General Car Related Discussion. To discuss anything that is related to cars and automotive technology that doesnt naturally fit into another forum catagory.

xrt-si, read this post !!!!!!

Thread Tools
 
Search this Thread
 
Old 04-05-2005, 11:52 AM
  #1  
Ginge !
just finding my feet
Thread Starter
 
Ginge !'s Avatar
 
Join Date: May 2003
Location: Im behind you
Posts: 41,046
Likes: 0
Received 1 Like on 1 Post
Default xrt-si, read this post !!!!!!

the aplication keeps opening up, ive got about 30 ipconfig.exe's in the task manager and its filling the pressesor usage up to 100% and the more i close em down it still keep opening em up and me pc is running very very slow

who can help me solve the issue, it might not be a ipconfig issue but thats the program that keeps opening up and its still doing it
Old 04-05-2005, 11:53 AM
  #2  
Stu.H
10K+ Poster!!
 
Stu.H's Avatar
 
Join Date: May 2003
Location: Brierley Hill
Posts: 11,973
Received 0 Likes on 0 Posts
Default

sounds like some sort of virus mate.

REINSTALL
Old 04-05-2005, 11:55 AM
  #3  
JohnnyB
PassionFord Post Whore!!
 
JohnnyB's Avatar
 
Join Date: May 2003
Location: Derby
Posts: 8,594
Likes: 0
Received 2 Likes on 2 Posts
Default

you have a virus, you must have

Ipconfig is used to see what IP address and Gatway etc. Even is you put it in the startup menu it would only run once.

Virus
Old 04-05-2005, 11:58 AM
  #4  
Ginge !
just finding my feet
Thread Starter
 
Ginge !'s Avatar
 
Join Date: May 2003
Location: Im behind you
Posts: 41,046
Likes: 0
Received 1 Like on 1 Post
Default

i cant find a virus though ????

help me please

if i write all the programs that appear in the task manager then can ya tell me if there ment to be there
Old 04-05-2005, 12:03 PM
  #5  
Ginge !
just finding my feet
Thread Starter
 
Ginge !'s Avatar
 
Join Date: May 2003
Location: Im behind you
Posts: 41,046
Likes: 0
Received 1 Like on 1 Post
Default

i canceled a binkara.exe program and seems to have closed the ipconfig.exe programs

does that sound like a virus and why couldnt my anti virus find the fooking thing
Old 04-05-2005, 12:09 PM
  #6  
AndyBlackFRST
Advanced PassionFord User
 
AndyBlackFRST's Avatar
 
Join Date: Jul 2003
Location: UK
Posts: 1,716
Likes: 0
Received 0 Likes on 0 Posts
Default

Sounds like spyware / adware loaded onto your machine.

There is one that replaces the mplayer32.exe so that when you try and run it, it executes another app and spreads more.

Can't find anything about that binkara.exe anywhere though.

Run adware, spybot and 'hijack this'
Old 04-05-2005, 12:18 PM
  #7  
AndyBlackFRST
Advanced PassionFord User
 
AndyBlackFRST's Avatar
 
Join Date: Jul 2003
Location: UK
Posts: 1,716
Likes: 0
Received 0 Likes on 0 Posts
Default

Just looking around this seems to be your problem..

filename is as follows: c:\windows\prefetch\ipconfig.exe-2395f30b.pf

So in task manager it looks like the legit ipconfig.exe, but is actually loading the program to download more ads etc onto your pc
Old 04-05-2005, 12:33 PM
  #8  
Jim Galbally
20K+ Super Poster.
 
Jim Galbally's Avatar
 
Join Date: May 2003
Location: Ramsgate, Kent Drives: E39 530D Touring
Posts: 20,599
Likes: 0
Received 0 Likes on 0 Posts
Default

stop downloading shit ginge
Old 04-05-2005, 12:43 PM
  #9  
Ginge !
just finding my feet
Thread Starter
 
Ginge !'s Avatar
 
Join Date: May 2003
Location: Im behind you
Posts: 41,046
Likes: 0
Received 1 Like on 1 Post
Default

jim i dont download anything

pc is fine since i closed the blankara or binkari.exe program

im running hitman pro now and gonna run another antivirus program and see what happens
Old 04-05-2005, 12:45 PM
  #10  
Jim Galbally
20K+ Super Poster.
 
