Question

qvkwjh.dll (Trojan Generic.PWS.y) is infecting .exe files....(Can't run any application)

Asked by: JatinHemant

Dear friends !

I am facing a very seriour problem in one of my pc. The pc is infected with viruses. When I installed McAfee Enterprise Edition Trial Version, it detected Virus-Worms and Trojans. Two of those threats are Trojans and they couldn't be deleted by the antivirus software. (Though AV informs that it has detected and deleted the Trojans but the pop-up window comes again.)

Please look at the general information about the files...

Name: hosts
In Folder: C:\WINDOWS\system32\drivers\etc  
Detected As:  PWS-QQRob!hosts
Detection Type: Trojan
Status :  Deleted        
Application infected: C :\WINDOWS\system32\svchost.exe

Name: qvkwjh.dll   C:\WINDOWS\system32
In Folder: C:\WINDOWS\system32
Detected As:  Generic PWS-y
Detection Type: Trojan
Status :  Deleted        
Application infected: (THIS LOCATION ALWAYS VARIES, BUT IT IS ALWAYS APPLICATION ' S EXE FILE)

Now the problems are:

1. I can't run any application. When I try to run any application, the Virus Scanning Screen Pops up and shows that threats were detected and deleted.

2. I can't run ComboFix, CCleaner, SDFix, Spybot-Search & Destroy.

3. I can't remove the McAfee Antivirus because I can't reach up to Add/Remove Programs

4. I want to install Kaspersky Antivirus Software but I can't. When I try to run the executable file for this antivirus, it again gives me pop up window for virus information.

5. I can't do anything because this Virus Information Screen pops up again and again and disturbs me.

I shared the hard disk of this pc and scanned it from another pc where I have Kaspersky Antivirus Software installed and updated. But I found only one virus. (The short log for Kaspersky is here below)

AV detected the one and only virus
detected:Virus Packed.Win32.NSAnti.r
Infected object: C:\ntde1ect.com

I am sending the HijackThis log. (Previously it was my luck that I could run HijackThis tool and could get the log)

Please see the HijackThis log:

Logfile of HijackThis v1.99.1
Scan saved at 10:36:40 AM, on 9/14/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Aclient\AClient.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\McAfee\Common Framework\FrameworkService.exe
C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\WINDOWS\system32\HPBPRO.EXE
C:\WINDOWS\system32\severe.exe
C:\WINDOWS\system32\drivers\conime.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\qvkwjh.exe
\192.168.5.85\bd85\ReadMeFirst\HijackThis\alternativ.exe
C:\WINDOWS\system32\dwwin.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 192.168.5.223:8080
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\system32\drivers\conime.exe
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\Scriptcl.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
O4 - HKLM\..\Run: [SetRefresh] C:\Program Files\COMPAQ\SetRefresh\\SetRefresh.exe
O4 - HKLM\..\Run: [AClntUsr] C:\Program Files\Aclient\AClntUsr.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe"
O4 - HKLM\..\Run: [StatusClient 2.6] C:\Program Files\Hewlett-Packard\Toolbox\StatusClient\StatusClient.exe /auto
O4 - HKLM\..\Run: [TomcatStartup 2.5] C:\Program Files\Hewlett-Packard\Toolbox\hpbpsttp.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [chiCkie] C:\WINDOWS\inf\chiCkie.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
O4 - HKLM\..\Run: [jwbnlb] C:\WINDOWS\system32\qvkwjh.exe
O4 - HKLM\..\Run: [qvkwjh] C:\WINDOWS\system32\severe.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [I just want to say I love Milko and I need a drink] C:\Documents and Settings\Sam\Local Settings\Application Data\svchost.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
O4 - HKCU\..\Run: [avpa] C:\WINDOWS\system32\avpo.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Altiris Client Service (AClient) - Altiris, Inc. - C:\Program Files\Aclient\AClient.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Unknown owner - C:\Program Files\McAfee\Common Framework\FrameworkService.exe" /ServiceStart (file missing)
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

IMP: I HAVE PRINTED THE SCREEN OF THE ERROR BY PRESSING PRINT SCREN KEY OF KEYBOARD. I WANT TO SEND THIS SCREEN SO THAT YOU CAN EASILY JUDGE THE PROBLEM. HOW CAN I SEND IT. I KNOW THAT THERE IS A WAY TO SEND IT, BUT I DON'T KNOW.  PLEASE SHOW ME HOW I CAN SEND IT SO THAT EXPERTS CAN GET IT.

Thanks...

Hemant

     

 

This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.

Subscribe now for full access to Experts Exchange and get

Instant Access to this Solution

  • Plus...
  • 30 Day FREE access, no risk, no obligation
  • Collaborate with the world's top tech experts
  • Unlimited access to our exclusive solution database
  • Never be left without tech help again

Subscribe Now

Trusted by hundreds of thousands everyday for fast, accurate and reliable tech support.

  • "The time we save is the biggest benefit of Experts Exchange to Warner Bros. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange." Mike Kapnisakis, Warner Bros.
  • "Our team likes having a resource that is more secure than just using Google and most experts using this service really know their stuff. It's nice to look here first versus using Google." Dayna Sellner, Lockheed Martin
  • "Anytime that I've been stumped with a problem, 9 out of 10 times Experts Exchange has either the accepted solution or an open discussion of the potential solution to the problem." Kenny Red, eBay Inc.

See what Experts Exchange can do for you.

Got a question?

We've got the answer.

Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.

Screenshot of Experts Exchange Knowledgebase

Need individual assistance?

Our experts are ready to help.

If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.

Screenshot of Experts Exchange Knowledgebase

Want to learn from the best?

Read articles from industry experts.

Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.

Screenshot of an Article

Working on a long term project?

Store your work and research.

Save solutions to your questions, answers you’ve discovered through searching plus helpful articles in your personal knowledgebase for easy future access.

Screenshot of Experts Exchange Knowledgebase

Access the answers to your technology questions today.

Subscribe Now

30-day free trial. Register in 60 seconds.

What Makes Experts Exchange Unique?

Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Trusted by the world's most respected brands.

image of each brand's logo

Faithfully serving IT professionals since 1996.

Experts Exchange Logo

Try it out and discover for yourself.

Subscribe Now

30-day free trial. Register in 60 seconds.

Related Solutions

  1. Hijackthis logfile
    My pc at work is going really slow and is giving a lot of errors. I run hijackthis.exe. Below I pasted the logfile. Can anyone help me t explain if there are some errors here? Logfile of Trend Micro HijackThis v2.0.0 (BETA) Scan saved at 12:30:31, on 13-06-2007 Platform: Win...
  2. how to repair a nexplorer.exe infected with Vundo trojan?
    Hello Experts. I'm using McAfee anti virus and he sometimes let me know that explorer.exe process is infected with Vundo.dr trojan. I have tried to remove it with vundofix and although it erased the corrupted files it doesnt seem to have taken care of explorer.exe which mcaf...

Free Tech Articles

  1. WARNING: 5 Reasons why you should NEVER fix a computer for free.
    It is in our nature to love the puzzle. We are obsessed. The lot of us. We love puzzles. We love the challenge. We thrive on finding the answer. We hate disarray. It bothers us deep in our soul. W...
  2. SCCM OSD Basic troubleshooting
    SCCM 2007 OSD is a fantastic way to deploy operating systems, however, like most things SCCM issues can sometimes be difficult to resolve due to the sheer volume of logs to sift through and the dispe...
  3. Migrate Small Business Server 2003 to Exchange 2010 and Windows 2008 R2
    This guide is intended to provide step by step instructions on how to migrate from Small Business Server 2003 to Windows 2008 R2 with Exchange 2010. For this migration to work you will need the fo...
  4. Create a Win7 Gadget
    This article shows you how to create a simple "Gadget" -- a sort of mini-application supported by Windows 7 and Vista. Gadgets can be dropped anywhere on the desktop to provide instant information, ...
  5. Outlook continually prompting for username and password
    There have been a lot of questions recently regarding Outlook prompting for a username and password whilst using Exchange 2007. There are a few reasons why this would happen and I will try to cover t...
  6. Backup Exchange 2010 Information Store using Windows Backup
    There seems to be quite a lot of confusion around the ability to backup Exchange 2010 using the built in Windows Backup feature. This stems from the omission of this feature prior to Exchange 2007 s...

Cloud Class Webinars

  1. Avoiding Bugs in Microsoft Access
    Alison Balter takes and in-depth look at avoiding bugs in Access. In this webinar you will learn about using the immediate window to debug your applications, invoking the debugger, using breakpoints to troubleshoot, stepping through code, setting the next statement to execute, ...
  2. Top 10 Best New Features in Visio 2010
    Scott Helmers gives live demonstrations of the top 10 new features in Visio 2010. This webinar will teach you how to create compelling diagrams by adding shapes to the page with a single click, linking the shapes in a diagram to data in Excel (or SQL Server, or SharePoint), ...
  3. IT Consultant Business Secrets Revealed
    Michael Munger, Experts Exchange tech pro and IT consultant, pulls back the curtain on his very successful businesses and answers question on every IT consultant and business owner should know about. He shares secrets on what he did to solve the 5 most common problems in IT, ...
  4. Disaster Recovery and Business Continuity
    Quest CTO, Mike Billon, gives an overview of the steps involved in building a dunamic disaster recovery plan. Through case studies and an examination of software/hardware tooles for monitoring and testing, you'll gain a better understandin of where you are, where you want ...
  5. Organize Your Visio Diagrams with Containers and Lists
    Scott Helmers uses cross functional flowcharts, wireframe diagrams, data graphic legends and seating charts to teach you: how to ustilize all three new structured diagram components in Visio 2010, the best practices for organizeing shapes in previous version of Visio, how to organize ...
  6. How to Us Objects, Properties, Events and Methods in Microsoft Access
    Alison Dalter gives an in-depbth look at objects, properties, events and methods in Microsoft Access. In this webinar you will learn about using the object browser, referring to objects, working with properties and methods, working with object variables, understanding the ...

Join the Community

Give a Little. Get a Lot.

Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.

Join the Community

Answers

 

by: SheharyaarSaahilPosted on 2007-09-14 at 07:16:39ID: 19891685

run your applications from safemode with Administrator account
clean the system there, and then post back a fresh hjt log from normal mode.....

 

by: rpggamergirlPosted on 2007-09-14 at 07:36:27ID: 19891887

Hijackthis log is heavily infected!

Tell us what happened when you tried to run SDFix or Combofix?
Did Command Prompt window flashes on then off again
OR
Was there an error that says........
"The command prompt has been disabled by your administrator."

We need to know the answer please so we'll know how to fix it.

 

by: rpggamergirlPosted on 2007-09-14 at 07:41:42ID: 19891955

You will find free file upload services at these sites, you can then upload there and post back the link. there's one upload site that I don't have the link of, "imageshack"

http://www.ee-stuff.com
http://storenow.net/
http://www.rapidupload.com/
http://rapidshare.de
http://supashare.com
http://yourfilehost.com
http://geocities.yahoo.com
http://yousendit.com

 

by: JatinHemantPosted on 2007-09-14 at 12:51:17ID: 19894672

Thanks again for your support.

I find the flash screen evertime when...

1. I try to run cmd.exe
2. I try to run regedit.exe
3. I double click on C: volume

I KNOW ABOUT THE MESSAGE "The command prompt has been disabled by your administrator.", BUT I AM NOT RECEIVING THIS MESSAGE. I RECEIVE THE Command Prompt FOR A SECOND AND IT DISAPPEARS AGAIN.

Because I can't access the registry from regedit.exe, I used third-party tool 'REGLITE'. I searched the entries

O4 - HKLM\..\Run: [jwbnlb] C:\WINDOWS\system32\qvkwjh.exe
O4 - HKLM\..\Run: [qvkwjh] C:\WINDOWS\system32\severe.exe
O4 - HKCU\..\Run: [I just want to say I love Milko and I need a drink] C:\Documents and Settings\Sam\Local Settings\Application Data\svchost.exe

I deleted these entries, but when I again run REGLITE, I found them again (PLEASE NOTE THAT PREVIOUSLY I WAS ABLE TO RUN AND INSTALL SOME APPLICATION, SO I INSTALLED CCleaner and Spybot - Search & Destroy. Spybot didn't give me any error.

