ComputerForum.com ComputerForum.com  

Go Back   Computer Forum > Computer Software > Operating Systems

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
Old 07-27-2005, 07:46 PM   #1 (permalink)
New Member
 
Join Date: Apr 2005
Posts: 19
Default computer infected by an incredible virus, help me

My computer doesn't open , when black windows loading screen appears, it restarts every time i open computer, now i'm on safe mode, i scanned computer with bitdefender 8 pro but no virus was found. My computer was infected by this virus before and i formatted, now i want to get rid of that virus not by formatting. Please help...

Last edited by ucanadam; 07-27-2005 at 07:56 PM.
ucanadam is offline   Reply With Quote


Old 07-27-2005, 08:10 PM   #2 (permalink)
Malware Destroyer
 
Byteman's Avatar
 
Join Date: Apr 2005
Location: Hurricane Heaven... still
Posts: 1,095
Default

try downloading ewido , download the full updates here , boot to safemode, install it and update it, then run a full scan and let us know the results, we'll go from there...
__________________
Don't byte off more than you can chew...
Byteman is offline   Reply With Quote
Old 07-27-2005, 08:12 PM   #3 (permalink)
New Member
 
Join Date: Apr 2005
Posts: 19
Default

i already scanned with ewido, but it wasn't solved
ucanadam is offline   Reply With Quote
Old 07-27-2005, 08:27 PM   #4 (permalink)
Digaredd
 
Buzz1927's Avatar
 
Join Date: May 2005
Location: Melbourne AU
Posts: 7,617
Default

Download Hijackthis here. Install and run it, hit "Scan and save logfile" and post the log here.
Buzz1927 is offline   Reply With Quote
Old 07-27-2005, 08:30 PM   #5 (permalink)
New Member
 
Join Date: Apr 2005
Posts: 19
Default

Logfile of HijackThis v1.99.1
Scan saved at 21:24:37, on 27.07.2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
D:\Belgelerim\emule gokhan mode\emule43b-freeangel-no ratio-no limits.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Downloads\a2personalsetup.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\is-PQLGD.tmp\is-LFIC1.tmp
C:\Program Files\a2\a2upd.exe
C:\Downloads\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\FlashGet\jccatch.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [BDMCon] C:\Program Files\Softwin\BitDefender8\\bdmcon.exe
O4 - HKLM\..\Run: [BDOESRV] C:\Program Files\Softwin\BitDefender8\\bdoesrv.exe
O4 - HKLM\..\Run: [BDNewsAgent] "C:\Program Files\Softwin\BitDefender8\bdnagent.exe"
O4 - HKLM\..\Run: [BDSwitchAgent] C:\Program Files\Softwin\BitDefender8\\bdswitch.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [a-squared] "C:\Program Files\a2\a2guard.exe"
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: BTTray.lnk = ?
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Download All by FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: Microsoft Excel'e Gö&nder - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\Billionton\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Araştır - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Billionton\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Billionton\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.com/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windows...b?1121513161560
O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe
O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Program Files\Billionton\Bluetooth Software\bin\btwdins.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - SOFTWIN S.R.L. - C:\Program Files\Softwin\BitDefender8\vsserv.exe
O23 - Service: BitDefender Communicator (XCOMM) - Softwin - C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe
ucanadam is offline   Reply With Quote


Old 07-27-2005, 08:39 PM   #6 (permalink)
Digaredd
 
Buzz1927's Avatar
 
Join Date: May 2005
Location: Melbourne AU
Posts: 7,617
Default

Download Ccleaner. Under Internet Explorer, uncheck "cookies". Then hit "Applications" and uncheck cookies in "Firefox". Then go to "options" and check "Run Ccleaner when computer starts". Then go to the "advanced" tab and uncheck "only delete files in windows temp folders older than 48 hours". Then run Ccleaner. Then try to reboot to normal mode.

Last edited by Buzz1927; 07-27-2005 at 08:47 PM.
Buzz1927 is offline   Reply With Quote
Old 07-27-2005, 08:45 PM   #7 (permalink)
New Member
 
Join Date: Apr 2005
Posts: 19
Default

that ccleaner link doesn't work
ucanadam is offline   Reply With Quote
Old 07-27-2005, 08:47 PM   #8 (permalink)
New Member
 
Join Date: Apr 2005
Posts: 19
Default

ok i downloaded it from somewhere else i will do what you said.
ucanadam is offline   Reply With Quote
Old 07-27-2005, 08:56 PM   #9 (permalink)
New Member
 
Join Date: Apr 2005
Posts: 19
Default

it didn't work...
ucanadam is offline   Reply With Quote
Old 07-27-2005, 09:21 PM   #10 (permalink)
Malware Destroyer
 
Byteman's Avatar
 
Join Date: Apr 2005
Location: Hurricane Heaven... still
Posts: 1,095
Default

It looks more like something else is your problem, other than malware. However, you do have something running from your temp file (usually a bad thing), delete it and reboot, see if that helps:
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\is-PQLGD.tmp\is-LFIC1.tmp

if still not fixed we may have to move this thread to the software or OS forum for resolution..
__________________
Don't byte off more than you can chew...
Byteman is offline   Reply With Quote
Reply

Bookmarks

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 10:35 AM.


Powered by: vBulletin Version 3.8.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.3.0 ©2009, Crawlability, Inc.