Jim Galbally's Avatar
 
Join Date: May 2003
Location: Ramsgate, Kent Drives: E39 530D Touring
Posts: 20,599
Likes: 0
Received 0 Likes on 0 Posts
Default

with the antivirus, make sure you update the thing 1st.... its a mistake a lot of people use running visus definitions 6 months+ old!
Old 04-05-2005, 12:50 PM
  #11  
AndyBlackFRST
Advanced PassionFord User
 
AndyBlackFRST's Avatar
 
Join Date: Jul 2003
Location: UK
Posts: 1,716
Likes: 0
Received 0 Likes on 0 Posts
Default

It doesn't look to be a virus, so it prob won't show up.

More than likely the apps your closed are set in the registry to run at startup.

Rub 'Hijack This' and post a report.. will be able to tell then
Old 04-05-2005, 12:56 PM
  #12  
Ginge !
just finding my feet
Thread Starter
 
Ginge !'s Avatar
 
Join Date: May 2003
Location: Im behind you
Posts: 41,046
Likes: 0
Received 1 Like on 1 Post
Default

whats hijack this ????

ya got a link as im not pc person

oh and jim im not totally stupid , i got me antivirus set to run every night at 3am adn that checks for updates automaticly

just for the last 4 days its been really slow so today i figured it was time to see and the ipconfig was all over the taks manager and so i kept closing em and thought all was ok till i realised it was opening em more
Old 04-05-2005, 01:03 PM
  #13  
Ginge !
just finding my feet
Thread Starter
 
Ginge !'s Avatar
 
Join Date: May 2003
Location: Im behind you
Posts: 41,046
Likes: 0
Received 1 Like on 1 Post
Default

this is the result , im confused about all of this so if ya can take the time to help id like it


Logfile of HijackThis v1.99.1
Scan saved at 1:57:57 PM, on 5/4/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Hitman Pro\hitmanpro2.exe
C:\Program Files\Hitman Pro\srhelper.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\Documents and Settings\Dan\Local Settings\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://passionford.com/forum/index....5b94d0c35615a2
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [C-Media Echo Control] C:\Program Files\PCI Audio Applications\Bin\EchoCtrl.exe
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [MSN service] mslima.exe
O4 - HKLM\..\Run: [NT Logging Service] syslog32.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [op3T36l] seron32.exe
O4 - HKLM\..\Run: [JAVA UPDATER DLL] javaupdate.exe
O4 - HKLM\..\Run: [WINRUN] taskgmr.exe
O4 - HKLM\..\Run: [WINRUN z] W1NT45K.exe
O4 - HKLM\..\Run: [A New Windows Updater] w32NTupdt.exe
O4 - HKLM\..\Run: [NDdehsetdapter] wow123.exe
O4 - HKLM\..\Run: [A N3w Windows Updater] w32NTupt.exe
O4 - HKLM\..\Run: [WIn32 Java DLLx] srtsr32.exe
O4 - HKLM\..\Run: [Windows 32Bit Fixer] bilankara.exe
O4 - HKLM\..\RunServices: [MSN service] mslima.exe
O4 - HKLM\..\RunServices: [Video Process] yejpnjd.exe
O4 - HKLM\..\RunServices: [WINRUN z] W1NT45K.exe
O4 - HKLM\..\RunServices: [A New Windows Updater] w32NTupdt.exe
O4 - HKLM\..\RunServices: [NDdehsetdapter] wow123.exe
O4 - HKLM\..\RunServices: [A N3w Windows Updater] w32NTupt.exe
O4 - HKLM\..\RunServices: [WIn32 Java DLLx] srtsr32.exe
O4 - HKLM\..\RunServices: [Windows 32Bit Fixer] bilankara.exe
O4 - HKLM\..\RunOnce: [Windows 32Bit Fixer] bilankara.exe
O4 - HKLM\..\RunOnce: [NDdehsetdapter] wow123.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Windows 32Bit Fixer] bilankara.exe
O4 - HKCU\..\Run: [ZEs3RWJ7i] mindexts.exe
O4 - HKCU\..\Run: [Hitman Pro SurfRight Helper] "C:\Program Files\Hitman Pro\srhelper.exe"
O4 - HKCU\..\Run: [WINRUN] taskgmr.exe
O4 - HKCU\..\Run: [WINRUN z] W1NT45K.exe
O4 - HKCU\..\Run: [A New Windows Updater] w32NTupdt.exe
O4 - HKCU\..\Run: [NDdehsetdapter] wow123.exe
O4 - HKCU\..\Run: [A N3w Windows Updater] w32NTupt.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\RunOnce: [NDdehsetdapter] wow123.exe
O4 - HKCU\..\RunOnce: [Windows 32Bit Fixer] bilankara.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O15 - Trusted Zone: http://ny.contentmatch.net (HKLM)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.co...?1108498775077
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/S.../bin/cabsa.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/Ms...Downloader.cab
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: NT login service (ntlogin32) - Unknown owner - C:\WINDOWS\System32\libsysmgr.exe (file missing)
O23 - Service: SpywareCleanerService - Unknown owner - C:\Program Files\Spyware Cleaner\SCService.exe (file missing)


ya see its got that blinkara thingy on it
Old 04-05-2005, 02:05 PM
  #14  
Ginge !
just finding my feet
Thread Starter
 
