This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] No internet, Antivirus Plus?

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,

There is no internet connect on my computer. I am writing this message from another one. I think someone downloaded a bad program. Antivirus Plus?

I've got two logs here, Malwarebytes and HijackThis.

Any help? In advance, thanks.

Malwarebytes' Anti-Malware 1.37
Database version: 2182
Windows 6.0.6001 Service Pack 1

01/06/2009 11:11:16 AM
mbam-log-2009-06-01 (11-11-11).txt

Scan type: Full Scan (C:\|D:\|)
Objects scanned: 202777
Time elapsed: 30 minute(s), 25 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 1
Registry Keys Infected: 8
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 2
Files Infected: 46

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
C:\Windows\System32\InternetExplorer.dll (Rogue.Agent) -> No action taken.

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d032570a-5f63-4812-a094-87d007c23012} (Trojan.BHO.H) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{d032570a-5f63-4812-a094-87d007c23012} (Trojan.BHO.H) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{d032570a-5f63-4812-a094-87d007c23012} (Rogue.Agent) -> No action taken.
HKEY_CLASSES_ROOT\TypeLib\{86676e13-d6d8-4652-9fcf-f2047f1fb000} (Trojan.BHO) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{83ff80f4-8c74-4b80-b5ba-c8ddd434e5c4} (Trojan.BHO) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{83ff80f4-8c74-4b80-b5ba-c8ddd434e5c4} (Trojan.BHO) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{83ff80f4-8c74-4b80-b5ba-c8ddd434e5c4} (Trojan.BHO) -> No action taken.
HKEY_CLASSES_ROOT\kt_bho.KettleBho (Trojan.BHO) -> No action taken.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\shell (Rogue.Installer) -> No action taken.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Antivirus Plus (Rogue.AntivirusPlus) -> No action taken.
C:\Program Files\Antivirus Plus (Rogue.AntivirusPlus) -> No action taken.

