appears AutoPlay after right click on each of Local Disks !!!!???
My PC Hell Forum
November 19, 2008, 08:33:19 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Moving to New Location Soon! Watch out for notification. 14th Dec 2007.
 
   Home   Help Search Calendar Login Register  
Pages: [1] 2 3
  Print  
Author Topic: appears AutoPlay after right click on each of Local Disks !!!!???  (Read 6766 times)
omid020
Contributor
**
Posts: 16


View Profile
« on: March 13, 2007, 12:31:59 PM »

Hi

At first on my windows SP2 startup appears an error with temp2.exe title . I always select Don`t Send and ignore it . Then when I want to open each of my Local Disks in my computer , after double clicking, selected drive will open in new window and not in same window . After right clicking on each of my disks drives appear an AutoPlay item in list menu , top of Search ... . What should I do ? please help me .
Logged
Squeezebox
Administrator
******
Posts: 2756



View Profile
« Reply #1 on: March 13, 2007, 02:32:33 PM »

Temp2.exe is most likely to be a virus (trojan). Have you scanned your system for viruses etc?

What antivirus software do you have?

You should also have a good firewall and at least one spyware detection tool. What do you have?
Logged

Essexboy
Administrator
*****
Posts: 899



View Profile WWW
« Reply #2 on: March 13, 2007, 02:39:25 PM »

Concur it is a baddie trying to phone home, the file belongs to irc.momma worm.  If you want help cleaning it

* Click here to download HJTsetup.exe
  • Save HJTsetup.exe to your desktop.
  • Doubleclick on the HJTsetup.exe icon on your desktop.
  • By default it will install to C:\Program Files\Hijack This.
  • Continue to click Next in the setup dialogue boxes until you get to the Select Addition Tasks dialogue.
  • Put a check by Create a desktop icon then click Next again.
  • Continue to follow the rest of the prompts from there.
  • At the final dialogue box click Finish and it will launch Hijack This.
  • Click on the Do a system scan and save a logfile button. It will scan and the log should open in notepad.
  • Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log.
  • Come back here to this thread and Paste the log in your next reply.
  • DO NOT have Hijack This fix anything yet. Most of what it finds will be harmless or even required.
Logged

VISTA
XPsp2
Avast (of course)



http://spaces.msn.com/members/essexboymkn/

 If ignorance is bliss  why aren't more people happy?
omid020
Contributor
**
Posts: 16


View Profile
« Reply #3 on: March 14, 2007, 09:50:45 AM »

Logfile of HijackThis v1.99.1
Scan saved at 05:18:23 ب.ظ, on 2007/03/14
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\AppServ\Apache\Apache.exe
C:\AppServ\mysql\bin\mysqld-nt.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\AppServ\Apache\Apache.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Babylon\Babylon-Pro\Babylon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\temp1.exe
C:\Program Files\ACD Systems\ImageFox\ImageFox.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Hijackthis\HijackThis.exe

F3 - REG:win.ini: load=C:\WINDOWS\svchost.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Babylon Client] C:\Program Files\Babylon\Babylon-Pro\Babylon.exe -AutoStart
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NVMCTRAY.DLL,NvTaskbarInit
O4 - Global Startup: ImageFox.lnk = ?
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: Apache - Unknown owner - C:\AppServ\Apache\Apache.exe" --ntservice (file missing)
O23 - Service: mysql - Unknown owner - C:\AppServ\mysql\bin\mysqld-nt.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

--------------------------------------------------------------------------------------------------------------------------------------------------
Ok , What should I do now ?
Logged
Essexboy
Administrator
*****
Posts: 899



View Profile WWW
« Reply #4 on: March 14, 2007, 06:20:16 PM »

OK not a pretty sight.  First thing I need you to do is rename HiJackThis to gotcha as some of the critters are trying to hide from me.  You possibly have a Vundo infection as well as the worm plus a few hangers on.  I will set this thread to notify so that I know as soon as you reply.  Be not afraid we can cure you      
Logged

VISTA
XPsp2
Avast (of course)



http://spaces.msn.com/members/essexboymkn/

 If ignorance is bliss  why aren't more people happy?
omid020
Contributor
**
Posts: 16


View Profile
« Reply #5 on: March 14, 2007, 07:10:20 PM »

oh,I`m confused .Please explain the solution to me clearly . I have done step by step
everything in your first post . I can`t imagine what do you need now .I place an image
of HijackThis window for you , maybe it would be useful for you !
http://www.savefile.com/files/553662
What do you mean from "First thing I need you to do is rename HiJackThis to gotcha as some of the critters are trying to hide from me" ????
Logged
Essexboy
Administrator
*****
Posts: 899



View Profile WWW
« Reply #6 on: March 15, 2007, 02:15:04 PM »

Sorry I wasn't sure of your expertise level, so what I will do is get rid of the Vundo first Which will then allow me to see the rest of your problems

Please download VundoFix.exe to your desktop
  • Double-click VundoFix.exe to run it.
  • Click the Scan for Vundo button.
  • Once it's done scanning, click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click YES
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will reboot your computer, click OK.
  • Please post the contents of C:\vundofix.txt and a new HiJackThis log in a reply to this thread.
Note: It is possible that VundoFix encountered a file it could not remove. In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button" when VundoFix appears upon rebooting.

Prior to reposting with the vundo log

Please re-open HiJackThis and scan.  Check the boxes next to all the entries listed below.

F3 - REG:win.ini: load=C:\WINDOWS\svchost.exe


Now close all windows other than HiJackThis, then click Fix Checked.  Close HiJackThis.

THEN

Please download the Killbox by Option^Explicit.

Note: In the event you already have Killbox, this is a new version that I need you to download.
  • Save it to your desktop.
  • Please double-click Killbox.exe to run it.
  • Select:
    • Delete on Reboot
    • then Click on the All Files button.
  • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\WINDOWS\system32\temp1.exe
    C:\WINDOWS\svchost.exe

  • Return to Killbox, go to the File menu, and choose Paste from Clipboard.

  • Click the red-and-white Delete File button.  Click Yes at the Delete on Reboot prompt.  Click OK at any PendingFileRenameOperations prompt (and please let me know if you receive this message!).
If your computer does not restart automatically, please restart it manually.

If you receive a message such as: "Component 'MsComCtl.ocx' or one of its dependencies not correctly registered: a file is missing or invalid." when trying to run Killbox, click here to download and run missingfilesetup.exe. Then try Killbox again.

Now repost with vundofix.txt and a new HJT log
Logged

VISTA
XPsp2
Avast (of course)



http://spaces.msn.com/members/essexboymkn/

 If ignorance is bliss  why aren't more people happy?
omid020
Contributor
**
Posts: 16


View Profile
« Reply #7 on: March 16, 2007, 01:40:14 PM »

excuse me! http://www.atribune.org/ccount/click.php?id=4 link doesn`t work . I can`t download it . cry2
« Last Edit: March 16, 2007, 01:43:59 PM by omid020 » Logged
Essexboy
Administrator
*****
Posts: 899



View Profile WWW
« Reply #8 on: March 16, 2007, 02:08:32 PM »

Intriguing works for me.  OK let me find another link http://www.majorgeeks.com/downloadget.php?id=4954&file=10&evp=441f76946860196bd11870d8d721ed46  try this one.  If that fails then we have something on your system blocking that programme. 

