I am having some serious trouble with this virus.I cant even load my safe mode because it is there as well. I tried to follow the instructions here given to other users but I am very computer illiterite...I have run my spybot and norton and avast and they say they are fixing the problems but to no avail they come back. I tried running the spybot in safe mode but as I said before the little yellow triangle is there as well.I do not really understand all the technical jargon used here so someone that is patient should probly take me on!!!
This si the result of the HJT log i ran. As I am not that computer smart I trid to follow the directions as well as I could.I also ran the SPYBOT and tried to fix the results but they keep coming back.Also the virus is in my safe mode.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:17:16 PM, on 4/3/2008
Platform: Windows 2000 SP3 (WinNT 5.00.2195)
MSIE: Internet Explorer v5.00 SP3 (5.00.2920.0000)
Boot mode: Normal
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINNT\system32\cisvc.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\TIREMOTE\TIRemoteService.exe
C:\WINNT\system32\cidaemon.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\System32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\sbwltbxa.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm
F2 - REG:system.ini: UserInit=C:\WINNT\system32\userinit.exe,C:\WINNT\system32\sbwltbxa.exe,
O1 - Hosts: 172.16.1.12 mhmvpn
O1 - Hosts: 172.16.1.35 RICOHA
O1 - Hosts: 172.16.1.200 MIS
O1 - Hosts: 172.16.1.200 MHMNET
O1 - Hosts: 172.16.1.201 MHM
O1 - Hosts: 172.16.1.202 DB
O1 - Hosts: 172.16.1.203 FS10
O1 - Hosts: 172.16.1.204 CDTOWER1
O1 - Hosts: 172.16.1.205 FDX
O1 - Hosts: 172.16.1.206 FS2
O1 - Hosts: 172.16.1.208 LEGALEX
O1 - Hosts: 172.16.1.207 DBACA
O1 - Hosts: 172.16.1.209
O1 - Hosts: 172.16.1.210 FSEXCH # Exchange 2003
O1 - Hosts: 172.16.1.211 VSERVER
O1 - Hosts: 172.16.1.212 COPYCENTER34COMP
O1 - Hosts: 172.16.1.213 CIM
O1 - Hosts: 172.16.1.214 SUMMATION
O1 - Hosts: 172.16.1.215 ACCUTRAC
O1 - Hosts: 172.16.1.216 FS8
O1 - Hosts: 172.16.1.217 SCANRTR
O1 - Hosts: 172.16.1.218 IPMASTER
O1 - Hosts: 172.16.1.219 CCURE
O1 - Hosts: 172.16.1.220 MITAI # TAPI Server
O1 - Hosts: 172.16.1.221 CPQTG2
O1 - Hosts: 172.16.1.222 FS1 # Win 2003 server
O1 - Hosts: 172.16.1.223 FSDC1 # W2K BAB Server
O1 - Hosts: 172.16.1.224 FSPAT # W2003 Patent Server
O1 - Hosts: 172.16.1.225 MHMPDC # W2003 DC
O1 - Hosts: 172.16.1.226 FS3 # SAVCE/SUS/Scan router
O1 - Hosts: 172.16.1.227 FS4 # Citrix
O1 - Hosts: 172.16.1.228 FS5 # Carpe Diem SQL
O1 - Hosts: 172.16.1.229 FS7 # Accuroute
O1 - Hosts: 172.16.1.230 FSSUMM # Summation SSE
O1 - Hosts: 172.16.1.231 FSMOM # Cheyenne Arcserve
O1 - Hosts: 172.16.1.232 TMM5 # Thing Magic Mercury
O1 - Hosts: 172.16.1.233 ZEBRAPRT # Zebra Printer
O1 - Hosts: 172.16.1.234
O1 - Hosts: 172.16.2.199 RECMGT # Attendance Controller
O2 - BHO: (no name) - {00000250-0320-4dd4-be4f-7566d2314352} - (no file)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {13197ace-6851-45c3-a7ff-c281324d5489} - (no file)
