Dear friends !
I am facing a very seriour problem in one of my pc. The pc is infected with viruses. When I installed McAfee Enterprise Edition Trial Version, it detected Virus-Worms and Trojans. Two of those threats are Trojans and they couldn't be deleted by the antivirus software. (Though AV informs that it has detected and deleted the Trojans but the pop-up window comes again.)
Please look at the general information about the files...
Name: hosts
In Folder: C:\WINDOWS\system32\driver
s\etc
Detected As: PWS-QQRob!hosts
Detection Type: Trojan
Status : Deleted
Application infected: C :\WINDOWS\system32\svchost
.exe
Name: qvkwjh.dll C:\WINDOWS\system32
In Folder: C:\WINDOWS\system32
Detected As: Generic PWS-y
Detection Type: Trojan
Status : Deleted
Application infected: (THIS LOCATION ALWAYS VARIES, BUT IT IS ALWAYS APPLICATION ' S EXE FILE)
Now the problems are:
1. I can't run any application. When I try to run any application, the Virus Scanning Screen Pops up and shows that threats were detected and deleted.
2. I can't run ComboFix, CCleaner, SDFix, Spybot-Search & Destroy.
3. I can't remove the McAfee Antivirus because I can't reach up to Add/Remove Programs
4. I want to install Kaspersky Antivirus Software but I can't. When I try to run the executable file for this antivirus, it again gives me pop up window for virus information.
5. I can't do anything because this Virus Information Screen pops up again and again and disturbs me.
I shared the hard disk of this pc and scanned it from another pc where I have Kaspersky Antivirus Software installed and updated. But I found only one virus. (The short log for Kaspersky is here below)
AV detected the one and only virus
detected:Virus Packed.Win32.NSAnti.r
Infected object: C:\ntde1ect.com
I am sending the HijackThis log. (Previously it was my luck that I could run HijackThis tool and could get the log)
Please see the HijackThis log:
Logfile of HijackThis v1.99.1
Scan saved at 10:36:40 AM, on 9/14/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.e
xe
C:\WINDOWS\system32\winlog
on.exe
C:\WINDOWS\system32\servic
es.exe
C:\WINDOWS\system32\lsass.
exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\system32\spools
v.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\ctfmon
.exe
C:\Program Files\Aclient\AClient.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.e
xe
C:\Program Files\McAfee\Common Framework\FrameworkService
.exe
C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Analog Devices\SoundMAX\SMAgent.e
xe
C:\WINDOWS\system32\svchos
t.exe
C:\Program Files\Yahoo!\Messenger\yms
gr_tray.ex
e
C:\WINDOWS\system32\HPBPRO
.EXE
C:\WINDOWS\system32\severe
.exe
C:\WINDOWS\system32\driver
s\conime.e
xe
C:\WINDOWS\system32\wscntf
y.exe
C:\WINDOWS\system32\cmd.ex
e
C:\WINDOWS\system32\cmd.ex
e
C:\WINDOWS\system32\cmd.ex
e
C:\WINDOWS\system32\cmd.ex
e
C:\WINDOWS\system32\qvkwjh
.exe
\192.168.5.85\bd85\ReadMeF
irst\Hijac
kThis\alte
rnativ.exe
C:\WINDOWS\system32\dwwin.
exe
R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Search Bar =
http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.htmlR1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Search Page =
http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.comR1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Page
_URL =
http://www.yahoo.com/R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Sear
ch_URL =
http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.comR1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Search Bar =
http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.htmlR1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Search Page =
http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.comR0 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://www.yahoo.com/R1 - HKCU\Software\Microsoft\In
ternet Explorer\SearchURL,(Defaul
t) =
http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.comR1 - HKCU\Software\Microsoft\Wi
ndows\Curr
entVersion
\Internet Settings,ProxyServer = 192.168.5.223:8080
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0
090271D4F8
8} - C:\PROGRA~1\Yahoo!\Compani
on\Install
s\cpn\yt.d
ll
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\system32\driver
s\conime.e
xe
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7
695ECA0567
0} - C:\PROGRA~1\Yahoo!\Compani
on\Install
s\cpn\yt.d
ll
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-7
84B7D6BE0B
3} - C:\Program Files\Common Files\Adobe\Acrobat\Active
X\AcroIEHe
lper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2
FC0DE4A789
7} - C:\Program Files\Yahoo!\Common\yiesrv
c.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6
309F01C523
1} - C:\Program Files\McAfee\VirusScan Enterprise\Scriptcl.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0
090271D4F8
8} - C:\PROGRA~1\Yahoo!\Compani
on\Install
s\cpn\yt.d
ll
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.ex
e
O4 - HKLM\..\Run: [SetRefresh] C:\Program Files\COMPAQ\SetRefresh\\S
etRefresh.
exe
O4 - HKLM\..\Run: [AClntUsr] C:\Program Files\Aclient\AClntUsr.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtr
ay.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.
exe
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe"
O4 - HKLM\..\Run: [StatusClient 2.6] C:\Program Files\Hewlett-Packard\Tool
box\Status
Client\Sta
tusClient.
exe /auto
O4 - HKLM\..\Run: [TomcatStartup 2.5] C:\Program Files\Hewlett-Packard\Tool
box\hpbpst
tp.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [chiCkie] C:\WINDOWS\inf\chiCkie.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dump
rep 0 -k
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtectio
n.exe"
O4 - HKLM\..\Run: [jwbnlb] C:\WINDOWS\system32\qvkwjh
.exe
O4 - HKLM\..\Run: [qvkwjh] C:\WINDOWS\system32\severe
.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe
" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon
.exe
O4 - HKCU\..\Run: [I just want to say I love Milko and I need a drink] C:\Documents and Settings\Sam\Local Settings\Application Data\svchost.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\Yah
ooMessenge
r.exe" -quiet
O4 - HKCU\..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtectio
n.exe
O4 - HKCU\..\Run: [avpa] C:\WINDOWS\system32\avpo.e
xe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync
.exe
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2
\OFFICE11\
EXCEL.EXE/
3000
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2
FC0DE4A789
7} - C:\Program Files\Yahoo!\Common\yiesrv
c.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3
C9C571A826
3} - C:\PROGRA~1\MICROS~2\OFFIC
E11\REFIEB
AR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.d
ll
O16 - DPF: {30528230-99f7-4bb4-88d8-f
a1d4f56a2a
b} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsth
elper.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsr
vc.dll
O23 - Service: Altiris Client Service (AClient) - Altiris, Inc. - C:\Program Files\Aclient\AClient.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - C:\Program Files\Common Files\LightScribe\LSSrvc.e
xe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Unknown owner - C:\Program Files\McAfee\Common Framework\FrameworkService
.exe" /ServiceStart (file missing)
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm
12.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.e
xe
IMP: I HAVE PRINTED THE SCREEN OF THE ERROR BY PRESSING PRINT SCREN KEY OF KEYBOARD. I WANT TO SEND THIS SCREEN SO THAT YOU CAN EASILY JUDGE THE PROBLEM. HOW CAN I SEND IT. I KNOW THAT THERE IS A WAY TO SEND IT, BUT I DON'T KNOW. PLEASE SHOW ME HOW I CAN SEND IT SO THAT EXPERTS CAN GET IT.
Thanks...
Hemant
Start Free Trial