PC Review


Reply
Thread Tools Rate Thread

Numerous virus issues

 
 
FJDx
Guest
Posts: n/a
 
      23rd May 2004
I have downloaded AVG anti virus and it detected the backdoor virus so
removed the system32.exe file. Now on reboot I get an error message
saying it cannot find the system.exe file. I did not see anything
linking to it in either
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run or
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run.
However, in the latter, I did find a %systemroot%\system32\dumprep 0 -k
but I read this was just an office system file (?).

Also, the report from AVG said that it could not access the following
files:

C:\Documents and Settings\All Users\Application
Data\Microsoft\NETWORK\Downloader\QMGR0.DAT Cannot open; not checked!
C:\Documents and Settings\All Users\Application
Data\Microsoft\NETWORK\Downloader\QMGR1.DAT Cannot open; not checked!
C:\Documents and Settings\LocalService\NTUSER.DAT Cannot open; not
checked!
C:\Documents and Settings\LocalService\NTUSER.DAT.LOG Cannot open; not
checked!
C:\Documents and Settings\LocalService\Local Settings\Application
Data\Microsoft\WINDOWS\USRCLASS.DAT Cannot open; not checked!
C:\Documents and Settings\LocalService\Local Settings\Application
Data\Microsoft\WINDOWS\UsrClass.dat.LOG Cannot open; not checked!
C:\Documents and Settings\NetworkService\NTUSER.DAT Cannot open; not
checked!
C:\Documents and Settings\NetworkService\NTUSER.DAT.LOG Cannot open; not
checked!
C:\Documents and Settings\NetworkService\Local Settings\Application
Data\Microsoft\WINDOWS\USRCLASS.DAT Cannot open; not checked!
C:\Documents and Settings\NetworkService\Local Settings\Application
Data\Microsoft\WINDOWS\UsrClass.dat.LOG Cannot open; not checked!
C:\Documents and Settings\xxx\NTUSER.DAT Cannot open; not checked!
C:\Documents and Settings\xxx\NTUSER.DAT.LOG Cannot open; not checked!
C:\Documents and Settings\xxx\Application Data\Kazaa
Lite\DB\DATA1024.DBB Cannot open; not checked!
C:\Documents and Settings\xxx\Application Data\Kazaa Lite\DB\DATA256.DBB
Cannot open; not checked!
C:\Documents and Settings\xxx\Local Settings\Application
Data\Microsoft\WINDOWS\USRCLASS.DAT Cannot open; not checked!
C:\Documents and Settings\xxx\Local Settings\Application
Data\Microsoft\WINDOWS\UsrClass.dat.LOG Cannot open; not checked!
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM.LOG Cannot open; not checked!

I did not have System Restore activated at the time of scan. I have
Windows XP Home and Office 2002.

Help - not very computer savvy and cannot make sense of all of this!


 
Reply With Quote
 
 
 
 
Rick \Nutcase\ Rogers
Guest
Posts: n/a
 
      23rd May 2004
Hi,

Look for a registry string referencing it here:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg

--
Best of Luck,

Rick Rogers aka "Nutcase" MS-MVP - Windows
Windows isn't rocket science! That's my other hobby!
http://mvp.support.microsoft.com/
Associate Expert - WinXP - Expert Zone
www.microsoft.com/windowsxp/expertzone
Win98 Help - www.rickrogers.org

