Computers |
|
| | #1 (permalink) |
| True Techie Join Date: Jul 2006 Location: Philippines
Posts: 136
| i am using avg free edition and ad-aware free edition, and the virus keeps creating a file named "games.exe" on the my documents folder. I just reformatted my computers but it keeps on coming back, i am having partitions in my hard drive which is obviously not reformatted because i have important files there. i think that is the cause why it came back... please help me... i don't know if this is the right place to post this, please do move this if it isn't... Logfile of HijackThis v1.99.1 Scan saved at 11:30:08 AM, on 7/1/2008 Platform: Windows XP SP3, v.5512 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.20733) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\RUNDLL32.EXE C:\PROGRA~1\AVG\AVG8\avgtray.exe C:\WINDOWS\RTHDCPL.EXE C:\WINDOWS\system32\ctfmon.exe C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\WINDOWS\system32\nvsvc32.exe c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe C:\PROGRA~1\AVG\AVG8\avgrsx.exe C:\PROGRA~1\AVG\AVG8\avgemc.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Hunt Virus Utilities\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Yahoo! SearchBar Home Page R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Yahoo! R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Yahoo! R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = Yahoo! SearchBar Home Page R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Yahoo! R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = MSN.com R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = Yahoo! R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = *.local O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll O3 - Toolbar: StylerToolBar - {D2F8F919-690B-4EA2-9FA7-A203D1E04F75} - C:\Program Files\Styler\TB\StylerTB.dll O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll O11 - Options group: [INTERNATIONAL] International* O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll O20 - AppInit_DLLs: avgrsstx.dll O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing) O20 - Winlogon Notify: WBSrv - C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbsrv.dll O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\wpdshserviceobj.dll O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762# # (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
__________________ intel core2quad q6600 msi p35 neo nvidia 8600gt 1gb corsair twin 1gb RAM (dual channel) = 2gb samsung 200gb sata gigabyte 3d rocket II (someone banned my sig because it was too big, but I see people here who has a sig, 6 million times bigger than mine, that's called pure luck!) |
| |
| | #2 (permalink) |
| Commander Super Mod Joker Join Date: Sep 2004 Location: In Trotter's crawl space
Posts: 15,433
| Hello, I will analyze this soon. But please make sure to post in the Analyze area. It is the top forum of this page. Moved. Just looked over your log and it is clean. There is nothing of a virus in there. If you want a better scan to run run this: Step1 | HiJack This Click here to download HJTInstall.exe You HiJack This is out of date. Please update it. Please re-open HiJackThis and scan. Check the boxes next to all the entries listed below. O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing) Now close all windows other than HiJackThis, then click Fix Checked. Close HiJackThis. Step2 | Deckard's System Scanner Please download Deckard's System Scanner (DSS) and save it to your Desktop.
Cheers, Mak Last edited by Mak213; 07-01-2008 at 04:47 AM. |
| |
| | #3 (permalink) |
| True Techie Join Date: Jul 2006 Location: Philippines
Posts: 136
| okay ive downloaded Malwarebytes' Anti-Malware and it looks like i've got a malware... i scanned and it found two infections... so i think im okay now, anyways thanks for the reply...
__________________ intel core2quad q6600 msi p35 neo nvidia 8600gt 1gb corsair twin 1gb RAM (dual channel) = 2gb samsung 200gb sata gigabyte 3d rocket II (someone banned my sig because it was too big, but I see people here who has a sig, 6 million times bigger than mine, that's called pure luck!) |
| |
| Thread Tools | |
| Display Modes | |
| |
Similar Threads | ||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| X-Fi XtremeGamer - Popping and crackling | Demalii | Hardware Troubleshooting | 0 | 06-04-2008 11:34 PM |
| Popping, Jumping, low, sound HELP! | DavidJC | Hardware Troubleshooting | 3 | 05-18-2008 01:41 PM |
| popping out car dent | robina_80 | Off Topic Discussion | 6 | 01-24-2008 02:28 PM |
| Popping sounds coming from onboard ASUS Mobo | djmaddogfreak | Hardware Troubleshooting | 8 | 01-08-2008 01:39 PM |
| Error message popping up! | cyclones | Windows Operating Systems and Software | 0 | 06-27-2007 05:43 PM |