkits. So again, the disclaimer is just to protect the developers from people crying if it messes up their machine.

  13. #13
    Pens win! Pens Win!!! PENS WIN!!!!!
    Sweaty Dick Punching Enthusiast

    Join Date
    Oct 2007
    Posts
    2,187
    BG Level
    7

    Quote Originally Posted by Kriz View Post
    Rename ComboFix to something like CF123.exe

    Most bad viruses auto-kill programs with names that are AV related.

    Navigate to Program Files/MalwareBytes and rename mbam.exe to something like lol.exe

    Best of luck
    Thank you, worked to a charm. Still havent run ComboFix but it seems that Malwarebytes took care of the problem, still going to try ComboFix later on though.

Similar Threads

  1. Problems with virus, idk what
    By Edgie in forum Tech
    Replies: 6
    Last Post: 2009-06-23, 03:33
  2. Virus/Spyware Problem
    By Stu in forum Tech
    Replies: 4
    Last Post: 2009-05-21, 03:51
  3. Replies: 4
    Last Post: 2009-04-30, 11:53