• Some users have recently had their accounts hijacked. It seems that the now defunct EVGA forums might have compromised your password there and seems many are using the same PW here. We would suggest you UPDATE YOUR PASSWORD and TURN ON 2FA for your account here to further secure it. None of the compromised accounts had 2FA turned on.
    Once you have enabled 2FA, your account will be updated soon to show a badge, letting other members know that you use 2FA to protect your account. This should be beneficial for everyone that uses FSFT.

viruses that installs from internet?

oqvist

[H]F Junkie
Joined
Dec 24, 2001
Messages
8,936
I get viruses and worms that just has to be specifically targeted at my IP. Because I just reformatted my harddrive and installed windows XP on a of course clean windows XP PRO cd and from the start the first time I opened Internet explorer there was a toolbar there.

Download all security updates ms antispyware and AVG antivirus and Spybot all find different stuff and there is literally tons of them!!! On a clean win xp reinstall!!

You let them erase them but they are back on the next reboot. If I don´t connect to the internet I get less but as soon I connect all 10 of them is there!

I have winmode.exe infected ntfssys.exe or something similar etc which I don´t know if they are vital? Running firewalls don´t help a bit. MS antispyware do warn but can´t stop anything. Get pop ups all the time. even with no web browser open.

I can´t see how I am be supposed to be able to stop these attacks since I have a static IP and can´t change it.

There is elite toolbar, alexa, IRC/backdoor sdbot 145 and many many more.

Also I am a bit worried about the ntfsfat or ntfssys file? I have got problems with stuttering while gaming and suspect this may be the reason? However I have also got issues with my 6800 ULTRA that says it don´t get enough current so...
 
Oh and I have a netstat.exe that I can´t get rid of. I search and delete it and it comes back within minutes.
 
hijackthislog

Logfile of HijackThis v1.99.1
Scan saved at 19:21:46, on 2005-03-07
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\Explorer.EXE
D:\WINDOWS\system32\spoolsv.exe
D:\WINDOWS\System32\MSWSCK32.exe
D:\WINDOWS\System32\MSWTASK32.exe
D:\Program\Microsoft AntiSpyware\gcasServ.exe
D:\WINDOWS\System32\winmgr.exe
D:\Program\Grisoft\AVGFRE~1\avgcc.exe
D:\Program\Grisoft\AVGFRE~1\avgemc.exe
D:\WINDOWS\System32\RUNDLL32.EXE
D:\WINDOWS\System32\ctfmon.exe
D:\Program\Messenger\msmsgs.exe
D:\WINDOWS\System32\MSWSCK32.exe
D:\WINDOWS\System32\MSWTASK32.exe
D:\Program\Microsoft AntiSpyware\gcasDtServ.exe
D:\Program\Grisoft\AVGFRE~1\avgamsvr.exe
D:\Program\Grisoft\AVGFRE~1\avgupsvc.exe
D:\WINDOWS\System32\nvsvc32.exe
D:\PROGRAM\MOZILL~1\FIREFOX.EXE
D:\Documents and Settings\Pär Öqvist\Lokala inställningar\Temp\Temporär katalog 1 för hijackthis.zip\HijackThis.exe
D:\Program\Grisoft\AVGFRE~1\avgwb.dat
c:\NETSTAT.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.rixmail.se/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.rixmail.se/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Länkar
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\Program\Spybot - Search & Destroy\SDHelper.dll
O4 - HKLM\..\Run: [Microsoft Winsocks 32 Controller] MSWSCK32.exe
O4 - HKLM\..\Run: [Win Update Microsoft] winmode.exe
O4 - HKLM\..\Run: [MS Windows TASK Service] MSWTASK32.exe
O4 - HKLM\..\Run: [gcasServ] "D:\Program\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [Windows Time] winmgr.exe
O4 - HKLM\..\Run: [AVG7_CC] D:\Program\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] D:\Program\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE D:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\RunServices: [Microsoft Winsocks 32 Controller] MSWSCK32.exe
O4 - HKLM\..\RunServices: [Win Update Microsoft] winmode.exe
O4 - HKLM\..\RunServices: [NTFSSAPI] ntfsapi.exe
O4 - HKLM\..\RunServices: [MS Windows TASK Service] MSWTASK32.exe
O4 - HKLM\..\RunServices: [Windows Time] winmgr.exe
O4 - HKCU\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "D:\Program\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Microsoft Winsocks 32 Controller] MSWSCK32.exe
O4 - HKCU\..\Run: [MS Windows TASK Service] MSWTASK32.exe
O4 - HKCU\..\Run: [Windows Time] winmgr.exe
O4 - HKCU\..\Run: [Win Update Microsoft] winmode.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - D:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - D:\WINDOWS\web\related.htm
O15 - ProtocolDefaults: 'http' protocol is in My Computer Zone, should be Internet Zone
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.c...ls/en/x86/client/wuweb_site.cab?1110203364219
O17 - HKLM\System\CCS\Services\Tcpip\..\{C4B9EA8F-C685-4143-8035-0F46E475C6B8}: Domain = 43178
O17 - HKLM\System\CCS\Services\Tcpip\..\{C4B9EA8F-C685-4143-8035-0F46E475C6B8}: NameServer = 81.8.223.2,81.8.223.3
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - D:\Program\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - D:\Program\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - D:\WINDOWS\System32\nvsvc32.exe

ntfsapi is in there but it doesn´t show up as infected anymore by AVG.
 
