This thread's last reply is from December 23, 2006, 11:43 PM UTC. Software, malware, and removal-tool
advice below may be out of date — treat specific steps and download links with caution.
pokhim
about 120gb of music and vids.
its going ok i'm gonna upload a firewall and a anti spyware from a disc that i burnt. then run updates and get a few more antivirus's. i'll let you know if and when i get this sorted.
wng_z3r0
Unplug your hard drive that has the music.
Format and reinstall windows on the OTHER one.
Plug in the hard drive that has your music, **MAKE SURE TO LOAD THE CLEAN OS, and not from the infected drive.
Turn your computer on, and transfer your music to the clean hard drive. Then format the infected one.
Run the scans and post back to Susan. If you are still infected, your music will have to go.
wng
pokhim
Okay, I've re-installed windows 3 times now (with both quick and long formats)
Every time I connect to the internet and launch IE (to try and run windows update) I get the same dialogue box I had before;
It asks for a username and password for my router
This happens every time a part of a web page starts to load e.g. every picture, so for each web page I get upwards of 20 of these boxes.
The main point is that the last two refomats and installs I haven't reconnected my IDE drive.
I am guessing that the virus (if it is a virus) is staying on the disk somewhere, the only place I can think of would be in the MBR or the 8MB unpartitionable space that I can see in the windows installation wizard.
Also this is browser specific, firefox will work okay without any boxes.
All of the other computers on the network are fine and have no problems accessing the internet through IE. The router in question does not ask for a username and password from within my LAN (only in the case of a Telnet operation)
pokhim
with regards to my post above,
I have now worked out how to stop the boxes appearing in IE
I can go to internet options then click on the connections tab
then click on the LAN settings button and uncheck the first box that says automatically detect settings
That will allow me to browse without the boxes.
Is this then a windows problem rather than a virus/malware?
wng_z3r0
Yeah it sounds like a windows problem.
pokhim
well thanks i think i got my computer sorted and up and running again. i dont have any problems and i managed to format both hard drives while keeping my music and vids. i've run a few of the virus and malware checkers and they come up with nothing. thanks for all your help you are a god amongst mortals.
pokhim
Logfile of HijackThis v1.99.1
Scan saved at 13:06:29, on 10/11/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\DOCUME~1\TARIQB~1\LOCALS~1\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
wng_z3r0
The gmer log is clean.
Lay off the torrents for now. It is an easy way to get infected.
I don't mean to condescend you, but if you are downloading pirated files, no amount of security precautions are going to keep your computer clean, and it is pointless to try to keep the machine clean. We would not be as forthcoming the second time your computer is infected.