Virus Problem !!!!! (Resolved)

  1. #11
    owen is offline D-A-L Team Member (UK)

    Re: Virus Problem !!!!!

    Hello

    Go to Start> Run. Copy and paste the bold text in the box:

    regedit /e c:\txtprtcl.txt "HKEY_CLASSES_ROOT\PROTOCOLS\Filter\text/plain"

    Click OK.

    A file will be made called txtprtcl.txt that can be found in the root (c:\txtprtcl.txt).

    If this file isn’t created, it should suffice to fix the above items with HijackThis.

    Upload the logfile created in your next reply by clicking Manage Attachments below the Post Reply box. Click Browse and locate the file and then click Upload.


  2. #12
    ant33 is offline Newbie
    Owen

    Once again thanks.
    Hopefully I am getting somewhere?. Again I have done as requested but I am not sure whether I have correctly followed your procedure for the manage attatchments section so I have copied and pasted the log below just in case (sorry still learning)

    Logfile of HijackThis v1.98.2
    Scan saved at 10:16:42, on 21/09/2004
    Platform: Windows ME (Win9x 4.90.3000)
    MSIE: Internet Explorer v5.50 (5.50.4134.0100)

    Running processes:
    C:\WINDOWS\SYSTEM\KERNEL32.DLL
    C:\WINDOWS\SYSTEM\MSGSRV32.EXE
    C:\WINDOWS\SYSTEM\mmtask.tsk
    C:\WINDOWS\SYSTEM\MPREXE.EXE
    C:\WINDOWS\SYSTEM\MSTASK.EXE
    C:\WINDOWS\SYSTEM\SSDPSRV.EXE
    C:\PROGRAM FILES\COMMON FILES\EPSON\EBAPI\SAGENT2.EXE
    C:\WINDOWS\SYSTEM\STIMON.EXE
    C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE
    C:\PROGRAM FILES\GRISOFT\AVG6\AVGSERV9.EXE
    C:\WINDOWS\EXPLORER.EXE
    C:\WINDOWS\SYSTEM\RPCSS.EXE
    C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
    C:\WINDOWS\TASKMON.EXE
    C:\WINDOWS\SYSTEM\SYSTRAY.EXE
    C:\WINDOWS\STARTER.EXE
    C:\PROGRAM FILES\LOGITECH\MOUSEWARE\SYSTEM\EM_EXEC.EXE
    C:\WINDOWS\SYSTEM\DDHELP.EXE
    C:\PROGRAM FILES\MCAFEE\QUICKCLEAN\PLGUNI.EXE
    C:\PROGRAM FILES\GRISOFT\AVG6\AVGCC32.EXE
    C:\WINDOWS\SYSTEM\WMIEXE.EXE
    C:\WINDOWS\SYSTEM\SPOOL32.EXE
    C:\WINDOWS\SYSTEM\TAPISRV.EXE
    C:\WINDOWS\SYSTEM\RNAAPP.EXE
    C:\PROGRAM FILES\HIJACK THIS\HIJACKTHIS.EXE