So I will then require you to rename hijack this - to do this right click the Dynamite icon in  C:\Program Files\Hijackthis and select rename then type in gotcha


« Last Edit: March 16, 2007, 02:11:53 PM by Essexboy » Logged

VISTA
XPsp2
Avast (of course)



http://spaces.msn.com/members/essexboymkn/

 If ignorance is bliss  why aren't more people happy?
omid020
Contributor
**
Posts: 16


View Profile
« Reply #9 on: March 16, 2007, 04:02:51 PM »

Now I have downloaded vundoFix v.4.2.22 from http://www.majorgeeks.com/VundoFix_d4954.html
 and then ran it . No infected files were found was the message of Scan for Vundo.
After this ,I executed HiJackThis again and fixed all own checked options .Then I was forced
to reboot my pc .It was amazing ! dribble temp2.exe windows error wasn`t at startup of windows.
Then I ran Killbox as yo said ,it was funny that with each of C:\WINDOWS\system32\temp1.exe and
C:\WINDOWS\svchost.exe path paste in Killbox result was temp1.exe in killbox window in blue color
statement
. "PendingFileRenameOperations prompt" wasn`t in messages .Then I reboot my computer
again through killbox command .Again at startup there was no temp2.exe error .
Now HijackThis log wes this:

Logfile of HijackThis v1.99.1
Scan saved at 10:52:54 ب.ظ, on 2007/03/16
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Hijackthis\HijackThis.exe

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

But my sadly experience yworried : still AutoPlay statement was constant on my right click action
on each of my hard drives (Local Disks),Please have a view on this screenshot :
http://www.savefile.com/files/557983
And when I had a double click on drive C , again
temp2.exe error was on my screen .
I ran HijackThis again and now log file was this:

Logfile of HijackThis v1.99.1
Scan saved at 11:16:22 ب.ظ, on 2007/03/16
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\EmEditor\EMEDITOR.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Babylon\Babylon-Pro\Babylon.exe
C:\Program Files\ACD Systems\ACDSee\ACDSee.exe
C:\WINDOWS\system32\temp1.exe
C:\Program Files\Hijackthis\HijackThis.exe

F3 - REG:win.ini: load=C:\WINDOWS\svchost.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

 Can I do more?
Logged
omid020
Contributor
**
Posts: 16


View Profile
« Reply #10 on: March 16, 2007, 04:24:06 PM »

I have renamed HiJackThis to "110" number and result was this:
Logfile of HijackThis v1.99.1
Scan saved at 11:46:41 ب.ظ, on 2007/03/16
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Babylon\Babylon-Pro\Babylon.exe
C:\Program Files\ACD Systems\ACDSee\ACDSee.exe
C:\WINDOWS\system32\temp1.exe
C:\Program Files\Hijackthis\110.exe

F3 - REG:win.ini: load=C:\WINDOWS\svchost.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
-------------------------------------------------------------------------------------------------------------
and again I have renamed HiJackThis to "gotcha" statement and result was this :
Logfile of HijackThis v1.99.1
Scan saved at 11:52:39 ب.ظ, on 2007/03/16
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Babylon\Babylon-Pro\Babylon.exe
C:\Program Files\ACD Systems\ACDSee\ACDSee.exe
C:\WINDOWS\system32\temp1.exe
C:\Program Files\Hijackthis\gotcha.exe

F3 - REG:win.ini: load=C:\WINDOWS\svchost.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

I hope that do your purpose correctly .
Logged
Essexboy
Administrator
*****
Posts: 899



View Profile WWW
« Reply #11 on: March 16, 2007, 06:25:09 PM »

Still not happy with what I am seeing so I will use a different analysis tool

Download ComboScan to your Desktop.
  • Close all applications and windows.
  • Double-click on comboscan.exe to run it, and follow the prompts.
  • The scan may take a minute. When the scan is complete, a text file will open - ComboScan.txt
Extra Note: When running Comboscan, some firewalls may warn that sigcheck.exe is trying to access the internet - please ensure that you allow sigcheck.exe permission to do so. Also, it may happen that your Antivirus flags Comboscan as suspicious. Please allow the Comboscan to run and don't let your Antivirus delete it. (In this case, it may be better to temporary disable your Antivirus)

Post the Comboscan.txt from the Comboscan into your next reply. 