Ginge !'s Avatar
 
Join Date: May 2003
Location: Im behind you
Posts: 41,046
Likes: 0
Received 1 Like on 1 Post
Default

come on peeps, help me out please
Old 04-05-2005, 02:10 PM
  #15  
Jim Galbally
20K+ Super Poster.
 
Jim Galbally's Avatar
 
Join Date: May 2003
Location: Ramsgate, Kent Drives: E39 530D Touring
Posts: 20,599
Likes: 0
Received 0 Likes on 0 Posts
Default

i got me antivirus set to run every night at 3am and that checks for updates automaticly
you realise you gotta have the pc switched on for it to work....


...don't you?


Old 04-05-2005, 02:19 PM
  #16  
CabrioTurbo
PassionFord Post Troll
 
CabrioTurbo's Avatar
 
Join Date: May 2003
Location: Nr Crewe, Cheshire
Posts: 3,225
Likes: 0
Received 0 Likes on 0 Posts
Default

right this is difinately a virus i had the same thing.. but i cant for the life of me think what it was called!
I will have a quick look on the symantec site and try and remember!
CheeRs
Phil
Old 04-05-2005, 02:20 PM
  #17  
Ginge !
just finding my feet
Thread Starter
 
Ginge !'s Avatar
 
Join Date: May 2003
Location: Im behind you
Posts: 41,046
Likes: 0
Received 1 Like on 1 Post
Default

i cant get access to te symantec site , i tried


jim my pc is never off as i hate waiting for it to load up
Old 04-05-2005, 02:21 PM
  #18  
Ginge !
just finding my feet
Thread Starter
 
Ginge !'s Avatar
 
Join Date: May 2003
Location: Im behind you
Posts: 41,046
Likes: 0
Received 1 Like on 1 Post
Default

anyone fancy looking at the log report and telling me what to scrap
Old 04-05-2005, 02:36 PM
  #20  
Ginge !
just finding my feet
Thread Starter
 
Ginge !'s Avatar
 
Join Date: May 2003
Location: Im behind you
Posts: 41,046
Likes: 0
Received 1 Like on 1 Post
Default

rudey thats too much like hard work, cant i just wipe the virus
Old 04-05-2005, 03:26 PM
  #21  
cossiechris
I'm Finding My Feet Here Now
 
cossiechris's Avatar
 
Join Date: Jul 2003
Location: Merseyside
Posts: 146
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by b19bal
this is the result , im confused about all of this so if ya can take the time to help id like it
ya see its got that blinkara thingy on it
Quick look at your log shows the following fella !

O4 - HKLM\..\Run: [WINRUN] taskgmr.exe

Variant of W32.Mytob.R@mm Virus.

O4 - HKLM\..\Run: [WINRUN z] W1NT45K.exe

Another variant of W32.Mytob.R@mm Virus.

