PDA

View Full Version : 12 Viruses and a bunch of fun...


LinkTheWorld
04-28-2006, 11:14 AM
First off thank you for taking the time to read this.

I have recently found that I have atleast 12 viruses on my computer. Ad-aware is clean as well as Spybot also Registry Mechanic and cleaner. Hear is the thing, I had AVG on my computer and when I first got it everything was fine, the scan came back clean. Then after 3 months and probably some high risk activities on my end a scan cameback with 12 viruses BUT that it couldnt clean or delete them. So I went to Download.com and downloaded Macafee/ Norton / and a couple other ones. The scans either did NOT find the viruses at all or they found them but coulnt fix them. I was going to buy the full version of whatever found them and could fix them but nothing did. I ran a housecall and it found a couple but couldnt fix them either.

The viruses are as follows:

Win32.Prop.B ( 4 )
Win32.SillyDI.JB ( 3 )
Win32.Propo!downloader
Win32.SillyDI.KL
Win32.Dyfuca.D
Win32.Dyfuca.A
Win32.Alcan.J

They are all in something like... C:\_Restore\Archive\something.cab.A0023210.cpy for example

Since I see most people are putting their HJ this log on I will do that too...

Logfile of HijackThis v1.99.1
Scan saved at 10:18:17 AM, on 4/28/2006
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\LVCOMSX.EXE
C:\PROGRAM FILES\LOGITECH\VIDEO\LOGITRAY.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\ESPNRUNTIME\DIGSERVICES.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\LOGITECH\VIDEO\FXSVR2.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\UNZIPPED\HIJACKTHIS\HIJACKTHIS.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = localhost
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\SYSTEM\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [DIGServices] C:\Program Files\ESPNRunTime\DIGServices.exe /brand=ESPN /priority=0 /poll=24
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\PROGRAM FILES\LOGITECH\VIDEO\MANIFESTENGINE.EXE" boot
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRAM FILES\AIM\AIM.EXE
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by107fd.bay107.hotmail.msn.com/resources/MsnPUpld.cab

By the way if I try to delete the 016 MSN photo upload tool my computer crashes everytime, I dont think that is the problem but just so you know.


Thank you for any help you can give me.

mjc
04-28-2006, 12:18 PM
They are all in something like... C:\_Restore\Archive\something.cab.A0023210.cpy for example


If all the ones that can't be 'fixed' are in there then whatever you do, don't use System Restore.

There is not a single AV product on the market that will clean a SysRestore cab. AVG probably killed them all when you first used it.

To get rid of them, turn off System Restore, clean out the folder (delete everything in it), scan the system again (AVG and House Call should be enough) and then turn System Restore back on. Make a manual restore point after turning it on again.

http://support.microsoft.com/kb/q263455/

LinkTheWorld
04-28-2006, 02:31 PM
ok thank you, I will try that.

Being that they are in that particular folder, would you say they are still a threat to my computer? I am not noticing any signs of a virus on my computer ( other than the positive scans ) So basically if you HAD to have a virus on your computer you would want it where I have it?

Budfred
04-28-2006, 10:11 PM
As long as they are in System Restore, they can't cause any problems, but they will reinstall if you use a Restore Point... I suggest that you clear System Restore and set a clean Restore Point promptly...

I would probably fix that O16 in HJT to see if it fixes the other problem you are having...

LinkTheWorld
04-29-2006, 01:44 AM
Thank You Budfred

In your first post you said to turn off systemn restore...How do I do that? Then you said to clear everything from that folder. So I should literally go to the _Restore folder and delete every single thing in it? Or would it be better to just delete the specific files that I know are infected???

mjc
04-29-2006, 02:15 AM
Use the Microsoft link in my first post...it has detailed instructions on how to turn off and clear the _Restore directory...and yes everything must go.

LinkTheWorld
04-30-2006, 02:22 AM
ok thank you, I deleted everything in the whole folder, and the virus scans come back clean. I will check back to see if you think I should do anything else.

Budfred
04-30-2006, 12:16 PM
Did you "delete" everything in the folder or did you follow the instructions to reset System Restore?? If you did not reset System Restore, you need to do that and set a clean Restore Point...