• Welcome to TechPowerUp Forums, Guest! Please check out our forum guidelines for info related to our community.

virus?

stealthfighter

New Member
Joined
Aug 5, 2006
Messages
557 (0.09/day)
Location
at my pc
Processor P4 2.8
Motherboard Intel D865PERL
Memory 2x512 Ballistix DDR400
Video Card(s) GeForce 5200
Storage Maxtor 120GB
Power Supply Allied 300w 10A
I found something wierd in my task manager that was never there before: a process called windrvr32.exe
I tried useing search but it did not come up with anything. So I looked in the most common place for viruses: system32. It was indeed there as a hidden file. Checking the properties it was created today by no corporation, unlike everything else in the folder created September 29 (the day I reformatted) by Microsoft. Virus??

HijackThis log:
*note* HijackThis reported 3 errors during the scan.
Code:
Logfile of HijackThis v1.99.1
Scan saved at 7:36:14 PM, on 11/18/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\windrvr32.exe
C:\Documents and Settings\vicente\Start Menu\Programs\Startup\utorrent.exe
C:\Program Files\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.isohunt.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = 
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Windows Update] windrvr32.exe
O4 - HKLM\..\RunServices: [Windows Update] windrvr32.exe
O4 - Startup: utorrent.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1159583340105
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe (file missing)
edit - Included hard hijackthis log
 

Attachments

  • hijackthis.log.txt
    2.2 KB · Views: 634
Last edited:
Joined
May 27, 2005
Messages
3,651 (0.53/day)
Location
Little Rock Arkansas, United States
System Name Monolith
Processor Intel Xeon E3110 Wolfdale@3.5GHz
Motherboard MSI P35-Neo
Cooling Active Air
Memory 4GB DDR2 800
Video Card(s) Sapphire HD 3850 512MB PCI-E
Storage 1 x 80GB Internal, 1 x 250GB Internal, 1 x 40GB External
Display(s) Acer X203w
Case Generic black case with locking front bezel
Audio Device(s) Creative SB Audigy 2 ZS
Power Supply 500 Watt Seasonic M12
Software Windows 7 Ultimate x64
Yeah, it's a virus. Added by the W32/Tilebot-AG worm. When started, this infection connects to a remote IRC server where it waits for commands to execute.
 

stealthfighter

New Member
Joined
Aug 5, 2006
Messages
557 (0.09/day)
Location
at my pc
Processor P4 2.8
Motherboard Intel D865PERL
Memory 2x512 Ballistix DDR400
Video Card(s) GeForce 5200
Storage Maxtor 120GB
Power Supply Allied 300w 10A
safemode'd
Now that that pice of shit is gone, do you think it could damage my system?

BTW this virus came from a trainer I was useing for Halo.
 
Last edited:
Joined
May 27, 2005
Messages
3,651 (0.53/day)
Location
Little Rock Arkansas, United States
System Name Monolith
Processor Intel Xeon E3110 Wolfdale@3.5GHz
Motherboard MSI P35-Neo
Cooling Active Air
Memory 4GB DDR2 800
Video Card(s) Sapphire HD 3850 512MB PCI-E
Storage 1 x 80GB Internal, 1 x 250GB Internal, 1 x 40GB External
Display(s) Acer X203w
Case Generic black case with locking front bezel
Audio Device(s) Creative SB Audigy 2 ZS
Power Supply 500 Watt Seasonic M12
Software Windows 7 Ultimate x64
Physically? No. As far as software corruption, it's possible. You'll just have to wait and see.
 
Top