Really nasty virus please help...

RoDDerz

Member
Hi all

Have been watching videos online for quite a long time now and have had a little trouble with viruses. But i've really come across a bunch of nasty one's this week.

At first my networking was completely bug**red but I finally managed to fix that. But the main problem is that i'm unable to open two of my most important anti virus programs. I've tried opening them in safe mode and it doesn't even work there. I've also reinstalled several times and even installed them in different places but still nothing. I click on the program and nothing happens...

I've had this once in the past and i'm convinced a virus of somesort is preventing them from opening but I just can't get it.

Also I ran a boot scan with "avast" (thankfully that runs) and it found something in system 32 but it said it was unable to repair or delete it.

secondly I had a message which said "system 32 error. "svhost"(maybe a fake svhost?) but that went away recently.

finally my system restore isn't working at all. I've tried about 5 different restore points...
 
System32 and svhost are (well can be) legit files on your windows installation. Sounds to me a lot like hijackware more than a virus to be honest.

Here is what I would do:

1) back up any data you cannot afford to lose. However, you should already have back ups, right? right?

2) boot into safe mode and run msconfig, and disable everything from running at start up. To do so just hit the disable all button.

3) reboot and run your AV software.

4) If all else fails wipe and reload.
 
The infections you have are stopping the programs from loading.

Please boot to safe mode on your machine.

Download the following file onto a usb flash drive and transfer it to the destop of the infected computer and run it. As you are saving it to download it, rename it to combo-fix, not combofix which is the default. This should spoof the infection and allow it to run. Please perfom all tasks listed.

Download and Run ComboFix
If you already have Combofix, please delete this copy and download it again as it's being updated regularly.
Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall

Combofix should never take more that 20 minutes including the reboot if malware is detected.

Please download Malwarebytes' Anti-Malware from here or here and save it to your desktop.
  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to
    • Update Malwarebytes' Anti-Malware
    • and Launch Malwarebytes' Anti-Malware
  • then click Finish.
  • If an update is found, it will download and install the latest version. Please keep updating until it says you have the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • A log will be saved automatically which you can access by clicking on the Logs tab within Malwarebytes' Anti-Malware


Download the HijackThis installer from here.
Run the installer and choose Install, indicating that you accept the licence agreement. The installer will place a shortcut on your desktop and launch HijackThis.

Click Do a system scan and save a logfile

Most of what HijackThis lists will be harmless or even essential, don't fix anything yet.

Post the logfile that HijackThis produces along with the Malwarebytes Anti-Malware log

In your next reply please post:
  • The ComboFix log
  • The Malwarebytes log
  • A fresh HiJackThis log
  • An update on how your computer is running
 
The combo fix exe. won't open :/. I saved it directly onto the flash drive and copied it to desktop like you said
 
i'm on safemode with networking could that be the issue? I could download the file from my laptop and then transfer it?
 
Did you save it as combo-fix instead of combofix? If that still don't work download and run rkill.scr. If it runs successfully you will see a log pop up on the screen telling you what it killed. Then you should be able to run combofix.
 
Ok a pretty bad update here

my laptop is now in an even worse state than my desktop. I plugged in my portable hard drive this morning and suddenly a virus was detected on AVG a few mins later.

The virus has literally gone through every single program on the computer and infected it. Loads of stuff including some of the core programs for the touch pad...managing the processor speed....photoshop...and even the sound drivers don't work. I'm currently on safe mode.

I'm assuming it's the same virus but it hasn't behaved at all like it has on the laptop. The only thing in common is that the sound won't work in the same way.

I've scanned the whole hard drive on my friends computer with two good programs and have found nothing..
 
Yeh i'm guna do that for the laptop. For the desktop I think i'm guna get windows 7.

