[Active] Infected with Netsky Virus, nothing works on startup, no Windows Explorer

  1. #1
    vasilicus is offline Newbie

    [Active] Infected with Netsky Virus, nothing works on startup, no Windows Explorer

    I would be really grateful if somebody would please take the time to help me! I was just reorganizing my music files and suddenly my whole computer freezes up and all these security popups come up and a bunch of things shut down. I closed the laptop screen (sending it in sleep mode) and then woke it back up and couldn't do anything. So I shut it down and when I loaded it back up it said

    "Security Warning! Worm.Win32.Netsky detected on your machine. This virus is distributed via the Internet through e-mail and Active-x objects. The worm has its own SMTP engine which means it gathers e-mails from your local computer and redistributes itself... etc etc
    Type: Virus, Security Risk: 5

    The rest of the screen is black and I can't do anything. I tried starting in safe mode and the exact same thing happened except the My Documents folder opened after I clicked "OK" but I can't do anything else and it won't recognize my flash drive.
    After that I restarted in regular mode and the same thing happened until I clicked OK, but then it said that Windows Explorer wouldn't work and when I clicked Debug it said "JIT Debugging failed with the following error: 0x800405a6". Then my desktop background loaded (The Screen was all black before) and it said "The file or directory C:\Program Files\Common Files\ULEADS~1 is corrupt and unreadable. Please run the Chkdsk utility." But I can't do anything because after I clicked ok on that a couple times (it came up three or four times) everything just stopped, I would presume because Windows Explorer won't work. So I hit Ctrl+alt+delete and logged out and back in and the same thing happened except when I logged in I got a popup that said that c.exe had stoped working as well. What can I do???????????????

  2. #2
    tallin is offline Australia
    If possible please follow this link for expert advice to clean your system of all Malware.

    kind regards,

  3. #3
    broni is online now Senior Member
    Try Avira AntiVir Rescue System

    Using another working computer...
    1. Download the Avira AntiVir Rescue System: Avira AntiVir Rescue System
    2. Place a blank CD in your burner and double-click on the downloaded file.
    3. The program will automatically burn the CD for you.
    4. Place the burned CD into the affected computer and start the computer with the CD in the CD tray.
    5. On the bottom left side of the screen there are 2 flags. Using your mouse click on the British flag to use English.
    6. Click on the Configuration button.

    - Select Scan all files
    - Select Try to repair infected files and Rename files, if they cannot be removed
    - Select Scan for dialers
    - Select Scan for joke programs (Jokes)
    - Select Scan for games
    - Select Scan for spyware (SPR)

    7. Click on Virus scanner
    8. Click on Start scanner at the bottom of the screen.

    9. Let Avira finish it's scan and then remove any threats found and then exit out of the scanner.
    10. Take the CD out of the CD/DVD tray and then restart the computer.

    If needed see this Tutorial for the Avira Rescue CD: [Rescue CD] Tutorial for Avira Rescue CD - Tipps und Tricks - Avira Support Forum

  4. #4
    vasilicus is offline Newbie
    OK, I was able to get Windows Explorer working but none of the viruses have been removed except for the one that Windows removed when I got Explorer back on. I still can't open Task Manager and can't run regedit because it says my administrator has disabled it.

  5. #5
    vasilicus is offline Newbie
    Hijackthis Log:

    Logfile of Trend Micro HijackThis v2.0.3 (BETA)
    Scan saved at 6:03:02 PM, on 1/4/2010
    Platform: Windows Vista SP1 (WinNT 6.00.1905)
    MSIE: Internet Explorer v7.00 (7.00.6001.18349)
    Boot mode: Normal

