Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
[HJT Log] Suspected virus.
#2
Greetings,

Whilst I am in the process of scrutinizing your complete set of provided logs for any possible infections or problems, I ask for your forbearance. Understand that the process of analysis requires time and careful examination hence the need for a cautious response. Accuracy is of the essence. Once I come across infections, I shall present the finest methods of removal for your convenience.

In return for this service, I propose to you two conditions:
  1. You are not to create any new threads regarding the similar topic as it will waste another helper's time.
  2. You are not to install any new software in your system, as it may hinder our process thus making this futile.
In accordance to my terms, I also ask of you five things, stated below:
  1. You are not to modify the logs in any way. Failure to do so will instantly deprive you of this service.
  2. You are to paste each log separately at PasteBin as it is. That is correct, no syntax highlighting, no editing - just the log purely. Post back the links for each log. You shall not hide them under spoiler codes.
  3. You are to provide the complete set of requested logs.
  4. You are to respond to every step I ask you to do using the format provided at the end of my post.
  5. You agree that I have the right to discontinue the analysis at any time, upon a violation of a single rule.
Provided that you will continue with this service, you hereby agree to the above statements. If you deem the conditions are portraying equality, I will willingly perform the analysis without further delay. Should you have any concerns or problems with the above conditions, or if you feel that I have overlooked your log, do inform me through a Private Message by clicking 'this'.

Thank you.

Genuinely yours,
Quintus
  • Prerequisite

    If you are having a problem running HijackThis as Administrator, please follow the steps below.
    • Go to My Computer and navigate to your default disc drive (C: is the most common).
    • Go to Program Files > Trend Micro > HijackThis.
    • Right-click HiJackThis.exe and run it as Administrator.
  • Step 1

    Please run HijackThis. Click 'Do a system scan only' and place a check next to the following line(s) if present:

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ask.com/?o=14302&l=dis
    R3 - URLSearchHook: (no name) - - (no file)
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O4 - HKLM\..\Run: [V0640Pin.dll] RunDLL32.exe V0640Pin.dll,RunDLL32EP 514,/d:2
    O4 - HKCU\..\Run: [U36VRSFLG6] C:\Users\Uzair\AppData\Local\Temp\Bqd.exe
    O4 - Startup: DesktopVideoPlayer.LNK = C:\Program Files\vghd\vghd.exe


    Then, close all other open windows and click 'Fix Checked'. You are to reboot your system afterwards.
  • Step 2

    Please download Combofix from one of the following locations:

    'Link 1'
    'Link 2'

    **IMPORTANT!**

    Let me give you a warning beforehand. I am instructing you to use one of the most powerful removal tool created. A simple mistake of running ComboFix without a helper's advice might render your machine unbootable. Do note that the steps below are crucial for the success of the clean-up you are currently undergoing. If by any chance you failed to meet any of them, I can almost guarantee a dreadful occurrence happening. See to it that you read the instructions first up to the very end and follow them accordingly after to ensure the best possible performance.
    • Save ComboFix to your Desktop.
    • Disable your anti-virus and anti-spyware applications, usually via a right-click on the System Tray icon. They may otherwise interfere with ComboFix. If you have difficulty properly disabling your protective programs, refer to 'this' link.

      Please open Notepad and copy and paste this code.

      Code:
      File::
      C:\Users\Uzair\AppData\Local\Temp\Bqd.exe

      Save this as CFScript.txt and change the Save As Type to All Files and place it on your Desktop. Make sure your security programs are disabled while we do this.

      [Image: CFScript.gif]

      Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.

      ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal. When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
Reminders:
  1. Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
  2. Do not "re-run" ComboFix. If you have a problem, reply back for further instructions.
  3. ComboFix may reset a number of Internet Explorer's settings, including making it the default browser.
  4. ComboFix prevents autorun of all CD, floppy and USB devices to assist with malware removal and increase security. If this is an issue or makes it difficult for you - please tell me.
  5. ComboFix disconnects your machine from the Internet. The connection is automatically restored before ComboFix completes its run. If ComboFix runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
  • In your next post, please provide the following:
    • A Fresh HijackThis (HJT) Log
    • ComboFix Log
    • Deckard's System Scanner (DDS) Logs
      • DDS.txt
      • Attach.txt
  • Format of Response

    Code:
    [color=#00BFFF][b]Step #[/b][/color]
    [color=#FFD700][b]Problems Encountered:[/b][/color]

    [color=#00BFFF][b]Step #[/b][/color]
    [color=#FFD700][b]Problems Encountered:[/b][/color]

    [color=#00BFFF][b]Step #[/b][/color]
    [color=#FFD700][b]Problems Encountered:[/b][/color]

    [color=#00BFFF][b]Link To Requested Logs:[/b][/color]
Reply


Messages In This Thread
[HJT Log] Suspected virus. - by TheGeniusism - 11-11-2010, 12:41 PM
RE: [HJT Log] Suspected virus. - by Quintus - 11-12-2010, 07:42 AM
RE: [HJT Log] Suspected virus. - by TheGeniusism - 11-14-2010, 04:56 AM
RE: [HJT Log] Suspected virus. - by Quintus - 11-15-2010, 04:48 AM
RE: [HJT Log] Suspected virus. - by TheGeniusism - 11-15-2010, 05:02 PM
RE: [HJT Log] Suspected virus. - by Quintus - 11-17-2010, 08:31 AM
RE: [HJT Log] Suspected virus. - by TheGeniusism - 11-20-2010, 06:05 AM
RE: [HJT Log] Suspected virus. - by Quintus - 11-21-2010, 02:34 AM

Possibly Related Threads…
Thread Author Replies Views Last Post
  Active HJT Graduate/Malware Remover now Brandenx781 2 1,711 02-19-2012, 05:38 PM
Last Post: Retribute
  Hooot.com redirect virus sarasmile 6 2,771 01-22-2012, 01:19 PM
Last Post: RDCA
  Many missing files - Hijackthis log kdang2 27 21,356 01-05-2012, 05:10 AM
Last Post: King
  i may be infected can you analyze this otl log please helpplease 6 3,138 11-23-2011, 08:58 PM
Last Post: Brandenx781
  Suspected RAT. TheGeniusism 6 2,131 08-05-2011, 04:39 AM
Last Post: Vexna

Forum Jump:


Users browsing this thread: 2 Guest(s)