Tech Clinic / USB Port Infected
« on: March 01, 2014, 04:06:57 AM »Hello,
I have a virus which began with an infected USB Drive. Now every time I plug in any USB Drive it doesn\'t work, all files have become shortcuts and none of them work. Microsoft Security Essentials has identified the virus as follows - Worm:VBS/Jenxcus!Ink It quarantines it but every time I use a USB it keeps coming back. I tried Super Antispyware but it hasn\'t identified it either. I tried to format all my USB\'s but even after formatting when I plug in the USB the virus comes back. I am not sure if any other areas of the computer are infected yet. Please help removing this!
Here is the hijack this log -
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 2:34:05 PM, on 3/1/2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.16518)
Boot mode: Normal
Running processes:
C:\\Windows\\system32\\taskhost.exe
C:\\Program Files\\Malwarebytes\' Anti-Malware\\mbamgui.exe
C:\\Windows\\system32\\Dwm.exe
C:\\Windows\\Explorer.EXE
C:\\Program Files\\Common Files\\Adobe\\ARM\\1.0\\AdobeARM.exe
C:\\Program Files\\Microsoft Security Client\\msseces.exe
C:\\Program Files\\Microsoft Office\\Office12\\GrooveMonitor.exe
C:\\Program Files\\iTunes\\iTunesHelper.exe
C:\\Windows\\System32\\wscript.exe
C:\\Program Files\\Mozilla Firefox\\firefox.exe
C:\\Program Files\\Mozilla Firefox\\plugin-container.exe
C:\\Users\\compag\\AppData\\Local\\Google\\Google Talk Plugin\\googletalkplugin.exe
C:\\Program Files\\Mozilla Firefox\\plugin-container.exe
C:\\Windows\\system32\\Macromed\\Flash\\FlashPlayerPlugin_12_0_0_70.exe
C:\\Windows\\system32\\Macromed\\Flash\\FlashPlayerPlugin_12_0_0_70.exe
C:\\Users\\compag\\AppData\\Roaming\\VanToM Folder\\Server.exe
C:\\Windows\\system32\\wuauclt.exe
C:\\Users\\compag\\AppData\\Local\\Google\\Chrome\\Application\\chrome.exe
C:\\Users\\compag\\AppData\\Local\\Google\\Chrome\\Application\\chrome.exe
C:\\Users\\compag\\AppData\\Local\\Google\\Chrome\\Application\\chrome.exe
C:\\Program Files\\SUPERAntiSpyware\\SUPERAntiSpyware.exe
C:\\Program Files\\Trend Micro\\HiJackThis\\HiJackThis.exe
C:\\Windows\\system32\\DllHost.exe
R1 - HKCU\\Software\\Microsoft\\Internet Explorer\\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896\'>http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\\Software\\Microsoft\\Internet Explorer\\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157\'>http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\\Software\\Microsoft\\Internet Explorer\\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141\'>http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\\Software\\Microsoft\\Internet Explorer\\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896\'>http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\\Software\\Microsoft\\Internet Explorer\\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896\'>http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\\Software\\Microsoft\\Internet Explorer\\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141\'>http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\\Software\\Microsoft\\Internet Explorer\\Search,SearchAssistant =
R0 - HKLM\\Software\\Microsoft\\Internet Explorer\\Search,CustomizeSearch =
R1 - HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings,ProxyOverride = *.local
R0 - HKCU\\Software\\Microsoft\\Internet Explorer\\Toolbar,LinksFolderName =
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\\Program Files\\Microsoft Office\\Office12\\GrooveShellExtensions.dll
O4 - HKLM\\..\\Run: [Adobe ARM] \"C:\\Program Files\\Common Files\\Adobe\\ARM\\1.0\\AdobeARM.exe\"
O4 - HKLM\\..\\Run: [APSDaemon] \"C:\\Program Files\\Common Files\\Apple\\Apple Application Support\\APSDaemon.exe\"
O4 - HKLM\\..\\Run: [MSC] \"C:\\Program Files\\Microsoft Security Client\\msseces.exe\" -hide -runkey
O4 - HKLM\\..\\Run: [GrooveMonitor] \"C:\\Program Files\\Microsoft Office\\Office12\\GrooveMonitor.exe\"
O4 - HKLM\\..\\Run: [iTunesHelper] \"C:\\Program Files\\iTunes\\iTunesHelper.exe\"
O4 - HKCU\\..\\Run: [Skype] \"C:\\Program Files\\Skype\\Phone\\Skype.exe\" /minimized /regrun
O4 - HKCU\\..\\Run: [Google Update] \"C:\\Users\\compag\\AppData\\Local\\Google\\Update\\GoogleUpdate.exe\" /c
O4 - HKCU\\..\\Run: [uTorrent] \"C:\\Users\\compag\\AppData\\Roaming\\uTorrent\\uTorrent.exe\" /MINIMIZED
O4 - HKCU\\..\\Run: [MICROS~1] wscript.exe //B \"C:\\Users\\compag\\AppData\\Local\\Temp\\MICROS~1.VBS\"
O4 - HKCU\\..\\Run: [Server] C:\\Users\\compag\\AppData\\Roaming\\VanToM Folder\\Server.exe
O4 - HKCU\\..\\Run: [SUPERAntiSpyware] C:\\Program Files\\SUPERAntiSpyware\\SUPERAntiSpyware.exe
O4 - HKUS\\S-1-5-18\\..\\RunOnce: [SPReview] \"C:\\Windows\\System32\\SPReview\\SPReview.exe\" /sp:1 /errorfwlink:\"http://go.microsoft.com/fwlink/?LinkID=122915\'>http://go.microsoft.com/fwlink/?LinkID=122915\" /build:7601 (User \'SYSTEM\')
O4 - HKUS\\.DEFAULT\\..\\RunOnce: [SPReview] \"C:\\Windows\\System32\\SPReview\\SPReview.exe\" /sp:1 /errorfwlink:\"http://go.microsoft.com/fwlink/?LinkID=122915\'>http://go.microsoft.com/fwlink/?LinkID=122915\" /build:7601 (User \'Default user\')
O4 - Startup: MICROS~1.VBS
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\\PROGRA~1\\MICROS~1\\Office12\\ONBttnIE.dll
O9 - Extra \'Tools\' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\\PROGRA~1\\MICROS~1\\Office12\\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\\PROGRA~1\\MICROS~1\\Office12\\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\\Program Files\\Microsoft Office\\Office12\\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\\PROGRA~1\\COMMON~1\\Skype\\SKYPE4~1.DLL
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\\Program Files\\SUPERAntiSpyware\\SASCORE.EXE
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\\Program Files\\Common Files\\Adobe\\ARM\\1.0\\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\\Windows\\system32\\Macromed\\Flash\\FlashPlayerUpdateService.exe
O23 - Service: AMD External Events Utility - AMD - C:\\Windows\\system32\\atiesrxx.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\\Program Files\\Common Files\\Apple\\Mobile Device Support\\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\\Program Files\\Bonjour\\mDNSResponder.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\\Program Files\\Google\\Common\\Google Updater\\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\\Program Files\\iPod\\bin\\iPodService.exe
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\\Program Files\\Malwarebytes\' Anti-Malware\\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\\Program Files\\Malwarebytes\' Anti-Malware\\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\\Program Files\\Mozilla Maintenance Service\\maintenanceservice.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\\Program Files\\Skype\\Updater\\Updater.exe
--
End of file - 6415 bytes
Thank you!
Tanya
What do i do?