Hi all, New to this Hijack stuff. I have abrand new XPS 630 running Vista. I somehow picked up that pesky Vundo / Cryp.... virus. My system is protected by PC Cillin internet security. I also have Spywareblaster installed, have run Spybot, Adaware and Superantispyware. They have all detected numerous virus's etc... I have cleaned and removed them and I keep getting pop ups from PCcillin saying it found more. Superantispyware is running right now and has already found a Vundo variant. how do I get rid of this thing ? Below is a hijack log. Any help is appreciated.
Thanks
Bill
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:52:46 AM, on 4/17/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16643)
Boot mode: Normal
We need to temporarily disable some protection programs so they don't interfere with our fixes.
1. SpyBotS&D Tea timer
1) Run Spybot-S&D 2) Go to the Mode menu, and make sure "Advanced Mode" is selected 3) On the left hand side, choose Tools -> Resident 4) Uncheck "Resident TeaTimer" and OK any prompts 5) Restart your computer.
2. Real-time Protection on Windows Defender
Open Windows Defender
Click Tools => Options
Scroll down and uncheck Use real-time protection (recommended).
Click Save
Close Windows Defender
3. *NOTE* CCleaner deletes EVERYTHING out of temp/temporary folders. If you have anything in a temp folder, back it up or move it to a permanent folder prior to running CCleaner!
Download CCleaner from here to clean temp files from your computer.
Double click on the file to start the installation of the program.
Select your language and click OK, then next.
Read the license agreement and click I Agree.
Click next to use the default install location. Click Install then finish to complete installation.
Double click the CCleaner shortcut on the desktop to start the program.
On the "Windows" tab, under "Internet Explorer," uncheck "Cookies" if you do not want them deleted. (If deleted, you will likely need to reenter your passwords at all sites where a cookie is used to recognize you when you visit).
If you use either the Firefox or Mozilla browsers, the box to uncheck for "Cookies" is on the Applications tab, under Firefox/Mozilla.
Click on the "Options" icon at the left side of the window, then click on "Advanced." deselect "Only delete files in Windows Temp folders older than 48 hours."
Click on the "Cleaner" icon on the left side of the window, then click Run Cleaner to run the program.
Caution: It is not recommended that you use the "Issues" feature unless you are very familiar with the registry as it has been known to find legitimate items.
After CCleaner has completed its process, click Exit.
4. Rerun Hijackthis (scan only) and place checks beside the following entries (With Vista you may need to Rt Click Hijackthis.exe and Select "Run as Administrator")
Thanks for the help. I did as you intructed. BTW Windows Defender was not on, but I did go in and uncheck real time protection anyways.
Here is my new Hijack log. BTW on reboot I got another PCcillin real time virus alert.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:38:34 PM, on 4/17/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16643)
Boot mode: Normal
Please...Intrude. I could use some help. I have updated PcCillin regularlly. Updated this morning. I am not running SuperantiSpyware in a real time mode. I have only loaded it and done a scan.
bama: Asking about an update that fixes a known issue is intruding? Sorry for trying to save everyone some time if that was causing the issue. You seem to be taking this way too personally.
bill: Looking at your log, because bama seems to have given up, there seem to be only a few issues left. Before trying to remove them, however, as a precaution, i would suggest making sure you have a backup of all your data. That being said, I would not tell you to erase any of your documents, but when dealing with infections, there is always a chance of data loss. Also, it looks like you may have a RAID setup, but RAID will not prevent software-caused data loss... only hardware failure.
Moving on, I just want to ask you a few quick questions about what is actually happening on the system.
1) How long has this been happening?
2) What are the specific symptoms, other than an alert about a vundo infection?
3) As stated before, what data is on the system that you would not want to lose?
4) Have you ever used a program such as CCleaner to clear temp files from your system?
5) It looks like you may have been speaking with a Dell technician who connected into your system. If yes, what work was done by them?
Please be aware that
Sylwyn is not listed as a graduate of the malware removal schools that we contacted.
It is understood by the trained analysts that once a helper replies to a log, he continues working with you until the issue is resolved.
Due to the intrusions, bamajim, an excellent malware removal expert and anti-malware tool developer has stepped out.
billwnh, you have some choices:
1. You can, at risk, continue working with the person who has taken ownership of this thread.
bamajim
10376 Posts
457
0
Posted April 17th, 2008 14:00
We need to temporarily disable some protection programs so they don't interfere with our fixes.
1. SpyBotS&D Tea timer
2) Go to the Mode menu, and make sure "Advanced Mode" is selected
3) On the left hand side, choose Tools -> Resident
4) Uncheck "Resident TeaTimer" and OK any prompts
5) Restart your computer.
2. Real-time Protection on Windows Defender
3. *NOTE* CCleaner deletes EVERYTHING out of temp/temporary folders. If you have anything in a temp folder, back it up or move it to a permanent folder prior to running CCleaner!
Download CCleaner from here to clean temp files from your computer.
4. Rerun Hijackthis (scan only) and place checks beside the following entries (With Vista you may need to Rt Click Hijackthis.exe and Select "Run as Administrator")
Close all other open windows except Hijackthis and Select " Fix checked"
Close Hijackthis ->> Reboot your PC ->> Rerun Hijackthis and post a fresh Hijackthis log
"The world is what you make of it"