Go Back   Computer Juice > Computer Software > Virus, Spyware & Security
Register Members New Posts Donate Unanswered Posts Site Spy Search


Reply
 
Thread Tools
  #1  
Old 18-05-2008, 10:53 PM
ruffryder2k7's Avatar
CJ Member
Intel Nvidia
ruffryder2k7 is offline
 
Join Date: May 2008
Last Online: 01-07-2008 09:43 PM
Posts: 11
iTrader: (0)
ruffryder2k7 is on a distinguished road
Default Infected with Virus.Win32.Tenga.a; Please Help !!

I recently formatted my computer, and after formatting and driver installation my computer was running perfectly fine. Then, after installing Kaspersky internet security and Limewire 4.17, programs started to load very slowly and web browsers are very slow even though I have full connectivity. Kaspersky cleaned out the computer from the virus (Virus.Win32.Tenga.a), and reported the computer virus free but my computer is still acting weird. Also, it says access denied to many programs such as WinZip, disabling me from extracting any files when I tried installing an anti-spyware program to try to find any infected files. I can't use most programs =(

The infected file is:

c:\windows\softwaredistribution\download\dfeddbe03 266add4998ad4eea2bf3073\update\update.exe 643.5 KB


Please help !!!!!!
Digg this postDel.icio.us this postTechnorati this postNetscape this postStumble this post
Reply With Quote
  #2  
Old 18-05-2008, 11:22 PM
Dave Hybrid's Avatar
CJ Administrator
Intel Nvidia
Dave Hybrid is offline
 
Join Date: Apr 2006
Last Online: Today 10:02 PM
Age: 26
Posts: 7,223
iTrader: (0)
Dave Hybrid has a reputation beyond reputeDave Hybrid has a reputation beyond reputeDave Hybrid has a reputation beyond reputeDave Hybrid has a reputation beyond reputeDave Hybrid has a reputation beyond reputeDave Hybrid has a reputation beyond reputeDave Hybrid has a reputation beyond reputeDave Hybrid has a reputation beyond reputeDave Hybrid has a reputation beyond reputeDave Hybrid has a reputation beyond reputeDave Hybrid has a reputation beyond repute
Default Infected with Virus.Win32.Tenga.a; Please Help !!

Start here > http://www.computer-juice.com/forums...-posting-7476/
__________________

Computer Juice raffle
- Win PC hardware of your choice worth £500 / €680 / $1000 - Enter HERE!
__________________

My System: The Hybrid Lappy

CPU(s):
AMD Turion 64 x2 TL-64 2.2GHz
Motherboard:
HP nForce 560
RAM:
2GB DDR2 PC2-5300
Graphics Card(s):
Nvidia 7150M Onboard Integrated
Sound Card:
5.1 Onboard Integrated
Hard Drive(s):
250GB 5400RPM SATA300
Optical Drive(s):
18x CD/DVDRW-DL ATA
Case / PSU:
Stock HP
Cooling:
Stock HP
Network / Internet:
10/100 Nic / 10MB Virgin Cable
Monitor(s):
17" WXGA+ HD BrightView Widescreen
Operating System(s):
Windows Vista Home Premium 32 SP1

Want your system info in your signature?
Digg this postDel.icio.us this postTechnorati this postNetscape this postStumble this post
Reply With Quote
  #3  
Old 18-05-2008, 11:54 PM
ruffryder2k7's Avatar
CJ Member
Intel Nvidia
ruffryder2k7 is offline
 
Join Date: May 2008
Last Online: 01-07-2008 09:43 PM
Posts: 11
iTrader: (0)
ruffryder2k7 is on a distinguished road
Default Infected with Virus.Win32.Tenga.a; Please Help !!

I can't extract the Zip file to use HostsXpert =(
Digg this postDel.icio.us this postTechnorati this postNetscape this postStumble this post
Reply With Quote
  #4  
Old 19-05-2008, 12:29 AM
kanoakavirus's Avatar
CJ Donator
Intel Nvidia
kanoakavirus is offline
 
Join Date: Mar 2008
Last Online: Today 10:05 AM
Age: 97
Posts: 1,205
iTrader: (0)
kanoakavirus is on a distinguished roadkanoakavirus is on a distinguished road
Default Infected with Virus.Win32.Tenga.a; Please Help !!

