Got a virus or two....URGENT!

Zero Signal said:
Start by getting rid of these. If you know that some of these are ok, then don't mess with it, so check first. As mentioned, you can do more damage than good if you start shooting from the hip with a program like this. Since I don't know everything you have installed, I can't tell which ones are good, but these are the ones I would instantly delete from MY machine. As a rule of thumb, if you have all your progams closed (nothing in the taskbar either) you should have 20-25 running processes. If you have a multi-function printer, it may be more like 30.

EDIT: Just saw that you got it fixed. Good deal :nice: Still worth looking into though . . .

C:\WINDOWS\znzniqj.exe
C:\WINDOWS\SYSC00.exe
C:\WINDOWS\ms0403007-625.exe
C:\WINDOWS\znzniqjA.exe
C:\WINDOWS\System32\wuauclt.exe

R3 - URLSearchHook: (no name) - _{EA756889-2338-43DB-8F07-D1CA6FB9C90D} - (no file)
R3 - URLSearchHook: (no name) - _{02EE5B04-F144-47BB-83FB-A60BD91B74A9} - (no file)
R3 - URLSearchHook: (no name) - {02EE5B04-F144-47BB-83FB-A60BD91B74A9} - C:\Program Files\SurfSideKick 3\SskBho.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll

O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,ClientStartup -s
O4 - HKLM\..\Run: [TheMonitor] C:\WINDOWS\SYSC00.exe
O4 - HKLM\..\Run: [ms0403007-625] C:\WINDOWS\ms0403007-625.exe
O4 - HKLM\..\Run: [znzniqjA] C:\WINDOWS\znzniqjA.exe
O4 - HKLM\..\RunServices: [freexstyle] lockbr.exe

O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O18 - Filter: text/html - {2F6E85DC-8D2D-4896-8A4F-7DF8A7B1749D} - C:\PROGRA~1\Jalmp\jalmp.dll
O20 - Winlogon Notify: DateTime - C:\WINDOWS\system32\lv4009hme.dll
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\TWljaGFlbCBCYXJiYWxpbmFyZG8\command.exe (file missing)

O23 - Service: Windows Overlay Components - Unknown owner - C:\WINDOWS\znzniqj.exe


Yeah, we deleted most of the hijackthis files.

We got in pretty deep too, we downloaded a file that was SUPPOSED to fix new.net spyware problem, which ****ing corrupted WinSock, so that killed his internet and he was left without internet without a windows cd, unable to reinstall TCP/IP.

****ING SYSTEM RESTORE FTW!!!
 
Chronos[AsG] said:
The problem with killing processes is that there is usually a large number of them and many of them are generic windows processes. It can get confusing about what you should kill and what you shouldn't. If Zero can help you with the HiJackThis results it would be extremely helpful but I still dont think it would hurt to run Ad Aware (which has become very mediocre in the last year or two), Spybot: Search and Destroy and then run a good anti-virus. I would recommend AVG as it is free and effective. Stay away from Norton and McAfee. They're both resource hogs and aren't very good anyway.

After everything is back to normal you might want to run spyware and virus scans every week or so.


I agree that McAfee sucks but i disagree with Norton being bad