Just for my own knowledge and curiosity i'll keep trying to fix them. Here's the combofix log




ComboFix 10-10-05.06 - Rhodri Spearing 06/10/2010 18:37:28.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2039.1558 [GMT 1:00]
Running from: c:\documents and settings\Rhodri Spearing\Desktop\Combo-Fix.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Application Data\Macromedia\SwUpdate
c:\documents and settings\All Users\Application Data\Macromedia\SwUpdate\Flags.dtd
c:\documents and settings\Rhodri Spearing\Application Data\Ynfo\fayq.exe
c:\documents and settings\Rhodri Spearing\GoToAssistDownloadHelper.exe
C:\install.exe
c:\program files\EeePC\ACPI\AsAcpiSvr.exe
c:\program files\EeePC\ACPI\AsEPCMon.exe
c:\program files\EeePC\ACPI\AsTray.exe
c:\program files\Elantech\ETDCtrl.exe
c:\program files\Elantech\ETDDect.exe
c:\program files\Microsoft\DesktopLayer.exe
c:\program files\QuickTime\QTTask.exe
c:\windows\system32\drivers\adnwvmdy.sys
c:\windows\system32\drivers\atmaafh.sys
c:\windows\system32\drivers\cgnpk.sys
c:\windows\system32\drivers\tees.sys
c:\windows\system32\PRAGMAsrcr.dat

Infected copy of c:\windows\system32\drivers\acpiec.sys was found and disinfected
Restored copy from - Kitty had a snack :p
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_bltvfk
-------\Legacy_psnnxu
-------\Legacy_qikgsue
-------\Legacy_vvcvqxvy
-------\Service_bltvfk
-------\Service_psnnxu
-------\Service_qikgsue
-------\Service_vvcvqxvy


((((((((((((((((((((((((( Files Created from 2010-09-06 to 2010-10-06 )))))))))))))))))))))))))))))))
.

