|
#1
|
|||
|
|||
|
|
|||
|
i have a virus and my norton cant find it it will post screenshots of the popups im getting this is really PSing me off cuz whenever i play WoW it minimizes every like 5 minutes because this popup keeps showing its head ill show you guys but it keeps saying do this win virus thingy and this drivecleaner thingy
Edit i got it http://i140.photobucket.com/albums/r...ock/Thingy.jpg |
|||
|
#2
|
|||
|
|||
|
|
|||
|
Hehe. I love these babies. Ok, I will get rid of it for you. Just simply follow these steps.
(Sexy Vista by the way. :P)1. Now, I need you to follow these steps carefully. I cannot post all steps until I recieve the answer from a certain step in a post. So I will give you all the steps up to the point where I need some information in a post from you. 2. Click Here and download Hijackthis. Just click any of the mirrors and download the file. 3. Save it to your desktop for easy access. 4. Once downloaded double click the ZIP file thats now on your desktop. Run it if you get a security warning from windows. Just open it. 5. Click Unzip on this new menu. Notice that its going to save in: C:\Program Files\HijackThis 6. Once its extracted everything close the little extractor thing, then go to: C:\Program Files\HijackThis 7. Double click the Hijackthis icon. Not the text file, the actual program :P 8. Click "Do a system scan and save a logfile". 9. Let it scan (Usually takes a few seconds), and then a text document should open. 10. Copy everything from that text document into a post below. Everything! Once you have completed these steps, I will be able to tell you which of these files to remove, and then we can continue the removal process. Your probably wondering why we cant just do the removal process. Well that reason is simple. If we do it now, the virus will block the removal, and say we can't access it. But by removing files using this log, we can remove the files that the virus needs to tell us that, and we can then go onto remove it from your computer. Good Luck. I am subscribed to this topic, so I will be emailed when you make a post. ~Xtr3me |
|||
|
#3
|
|||
|
|||
|
|
|||
|
Okay so i had some errors but then i made it run as administrator and it worked so heres the filez
Logfile of HijackThis v1.99.1 Scan saved at 5:52:01 PM, on 12/05/2007 Platform: Unknown Windows (WinNT 6.00.1904) MSIE: Internet Explorer v7.00 (7.00.6000.16386) Running processes: C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Windows\system32\taskeng.exe C:\Program Files\Windows Defender\MSASCui.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\Program Files\HP\QuickPlay\QPService.exe C:\Program Files\HP\HP Software Update\hpwuSchd2.exe C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe C:\Program Files\Java\jre1.6.0\bin\jusched.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Windows\ehome\ehtray.exe C:\Windows\System32\rundll32.exe C:\Windows\ehome\ehmsas.exe C:\Program Files\HP Connections\6811507\Program\HP Connections.exe C:\PROGRA~1\HEWLET~1\Shared\HPQTOA~1.EXE C:\Program Files\Xfire\xfire.exe C:\Program Files\World of Warcraft\BackgroundDownloader.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\HijackThis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&t...ilion&pf=laptop R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&t...ilion&pf=laptop R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O1 - Hosts: ::1 localhost O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [osCheck] "c:\Program Files\Norton Internet Security\osCheck.exe" O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe" O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start O4 - HKLM\..\Run: [HP Health Check Scheduler] C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe O4 - HKLM\..\Run: [WAWifiMessage] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe O4 - HKLM\..\Run: [hpWirelessAssistant] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [SManager] smanager.7.exe O4 - HKLM\..\Run: [runner1] C:\Windows\retadpu2000352.exe 61A847B5BBF72810329B385577FB01F0B3E35B6638993F4661 AA4EBD86D67C56389B284534F310 O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter O4 - HKCU\..\Run: [Steam] "c:\steam\steam.exe" -silent O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033 O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe O4 - Global Startup: HP Connections.lnk = C:\Program Files\HP Connections\6811507\Program\HP Connections.exe O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL O10 - Unknown file in Winsock LSP: c:\windows\system32\nlaapi.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\napinsp.dll O11 - Options group: [INTERNATIONAL] International* O13 - Gopher Prefix: O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - http://www.fileplanet.com/fpdlmgr/ca..._2.3.6.108.cab O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secur...loadManager.ocx O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DL L O20 - Winlogon Notify: winvnv32 - C:\Windows\SYSTEM32\winvnv32.dll O23 - Service: AddFiltr - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing) O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing) O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLSched.exe O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing) O23 - Service: COM Host (comHost) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe O23 - Service: @%SystemRoot%\ehome\ehstart.dll,-101 (ehstart) - Unknown owner - %windir%\system32\svchost.exe (file missing) O23 - Service: HP Health Check Service - Hewlett-Packard - C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Roxio\Roxio MyDVD Basic v9\InstallShield\Driver\1050\Intel 32\IDriverT.exe O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\isPwdSvc.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - %windir%\system32\svchost.exe (file missing) O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - %windir%\system32\svchost.exe (file missing) O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - %ProgramFiles%\Windows Media Player\wmpnetwk.exe (file missing) O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe |
|||
|
#4
|
|||
|
|||
|
|
|||
|
Ok. It seems there is no files that will cause problems during removal there. So follow these steps:
Click this link >>> http://free.grisoft.com/softw/70free/setup...up-7.5.0.50.exe Click open Install it. Update it. When it says "Update Successful" click the "Status" tab at the top Click scan now Click "Complete System Scan" Leave it to scan the entire PC. Don't pause, stop. It may take over an hour. Once the scan is complete, delete all that it finds. Quarantine if it recommends it only. Reboot the PC Problem Solved I think. If not, let me know in the topic, and we'll try Plan B. Also, lemme know if it works
|
|||
|
#5
|
|||
|
|||
|
|
|||
|
well ahem actually i havent been having any problems today for some reason so should i still do the scan or no ?