    Running processes:
    C:\Windows\system32\taskeng.exe
    C:\Windows\system32\Dwm.exe
    C:\Windows\System32\rundll32.exe
    C:\Windows\explorer.exe
    C:\Program Files\Toshiba\Power Saver\TPwrMain.exe
    C:\Program Files\Toshiba\SmoothView\SmoothView.exe
    C:\Program Files\Toshiba\FlashCards\TCrdMain.exe
    C:\Program Files\Apoint2K\Apoint.exe
    C:\Program Files\Windows Defender\MSASCui.exe
    C:\Program Files\Toshiba\ConfigFree\NDSTray.exe
    C:\Program Files\Toshiba\Utilities\KeNotify.exe
    C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
    C:\Windows\RtHDVCpl.exe
    C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Windows\System32\igfxtray.exe
    C:\Windows\System32\hkcmd.exe
    C:\Windows\System32\igfxpers.exe
    C:\Program Files\Toshiba\TOSCDSPD\TOSCDSPD.exe
    C:\Windows\ehome\ehtray.exe
    C:\Program Files\DNA\btdna.exe
    C:\Users\Dad\AppData\Local\Google\Update\GoogleUpd ate.exe
    C:\Program Files\Windows Media Player\wmpnscfg.exe
    C:\Users\Dad\AppData\Local\Temp\setup.exe
    C:\Windows\System32\rundll32.exe
    C:\Users\Dad\AppData\Local\Temp\c.exe
    C:\Program Files\Common Files\microsoft shared\Works Shared\wkcalrem.exe
    C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
    C:\Windows\system32\wuauclt.exe
    C:\Windows\system32\wbem\unsecapp.exe
    C:\Windows\system32\igfxsrvc.exe
    C:\Program Files\Apoint2K\ApMsgFwd.exe
    C:\Windows\ehome\ehmsas.exe
    C:\Users\Dad\AppData\Local\Google\Update\1.2.183.1 3\GoogleCrashHandler.exe
    C:\Program Files\Apoint2K\Apntex.exe
    C:\Program Files\Toshiba\ConfigFree\CFSwMgr.exe
    C:\Windows\msa.exe
    C:\Windows\System32\osk.exe
    C:\Windows\system32\rundll32.exe
    C:\Program Files\HijackThis\TrendMicro\HiJackThis\HiJackThis. exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = Personalized Start Page
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Bing
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Personalized Start Page
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = Personalized Start Page
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = Hotmail, News, Sport, Music, Movies, Money, Cars, Shopping, Windows Live from MSN UK
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    F2 - REG:system.ini: Shell=explorer.exe rundll32.exe bwsb.gio gltbr
    F2 - REG:system.ini: UserInit=C:\Windows\system32\winlogon86.exe
    O1 - Hosts: ::1 localhost
    O2 - BHO: C:\Windows\system32\qclh965.dll - {A5BF49A2-94F1-42BD-F434-3604812C807D} - C:\Windows\system32\qclh965.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
    O4 - HKLM\..\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
    O4 - HKLM\..\Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
    O4 - HKLM\..\Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
    O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
    O4 - HKLM\..\Run: [jswtrayutil] "C:\Program Files\Jumpstart\jswtrayutil.exe"
    O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
    O4 - HKLM\..\Run: [ITSecMng] %ProgramFiles%\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe /START
    O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
    O4 - HKLM\..\Run: [HWSetup] \HWSetup.exe hwSetUP
    O4 - HKLM\..\Run: [SVPWUTIL] C:\Program Files\TOSHIBA\Utilities\SVPWUTIL.exe SVPwUTIL
    O4 - HKLM\..\Run: [KeNotify] C:\Program Files\TOSHIBA\Utilities\KeNotify.exe
    O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
    O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
    O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
    O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
    O4 - HKLM\..\Run: [net] "C:\Windows\system32\net.net"
    O4 - HKLM\..\Run: [winupdate86.exe] C:\Windows\system32\winupdate86.exe
    O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
    O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
    O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
    O4 - HKCU\..\Run: [Google Update] "C:\Users\Dad\AppData\Local\Google\Update\GoogleUp date.exe" /c
    O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
    O4 - HKCU\..\Run: [ygua8e7yhuiesfha876yfauy8fe] C:\Users\Dad\AppData\Local\Temp\jng0psp.exe
    O4 - HKCU\..\Run: [RTHDBPL] C:\Users\Dad\AppData\Local\Temp\wrnmoxecsa.exe
    O4 - HKCU\..\Run: [asg984jgkfmgasi8ug98jgkfgfb] C:\Users\Dad\AppData\Local\Temp\setup.exe
    O4 - HKCU\..\Run: [LosAlamos] rundll32.exe C:\Windows\system32\sshnas.dll,AddConsoleAliasAW
    O4 - HKCU\..\Run: [PUT2VIDQLG] C:\Users\Dad\AppData\Local\Temp\c.exe
    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
    O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
    O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
    O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Pol icies\System, DisableRegedit=1
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
    O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
    O13 - Gopher Prefix:
    O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
    O20 - AppInit_DLLs: C:\Windows\system32\kbdsock.dll
    O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
    O22 - SharedTaskScheduler: ujhsf879fiosdfhgs98fudifmnddfdfd - {A5BF49A2-94F1-42BD-F434-3604812C807D} - C:\Windows\system32\qclh965.dll
    O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
    O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
    O23 - Service: ConfigFree Service - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
    O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\TOSHIBA Games\TOSHIBA Game Console\GameConsoleService.exe
    O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: Jumpstart Wifi Protected Setup (jswpsapi) - Atheros Communications, Inc. - C:\Program Files\Jumpstart\jswpsapi.exe
    O23 - Service: pinger - Unknown owner - C:\Toshiba\IVP\ISM\pinger.exe
    O23 - Service: Swupdtmr - Unknown owner - c:\Toshiba\IVP\swupdate\swupdtmr.exe
    O23 - Service: TOSHIBA Navi Support Service (TNaviSrv) - TOSHIBA Corporation - C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe
    O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe
    O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe
    O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
    O23 - Service: TOSHIBA SMART Log Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe
    O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe

    --
    End of file - 9622 bytes


    Programs List or whatever it is

    Acoustica Effects Pack
    Acoustica Mixcraft 4.2
    Activation Assistant for the 2007 Microsoft Office suites
    Adobe Flash Player 10 Plugin
    Adobe Flash Player 9 ActiveX
    Adobe Reader 8.1.0
    Adobe Shockwave Player
    Advertisement Service
    ALPS Touch Pad Driver
    AnalogX Rhyme
    ArtMoney SE v7.30.3
    Atheros Driver Installation Program
    Atheros Wi-Fi Protected Setup Library
    Axis and Allies
    BabasChess
    BlitzIn 2.7
    Bluetooth Stack for Windows by Toshiba
    CD/DVD Drive Acoustic Silencer
    Champion screen saver
    Chess Position Trainer 3.2
    Chessimo 3.02
    Compatibility Pack for the 2007 Office system
    Console Classix 4.04
    Ct-Art 3.0
    Dasher
    DivX Web Player
    DjVuLibre+DjView
    DVD MovieFactory for TOSHIBA
    FLV Converter 2.4
    Fritz11
    FrostWire 4.18.3
    GearDrvs
    Google Desktop
    Google Toolbar for Internet Explorer
    Google Toolbar for Internet Explorer
    Higher Score on the ACT
    HiJackThis
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
    Intel(R) Graphics Media Accelerator Driver
    Intel(r) Play(tm) Digital Movie Creator
    Intel(r) System Information Viewer
    Java(TM) 6 Update 3
    jZip
    Memeo AutoBackup
    Microsoft .NET Framework 1.1
    Microsoft .NET Framework 1.1
    Microsoft .NET Framework 1.1 Security Update (KB953297)
    Microsoft .NET Framework 3.5 SP1
    Microsoft .NET Framework 3.5 SP1
    Microsoft Age of Empires II
    Microsoft Home Publishing 2000
    Microsoft Office 2007 Service Pack 2 (SP2)
    Microsoft Office 2007 Service Pack 2 (SP2)
    Microsoft Office 2007 Service Pack 2 (SP2)
    Microsoft Office 2007 Service Pack 2 (SP2)
    Microsoft Office 2007 Service Pack 2 (SP2)
    Microsoft Office 2007 Service Pack 2 (SP2)
    Microsoft Office 2007 Service Pack 2 (SP2)
    Microsoft Office 2007 Service Pack 2 (SP2)
    Microsoft Office 2007 Service Pack 2 (SP2)
    Microsoft Office 2007 Service Pack 2 (SP2)
    Microsoft Office 2007 Service Pack 2 (SP2)
    Microsoft Office 2007 Service Pack 2 (SP2)
    Microsoft Office 2007 Service Pack 2 (SP2)
    Microsoft Office 2007 Service Pack 2 (SP2)
    Microsoft Office 2007 Service Pack 2 (SP2)
    Microsoft Office 2007 Service Pack 2 (SP2)
    Microsoft Office 2007 Service Pack 2 (SP2)
    Microsoft Office 2007 Service Pack 2 (SP2)
    Microsoft Office 2007 Service Pack 2 (SP2)
    Microsoft Office 2007 Service Pack 2 (SP2)
    Microsoft Office 2007 Service Pack 2 (SP2)
    Microsoft Office Access MUI (English) 2007
    Microsoft Office Access Setup Metadata MUI (English) 2007
    Microsoft Office Enterprise 2007
    Microsoft Office Enterprise 2007
    Microsoft Office Excel MUI (English) 2007
    Microsoft Office FrontPage 2003
    Microsoft Office Groove MUI (English) 2007
    Microsoft Office Groove Setup Metadata MUI (English) 2007
    Microsoft Office Home and Student 2007
    Microsoft Office Home and Student 2007
    Microsoft Office InfoPath MUI (English) 2007
    Microsoft Office OneNote MUI (English) 2007
    Microsoft Office Outlook MUI (English) 2007
    Microsoft Office PowerPoint MUI (English) 2007
    Microsoft Office PowerPoint Viewer 2007 (English)
    Microsoft Office Proof (English) 2007
    Microsoft Office Proof (French) 2007
    Microsoft Office Proof (Spanish) 2007
    Microsoft Office Proofing (English) 2007
    Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
    Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
    Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
    Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
    Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
    Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
    Microsoft Office Publisher MUI (English) 2007
    Microsoft Office Shared MUI (English) 2007
    Microsoft Office Shared Setup Metadata MUI (English) 2007
    Microsoft Office Word MUI (English) 2007
    Microsoft Silverlight
    Microsoft Virtual PC 2007
    Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
    Microsoft Visual C++ 2005 Redistributable
    Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
    Microsoft Visual J# .NET Redistributable Package 1.1