"FJDx" <(E-Mail Removed)> wrote in message
news:c8q5b0$6ie$(E-Mail Removed)...
>I have downloaded AVG anti virus and it detected the backdoor virus so
> removed the system32.exe file. Now on reboot I get an error message
> saying it cannot find the system.exe file. I did not see anything
> linking to it in either
> HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run or
> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run.
> However, in the latter, I did find a %systemroot%\system32\dumprep 0 -k
> but I read this was just an office system file (?).
>
> Also, the report from AVG said that it could not access the following
> files:
>
> C:\Documents and Settings\All Users\Application
> Data\Microsoft\NETWORK\Downloader\QMGR0.DAT Cannot open; not checked!
> C:\Documents and Settings\All Users\Application
> Data\Microsoft\NETWORK\Downloader\QMGR1.DAT Cannot open; not checked!
> C:\Documents and Settings\LocalService\NTUSER.DAT Cannot open; not
> checked!
> C:\Documents and Settings\LocalService\NTUSER.DAT.LOG Cannot open; not
> checked!
> C:\Documents and Settings\LocalService\Local Settings\Application
> Data\Microsoft\WINDOWS\USRCLASS.DAT Cannot open; not checked!
> C:\Documents and Settings\LocalService\Local Settings\Application
> Data\Microsoft\WINDOWS\UsrClass.dat.LOG Cannot open; not checked!
> C:\Documents and Settings\NetworkService\NTUSER.DAT Cannot open; not
> checked!
> C:\Documents and Settings\NetworkService\NTUSER.DAT.LOG Cannot open; not
> checked!
> C:\Documents and Settings\NetworkService\Local Settings\Application
> Data\Microsoft\WINDOWS\USRCLASS.DAT Cannot open; not checked!
> C:\Documents and Settings\NetworkService\Local Settings\Application
> Data\Microsoft\WINDOWS\UsrClass.dat.LOG Cannot open; not checked!
> C:\Documents and Settings\xxx\NTUSER.DAT Cannot open; not checked!
> C:\Documents and Settings\xxx\NTUSER.DAT.LOG Cannot open; not checked!
> C:\Documents and Settings\xxx\Application Data\Kazaa
> Lite\DB\DATA1024.DBB Cannot open; not checked!
> C:\Documents and Settings\xxx\Application Data\Kazaa Lite\DB\DATA256.DBB
> Cannot open; not checked!
> C:\Documents and Settings\xxx\Local Settings\Application
> Data\Microsoft\WINDOWS\USRCLASS.DAT Cannot open; not checked!
> C:\Documents and Settings\xxx\Local Settings\Application
> Data\Microsoft\WINDOWS\UsrClass.dat.LOG Cannot open; not checked!
> C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM.LOG Cannot open; not checked!
>
> I did not have System Restore activated at the time of scan. I have
> Windows XP Home and Office 2002.
>
> Help - not very computer savvy and cannot make sense of all of this!
>
>



 
Reply With Quote
 
 
 
 
FJDx
Guest
Posts: n/a
 
      23rd May 2004
"Rick "Nutcase" Rogers" <(E-Mail Removed)> wrote in message
news:(E-Mail Removed)...
> Hi,
>
> Look for a registry string referencing it here:
>
> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg


Hi, there was nothign referring to it in there either.


 
Reply With Quote
 
Ramesh [MVP]
Guest
Posts: n/a
 
      23rd May 2004
Hi,

You may try this VBS from MVP Doug Knox.

Clean KWBot Worm Registry and File Remnants:
http://www.dougknox.com/xp/scripts_d...lean_kwbot.htm

In addition, download Autoruns utility to manage your startup effectively:
http://www.spychecker.com/program/autoruns.html

--
Ramesh - Microsoft MVP
Windows XP Shell
http://www.mvps.org/sramesh2k

The Antivirus Defense-in-Depth Guide
http://go.microsoft.com/fwlink/?LinkId=28734

"FJDx" <(E-Mail Removed)> wrote in message news:c8qa5j$gbt$(E-Mail Removed)...
"Rick "Nutcase" Rogers" <(E-Mail Removed)> wrote in message
news:(E-Mail Removed)...
> Hi,
>
> Look for a registry string referencing it here:
>
> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg


Hi, there was nothign referring to it in there either.


 
Reply With Quote
 
 
 
Reply

Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Re: Use this important VIRUS ALERT - VIRUS ALERT - W32.Swen.A@mm Worm - VIRUS ALERT - VIRUS ALERT - VIRUS ALERT - VIRUS ALERT nemo Microsoft VC .NET 0 3rd Nov 2003 09:34 PM
Re: See update - VIRUS ALERT - VIRUS ALERT - W32.Swen.A@mm Worm - VIRUS ALERT - VIRUS ALERT - VIRUS ALERT - VIRUS ALERT nemo Microsoft Dot NET Framework 0 12th Oct 2003 01:29 PM
Re: See update - VIRUS ALERT - VIRUS ALERT - W32.Swen.A@mm Worm - VIRUS ALERT - VIRUS ALERT - VIRUS ALERT - VIRUS ALERT nemo Microsoft Outlook Contacts 0 12th Oct 2003 01:29 PM
Re: See update - VIRUS ALERT - VIRUS ALERT - W32.Swen.A@mm Worm - VIRUS ALERT - VIRUS ALERT - VIRUS ALERT - VIRUS ALERT nemo Windows XP Print / Fax 0 12th Oct 2003 01:29 PM
Re: See update - VIRUS ALERT - VIRUS ALERT - W32.Swen.A@mm Worm - VIRUS ALERT - VIRUS ALERT - VIRUS ALERT - VIRUS ALERT nemo Windows XP Photos 0 12th Oct 2003 01:29 PM


Features
 

Advertising
 

Newsgroups
 


All times are GMT +1. The time now is 08:25 AM.