PDA

View Full Version : Son Of A Bitch!


0rk.p0rk
07-16-04, 03:03 PM
Ok, I reinstalled Windows a few weeks ago due to my computer being riddled with viruses. Right off the bat, I couldn't open notepad. (Virus!) A few days later, my CPU usage is always at 100% (Virus!), and my system has slowed to a crawl. (Virus!)

What I want to know right now is how to get rid of these ****ing things. I plan on re-installing again, and I want a virus clean PC. I have 16 right now, thanks to a younger influence around here and I have established that there will be no more Kazaa Lite. (Virus galore!)

So I downloaded Bullguard, signed up for the free trial, and it turns out it can't disinfect/move more then half the trojans on my system.

C:\Documents and Settings\Default User\Start Menu\Programs\Accessories\Notepad.lnk=>C:\WINDOWS\system32\notepad.exe Infected Trojan.Downloader.Small.JC
C:\Documents and Settings\Default User\Start Menu\Programs\Accessories\Notepad.lnk=>C:\WINDOWS\system32\notepad.exe Disinfection failed - Trying second action
C:\Documents and Settings\Default User\Start Menu\Programs\Accessories\Notepad.lnk=>C:\WINDOWS\system32\notepad.exe Move failed
C:\Documents and Settings\Paul Florek\Local Settings\Temp\polmx.cab=>polmx.exe=>(Upx) Infected Trojan.Downloader.Agent.AE
C:\Documents and Settings\Paul Florek\Local Settings\Temp\polmx.cab=>polmx.exe=>(Upx) Disinfection failed - Trying second action
C:\Documents and Settings\Paul Florek\Local Settings\Temp\polmx.exe=>(Upx) Infected Trojan.Downloader.Agent.AE
C:\Documents and Settings\Paul Florek\Local Settings\Temp\polmx.exe=>(Upx) Disinfection failed - Trying second action
C:\Documents and Settings\Paul Florek\Local Settings\Temp\polmx.exe
C:\Documents and Settings\Paul Florek\Start Menu\Programs\Accessories\Notepad.lnk=>C:\WINDOWS\system32\notepad.exe Infected Trojan.Downloader.Small.JC
C:\Documents and Settings\Paul Florek\Start Menu\Programs\Accessories\Notepad.lnk=>C:\WINDOWS\system32\notepad.exe Disinfection failed - Trying second action
C:\Documents and Settings\Paul Florek\Start Menu\Programs\Accessories\Notepad.lnk=>C:\WINDOWS\system32\notepad.exe Move failed
C:\Documents and Settings\Tom Orzechowski\Local Settings\Temp\alchem.cab=>alchem.exe Infected Trojan.Downloader.Alchemic.A
C:\Documents and Settings\Tom Orzechowski\Local Settings\Temp\alchem.cab=>alchem.exe Disinfection failed - Trying second action
C:\Documents and Settings\Tom Orzechowski\Local Settings\Temp\alchem.cab=>alchem.exe Move failed
C:\Documents and Settings\Tom Orzechowski\Local Settings\Temp\alchem.exe Infected Trojan.Downloader.Alchemic.A
C:\Documents and Settings\Tom Orzechowski\Local Settings\Temp\alchem.exe Disinfection failed - Trying second action
C:\Documents and Settings\Tom Orzechowski\Local Settings\Temp\alchem.exe Moved
C:\Documents and Settings\Tom Orzechowski\Local Settings\Temp\cpr_mm2.exe=>wise0010 Infected Trojan.Downloader.Adroar.A
C:\Documents and Settings\Tom Orzechowski\Local Settings\Temp\cpr_mm2.exe=>wise0010 Disinfection failed - Trying second action
C:\Documents and Settings\Tom Orzechowski\Local Settings\Temp\cpr_mm2.exe=>wise0010 Move failed
C:\Documents and Settings\Tom Orzechowski\Local Settings\Temp\IExploreSkins.exe Infected Application.IBIS.Toolbar
C:\Documents and Settings\Tom Orzechowski\Local Settings\Temp\IExploreSkins.exe Disinfection failed - Trying second action
C:\Documents and Settings\Tom Orzechowski\Local Settings\Temp\IExploreSkins.exe Moved
C:\Documents and Settings\Tom Orzechowski\Local Settings\Temp\MemoryWatcher_b.exe Infected Trojan.Sandbox.A
C:\Documents and Settings\Tom Orzechowski\Local Settings\Temp\MemoryWatcher_b.exe Disinfection failed - Trying second action
C:\Documents and Settings\Tom Orzechowski\Local Settings\Temp\MemoryWatcher_b.exe Moved
C:\Documents and Settings\Tom Orzechowski\Local Settings\Temp\polmx.cab=>polmx.exe=>(Upx) Infected Trojan.Downloader.Agent.AE
