This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

virus removal

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Please can someone help me? I can't get rid of some nasty virus
McAfee Virus on-acces scan reports regularly the folowing kind of problems.
5/01/2007 9:36:30 Statistics:
5/01/2007 9:36:30 Files scanned: 907
5/01/2007 9:36:30 Files detected: 0
5/01/2007 9:36:30 Files cleaned: 0
5/01/2007 9:36:30 Files deleted: 0
5/01/2007 9:36:30 Files moved: 0
5/01/2007 9:37:58 Engine version = 5.1.00
5/01/2007 9:37:58 DAT version = 4932
5/01/2007 9:37:58 Number of virus signatures in EXTRA.DAT = None
5/01/2007 9:37:58 Names of viruses that EXTRA.DAT can detect = None
5/01/2007 9:38:29 Moved (Clean failed because the file isn't cleanable) LUC\User ETGL.exe C:\WINDOWS\system32\loadadv559.exe New Malware.j (Trojan)
5/01/2007 9:38:48 Move failed (Clean failed) LUC\User ETGL.exe C:\Documents and Settings\User\Local Settings\Temporary Internet Files\Content.IE5\YBMZZF31\install[1].exe MultiDropper-RH (Trojan)
5/01/2007 9:38:49 Deleted LUC\User ETGL.exe C:\WINDOWS\system32\install.exe MultiDropper-RH (Trojan)
5/01/2007 9:38:50 Move failed (Clean failed) LUC\User IRIB.exe C:\Documents and Settings\User\Local Settings\Temporary Internet Files\Content.IE5\YBMZZF31\install[1].exe MultiDropper-RH (Trojan)
5/01/2007 9:38:50 Deleted LUC\User IRIB.exe C:\WINDOWS\system32\install.exe MultiDropper-RH (Trojan)
5/01/2007 9:38:57 Deleted LUC\User si.exe C:\WINDOWS\system32\kbdal.exe Downloader-ARA (Trojan)
5/01/2007 9:38:58 Deleted LUC\User si.exe C:\WINDOWS\system32\wmsdmoe.exe Downloader-ARA (Trojan)
5/01/2007 10:07:27 Moved (Clean failed because the file isn't cleanable) LUC\User MQPK.exe C:\WINDOWS\system32\loadadv559.exe New Malware.j (Trojan)
5/01/2007 10:07:34 Move failed (Clean failed) LUC\User MQPK.exe C:\Documents and Settings\User\Local Settings\Temporary Internet Files\Content.IE5\EME44ZZW\install[1].exe MultiDropper-RH (Trojan)
5/01/2007 10:07:34 Deleted LUC\User MQPK.exe C:\WINDOWS\system32\install.exe MultiDropper-RH (Trojan)
5/01/2007 10:07:35 Deleted LUC\User si.exe C:\WINDOWS\system32\usrdtea.exe Downloader-ARA (Trojan)

I have been trying to run a recent version of McAfee virus scan (also in safe windows mode) but no virus is detected.
Operating system: Windows XP second edition

Thanks
This is the Hijackthis logfile

Logfile of HijackThis v1.99.1
Scan saved at 14:04:53, on 5/01/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Network Associates\VirusScan\mcshield.exe
C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
C:\WINDOWS\System32\igfxtray.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\ltmoh\Ltmoh.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\Symantec\Norton Ghost 2003\GhostStartTrayApp.exe
C:\Program Files\Common Files\Network Associates\TalkBack\tbmon.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\37.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Corel\Graphics8\Programs\MFIndexer.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.kuleuven.be/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.kuleuven.be/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: ThreeShips IEHelper - {17FDB9F8-DCC4-4F6A-AE07-B16018A48469} - C:\Program Files\Common Files\Threeships Shared\DLL\ThreeShipsIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [LtMoh] "C:\Program Files\ltmoh\Ltmoh.exe"
O4 - HKLM\..\Run: [Apoint] "C:\Program Files\Apoint2K\Apoint.exe"
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [GhostStartTrayApp] "C:\Program Files\Symantec\Norton Ghost 2003\GhostStartTrayApp.exe"
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\tbmon.exe"
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [37] "C:\WINDOWS\system32\37.exe"
O4 - HKCU\..\Run: [1] "C:\WINDOWS\system32\1.exe"
O4 - HKCU\..\Run: [96] "C:\WINDOWS\system32\96.exe"
O4 - HKCU\..\Run: [HTFQ] "C:\WINDOWS\system32\HTFQ.exe"
O4 - HKCU\..\Run: [MSRF] "C:\WINDOWS\system32\MSRF.exe"
O4 - HKCU\..\Run: [ARJK] "C:\Documents and Settings\User\ARJK.exe"
O4 - HKCU\..\Run: [IRIB] "C:\Documents and Settings\User\IRIB.exe"
O4 - HKCU\..\Run: [ETGL] "C:\Documents and Settings\User\ETGL.exe"
O4 - HKCU\..\Run: [ARQU] "C:\Documents and Settings\User\ARQU.exe"
O4 - HKCU\..\Run: [MQPK] "C:\Documents and Settings\User\MQPK.exe"
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart16.exe
O4 - Global Startup: Corel MEDIA FOLDERS INDEXER 8.LNK = C:\Corel\Graphics8\Programs\MFIndexer.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: GhostStartService - Symantec Corporation - C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: sasrfc Service (sasrfcService) - Unknown owner - C:\Program Files\SAS Institute\SAS\V8\access\sasexe\sasrfc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
Sorry for the delay :oops:
If you still need help and haven't posted at another forum.

Download and install AVG Anti-Spyware (ewido). Then scan and save the log from the scan.
Instructions and download link can be found here.

Then run this online scan. Save the report.

Rescan with HJT and post a new log with the results from AVG .
Also please describe how your computer behaves at the moment.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI