|
|
#1 (permalink) |
|
New Member
![]() Join Date: Sep 2006
Posts: 21
|
Hi, I've just come home to find what I presume must be a virus on the family home computer. Whenever Norton scans, it is scanning a multitude of .avi files which are clearly porn, or have pornographic names. They seem to be being found in a folder which does not exist, even when hidden folders are made visible, for example: g:\Documents And Settings\*username*\l\...*name of porn movie.avi*
So i'm not at all sure what's going on! Or what or where this mysterious 'l' folder is! :S Furthermore, there is a problem with the taskbar - when the arrow to open up hidden items is clicked, all that happens is several end brackets appear, then another arrow. It now seems to have been frozen - it still says the internet is disconnected, even though it is connected now I also don't seem to be able to access Task Manager or regedit. Finally, it takes 4 or 5 attempts to start up the computer if left off for long periods, and it says 'overclocking failed' even though i believe this has been turned off! Phew, i think that's it! Any help with any of these problems much appreciated. Thanks, Luke |
|
|
|
|
|
#2 (permalink) |
|
Diamond Member
![]() Join Date: Jan 2006
Location: Essex, UK
Age: 16
Posts: 1,180
|
Google for HijackThis and post the log here
__________________
Main System Proccy - Intel E6400 @ 3440 | Mobo - P5B DLX | RAM - 2GB TwinX 6400 C5 | GPU - 96GT HDD - WD 400GB Caviar SE - WD 320GB Caviar SE - 160GB Seagate Ext Monitor - Asus 19" Wide LCD | PSU - Tagan 600W Dual Engine | Soundcard - SB Live Ext 24 Heatsink - S Infinity | Optical - Pioneer DVDRW | OS - Vista Ult64 SP1 |
|
|
|
|
|
#3 (permalink) |
|
New Member
![]() Join Date: Sep 2006
Posts: 21
|
Ok cool, here's the log:
Logfile of HijackThis v1.99.1 Scan saved at 14:42:11, on 03/05/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16640) Running processes: G:\WINDOWS\System32\smss.exe G:\WINDOWS\system32\winlogon.exe G:\WINDOWS\system32\services.exe G:\WINDOWS\system32\lsass.exe G:\WINDOWS\system32\Ati2evxx.exe G:\WINDOWS\system32\svchost.exe G:\WINDOWS\System32\svchost.exe G:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe G:\WINDOWS\system32\spoolsv.exe G:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe G:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe G:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE G:\Program Files\Analog Devices\SoundMAX\SMAgent.exe G:\WINDOWS\system32\svchost.exe G:\Program Files\Canon\CAL\CALMAIN.exe G:\WINDOWS\system32\Ati2evxx.exe G:\WINDOWS\Explorer.EXE G:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe G:\Program Files\Microsoft Hardware\Keyboard\type32.exe G:\Program Files\ATI Technologies\ATI.ACE\cli.exe G:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe G:\Program Files\Common Files\Real\Update_OB\realsched.exe G:\Program Files\Kontiki\KHost.exe G:\Program Files\iTunes\iTunesHelper.exe G:\Program Files\Common Files\Symantec Shared\ccApp.exe G:\WINDOWS\mrofinu1188.exe G:\WINDOWS\system32\ctfmon.exe G:\Program Files\Windows Live\Messenger\MsnMsgr.Exe G:\Documents and Settings\Luke\svchost.exe G:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe G:\Program Files\iPod\bin\iPodService.exe G:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe G:\WINDOWS\system32\rundll32.exe G:\Program Files\ATI Technologies\ATI.ACE\cli.exe G:\Program Files\ATI Technologies\ATI.ACE\cli.exe G:\Program Files\Real\RealOne Player\RealPlay.exe G:\Program Files\Norton 360\ScanStub.exe I:\Program Files\foxmovies\bin\bin-0\foxmovies.exe I:\Program Files\foxmovies\bin\bin-0\foxmoviesController.exe G:\Program Files\Java\jre1.6.0_05\bin\jusched.exe G:\Program Files\Mozilla Firefox\firefox.exe G:\Program Files\limewire\limewire.exe G:\Program Files\Spybot - Search & Destroy\SpybotSD.exe G:\My Downloads\ewido_micro.exe G:\Program Files\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file) O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - G:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - G:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - G:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - G:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - G:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll O4 - HKLM\..\Run: [MBpatch] C:\program files\Creative\MBsetup\RemoveKey.exe O4 - HKLM\..\Run: [SoundMAXPnP] G:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe O4 - HKLM\..\Run: [SoundMAX] "G:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray O4 - HKLM\..\Run: [POINTER] point32.exe O4 - HKLM\..\Run: [IntelliType] "G:\Program Files\Microsoft Hardware\Keyboard\type32.exe" O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "G:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon O4 - HKLM\..\Run: [ATICCC] "G:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay O4 - HKLM\..\Run: [ATIPTA] G:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe O4 - HKLM\..\Run: [TkBellExe] "G:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [4oD] "G:\Program Files\Kontiki\KHost.exe" -all O4 - HKLM\..\Run: [QuickTime Task] "G:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [iTunesHelper] "G:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [ccApp] "G:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [Symantec PIF AlertEng] "G:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "G:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll" O4 - HKLM\..\Run: [runner1] G:\WINDOWS\mrofinu1188.exe 61A847B5BBF72813339330466188719AB689201522886B092C BD44BD8689220221DD325762E902BC9ED7286538F75F2F0C8D 6E84A1EF7F506DCD610837F810EBCA9D775A67 O4 - HKLM\..\Run: [Host Process] G:\Documents and Settings\Luke\svchost.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] G:\Program Files\Java\jre1.6.0_05\bin\jusched.exe O4 - HKCU\..