O2 - BHO: (no name) - {15651c7c-e812-44a2-a9ac-b467a2233e7d} - (no file)
O2 - BHO: (no name) - {4e1075f4-eec4-4a86-add7-cd5f52858c31} - (no file)
O2 - BHO: (no name) - {4e7bd74f-2b8d-469e-92c6-ce7eb590a94d} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {5929cd6e-2062-44a4-b2c5-2c7e78fbab38} - (no file)
O2 - BHO: (no name) - {5dafd089-24b1-4c5e-bd42-8ca72550717b} - (no file)
O2 - BHO: (no name) - {5fa6752a-c4a0-4222-88c2-928ae5ab4966} - (no file)
O2 - BHO: (no name) - {622cc208-b014-4fe0-801b-874a5e5e403a} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {8674aea0-9d3d-11d9-99dc-00600f9a01f1} - (no file)
O2 - BHO: (no name) - {965a592f-8efa-4250-8630-7960230792f1} - (no file)
O2 - BHO: (no name) - {9c5b2f29-1f46-4639-a6b4-828942301d3e} - (no file)
O2 - BHO: (no name) - {cf021f40-3e14-23a5-cba2-717765728274} - (no file)
O2 - BHO: (no name) - {fc3a74e5-f281-4f10-ae1e-733078684f3c} - (no file)
O2 - BHO: (no name) - {ffff0001-0002-101a-a3c9-08002b2f49fb} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck /autofix /autoclose
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O8 - Extra context menu item: &Search - ?p=ZK
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\nwprovau.dll
O16 - DPF: {106E49CF-797A-11D2-81A2-00E02C015623} (AlttiffCtl Class) - http://www.alternatiff.com/install/00/alttiff.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/win...ls/en/x86/client/wuweb_site.cab?1204448245437
O16 - DPF: {6963E8DD-A2ED-4672-B950-23A571EE8684} (ClivalX.Clival) - https://www.lexis.com/ri/Clival.CAB
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: Track-It! Remote Control (TIRmtCtl) - Blue Ocean Software, Inc. - C:\WINNT\TIREMOTE\wuser32.exe
O23 - Service: Track-It! Remote (TIRmtSvc) - Blue Ocean Software, Inc. - C:\WINNT\TIREMOTE\TIRemoteService.exe
--
End of file - 7114 bytes
This si the result of the HJT log i ran. As I am not that computer smart I trid to follow the directions as well as I could.I also ran the SPYBOT and tried to fix the results but they keep coming back.Also the virus is in my safe mode.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:17:16 PM, on 4/3/2008
Platform: Windows 2000 SP3 (WinNT 5.00.2195)
MSIE: Internet Explorer v5.00 SP3 (5.00.2920.0000)
Boot mode: Normal
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINNT\system32\cisvc.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\TIREMOTE\TIRemoteService.exe
C:\WINNT\system32\cidaemon.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\System32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\sbwltbxa.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm
F2 - REG:system.ini: UserInit=C:\WINNT\system32\userinit.exe,C:\WINNT\system32\sbwltbxa.exe,
O1 - Hosts: 172.16.1.12 mhmvpn
O1 - Hosts: 172.16.1.35 RICOHA
O1 - Hosts: 172.16.1.200 MIS
O1 - Hosts: 172.16.1.200 MHMNET
O1 - Hosts: 172.16.1.201 MHM
O1 - Hosts: 172.16.1.202 DB
O1 - Hosts: 172.16.1.203 FS10
O1 - Hosts: 172.16.1.204 CDTOWER1
O1 - Hosts: 172.16.1.205 FDX
O1 - Hosts: 172.16.1.206 FS2
O1 - Hosts: 172.16.1.208 LEGALEX
O1 - Hosts: 172.16.1.207 DBACA
O1 - Hosts: 172.16.1.209