Now, I did nothing but I can't run any of these tools : SDFix, ComboFix, CCleaner, Spybot - Search & Destroy, VundoFix. I can't run MSWord (Any application of MS-Office Suite), MS-Paint or any other application. When I try to run these applications, I notice that corresponding executable file for that application is infected with the Trojan. ( AND APPLICATION DOESN'T OPEN, A VIRUS INFORMATION SCREEN OPENS ALWAYS. IT POPS UP IN SECONDS SO I CAN'T DO ANYTHING)

NOTE: UNFORTUNATELY I MISSED THE SCREEN-SHOT FOR THAT McAfee VIRUS INFORMATION, BUT THE SAME PROBLEM IS COMING IN ANOTHER PC WHERE AVG 7.5 484 Trial Version IS INSTALLED. I AM SENDING THAT SCREEN FROM THE LINK PROVIDED ABOVE.

Kindly check it.

Thanks...

Hemant




 

by: SheharyaarSaahilPosted on 2007-09-14 at 14:02:38ID: 19895144

first of all.......will you do a favour please.....can you please turn off that CAPSLOCK while typing.....it makes the text really hard to read......thanks :)

secondly....we can ONLY try to clean a machine even when its badly infected.....you have to understand one point here.....that there are some cases when the best thing is to format and clean install of the system......though its always a last resort......so don't make up your mind that everything is going to be cleaned always....i hope you are getting my point here :)

third.....you cannot run your programs in normal mode because you always get some virus warnings and stuff like that.......what happens when you boot your system under safemode and login as Administrator to run these applications.......same results there too?

 

by: rpggamergirlPosted on 2007-09-14 at 17:35:47ID: 19895986

>>Now, I did nothing but I can't run any of these tools : SDFix, ComboFix, CCleaner, Spybot - Search & Destroy, VundoFix. I can't run MSWord (Any application of MS-Office Suite), MS-Paint or any other application. When I try to run these applications, I notice that corresponding executable file for that application is infected with the Trojan.<<

Look very much like a file infector to me. Don't worry we'll try our best, we don't give up easily.

Download SDFix and save it to your desktop.
http://downloads.andymanchesta.com/RemovalTools/SDFix.zip

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)


Then please go to Start Menu > Run > then copy and paste the following line:

%systemdrive%\SDFix\apps\FixPath.exe /Q

Reboot and then run SDFix
reboot your computer in Safe Mode by doing the following :

* Restart your computer
* After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
*  Instead of Windows loading as normal, a menu with options should appear;
*  Select the first option, to run Windows in Safe Mode, then press "Enter".
*  Choose your usual account.

*  Open the extracted folder and double click "RunThis.bat" to start the script.
*  Type "Y" to begin the script.
*  It will remove the Trojan Services then make some repairs to the registry and prompt you to press any key to Reboot.
*  Press any Key and it will restart the PC.
*  Your system will take longer that normal to restart as the fixtool will be running and removing files.
*  When the desktop loads the Fixtool will complete the removal and display "Finished", then press any key to end the script and load your desktop icons.
*  Finally open the SDFix folder on your desktop and copy and paste the contents of the results file "Report.txt" back


After you run SDFix and Combofix, we need you to run this tool please.
Download FindAWF.exe.
http://noahdfear.net/downloads/FindAWF.exe
and save it to your desktop.
Double-click on the FindAWF.exe file to run it.
It will open a command prompt and ask you to "Press any key to continue".

You will be presented with the following Menu.
1. Press 1 then Enter to scan for bak folders
2. Press 2 then Enter to restore files from bak folders
3. Press 3 then Enter to remove bak folders
4. Press 4 then Enter to reset domain zones
5. Press E then Enter to EXIT

Select 1, then press Enter
It may take a few minutes to complete so be patient.
When it is complete, it will open a text file in Notepad called AWF.txt.
Please copy and paste the contents of the AWF.txt file in your next reply.

 

by: rpggamergirlPosted on 2007-09-14 at 17:39:30ID: 19896001

You also need to isolate an infected pc till it is clean.

Please don't share/use any usbs/flash drives from infected pc to a clean pc

 

by: JatinHemantPosted on 2007-09-15 at 00:47:52ID: 19896847

Hello rpggamergirl and SheharyaarSaahil !

I got your comment. Lets try the best, then if it is not possible then, We will prefer for the clean installation.

You sugested that it may be a file infector and I should run SDFix, ComboFix and other FindAWF. Please look at the problem that I am not able to run SDFix, ComboFix or any application. But I will try again to run them. (It may be possible that I succeed to run them next time. Saturday and Sunday are weekends so my workplace is closed but I will definately try it on Monday.)

Pleas find the Virus Information Screen that I have uploaded on http://www.ee-stuff.com

This is the link:

http://www.ee-stuff.com/Expert/Upload/getFile.php?fid=4675

Note: You will find a jpeg file qvkwjh-error.jpg. This screen is not from the same pc which is highly infected. Unfortunately I couldn't get the screen. But this is from another pc (AVG 7.5 484 installed) which is  infected (though not so much) with  Trojan PSW.3X.AQ and gives the same window showing qvkwjh.dll error.

Please see the file on the above link and give your valuable comments.

Thanks again.

Hemant





 

by: rpggamergirlPosted on 2007-09-15 at 06:32:15ID: 19897464

Hemant,
In order for the tools that needs cmd.exe to run, like SDFix and Combofix, you need to fix the path by doing this:
Start Menu > Run > then copy and paste the following line:

%systemdrive%\SDFix\apps\FixPath.exe /Q

Reboot, and then you can run SDFix, Combofix etc.......you still won't be able to run other apps like Spybot, MS Word, CCleaner because their files are being replaced by the file infector, that's why we need to run FindAWF.exe in order to put back the legit file missing(other alternative is to reinstall those programs replaced by the file infector.

