Windows 7 Support
Become a Fan of PCHF on Facebook!
User Reviews - Add Yours!
The PCHF Lounge
Go Back   PC Help Forum » Security & Safety » [Pending] HJT Logs
Register for a Free Account

[Pending] HJT Logs - Registry affected by virus? posted in the Security & Safety forums; Hello, I just recently got hit with a pretty virus, or so I believe. Immediately after Norton picked up the virus, I ran Malwarebytes' Anti-Malware. It detected a few viruses ...

Advertisement
Advertisement

Reply
Recommended Driver Scanner
Old 04-18-2009   #1
Bronze Member
 
Join Date: Apr 2009
Posts: 7
PC Experience: Beginner
Default Registry affected by virus?

Hello,

I just recently got hit with a pretty virus, or so I believe. Immediately after Norton picked up the virus, I ran Malwarebytes' Anti-Malware. It detected a few viruses that affected the registry key and asked me to restart the computer to remove it.

However, after the restart, instead of the blue welcome screen, I saw a log in screen of that which was just like the Windows 98's. I entered my password and waited for explorer to start up. I then noticed that all I could see was my desktop background and my mouse cursor.

I restarted the computer in safe mode, disabled system restore, and ran MBAM and SUPERAntiSpyware as well. They detected a total of about 20 viruses. I deleted them as prompted and restarted the computer.

Yet again, I was back to the desktop background with no icons or taskbar. I brought up the task manager in attempts to run an exe file, but DEP kept blocking everything.

I went back into safe mode and disabled DEP. I restarted the computer regularly, and I could see the blue welcome screen. Thinking that the problem had been fixed, I logged on. Just to doublecheck, I decided to rerun MBAM. Immediately, I got a prompt from Norton that the MBAM.exe is a threat, and it automatically deleted the source. When I tried to reinstall it, the same thing happened. From then on, whatever this virus is started deleting my useful .exe files such as my ATF-Registry Cleaner. When I attempted to go to anti-malware websites, the browser (IE and Firefox) shut down. After about 30 prompts of virus threats from Norton, I gave up and am currently using safe mode to get what I need.

I've installed and run MBAM (most likely not up to date) in safe mode and deleted the registry problems. I ran it again few more times, and my computer appeared to be clean. So, I restarted normally and still got the same problem. What should I do?

Here are a few things that may help:
Specs
- Windows XP Professional
-Version 2002
-SP2
-2.0 GHz
-.99GB RAM
A dll file that keeps appearing under C:/Avenger, after being removed
-phxmsi.dll (U.s. Robots shutdown helper?)
-I never recall installing Avenger
I cannot get access to the internet using my cpu except at risk of getting more infections (I do have other pcs I could use).

Please help me out. I have 3 years worth of college data on my harddrive...Thank you.
southernirishnd is offline   Reply With Quote
Old 04-18-2009   #2
Stoooooopid Girl.
 
Jelly Bean's Avatar
 
Join Date: Feb 2008
Location: Swansea
Posts: 12,803
PC Experience: None.
Default Re: Registry affected by virus?

Hello and welcome to PCHelpForum.

Let us firstly have our Security Tea to fully check you are clean.

I recommend you have a system health check.

Please click this:Prework

Follow the instructions then copy and paste the results of Hijackthis and Malwarebytes back here on your thread.

I will then move your thread to the NEW Hijackthis Section in readyness for our excellent Security Team to help you further and give you any fixes that are required.

If you have trouble connecting to the internet or downloading the software then you can use another computer.

Download and save the software files to the computer,then copy the software to a CD/DVD,floppy disk,USB pen drive or even an external hard drive.You can then transfer the software to the problem computer.

You can also run in safe mode with networking if needs be.Restart the computer and repeatedly tap F8 and choose safe mode with networking.


If you need further help please feel free to ask.

Jelly Bean.
__________________
Rwy'n ceisio fy ngorau.
Jelly Bean is offline   Reply With Quote
Old 04-18-2009   #3
Bronze Member
 
Join Date: Apr 2009
Posts: 7
PC Experience: Beginner
Default Re: Registry affected by virus?

I can only run .exe in safemode. Would the logs be adequate if they were run in safemode?
southernirishnd is offline   Reply With Quote
Old 04-18-2009   #4
Stoooooopid Girl.
 
Jelly Bean's Avatar
 
Join Date: Feb 2008
Location: Swansea
Posts: 12,803
PC Experience: None.
Default Re: Registry affected by virus?