2010-10-06 16:03 . 2010-10-06 16:03 -------- d-----w- c:\program files\sys23
2010-10-06 15:13 . 2010-10-06 16:39 737280 ----a-w- c:\documents and settings\Rhodri Spearing\Application Data\Spotify\Gracenote\gnsdk_sdkmanager.dll
2010-10-06 15:13 . 2010-10-06 16:39 364544 ----a-w- c:\documents and settings\Rhodri Spearing\Application Data\Spotify\Gracenote\gnsdk_musicid_file.dll
2010-10-06 15:13 . 2010-10-06 16:39 290816 ----a-w- c:\documents and settings\Rhodri Spearing\Application Data\Spotify\Gracenote\gnsdk_dsp.dll
2010-10-06 14:39 . 2010-10-06 14:39 -------- d-----w- c:\documents and settings\Rhodri Spearing\Application Data\Utowty
2010-10-06 14:39 . 2010-10-06 14:39 -------- d-----w- c:\documents and settings\Rhodri Spearing\Application Data\Isacut
2010-09-23 10:42 . 2010-09-23 10:42 1690952 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgupd.dll
2010-09-08 14:59 . 2010-09-08 14:59 -------- d-----w- c:\program files\NOS
2010-09-08 14:59 . 2010-08-13 08:13 35136 ----a-w- c:\documents and settings\Rhodri Spearing\Application Data\Mozilla\Firefox\Profiles\vbvkc72u.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll
2010-09-08 14:59 . 2010-08-13 08:13 32032 ----a-w- c:\documents and settings\Rhodri Spearing\Application Data\Mozilla\Firefox\Profiles\vbvkc72u.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\chrome\content\getPlusPlus_Adobe_reg.exe
2010-09-07 12:04 . 2008-04-14 12:00 26112 ----a-w- c:\windows\system32\stu2.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-10-06 17:44 . 2010-03-02 17:11 -------- d-----w- c:\program files\QuickTime
2010-10-06 17:44 . 2009-11-30 13:59 -------- d-----w- c:\program files\Microsoft
2010-10-06 17:44 . 2008-06-27 07:40 -------- d-----w- c:\program files\Elantech
2010-10-06 17:44 . 2009-06-06 16:44 -------- d-----w- c:\documents and settings\Rhodri Spearing\Application Data\Ynfo
2010-10-06 17:26 . 2009-12-09 18:26 -------- d-----w- c:\documents and settings\Rhodri Spearing\Application Data\Spotify
2010-10-06 16:03 . 2009-06-13 21:13 -------- d-----w- c:\documents and settings\Rhodri Spearing\Application Data\Neolke
2010-10-06 15:23 . 2009-02-08 19:10 -------- d-----w- c:\program files\Audacity
2010-10-06 15:03 . 2010-05-11 15:38 0 ----a-w- c:\documents and settings\Rhodri Spearing\Local Settings\Application Data\prvlcl.dat
2010-10-06 14:34 . 2008-11-11 22:59 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-09-08 15:00 . 2009-10-04 11:05 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2010-09-02 12:38 . 2010-09-02 12:38 -------- d-----w- c:\documents and settings\All Users\Application Data\Trusteer
2010-08-20 13:38 . 2008-11-11 21:13 -------- d-----w- c:\documents and settings\Rhodri Spearing\Application Data\Skype
2010-08-20 13:36 . 2008-11-11 23:10 -------- d-----w- c:\documents and settings\Rhodri Spearing\Application Data\skypePM
2010-08-12 12:35 . 2008-11-11 19:24 7100 -c--a-w- c:\documents and settings\Rhodri Spearing\Application Data\wklnhst.dat
2010-08-07 17:53 . 2008-11-11 19:20 -------- d-----w- c:\documents and settings\Rhodri Spearing\Application Data\BitTorrent
2010-07-21 09:12 . 2008-11-12 15:43 243024 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-07-21 09:12 . 2010-07-21 09:12 12536 ----a-w- c:\windows\system32\avgrsstx.dll
2010-07-21 09:12 . 2008-11-12 15:43 29584 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-07-21 09:11 . 2008-11-12 15:43 216400 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2008-05-07 23:34 . 2008-06-27 06:48 15523560 ----a-w- c:\program files\U1 Setup.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-12-19 159744]
"RTHDCPL"="RTHDCPL.EXE" [2008-05-26 16862720]
"SoundMan"="SOUNDMAN.EXE" [2006-07-21 86016]
"AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2010-10-05 2067808]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\Rhodri Spearing\Start Menu\Programs\Startup\
ObjectDock.lnk - c:\program files\Stardock\ObjectDock\ObjectDock.exe [2010-1-3 3450608]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-07-21 09:12 12536 ----a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2009-12-18 07:58 40368 ----a-w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeUpdater]
2008-09-26 10:02 2356088 ----a-r- c:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
2005-05-04 01:43 69632 ----a-w- c:\windows\Alcmtr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcWzrd]
2006-05-04 23:26 2808832 ----a-w- c:\windows\alcwzrd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 12:00 15360 ----a-w- c:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2010-02-15 18:07 141608 ----a-w- c:\program files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes Anti-Malware (rootkit-scan)]
2010-04-29 14:39 1090952 ----a-w- c:\program files\Malwarebytes' Anti-Malware\mbam.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
2009-07-26 16:44 3883856 ----a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]
2007-12-19 15:07 131072 ----a-r- c:\windows\system32\igfxpers.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
2006-11-03 18:20 866584 ----a-w- c:\program files\Windows Defender\MSASCui.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\Last.fm\\LastFM.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\AVS4YOU\\Registration.exe"=
"c:\\Program Files\\AVS4YOU\\AVSUpdateManager\\AVSUpdateManager.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Spotify\\spotify.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [12/11/2008 16:43 216400]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [12/11/2008 16:43 243024]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [21/07/2010 10:12 308136]
R3 RT80x86;Ralink 802.11n Wireless Driver;c:\windows\system32\drivers\rt2860.sys [27/06/2008 06:36 933504]
R3 tenCapture;tenCapture;c:\windows\system32\drivers\tenCapture.sys [21/04/2007 15:15 9344]
R3 VCSVADHWSer;Avnex Virtual Audio Device (WDM);c:\windows\system32\drivers\vcsvad.sys [26/08/2009 20:45 17792]
S2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [03/11/2006 19:19 13592]
S3 nosGetPlusHelper;getPlus(R) Helper 3004;c:\windows\System32\svchost.exe -k nosGetPlusHelper [27/06/2008 06:13 14336]
S3 SCREAMINGBDRIVER;Screaming Bee Audio;c:\windows\system32\drivers\ScreamingBAudio.sys [06/04/2009 13:19 23064]
S3 XoftSpyService;XoftSpyService;c:\program files\Common Files\XoftSpySE\6\xoftspyservice.exe [28/08/2009 22:15 582424]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
nosGetPlusHelper REG_MULTI_SZ nosGetPlusHelper
.
Contents of the 'Scheduled Tasks' folder

