QJ.NET | Videos | Forums | iPhone | MMORPG | Nintendo DS | Wii | PlayStation 3 | PSP | Xbox 360 | PC | Downloads | Contact Us
Forums | Gaming News | Videos | Downloads | Today's Posts | Mark Forums Read | Chat | FAQ | Members List | Contact

QJ.net Game Discussion - PSP, Xbox, Wii, PS3, PSP Homebrew, and PSP Guides

Go Back   QJ.net Game Discussion - PSP, Xbox, Wii, PS3, PSP Homebrew, and PSP Guides > Consumer > General PC Forums > Everything Windows
The above video goes away if you are a member and logged in, so log in now!

great... just GREAT!

This is a discussion on great... just GREAT! within the Everything Windows forums, part of the General PC Forums category; I had my antivir off for 30 min, and I got some cind of virus... Everytime I boot windows, it ...

Reply
 
LinkBack Thread Tools
Old 11-07-2006, 05:39 AM   #1
No longer a community member.
 
Join Date: Jun 2006
Location: Nederland
Posts: 3
Trader Feedback: 0
Default great... just GREAT!

I had my antivir off for 30 min,
and I got some cind of virus...
Everytime I boot windows, it will stay on for about 20 min and shuts itself down again with a message:
OMG h4X!!!

( )


Can someone please help me?
Savagefreak is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 11-07-2006, 05:41 AM   #2

73|-| m4573r poker
 
delight1's Avatar
 
Join Date: Jan 2006
Location: some place fun
Posts: 4,117
Trader Feedback: 0
Default

1. erase hard drave
2. install linux
:P
__________________
delight1 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 11-07-2006, 05:45 AM   #3
 
Join Date: Jan 2006
Location: stevens bumhole
Posts: 10,308
Trader Feedback: 0
Default

lool, funny virus

uhnmm, well try to reistall windows maybe..?
madsoul is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 11-07-2006, 05:45 AM   #4
No longer a community member.
 
Join Date: Jun 2006
Location: Nederland
Posts: 3
Trader Feedback: 0
Default

1. HELL NO!
2. I have linux on my PC, but I gaame on Windows (I have dual boot)
Savagefreak is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 11-07-2006, 05:45 AM   #5
 

 
Join Date: Jun 2005
Location: London UK
Posts: 3,739
Trader Feedback: 0
Default

Boot into safemode and use virus scanner, a free one is AVG.

If that fails, try a system restore to before you turned off your anti virus.

If that fails, run Hijackthis and post a log here. You can get hijackthis from http://www.majorgeeks.com/download3155.html

If that fails, try a repair install if you have your Windows CD.
PopeOfDope is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 11-07-2006, 05:51 AM   #6
No longer a community member.
 