O1 - Hosts: 172.16.1.210 FSEXCH # Exchange 2003
O1 - Hosts: 172.16.1.211 VSERVER
O1 - Hosts: 172.16.1.212 COPYCENTER34COMP
O1 - Hosts: 172.16.1.213 CIM
O1 - Hosts: 172.16.1.214 SUMMATION
O1 - Hosts: 172.16.1.215 ACCUTRAC
O1 - Hosts: 172.16.1.216 FS8
O1 - Hosts: 172.16.1.217 SCANRTR
O1 - Hosts: 172.16.1.218 IPMASTER
O1 - Hosts: 172.16.1.219 CCURE
O1 - Hosts: 172.16.1.220 MITAI # TAPI Server
O1 - Hosts: 172.16.1.221 CPQTG2
O1 - Hosts: 172.16.1.222 FS1 # Win 2003 server
O1 - Hosts: 172.16.1.223 FSDC1 # W2K BAB Server
O1 - Hosts: 172.16.1.224 FSPAT # W2003 Patent Server
O1 - Hosts: 172.16.1.225 MHMPDC # W2003 DC
O1 - Hosts: 172.16.1.226 FS3 # SAVCE/SUS/Scan router
O1 - Hosts: 172.16.1.227 FS4 # Citrix
O1 - Hosts: 172.16.1.228 FS5 # Carpe Diem SQL
O1 - Hosts: 172.16.1.229 FS7 # Accuroute
O1 - Hosts: 172.16.1.230 FSSUMM # Summation SSE
O1 - Hosts: 172.16.1.231 FSMOM # Cheyenne Arcserve
O1 - Hosts: 172.16.1.232 TMM5 # Thing Magic Mercury
O1 - Hosts: 172.16.1.233 ZEBRAPRT # Zebra Printer
O1 - Hosts: 172.16.1.234
O1 - Hosts: 172.16.2.199 RECMGT # Attendance Controller
O2 - BHO: (no name) - {00000250-0320-4dd4-be4f-7566d2314352} - (no file)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {13197ace-6851-45c3-a7ff-c281324d5489} - (no file)
O2 - BHO: (no name) - {15651c7c-e812-44a2-a9ac-b467a2233e7d} - (no file)
O2 - BHO: (no name) - {4e1075f4-eec4-4a86-add7-cd5f52858c31} - (no file)
O2 - BHO: (no name) - {4e7bd74f-2b8d-469e-92c6-ce7eb590a94d} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {5929cd6e-2062-44a4-b2c5-2c7e78fbab38} - (no file)
O2 - BHO: (no name) - {5dafd089-24b1-4c5e-bd42-8ca72550717b} - (no file)
O2 - BHO: (no name) - {5fa6752a-c4a0-4222-88c2-928ae5ab4966} - (no file)
O2 - BHO: (no name) - {622cc208-b014-4fe0-801b-874a5e5e403a} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {8674aea0-9d3d-11d9-99dc-00600f9a01f1} - (no file)
O2 - BHO: (no name) - {965a592f-8efa-4250-8630-7960230792f1} - (no file)
O2 - BHO: (no name) - {9c5b2f29-1f46-4639-a6b4-828942301d3e} - (no file)
O2 - BHO: (no name) - {cf021f40-3e14-23a5-cba2-717765728274} - (no file)
O2 - BHO: (no name) - {fc3a74e5-f281-4f10-ae1e-733078684f3c} - (no file)
O2 - BHO: (no name) - {ffff0001-0002-101a-a3c9-08002b2f49fb} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck /autofix /autoclose
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O8 - Extra context menu item: &Search - ?p=ZK
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\nwprovau.dll
O16 - DPF: {106E49CF-797A-11D2-81A2-00E02C015623} (AlttiffCtl Class) - http://www.alternatiff.com/install/00/alttiff.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/win...ls/en/x86/client/wuweb_site.cab?1204448245437
O16 - DPF: {6963E8DD-A2ED-4672-B950-23A571EE8684} (ClivalX.Clival) - https://www.lexis.com/ri/Clival.CAB
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: Track-It! Remote Control (TIRmtCtl) - Blue Ocean Software, Inc. - C:\WINNT\TIREMOTE\wuser32.exe
O23 - Service: Track-It! Remote (TIRmtSvc) - Blue Ocean Software, Inc. - C:\WINNT\TIREMOTE\TIRemoteService.exe
--
End of file - 7114 bytes
Last edited by a moderator: