Virus Help Please :-( - testmy.net resource / tool
Home
Welcome, Guest. Please login or register.
Did you miss your activation email?

 



donations help testmy.net pay for the very high cost to run the site. Any amount is greatly appreciated.
Click to read why...

  spcr
    
News : Have an idea that will make testmy.net better?  Click here to post it!  We love to hear feedback, user feedback like yours have helped build testmy.net over the years.. true story wink August 30, 2008, 09:47:23 AM
testmy.net Broadband  |  Main Forum  |  PC Security  |  Security Threats  |  Topic: Virus Help Please :-( Advanced search
  0 Members and 1 Guest are viewing this topic. « previous next »
Pages 1 2  All Go Down
Author
Topic: Virus Help Please :-(  (Read 6303 times)
wyantm06
TMN Weightloss Guru
Sophist Member
Expert
*
Offline Offline

Gender: Male
Posts: 1035

RoadRunner 15 Mbps - 768 Kbps


View Profile
« on: March 03, 2006, 03:11:48 PM »

Hello all for some reason I have been getting the same two viruses everytime I start my PC up. I tried removing them in safe mode, nothing. Tried just plain removing them, and nothing. Please help! I was going to reboot Windows back to new but that'll take 6 hours for me.
Logged

Xbox Live - WEEZYx420

PSN - WEEZYx420

Wii - 6718 0451 8450 2449

wyantm06
TMN Weightloss Guru
Sophist Member
Expert
*
Offline Offline

Gender: Male
Posts: 1035

RoadRunner 15 Mbps - 768 Kbps


View Profile
« Reply #1 on: March 03, 2006, 03:44:00 PM »

Anyone? Btw I use AVG Free...
Logged

Xbox Live - WEEZYx420

PSN - WEEZYx420

Wii - 6718 0451 8450 2449

|3v|lon3|
Sr. Member
*
Offline Offline

Posts: 173


View Profile
« Reply #2 on: March 03, 2006, 04:18:15 PM »

now i know google could have helped you with this.. try there

jeez

use a firewall and a anti virus if ur that worried
Logged
wyantm06
TMN Weightloss Guru
Sophist Member
Expert
*
Offline Offline

Gender: Male
Posts: 1035

RoadRunner 15 Mbps - 768 Kbps


View Profile
« Reply #3 on: March 03, 2006, 04:32:18 PM »

now i know google could have helped you with this.. try there

jeez

use a firewall and a anti virus if ur that worried
Please read my posts before you start coming on here acting like king! I said I HAVE 2 VIRUSES!!!! I NEED TO KNOW HOW TO GET RID OF THEM!!! I NEVER ASKED WHICH SOFTWARE WILL!!! READ MY POST FOR ONCEEEE!
Logged

Xbox Live - WEEZYx420

PSN - WEEZYx420

Wii - 6718 0451 8450 2449

Swimmer
Vice Admin
TMN Seasoned Veteran
*
Offline Offline

Gender: Male
Posts: 6393



View Profile
« Reply #4 on: March 03, 2006, 04:42:27 PM »

dude settle down.. what viruses are they detected as?
Logged

wyantm06
TMN Weightloss Guru
Sophist Member
Expert
*
Offline Offline

Gender: Male
Posts: 1035

RoadRunner 15 Mbps - 768 Kbps


View Profile
« Reply #5 on: March 03, 2006, 04:53:50 PM »

dude settle down.. what viruses are they detected as?
I know I am sorry. It's just this guy always gets on my case telling me to Google. But a forum is where your supposed to ask questions. Anyways I keep getting the notnotspy.exe virus every time I start my pc up. I delete with AVG then restart and it is back again. Thanks if you can help
Logged

Xbox Live - WEEZYx420

PSN - WEEZYx420

Wii - 6718 0451 8450 2449

Swimmer
Vice Admin
TMN Seasoned Veteran
*
Offline Offline

Gender: Male
Posts: 6393



View Profile
« Reply #6 on: March 03, 2006, 05:00:07 PM »

run hijack this.. paste the log into this forum.. it is a trojan horse Generic.PZT.. then when you get a change use http://virusscan.jotti.org/ and scan the computer..

is there also a process called msnmm.exe running?

read that..
http://forums.techguy.org/security/446560-notnotspy-exe-wont-leave-my.html?highlight=notnotspy.exe
Logged

wyantm06
TMN Weightloss Guru
Sophist Member
Expert
*
Offline Offline

Gender: Male
Posts: 1035

RoadRunner 15 Mbps - 768 Kbps


View Profile
« Reply #7 on: March 03, 2006, 05:14:09 PM »

Here...

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\VIA\RAID\raid_tool.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\NetLimiter\NetLimiter.exe
C:\Program Files\Windows Media Connect 2\WMCCFG.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Common Files\Ulead Systems\DVD\USISrv.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\WINDOWS\system32\msngm.exe
C:\Program Files\Trillian\trillian.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Mark\Desktop\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [RaidTool] C:\Program Files\VIA\RAID\raid_tool.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [Microsoft M.S.N Services] msngm.exe
O4 - HKLM\..\Run: [NetLimiter] C:\Program Files\NetLimiter\NetLimiter.exe /s
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Windows Media Connect 2] "C:\Program Files\Windows Media Connect 2\WMCCFG.exe" /StartQuiet
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [USIUDF_Eject_Monitor] C:\Program Files\Common Files\Ulead Systems\DVD\USISrv.exe
O4 - HKLM\..\RunServices: [Microsoft M.S.N Services] msngm.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe

Logged

Xbox Live - WEEZYx420

PSN - WEEZYx420

Wii - 6718 0451 8450 2449

wyantm06
TMN Weightloss Guru
Sophist Member
Expert
*
Offline Offline

Gender: Male
Posts: 1035

RoadRunner 15 Mbps - 768 Kbps


View Profile
« Reply #8 on: March 03, 2006, 05:30:08 PM »

Ok I ran HJT and deleted those two files the one person said to, thats all I did and now it's gone! Thanks
Logged

Xbox Live - WEEZYx420

PSN - WEEZYx420

Wii - 6718 0451 8450 2449

wyantm06
TMN Weightloss Guru
Sophist Member
Expert
*
Offline Offline

Gender: Male
Posts: 1035

RoadRunner 15 Mbps - 768 Kbps


View Profile
« Reply #9 on: March 03, 2006, 05:31:08 PM »

Dang nevermind...It doesn't pop up at the beggining. But if I do a scan with avg it still shows there Sad

EDIT: Nevermind I definatley got it fixed now. Thanks
« Last Edit: March 03, 2006, 05:45:39 PM by wyantm06 » Logged

Xbox Live - WEEZYx420

PSN - WEEZYx420

Wii - 6718 0451 8450 2449

cholla
TMN Veteran
*
Offline Offline

Gender: Male
Posts: 2843


View Profile
« Reply #10 on: March 03, 2006, 06:17:47 PM »

wyantm06 ;It looks like you have it fixed but if it shows back up try disabling your System Restore if its not already disabled.Then run AVG in safe mode.It doesn't hurt to run Spybot S&D or Adaware to hunt for spyware while in safe mode as well.
There is a virus killer program called Stinger that is good to run in safe mode.
Then if you use or like to have your System Restore enable it when you return to normal mode.
Logged
|3v|lon3|
Sr. Member
*
Offline Offline

Posts: 173


View Profile
« Reply #11 on: March 03, 2006, 07:17:06 PM »

get rid of avg

how about that?

and use mcafee or panda :haha: :whaa:
Logged
Swimmer
Vice Admin
TMN Seasoned Veteran
*
Offline Offline

Gender: Male
Posts: 6393



View Profile
« Reply #12 on: March 03, 2006, 07:41:52 PM »

get rid of avg

how about that?

and use mcafee or panda :haha: :whaa:

mcafee.. Laughing that is funny..
Logged

|3v|lon3|
Sr. Member
*
Offline Offline

Posts: 173


View Profile
« Reply #13 on: March 03, 2006, 08:51:25 PM »

i dont have any av or firewall's installed.. if i need to remove something i install mcafee.. and let it scan and remove.. and uninstall it
Logged
Kouin
Jr. Member
*
Offline Offline

Posts: 28


View Profile
« Reply #14 on: March 03, 2006, 09:08:57 PM »

Try housecall.trendmicro.com, I dont deal with viruses....I reformat whenever I have one. Smile
Logged
Print  Pages 1 2  All Go Up
testmy.net Broadband  |  Main Forum  |  PC Security  |  Security Threats  |  Topic: Virus Help Please :-( « previous next »
Jump to:  

    
testmy.net's forum is proudly Powered by SMF | SMF © 2006-2007, Simple Machines LLC
Bookmark: Del.icio.us    StumbleUpon
 
 

 

© 1999-2008 testmy.net - Contact - Legal - Facts & FAQs
Page Loading Stats: This forum Page created in 0.122 seconds with 54 queries.