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\SYSTEM\EEAF.DLL/sp.html (obfuscated)
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\SYSTEM\EEAF.DLL/sp.html (obfuscated)
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\SYSTEM\EEAF.DLL/sp.html (obfuscated)
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\SYSTEM\EEAF.DLL/sp.html (obfuscated)
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\SYSTEM\EEAF.DLL/sp.html (obfuscated)
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\SYSTEM\EEAF.DLL/sp.html (obfuscated)
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL
    O2 - BHO: (no name) - {E70CAD2A-3354-47F5-8958-070F6747E350} - C:\WINDOWS\SYSTEM\EEAF.DLL (file missing)
    O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
    O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
    O4 - HKLM\..\Run: [PCHealth] C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s
    O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
    O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    O4 - HKLM\..\Run: [EnsoniqMixer] starter.exe
    O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\LOGITECH\MOUSEW~1\SYSTEM\EM_EXEC.EXE
    O4 - HKLM\..\Run: [AttuneSysTray] C:\PROGRA~1\AVEO\ATTUNE\Bin\Attune_st.exe /boot
    O4 - HKLM\..\Run: [AtiCwd32] Aticwd32.exe
    O4 - HKLM\..\Run: [AtiQiPcl] AtiQiPcl.exe
    O4 - HKLM\..\Run: [AtiPTA] Atiptaxx.exe
    O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
    O4 - HKLM\..\Run: [Imonitor] "C:\Program Files\McAfee\QuickClean\Plguni.exe" /START
    O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\GRISOFT\AVG6\avgcc32.exe /STARTUP
    O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
    O4 - HKLM\..\RunServices: [SSDPSRV] C:\WINDOWS\SYSTEM\ssdpsrv.exe
    O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
    O4 - HKLM\..\RunServices: [SAgent2ExePath] C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
    O4 - HKLM\..\RunServices: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
    O4 - HKLM\..\RunServices: [TrueVector] C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE -service
    O4 - HKLM\..\RunServices: [Avgserv9.exe] C:\PROGRA~1\GRISOFT\AVG6\Avgserv9.exe
    O4 - HKCU\..\Run: [McAfee.InstantUpdate.Monitor] "C:\Program Files\McAfee\McAfee Shared Components\Instant Updater\RuLaunch.exe" /STARTMONITOR
    O4 - HKCU\..\Run: [Adaware Bootup] C:\PROGRAM FILES\LAVASOFT AD-AWARE\AD-AWARE.EXE /Auto /Log "C:\PROGRAM FILES\LAVASOFT AD-AWARE\"
    O4 - Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\SYSTEM\E_SRCV02.EXE
    O4 - Startup: ATISched.lnk = C:\ATI\ATIDESK\atisched.exe
    O4 - Global Startup: ZoneAlarm.lnk = C:\Program Files\Zone Labs\ZoneAlarm\zonealarm.exe
    O8 - Extra context menu item: &Google Search - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmsearch.html
    O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmcache.html
    O8 - Extra context menu item: Si&milar Pages - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmsimilar.html
    O8 - Extra context menu item: Backward &Links - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmbacklinks.html
    O8 - Extra context menu item: Translate into English - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmtrans.html
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSEN~1\MSMSGS.EXE
    O9 - Extra 'Tools' menuitem: MSN Messenger Service - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSEN~1\MSMSGS.EXE
    O15 - Trusted Zone: http://*.216.187.80.232
    O16 - DPF: {C81B5180-AFD1-41A3-97E1-99E8D254DB98} (CSS Web Installer Class) - http://www.command2.co.uk/cod_ev/cabs/cssweb.cab
    O18 - Filter: text/html - {E2A8B62D-7D07-45A2-A09B-5BED0CCA87F1} - C:\WINDOWS\SYSTEM\EEAF.DLL
    O18 - Filter: text/plain - {E2A8B62D-7D07-45A2-A09B-5BED0CCA87F1} - C:\WINDOWS\SYSTEM\EEAF.DLL

    Thanks ant33

    PS for info when I run AGV It still detects that I have 8 files infected with the Trojan virus which it is unable to place in the vault. All 8 are located in
    c:\_RESTORE\TEMP\A0002857.CPY

  3. #13
    owen is offline D-A-L Team Member (UK)
    I'm sure I replyed to this post, I can remember writing the reply...

    Anyway, your system has saved a copy of the virus in System Restore and your antivirus program is unable to access System Restore. Follow the instructions for Windows Me here and disable then Reenable System Restore to flush the contents and get rid of the Trojan.

    You haven't attached the file correctly.

    Follow these instructions to upload the log:
    1. Come back to this thread and click the button

    2. Beneath the Reply box is button that says Manage Attachments. Press Manage Attachments

    3. A popup windows will appear. Click the browse button and locate the file. Click it and then click Ok. The Browse... window will then close.

    4. Below the Browse button, click Upload. The log will upload and the name of the file will appear above the Upload button.

    5. Close the popup window and type your reply and post it.

  4. #14
    ant33 is offline Newbie
    Owen

    Once again thanks for all the help to date.

