Go Back   Computer Juice > Computer Software > Virus, Spyware & Security
Register Points Site Spy New Posts Donate Unanswered Posts Search Forum Rules


Reply
 
LinkBack Thread Tools
  #31  
Old 27th Dec 2007, 05:57 PM
No Avatar
Member Group
 
howardhopkinson is offline
 
Join Date: 17th Sep 2007
Last Online: 24th Jan 2008 05:43 PM
Age: 54
Posts: 108
iTrader: (0)
howardhopkinson is on a distinguished roadhowardhopkinson is on a distinguished road
Default trojan horse BHO.CVX has stolen my computer !!!!!

Don`t panic just yet, there`s still a few things we can try to solve your problems.

Try this to fix your net problems.

1.) Download Winsockfix from HERE.
2.) Run WinsockFix.exe.
3.) Click the Fix button.

Reboot your system and see if you can access the net.

Your HJT log is clean.

However, some malware can hide from HJT, unless the HijackThis.exe file is renamed.

Go to C:\Program Files\Trend Micro\HijackThis\HijackThis.exe and right click on the HijackThis.exe file, choose rename. Click in the title box and hit the enter key to clear what`s there. Rename it to crusty.exe and hit the enter key. Right click on the crusty.exe file and choose send to desktop, create shortcut.

From your desktop double click on the crusty.exe shortcut and run a fresh HJT scan. Post a fresh HJT log.

Regards Howard.

Last edited by howardhopkinson : 27th Dec 2007 at 06:02 PM.
Digg this postDel.icio.us this postReddit this post Stumble this postFacebook this post
Reply With Quote
  #32  
Old 28th Dec 2007, 03:18 AM
slime's Avatar
slime  United Kingdom
Donor Group
 
slime is offline
 
Join Date: 24th Dec 2007
Last Online: Today 11:49 AM
Posts: 69
iTrader: (0)
slime is on a distinguished road
Default trojan horse BHO.CVX has stolen my computer !!!!!

[quote=howardhopkinson;46621]Don`t panic just yet, there`s still a few things we can try to solve your problems.

Just starting to panic a it now Howard.
Did as requested & have the followinh HJT (or Crusty) log,

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:01:35, on 12/28/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb0 4.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Trend Micro\HijackThis\Crusty.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb0 4.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsu...?1154716096448
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
--
End of file - 6881 bytes

However I still have NO internet access at all.
Firefox says it's not my default browser, when I know it is, & every site I try to connet to, (from my bookmarked sites), it just says "Firefox can't find the server at ....."!
Regards,
Slime.
Digg this postDel.icio.us this postReddit this post Stumble this postFacebook this post
Reply With Quote
  #33  
Old 28th Dec 2007, 04:37 AM
No Avatar
Member Group
 
howardhopkinson is offline
 
Join Date: 17th Sep 2007
Last Online: 24th Jan 2008 05:43 PM
Age: 54
Posts: 108
iTrader: (0)
howardhopkinson is on a distinguished roadhowardhopkinson is on a distinguished road
Default trojan horse BHO.CVX has stolen my computer !!!!!

Ok, your HJT is clean, which is good news.

Now, try the following one at a time and see if it helps any.

Make sure your modem is connected and turned on. Click start/run and type cmd into the run box and hit the enter key.

At the command prompt type the following. ipconfig /all Note the space after the ipconfig part.

You sholud see your ip address/mac address etc come up. Once it`s finished, type exit. See if you now have net access.

No? Then do the following.

Click start/run and type sfc /scannow into the run box and hit the enter key. Windows will scan for and attempt to replace any missing or damaged system files. You will need to have your Windows CD handy.

Once it`s done, see if you have net access.

No? Then do the following.

Do a Windows repair as per this guide HERE.

Once done see if you have net access.

No? Now is the time to backup your important data and reformat.

Take a look at the attached instructions on how to reinstall windows.

Please let us know how you get on.

Regards Howard.
Attached Files
File Type: txt How to install Windows Xp.txt (1.7 KB, 2 views)
Digg this postDel.icio.us this postReddit this post Stumble this postFacebook this post
Reply With Quote
  #34  
Old 28th Dec 2007, 07:23 AM
slime's Avatar
slime  United Kingdom
Donor Group
 
slime is offline
 
Join Date: 24th Dec 2007
Last Online: Today 11:49 AM
Posts: 69
iTrader: (0)
slime is on a distinguished road
Default trojan horse BHO.CVX has stolen my computer !!!!!

Hi Howard,
I did the ipconfig /all thing..........no good.
I did the sfc /scannow thing........no good.
Re-booted before doing the Windows repair thing........Woooo Hoooo.
We have an Internet situation & everything looks good.
You, Sir, are a star, but you probably already know that!
Once again, many thanks to you & evilfantasy for your efforts in sorting my problem.
Regards in reverance,
Slime.

P.S. What should I do with all the progs & logfiles I've used recently.
P.P.S. Have a great new year, all of you guys.
Digg this postDel.icio.us this postReddit this post Stumble this postFacebook this post
Reply With Quote
  #35  
Old 28th Dec 2007, 08:05 AM
No Avatar
Member Group
 
howardhopkinson is offline
 
Join Date: 17th Sep 2007
Last Online: 24th Jan 2008 05:43 PM
Age: 54
Posts: 108
iTrader: (0)
howardhopkinson is on a distinguished roadhowardhopkinson is on a distinguished road
Default trojan horse BHO.CVX has stolen my computer !!!!!

That`s great news and I`m chuffed your problem is now solved.

As regards all the tools etc you used, please do the following.

Click start run and type combofix /u and hit the enter key. This will uninstall Combofix and all it`s folders etc.

As for the other tools you used, feel free to get rid of them if you want.

Regards Howard.

This thread is for the use of Slime only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our Virus, spyware & Security forum.
Digg this postDel.icio.us this postReddit this post Stumble this postFacebook this post
Reply With Quote

Please support this forum, donate towards our running costs.
Reply

Thread Tools
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
TROJAN HORSE iana Virus, Spyware & Security 11 28th May 2008 11:40 PM
Trojan Horse; Help!! Phil1706 Virus, Spyware & Security 4 17th Mar 2008 07:39 AM
AVG reporting trojan horse BHO.CVX - Help please chrisleech11 Virus, Spyware & Security 24 20th Dec 2007 10:17 AM
Help again evilfantasy!! avast found TROJAN HORSE! guccijana Virus, Spyware & Security 58 11th Oct 2007 08:47 PM
Trojan Horse and AVG chuckeruk Virus, Spyware & Security 8 2nd Jul 2007 09:02 AM


Copyright ©2006 - 2008 Computer Juice.

Powered by vBulletin® Copyright ©2000 - 2008 Jelsoft Enterprises Ltd. SEO by vBSEO ©2008, Crawlability, Inc.