 

by: JatinHemantPosted on 2007-09-16 at 01:48:13ID: 19899952

Thanks...

I will run the commnad that you provided. Well...I had posted the jpeg file showing the screen that pops up again and again. Have you seen it. I have provided the link above. I am sending the link again.

Here is the link:

http://www.ee-stuff.com/Expert/Upload/getFile.php?fid=4675

Regards...

Hemant

 

by: JatinHemantPosted on 2007-10-02 at 03:11:20ID: 19997235

Hi rpggamergirl and SheharyaarSaahil !

Sorry for not posting the logs for a long time. Actually I was engaged in some other work and so couldn't join the discussion. BUT...my problem is still unsolved.

You see as I told you about the Trojan Generic.PWS.y, In another PC, I found the Trojan hors PWS.Generic 3XAQ. It is giving the same problems.

1. When I start the pc, after profile loading, it shows me the errors on the screen. (I am sending one jpeg file so that you can see the errors. I request you to see this jpeg file I am going to post with my next comment.

2. I receive the following message: A single step or trace operation has just been completed (0x80000004) occured in the application at location 0x00000000. Click on Ok to terminate the Program. Click on CANCEL to debug the program.

3. I receive may Run time errors

4. qvkwjh.exe and severe.exe error

I have taken the following steps...

1. I removed the hard disk and made it slave and scanned with Updated Kaspersky 6.0 Antivirus but it didn't show me viruses.

2. I run SDFix and sending you the log file but it is almost empty.

3. Then I ran ComboFix and HijackThis and sending you the log file.

                                                SDFix Report:
*****************************************************************************

SDFix: Version 1.107

Run by Administrator on 02/10/2007 at 10:45

Microsoft Windows XP [Version 5.1.2600]

Running From: C:\SDFix

Safe Mode:
Checking Services:


Restoring Windows Registry Values
Restoring Windows Default Hosts File
************************************************************************

ComboFix Report
*************************************************************************
ComboFix 07-10-02.2 - Administrator 2007-10-02 11:09:37.1 - NTFSx86
Microsoft Windows XP Professional  5.1.2600.2.1252.1.1033.18.66 [GMT 2:00]
Running from: C:\ComboFix.exe
 * Created a new restore point
.

(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Autorun.inf
C:\WINDOWS\svchost.exe
C:\WINDOWS\system32\drivers\conime.exe
C:\WINDOWS\system32\drivers\jwbnlb.exe
C:\WINDOWS\system32\severe.exe
C:\WINDOWS\system32\verclsid.dat

.
(((((((((((((((((((((((((   Files Created from 2007-09-02 to 2007-10-02  )))))))))))))))))))))))))))))))
.

2007-10-02 11:04      1,470,281      --a------      C:\ComboFix.exe
2007-10-02 11:01      <DIR>      d--------      C:\VundoFix Backups
2007-10-02 10:58      98,304      ---h-----      C:\WINDOWS\system32\BttnServ.exe
2007-10-02 10:52      51,200      --a------      C:\WINDOWS\NirCmd.exe
2007-10-02 10:34      38,400      ---------      C:\WINDOWS\system32\qvkwjh.dll
2007-10-02 10:09      28,364      -r-hs----      C:\WINDOWS\system32\avpo0.dll
2007-10-02 10:06      28,364      -r-hs----      C:\WINDOWS\system32\avpo1.dll
2007-10-02 09:19      <DIR>      d--------      C:\WINDOWS\ERUNT
2007-10-01 16:44      46,816      --a------      C:\WINDOWS\system32\pz.exe
2007-10-01 16:44      46,816      --a------      C:\WINDOWS\system32\newpz.exe
2007-10-01 16:26      28,364      -r-hs----      C:\WINDOWS\system32\avpo2.dll
2007-10-01 16:03      499,744      --ahs----      C:\WINDOWS\system32\drivers\fidbox.dat
2007-10-01 16:03      1,568      --ahs----      C:\WINDOWS\system32\drivers\fidbox2.dat
2007-10-01 16:03      <DIR>      d--------      C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2007-10-01 08:56      <DIR>      d--------      C:\Backup of VRF
2007-09-27 16:40      <DIR>      d--hs----      C:\Recycled
2007-09-27 10:01      87,740      -r-hs----      C:\ntde1ect.com
2007-09-27 10:00      87,740      -r-hs----      C:\WINDOWS\system32\avpo.exe
2007-09-27 09:57      77      --a------      C:\WINDOWS\system32\hx1.bat
2007-09-27 09:57      69,246      ---hs----      C:\WINDOWS\system32\qvkwjh.exe

.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-02 10:39      2468      --ahs----      C:\WINDOWS\system32\drivers\fidbox.idx
2007-10-02 10:39      1196      --ahs----      C:\WINDOWS\system32\drivers\fidbox2.idx
2007-09-24 08:06      ---------      d--------      C:\Documents and Settings\Administrator\Application Data\AdobeUM
2007-09-17 06:44      ---------      d--------      C:\Documents and Settings\Administrator\Application Data\U3
2007-08-24 06:37      ---------      d--------      C:\Program Files\WinUpdater
2007-08-08 08:18      ---------      d--------      C:\Program Files\Kaspersky Lab
2007-04-17 08:40:16      69,246      --sh--w      C:\WINDOWS\system32\qvkwjh.exe
.

