General Discussion Off-Topic Discussion and Enlightenment

Need help from the computer nerds

Thread Tools
 
Search this Thread
 
Old 06-01-2005, 03:27 AM
  #1  
3.0 BAR
Thread Starter
 
Cray91's Avatar
 
Join Date: May 2004
Posts: 5,042
Default Need help from the computer nerds

I think that I have a virus. If I leave my computer for an hour or so I can't get online. I then go to the taskmanager and end sys32 and osae and I can go online again. I have heard of the system 32 virus, but my pirated copy of Norton doesn't seem to catch it at all. Now I can't get my computer to start properly, it loads all the way upp til when the desktop should show up and it just shuts off instantly.

Any help would be great appreciated. Even if just how to get the virus off there.
Cray91 is offline  
Old 06-01-2005, 03:33 AM
  #2  
1.0 BAR
 
Cadracer's Avatar
 
Join Date: Dec 2002
Posts: 366
Default Re: Need help from the computer nerds

SAFE MODE

look into the registry

lol
that`ll fix it
Cadracer is offline  
Old 06-01-2005, 03:39 AM
  #3  
3.0 BAR
Thread Starter
 
Cray91's Avatar
 
Join Date: May 2004
Posts: 5,042
Default Re: Need help from the computer nerds

Originally Posted by Cadracer
SAFE MODE

look into the registry

lol
that`ll fix it
wow that was helpful
Cray91 is offline  
Old 06-01-2005, 05:59 AM
  #4  
3.0 BAR
 
88crxSi's Avatar
 
Join Date: Feb 2003
Posts: 9,089
Default Re: Need help from the computer nerds

What OS?
What method of connecting?
Download HighJackThis and put it in its own directory and run the program, save the log, and post it on here.
88crxSi is offline  
Old 06-01-2005, 11:35 AM
  #5  
1.5 BAR
 
PureCRXtasy's Avatar
 
Join Date: Dec 2002
Posts: 1,065
Default Re: Need help from the computer nerds

Sounds like you have an SDBot infection.

http://securityresponse.symantec.com...oor.sdbot.html
PureCRXtasy is offline  
Old 06-01-2005, 12:31 PM
  #6  
3.0 BAR
Thread Starter
 
Cray91's Avatar
 
Join Date: May 2004
Posts: 5,042
Default Re: Need help from the computer nerds

This is Windows XP Pro, Wireless network with DSL for connection.

I am not sure that it is that thing you showed me from the symantec website, I have norton, and it misses it.
Cray91 is offline  
Old 06-01-2005, 12:45 PM
  #7  
0.0 BAR
 
jinxy's Avatar
 
Join Date: Feb 2005
Posts: 0
Default Re: Need help from the computer nerds

http://www.spywareinfo.com/~merijn/downloads.html

get hijack this and post up your log like crx88si said. then we might be able to tell you whats up
jinxy is offline  
Old 06-01-2005, 12:58 PM
  #8  
3.0 BAR
 
kain's Avatar
 
Join Date: Sep 2003
Posts: 5,448
Default Re: Need help from the computer nerds

go to symantec and do their housecall virus scanning. its completly free and you dont download anything. it just runs a virus scanner from their web sight. its pretty fast and catches pretty much everything, so give them a try.
kain is offline  
Old 06-01-2005, 01:02 PM
  #9  
0.0 BAR
 
jinxy's Avatar
 
Join Date: Feb 2005
Posts: 0
Default Re: Need help from the computer nerds

that scan is also good. but if you do that scan rember to copy and paste the list of files to a txt document and put it on your desktop. so when you reboot in safemode youl still have it. and if your doing that tis good to have KillBox. if you cant find it anywhere ill send it to you. its basicly a program that force deletes files when windows is being a bitch about it
jinxy is offline  
Old 06-01-2005, 01:49 PM
  #10  
3.0 BAR
Thread Starter
 
Cray91's Avatar
 
Join Date: May 2004
Posts: 5,042
Default Re: Need help from the computer nerds

I got the scan but it tells me to ask someone with a clue what to fix and what not to.

Logfile of HijackThis v1.99.1
Scan saved at 17:57 PM, on 06/01/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Google\Gmail Notifier\G001-1.0.24.0\gnotify.exe
C:\WINDOWS\system32\sys32.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\AWS\WeatherBug\Weather.exe
C:\WINDOWS\system32\?hkdsk.exe
C:\Program Files\nsab\osae.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\Creighton Engen\Desktop\HijackThis1991.exe
C:\WINDOWS\system32\wuauclt.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = *.r21.mchsi.com
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1324122C-B588-FF5A-902C-8FC3BCC494AA} - C:\WINDOWS\system32\cuksutry.dll (file missing)
O2 - BHO: (no name) - {1A913446-868B-DE23-D858-A77F6419D2C3} - C:\WINDOWS\system32\eatsbb.dll
O2 - BHO: (no name) - {26092225-98B8-BC68-BD1C-B7EEFD80B993} - C:\WINDOWS\system32\cuksutry.dll (file missing)
O2 - BHO: (no name) - {26092229-98B8-CD1C-BD1B-BDEEF985B9E9} - C:\WINDOWS\system32\cuksutry.dll (file missing)
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [RDLL] RunDll16.exe
O4 - HKLM\..\Run: [SmartGuardian] C:\Program Files\SOYO\HW Monitor\Itesmart.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [ElbyCheckElbyCDFL] "C:\Program Files\Elaborate Bytes\CloneCD\ElbyCheck.exe" /L ElbyCDFL
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [POINTER] point32.exe
O4 - HKLM\..\Run: [Taskmon driver] winampa.exe
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\G001-1.0.24.0\gnotify.exe
O4 - HKLM\..\Run: [api driver] sys32.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [lmu] C:\WINDOWS\LMU.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\RunServices: [RDLL] RunDll16.exe
O4 - HKCU\..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe 1
O4 - HKCU\..\Run: [Mpfltw] C:\WINDOWS\system32\?hkdsk.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [Eaai] C:\Program Files\nsab\osae.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (HKCU)
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} - http://us.chat1.yimg.com/us.yimg.com...45/yacscom.cab
O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - http://wdownload.weatherbug.com/mini...ansporter.cab?
O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} - http://chat.yahoo.com/cab/yacsui.cab
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe

Cray91 is offline  


Quick Reply: Need help from the computer nerds



All times are GMT -5. The time now is 10:21 AM.