Member Panel


Sponsors and Ads

Live Tag Cloud

PC Forum PC Help Forum » Security & Safety » [Fixed] Hijackthis! Logs » [Answered] win32-gen-vc virus!

[Fixed] Hijackthis! Logs - [Answered] win32-gen-vc virus! posted in the Security & Safety forums; hey guys, im new here but i found this page whilst looking for information the virus i just found out i had. i was using avast when several alerts came ...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #1  
Old 06-06-2005
hayden49's Avatar
Bronze Member
 
Join Date: Jun 2005
Posts: 5
hayden49 - See this Members User comments on their Profile page
Default [Answered] win32-gen-vc virus!

hey guys,
im new here but i found this page whilst looking for information the virus i just found out i had. i was using avast when several alerts came up saying i had the win32-gen-vc virus? it was sumthing like that, yes i know i should taken a screen shot but i was panicing.
anyways, everything stopped responding and all my icons were dissapearing and weirds things like that so i installed avg and it found a heap of infected registry keys and deleted the nasty ones.
i made a HJT log which is here for you to view.
avg hasnt found any viruses since but ithe pc seems slow and now its saying i dont have an ATI driver installed, and when i install the newest one and restart, it still doesnt acnowladge that i have installed the new driver!
also, my HD is 200gb and i have broke it up into different partions e.g games, music, windows partition.
will the virus be in all of the partitions or just the windows one? i have scan all with avg but nothing has come up. now its just the driver that isnt behaving.
argg! help help help!
-hayden
Running processes:
F:\WINDOWS\System32\smss.exe
F:\WINDOWS\system32\winlogon.exe
F:\WINDOWS\system32\services.exe
F:\WINDOWS\system32\lsass.exe
F:\WINDOWS\system32\svchost.exe
F:\WINDOWS\System32\svchost.exe
F:\WINDOWS\system32\spoolsv.exe
F:\WINDOWS\Explorer.EXE
F:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
F:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
F:\WINDOWS\system32\ZoneLabs\vsmon.exe
F:\WINDOWS\SOUNDMAN.EXE
F:\Program Files\Microsoft Hardware\Keyboard\type32.exe
D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
F:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb0 7.exe
F:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
F:\Program Files\MessengerPlus! 3\MsgPlus.exe
F:\PROGRA~1\Grisoft\AVG7\avgcc.exe
F:\PROGRA~1\Grisoft\AVG7\avgemc.exe
F:\Program Files\MSN Messenger\msnmsgr.exe
F:\WINDOWS\System32\wuauclt.exe
F:\PROGRA~1\Grisoft\AVG7\avgwa.dat
F:\PROGRA~1\Grisoft\AVG7\avgw.exe
F:\WINDOWS\System32\taskmgr.exe
F:\PROGRA~1\MOZILL~1\FIREFOX.EXE
F:\Program Files\Windows Media Player\wmplayer.exe
F:\WINDOWS\System32\wuauclt.exe
D:\WinAce\WinAce.exe
F:\DOCUME~1\Hayden\LOCALS~1\Temp\~AceTemp\hijackth is\HijackThis.exe


  #2  
Old 06-06-2005
hayden49's Avatar
Bronze Member
 
Join Date: Jun 2005
Posts: 5
hayden49 - See this Members User comments on their Profile page
Default Re: win32-gen-vc virus!

O2 - BHO: DAPHelper Class - {0000CC75-ACF3-4cac-A0A9-DD3868E06852} - D:\Program Files\DAP\DAPBHO.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - F:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - F:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: DAP Bar - {62999427-33FC-4baf-9C9C-BCE6BD127F08} - D:\Program Files\DAP\DAPIEBar.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ATIPTA] F:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [IntelliType] "F:\Program Files\Microsoft Hardware\Keyboard\type32.exe"
O4 - HKLM\..\Run: [PRONoMgrWired] F:\Program Files\Intel\PROSetWired\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [NeroCheck] F:\WINDOWS\System32\\NeroCheck.exe
O4 - HKLM\..\Run: [Zone Labs Client] "D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] F:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb0 7.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] F:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "F:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Daily Weather Forecast] F:\Program Files\Daily Weather Forecast\weather.exe
O4 - HKLM\..\Run: [MessengerPlus3] "F:\Program Files\MessengerPlus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [AVG7_CC] F:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] F:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O4 - HKCU\..\Run: [Steam] "d:\valve\steam\steam.exe" -silent
O4 - HKCU\..\Run: [MessengerPlus3] "F:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [msnmsgr] "F:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: Adobe Reader Speed Launch.lnk = F:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &Download with &DAP - D:\PROGRA~1\DAP\dapextie.htm
O8 - Extra context menu item: Download &all with DAP - D:\PROGRA~1\DAP\dapextie2.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra button: Run DAP - {669695BC-A811-4A9D-8CDF-BA8C795F261C} - D:\PROGRA~1\DAP\DAP.EXE
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} (MetaStreamCtl Class) - https://components.viewpoint.com/MTS...s/3d/700_rifle
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...t.cab31267.cab
O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) - http://www.cult3d.com/download/cult.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.co...?1099376721530
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2...ll/xscan53.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/Ms...Downloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary...o.cab32846.cab
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - F:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - F:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - F:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - F:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - F:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - F:\WINDOWS\system32\ZoneLabs\vsmon.exe


  #3  
Old 06-06-2005
hayden49's Avatar
Bronze Member
 
Join Date: Jun 2005
Posts: 5
hayden49 - See this Members User comments on their Profile page
Default Re: win32-gen-vc virus!

cmon guys this is really really kicking my a$$... my pc is lagging really really badly and i have run like 30 anti virus programs but they find nothing!
please hepl!


  #4  
Old 06-06-2005
Zimbo's Avatar
Friend of PCHF
 
Join Date: Sep 2004
Location: Right here !
Posts: 2,150
Zimbo - See this Members User comments on their Profile page
Default Re: win32-gen-vc virus!

Howdy

To be honest your HJT log looks clear to me.

Run this program to try and detect any other nasty viruses (trojans) that may be on the system:
http://vil.nai.com/vil/stinger/

Viruses will be spread to any drive that you access often, so it is worth checking all partitions.

Lets try to sort your video card out:

? ? ? ? -? Boot your PC into safe mode and go to add/remove programs
? ? ? ? -? Try to uninstall your graphics driver from there, if you can't find anything then run this tool ATI removal tool

Also run a regcleaner program to help clear any unwanted / unused registry entries : Regclean

Once you have done all that, restart your PC and load the latest ATI drivers.
They can be found here.
https://support.ati.com/ics/support/...ge&folderID=27



Reply
New! Norton Internet Security 2008 – Download Now Click Here

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On


All times are GMT +1. The time now is 03:26 PM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top