Question:
HijackThis Code for anyone that can fix my malware problem?
2008-11-26 03:05:28 UTC
Logfile of HijackThis v1.99.1
Scan saved at 21:55:13, on 11/26/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\netdde.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\vssvc.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\DNA\btdna.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Documents and Settings\Miyuru\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\NETGEAR\WG111v2\WG111v2.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Java\jre1.6.0_04\bin\jucheck.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\PROGRA~1\FREEDO~1\fdm.exe
E:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - E:\Program Files\BitComet\tools\BitCometBHO_1.2.8.7.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: (no name) - {be8de0f8-7f43-487a-9006-ff841edc3741} - C:\WINDOWS\system32\runasate.dll (file missing)
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll
O2 - BHO: PicLens plug-in for Internet Explorer - {EAEE5C74-6D0D-4aca-9232-0DA4A7B866BA} - C:\Program Files\PicLensIE\PicLens.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: (no name) - {B85684C0-6279-43AC-9158-AB96AA390B8D} - (no file)
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [mmtask] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe"
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [LanTalk.NET] C:\Documents and Settings\Miyuru\Desktop\Miyuru's Files\zmisc\CEZEO software\LanTalk NET\LanTalk.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [CPMeb99bde0] Rundll32.exe "c:\windows\system32\hulubera.dll",a
O4 - HKLM\..\Run: [pojezupiye] Rundll32.exe "C:\WINDOWS\system32\wevoyira.dll",s
O4 - HKLM\..\RunOnce: [symPCCheckup] "C:\WINDOWS\system32\Adobe\Shockwave 11\symcheckupstub.exe" /reboot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4
Seven answers:
Manuel
2008-11-29 08:09:19 UTC
in safe mode F8 run malwarebytes anti-malware and SUPERAntispyware,and what they find you

delete it manually. then run ccleaner to cleand your pc, and mvregclean, to clean registry.

what mvregclean find you remove because the key is there but not the file ,folder or program.

even you reformat and it finds anything remove dont be afraid.

f
keef
2016-11-06 11:46:19 UTC
First u could get a reliable anti virus application, the virus r speaking approximately runs as u start up up ur device, if u u can to to activity supervisor then to flow the precesses tab and then locate the record that's doing this, u will could terminate that technique, If u have stumbled on the approach call then do a seek to locate the place is the virus placed, then merely delete it. warning the virus frequently locates itself in a device folder utilising a acceptance very such as device information, u could by probability delete device record on a similar time as doing this. there are particular classes the can seek the startup entries and locate the virus record or maybe supply u the region, I used TuneUp Utilities. And if all fails u could format ur laptop, backup information that u choose do no longer backup the rest, this virus creates copies of itself so as that it may come again even after u format the laptop desire this helps
jian9007
2008-11-26 03:42:41 UTC
It is a variant of the Vundo trojan. If you notice the entry in the registry it shows as O3 - Toolbar: (no name) - {B85684C0-6279-43AC-9158-AB96AA390B8D} - (no file)

This is associated with the Vundo trojan (aka Virtumonde or Virtumondo). I would suggest Vundofix 7.06 or if you prefer, the combofix.exe program if the Vundofix does not remove it. You can google either program and there are many downloads for them. Bleeping computer has a good tutorial and download link for combofix http://www.bleepingcomputer.com/combofix/how-to-use-combofix



and the vundofix and guide can be found at http://www.bleepingcomputer.com/malware-removal/remove-vundo-virtumonde



Hope it helps!
2008-11-26 03:14:29 UTC
At quick glance remove at least these:



O2 - BHO: (no name) - {be8de0f8-7f43-487a-9006-ff841edc3741} - C:\WINDOWS\system32\runasate.dll (file missing)

O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll



O4 - HKLM\..\Run: [CPMeb99bde0] Rundll32.exe "c:\windows\system32\hulubera.dll",a

O4 - HKLM\..\Run: [pojezupiye] Rundll32.exe "C:\WINDOWS\system32\wevoyira.dll",s
Sly_Old_Mole
2008-11-26 03:38:09 UTC
remove:



O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)



O2 - BHO: (no name) - {be8de0f8-7f43-487a-9006-ff841edc3741} - C:\WINDOWS\system32\runasate.dll (file missing)



O3 - Toolbar: (no name) - {B85684C0-6279-43AC-9158-AB96AA390B8D} - (no file)



now show us the rest of the log & tell us what type of pop up your getting.
REDMAN
2008-11-26 03:40:14 UTC
http://www.techsupportforum.com/security-center/hijackthis-log-help/

There is a free version of Malwarebytes at download.com

you can also try this.

http://www.superantispyware.com/
2008-11-26 03:11:39 UTC
THIS WEBSITE HAS YOUR IP ADDRESS ASWELLL OMG

THIS WEBSITE CAN GET IT AS WELL http://www.geoiptool.com/ RUNNNNNNNNNNNNNNNNNNNNNNNNNNNN


This content was originally posted on Y! Answers, a Q&A website that shut down in 2021.
Loading...