C:\Documents and Settings\Tom Orzechowski\Local Settings\Temp\polmx.cab=>polmx.exe=>(Upx) Disinfection failed - Trying second action
C:\Documents and Settings\Tom Orzechowski\Local Settings\Temp\polmx.exe=>(Upx) Infected Trojan.Downloader.Agent.AE
C:\Documents and Settings\Tom Orzechowski\Local Settings\Temp\polmx.exe=>(Upx) Disinfection failed - Trying second action
C:\Documents and Settings\Tom Orzechowski\Local Settings\Temp\polmx.exe
C:\Documents and Settings\Tom Orzechowski\Local Settings\Temp\temp.cab=>IExploreSkins.exe Infected Application.IBIS.Toolbar
C:\Documents and Settings\Tom Orzechowski\Local Settings\Temp\temp.cab=>IExploreSkins.exe Disinfection failed - Trying second action
C:\Documents and Settings\Tom Orzechowski\Local Settings\Temp\temp.cab=>IExploreSkins.exe Move failed
C:\Documents and Settings\Tom Orzechowski\Local Settings\Temp\THI5790.tmp\polall1t.exe=>(Upx) Infected Trojan.Downloader.Agent.AE
C:\Documents and Settings\Tom Orzechowski\Local Settings\Temp\THI5790.tmp\polall1t.exe=>(Upx) Disinfection failed - Trying second action
C:\Documents and Settings\Tom Orzechowski\Local Settings\Temp\THI5790.tmp\polall1t.exe
C:\Documents and Settings\Tom Orzechowski\Local Settings\Temp\THI5790.tmp\preInsTT.exe Infected Adware.Serchentrix.A
C:\Documents and Settings\Tom Orzechowski\Local Settings\Temp\THI5790.tmp\preInsTT.exe Disinfection failed - Trying second action
C:\Documents and Settings\Tom Orzechowski\Local Settings\Temp\THI5790.tmp\preInsTT.exe Moved
C:\Documents and Settings\Tom Orzechowski\Local Settings\Temp\THI5790.tmp\twaintec.cab=>twaintec.dll Infected Trojan.Spy.BiSpy.C
C:\Documents and Settings\Tom Orzechowski\Local Settings\Temp\THI5790.tmp\twaintec.cab=>twaintec.dll Disinfection failed - Trying second action
C:\Documents and Settings\Tom Orzechowski\Local Settings\Temp\THI5790.tmp\twaintec.cab=>twaintec.dll Move failed
C:\Documents and Settings\Tom Orzechowski\Local Settings\Temp\THI5790.tmp\twaintec.cab=>preInsTT.exe Infected Adware.Serchentrix.A
C:\Documents and Settings\Tom Orzechowski\Local Settings\Temp\THI5790.tmp\twaintec.cab=>preInsTT.exe Disinfection failed - Trying second action
C:\Documents and Settings\Tom Orzechowski\Local Settings\Temp\THI5790.tmp\twaintec.cab=>preInsTT.exe Move failed
C:\Documents and Settings\Tom Orzechowski\Local Settings\Temp\THI5790.tmp\twaintec.cab=>polall1t.exe=>(Upx) Infected Trojan.Downloader.Agent.AE
C:\Documents and Settings\Tom Orzechowski\Local Settings\Temp\THI5790.tmp\twaintec.cab=>polall1t.exe=>(Upx) Disinfection failed - Trying second action
C:\Documents and Settings\Tom Orzechowski\Local Settings\Temp\THI5790.tmp\twaintec.dll Infected Trojan.Spy.BiSpy.C
C:\Documents and Settings\Tom Orzechowski\Local Settings\Temp\THI5790.tmp\twaintec.dll Disinfection failed - Trying second action
C:\Documents and Settings\Tom Orzechowski\Local Settings\Temp\THI5790.tmp\twaintec.dll Moved
C:\Program Files\Common Files\updater\sui.exe Infected Trojan.Downloader.KeenValue.C
C:\Program Files\Common Files\updater\sui.exe Disinfection failed - Trying second action
C:\Program Files\Common Files\updater\sui.exe Moved
C:\Program Files\IncrediFind\BHO\IncFindBHO.dll Infected Trojan.Downloader.KeenValue.A
C:\Program Files\IncrediFind\BHO\IncFindBHO.dll Disinfection failed - Trying second action
C:\Program Files\IncrediFind\BHO\IncFindBHO.dll Moved
C:\Program Files\MemoryWatcher\wowex32.exe Infected Trojan.Sandbox.A
C:\Program Files\MemoryWatcher\wowex32.exe Disinfection failed - Trying second action
C:\Program Files\MemoryWatcher\wowex32.exe Moved
C:\WINDOWS\alchem.exe Infected Trojan.Downloader.Alchemic.A
C:\WINDOWS\alchem.exe Disinfection failed - Trying second action
C:\WINDOWS\alchem.exe Moved
C:\WINDOWS\ARUpdate.exe Infected Trojan.Downloader.Adroar.A
C:\WINDOWS\ARUpdate.exe Disinfection failed - Trying second action
C:\WINDOWS\ARUpdate.exe Moved
C:\WINDOWS\cpruninst.exe=>wise0010 Infected Trojan.Downloader.Adroar.A
C:\WINDOWS\cpruninst.exe=>wise0010 Disinfection failed - Trying second action
C:\WINDOWS\cpruninst.exe=>wise0010 Move failed
