Photobucket Virus?
Moderator: Moderators
-
- Fourth Gear
- Posts: 2045
- Joined: Tue Nov 28, 2006 8:17 am
- Location: Spokane, WA
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-02-22 00:37:05
Windows 5.1.2600 Service Pack 2
Running: 07pz6rni.exe; Driver: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\axxoapog.sys
---- Kernel code sections - GMER 1.0.15 ----
? pkshbhxa.sys The system cannot find the file specified. !
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe[1888] kernel32.dll!CreateThread + 1A 7C810661 4 Bytes CALL 0316A939 C:\Program Files\Spybot - Search & Destroy\Plugins\Chai.dll
---- EOF - GMER 1.0.15 ----
Rootkit scan 2010-02-22 00:37:05
Windows 5.1.2600 Service Pack 2
Running: 07pz6rni.exe; Driver: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\axxoapog.sys
---- Kernel code sections - GMER 1.0.15 ----
? pkshbhxa.sys The system cannot find the file specified. !
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe[1888] kernel32.dll!CreateThread + 1A 7C810661 4 Bytes CALL 0316A939 C:\Program Files\Spybot - Search & Destroy\Plugins\Chai.dll
---- EOF - GMER 1.0.15 ----
1991 Subaru Legacy SS 5MT: Revtronix Stage 2 Set-up with a few other "tasteful" mods :D
I'd have to say pkshbhxa.sys, 07pz6rni.exe, and the axxoapogo.sys files are what's causing your problems.
I have never heard of either of those system files, and they do not sound legitimate. Will it physically let you find and delete those system files? or disable that 07pz6rni.exe?
Right click my computer and go to properties.
Go to hardware tab and click on device manager. Under View click view hidden devices. Go to non plug and play drivers. Look for any of those instances that log found, and disable them if possible. See if Internet access returns.
The key indication of the problem is that .sys file sitting in a temp folder. Sys files don't sit there. Can you run CCleaner and delete it? Right click on my computer and go to the restore tab. Turn off ssytem restore for the time being.
I have never heard of either of those system files, and they do not sound legitimate. Will it physically let you find and delete those system files? or disable that 07pz6rni.exe?
Right click my computer and go to properties.
Go to hardware tab and click on device manager. Under View click view hidden devices. Go to non plug and play drivers. Look for any of those instances that log found, and disable them if possible. See if Internet access returns.
The key indication of the problem is that .sys file sitting in a temp folder. Sys files don't sit there. Can you run CCleaner and delete it? Right click on my computer and go to the restore tab. Turn off ssytem restore for the time being.
1992 Legacy LS Special Wagon..
-
- Fourth Gear
- Posts: 2045
- Joined: Tue Nov 28, 2006 8:17 am
- Location: Spokane, WA
-
- Second Gear
- Posts: 502
- Joined: Fri Sep 03, 2004 3:14 am
- Location: Armpit, USA
If I were you, I would just get your files off and reinstall windows. You probably could have done it twice in the amount of time you've spent chasing this thing around, and the fix is going to be complicated. A fresh install always runs faster anyway.
Cheers,
morgan
1992 Legacy BF
1946 Ford 1.5 Ton Truck (The Beast): http://community.webshots.com/user/fishbone79
morgan
1992 Legacy BF
1946 Ford 1.5 Ton Truck (The Beast): http://community.webshots.com/user/fishbone79
the only other program I could recommend running is combofix. Or install ms recovery console (or run from disk) and delete those .sys files mentioned in the GMER report along with that exe file.
Malware has gotten very complicated. as Fishbones states if you don't want to spend anymore time, you're almost better off reinstalling windows.
Malware has gotten very complicated. as Fishbones states if you don't want to spend anymore time, you're almost better off reinstalling windows.
1992 Legacy LS Special Wagon..
-
- Fourth Gear
- Posts: 2045
- Joined: Tue Nov 28, 2006 8:17 am
- Location: Spokane, WA
-
- Fourth Gear
- Posts: 2045
- Joined: Tue Nov 28, 2006 8:17 am
- Location: Spokane, WA
-
- Fourth Gear
- Posts: 2045
- Joined: Tue Nov 28, 2006 8:17 am
- Location: Spokane, WA
hmmmm... well what do you thin would be the best way of "restoring" my computer without a recovery disc? I don't have ANY of the discs... this comp is like 8 years old, still runs good though when its not infected haha
1991 Subaru Legacy SS 5MT: Revtronix Stage 2 Set-up with a few other "tasteful" mods :D
without the disc you're pretty much hosed. You could download keyfinder and get your product key, and see if one of your friends will let you borrow their OS disc.
That or remove those files listed in the GMER report. They are more than likely the cause of your infection as stated earlier, because of their location, and oddball naming structure.
That or remove those files listed in the GMER report. They are more than likely the cause of your infection as stated earlier, because of their location, and oddball naming structure.
1992 Legacy LS Special Wagon..
-
- Fourth Gear
- Posts: 2045
- Joined: Tue Nov 28, 2006 8:17 am
- Location: Spokane, WA
-
- Fourth Gear
- Posts: 2045
- Joined: Tue Nov 28, 2006 8:17 am
- Location: Spokane, WA
-
- Fourth Gear
- Posts: 2045
- Joined: Tue Nov 28, 2006 8:17 am
- Location: Spokane, WA
-
- Fourth Gear
- Posts: 2045
- Joined: Tue Nov 28, 2006 8:17 am
- Location: Spokane, WA
Re: Photobucket Virus?
finally got my damn computer back, my friend reformatted it for me and put windows 7 on here. It should work fine until I can afford a new one!