This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] HJT Log - all kinds of trojans

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

my told me that she was getting all kinds of popups and that it was running really slow and since i know just enough to be dangerous i ran hjt and some other spyware and anti-virus programs and this stuff is way beyond my abilities. so here';s the log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:39:25 PM, on 5/16/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\afisicx.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\dhcp\svchost.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\system32\sopidkc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\tdctxte.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Scott\apps\security\hackthis\HijackThis.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\DOCUME~1\Scott\LOCALS~1\Temp\2651750294.exe
C:\Scott\apps\security\hjt\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.guarddog2009.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://global.acer.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://global.acer.com/
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\ntos.exe,
O2 - BHO: C:\WINDOWS\system32\sdrgfcvbf.dll - {C2BA40A1-74F3-42BD-F434-12345A2C8953} - C:\WINDOWS\system32\sdrgfcvbf.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
O4 - HKLM\..\Run: [AzMixerSel] C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
O4 - HKLM\..\Run: [ntiMUI] C:\Program Files\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe
O4 - HKLM\..\Run: [Acer ePresentation HPD] C:\Acer\Empowering Technology\ePresentation\ePresentation.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\LManager.exe
O4 - HKLM\..\Run: [KTPWare] C:\Program Files\Elantech\ktp.exe
O4 - HKLM\..\Run: [Java Load] C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\websvr.exe
O4 - HKLM\..\Run: [reader_s] C:\WINDOWS\System32\reader_s.exe
O4 - HKLM\..\Run: [autochk] rundll32.exe C:\WINDOWS\system32\autochk.dll,_IWMPEvents@16
O4 - HKLM\..\Run: [svchost.exe] "C:\WINDOWS\system32\3361\SVCHOST.exe"
O4 - HKLM\..\Run: [Secure AntiVirus Pro] C:\WINDOWS\AV.EXE
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [reader_s] C:\Documents and Settings\Scott\reader_s.exe
O4 - HKCU\..\Run: [Diagnostic Manager] C:\DOCUME~1\Scott\LOCALS~1\Temp\2651750294.exe
O4 - HKUS\S-1-5-19\..\Run: [ginukotuhe] Rundll32.exe "C:\WINDOWS\system32\ravufuge.dll",s (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [] C:\WINDOWS\TEMP\mylk1b5q.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Diagnostic Manager] C:\WINDOWS\TEMP\2388592568.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [reader_s] C:\Documents and Settings\LocalService\reader_s.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [svc] C:\program Files\ThunMail\testabd.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [nDler2] \\?\globalroot\systemroot\system32\nDler2.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [autochk] rundll32.exe C:\DOCUME~1\NETWOR~1\protect.dll,_IWMPEvents@16 (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [uidenhiufgsduiazghs] C:\WINDOWS\TEMP\v7yj9qtrmh.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [] C:\WINDOWS\TEMP\mylk1b5q.exe (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFrameWork/v10/StagingUI.cab55579.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1DB93715-3B60-43EE-93E6-279BB3E1DF76} (OCXDownloadChecker Control) - http://moes974.srsflex.com/cab/OCXChecker_6110.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (MSN Games – Buddy Invite) - http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab55579.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by134fd.bay134.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/binframework/v10/ZPAChat.cab55579.cab
O16 - DPF: {80B626D6-BC34-4BCF-B5A1-7149E4FD9CFA} (UnoCtrl Class) - http://zone.msn.com/bingame/zpagames/GAME_UNO1.cab60096.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (MSN Games – Game Communicator) - http://zone.msn.com/binframework/v10/StProxy.cab55579.cab
O16 - DPF: {FF3C5A9F-5A99-4930-80E8-4709194C2AD3} (MSN Games – Backgammon) - http://zone.msn.com/bingame/zpagames/ZPA_B…on.cab64162.cab
O20 - AppInit_DLLs: c:\windows\system32\lolajeyo.dll ,c:\progra~1\ThunMail\testabd.dll
O20 - Winlogon Notify: !saswinlogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O22 - SharedTaskScheduler: lkjf9873jhifjnsfi8w3fe - {D5BF49A0-94F3-42BD-F434-3604812C8955} - C:\WINDOWS\system32\zfgh83jg3.dll
O22 - SharedTaskScheduler: jso8joigm409gopgmrlgd - {B2BA40A2-74F0-42BD-F434-12345A2C8953} - C:\WINDOWS\system32\kjsdiowq8oikf.dll
O22 - SharedTaskScheduler: sdfsefsfdvdubgiungfuyd - {C2BA40A1-74F3-42BD-F434-12345A2C8953} - C:\WINDOWS\system32\sdrgfcvbf.dll
O23 - Service: Memory Check Service (AcerMemUsageCheckService) - Acer Inc. - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: afisicx Service (afisicx) - Unknown owner - C:\WINDOWS\system32\afisicx.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Background Intelligent Transfer Service (BITS) - Unknown owner - C:\WINDOWS\
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Dhcp server (dhcpsrv) - Unknown owner - C:\WINDOWS\dhcp\svchost.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: sopidkc Service (sopidkc) - Unknown owner - C:\WINDOWS\system32\sopidkc.exe
O23 - Service: SPBBCSvc - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: tdctxte Service (tdctxte) - Unknown owner - C:\WINDOWS\system32\tdctxte.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

