Bullguard Antivirus Forum Download A Free Copy Of Bullguard Antivirus Software
Free Antivirus Forum - Learn about antivirus, firewalls and personal security Free Antivirus Forum - Learn about antivirus, firewalls and personal security
 HomeLog InRegisterCommunity CalendarSearch the ForumView The Member ListHelp
Need remove a spyware virus
   
BullGuard Antivirus Forum > Virus Removal > Removal Help > Need remove a spyware virus  
Forum Quick Jump
 
Vote Results :: 0 vote(s) total
0
daniel felipe - 0,0%
0
jose angel - 0,0%
0
federico - 0,0%

 
New Topic Post reply to : Need remove a spyware virus Printable version of : Need remove a spyware virus
[ << Previous Thread | Next Thread >> ]

diablofast
New Member


Date Joined Oct 2006
Total Posts : 1
 
   Posted 10-18-2006 12:35 (GMT +1)    Quote: Need remove a spyware virusAlert an admin about: Need remove a spyware virus
wave, like they are. I need to eliminate a virus it scouts that he/she has me slow the computer and the sailing in internet. I´m runned hijackthis with the option "Do a system scan and save a log file" and he gave me the following results

Logfile of HijackThis v1.99.1
Scan saved at 06:12:58 p.m., on 17/10/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Archivos of programa\Archivos comunes\Symantec Shared\ccSetMgr.exe
C:\Archivos of programa\Archivos comunes\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Archivos of programa\Archivos comunes\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Archivos of programa\Archivos comunes\Microsoft Shared\VS7DEBUG\MDM.EXE
Programa\Norton C:\Archivos AntiVirus\navapsvc.exe
Programa\Norton C:\Archivos AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\Explorer.EXE
C:\Archivos of programa\SoftCodec\pmsngr.exe
Programa\MSN C:\Archivos Messenger\msnmsgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\icpldrvx.exe
Programa\Adobe\Acrobat C:\Archivos 5.0\Reader\AcroRd32.exe
Programa\Internet C:\Archivos Explorer\IExplore.exe
Programa\LHSP\L&H C:\Archivos Power Translator Pro\ptpro.exe
C:\Documents and Settings\José Angel\Configuración temporary local\Archivos of Internet\Content.IE5\6G0TR34M\HijackThis. exe

O4 - HKLM \.. \ Run: [Avg Antivirus] C:\WINDOWS\system32\icpldrvx.exe
O4 - HKLM \.. \ Run: [QuickTime Task] "C:\Archivos of programa\QuickTime\qttask.exe" - atboottime
O4 - HKCU \.. \ Run: [msnmsgr] "programa\MSN C:\Archivos Messenger\msnmsgr.exe" / background
O4 - HKCU \.. \ Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O17 - HKLM\System\CCS\Services\Tcpip \.. \ {77BA27DF-3F95-4166-9D77-10F6FC07CA12}: NameServer = 200.21.200.2,200.21.200.79
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Archivos of programa\Archivos comunes\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Archivos of programa\Archivos comunes\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Archivos of programa\Archivos comunes\Symantec Shared\ccSetMgr.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Archivos of programa\Archivos comunes\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Norton Antivirus Car-Protect Service (navapsvc) - Symantec Corporation - programa\Norton C:\Archivos AntiVirus\navapsvc.exe
O23 - Service: Norton Antivirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - programa\Norton C:\Archivos AntiVirus\IWP\NPFMntor.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\ARCHIV~1\ARCHIV~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Archivos of programa\Archivos comunes\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Archivos de programa\Archivos comunes\Symantec Shared\SPBBC\SPBBCSvc.exe

and I don´t that to make now, for this reason I ask them to guide me in this problem
jumpin jumpin jumpin jumpin jumpin jumpin jumpin jumpin jumpin jumpin jumpin turn turn
Back to Top
 

Tron
Trusted Member




Date Joined Oct 2006
Total Posts : 290
 
   Posted 10-18-2006 12:23 (GMT +1)    Quote: Need remove a spyware virusAlert an admin about: Need remove a spyware virus
Hi Diablofast.

Run HJT again and place a tick next to this item and click 'Fix'.

C:\Archivos of programa\SoftCodec\pmsngr.exe

'pmsngr.exe' is a process associated with Trojan.Media-Codec.Process from NA. pmsngr.exe is a dangerous program. Trojan.Media-Codec.Process often silently downloads and installs rogue security programs such as SpywareQuake, SpyFalcon and WinAntivirusPro, but may install other malware as well. Some variants of Trojan-Downloader.Zlob.Media-Codec have backdoor functionality, giving a remote attacker the ability to control and use the infected machine for malicious purposes.

It is recommended to disable System Restore feature of these operating systems to prevent a computer from re-infection by an already removed malware. The fact is that System Restore feature of these operating systems might save an infected file into the special folder and copy it back to a hard drive it every time it's been renamed or deleted by a user.

Click Start/All Programs/Accessories/System Tools/System Restore
On the right of the system restore window click 'System Restore Settings'.
Place a tick in the box 'Turn off System Restore' Apply, Ok.
If your system requires a reboot then let it reboot.

When your system comes back online - Click Start/All Programs/Accessories/System Tools/System Restore
On the right of the system restore window click 'System Restore Settings'.
Untick the box 'Turn off System Restore' Apply, Ok.
If your system requires a reboot then let it reboot.

Next: Please go here and run an online scan with kaspersky and let it delete whatever it finds.
http://www.kaspersky.com/virusscanner

Next: Download Ccleaner and clean out all your Temp Junk Files Etc.
http://www.filehippo.com/download_ccleaner/

Next: Try AVG AntiSpyware. Download the trial version of AVG Anti-Spyware from here to your Desktop and doubleclick on the executable to install it. http://www.ewido.net/en/download

Launch AVG Anti-Spyware (there should be an icon on your desktop doubleclick it). The program will now go to the main screen. You will need to update AVG Anti-Spyware to the latest definition files.

On the left hand side of the main screen click update and then click on Start Update. The update will start and a progress bar will show the updates being installed. Do not run a scan yet.

When you have done this, boot into Safe Mode.

Run AVG Anti-Spyware now. Click Scanner, then click on the Scan tab. Click Complete System Scan to begin scanning. When the scan is complete click Recommended Action and change it to Quarantine. Then click Apply all actions. When the scan is finished, click the Save report button at the bottom of the screen. Save the report to your desktop and close AVG Anti-Spyware.

Reboot and post and your AVG Anti-Spyware report & FULL HJT Logfile.

Kind Regards.
Tron.
Back to Top
 
New Topic Post reply to : Need remove a spyware virus Printable version of : Need remove a spyware virus
 
Forum Information
Currently it is Tuesday, January 06, 2009 2:59 PM (GMT +1)
There are a total of 65.864 posts in 16.165 threads.
In the last 3 days there were 22 new threads and 87 reply posts. View Active Threads
Who's Online
This forum has 27758 registered members. Please welcome our newest member, Nards.
42 Guest(s), 0 Registered Member(s) are currently online.  Details
5 Latest Threads
Virus stopping AVG and spybot from running (6)06-01-2009 13:27:28 (N11xxy)
Error message (0)06-01-2009 13:24:43 (tariq1)
Cannot remove malware (4)06-01-2009 13:13:30 (phill)
Have I a machine infection? (8)06-01-2009 12:42:25 (Geekguy)
How to restore missing control panel and properties (0)06-01-2009 12:30:09 (Nards)