|
|||
|
#6
|
|||
|
|||
|
|
|||
|
Just do it, so you can actually get that virus
|
|||
|
#7
|
|||
|
|||
|
|
|||
|
what? scan it so i can catch the virus? but i scanned with my norton before and it didnt find nothing :\
|
|||
|
#8
|
|||
|
|||
|
|
|||
|
Ffs. I reallllyy hate people like you.
I spend 50 minutes of my time writing out these posts and you dont even bother to follow them. yet they help you? Fine, dont, I dont give a crap about your PC. I am actually a qualified virus remover. Also I have 4 AQA Qualifications in ICT Principles, Hardware, Virus Removal, and web/forum development. But hey, your PC. Whatever. EDIT: Also to add. I actually spent about 1 hour and 25 minutes on this topic. Around 20 mins writing the posts, checking it was all correct by doing it myself. On your log, I spent an hour reading it through throroughly, and checking every single line was ok. And then, I spent 5 mins on that last post. And now, you have the cheek to turn round and say why should I scan.. :hahano: Seriously. If your gonna ask for help, ATLEAST TAKE THE HELP GIVEN TO YOU. |
|||
|
#9
|
|||
|
|||
|
|
|||
|
Heartshock, i'd listen to Xtr3me, he's even helped me on occasions. He knows what he's talking about.
Also, just because you haven't had any problems with this "virus" doesn't neccesarily mean that you don't still have it. Viruses don't just attack your pc all the time, they just sit there growing until they can just wipe you out completely, so take the time to listen to the help Xtr3me is trying to give you - that or ignore him and get owned.
__________________
<div align="center">supermangoneEVIL http://i59.photobucket.com/albums/g2...s/superman.png Checked out the Competitions in the Design Forum yet? Pure 99 WOODCUTTER: http://www.rsbandb.com/goalsigs/mod-...68/iziller.png</div> |
|||
|
#10
|
|||
|
|||
|
|
|||
|
Thanks for that supportive post.
|
|||
|
#11
|
|||
|
|||
|
|
|||
|
I double checked your hijack this post, and second xtr3me's help. Try that link he posted, if the popup reoccurs, try adaware or spybot Search and Destroy.
PS: Just because the popup isn't there, doesn't mean it dissapeared on it's own. Viruses don't just up and leave, if it was there then it still is. |
|||
|
#12
|
|||
|
|||
|
|
|||
|
Its still there. It doesnt show on all boots. Its moving to other files that you open while your at the PC. Ive been in this situation many times.
Oh, and by the way heartshock, think twice about the websites you are going on. Only the worst of websites will give these sorts of viruses.
|
|||
|
#13
|
|||
|
|||
|
|
|||
|
Quote:
|
|||
|
#14
|
|||
|
|||
|
|
|||
|
Hehe, you would know wouldn't you Dococ. :P
|
|||
|
#15
|
|||
|
|||
|
|
|||
|
well i can tell you one thing dont ever ever you hear me EVER go to [Removed]
u get 10 + trojan viruses for every 10 seconds your on there trust me why do you think i just got a new computer I know your only trying to help, but we don't want links like that in posts. Thanks. ![]() |
|||
|
#16
|
|||
|
|||
|
|
|||
|
Umm, we dont intend to crack software, Link removed from post.
Have you scanned or not? |
|||
![]() |
| Thread Tools | |
| Display Modes | |
|
|