2010-10-01 c:\windows\Tasks\ParetoLogic Registration3.job
- c:\program files\Common Files\ParetoLogic\UUS3\UUS3.dll [2009-08-28 21:15]

2010-09-10 c:\windows\Tasks\ParetoLogic Update Version3.job
- c:\program files\Common Files\ParetoLogic\UUS3\Pareto_Update3.exe [2009-08-28 21:15]

2010-04-07 c:\windows\Tasks\XoftSpySE.job
- c:\program files\XoftSpySE6\XoftSpySELauncher.exe [2009-08-28 13:57]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.thegrumpyoldgits.co.uk/
uInternet Connection Wizard,ShellNext = wmplayer.exe //ICWLaunch
uInternet Settings,ProxyOverride = <local>
uInternet Settings,ProxyServer = http=127.0.0.1:5555
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
IE: Send to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send To Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
FF - ProfilePath - c:\documents and settings\Rhodri Spearing\Application Data\Mozilla\Firefox\Profiles\vbvkc72u.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk/
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - plugin: c:\documents and settings\Rhodri Spearing\Application Data\Mozilla\Firefox\Profiles\vbvkc72u.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX POLICIES ----
FF - user.js: network.cookie.cookieBehavior - 0
FF - user.js: privacy.clearOnShutdown.cookies - false
FF - user.js: security.warn_viewing_mixed - false
FF - user.js: security.warn_viewing_mixed.show_once - false
FF - user.js: security.warn_submit_insecure - false
FF - user.js: security.warn_submit_insecure.show_once - false
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-{4A03A45A-7427-82F5-C866-A62F02BAD76C} - c:\documents and settings\Rhodri Spearing\Application Data\Ynfo\fayq.exe
HKLM-Run-AsusTray - c:\program files\EeePC\ACPI\AsTray.exe
HKLM-Run-AsusACPIServer - c:\program files\EeePC\ACPI\AsAcpiSvr.exe
HKLM-Run-AsusEPCMonitor - c:\program files\EeePC\ACPI\AsEPCMon.exe
HKLM-Run-ETDWare - c:\program files\Elantech\ETDCtrl.exe
HKLM-Run-ETDWareDetect - c:\program files\Elantech\ETDDect.exe
MSConfigStartUp-net - c:\windows\system32\net.net
MSConfigStartUp-QuickTime Task - c:\program files\QuickTime\QTTask.exe


.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'explorer.exe'(3620)
c:\program files\Stardock\ObjectDock\DockShellHook.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\btncopy.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\program files\AVG\AVG9\avgchsvx.exe
c:\program files\AVG\AVG9\avgrsx.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\CTsvcCDA.exe
c:\program files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
c:\program files\AVG\AVG9\avgnsx.exe
c:\windows\RTHDCPL.EXE
c:\windows\SOUNDMAN.EXE
.
**************************************************************************
.
Completion time: 2010-10-06 18:52:55 - machine was rebooted
ComboFix-quarantined-files.txt 2010-10-06 17:52

Pre-Run: 7,815,274,496 bytes free
Post-Run: 7,681,318,912 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

- - End Of File - - CC6ED36A818AAFDB4D1227C572F07772
 
As for malware bytes I already have it and have ran it on the laptop finding a couple of things which seemed to do very little. But on the desktop it's one of the programs that the virus is preventing from running
 
I need to see the malwarebyes and hijackthis log for the computer that you just posted the combofix log for. The combofix log still shows some infections but I would like to see the malwarebytes and hijactkhis logs before I have you run a script.
 
Back
Top