Files Infected:
C:\Windows\System32\InternetExplorer.dll (Trojan.BHO.H) -> No action taken.
C:\Windows\system\rundll32.exe (Rogue.Installer) -> No action taken.
c:\program files\antivirus plus\AntivirusPlus.exe (Rogue.Installer) -> No action taken.
c:\programdata\Partner\partner.dll (Trojan.BHO) -> No action taken.
c:\programdata\Partner\partner.exe (Trojan.BHO) -> No action taken.
c:\Users\Cynthia\AppData\Local\microsoft\Windows\temporary internet files\Content.IE5\B049525H\installer_70195[1].exe (Rogue.Installer) -> No action taken.
c:\Users\Cynthia\AppData\Local\microsoft\Windows\temporary internet files\Content.IE5\NQMIQJ5K\installer_70195[1].exe (Rogue.Installer) -> No action taken.
c:\Users\Cynthia\AppData\Local\microsoft\Windows\temporary internet files\Content.IE5\NQMIQJ5K\installer_70195[2].exe (Rogue.Installer) -> No action taken.
c:\Users\Cynthia\AppData\Local\microsoft\Windows\temporary internet files\Content.IE5\W671AILA\installer_70195[1].exe (Rogue.Installer) -> No action taken.
c:\programdata\microsoft\Windows\start menu\Programs\antivirus plus\Antivirus Plus(1).lnk (Rogue.AntivirusPlus) -> No action taken.
c:\programdata\microsoft\Windows\start menu\Programs\antivirus plus\Antivirus Plus(2).lnk (Rogue.AntivirusPlus) -> No action taken.
c:\programdata\microsoft\Windows\start menu\Programs\antivirus plus\Antivirus Plus.lnk (Rogue.AntivirusPlus) -> No action taken.
c:\programdata\microsoft\Windows\start menu\Programs\antivirus plus\EULA(1).lnk (Rogue.AntivirusPlus) -> No action taken.
c:\programdata\microsoft\Windows\start menu\Programs\antivirus plus\EULA(2).lnk (Rogue.AntivirusPlus) -> No action taken.
c:\programdata\microsoft\Windows\start menu\Programs\antivirus plus\EULA.lnk (Rogue.AntivirusPlus) -> No action taken.
c:\program files\antivirus plus\AntivirusPlus.grn (Rogue.AntivirusPlus) -> No action taken.
c:\Users\Admin\AppData\Roaming\microsoft\internet explorer\quick launch\Antivirus Plus(1).lnk (Rogue.AntivirusPlus) -> No action taken.
c:\Users\Admin\AppData\Roaming\microsoft\internet explorer\quick launch\Antivirus Plus(2).lnk (Rogue.AntivirusPlus) -> No action taken.
c:\Users\Admin\AppData\Roaming\microsoft\internet explorer\quick launch\Antivirus Plus.lnk (Rogue.AntivirusPlus) -> No action taken.
c:\Users\Alex\AppData\Roaming\microsoft\internet explorer\quick launch\Antivirus Plus(1).lnk (Rogue.AntivirusPlus) -> No action taken.
c:\Users\Alex\AppData\Roaming\microsoft\internet explorer\quick launch\Antivirus Plus(2).lnk (Rogue.AntivirusPlus) -> No action taken.
c:\Users\Alex\AppData\Roaming\microsoft\internet explorer\quick launch\Antivirus Plus.lnk (Rogue.AntivirusPlus) -> No action taken.
c:\Users\Ben\AppData\Roaming\microsoft\internet explorer\quick launch\Antivirus Plus(1).lnk (Rogue.AntivirusPlus) -> No action taken.
c:\Users\Ben\AppData\Roaming\microsoft\internet explorer\quick launch\Antivirus Plus(2).lnk (Rogue.AntivirusPlus) -> No action taken.
c:\Users\Ben\AppData\Roaming\microsoft\internet explorer\quick launch\Antivirus Plus.lnk (Rogue.AntivirusPlus) -> No action taken.
c:\Users\Cynthia\AppData\Roaming\microsoft\internet explorer\quick launch\Antivirus Plus(1).lnk (Rogue.AntivirusPlus) -> No action taken.
c:\Users\Cynthia\AppData\Roaming\microsoft\internet explorer\quick launch\Antivirus Plus(2).lnk (Rogue.AntivirusPlus) -> No action taken.
c:\Users\Cynthia\AppData\Roaming\microsoft\internet explorer\quick launch\Antivirus Plus.lnk (Rogue.AntivirusPlus) -> No action taken.
c:\Users\Elaine\AppData\Roaming\microsoft\internet explorer\quick launch\Antivirus Plus(1).lnk (Rogue.AntivirusPlus) -> No action taken.
c:\Users\Elaine\AppData\Roaming\microsoft\internet explorer\quick launch\Antivirus Plus(2).lnk (Rogue.AntivirusPlus) -> No action taken.
c:\Users\Elaine\AppData\Roaming\microsoft\internet explorer\quick launch\Antivirus Plus.lnk (Rogue.AntivirusPlus) -> No action taken.
c:\Users\Jennifer\AppData\Roaming\microsoft\internet explorer\quick launch\Antivirus Plus(1).lnk (Rogue.AntivirusPlus) -> No action taken.
c:\Users\Jennifer\AppData\Roaming\microsoft\internet explorer\quick launch\Antivirus Plus(2).lnk (Rogue.AntivirusPlus) -> No action taken.
c:\Users\Jennifer\AppData\Roaming\microsoft\internet explorer\quick launch\Antivirus Plus.lnk (Rogue.AntivirusPlus) -> No action taken.
c:\Users\Joel\AppData\Roaming\microsoft\internet explorer\quick launch\Antivirus Plus(1).lnk (Rogue.AntivirusPlus) -> No action taken.
c:\Users\Joel\AppData\Roaming\microsoft\internet explorer\quick launch\Antivirus Plus(2).lnk (Rogue.AntivirusPlus) -> No action taken.
c:\Users\Joel\AppData\Roaming\microsoft\internet explorer\quick launch\Antivirus Plus.lnk (Rogue.AntivirusPlus) -> No action taken.
c:\Users\Michelle\AppData\Roaming\microsoft\internet explorer\quick launch\Antivirus Plus(1).lnk (Rogue.AntivirusPlus) -> No action taken.
c:\Users\Michelle\AppData\Roaming\microsoft\internet explorer\quick launch\Antivirus Plus(2).lnk (Rogue.AntivirusPlus) -> No action taken.
c:\Users\Michelle\AppData\Roaming\microsoft\internet explorer\quick launch\Antivirus Plus.lnk (Rogue.AntivirusPlus) -> No action taken.
c:\Users\Tanya\AppData\Roaming\microsoft\internet explorer\quick launch\Antivirus Plus(1).lnk (Rogue.AntivirusPlus) -> No action taken.
c:\Users\Tanya\AppData\Roaming\microsoft\internet explorer\quick launch\Antivirus Plus(2).lnk (Rogue.AntivirusPlus) -> No action taken.
c:\Users\Tanya\AppData\Roaming\microsoft\internet explorer\quick launch\Antivirus Plus.lnk (Rogue.AntivirusPlus) -> No action taken.
C:\Windows\system\dop.exe (Trojan.FakeAlert) -> No action taken.
C:\Windows\System32\dmns.cfg (Rogue.AntiVirusPro) -> No action taken.
C:\Windows\System32\avp.id (Rogue.AntiVirusPro) -> No action taken.





HijackThis:


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:05:52 PM, on 01/06/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18226)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\AVG\AVG8\avgtray.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
c:\PROGRA~1\mcafee\msc\mcuimgr.exe
C:\Windows\explorer.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&a;…;m=veriton_m460
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACAW&a;…;m=veriton_m460
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://en.us.acer.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACAW&a;…;m=veriton_m460
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: (no name) - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - (no file)
O2 - BHO: Partner BHO Class - {83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4} - C:\ProgramData\Partner\partner.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O2 - BHO: (no name) - {D032570A-5F63-4812-A094-87D007C23012} - C:\Windows\system32\InternetExplorer.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [Skytel] Skytel.exe
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [shell] C:\Windows\system\rundll32.exe 70195[1]
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: VPN Client.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Filter: x-sdch - (no CLSID) - (no file)
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL,avgrsstx.dll
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
O23 - Service: Google Desktop Manager 5.7.808.7150 (GoogleDesktopManager-080708-050100) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe

–
End of file - 6875 bytes
[external image: Posted Image]

Sorry about the delay in responding :(

If you still need help, Scan again with HijackThis, and "copy/paste" a new log file into this thread.

Also please describe how your computer behaves at the moment.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI