 
                 
                InterviewSolution
 Saved Bookmarks
    				| 1. | Solve : bigtime virus/trojon/downloader problem? | 
| Answer» Some stubborn ones to get rid of. 
 Registry values to delete: HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\jdgf894jrghoiiskd HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\jnskdfmf9eldfd HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\plyrihnpsoi HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\rdpdd HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\webrebates0 HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WildTangent CDA HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\wintelupdate Note: the above instructions were created specifically for this user. If you are not this user, DO NOT follow these directions as they could damage the workings of your system 
 
 ---------- Your Java is out of date. Older versions of Java have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version(s) of Java components and update. Step 1 - Get the new version 
 
 
 ---------- Also uninstall Viewpoint Media Player See Viewpoint to Plunge Into Adware ---------- Next post add Avenger log Hopefully the boot times will start to improve. Let me know how everything is now.Boot time was a little improved but I think a scan is running every time I boot up. In the task manager it's called DoScan? After doing the avenger, on the reboot several pop up errors with the title of "no disk" kept appearing which was very odd. Here's the log... ////////////////////////////////////////// Avenger Pre-Processor log ////////////////////////////////////////// Platform: Windows XP (build 2600, Service Pack 2) Sun May 25 01:12:33 2008 01:12:10: Error: Invalid syntax in command: "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\jdgf894jrghoiiskd" Skipping line. (Registry value deletion mode) 01:12:12: Error: Invalid syntax in command: "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\jnskdfmf9eldfd" Skipping line. (Registry value deletion mode) 01:12:13: Error: Invalid syntax in command: "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\plyrihnpsoi" Skipping line. (Registry value deletion mode) 01:12:21: Error: Invalid syntax in command: "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\rdpdd" Skipping line. (Registry value deletion mode) 01:12:22: Error: Invalid syntax in command: "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\webrebates0" Skipping line. (Registry value deletion mode) 01:12:24: Error: Invalid syntax in command: "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WildTangent CDA" Skipping line. (Registry value deletion mode) 01:12:25: Error: Invalid syntax in command: "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\wintelupdate" Skipping line. (Registry value deletion mode) ////////////////////////////////////////// Logfile of The Avenger Version 2.0, (c) by Swandog46 http://swandog46.geekstogo.com Platform: Windows XP ******************* Script file opened successfully. Script file read successfully. Backups directory opened successfully at C:\Avenger ******************* Beginning to process script file: Rootkit scan active. No rootkits found! Completed script processing. ******************* Finished! Terminate. [recovering space - attachment deleted by admin] Look here for information on the DoScan. For some reason the reg values aren't going away with any of the tools used....yet! ---------- Open Hijackthis and select Do a system scan only. Place a check mark next to the following entries: (if there) - C:\WINDOWS\system32\ScsiAcc.exe - R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 216.133.248.230:80 <<--Unless you did this yourself - O2 - BHO: (no name) - SOFTWARE - (no file) - O8 - Extra context menu item: Open with &ZipScan - C:\PROGRA~1\ZIPSCA~1\zs_ie.htm - O9 - Extra button: (no name) - cmdmapping - (no file) (HKCU) - O23 - Service: ScsiAccess - Unknown owner - C:\WINDOWS\system32\ScsiAcc.exe Important: Close all windows except for Hijackthis and then click Fix checked. Exit Hijackthis. ---------- Download OTMoveIt2 by OldTimer 
 
 
 ---------- Next post add OTMoveIt log Here's the log: C:\WINDOWS\system32\ScsiAcc.exe moved successfully. < HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\jdgf894jrghoiiskd > Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\jdgf894jrghoiiskd\\ deleted successfully. < HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\jnskdfmf9eldfd > Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\jnskdfmf9eldfd\\ deleted successfully. < HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\plyrihnpsoi > Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\plyrihnpsoi\\ not found. < HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\rdpdd > Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\rdpdd\\ not found. < HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\webrebates0 > Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\webrebates0\\ deleted successfully. < HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WildTangent CDA > Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WildTangent CDA\\ deleted successfully. < HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\wintelupdate > Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\wintelupdate \\ not found. OTMoveIt2 by OldTimer - Version 1.0.4.2 log created on 05252008_131353 Let's clear out the programs we've been using to clean up your computer, they are not suitable for general malware removal and could cause damage if launched accidentally. These steps will also help secure the work you have done. . 
 . The above procedure will: 
 
 1. Double click OTMoveIt2.exe to launch it. Vista users right click and choose Run As Administrator 2. Click on the CleanUp! button. 3. OTMoveIt2 will download a list from the Internet, if your firewall or other defensive programs alerts you, allow it access. 4. Click YES at the next prompt (list downloaded, Do you want to begin cleanup process?) 5. Once complete exit out of OTMoveIt2 Set a New Restore Point to prevent possible reinfection from an old one Setting a new restore point AFTER cleaning your system will enable your computer to roll-back to a clean working state if needed. 
 Use the Secunia Software Inspector to check for out of date software. 
 How is everything now? | |