ok i have some virus's and cant get rid of them.they are trojan horse clickers and delf downloaders and trojan horse generic.i have loads.i just got them one day and cant get rid of them with nortan,AVG,protecter plus or spyware removal programs.and since yesterday the pc randomly restarts to a blue screen.i cant really see what it says cause its only there for a second or so but it says system shutdown or something.can anyone help?
Logfile of HijackThis v1.99.1
Scan saved at 3:42:26 AM, on 3/4/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
You have two antivirus programs running and it may be one reason for your crashes. You must remove one of them. I suggest that you remove AVG Antivirus especially if you have a licence to Norton. So go to the Control Panel --> Add or remove programs and remove AVG OR Norton.
You also have some malware on your computer.
Cleaning instructions
Disable Microsoft Antispyware (it may hinder the cleaning process. Also check that it is disabled after every restart)
4. Close all windows before proceeding.
->Doubleclick Look2Me-Destroyer.exe to run the program
->Check Run this program as a task option.
->You get a message: "Look2Me-Destroyer will close and re-open in approximately 10 seconds". Click OK ->When Look2Me-Destroyer opens again click Scan for L2M option, your desktop icons will disappear for a seconds but it is normal.
->When scanning is ready, click Remove L2M option.
->When you get the message Done Scanning, click OK.
->When ready you'll get this message: Done removing infected files! Look2Me-Destroyer will now shutdown your computer, Click OK.
->Your computer will shutdown..
->Restart your computer.
If your firewall alerts about connections to this program, allow those.
5. Doubleclick windelfkill32.exe file on your desktop. A win32delfkill folder will appear to your desktop.
->Close all windows open win32delfkil folder. Doubleclick fix.bat. Answer yes to any questions. If your computer doesn't restart, restart it
6. Run HijackThis and fix these entries (do a system scan only, check entries, close all other windows, press Fix checked).
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
O4 - HKCU\..\Run: [AlexaToolbar] C:\WINDOWS\alt.exe
O15 - Trusted Zone: www.archiviosex.net
O15 - Trusted Zone: www.contentcooler.biz
O15 - Trusted Zone: www.new-access.biz
O15 - Trusted Zone: www.redfunny.com
O15 - Trusted Zone: www.skymasters.biz
O16 - DPF: {85D1F3B2-2A21-11D7-97B9-0010DC2A6243} (SecureLogin class) - http://secure2.comned.com/signuptemplates/securelogin-devel.cab
7. Restart your computer to the safe mode (Press F8 button when computer is starting)
8. Make your hidden files visible:
->On the Tools menu in Windows Explorer, click Folder Options.
->Click the View tab.
->Under Hidden files and folders, click Show hidden files and folders.
9. Delete this file:
C:\WINDOWS\-->alt.exe<--
10. Empty the Recycle Bin
11.Make your hidden files invisible again:
->On the Tools menu in Windows Explorer, click Folder Options.
->Click the View tab.
->Under Hidden files and folders, click Do not show hidden files and folders.
12. Scan yor computer with Ewido and save the log file.
13. Restart your computer normally.
14. Run HijackThis and post its fresh log and Ewido's log and logs from c:\windelf.txt and C:\Look2Me-Destroyer.txt to here so we can see if you computer is now clean. :)
Now you can enable Microsoft Antispyware.
You have many programs starting when you start your computer and if you want to make your computer (especially the start) faster, you can fix these entries with HijackThis.
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
You're welcome but please post a fresh HijackThis log and Ewido's log and logs from c:\windelf.txt and C:\Look2Me-Destroyer.txt to here so we can see if you computer is now clean. :)
i tryed to run Look2Me-Destroyer it wont work.it says component 'mswinsck.ocx' or one of its dependencies not correctly registered:a file is missing or invalid
help
In normal mode (not in the safe mode)
-> Unplug your computer from the internet (unplug your cable)
-> Disable Antivirus
-> Disable Firewall
-> Run Look2Me-Destroyder
Then
-> Restart you computer
-> Enable Firewall
-> Enable Antivirus
-> Plug your internet cable back
->Post a fresh HijackThis log and Ewido's log and logs from c:\windelf.txt and C:\Look2Me-Destroyer.txt to here so we can see if you computer is now clean. :)