(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\j2re1.4.2_01\bin\jusched.exe" [2003-08-20 02:23]
"srmclean"="C:\Cpqs\Scom\srmclean.exe" [2001-07-24 23:34]
"SetRefresh"="C:\Program Files\Compaq\SetRefresh\SetRefresh.exe" [2003-11-06 15:22]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2003-10-31 18:42]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 09:50]
"DXDllRegExe"="dxdllreg.exe" []
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd.exe" [2003-08-04 16:28]
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2003-12-22 07:38]
"Yahoo Messenger"="C:\WINDOWS\system\svchost32.exe" []
"jwbnlb"="C:\WINDOWS\system32\qvkwjh.exe" [2007-04-17 10:40]
"qvkwjh"="C:\WINDOWS\system32\severe.exe" []
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe" [2006-11-08 18:28]
"(Default)"="C:\Windows\svchost.exe" []
"CPQEASYBTTN"="C:\WINDOWS\system32\BttnServ.exe" [2006-06-01 21:56]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-10-01 16:06]
"SDFix"="C:\SDFix\RunThis.bat /second" []

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-08-04 05:06]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\ypager.exe" [2005-08-19 18:34]
"WinUpdater"="C:\Program Files\WinUpdater\update.exe" [2007-07-29 20:12]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 21:56]
"avpa"="C:\WINDOWS\system32\avpo.exe" [2007-10-02 10:09]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2003-09-16 04:19:24]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 00:01:04]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2003-09-16 04:19:24]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 00:01:04]



[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\C]
AutoRun\command- C:\ntde1ect.com
explore\Command- C:\ntde1ect.com
open\Command- C:\ntde1ect.com

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{073ce110-d1f3-11db-bbdb-000ffe32a4e2}]
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Sys.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{077a59a6-3787-11dc-bc5d-000ffe32a4e2}]
Auto\command- bittorrent.exe e
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL bittorrent.exe e

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{077a59a7-3787-11dc-bc5d-000ffe32a4e2}]
AutoRun\command- E:\ntde1ect.com
explore\Command- E:\ntde1ect.com
open\Command- E:\ntde1ect.com

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{09d09f46-4a22-11dc-bc75-000ffe32a4e2}]
Auto\command- E:\boot.exe
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL boot.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0b7c0a4b-6029-11dc-bc91-000ffe32a4e2}]
AutoRun\command- E:\ntde1ect.com
explore\Command- E:\ntde1ect.com
open\Command- E:\ntde1ect.com

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{12060b54-59d6-11dc-bc89-000ffe32a4e2}]
AutoRun\command- E:\ntde1ect.com
explore\Command- E:\ntde1ect.com
open\Command- E:\ntde1ect.com

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1437e0d3-7dfb-11db-bb71-000ffe32a4e2}]
Auto\command- AdobeR.exe e
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL AdobeR.exe e

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{14af6ccf-be34-11da-a5d3-000ffe1be200}]
Auto\command- E:\setup.exe
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL setup.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1a1231b8-b8b4-11da-a5cd-000ffe1be200}]
AutoRun\command- "E:\COMMAND.EXE" /StartExplorer

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1dd4be05-448a-11db-bb2d-000ffe32a4e2}]
AutoRun\command- E:\ntde1ect.com
explore\Command- E:\ntde1ect.com
open\Command- E:\ntde1ect.com

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{22346821-5088-11dc-bc7b-000ffe32a4e2}]
AutoRun\command- E:\ntde1ect.com
explore\Command- E:\ntde1ect.com
open\Command- E:\ntde1ect.com

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2a27aff8-3f43-11dc-bc67-000ffe32a4e2}]
AutoRun\command- E:\ntde1ect.com
explore\Command- E:\ntde1ect.com
open\Command- E:\ntde1ect.com

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2bdf6af1-ebae-11da-a613-000ffe1be200}]
AutoRun\command- "E:\COMMAND.EXE" /StartExplorer

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{31d55f1e-ef1d-11db-bc0b-000ffe32a4e2}]
Auto\command- F:\bittorrent.exe e
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL bittorrent.exe e

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{36123480-4bb8-11dc-bc76-000ffe32a4e2}]
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Sys.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4345fc88-ac5e-11db-bba5-000ffe32a4e2}]
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Sys.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{48039b40-b359-11db-bbad-000ffe32a4e2}]
1\Command- E:\.\RECYCLER\RECYCLER\autorun.exe
2\Command- E:\.\RECYCLER\RECYCLER\autorun.exe
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL .\RECYCLER\RECYCLER\autorun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4bab9386-aac6-11db-bba3-000ffe32a4e2}]
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Setup.pif

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{51e2a4be-0271-11da-8f87-806d6172696f}]
AutoRun\command- C:\ntde1ect.com
explore\Command- C:\ntde1ect.com
open\Command- C:\ntde1ect.com

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{57bec4f0-047f-11dc-bc20-000ffe32a4e2}]
Auto\command- E:\OSO.exe
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL OSO.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5ce80646-1297-11dc-bc36-000ffe32a4e2}]
Auto\command- E:\OSO.exe
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL OSO.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{66d5cf6c-1d8c-11dc-bc40-000ffe32a4e2}]
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Sys.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7134841e-072e-11db-a63f-000ffe1be200}]
AutoRun\command- F:\ntde1ect.com
explore\Command- F:\ntde1ect.com
open\Command- F:\ntde1ect.com

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{72bb0cb2-baad-11db-bbbc-000ffe32a4e2}]
AutoRun\command- E:\ntde1ect.com
explore\Command- E:\ntde1ect.com
open\Command- E:\ntde1ect.com

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{75d6ff47-4578-11dc-bc6e-000ffe32a4e2}]
Auto\command- OSO.exe
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL OSO.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8274fe10-8100-11db-bb79-000ffe32a4e2}]
Auto\command- bittorrent.exe e
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL bittorrent.exe e

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{882d6e12-4f9f-11dc-bc7a-000ffe32a4e2}]
AutoRun\command- E:\ntde1ect.com
explore\Command- E:\ntde1ect.com
open\Command- E:\ntde1ect.com

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8b9426b7-3ce8-11dc-bc65-000ffe32a4e2}]
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Sys.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8fb39701-84ff-11db-bb7d-000ffe32a4e2}]
1\Command- E:\.\RECYCLER\RECYCLER\autorun.exe
2\Command- E:\.\RECYCLER\RECYCLER\autorun.exe
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL .\RECYCLER\RECYCLER\autorun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9ecb4efa-1333-11dc-bc37-000ffe32a4e2}]
Auto\command- F:\bittorrent.exe e
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL bittorrent.exe e