–
End of file - 12212 bytes

i also got a corrupt file popup when i ran hjt.

let me know where to start. thanks
Hi,

From the initial analysis, this machine is very heavily infected.
there are signs you have VIRUT which is a polymorphic file infector.
The only course of action is a total reformat and reinstall.

To confirm this - please do the following:


  • Make sure to use Internet Explorer for this
  • Please go to VirSCAN.org FREE on-line scan service
  • Copy and paste the following file path into the "Suspicious files to scan" box on the top of the page:
    • C:\Documents and Settings\Scott\reader_s.exe
  • Click on the Upload button
  • If a pop-up appears saying the file has been scanned already, please select the ReScan button.
  • Once the Scan is completed, click on the "Copy to Clipboard" button. This will copy the link of the report into the Clipboard.

    Do the same for the following files:

    C:\WINDOWS\System32\reader_s.exe
    C:\Documents and Settings\LocalService\reader_s.exe
    C:\WINDOWS\system32\userinit.exe
    C:\WINDOWS\system32\ntos.exe

  • Paste the contents of the Clipboards in your next reply.
it couldnt find the first file.

this is the 2nd: C:\WINDOWS\System32\reader_s.exe
VirSCAN.org Scanned Report :
Scanned time : 2009/05/16 17:00:06 (EDT)
Scanner results: 92% Scanner(35/38) found malware!
File Name : reader_s.exe
File Size : 76288 byte
File Type : PE32 executable for MS Windows (GUI) Intel 80386 32-bit
MD5 : 334515d950e681d16a762c737098a5aa
SHA1 : 2b40790c69f9a7aa0832f23d8a98c2b2ff3c2436
Online report : http://virscan.org/report/38e8792489a5aa62…38285ed7b1.html

Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 4.0.0.32 20090516190230 2009-05-16 2.85 Trojan-Downloader.Win32.Adload!IK
AhnLab V3 2009.05.17.00 2009.05.17 2009-05-17 1.01 Win-Trojan/Agent.36352.IN
AntiVir 8.2.0.168 7.1.3.215 2009-05-15 0.41 W32/Sality.L
Antiy 2.0.18 20090516.2420010 2009-05-16 0.12 -
Arcavir 2009 200905160757 2009-05-16 0.03 W32.Sality.L
Authentium 5.1.1 200905161041 2009-05-16 1.11 W32/Sality.K (Exact)
AVAST! 4.7.4 090516-0 2009-05-16 0.01 Win32:Sality-AB
AVG 8.5.286 270.12.32/2118 2009-05-17 3.20 Win32/Sality
BitDefender 7.81008.2985031 7.25443 2009-05-17 2.77 Trojan.Agent.AMOR
CA (VET) 9.0.0.143 31.6.6507 2009-05-16 7.78 Win32/Virut.17408 virus.
ClamAV 0.95 9364 2009-05-16 0.01 W32.Sality.N
Comodo 3.8 1157 2009-05-08 0.73 -
CP Secure 1.1.0.715 2009.05.17 2009-05-17 9.06 W32.Sality.L
Dr.Web 4.44.0.9170 2009.05.16 2009-05-16 4.54 Win32.Virut.56
F-Prot 4.4.4.56 20090516 2009-05-16 1.10 W32/Sality.K (exact)
F-Secure 5.51.6100 2009.05.16.01 2009-05-16 5.50 Virus.Win32.Sality.l [AVP]
Fortinet 2.81-3.117 10.396 2009-05-16 0.20 W32/Sality.K
GData 19.5251/19.333 20090516 2009-05-16 3.70 Virus.Win32.Sality.l [Engine:A]
ViRobot 20090515 2009.05.15 2009-05-15 0.41 Backdoor.Win32.Small.36352.D
Ikarus T3.1.01.49 2009.05.16.72727 2009-05-16 3.18 Trojan-Downloader.Win32.Adload
JiangMin 11.0.706 2009.05.16 2009-05-16 1.85 Win32/HLLP.Kuku.a
Kaspersky 5.5.10 2009.05.16 2009-05-16 0.05 Virus.Win32.Sality.l
KingSoft 2009.2.5.15 2009.5.16.21 2009-05-16 0.52 Win32.Virut.xd.19328
McAfee 5.3.00 5616 2009-05-15 2.87 W32/Sality.n
Microsoft 1.4602 2009.05.15 2009-05-15 4.50 Virus:Win32/Virut.BM
mks_vir 2.01 2009.05.16 2009-05-16 3.22 -
Norman 6.01.05 6.01.00 2009-05-15 4.01 W32/Sality.N
Panda 9.05.01 2009.05.16 2009-05-16 1.61 W32/Sality.O
Trend Micro 8.700-1004 6.134.06 2009-05-16 0.02 PE_SALITY.AE
Quick Heal 10.00 2009.05.15 2009-05-15 1.18 W32.Sality.K
Rising 20.0 21.29.52.00 2009-05-16 0.89 Worm.Win32.Agent.aph
Sophos 2.86.0 4.41 2009-05-17 2.33 W32/Sality-AI
Sunbelt 5139 5139 2009-05-16 0.87 Virus.Win32.Virut.ce (v)
Symantec 1.3.0.24 20090516.003 2009-05-16 0.05 W32.Virut.CF
nProtect 20090516.01 3700025 2009-05-16 5.31 Trojan.Agent.AMOR
The Hacker 6.3.4.1 v00326 2009-05-15 0.64 W32/Virut.gen2
VBA32 3.12.10.5 20090515.1445 2009-05-15 1.84 Win32.HLLP.Kuku.304
VirusBuster 4.5.11.10 10.105.28/1378347 2009-05-16 1.77 Win32.Sality.L

it couldnt find the 3rd

the fourth
VirSCAN.org Scanned Report :
Scanned time : 2009/05/16 17:05:50 (EDT)
Scanner results: 71% Scanner(27/38) found malware!
File Name : userinit.exe
File Size : 44032 byte
File Type : PE32 executable for MS Windows (GUI) Intel 80386 32-bit
MD5 : bb5fb3e8a4ddcb7240a9b211debdbcfe
SHA1 : c5bd3dba2cd9c960c2195900ca895d001e49978f
Online report : http://virscan.org/report/816d41d6df158874…7c7f114de4.html

Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 4.0.0.32 20090516190230 2009-05-16 2.64 -
AhnLab V3 2009.05.17.00 2009.05.17 2009-05-17 0.73 Win32/Virut.E
AntiVir 8.2.0.168 7.1.3.215 2009-05-15 0.15 W32/Virut.Gen
Antiy 2.0.18 20090516.2420010 2009-05-16 0.12 -
Arcavir 2009 200905160757 2009-05-16 0.10 -
Authentium 5.1.1 200905161041 2009-05-16 1.54 W32/Virut.AI!Generic (Possible)
AVAST! 4.7.4 090516-0 2009-05-16 0.01 Win32:Vitro
AVG 8.5.286 270.12.32/2118 2009-05-17 3.27 Win32/Virut
BitDefender 7.81008.2985350 7.25445 2009-05-17 2.76 Win32.Virtob.Gen.12
CA (VET) 9.0.0.143 31.6.6507 2009-05-16 3.22 Win32/Virut.17408 virus.
ClamAV 0.95 9364 2009-05-16 0.02 -
Comodo 3.8 1157 2009-05-08 0.72 -
CP Secure 1.1.0.715 2009.05.17 2009-05-17 9.14 -
Dr.Web 4.44.0.9170 2009.05.16 2009-05-16 4.51 Win32.Virut.56
F-Prot 4.4.4.56 20090516 2009-05-16 1.45 W32/Virut.AI!Generic
F-Secure 5.51.6100 2009.05.16.01 2009-05-16 0.06 Virus.Win32.Virut.ce [AVP]
Fortinet 2.81-3.117 10.396 2009-05-16 0.19 W32/Virut.CE
GData 19.5251/19.333 20090516 2009-05-16 4.81 Virus.Win32.Virut.ce [Engine:A]
ViRobot 20090515 2009.05.15 2009-05-15 0.41 -
Ikarus T3.1.01.49 2009.05.16.72727 2009-05-16 5.21 -
JiangMin 11.0.706 2009.05.16 2009-05-16 2.01 Win32/Virut.bn
Kaspersky 5.5.10 2009.05.16 2009-05-16 0.05 Virus.Win32.Virut.ce
KingSoft 2009.2.5.15 2009.5.16.21 2009-05-16 0.58 Win32.Virut.xd.19328
McAfee 5.3.00 5616 2009-05-15 2.88 W32/Virut.n.gen
Microsoft 1.4602 2009.05.15 2009-05-15 4.46 Virus:Win32/Virut.BM
mks_vir 2.01 2009.05.16 2009-05-16 3.13 Trojan.Exploit.Iis.Printeroverflow.C
Norman 6.01.05 6.01.00 2009-05-15 4.01 W32/Virut.CG
Panda 9.05.01 2009.05.16 2009-05-16 1.63 -
Trend Micro 8.700-1004 6.134.09 2009-05-16 0.03 PE_VIRUX.F-1
Quick Heal 10.00 2009.05.15 2009-05-15 1.17 W32.Virut.G
Rising 20.0 21.29.52.00 2009-05-16 0.90 Win32.Virut.bm
Sophos 2.86.0 4.41 2009-05-17 2.34 W32/Scribble-B
Sunbelt 5139 5139 2009-05-16 0.78 Virus.Win32.Virut.ce (v)
Symantec 1.3.0.24 20090516.003 2009-05-16 0.06 W32.Virut.CF
nProtect 20090516.01 3700025 2009-05-16 5.06 -
The Hacker 6.3.4.1 v00326 2009-05-15 0.62 W32/Virut.gen2
VBA32 3.12.10.5 20090515.1445 2009-05-15 2.08 -
VirusBuster 4.5.11.10 10.105.28/1378347 2009-05-16 1.76 Win32.Virut.Y.Gen

and it didnt find the 5th

i have the system restore disk that we made when we bought the machine, but now its not finding the cd drive
Hi,

Sorry it has been confirmed that VIRUT is the infection.

I have included my usual explanation of the infection and how to deal with it.

If you now need assistance in reformatting please post a new topic in our windows forum - title it "Reformat help needed after Virut infection"

Advise I have sent you and link back to this topic, let the experts in our tech section guide you on the best way to reformat.



We have an excellent tutorial on how to reformat here

Things to bear in mind, only back up data files (word, excell etc.) DO NOT backup any .exe/.scr/.htm/.html/.xml/.zip/.pif/.com/.rar files… as they could all be infected and will simply re-infect your system again, there is no way of being certain what this infection can do.

Read more about the VIRUT FILE INFECTOR HERE

Here is a guide on backing up your data;
Although you can use whatever method you prefer.

Do not back up to another machine, as it may become compromised.

Burn to DVD/CD, or to an external drive which has nothing else on it, and which you can format should it happen to become infected from the backups.

I am sorry there is nothing more that we can do.


More information:

http://free.avg.com/66558
There are bugs in the viral code. When the virus produces infected files, it also creates non-functional files that also contain the virus.

http://home.mcafee.com/VirusInfo/VirusProf…aspx?key=143034
W32/Virut.h is a polymorphic, entry point obscuring (EPO) file infector with IRC bot functionality. It can accept commands to download other malware on the compromised machine.
It appends to the end of the last section of executable (PE) files an encrypted copy of its code. The decryptor is polymorphic and can be located either:
Immediately before the encrypted code at the end of the last section
At the end of the code section of the infected host in 'slack-space' (assuming there is any)
At the original entry point of the host (overwriting the original host code)



Miekiemoes
, a highly regarded expert in malware removal, and an MS-MVP,
has an extremely informative blog post about Virut. - she only ever recommends a total reformat.

At least this way, you have the best chance of having a clean machine once more.

For future protection read this very well written article Think Prevention.
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI