Author Topic: Repeated alerts for same virus  (Read 45007 times)

0 Members and 2 Guests are viewing this topic.

BarbeeGee

  • Guest
Re:Repeated alerts for same virus
« Reply #30 on: August 08, 2004, 08:04:19 PM »
Logfile of HijackThis v1.97.7
Scan saved at 1:12:57 PM, on 8/8/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

I downloaded one of those scanners last night and can't find it on my computer.  It didn't give me the option of where it should go or would go.  I'll try again.

Stephan123

  • Guest
Re:Repeated alerts for same virus
« Reply #31 on: August 08, 2004, 08:06:46 PM »
wheres the log??

whocares

  • Guest
Re:Repeated alerts for same virus
« Reply #32 on: August 08, 2004, 08:10:14 PM »
There are at least 2 trojan-downloader in your O16 - DPF entries:

QDow.cab infected by "TrojanDownloader.Win32.QDown.l" Virus.

UCSearch.CAB infected by "TrojanDownloader.Win32.VB.bn" Virus.


the best way would be to clear them all out, or at least the ones you don't know

(they will all be redownloaded next time you need to play and visit the respective site....)


BarbeeGee

  • Guest
Re:Repeated alerts for same virus
« Reply #33 on: August 08, 2004, 08:12:09 PM »
OK I'm scnning with RAV now.
When I check the 016 will that do it (get rid of them?)

This gets more confsing all the time

whocares

  • Guest
Re:Repeated alerts for same virus
« Reply #34 on: August 08, 2004, 08:13:51 PM »
when you check them, and then click "FIX checked" and then reboot..

 ;)

please REread "VirusRemoval" below with special care on how to secure your system & browser better..


Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31080
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re:Repeated alerts for same virus
« Reply #35 on: August 08, 2004, 08:21:41 PM »
Fix all lines starting with 016 - DPF
Also fix these lines :
\progra~1\adelph~1\smartb~1\motivesb.exe
\progra~1\hpinst~1\plugin\bin\pchbutton.exe
r1 - hkcu\software\microsoft\internet explorer\main,search bar = http://if.searchcentrix.com/sidecat.jsp?p=98567&appid=21&id=1928356723113218
r1 - hkcu\software\microsoft\internet explorer\main,search page = http://www.searchwww.com/
r0 - hklm\software\microsoft\internet explorer\search,searchassistant = http://www.searchwww.com/bar.html
o1 - hosts: 216.93.168.167 auto.search.msn.com
o1 - hosts: 216.93.168.167 auto.search.msn.com
o1 - hosts: comments (such as these) may be inserted on individual
o1 - hosts: 255.255.255.255 www.casinoxo.com
o1 - hosts: 216.93.168.167 auto.search.msn.com
o1 - hosts: 216.93.168.167 sitefinder.verisign.com
o2 - bho: (no name) - {0000607d-d204-42c7-8e46-216055bf9918} - (no file)
o2 - bho: (no name) - {4e7bd74f-2b8d-469e-dff7-ec6bf4d5fa7d} - (no file)
o4 - hklm\..\run: [motive smartbridge] c:\progra~1\adelph~1\smartb~1\motivesb.exe
o4 - hklm\..\run: [kernelfaultcheck] %systemroot%\system32\dumprep 0 -k
o4 - startup: powerreg scheduler.exe
o4 - global startup: gstartup.lnk = ?
o4 - global startup: precisiontime.lnk = c:\program files\precisiontime\precisiontime.exe
o4 - global startup: search.vbs
o8 - extra context menu item: web savings - file://c:\program files\websavingsfromebates\system\temp\ebateswebsavings_script0.htm

Then create a new log and copy/paste it HERE

Fix also all the things that site report as bad, and research the things unknow to see what they are. If bad (spy/-adware, virus, trojan etc  related) fix them also. After doing so, reboot and run a full system scan with Avast.
« Last Edit: August 08, 2004, 08:26:29 PM by Eddy »

whocares

  • Guest
Re:Repeated alerts for same virus
« Reply #36 on: August 08, 2004, 08:32:42 PM »

\progra~1\adelph~1\smartb~1\motivesb.exe
\progra~1\hpinst~1\plugin\bin\pchbutton.exe

o4 - hklm\..\run: [motive smartbridge] c:\progra~1\adelph~1\smartb~1\motivesb.exe
o4 - hklm\..\run: [kernelfaultcheck] %systemroot%\system32\dumprep 0 -k

[EDITED]


Hi Artras, please recalibrate your HJT-Analyzer..

why would you fix those ?

these items are not necessary, but not evil..

« Last Edit: August 08, 2004, 08:49:39 PM by whocares »

BarbeeGee

  • Guest
Re:Repeated alerts for same virus
« Reply #37 on: August 08, 2004, 08:37:13 PM »
I don't want to touch any files that begin with Adelphia because that is my cable company.

BarbeeGee

  • Guest
Re:Repeated alerts for same virus
« Reply #38 on: August 08, 2004, 08:38:21 PM »
The scan is still in progress but so far it found this:

Scanning memory...
Scanning boot sectors...
Scanning files...
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Search.vbs - VBS/Krepper.A* -> Infected

BarbeeGee

  • Guest
Re:Repeated alerts for same virus
« Reply #39 on: August 08, 2004, 09:22:09 PM »
I saw at least 4 virus's on the log and then when the scan was done... the window closed and was gone.

Now that scan took over an hour...  do I have to do it all over again and why did it close before I could copy it?

BarbeeGee

  • Guest
Re:Repeated alerts for same virus
« Reply #40 on: August 08, 2004, 09:26:35 PM »
This is scary.   I thought if I purchased AVAST I'd be virus free and I wouldn't have to go through all this rigamarro.

Now I discover 4 or 5 viruses?    Just what exactly is AVAST doing?

whocares

  • Guest
Re:Repeated alerts for same virus
« Reply #41 on: August 08, 2004, 09:41:20 PM »
NO virus-scanner detects everything..

-> you also have to exercise some caution and common sense when using your PC / surfing / emailing..

please 1st follow the advice from Eddy and me to clean up your Hijackthis-Log

then reboot and post a new log..

the Onlinescan shouldn't close unless you clicked the wrong button.. try the one to the lower right where it says "REPORT"

« Last Edit: August 08, 2004, 09:41:32 PM by whocares »

BarbeeGee

  • Guest
Re:Repeated alerts for same virus
« Reply #42 on: August 08, 2004, 10:03:17 PM »
You are not going to be happy with me.

I closed Hijack and now the report is gone.  I'll have to wait until the scan finishes and redo that too.

I went into Startup and disabled the place where the scan said there was a virus:

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Search.vbs - VBS/Krepper.A* -> Infected

BarbeeGee

  • Guest
Re:Repeated alerts for same virus
« Reply #43 on: August 08, 2004, 10:05:55 PM »
you say:  you also have to exercise some caution and common sense when using your PC / surfing / emailing..



I never open an attachment EVER.  How do you use caution surfing... I go to medical site, I go to The Sims sites and forums, I go to Pogo ( a reputatble game site).
I don't do much of anything else.    

So what am I doing wrong?

BarbeeGee

  • Guest
Re:Repeated alerts for same virus
« Reply #44 on: August 08, 2004, 10:31:13 PM »
Scan started at 8/8/2004 3:23:18 PM
 
Scanning memory...
Scanning boot sectors...
Scanning files...
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Search.vbs - VBS/Krepper.A* -> Infected
C:\WINDOWS\pss\Search.vbsCommon Startup - VBS/Krepper.A* -> Infected
C:\WINDOWS\system32\ATPartners.dll - TrojanDownloader:Win32/Rameh.C -> Infected
C:\WINDOWS\system32\bolae9.dll - TrojanDownloader:Win32/Rameh.B -> Infected

Scanned
============================
   Objects: 125730
   Directories: 7118
   Archives: 22191
   Size(Kb): -1959519
   Infected files: 4

Found
============================
   Viruses found: 3
   Suspicious files: 0
   Disinfected files: 0
   Mail files: 1176