Mary Kate Posted March 30, 2005 Report Share Posted March 30, 2005 (edited) Hello 1.) i've never posted on a board at all before so i hope i'm doing it right 2) my computer was a mess........I ran nortons and it came back with 236 viruses. I was able to delete the majority of them by simply finding where they were in the program files and deleting them. A few however were listed as locked. I went to the task manager and shut them off and tried to delete them again but to no avail.3) the remaining pain in the rear viruses are: winik.sys -C:\WINDOWS\SYSTEM32\DRIVERS\winik.sys cnml.exe GEACH8hM.dll GEACH8hM.exe Mh8HCAEG.exe -C:\ProgramFiles\wsruswpv\cnml.exe (The last four are all in the same program file and i guess are related??)I ran a Highthis log and will post it below.........Any help @ all that you can give me would be mUcH MuCh appreciated!!!!!!!! MK!Removed attachment, placed it into the right log -- dk Logfile of HijackThis v1.99.1Scan saved at 2:33:21 AM, on 3/30/2005Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\Program Files\Common Files\Symantec Shared\ccSetMgr.exeC:\WINDOWS\Explorer.EXEC:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exeC:\WINDOWS\system32\LEXBCES.EXEC:\WINDOWS\system32\spoolsv.exeC:\WINDOWS\system32\LEXPPS.EXEC:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exeC:\Program Files\Norton AntiVirus\navapsvc.exeC:\WINDOWS\system32\pctspk.exeC:\Program Files\Norton AntiVirus\SAVScan.exeC:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exeC:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exeC:\Program Files\Common Files\Symantec Shared\ccApp.exeC:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exeC:\PROGRA~1\wsruswpv\GEACH8hM.exeC:\Program Files\AIM95\aim.exeC:\PROGRA~1\wsruswpv\Mh8HCAEG.exeC:\WINDOWS\system32\ctfmon.exeC:\WINDOWS\system32\taskmgr.exeC:\Program Files\Internet Explorer\iexplore.exeC:\Program Files\Messenger\msmsgs.exeC:\Program Files\Hijack\hijackthis\HijackThis.exeR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.psu.edu/R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocxO2 - BHO: Viewpoint Toolbar BHO - {A7327C09-B521-4EDB-8509-7D2660C9EC98} - C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBarBHO.dllO2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dllO3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dllO3 - Toolbar: Viewpoint Toolbar - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBar.dllO4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottimeO4 - HKLM\..\Run: [Registry Loader] regloadr.exeO4 - HKLM\..\Run: [Config Loader] scvhost.exeO4 - HKLM\..\Run: [Configuration Loader] wincrt32.exeO4 - HKLM\..\Run: [Antivirus] C:\WINDOWS\av.exeO4 - HKLM\..\Run: [eeomhoik] C:\WINDOWS\owpmxdwj.exeO4 - HKLM\..\Run: [] c:\WINDOWS\System32\O4 - HKLM\..\Run: [zzb] c:\WINDOWS\System32\zzb.exeO4 - HKLM\..\Run: [Windows DEC] windec.exeO4 - HKLM\..\Run: [Microsoft Update] msawindows.exeO4 - HKLM\..\Run: [Microsoft Services] svssshost.exeO4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exeO4 - HKLM\..\Run: [symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exeO4 - HKLM\..\RunServices: [Registry Loader] regloadr.exeO4 - HKLM\..\RunServices: [Config Loader] scvhost.exeO4 - HKLM\..\RunServices: [Configuration Loader] wincrt32.exeO4 - HKLM\..\RunServices: [Windows DEC] windec.exeO4 - HKLM\..\RunServices: [Microsoft Update] msawindows.exeO4 - HKLM\..\RunServices: [Microsoft Services] svssshost.exeO4 - HKCU\..\Run: [AIM] C:\Program Files\AIM95\aim.exe -cnetwait.odlO4 - HKCU\..\Run: [] c:\WINDOWS\System32\O4 - HKCU\..\Run: [Microsoft Services] svssshost.exeO4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exeO4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXEO8 - Extra context menu item: &Viewpoint Search - res://C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBar.dll/CXTSEARCH.HTMLO8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exeO9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO15 - Trusted Zone: cms.psu.eduO15 - Trusted Zone: http://*.windowsupdate.comO16 - DPF: {072D3F2E-5FB6-11D3-B461-00C04FA35A21} (CFForm Runtime) - http://www.mbakercorp.com/CFIDE/classes/CFJava.cabO20 - Winlogon Notify: ComPlusSetup - C:\WINDOWS\System32\catsrvut.dllO23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exeO23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exeO23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exeO23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXEO23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exeO23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel, Inc. - C:\WINDOWS\system32\pctspk.exeO23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exeO23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exeO23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exeO23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exeO23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exeO23 - Service: Windows Update (wupdate) - Unknown owner - C:\WINDOWS\System32\wudate.exe" -service (file missing) Edited March 30, 2005 by dknoppix Link to post Share on other sites
Besttechie Posted March 30, 2005 Report Share Posted March 30, 2005 Hi and Welcome,Please run the following scan:http://housecall.trendmicro.com/Make sure you check the autoclean box. Then after the scan post a brand new HijackThis log.Good luck! B Link to post Share on other sites
Recommended Posts