Join Date: Jun 2006
Location: Nederland
Posts: 3
Trader Feedback: 0
Default

Quote:
Originally Posted by MaDSouL
lool, funny virus

uhnmm, well try to reistall windows maybe..?
Yeah... REALLY funny..... NOT
-= Double Post =-
Logfile of HijackThis v1.99.1
Scan saved at 14:51:30, on 7-11-2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
D:\WINDOWS\System32\smss. exe
D:\WINDOWS\system32\winlo gon.exe
D:\WINDOWS\system32\servi ces.exe
D:\WINDOWS\system32\lsass .exe
D:\WINDOWS\system32\svcho st.exe
D:\WINDOWS\System32\svcho st.exe
D:\WINDOWS\system32\spool sv.exe
D:\WINDOWS\Explorer.EXE
D:\WINDOWS\system32\RUNDL L32.EXE
D:\Program Files\Java\jre1.5.0_03\bi n\jusched.exe
D:\Program Files\iTunes\iTunesHelper .exe
D:\Program Files\HighCriteria\TotalR ecorder\TotRecSched.exe
D:\Program Files\SyncroSoft\Pos\H2O\ cledx.exe
D:\Program Files\Common Files\InstallShield\Updat eService\ISUSPM.exe
D:\WINDOWS\system32\ctfmo n.exe
D:\Program Files\MSN Messenger\MsnMsgr.Exe
D:\Program Files\Stardock\ObjectDock \ObjectDock.exe
D:\WINDOWS\system32\dxcom bin.exe
D:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
D:\WINDOWS\system32\nvsvc 32.exe
D:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServ ice.exe
D:\Program Files\iPod\bin\iPodServic e.exe
D:\WINDOWS\system32\wscnt fy.exe
D:\WINDOWS\system32\wuauc lt.exe
D:\WINDOWS\system32\svcho st.exe
D:\WINDOWS\system32\svcho st.exe
C:\BitLord\BitLord.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\WINDOWS\system32\dllho st.exe
C:\Program Files\Microsoft Visual Studio\VB98\Project1.exe
C:\Program Files\WinRAR\WinRAR.exe
D:\DOCUME~1\WILLEM~1\LOCA LS~1\Temp\Rar$EX00.963\Hi jackThis.exe

R0 - HKCU\Software\Microsoft\I nternet Explorer\Main,Start Page = http://forums.qj.net/
R0 - HKCU\Software\Microsoft\I nternet Explorer\Toolbar,LinksFol derName = Koppelingen
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper. dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINDOWS\system32\NvCpl .dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE D:\WINDOWS\system32\NvMcT ray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] D:\Program Files\Java\jre1.5.0_03\bi n\jusched.exe
O4 - HKLM\..\Run: [iTunesHelper] "D:\Program Files\iTunes\iTunesHelper .exe"
O4 - HKLM\..\Run: [TotalRecorderScheduler] "D:\Program Files\HighCriteria\TotalR ecorder\TotRecSched.exe"
O4 - HKLM\..\Run: [H2O] D:\Program Files\SyncroSoft\Pos\H2O\ cledx.exe
O4 - HKLM\..\Run: [ISUSPM] "D:\Program Files\Common Files\InstallShield\Updat eService\ISUSPM.exe" -scheduler
O4 - HKCU\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\ctfmo n.exe
O4 - HKCU\..\Run: [MsnMsgr] "D:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Startup: Adobe Gamma.lnk = D:\Program Files\Common Files\Adobe\Calibration\A dobe Gamma Loader.exe
O4 - Startup: Stardock ObjectDock.lnk = D:\Program Files\Stardock\ObjectDock \ObjectDock.exe
O4 - Global Startup: Adobe Reader Snelle start.lnk = D:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\OFFI CE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\OFFI CE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.ex e
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.ex e
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - D:\PROGRA~1\MSNMES~1\MSGR AP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - D:\PROGRA~1\MSNMES~1\MSGR AP~1.DLL
O23 - Service: Adobe LM Service - Adobe Systems - D:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc .exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - D:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: DirectX multi version - Unknown owner - D:\WINDOWS\system32\dxcom bin.exe
O23 - Service: InstallShield Licensing Service - Macrovision - D:\Program Files\Common Files\InstallShield Shared\Service\InstallShi eld Licensing Service.exe
O23 - Service: iPod Service - Apple Computer, Inc. - D:\Program Files\iPod\bin\iPodServic e.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - D:\WINDOWS\system32\nvsvc 32.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - D:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServ ice.exe

Last edited by savagefreak; 11-07-2006 at 05:51 AM.. Reason: Automerged Doublepost
Savagefreak is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 11-07-2006, 05:58 AM   #7
Veteran
 
-TheSilenceOfNoOne-'s Avatar
 
Join Date: Jul 2006
Real First Name: [TSON]
Location: Location?
Just Played: PKMN Crystal (WIP)
Posts: 1,862
Trader Feedback: 0
Default

