alpha2211
Topic Starter
Please excuse my spelling, I have no spell checker and spelling was never my strongest english topic
Hi, I've had my computer in a mess for about a week over this problem now. The basic symptom is internet traffic being redirected to 161816.com, or 121161.com, or other 6 digit varients. The only reason I noticed there was a problem was the fact that in doing this, it also downloaded more worms for me, which were caught by Avast AV. It is worth mentioning at this point that the only research I can find on this virus by googling, is another thread on this site (the only english site anyway, the rest are chinese.)
Initially I backed everything up to an external HD, formatted the machines hard drive and reloaded my software, only to find "waiting for 161818.com" back in firefox's status bar. I assumed this was because I had infected my external and subsequently re-infected my machine. I am now using the PC with a freshly formatted HD, the only things that have been installed are Windows, Dell drivers, Firefox and now HijackThis v1.99.1. Needless to say it's still infected or I wouldn't be posting this here
I'm at a total loss, a complete system wipe has always sorted me out in the past, I've never had a virus this persistant, in case it helps this is the HijackThis log;
Logfile of HijackThis v1.99.1
Scan saved at 10:02:12, on 10/10/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\stsystra.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Hijackthis\HijackThis.exe
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
Any way you can help is much appreciated.
* * Edit * *
I have just installed and run Fixwareout, as advised in the self help section of the forum, here is the report from that program;
Username "Rob" - 10/10/2007 10:36:02 [Fixwareout edited 9/01/2007]
~~~~~ Prerun check
Successfully flushed the DNS Resolver Cache.
System was rebooted successfully.
~~~~~ Postrun check
HKLM\SOFTWARE\~\Winlogon\ "System"=""
….
….
~~~~~ Misc files.
….
~~~~~ Checking for older varients.
….
~~~~~ Current runs (hklm hkcu "run" Keys Only)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\\WINDOWS\\ehome\\ehtray.exe"
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
"SigmatelSysTrayApp"="stsystra.exe"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
….
Hosts file was reset, If you use a custom hosts file please replace it…
~~~~~ End report ~~~~~