C:\WINDOWS\Downloaded Program Files\bridge.dll Infected Trojan.PWS.Briss.A
C:\WINDOWS\Downloaded Program Files\bridge.dll Disinfection failed - Trying second action
C:\WINDOWS\Downloaded Program Files\bridge.dll Moved
C:\WINDOWS\Downloaded Program Files\jao.dll Infected Trojan.PWS.Briss.A
C:\WINDOWS\Downloaded Program Files\jao.dll Disinfection failed - Trying second action
C:\WINDOWS\Downloaded Program Files\jao.dll Moved
C:\WINDOWS\mm20.ocx Infected Trojan.Downloader.VB.DB
C:\WINDOWS\mm20.ocx Disinfection failed - Trying second action
C:\WINDOWS\mm20.ocx Moved
C:\WINDOWS\polmx.exe=>(Upx) Infected Trojan.Downloader.Agent.AE
C:\WINDOWS\polmx.exe=>(Upx) Disinfection failed - Trying second action
C:\WINDOWS\polmx.exe
C:\WINDOWS\preInsTT.exe Infected Adware.Serchentrix.A
C:\WINDOWS\preInsTT.exe Disinfection failed - Trying second action
C:\WINDOWS\preInsTT.exe Moved
C:\WINDOWS\system32\Ccbs.exe Infected Trojan.Sandbox.A
C:\WINDOWS\system32\Ccbs.exe Disinfection failed - Trying second action
C:\WINDOWS\system32\Ccbs.exe Moved
C:\WINDOWS\system32\dp-him.exe Infected Application.Adware.IEDriver.A
C:\WINDOWS\system32\dp-him.exe Disinfection failed - Trying second action
C:\WINDOWS\system32\dp-him.exe Moved
C:\WINDOWS\system32\GtgRBZ.exe Infected Trojan.Sandbox.A
C:\WINDOWS\system32\GtgRBZ.exe Disinfection failed - Trying second action
C:\WINDOWS\system32\GtgRBZ.exe Moved
C:\WINDOWS\system32\HisQf.exe Infected Trojan.Sandbox.A
C:\WINDOWS\system32\HisQf.exe Disinfection failed - Trying second action
C:\WINDOWS\system32\HisQf.exe Moved
C:\WINDOWS\system32\HotElc.exe Infected Trojan.Sandbox.A
C:\WINDOWS\system32\HotElc.exe Disinfection failed - Trying second action
C:\WINDOWS\system32\HotElc.exe Moved
C:\WINDOWS\system32\IEHost.EXE Infected Trojan.Downloader.Turown.H
C:\WINDOWS\system32\IEHost.EXE Disinfection failed - Trying second action
C:\WINDOWS\system32\IEHost.EXE Moved
C:\WINDOWS\system32\Lwhv0Ua.exe Infected Trojan.Sandbox.A
C:\WINDOWS\system32\Lwhv0Ua.exe Disinfection failed - Trying second action
C:\WINDOWS\system32\Lwhv0Ua.exe Moved
C:\WINDOWS\system32\MgzxCE.exe Infected Trojan.Sandbox.A
C:\WINDOWS\system32\MgzxCE.exe Disinfection failed - Trying second action
C:\WINDOWS\system32\MgzxCE.exe Moved
C:\WINDOWS\system32\ms.exe Infected Application.Adware.IEDriver.A
C:\WINDOWS\system32\ms.exe Disinfection failed - Trying second action
C:\WINDOWS\system32\ms.exe Moved
C:\WINDOWS\system32\notepad.exe Infected Trojan.Downloader.Small.JC
C:\WINDOWS\system32\notepad.exe Disinfection failed - Trying second action
C:\WINDOWS\system32\notepad.exe Moved
C:\WINDOWS\system32\SqegM9.exe Infected Trojan.Sandbox.A
C:\WINDOWS\system32\SqegM9.exe Disinfection failed - Trying second action
C:\WINDOWS\system32\SqegM9.exe Moved
C:\WINDOWS\system32\TcvE9HdT.exe Infected Trojan.Sandbox.A
C:\WINDOWS\system32\TcvE9HdT.exe Disinfection failed - Trying second action
C:\WINDOWS\system32\TcvE9HdT.exe Moved
C:\WINDOWS\system32\terrabyte.exe Infected Trojan.Downloader.Turown.G
C:\WINDOWS\system32\terrabyte.exe Disinfection failed - Trying second action
C:\WINDOWS\system32\terrabyte.exe Moved
C:\WINDOWS\system32\tksrv98.exe=>(Upx) Infected Application.XPlugin.A
C:\WINDOWS\system32\tksrv98.exe=>(Upx) Disinfection failed - Trying second action
C:\WINDOWS\system32\tksrv98.exe
C:\WINDOWS\system32\tmksrvu.exe Infected Application.XPlugin.A
C:\WINDOWS\system32\tmksrvu.exe Disinfection failed - Trying second action
C:\WINDOWS\system32\tmksrvu.exe Moved
C:\WINDOWS\system32\VmvDwc.exe Infected Trojan.Sandbox.A
C:\WINDOWS\system32\VmvDwc.exe Disinfection failed - Trying second action
C:\WINDOWS\system32\VmvDwc.exe Moved
C:\WINDOWS\system32\Wlsb9TH.exe Infected Trojan.Sandbox.A
C:\WINDOWS\system32\Wlsb9TH.exe Disinfection failed - Trying second action
C:\WINDOWS\system32\Wlsb9TH.exe Moved
C:\WINDOWS\twaintec.dll Infected Trojan.Spy.BiSpy.C
C:\WINDOWS\twaintec.dll Disinfection failed - Trying second action
C:\WINDOWS\twaintec.dll Moved