    The latest advice seems to have got rid of the Trojan and the previous advice seems have my browser working fine. Lets hope once you've checked my latest Hijack This Log my PC might be given a clean bill of health.

    Heres hoping.

    PS I hope I have attached the file correctly. I did the same last time but it did not attach as the file (hijackthis.log) was not recognised. I have therfore saved it as a .doc file in word, please tell me I've got something right.
    Attached Files

  5. #15
    owen is offline D-A-L Team Member (UK)
    Hiya,
    You've got the attaching right- but you have attached the wrong log.

    Follow these instructions and then upload the log created by this procedure:

    Go to Start> Run. Copy and paste the bold text in the box:

    regedit /e c:\txtprtcl.txt "HKEY_CLASSES_ROOT\PROTOCOLS\Filter\text/plain"

    Click OK.

    A file will be made called txtprtcl.txt that can be found in the root (c:\txtprtcl.txt).

  6. #16
    ant33 is offline Newbie
    owen

    Heres hoping third time lucky

    ant33
    Attached Files

  7. #17
    owen is offline D-A-L Team Member (UK)
    Third time is very lucky. I'll write up the removal instructions now.

  8. #18
    owen is offline D-A-L Team Member (UK)
    I will get back to your tommorow. I'm off for the night now. Midnight.

  9. #19
    owen is offline D-A-L Team Member (UK)
    To anybody reading this thread, do not try to use hijacktools.zip on your computer, the fix is specific to ant33's computer

    Hello ant33,
    Could you please download the file I have attached called hijacktools.zip. Then close all running programs. You may want to print these instructions.

    Unzip the file and copy all three files (cwstemp.bat, cwsuni.exe and cwsreg.reg) into your C:\Windows folder.

    Then go to Start> Run and type cmd

    When the windows appears type the following:
    Type cd.. Press Enter
    Type cd.. again. Press Enter
    Type cd windows. Press Enter
    Type cwstemp.bat. Press Enter and allow the file to run.
    Type explorer.exe

    When you are done, close all browser windows, restart Hijack This and put a checkmark next to the following entries:

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\SYSTEM\EEAF.DLL/sp.html (obfuscated)
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\SYSTEM\EEAF.DLL/sp.html (obfuscated)
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\SYSTEM\EEAF.DLL/sp.html (obfuscated)
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\SYSTEM\EEAF.DLL/sp.html (obfuscated)
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\SYSTEM\EEAF.DLL/sp.html (obfuscated)
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\SYSTEM\EEAF.DLL/sp.html (obfuscated)
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
    O2 - BHO: (no name) - {E70CAD2A-3354-47F5-8958-070F6747E350} - C:\WINDOWS\SYSTEM\EEAF.DLL (file missing)
    O15 - Trusted Zone: http://*.216.187.80.232
    O18 - Filter: text/html - {E2A8B62D-7D07-45A2-A09B-5BED0CCA87F1} - C:\WINDOWS\SYSTEM\EEAF.DLL
    O18 - Filter: text/plain - {E2A8B62D-7D07-45A2-A09B-5BED0CCA87F1} - C:\WINDOWS\SYSTEM\EEAF.DLL

    Click Fix Checked

    Then reboot and post a fresh log
    Attached Files
    Last edited by owen; 24-09-2004 at 09:41 AM.

  10. #20
    ant33 is offline Newbie
    Save 20% on AVG Internet Security 2012 Suite!
    Hi Owen

    Once again I have done exactly as requested but things never seem to be as straight forward as the e-mail sounds (maybe its just me).

    Downloaded the file, closed all running programs, copied 3 files to c:\Windows
    went to Start> Run typed cmd got this reply

    Windows cannot find 'cmd'. You may have typed the name incorrectly in the Run Dialog or another programme cannot find a system file. To search for a file, click the Start button and click Search.

    I did a search for cmd and ended up with list too long to type. So Im sorry its back to you for more help (sorry).

    ant33 (just when I thought things were starting to look good)

Closed Thread
Page 2 of 3 FirstFirst 1 2 3 LastLast