My only advise would be to stay clear of limewire.
__________________
Behind Every Strong Man Stands An Even Stronger Woman.
__________________

My System: KaV

CPU(s):
Intel(R) Pentium(R) 4 CPU 3.00GHz
Motherboard:
DCC 0N2828
RAM:
Dell 2 x 256 mb DDR
Graphics Card(s):
NVIDIA GeForce4 MX 440 with AGP8x
Sound Card:
Creative Sound Blaster 5.1
Hard Drive(s):
Maxtor 2x 60gb
Optical Drive(s):
Generic Shite
Case / PSU:
Dell/Custom - 550w Trust
Cooling:
1 x 120/80mm led fans 2x 40mm led fans
Network / Internet:
Broadband 2mb
Monitor(s):
DELL M992 17"
Operating System(s):
Windows XP Home/Service pack 2 /32bit

Want your system info in your signature?
Digg this postDel.icio.us this postTechnorati this postNetscape this postStumble this post
Reply With Quote
  #5  
Old 19-05-2008, 12:33 AM
ruffryder2k7's Avatar
CJ Member
Intel Nvidia
ruffryder2k7 is offline
 
Join Date: May 2008
Last Online: 01-07-2008 09:43 PM
Posts: 11
iTrader: (0)
ruffryder2k7 is on a distinguished road
Default Infected with Virus.Win32.Tenga.a; Please Help !!

I used my other computer to put CC cleaner, Super anti-spyware and HostsXpert on a CD. When I put the CD into my infected computer and tried to install any of the programs, it said access denied.

Now what?!
Digg this postDel.icio.us this postTechnorati this postNetscape this postStumble this post
Reply With Quote
  #6  
Old 19-05-2008, 01:14 AM
evilfantasy's Avatar
CJ Moderator
Intel ATi
evilfantasy is offline
Send a message via Yahoo to evilfantasy
 
Join Date: Jul 2007
Last Online: Today 08:43 PM
Posts: 4,605
iTrader: (0)
evilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond repute
Default Infected with Virus.Win32.Tenga.a; Please Help !!

Try this.
  • Go to Start > Control Panel > Internet Options
  • In the General tab, Temporary Internet Files, click: Delete Files
  • When prompted, check: Delete all offline content
  • You can also check: Delete Cookies
    • You will have to re-enter passwords at websites that require them.
  • Click OK
  • Then, go to Start >Run and enter: cleanmgr
  • Select the drive to clean:
  • Check the following boxes and then press OK to remove:
    • Temporary Files
    • Temporary Internet Files
    • RecycleBin
Agree to the prompt to perform the action...
__________________
.
.
Digg this postDel.icio.us this postTechnorati this postNetscape this postStumble this post
Reply With Quote
  #7  
Old 19-05-2008, 02:09 AM
ruffryder2k7's Avatar
CJ Member
Intel Nvidia
ruffryder2k7 is offline
 
Join Date: May 2008
Last Online: 01-07-2008 09:43 PM
Posts: 11
iTrader: (0)
ruffryder2k7 is on a distinguished road
Default Infected with Virus.Win32.Tenga.a; Please Help !!

After doing that, I still can't install HostXpert, it says Error; cannot create file F;/HostXpert/hostxpert.tmp

However, I was able to install Super Anti-Spyware and I'm running a full system scan now. It found a lot of spyware so far.

Is there anything else I should do?
Digg this postDel.icio.us this postTechnorati this postNetscape this postStumble this post
Reply With Quote
  #8  
Old 19-05-2008, 02:44 AM
evilfantasy's Avatar
CJ Moderator
Intel ATi
evilfantasy is offline
Send a message via Yahoo to evilfantasy
 
Join Date: Jul 2007
Last Online: Today 08:43 PM
Posts: 4,605
iTrader: (0)
evilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond repute
Default Infected with Virus.Win32.Tenga.a; Please Help !!

If you can get a Hijackthis log after SAS is done running that would be good.
__________________
.
.
Digg this postDel.icio.us this postTechnorati this postNetscape this postStumble this post
Reply With Quote
  #9  
Old 19-05-2008, 02:51 AM
ruffryder2k7's Avatar
CJ Member
Intel Nvidia
ruffryder2k7 is offline
 
Join Date: May 2008
Last Online: 01-07-2008 09:43 PM
Posts: 11
iTrader: (0)
ruffryder2k7 is on a distinguished road
Default Infected with Virus.Win32.Tenga.a; Please Help !!

after i scanned with anti-spyware and anti-malware the computer started to behave more normal

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:46:31 PM, on 5/18/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Creative\Shared Files\CTAudSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\CTHELPER.EXE
C:\WINDOWS\system32\CTXFIHLP.EXE
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE
C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe
C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe
C:\Program Files\U-ABIT\uGuru\uGuru.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\SYSTEM32\CTXFISPI.EXE
C:\Program Files\Veoh Networks\Veoh\VeohClient.exe
C:\Program Files\ParetoLogic\Anti-Spyware\Pareto_AS.exe
C:\Program Files\Creative\Sound Blaster X-Fi\Entertainment Center\EAXLoadr.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Creative\ShareDLL\CADI\NotiMan.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\uTorrent\uTorrent.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
O2 - BHO: {7a39a7f9-3a1a-b16b-2094-9e56052d96a6} - {6a69d250-65e9-4902-b61b-a1a39f7a93a7} - C:\WINDOWS\system32\ilcvgldl.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\WINDOWS\RaidTool\xInsIDE.exe
O4 - HKLM\..\Run: [36X Raid Configurer] C:\WINDOWS\System32\xRaidSetup.exe boot
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [CTDVDDET] "C:\Program Files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE"
O4 - HKLM\..\Run: [RCSystem] "C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" RCSystem * -Startup
O4 - HKLM\..\Run: [AudioDrvEmulator] "C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" -1 AudioDrvEmulator "C:\Program Files\Creative\Shared Files\Module Loader\Audio Emulator\AudDrvEm.dll"
O4 - HKLM\..\Run: [VolPanel] "C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe" /r
O4 - HKCU\..\Run: [ABIT uGuruIII] C:\Program Files\U-ABIT\uGuru\uGuru.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Veoh] "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
O4 - HKCU\..\Run: [ParetoLogic Anti-Spyware] "C:\Program Files\ParetoLogic\Anti-Spyware\Pareto_AS.exe" -NM -hidesplash
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: Add to Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\ie_banner_deny.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\SCIEPlgn.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Kaspersky Internet Security 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
O23 - Service: Creative Audio Service (CTAudSvcService) - Creative Technology Ltd - C:\Program Files\Creative\Shared Files\CTAudSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Viewpoint Manager Service - Unknown owner - C:\Program Files\Viewpoint\Common\ViewpointService.exe (file missing)

--
End of file - 5460 bytes
Digg this postDel.icio.us this postTechnorati this postNetscape this postStumble this post
Reply With Quote
  #10  
Old 19-05-2008, 02:54 AM
evilfantasy's Avatar
CJ Moderator
Intel ATi
evilfantasy is offline
Send a message via Yahoo to evilfantasy
 
Join Date: Jul 2007
Last Online: Today 08:43 PM
Posts: 4,605
iTrader: (0)
evilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond repute
Default Infected with Virus.Win32.Tenga.a; Please Help !!

I need the logs from both SAS and MBAM.

Looking at the HJT log...
__________________
.
.
Digg this postDel.icio.us this postTechnorati this postNetscape this postStumble this post
Reply With Quote

Please support this forum, donate towards our running costs.


Reply


Thread Tools

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Infected with Spyware Greenhorn Virus, Spyware & Security 4 09-04-2008 07:14 PM
I'm not sure if my computer is infected or not Rob1 Virus, Spyware & Security 4 04-02-2008 09:14 PM
New Win32 has disabled my computer - urgent help, please catmartin Virus, Spyware & Security 1 05-01-2008 01:06 AM
Win32.Poison.k Trojan casselle Virus, Spyware & Security 7 22-10-2007 08:28 AM


Copyright ©2006 - 2008 Computer Juice.

Powered by vBulletin® Copyright ©2000 - 2008 Jelsoft Enterprises Ltd. SEO by vBSEO ©2008, Crawlability, Inc.

Page copy protected against web site content infringement by Copyscape