\Run: [CTFMON.EXE] G:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [MsnMsgr] "G:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [kdx] G:\Program Files\KHost.exe -all O4 - HKCU\..\RunOnce: [FlashPlayerUpdate] G:\WINDOWS\system32\Macromed\Flash\NPSWF32_FlashUt il.exe -p O4 - Global Startup: Adobe Reader Speed Launch.lnk = G:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: Kodak EasyShare software.lnk = G:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe O8 - Extra context menu item: E&xport to Microsoft Excel - res://G:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - G:\Program Files\Java\jre1.6.0_05\bin\npjpi160_05.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - G:\Program Files\Java\jre1.6.0_05\bin\npjpi160_05.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - G:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - G:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - G:\Program Files\Messenger\msmsgs.exe O11 - Options group: [INTERNATIONAL] International* O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - G:\Program Files\Yahoo!\Common\Yinsthelper.dll O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://bubblybethansworld.spaces.liv...d/MsnPUpld.cab O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary...n.cab56986.cab O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-GB/.../GAME_UNO1.cab O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1136039924750 O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...t.cab31267.cab O16 - DPF: {9122D757-5A4F-4768-82C5-B4171D8556A7} (PhotoPickConvert Class) - http://appdirectory.messenger.msn.co...p/PhtPkMSN.cab O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary...o.cab56649.cab O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...t.cab56907.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/ge...sh/swflash.cab O16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} - http://download.abacast.com/download...basetup161.cab O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary...r.cab56986.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{2C749D9E-23D8-4AC1-8671-426DEC33A314}: NameServer = 194.168.4.100 194.168.8.100 O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - G:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL O18 - Protocol: maven-8110 - {A055BE1D-40B4-4124-922E-542CE1D3F455} - I:\Program Files\foxmovies\bin\bin-0\protocolHandler.dll O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - G:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - G:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL O18 - Protocol: talkto - {828030A1-22C1-4009-854F-8E305202313F} - G:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL O20 - Winlogon Notify: WgaLogon - G:\WINDOWS\SYSTEM32\WgaLogon.dll O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - G:\WINDOWS\system32\WPDShServiceObj.dll O23 - Service: Apple Mobile Device - Apple, Inc. - G:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - G:\WINDOWS\system32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - G:\WINDOWS\system32\ati2sgag.exe O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - G:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - G:\Program Files\Canon\CAL\CALMAIN.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - G:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing) O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - G:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing) O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - G:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing) O23 - Service: COM Host (comHost) - Symantec Corporation - G:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - G:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPod Service - Apple Inc. - G:\Program Files\iPod\bin\iPodService.exe O23 - Service: Kodak Camera Connection Software (KodakCCS) - Unknown owner - G:\WINDOWS\system32\drivers\KodakCCS.exe (file missing) O23 - Service: LiveUpdate - Symantec Corporation - G:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - G:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing) O23 - Service: LiveUpdate Notice Service - Unknown owner - G:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /m "G:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng.dll (file missing) O23 - Service: Pml Driver HPZ12 - HP - G:\WINDOWS\system32\HPZipm12.exe O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - G:\Program Files\Analog Devices\SoundMAX\SMAgent.exe O23 - Service: Symantec Core LC - Unknown owner - G:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe |
|
|
|
|
|
#4 (permalink) |
|
Diamond Member
![]() Join Date: Oct 2006
Location: Yorkshire, UK
Posts: 1,517
|
Luke you have a couple of Trojans and svhost files that should only reside in the System32 directory.
You'll get a better/faster response if you post it in the Security section. O4 - HKLM\..\Run: [Host Process] G:\Documents and Settings\Luke\svchost.exe G:\Documents and Settings\Luke\svchost.exe
__________________
Operator: Dave Operating System: XP Professional SP2 Processor: Intel E6750 Core Duo@3.20GHz Graphics: Nvidia 8500GT C: Drive 500GB D: Drive 250GB Memory: 2GB Last edited by TFT; 05-03-2008 at 02:00 PM. |
|
|
|
![]() |
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Computer restarting..Hijackthis log | TucanSpam | Computer Security | 4 | 09-17-2006 12:05 AM |
| Infected With Look2me;Popups include:Dofact,Yourtruths,Drivecleaner.Here is HJT Log. | ranzy | Computer Security | 9 | 09-05-2006 02:54 PM |
| Base 64.dll | soccerdude | Computer Security | 3 | 09-04-2006 02:16 PM |
| My Computer is also sick! | beergoggles | Computer Security | 12 | 02-26-2006 08:51 PM |
| Computer Problems - A joke | Darkomen | General Computer Chat | 31 | 10-31-2005 05:37 PM |