    Microsoft Visual Studio .NET Professional 2003 - English
    Microsoft Works
    Midi2Wav Recorder DEMO 4.0
    Mozilla Firefox (3.0.16)
    MSDN Library - October 2004
    MSXML 4.0 SP2 (KB941833)
    MSXML 4.0 SP2 (KB954430)
    MSXML 4.0 SP2 (KB973688)
    Napster
    Napster Burn Engine
    Norton 360
    Picasa 2
    QuickBooks Financial Center
    QuickTime
    RealPlayer
    Realtek 8169 PCI, 8168 and 8101E PCIe Ethernet Network Card Driver for Windows Vista
    Realtek High Definition Audio Driver
    Risk
    RPGcN[2003 - Adventure
    Sansa Media Converter
    SecondLife (remove only)
    Security Update for 2007 Microsoft Office System (KB969559)
    Security Update for 2007 Microsoft Office System (KB969559)
    Security Update for 2007 Microsoft Office System (KB973704)
    Security Update for 2007 Microsoft Office System (KB973704)
    Security Update for CAPICOM (KB931906)
    Security Update for CAPICOM (KB931906)
    Security Update for Microsoft Office Excel 2007 (KB973593)
    Security Update for Microsoft Office Excel 2007 (KB973593)
    Security Update for Microsoft Office Outlook 2007 (KB972363)
    Security Update for Microsoft Office PowerPoint 2007 (KB957789)
    Security Update for Microsoft Office PowerPoint 2007 (KB957789)
    Security Update for Microsoft Office Publisher 2007 (KB969693)
    Security Update for Microsoft Office system 2007 (972581)
    Security Update for Microsoft Office system 2007 (972581)
    Security Update for Microsoft Office system 2007 (KB969613)
    Security Update for Microsoft Office system 2007 (KB969613)
    Security Update for Microsoft Office system 2007 (KB974234)
    Security Update for Microsoft Office system 2007 (KB974234)
    Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
    Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
    Security Update for Windows Media Encoder (KB954156)
    Swiff Player 1.1
    Tal
    Texas Instruments PCIxx21/x515/xx12 drivers.
    Toby Deep Tactics 5.0
    TOSHIBA Assist
    TOSHIBA ConfigFree
    TOSHIBA Disc Creator
    TOSHIBA DVD PLAYER
    TOSHIBA Extended Tiles for Windows Mobility Center
    TOSHIBA Flash Cards Support Utility
    TOSHIBA Games
    TOSHIBA Hardware Setup
    Toshiba Registration
    TOSHIBA SD Memory Utilities
    TOSHIBA Software Modem
    TOSHIBA Software Upgrades
    TOSHIBA Speech System Applications
    TOSHIBA Speech System SR Engine(U.S.) Version1.0
    TOSHIBA Speech System TTS Engine(U.S.) Version1.0
    TOSHIBA Supervisor Password
    TOSHIBA Value Added Package
    Total Video Player 1.03
    TripleA Version 1_0_0_3
    Update for 2007 Microsoft Office System (KB967642)
    Update for 2007 Microsoft Office System (KB967642)
    Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
    Update for Microsoft Office 2007 Help for Common Features (KB963673)
    Update for Microsoft Office 2007 Help for Common Features (KB963673)
    Update for Microsoft Office Access 2007 Help (KB963663)
    Update for Microsoft Office Excel 2007 Help (KB963678)
    Update for Microsoft Office Excel 2007 Help (KB963678)
    Update for Microsoft Office InfoPath 2007 (KB976416)
    Update for Microsoft Office InfoPath 2007 (KB976416)
    Update for Microsoft Office Infopath 2007 Help (KB963662)
    Update for Microsoft Office OneNote 2007 Help (KB963670)
    Update for Microsoft Office OneNote 2007 Help (KB963670)
    Update for Microsoft Office Outlook 2007 Help (KB963677)
    Update for Microsoft Office Powerpoint 2007 Help (KB963669)
    Update for Microsoft Office Powerpoint 2007 Help (KB963669)
    Update for Microsoft Office Publisher 2007 Help (KB963667)
    Update for Microsoft Office Script Editor Help (KB963671)
    Update for Microsoft Office Script Editor Help (KB963671)
    Update for Microsoft Office Word 2007 (KB974561)
    Update for Microsoft Office Word 2007 (KB974561)
    Update for Microsoft Office Word 2007 Help (KB963665)
    Update for Microsoft Office Word 2007 Help (KB963665)
    Update for Outlook 2007 Junk Email Filter (kb976884)
    VC80CRTRedist - 8.0.50727.762
    Web CEO 7.7
    Windows Media Encoder 9 Series
    Windows Media Encoder 9 Series
    Windows Media Player Firefox Plugin
    WinRAR archiver
    WinTD
    WinZip 12.0
    WriteExpress Rhymer and Phonetic Finder
    ZIP Reader 8.00.0018