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9f2872b4-d6b2-11db-bbea-000ffe32a4e2}]
AutoRun\command- E:\ntde1ect.com
explore\Command- E:\ntde1ect.com
open\Command- E:\ntde1ect.com

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a093febe-6bea-11dc-bc9d-000ffe32a4e2}]
Auto\command- E:\MicrosoftPowerPoint.exe
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL MicrosoftPowerPoint.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a5427bf0-8ce8-11da-a59a-000ffe1be200}]
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Sys.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a88a6a85-4edb-11dc-bc79-000ffe32a4e2}]
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Sys.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{aceeb264-967a-11db-bb91-000ffe32a4e2}]
Auto\command- E:\AdobeR.exe e
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL AdobeR.exe e

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b1f5796e-3431-11dc-bc59-000ffe32a4e2}]
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Sys.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b6997117-44ad-11dc-bc6c-000ffe32a4e2}]
Auto\command- E:\boot.exe
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL boot.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b7342bca-51fb-11dc-bc7c-000ffe32a4e2}]
Auto\command- G:\setup.exe
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL setup.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b7342d1d-51fb-11dc-bc7c-000ffe32a4e2}]
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Sys.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ba0dd4b1-3432-11dc-bc5a-000ffe32a4e2}]
Auto\command- boot.exe
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL boot.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{bc15ab1c-b84b-11db-bbb9-000ffe32a4e2}]
Auto\command- E:\boot.exe
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL boot.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{bc15ab1d-b84b-11db-bbb9-000ffe32a4e2}]
Auto\command- G:\boot.exe
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL boot.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{be265c40-4668-11dc-bc70-000ffe32a4e2}]
AutoRun\command- E:\ntde1ect.com
explore\Command- E:\ntde1ect.com
open\Command- E:\ntde1ect.com

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c5384d6b-60e9-11dc-bc92-000ffe32a4e2}]
Auto\command- E:\OSO.exe
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL OSO.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cabfc592-d871-11db-bbf0-000ffe32a4e2}]
Auto\command- F:\boot.exe
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL boot.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cabfc593-d871-11db-bbf0-000ffe32a4e2}]
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Boot.exe e
Open\command- Boot.exe e

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cba5355c-101e-11dc-bc33-000ffe32a4e2}]
Auto\command- F:\bittorrent.exe e
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL bittorrent.exe e

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ce2aa7db-a693-11da-a5b8-000ffe1be200}]
1\Command- E:\.\RECYCLER\RECYCLER\autorun.exe
2\Command- E:\.\RECYCLER\RECYCLER\autorun.exe
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL .\RECYCLER\RECYCLER\autorun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d5c2fc86-f340-11db-bc0f-000ffe32a4e2}]
Auto\command- boot.exe
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL boot.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{de2508a6-85bd-11db-bb7e-000ffe32a4e2}]
1\Command- E:\.\RECYCLER\RECYCLER\autorun.exe
2\Command- E:\.\RECYCLER\RECYCLER\autorun.exe
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL .\RECYCLER\RECYCLER\autorun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e1063084-d858-11db-bbef-000ffe32a4e2}]
Auto\command- boot.exe
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL boot.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e3f5a2c0-ec26-11db-bc06-000ffe32a4e2}]
Auto\command- boot.exe
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL boot.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e4ca977d-702d-11dc-bca5-000ffe32a4e2}]
AutoRun\command- E:\ntde1ect.com
explore\Command- E:\ntde1ect.com
open\Command- E:\ntde1ect.com

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e831a766-2b30-11da-a4e5-000ffe1be200}]
Auto\command- boot.exe
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL boot.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e9285cec-86a0-11db-bb80-000ffe32a4e2}]
Auto\command- E:\bittorrent.exe e
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL bittorrent.exe e

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ef1a6a21-45b4-11dc-bc6f-000ffe32a4e2}]
Auto\command- E:\OSO.exe
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL OSO.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f163124c-ef99-11da-a619-000ffe1be200}]
Auto\command- E:\OSO.exe
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL OSO.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f2e0e61f-6b13-11db-bb5d-000ffe32a4e2}]
1\Command- E:\.\RECYCLER\RECYCLER\autorun.exe
2\Command- E:\.\RECYCLER\RECYCLER\autorun.exe
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL .\RECYCLER\RECYCLER\autorun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f5ea92c5-577b-11dc-bc85-000ffe32a4e2}]
Auto\command- E:\OSO.exe
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL OSO.exe

*Newly Created Service* - CATCHME
.
**************************************************************************

catchme 0.3.1169 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-10-02 11:11:50
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

Completion time: 2007-10-02 11:12:32
C:\ComboFix-quarantined-files.txt ... 2007-10-02 11:12
.
      --- E O F ---
**************************************************************************


ComboFix Quarantined Files Report
**************************************************************************
[code]
2006-06-01 21:56      98304    --a------    C:\Qoobox\Quarantine\C\WINDOWS\svchost.exe.vir
2007-04-17 10:40      69246    --a------    C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\conime.exe.vir
2007-04-17 10:40      69246    --a------    C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\jwbnlb.exe.vir
2007-04-17 10:40      69246    --a------    C:\Qoobox\Quarantine\C\WINDOWS\system32\severe.exe.vir
2007-04-17 10:40      69246    --a------    C:\Qoobox\Quarantine\C\WINDOWS\system32\verclsid.dat.vir
2007-10-02 11:11      260    --a------    C:\Qoobox\Quarantine\C\autorun.inf.vir


Folder PATH listing
Volume serial number is 6A81-82FE
C:\QOOBOX\QUARANTINE
+---C
|   |   autorun.inf.vir
|   |  
|   \---WINDOWS
|       |   svchost.exe.vir
|       |  
|       \---system32
|           |   severe.exe.vir
|           |   verclsid.dat.vir
|           |  
|           \---drivers
|                   conime.exe.vir
|                   jwbnlb.exe.vir
|                  
\---Registry_backups
[/code]
******************************************************************


