Member Panel


Sponsors and Ads

Join the Team

Live Tag Cloud

PC Forum PC Help Forum » Security & Safety » [Fixed] Hijackthis! Logs » [Fixed] A troublesome virus

[Fixed] Hijackthis! Logs - [Fixed] A troublesome virus posted in the Security & Safety forums; Hello to all. While trying to scan my computer, it froze shortly after finding this file and one other: sd934k.exe and ws2.exe Some help on removing these would be greatly ...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #1  
Old 11-15-2005
Silver Member
 
Join Date: Oct 2005
Location: Where the President never stays...
Posts: 177
Gray - See this Members User comments on their Profile page
Send a message via Yahoo to Gray
Default [Fixed] A troublesome virus

Hello to all.

While trying to scan my computer, it froze shortly after finding this file and one other:

sd934k.exe

and

ws2.exe

Some help on removing these would be greatly appreciated. If this is the wrong thread to put it in, can someone move it for me?


  #2  
Old 11-15-2005
ladygreenwitch's Avatar
Elite Member
 
Join Date: Jul 2005
Location: Bay Area California
Posts: 4,643
ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page
Default

Hi Gray,

Welcome back, sorry to have it be under such negative circumstances though.

Can you please follow these instructions and then post back your logs?


To start with I would like you to do this:


First disable system restore to prevent re-infection.
(you can turn it back on when youre pc is clean).


How to disable system restore:

WinXP.

Click the Start button.
Right-click My Computer, and then click Properties.
On the System Restore tab, check Turn off System Restore or Turn off System Restore on all drives.

Make sure all files and folders are showing; Right click on My Computer, click on Explore, Tools, Folder Options, View. Make sure Show All Files and Folders is selected.

Clean out your computer
Please download CCleaner Install and run it, make sure that all options are selected including Advanced, answer OK to all warnings. Click on Analyze, when it has finished, click on Run Cleaner. Close out of CCleaner.


Do a virus scan Housecall. Also run Stinger - Trojan Remover.
If you get report of files that can?t be cleaned/deleted please write down the filenames and locations and post that in your reply.

Download Ewido Security Suite
  • Install Ewido Security Suite.
  • When installing, under Additional Options uncheck Install background guard and Install scan via context menu
  • Launch Ewido, there should be a big "E" icon on your desktop, double-click it.
  • The program will prompt you to update click the "OK" button
  • The program will now go to the main screen
  • You will need to update Ewido to the latest definition files.
  • On the left hand side of the main screen click update
  • Click on Start
  • The update will start and a progress bar will show the updates being installed.*
  • After the updates are installed, exit ewido.
Once the updates are installed do the following:
  • If you have an "always on" connection to the internet, physically disconnect that connection until you are finished with Safe Mode and have rebooted back into normal mode.
  • Reboot into Safe Mode, restart your computer, tap the F8* key. Use your up arrow key to highlight Safe Mode, then hit enter.
Close all open windows/programs/folders and then run Ewido.* Have nothing else open while ewido performs its scan!
  • Click on Scanner , Settings
  • Under "How to scan" all boxes should be selected
  • Under "Possibly unwanted software" all boxes should be selected
  • Under "What to scan" select scan every file
  • Click OK, Complete system scan
  • Let the program scan the machine
  • If ewido finds anything, it will pop up a notification.*
NOTE:* We have been finding some cases of false positives with the new version of Ewido, so you need to step through the fixes one-by-one.* If Ewido finds something that you KNOW is legitimate (for example, parts of AVG Antivirus, AOL, pcAnywhere and the game "Risk" have been flagged.* In particular, watch for alerts that have the word "Heuristic" in them - if you recognize the file name as "friendly," these may actually be false positives) select "none" as the action.*

DO NOT check "Perform action with all infections."* If you are unsure of an entry, select "none" for the time being.* We will see that in the log when you post it later and let you know if ewido needs to be run again.

Once the scan has completed, there will be a button located on the bottom of the screen named Save report.

Click Save report. Save the report to your desktop, exit ewido


Note:

If during your scan Ewido "crashes" or "hangs", please try scanning again. Before running the scan, click on 'Scanner' (the 3rd bar from the top on the left) and Choose 'Settings'. Uncheck 'Scan in NTFS Alternate Data Streams' as this can cause problems in overly infected systems. Click 'OK' and run a new scan.

Download HijackThis from my signature, make sure to install it into its own folder. Run it using the top option of saving a log file, save both the ewido and HijackThis logs back here.


Look forward to your reply,

TTFN

LGW


  #3  
Old 11-16-2005
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,044
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Looks like you have (atleast) an "Trojan.WinREG.LowZones" and a "Spyware/Virtumonde" infection.
But if you start with the instructions above , then we'll have that cleaned up in no time. :smiley:


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #4  
Old 11-16-2005
Silver Member
 
Join Date: Oct 2005
Location: Where the President never stays...
Posts: 177
Gray - See this Members User comments on their Profile page
Send a message via Yahoo to Gray
Default

Okay, CCleaner went well and I tried to do the TrendMicro scan, but basically, my computer froze and it seems to freeze whenever I try to scan. I did on the other hand, pick up these two files which rang up when I did the TrendMicro scan. They're attached...sorry it couldn't be more helpful.
Attached Files
File Type: txt Viruses.txt (53 Bytes, 5 views)


  #5  
Old 11-16-2005
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,044
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

That shows the presence of two more malware problems , But can you also post the Ewido and Hijackthis log?


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #6  
Old 11-16-2005
Silver Member
 
Join Date: Oct 2005
Location: Where the President never stays...
Posts: 177
Gray - See this Members User comments on their Profile page
Send a message via Yahoo to Gray
Default

Okay, here they are. The first is the Ewido log and the second is the HijackThis! log.
Attached Files
File Type: txt Scan report_20051116.txt.txt (20.8 KB, 3 views)
File Type: log hijackthis.log (9.1 KB, 5 views)



Reply
Satellite TV on your PC - over 3000 Channels! Click Here!

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On

Similar Threads
Thread Thread Starter Forum Replies Last Post
new virus? a nobody Security Watch 4 09-02-2005 01:20 AM
Microsoft hit by virus. joe5 Security Watch 0 08-30-2005 12:59 AM
[false positive] Virus Found In HijackThis ! Rod-O-Matic Security Watch 5 08-23-2005 06:48 PM
[Answered] Virus Infected Windows 2000 Server anteaus [Fixed] Hijackthis! Logs 6 08-09-2005 01:20 AM
[Fixed] Possible Virus problem.. Graham- [Fixed] Hijackthis! Logs 9 08-04-2005 10:22 PM


All times are GMT +1. The time now is 05:46 PM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top
Final Fantasy Soundtracks
Large selection of Final Fantasy content

2008 NFL Draft
The Jungle offers information on the 2008 NFL draft.

Mortgage Loans
Mortgage loans for any purpose, check out the great deals from Money Expert.