  6. #6
    broni is online now Senior Member
    I'm glad, you're able to run something

    Please download ComboFix from Here or Here to your Desktop.


    **Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**
    • Please, never rename Combofix unless instructed.
    • Close any open browsers.
    • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
    • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
    • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

    NOTE. If Combofix asks you to install Recovery Console, please allow it.

    • Close any open browsers.
    • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
    • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
    • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.
    • Double click on combofix.exe & follow the prompts.
    • When finished, it will produce a report for you.
    • Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review.

    **Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**

    Make sure, you re-enable your security programs, when you're done with Combofix.

    DO NOT make any other changes to your computer (like installing programs, using other cleaning tools, etc.), until it's officially declared clean!!!

  7. #7
    vasilicus is offline Newbie
    OK, the "Netsky Virus" popup stopped coming up when I logged in and I can visit webpages on firefox now (I used to get redirected every time I tried to visit a webpage so I had to use Google Chrome) but whenever I log it still says "c.exe has stopped working" and Windows Explorer still won't load (A My Documents folder loads for some reason so I can search for windows explorer and load it manually). I found "c.exe" and there were files named "a" and "b" and a couple other things that all appeared at the same time (10:22 last night) and I tried to delete all of them but c.exe wouldn't delete, it said I had to have special priveleges to delete it. I think the failure of windows explorer to load has something to do with the registry (I had two files named winlogin86.exe and winupdate86.exe that I read about and deleted them and all the files I could find that went with them, but I read here How to remove winlogon86.exe winupdate86.exe that they also make changes to your registry that are probably responsible for windows explorer not loading just by looking at the filenames) so how would I fix the problems with the registry? I used to not even be able to get in but used HijackThis to fix that. Oh, and it's also running very very slowly.

    All ComboFix did was run a little blue loading bar. Was that all it was supposed to do?
    Last edited by vasilicus; 05-01-2010 at 03:37 AM.

  8. #8
    broni is online now Senior Member
    So, what's the actual issue with running Combofix?

  9. #9
    vasilicus is offline Newbie
    Nothing, it seems like it worked fine. I also used Command Prompt to get rid of c.exe.

    The computer is still running slowly, though, and Windows Explorer won't load when it starts up, instead My Documents opens.

    I think that the windows explorer not loading up is linked to changes the virus made to my registry and that the slowness is because I didn't get rid of everything. How can I find out and what can I do about it?

  10. #10
    broni is online now Senior Member
    Save 20% on AVG Internet Security 2012 Suite!
    Don't do anything by yourself.
    I need to see Combofix and HJT logs.

+ Reply to Thread
Page 1 of 3 1 2 3 LastLast