HijackThis Report
******************************************************************
Logfile of HijackThis v1.99.1
Scan saved at 11:21:02, on 02/10/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\severe.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\drivers\conime.exe
C:\WINDOWS\system32\drivers\conime.exe
C:\Program Files\Java\j2re1.4.2_01\bin\jusched.exe
C:\WINDOWS\system32\severe.exe
C:\WINDOWS\system32\drivers\conime.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\HP\HP Software Update\HPWuSchd.exe
C:\WINDOWS\system32\severe.exe
C:\WINDOWS\system32\drivers\conime.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\system32\severe.exe
C:\WINDOWS\system32\severe.exe
C:\WINDOWS\system32\drivers\conime.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\WINDOWS\system32\severe.exe
C:\WINDOWS\system32\drivers\conime.exe
C:\WINDOWS\system32\severe.exe
C:\WINDOWS\system32\drivers\conime.exe
C:\Windows\svchost.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\drivers\jwbnlb.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\qvkwjh.exe
C:\WINDOWS\system32\severe.exe
C:\WINDOWS\system32\qvkwjh.exe
C:\WINDOWS\system32\severe.exe
C:\WINDOWS\system32\drivers\conime.exe
C:\WINDOWS\system32\dwwin.exe
C:\WINDOWS\system32\severe.exe
C:\WINDOWS\system32\dwwin.exe
C:\WINDOWS\system32\drivers\conime.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\system32\severe.exe
C:\WINDOWS\system32\drivers\conime.exe
C:\WINDOWS\system32\drivers\jwbnlb.exe
C:\WINDOWS\system32\severe.exe
C:\WINDOWS\system32\drivers\conime.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\severe.exe
C:\WINDOWS\system32\drivers\conime.exe
C:\WINDOWS\system32\severe.exe
C:\WINDOWS\system32\drivers\conime.exe
C:\WINDOWS\system32\qvkwjh.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\severe.exe
C:\WINDOWS\system32\drivers\conime.exe
C:\WINDOWS\system32\dwwin.exe
C:\WINDOWS\system32\severe.exe
C:\WINDOWS\system32\drivers\conime.exe
C:\WINDOWS\system32\severe.exe
C:\WINDOWS\system32\drivers\conime.exe
C:\WINDOWS\system32\severe.exe
C:\WINDOWS\system32\drivers\conime.exe
C:\Documents and Settings\Administrator\Desktop\Cleaning and Fixing Tools\HijackThis\alternativ.exe
C:\WINDOWS\system32\severe.exe
C:\WINDOWS\system32\drivers\conime.exe
C:\WINDOWS\system32\severe.exe
C:\WINDOWS\system32\drivers\conime.exe
C:\WINDOWS\system32\severe.exe
C:\WINDOWS\system32\drivers\conime.exe
C:\WINDOWS\system32\severe.exe
C:\WINDOWS\system32\drivers\conime.exe
C:\WINDOWS\system32\severe.exe
C:\WINDOWS\system32\drivers\conime.exe
C:\WINDOWS\system32\severe.exe
C:\WINDOWS\system32\drivers\conime.exe
C:\WINDOWS\system32\severe.exe
C:\WINDOWS\system32\drivers\conime.exe
C:\WINDOWS\system32\severe.exe
C:\WINDOWS\system32\drivers\conime.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://awesomehomepage.com/newsletter.php?list=flashfunpages
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr7/*http://www.yahoo.com/ext/search/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr7/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 192.168.5.223:8080
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\system32\drivers\conime.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\Common\YIeTagBm.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_01\bin\jusched.exe
O4 - HKLM\..\Run: [srmclean] C:\Cpqs\Scom\srmclean.exe
O4 - HKLM\..\Run: [SetRefresh] C:\Program Files\Compaq\SetRefresh\SetRefresh.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [DXDllRegExe] dxdllreg.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [Yahoo Messenger] C:\WINDOWS\system\svchost32.exe
O4 - HKLM\..\Run: [jwbnlb] C:\WINDOWS\system32\qvkwjh.exe
O4 - HKLM\..\Run: [qvkwjh] C:\WINDOWS\system32\severe.exe
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe"
O4 - HKLM\..\Run: [(Default)] C:\Windows\svchost.exe
O4 - HKLM\..\Run: [CPQEASYBTTN] C:\WINDOWS\system32\BttnServ.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SDFix] C:\SDFix\RunThis.bat /second
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [WinUpdater] "C:\Program Files\WinUpdater\update.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [avpa] C:\WINDOWS\system32\avpo.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_01\bin\npjpi142_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_01\bin\npjpi142_01.dll
O9 - Extra button: Web Anti-Virus - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei/MyFunCardsFWBInitialSetup1.0.0.15.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,83/mcinsctl.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,20/mcgdmgr.cab
O16 - DPF: {C4847596-972C-11D0-9567-00A0C9273C2A} (Crystal Report Smart Viewer 7) - http://reports.minecofin.gov.rw:8089/viewer/activeXViewer/activexviewer.cab
O20 - Winlogon Notify: igfxcui - igfxsrvc.dll (file missing)
O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Kaspersky Anti-Virus 6.0 (AVP) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe" -r (file missing)
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
********************************************************************************************************************

Please see these report. I hope that now you will be completely aware of the problem.

Please also look at the error screens. It will clear everything. It is my request that you don't neglect the files that I am posting on www.ee-stuff.com

( I know that the last solution is formatting but if there are some chances to get ride of these problems then I think it is better to find solution rather than formatting.)

Thanks,

Hemant

 

by: JatinHemantPosted on 2007-10-02 at 03:20:31ID: 19997256

Please see the links, I have post two jpeg files (named Error Screen 1.jpg and Error Screen 2.jpg)  here :

The Direct Links are:
http://www.ee-stuff.com/Expert/Upload/getFile.php?fid=4882
and
http://www.ee-stuff.com/Expert/Upload/getFile.php?fid=4883

And link for all the files for this question is:
http://www.ee-stuff.com/Expert/Upload/viewFilesQuestion.php?qid=22828907

Thanks,

Hemant




 

by: JatinHemantPosted on 2007-10-02 at 06:44:05ID: 19998497

Hi

You see that I used third pc where I had Kaspersky Antivirus 6.0 and I made the defective hard disk as slave and scanned and it found some viruses and now it is OK. it detected the following files infected and I deleted them. These were the infected files (Kaspersky log)...