Statistics

Scan path : C:\
Folders : 1371
Files : 55829
Archives : 942
Packed files : 2604
Identified viruses : 16
Infected files : 47
Warnings : 0
Suspect files : 0
Disinfected files : 0
Deleted files : 0
Copied files : 0
Moved files : 36
Renamed files : 0
I/O errors : 34
Scan time : 00:49:14
Scan speed (files/sec) : 18

Virus definitions : 85967
Scan plugins : 12
Archive plugins : 36
Unpack plugins : 3
Mail plugins : 6
System plugins : 1

Scan options

Detection
[X] Scan boot sectors
[X] Scan archives
[X] Scan packed files
[X] Scan email

Now I want to get rid of these buggers for GOOD, before I reinstall. So that when I start up they won't reinstall themselves onto my HDD, etc. I heard about people doing stuff in safe mode, but I'm clueless. Somebody, somebody PLEASE help me.

Rytr
07-16-04, 03:19 PM
My daughter had about that many viruses on her pc at school. When she brought it home it would barely run. I did a low level scan on her WD 30GB drive with the WD utility to remove all the files. Installed a new mobo (it was time for an upgrade), new ram, and cpu. Used the old drive and all other components that was originally in the pc. No evidence of any viruses after fresh install.
She has her own apartment now and nobody else has access to the pc. Plus, I told her to avoid opening any attachments unless she is sure that they are OK.

OldOfEvil
07-16-04, 03:23 PM
First of you want to download all the security updates and burn them to a CD. Do a full format, make sure your computer is disconected from any kind of internet connection before installing windows too, then install all the secruity updates from the CD, drivers, etc. Turn on your Windows firewall and any other AV/Firewall progs you have. First site you should hit is windows update just to make sure.

And stop visitng pr0n sites! :angel2:


Hope it works out.

evilchris
07-17-04, 11:24 PM
Agree, no more pr0n.