Just got a bad virus.. need some advice [HJT Log]

Discussion in 'Windows - Virus and spyware problems' started by Cill, Aug 20, 2008.

  1. Cill

    Cill Guest

    Hi there. I literally just got this bad virus.

    It crashes every application with a critical error as soon as I try to open them.

    It changed my background to a blue screen telling me I have a virus

    It won't let me install any programs by telling me "The Systems Administrator has set policies to prevent this installation"

    Random critical application errors. One regular critical error happens to mdm.exe and I don't know what that is.

    Blue Screen of Death, giving an error with the driver BOGUS_DRIVER. I assume something the virus created.

    Mind you also, this is all in safe mode (apart from background).

    This is all I've noticed so far.

    Here is the Hijack This log I did 10 minutes ago,


    Thanks everyone.
     
    Last edited by a moderator: Aug 20, 2008
  2. kingy1213

    kingy1213 Regular member

    Joined:
    Jul 26, 2007
    Messages:
    109
    Likes Received:
    0
    Trophy Points:
    26
    ok this is the 1's i would delete

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.bearshare.com/au/

    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\ntos.exe, VERY BAD

    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

    O3 - Toolbar: (no name) - {37B85A29-692B-4205-9CAD-2626E4993404} - (no file)

    O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)

    O4 - HKLM\..\Run: [microsoft windows updaters] WINUPDATERS.EXE

    O4 - HKLM\..\Run: [lphcteoj0ee5a] C:\WINDOWS\system32\lphcteoj0ee5a.exe

    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)

    O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Jason Orr\Start Menu\Programs\IMVU\Run IMVU.lnk (file missing)

    O16 - DPF: {3D3BF1F8-9696-4A5E-B4F1-49101C997B70} (VaxSIPUserAgentCAB Control) - http://www.earthcaller.com/VaxSIPUserAgentCAB.cab

    O23 - Service: EasyVoipRecorder - Unknown owner - C:\Program Files\EasyVoipRecorder\EasyVoipRecorderService.exe

    do u have a anti-virus software?
     

Share This Page