Quote:
Originally Posted by savagefreak
Yeah... REALLY funny..... NOT
-= Double Post =-
Logfile of HijackThis v1.99.1
Scan saved at 14:51:30, on 7-11-2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
D:\WINDOWS\System32\smss. exe
D:\WINDOWS\system32\winlo gon.exe
D:\WINDOWS\system32\servi ces.exe
D:\WINDOWS\system32\lsass .exe
D:\WINDOWS\system32\svcho st.exe
D:\WINDOWS\System32\svcho st.exe
D:\WINDOWS\system32\spool sv.exe
D:\WINDOWS\Explorer.EXE
D:\WINDOWS\system32\RUNDL L32.EXE
D:\Program Files\Java\jre1.5.0_03\bi n\jusched.exe
D:\Program Files\iTunes\iTunesHelper .exe
D:\Program Files\HighCriteria\TotalR ecorder\TotRecSched.exe
D:\Program Files\SyncroSoft\Pos\H2O\ cledx.exe
D:\Program Files\Common Files\InstallShield\Updat eService\ISUSPM.exe
D:\WINDOWS\system32\ctfmo n.exe
D:\Program Files\MSN Messenger\MsnMsgr.Exe
D:\Program Files\Stardock\ObjectDock \ObjectDock.exe
D:\WINDOWS\system32\dxcom bin.exe
D:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
D:\WINDOWS\system32\nvsvc 32.exe
D:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServ ice.exe
D:\Program Files\iPod\bin\iPodServic e.exe
D:\WINDOWS\system32\wscnt fy.exe
D:\WINDOWS\system32\wuauc lt.exe
D:\WINDOWS\system32\svcho st.exe
D:\WINDOWS\system32\svcho st.exe
C:\BitLord\BitLord.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\WINDOWS\system32\dllho st.exe
C:\Program Files\Microsoft Visual Studio\VB98\Project1.exe
C:\Program Files\WinRAR\WinRAR.exe
D:\DOCUME~1\WILLEM~1\LOCA LS~1\Temp\Rar$EX00.963\Hi jackThis.exe

R0 - HKCU\Software\Microsoft\I nternet Explorer\Main,Start Page = http://forums.qj.net/
R0 - HKCU\Software\Microsoft\I nternet Explorer\Toolbar,LinksFol derName = Koppelingen
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper. dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINDOWS\system32\NvCpl .dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE D:\WINDOWS\system32\NvMcT ray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] D:\Program Files\Java\jre1.5.0_03\bi n\jusched.exe
O4 - HKLM\..\Run: [iTunesHelper] "D:\Program Files\iTunes\iTunesHelper .exe"
O4 - HKLM\..\Run: [TotalRecorderScheduler] "D:\Program Files\HighCriteria\TotalR ecorder\TotRecSched.exe"
O4 - HKLM\..\Run: [H2O] D:\Program Files\SyncroSoft\Pos\H2O\ cledx.exe
O4 - HKLM\..\Run: [ISUSPM] "D:\Program Files\Common Files\InstallShield\Updat eService\ISUSPM.exe" -scheduler
O4 - HKCU\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\ctfmo n.exe
O4 - HKCU\..\Run: [MsnMsgr] "D:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Startup: Adobe Gamma.lnk = D:\Program Files\Common Files\Adobe\Calibration\A dobe Gamma Loader.exe
O4 - Startup: Stardock ObjectDock.lnk = D:\Program Files\Stardock\ObjectDock \ObjectDock.exe
O4 - Global Startup: Adobe Reader Snelle start.lnk = D:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\OFFI CE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\OFFI CE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.ex e
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.ex e
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - D:\PROGRA~1\MSNMES~1\MSGR AP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - D:\PROGRA~1\MSNMES~1\MSGR AP~1.DLL
O23 - Service: Adobe LM Service - Adobe Systems - D:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc .exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - D:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: DirectX multi version - Unknown owner - D:\WINDOWS\system32\dxcom bin.exe
O23 - Service: InstallShield Licensing Service - Macrovision - D:\Program Files\Common Files\InstallShield Shared\Service\InstallShi eld Licensing Service.exe
O23 - Service: iPod Service - Apple Computer, Inc. - D:\Program Files\iPod\bin\iPodServic e.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - D:\WINDOWS\system32\nvsvc 32.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - D:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServ ice.exe
You need to post this on Dell.com annd someone'll help you.