This tool will give me an insight into all your recently added files and registry.  Looks like you have something new 
Logged

VISTA
XPsp2
Avast (of course)



http://spaces.msn.com/members/essexboymkn/

 If ignorance is bliss  why aren't more people happy?
Essexboy
Administrator
*****
Posts: 899



View Profile WWW
« Reply #12 on: March 16, 2007, 06:30:11 PM »

Further information shows that it might be a Chinese variant
Logged

VISTA
XPsp2
Avast (of course)



http://spaces.msn.com/members/essexboymkn/

 If ignorance is bliss  why aren't more people happy?
Essexboy
Administrator
*****
Posts: 899



View Profile WWW
« Reply #13 on: March 16, 2007, 06:33:10 PM »

I also notice that you do not have an anti-virus.  You must get one immediately, or if you do have one it has been disabled.

If you have no AV then

First you have to download an antivirus.  This program is basic for the security of your computer and in todays age not having one will probably lead to disaster for your computer.

Please go HERE and download avast! 4 Home Edition to your desktop. Locate the file that you just downloaded, double-click on the file to launch the installation of avast!

Click Next on the avast! Setup window and on the next window with the ReadMe File.
Now you will see the Legal Agreement, just click I agree, and then click Next to continue.

You will be prompted with Configuration window, make sure that you choose Typical configuration and then click Next. Click Next to the windows that will follow, when the installation will finish, you will be given an option to schedule a boot time scan, select No

Now you have to restart your machine, select Restart and then click Finish.

After you restart you will get a message about avast! it will give you the general "Hello and Thank you for choicing our Product." Also after you restart you will notice 2 new icons in the bottom right corner of the screen.

VERY IMPORTANT - after restarting, right click on the a in the taskbar and select Updating, then highlight and click Program.

You will get  popup after its done updating. If avast! had to download anything for your computer you may get a message asking you to restart.

After you have updated avast! right click the small icon a in task bar and click Start Avast! AntiVirus

Click Program Registration and you will be taken to their website. Fill out the form and then check you e-mail. Once you get an e-mail from them (usually about 1 minute after submitting the form) copy and paste the serial they provided into the highlighted box. Then click ok.

After this, you will need to Schedule Boot-Time Scan with avast! Click on the little button placed up in the left  corner, and select Schedule Boot-Time Scan. Read also this tutorial HERE it may make it easier to you to follow the steps.

Next, choose
  • Scan all local disks   
  • scan archive files
  • click on Schedule
On the next dialog Operating system restart needed select Yes
Now avast! will restart your computer and start to scan before Windows fully loads.

IMPORTANT NOTE since your system has infections on it, avast! will give you dialog box with recommended actions, and options, please make sure if this happens, to click the Move to Chest button, and not to delete any reported files.
Logged

VISTA
XPsp2
Avast (of course)



http://spaces.msn.com/members/essexboymkn/

 If ignorance is bliss  why aren't more people happy?
omid020
Contributor
**
Posts: 16


View Profile
« Reply #14 on: March 17, 2007, 07:13:24 AM »

Thanks a lot for introducing avast! , it`s a good antivirus protector that doesn`t affect on my
PC speed  . Decreasing PC speed was my reason for not using a famous anti-virus.I had a cleanup
with Schedule Boot-Time Scan and it was very good . I think 2 files were creators of my
problems.copy.exe and host.exe . Each of them were on my all Local Drives and my USB Flash
Disk , and were found by avast! .
Still there is an AutPlay statement in right click on my drives , But when I had a
double click on my drives , an new error message shown on my screen with copy.exe title
and this content: Windows cannot find 'copy.exe' .Make sure you typed name correctly , and then try
again .To search for a file click the Start button ,and then click Search.

And at last this is ComboScan report after checking system with avast! anti-virus.

http://www.savefile.com/files/559378

I think that worm is removed from my PC but I don`t know why still AutoPlay item
is visible and how can I remove new error message ? yathink
Logged
Pages: [1] 2 3
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.2 | SMF © 2006-2007, Simple Machines LLC Valid XHTML 1.0! Valid CSS!