Only way for you to get infected like this is if you're on a public IP with no firewall enabled on an unpatched windows install.

What I would do is reinstall XP, leave your network cable unplugged, and then turn on the windows firewall for your NIC. Plug your cable back in then proceed to do all the upgrades/service packs.

A second option would be to get a router and put your computer behind that, as outside computers won't be able to connect directly to your machine.
 
Just shooting in the dark here - stuff could be installed on another drive/partition that you aren't formatting. You could also zero fill the drive before re-installing.
 
Well I have a C partition that I only have the swap file on. But really disconnect from internet and I am fine. Connect to internet firewall or not I am helpless :/

I have a switch but that won´t help I need a router I guess.

But if I can get hold of say service pack 1a (2.0 just doesn´t work on my computer) I wouldn´t be able to be hijacked after that? Or since they already know my IP it maybe doesn´t matter?

Anyway it´s a bit better know after getting rid of internet explorer. Now AVG/SPYBOT and MS antispyware don´t find any more viruses however the netstat thingie still installs and gives me pop up commercials.

In the registry where should I look to remove entries?
 
oqvist said:
Well I have a C partition that I only have the swap file on. But really disconnect from internet and I am fine. Connect to internet firewall or not I am helpless :/

I have a switch but that won´t help I need a router I guess.

But if I can get hold of say service pack 1a (2.0 just doesn´t work on my computer) I wouldn´t be able to be hijacked after that? Or since they already know my IP it maybe doesn´t matter?

Anyway it´s a bit better know after getting rid of internet explorer. Now AVG/SPYBOT and MS antispyware don´t find any more viruses however the netstat thingie still installs and gives me pop up commercials.

In the registry where should I look to remove entries?

I highly doubt anyone is intentionally targeting your computer. It's most likely other virus infested computers scanning large ranges of IP's and trying to infect them as well. If you have a firewall that logs these types of requests you'd see random IP's trying to connect to certain TCP ports all the time.

Have you tried SP2 on a fresh install of windows? There should be no reason why it won't work on your new system unless it's already jacked up with spyware.

I'd burn both SP1 and SP2 & MS antispyware to CD. Reinstall your OS without the network cable plugged in, install a SP & MS AS, enable the firewall and go on.

The firewall will protect you from exploits against known microsoft remote vulnerabilities whether you think it will or not.

You can probably get rid of that netstat spyware by going into MS antispyware and selecting Advanced Tools->System Explorers->Startup programs. Disable all the entries you don't recognize and CUT THE POWER to your computer. Do not go through the normal shutdown process as some spyware will try to activate itself again when the system shuts down.
 
Okey thanks a lot :)

that nettask stuff the pop up closes when closing that but there is obviously another file that installs it over and over again.

Does anyone recognize the MSwsck32 and mswtask32.exe files? Is those part of the MS antispyware package?

winmgr.exe?
 
Aah I installed Adaware and it erased another 20 entries and seem like it´s finally gone :)
 
Aah I installed Adaware and it erased another 20 entries and seem like it´s finally gone :)

I have never had so much junk on my computer before not even when have it running for like a year without reformatting. I have recently discovered DC does that open a lot of ports?

edit: not gone
 
You could burn a cd with XP2, antivirus software, patches, spyware software, etc. Then unplug your computer from the network. Then reinstall, after reinstalling just load everything from the cd that you burned with sp2, drivers, antivirus programs, etc.....or you could slipstream SP2...Then plug back your network..
 
Yeah seem like that is the only way to go.

Anyway I have wanted to try windows XP 64 now seem to be the perfect time.
 
you know i just had the same problem, i formatted my laptop connected to my schools wifi network and already got spyware.

When you format, make sure you turn off Messenger right away b4 plugging in the network. If its a sp2 cd you should be fine.

Right click on My Computer > Manage > Services and just disable messenger.

I suggest just formatting again if you already have just dont that should be much harder, another 30min and u should be set :)
 
Yeah though windows XP 64 beta should be as safe as SP 2 hopefully :).

Anyway I tried another computer got the exact same thing immediately so it´s definiatly something that is coming over the internet.

I am wondering if me being connected to DC people will try to contact me even when I am not on-line and thus I am more vulnerable?
 
Buy a hardware firewall. Put it in between you and the Internet. Make sure it can perform Stateful Packet Inspection.

You should still lock down your machine after reformatting and reinstalling Winderz. You should still run anti-virus software. You should still be wary of web sites and run a web browser that has less potential of being hacked.
 
Yep looks like those bastards can´t touch windows XP 64 :). Seem promising otherwise also can´t believe how fast things loads all suddenly :)
 
Back
Top