LAWLZ, Your starting webpage is forums.qj.net... XD
__________________
This signature has been raped by the rep system
-TheSilenceOfNoOne- is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 11-07-2006, 06:05 AM   #8

Mindless Self Indulgence
 
Realn0whereman's Avatar
 
Join Date: Oct 2005
Location: afk
Posts: 7,212
Trader Feedback: 0
Default

rofl


hackers these days have a sense of humor. go into linux and scan ur windows partition from there. also u can game in linux....
-= Double Post =-
also maybe creat a partition in linux and back ur **** up and just delete windows
__________________
PSN:realn0whereman
NEW MSI ALBUM APRIL 29TH: IF
*orgasm*

Last edited by Yev Kasem; 11-07-2006 at 06:05 AM.. Reason: Automerged Doublepost
Realn0whereman is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 11-07-2006, 06:06 AM   #9
 

 
Join Date: Jun 2005
Location: London UK
Posts: 3,739
Trader Feedback: 0
Default

Hmm I can't see anything particularly incriminating but I can't read logs that well just yet.

Uninstall BitLord. The older versions were littered with spywayre and adware so use uTorrent or Azureus instead.

dxcombin could be potentially infected, but there's very little information on it. It's real owner should be microsoft so it may have been modified. Try reinstalling DirectX 9.0c perhaps?

Other than that, nothing seems too wrong. Project1.exe is your own I'm assuming?

Also run this and check if theres any suspicios processes running. http://www.sysinternals.com/Utilitie...sExplorer.html
PopeOfDope is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 11-07-2006, 06:11 AM   #10
No longer a community member.
 
Join Date: Jun 2006
Location: Nederland
Posts: 3
Trader Feedback: 0
Default

Ive DONE IT!!!!
ZOMFG IT WORKS AGAIN!
I have formatted my harddrive
and installed linux on it...

Maybe Ill reinstall windows later this dayy......

But w/e, thanks for the help :-p

(BTW: when I tryed system-recovery it comes up with another box that says:
''Aw, Hell no!''.......)
-= Double Post =-
Project1 wasn't my own...
Could I be that then?

Last edited by savagefreak; 11-07-2006 at 06:11 AM.. Reason: Automerged Doublepost
Savagefreak is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 11-07-2006, 06:18 AM   #11
 

 
Join Date: Jun 2005
Location: London UK
Posts: 3,739
Trader Feedback: 0
Default

Yeah, project1.exe is a trojan apparently. Several viruses rename themselves to project1 like codebase-e and count2k.

I guess it doesn't matter anymore
PopeOfDope is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 11-07-2006, 07:38 AM   #12
 
FreePlay's Avatar
 
Join Date: Dec 2005
Location: h0000000rj
Posts: 12,858
Trader Feedback: 0
Default

*LOL*
http://www.greatis.com/appdata/d/d/dxcombin.exe.htm
D:\WINDOWS\system32\dxcom bin.exe was also a backdoor/trojan.

C:\Program Files\Microsoft Visual Studio\VB98\Project1.exe wasn't a virus, it was a VB program. Unless, of course, you weren't making any VB programs at the time, in which case it was probably a virus.

Tip: Stay off porn sites if your antivirus is turned off -_-
__________________
[qj now fails.]
FreePlay is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply

Tags
great

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off



All times are GMT -8. The time now is 08:03 PM.



Use of this Web site constitutes acceptance of the TERMS & CONDITIONS and PRIVACY POLICY
Copyright © 2009, QJ.NET. All Rights Reserved.
Contact Us