Yes you can run in safe mode.
__________________
Rwy'n ceisio fy ngorau.
Jelly Bean is offline   Reply With Quote
Old 04-18-2009   #5
Bronze Member
 
Join Date: Apr 2009
Posts: 7
PC Experience: Beginner
Default Re: Registry affected by virus?

Here you go:

Malwarebytes' Anti-Malware 1.36
Database version: 1945
Windows 5.1.2600 Service Pack 2
4/18/2009 8:32:39 AM
mbam-log-2009-04-18 (08-32-39).txt
Scan type: Full Scan (C:\|)
Objects scanned: 129512
Time elapsed: 1 hour(s), 4 minute(s), 8 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:35:14 AM, on 4/18/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Safe mode
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\igfxsrvc.exe
C:\Documents and Settings\Administrator\Application Data\U3\0000184F74701755\LaunchPad.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX00.422\Hi jackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Live Search
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Live Search
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = MSN.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = *.local
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\stsystra.exe
O4 - HKLM\..\Run: [PC-Checkup] "C:\PC-Checkup\PCCheckUp.exe" -mini
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\cat\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [AdobeUpdater] C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
O4 - HKCU\..\Run: [Active Desktop Calendar] C:\Program Files\XemiComputers\Active Desktop Calendar\ADC.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\gvwgpa3i4.exe
O4 - HKUS\S-1-5-20\..\Run: [fowivewase] Rundll32.exe "C:\WINDOWS\system32\pagavehe.dll",s (User 'NETWORK SERVICE')
O4 - S-1-5-18 Startup: WireChanger.lnk = C:\Program Files\WiredPlane\WireChanger\WireChanger.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: WireChanger.lnk = C:\Program Files\WiredPlane\WireChanger\WireChanger.exe (User 'Default user')
O4 - Startup: WireChanger.lnk = C:\Program Files\WiredPlane\WireChanger\WireChanger.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://pccheckup.dellfix.com/sdccomm...ad/tgctlcm.cab
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/...oUploader5.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Background Intelligent Transfer Service (BITS) - Unknown owner - C:\WINDOWS\
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\McAfee\Common Framework\FrameworkService.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE
--
End of file - 7008 bytes
southernirishnd is offline   Reply With Quote
Old 04-18-2009   #6
Stoooooopid Girl.
 
Jelly Bean's Avatar
 
Join Date: Feb 2008
Location: Swansea
Posts: 12,803
PC Experience: None.
Default Re: Registry affected by virus?

Thankyou moved to NEW HJT Section.

As you deleted regkeys you may need to do:

In XP click on start then open the run box.

Type in the run box cmd and hit the ok button.

Copy and paste in scf /scannow and put in the XP install disk and hit enter on your keyboard.

Let sfc /scannow run.

Please post results.

Note: sfc /scannow is sfc "space" /scannow.


In Vista click start/All Programs/Accessories/Right click on command prompt and choose run as Admin.

Copy and paste in the command prompt window sfc /scannow and hit enter on your keyboard.Let sfc /scannow now run.

Please post results.

Note: sfc /scannow is sfc "space" /scannow.
__________________
Rwy'n ceisio fy ngorau.
Jelly Bean is offline   Reply With Quote
Old 04-18-2009   #7
Bronze Member
 
Join Date: Apr 2009
Posts: 7
PC Experience: Beginner
Default Re: Registry affected by virus?

Thank you for the quick response.

I typed in "sfc /scannow" in the command window with the Windows XP Professiona SP2 CD. This was the error message that I got:

Windows File Protection could not initiate a scan of protected system files.
The specific error code is 0x000006ba [The RPC server is unavailable.].
southernirishnd is offline   Reply With Quote

Reply

Bookmarks

Tags
affected, Pending:, registry, virus, [Pending]
Similar discussions...
Thread Thread Starter Forum Replies Last Post
Question: html pages are affected by a unwanted link soumyanaskar Anti-Virus 3 02-16-2009 05:30 PM
Virus and registry Ron Mollins Peripherals 7 04-27-2008 09:44 PM
<News> Skype Outage Continues For Some, Businesses Affected Newsie IT News 0 08-18-2007 07:30 AM
<News> Palm Revenues Affected by Treo 750 Delay Newsie IT News 0 11-29-2006 06:30 AM
PC now virus free, but still a few annoying registry problems, ash182 Windows XP/2000 5 02-06-2006 07:03 PM

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On




All times are GMT. The time now is 09:06 PM.
Powered by vBulletin
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.3.2