Scan your PC for Errors

Member Panel



Join the PC Help Forum Team

Join PC Help Forum on Facebook

Join the PCHF Distributed Computing Teams

Try the NEW PC Help Forum Dark style

Link to PCHF from other parts of the Internet
PC Forum PC Help Forum » Security & Safety » [Fixed] Hijackthis! Logs » [Resolved] PC Infected with "winupsvc" and I think there is more virus/trojan.

[Fixed] Hijackthis! Logs - [Resolved] PC Infected with "winupsvc" and I think there is more virus/trojan. posted in the Security & Safety forums; Hi I read and did all you guys said on http://www.pchelpforum.com/hijackthi...a-prework.html When AVG finished the update it didnīt say "Update succesfull message" but i tried to update again and it ...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #1  
Old 02-03-2007
Bronze Member
 
Join Date: Feb 2007
Posts: 6
PedroLuiz - See this Members User comments on their Profile page
Post [Resolved] PC Infected with "winupsvc" and I think there is more virus/trojan.

Hi I read and did all you guys said on
http://www.pchelpforum.com/hijackthi...a-prework.html
When AVG finished the update it didnīt say "Update succesfull message" but i tried to update again and it update the avgas.exe file and then i tried to update again and it said "no update was avaiable".
I think i am infected with "winupsvc".
I use Windows XP SP2.
Please if you guys see I am infected with more things than "winupsvc", help me solve the problem.
Thank you in advance,
Pedro Luiz
Sorry about the english, still learning.
On AVG Scan "Not-A-Virus.Monitor.Win32.007SpySoft.308" itīs not a virus itīs part of a program i installed to monitor people using my pc.

Logs are attached.
Attached Files
File Type: log hijackthis.log (7.8 KB, 2 views)
File Type: txt Report-Scan-20070203-140744.txt (1.9 KB, 2 views)


  #2  
Old 02-03-2007
Wolfeymole's Avatar
Resident WereWolf
 
Join Date: Nov 2006
Posts: 1,583
PC Experience: Enough to choke a Mule
Wolfeymole - See this Members User comments on their Profile page Wolfeymole - See this Members User comments on their Profile page Wolfeymole - See this Members User comments on their Profile page
Default

Hello Pedro

Welcome to PC Help Forums

Please do not apologise regarding your ability to speak English, it is very good.
A Hijack This specialist will assist you with this problem as soon as they come online.
Please be patient. Thank you.


__________________

  #3  
Old 02-04-2007
Bronze Member
 
Join Date: Feb 2007
Posts: 6
PedroLuiz - See this Members User comments on their Profile page
Default

Hi I see that you guys still dont have time to help me.
So i decided to download Spy Sweeper too, to try to make things easier.

When you guys say:
From the left pane, click Options.
Select the Sweep Options tab & ensure the following are ticked:
Windows Registry
Memory objects
Cookies
Compressed files
Do Not select System Restore Folder
Sweep All Users accounts
Enable Direct Disk Sweeping
Sweep For Rootkits

Itīs that i have to tick:
Windows Registry
Memory objects
Cookies
Compressed files

And do not tick:
Do Not select System Restore Folder
Sweep All Users accounts
Enable Direct Disk Sweeping
Sweep For Rootkits

Or i have only TO NOT tick:
Virus Sweep(itīs disabled), Rootkits and System Restore Folder

Anyway i will make a "Full Sweep Scan" and attach here. But if i have to change settings, tell me then i change and post another log.

Thanks again,
Pedro Luiz


  #4  
Old 02-04-2007
Pancake's Avatar
Senior Security Analyst
 
Join Date: Jun 2006
Location: Victoria, Australia
Posts: 4,079
PC Experience: Elite PC Guru
Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page
Default

Hello......

Please download the Killbox.
Run Killbox, left click and drag you mouse over the highlighted files below (including filepath) then right click and choose Copy (including filepath) with your mouse, rightclick and choose Copy. Insert your mouse pointer within the box entitled "Full Filepath of File to Delete", rightclick again and choose File > Paste from Clipboard. All the files should now appear in the box (click on the Tab and check to make sure that only the files I have identified as malware and marked for deletion are there). If each file exists, it will appear in blue under that window when you click on it. Click on Delete on Reboot. Next click on > "Delete on Reboot" and click on "All Files". Please do this even if this option is already checked. You will get a message saying "File with be deleted on next reboot, click "Yes". Process and Reboot now?" Click "Yes" to reboot


C:\WINDOWS\system32\winsecurityxp\mswinup.exe


Have "Hijack This" fix all the following items in the list below by placing a check in the appropriate boxes.Confirm that you have only the listed ones checked, then press <Fix checked> and Close HJT.

O4 - HKLM\..\Run: [MSWindowsUpdate] C:\WINDOWS\system32\winsecurityxp\mswinup.exe

Reboot and post a new HJT log....


__________________
  • An Australian Member of
  • and
My real name is Eddy
  #5  
Old 02-04-2007
Bronze Member
 
Join Date: Feb 2007
Posts: 6
PedroLuiz - See this Members User comments on their Profile page
Default

Hi Spy Sweeper found:
System Monitor found: ufp 007 spy
System Monitor found: spyanytime pcspy
But
System Monitor found: ufp 007 spy
I think its from the program 007 spy software i installed so no problem with it.
But is aw the log and i think itīs not a part of 007 spy.
But
System Monitor found: spyanytime pcspy
I donīt know if itīs from 007 spy software.(If itīs part of 007 spy if i delete it the program may not work anymore).
So i donīt know if itīs secure or not.
Spy Sweeper didnīt found the rootkit AVG found because i coudlnīt tick Rootkit on Spy Sweeper.(And i do not know the reason)

I set Spy Sweeper to fix all.
The log is attached.
Attached Files
File Type: txt Spy Sweeper Session Log.txt (8.0 KB, 1 views)
File Type: txt Spy Sweeper Session Log after quarantine.txt (8.7 KB, 1 views)


  #6  
Old 02-04-2007
Bronze Member
 
Join Date: Feb 2007
Posts: 6
PedroLuiz - See this Members User comments on their Profile page
Default

Weird i THink Spy Sweeper cleaned all, cause i coudlnīt delete the file because it disappeared and itīs not showing anymore on hijacksthis.

Here is the log.
Attached Files
File Type: txt hijackthis2.txt (8.0 KB, 1 views)


  #7  
Old 02-04-2007
Pancake's Avatar
Senior Security Analyst
 
Join Date: Jun 2006
Location: Victoria, Australia
Posts: 4,079
PC Experience: Elite PC Guru
Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page
Default

One more to fix then all done


Run Killbox, left click and drag you mouse over the highlighted files below (including filepath) then right click and choose Copy (including filepath) with your mouse, rightclick and choose Copy. Insert your mouse pointer within the box entitled "Full Filepath of File to Delete", rightclick again and choose File > Paste from Clipboard. All the files should now appear in the box (click on the Tab and check to make sure that only the files I have identified as malware and marked for deletion are there). If each file exists, it will appear in blue under that window when you click on it. Click on Delete on Reboot. Next click on > "Delete on Reboot" and click on "All Files". Please do this even if this option is already checked. You will get a message saying "File with be deleted on next reboot, click "Yes". Process and Reboot now?" Click "Yes" to reboot


C:\WINDOWS\system32\mswinup.exe


Reboot and post a new HJT log...


__________________
  • An Australian Member of
  • and
My real name is Eddy

Reply
Satellite TV on your PC - over 3000 Channels! Click Here!

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On

All times are GMT +1. The time now is 08:25 AM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top