O4 - HKLM\..\Run: [A New Windows Updater] w32NTupdt.exe

Another variant of W32.Mytob.BM@mm

O4 - HKLM\..\Run: [NDdehsetdapter] wow123.exe

Unsure, probably randomly generated filename for the MYTOB virus

O4 - HKLM\..\Run: [A N3w Windows Updater] w32NTupt.exe

another variant of the MYBTOB virus

O4 - HKLM\..\Run: [WIn32 Java DLLx] srtsr32.exe

Unsure, probably randomly generated filename for the MYTOB virus

O4 - HKLM\..\Run: [Windows 32Bit Fixer] bilankara.exe

Unsure, probably randomly generated filename for the MYTOB virus

O4 - HKLM\..\RunServices: [MSN service] mslima.exe

Spyware/malaware REMOVE

O4 - HKLM\..\RunServices: [Video Process] yejpnjd.exe

Unsure, probably randomly generated filename for the MYTOB virus

O4 - HKLM\..\RunServices: [WINRUN z] W1NT45K.exe

Variant of the W32.Mytob.BL@mm virus

O4 - HKLM\..\RunServices: [A New Windows Updater] w32NTupdt.exe

Variant of the W32.Mytob.BL@mm virus

O4 - HKLM\..\RunServices: [NDdehsetdapter] wow123.exe

Unsure, probably randomly generated filename for the MYTOB virus

O4 - HKLM\..\RunServices: [A N3w Windows Updater] w32NTupt.exe

Variant of the W32.Mytob.BL@mm virus

O4 - HKLM\..\RunServices: [WIn32 Java DLLx] srtsr32.exe

Unsure, probably randomly generated filename for the MYTOB virus

O4 - HKLM\..\RunServices: [Windows 32Bit Fixer] bilankara.exe

Unsure, probably randomly generated filename for the MYTOB virus

O4 - HKLM\..\RunOnce: [Windows 32Bit Fixer] bilankara.exe

Unsure, probably randomly generated filename for the MYTOB virus

O4 - HKLM\..\RunOnce: [NDdehsetdapter] wow123.exe

Unsure, probably randomly generated filename for the MYTOB virus

O4 - HKCU\..\Run: [Windows 32Bit Fixer] bilankara.exe

Unsure, probably randomly generated filename for the MYTOB virus

O4 - HKCU\..\Run: [ZEs3RWJ7i] mindexts.exe

Unsure, probably randomly generated filename for the MYTOB virus

O4 - HKCU\..\Run: [WINRUN] taskgmr.exe

Variant of W32.Mytob.R@mm Virus.

O4 - HKCU\..\Run: [WINRUN z] W1NT45K.exe

Unsure, probably randomly generated filename for the MYTOB virus

O4 - HKCU\..\Run: [A New Windows Updater] w32NTupdt.exe

Unsure, probably randomly generated filename for the MYTOB virus

O4 - HKCU\..\Run: [NDdehsetdapter] wow123.exe

Unsure, probably randomly generated filename for the MYTOB virus

O4 - HKCU\..\Run: [A N3w Windows Updater] w32NTupt.exe

Unsure, probably randomly generated filename for the MYTOB virus

O4 - HKCU\..\RunOnce: [NDdehsetdapter] wow123.exe

Unsure, probably randomly generated filename for the MYTOB virus

O4 - HKCU\..\RunOnce: [Windows 32Bit Fixer] bilankara.exe

Unsure, probably randomly generated filename for the MYTOB virus


O23 - Service: NT login service (ntlogin32) - Unknown owner - C:\WINDOWS\System32\libsysmgr.exe (file missing)

SDBot Worm. Remove this entry.

I would say you have the MYTOB Virus !

Here’s how to remove it…. Use this removal tool.
http://securityresponse.symantec.com...oval.tool.html

First turn off system restore (if you have ME or XP)
http://service1.symantec.com/SUPPORT...rc=sec_doc_nam

Follow the instructions on the above page and then turn System Restore back on. It’s actually not as bad as it looks as I can only see one infection, just a lot of variants of it !

Enjoy.………….. sort of !
Old 04-05-2005, 03:35 PM
  #22  
Ginge !
just finding my feet
Thread Starter
 
Ginge !'s Avatar
 
Join Date: May 2003
Location: Im behind you
Posts: 41,046
Likes: 0
Received 1 Like on 1 Post
Default

okmwhat does the mytob virus do

cheers for taking the time to reead all through it and tell me what to do
Old 04-05-2005, 03:44 PM
  #23  
cossiechris
I'm Finding My Feet Here Now
 
cossiechris's Avatar
 
Join Date: Jul 2003
Location: Merseyside
Posts: 146
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by b19bal
okmwhat does the mytob virus do

cheers for taking the time to reead all through it and tell me what to do
PM'd ya fella

Any time
Old 05-05-2005, 03:54 PM
  #24  
Ginge !
just finding my feet
Thread Starter
 
Ginge !'s Avatar
 
Join Date: May 2003
Location: Im behind you
Posts: 41,046
Likes: 0
Received 1 Like on 1 Post
Default

FAO:xrt-si
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
The Youth.
General Car Related Discussion.
11
11-09-2015 05:38 PM
sunburstred
Cars & Parts Wanted.
0
09-09-2015 11:24 PM
stevierob
Technical help Q & A
2
07-09-2015 07:09 PM
Adam Graham
Restorations, Rebuilds & Projects.
7
06-09-2015 06:04 AM



Quick Reply: xrt-si, read this post !!!!!!



All times are GMT. The time now is 06:04 AM.