Kaspersky Log:
*********************************************************************************
Status      Object
------      ------
detected: virus Email-Worm.Win32.VB.cb      File: E:\qoobox\Quarantine\C\WINDOWS\svchost.exe.vir
detected: virus Packed.Win32.NSAnti.r      File: E:\qoobox\Quarantine\C\WINDOWS\system32\severe.exe.vir
detected: virus Packed.Win32.NSAnti.r      File: E:\qoobox\Quarantine\C\WINDOWS\system32\verclsid.dat.vir
detected: virus Packed.Win32.NSAnti.r      File: E:\qoobox\Quarantine\C\WINDOWS\system32\drivers\conime.exe.vir
detected: virus Packed.Win32.NSAnti.r      File: E:\qoobox\Quarantine\C\WINDOWS\system32\drivers\jwbnlb.exe.vir
detected: virus Worm.Win32.VB.du      File: E:\Recycled\CTFMON.EXE//ASPack
detected: virus Worm.Win32.VB.du      File: E:\Recycled\SMSS.EXE//ASPack
detected: virus Worm.Win32.VB.du      File: E:\Recycled\SPOOLSV.EXE//ASPack
detected: virus Worm.Win32.VB.du      File: E:\recycled\SVCHOST.EXE//ASPack
detected: Trojan program Trojan.Win32.Qhost.kh      File: E:\SDFix\backups\HOSTS
detected: virus Email-Worm.Win32.VB.cb      File: E:\WINDOWS\winst.log
detected: virus Email-Worm.Win32.VB.cb      File: E:\WINDOWS\system32\BttnServ.exe
detected: Trojan program Trojan.BAT.KillAV.ec      File: E:\WINDOWS\system32\hx1.bat
detected: Trojan program Trojan-PSW.Win32.OnLineGames.pi      File: E:\WINDOWS\system32\qvkwjh.dll
detected: virus Packed.Win32.NSAnti.r      File: E:\WINDOWS\system32\qvkwjh.exe
detected: virus Packed.Win32.NSAnti.r      File: E:\WINDOWS\system32\severe.exe
detected: virus Packed.Win32.NSAnti.r      File: E:\WINDOWS\system32\drivers\conime.exe
detected: virus Packed.Win32.NSAnti.r      File: E:\WINDOWS\system32\drivers\jwbnlb.exe
detected: Trojan program Trojan.Win32.Qhost.kh      File: E:\WINDOWS\system32\drivers\etc\hosts

*********************************************************************************

Now when I removed the hard disk and connected it again in its original pc and try to install Kaspersky Antivirus 6.0 it is installed but when I try to go to the console from Start---.All Programs--->Kaspersky Antivirus--->Kaspersky Antivirus 6.0 then I receive the error message stating that...

C:\Program Files\Kaspersy Labs\Kaspersky Antivirus 6.0\avp.exe can not be found. Make sure that filename is correct.....

When I search for this file in the following location, I can see this file.

Can you tell me what may be the problem ?

Thanks,

Hemant

 

by: rpggamergirlPosted on 2007-10-06 at 17:38:53ID: 20028845

Sorry Hemant, I only got the alert when you posted your last post.
ghees, the logs showed heavily infected pc.

So, now the pc is clean but Kaspersky is not working? Is it only Kaspersky not working? how about other programs? try uninstalling it and reinstalling?

 

by: JatinHemantPosted on 2007-10-06 at 23:48:04ID: 20029371

Thanks for your reply,

You see only Kaspersky is not being installed. I installed it completely and checked but it gives the same error. It is listed in the All Programs list but when I click on it, it gives me the error message dialog box stating that...

C:\Program Files\Kaspersy Labs\Kaspersky Antivirus 6.0\avp.exe can not be found. Make sure that filename is correct.....

And as I told you that when I locate this file avp.exe, then I find it there. So I am surprised why this problem is coming.

I am little bit hesistating to ask you the question as I have been discussing on this qvkwjh.exe error for a long time with you and SheharyaarSaahil. I understand that sometimes it is better to format the pc as it is also time saving. BUT...I think the formation of pc as a last resort. So I continued with this error.

I am happy that with your help, I succeeded to get ride of this qvkwjh.exe (As I told you that I removed the infected hard disk and made it slave to another pc and run with Kaspersky so Kaspersky detected them and deleted them. When I again connected the scanned hard disk to its original pc, this error was not there. Every thing was OK...except that Kaspersky is not being installed.

Bye the way, if I will not be able to install Kaspesky then I will install another Antivirus, so it isn't a big problem.

I am always thankful for your continuous support.

Regards,

Hemant

20120131-EE-VQP-002

3 Ways to Join

30-Day Free Trial

The Experts

98% positive feedback on 31,087 answers since March 2000. angeliii is a Microsoft Most Valuable Professional for his work with MS SQL Server & Develoment.

He has also proven his knowledge of Visual Basic Programming, PHP Scripting and Oracle Databases.

The Experts

97% positive feedback on 10,752 answers since July 2000. lrmoore has more than 18 years experience in the networking industry.

The six-time Mircosoft MVPs specialties include firewalls, virtual private networking, and network management.

Testimonials

"...and excellent source for support... Kind of like having your very own IT dept." Electriciansnet

Testimonials

"I was apprehensive at signing up at first. However... it has already made my life as an IT administrator much easier." JaCrews

Testimonials

"WOW! You guys have great, active, and knowledgeable people on here." moore50

Business Clients

Business Clients

In the Press

"If you’ve got a question... Experts Exchange can supply an answer.”

In the Press

"...an invaluable aid for both IT professionals and those who require tech support."

In the Press

"where IT professionals provide quick answers on just about any topic"

Business Account Plans

Loading Advertisement...