Hi,
I had a virus the red circle with the White x in it. I followed the suggestions on here and Ran Malwarebytes, smitfraud, and SDfix. they were all ran in safe mode because if I logn in normal it loads up and then shuts down. Maleware bytes and smitfraud didn't find anything. Also ran avast at boot and found nothing.
SDfix did and this is the log
[b]SDFix: Version 1.240 [/b]
Run by Administrator on Tue 08/18/2009 at 08:31
Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix
[b]Checking Services [/b]:
Restoring Default Security Values
Restoring Default Hosts File
Rebooting
[b]Checking Files [/b]:
Trojan Files Found:
C:\WINDOWS\system32\bravia
x.exe - Deleted
Removing Temp Files
[b]ADS Check [/b]:
[b]Final Check [/b]:
catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-08-18 08:40:06
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
scanning hidden registry entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
[b]Remaining Services [/b]:
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system
\currentco
ntrolset\s
ervices\sh
aredaccess
\parameter
s\firewall
policy\sta
ndardprofi
le\authori
zedapplica
tions\list
]
"%windir%\\system32\\sessm
gr.exe"="%
windir%\\s
ystem32\\s
essmgr.exe
:*:enabled
:@xpsp2res
.dll,-2201
9"
"C:\\Program Files\\Messenger\\msmsgs.e
xe"="C:\\P
rogram Files\\Messenger\\msmsgs.e
xe:*:Enabl
ed:Windows
Messenger"
"C:\\Program Files\\Symantec\\pcAnywher
e\\AWHOST3
2.EXE"="C:
\\Program Files\\Symantec\\pcAnywher
e\\AWHOST3
2.EXE:*:Di
sabled:pcA
nywhere Host Service"
"C:\\Program Files\\Symantec\\pcAnywher
e\\awrem32
.exe"="C:\
\Program Files\\Symantec\\pcAnywher
e\\awrem32
.exe:*:Dis
abled:pcAn
ywhere Remote Service"
"C:\\Program Files\\LimeWire\\LimeWire.
exe"="C:\\
Program Files\\LimeWire\\LimeWire.
exe:*:Disa
bled:LimeW
ire"
[HKEY_LOCAL_MACHINE\system
\currentco
ntrolset\s
ervices\sh
aredaccess
\parameter
s\firewall
policy\dom
ainprofile
\authorize
dapplicati
ons\list]
"%windir%\\system32\\sessm
gr.exe"="%
windir%\\s
ystem32\\s
essmgr.exe
:*:enabled
:@xpsp2res
.dll,-2201
9"
[b]Remaining Files [/b]:
File Backups: - C:\SDFix\backups\backups.z
ip
[b]Files with Hidden Attributes [/b]:
Mon 9 Jan 2006 4,348 A.SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Tue 30 Oct 2007 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tm
p"
Wed 31 Oct 2007 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv02.tm
p"
[b]Finished![/b]
Ran hijack this and this is the log file
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 09:24:39, on 8/18/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Safe mode with network support
Running processes:
C:\WINDOWS\System32\smss.e
xe
C:\WINDOWS\system32\winlog
on.exe
C:\WINDOWS\system32\servic
es.exe
C:\WINDOWS\system32\lsass.
exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThi
s.exe
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0
819E2EAAC9
3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClien
t.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-0
09027A5CD4
F} - c:\program files\google\googletoolbar
4.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin
\jusched.e
xe"
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\D
VDLauncher
.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe
" -atboottime
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.e
xe" runtime
O4 - HKLM\..\Run: [WinVNC] "C:\Program Files\RealVNC\WinVNC\WinVN
C.exe" -servicehelper
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTra
y.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast
4\ashDisp.
exe
O4 - HKLM\..\Run: [braviax] C:\WINDOWS\system32\bravia
x.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon
.exe
O4 - HKCU\..\Run: [braviax] C:\WINDOWS\system32\bravia
x.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: ATI CATALYST System Tray.lnk = C:\Program Files\ATI Technologies\ATI.ACE\CLI.e
xe
O4 - Global Startup: office.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2
\OFFICE11\
EXCEL.EXE/
3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-0
0401C60850
1} - C:\Program Files\Java\jre1.5.0_10\bin
\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-0
0401C60850
1} - C:\Program Files\Java\jre1.5.0_10\bin
\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3
C9C571A826
3} - C:\PROGRA~1\MICROS~2\OFFIC
E11\REFIEB
AR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C
7C580BBF70
0} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft.com/fwlink/?linkid=48835O16 - DPF: {6414512B-B978-451D-A0D8-F
CFDF33E833
C} (WUWebControl Class) -
http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1111067940859O16 - DPF: {A90A5822-F108-45AD-8482-9
BC8B12DD53
9} (Crucial cpcScan) -
http://www.crucial.com/controls/cpcScanner.cabO17 - HKLM\System\CCS\Services\T
cpip\Param
eters: Domain = allied.ad
O17 - HKLM\Software\..\Telephony
: DomainName = allied.ad
O17 - HKLM\System\CCS\Services\T
cpip\..\{6
C2079B4-5B
E3-48B9-A9
BD-9388346
54323}: Domain = allied-online.com
O17 - HKLM\System\CS1\Services\T
cpip\Param
eters: Domain = allied.ad
O17 - HKLM\System\CS1\Services\T
cpip\Param
eters: SearchList = allied-online.com
O17 - HKLM\System\CS1\Services\T
cpip\..\{6
C2079B4-5B
E3-48B9-A9
BD-9388346
54323}: Domain = allied-online.com
O17 - HKLM\System\CCS\Services\T
cpip\Param
eters: SearchList = allied-online.com
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.e
xe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2ev
xx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.ex
e
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.e
xe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.e
xe
O23 - Service: pcAnywhere Host Service (awhost32) - Symantec Corporation - C:\Program Files\Symantec\pcAnywhere\
awhost32.e
xe
O23 - Service: Broadcom ASF IP monitoring service v6.0.4 (BAsfIpM) - Broadcom Corp. - C:\WINDOWS\system32\basfip
m.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Google Update Service (gupdate1c9f0358c877af) (gupdate1c9f0358c877af) - Google Inc. - C:\Program Files\Google\Update\Google
Update.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google
Updater\GoogleUpdaterServi
ce.exe
O23 - Service: IAA Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEU
P~1\LUCOMS
~1.EXE
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: SysAid Agent (SysAidAgent) - Ilient Ltd. - C:\Program Files\SysAid\\IliAS.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\Vie
wpointServ
ice.exe
O23 - Service: VNC Server (winvnc) - RealVNC Ltd. - C:\Program Files\RealVNC\WinVNC\WinVN
C.exe
--
End of file - 6388 bytes