Mourning the loss of our friend, WhitPhil.
There's no such thing as a stupid question, but they're the easiest to answer.
JoinTour
Login
Search
 
General Security
Tag Cloud
access audio black screen blue screen boot bsod connection crash dell desktop drivers dvd email error excel excel 2003 firefox hard drive hardware hdmi hijackthis internet keyboard laptop malware monitor motherboard network networking outlook problem processor recovery router safe mode screen slow sound spyware tdlwsp.dll trojan video virus vista vundo windows windows 7 windows vista windows xp wireless
Search
Search for:
Tech Support Guy Forums > Security & Malware Removal > General Security >
Solved: Gateway's recovery included virus?

Tip: Click here to scan for System Errors and Optimize PC performance
[ Sponsored Link ]

Closed Thread
 
Thread Tools
jwv13's Avatar
Computer Specs
Member with 96 posts.
 
Join Date: Aug 2008
Location: Akron
Experience: Advanced
24-Sep-2009, 09:29 AM #1
Talking Solved: Gateway's recovery included virus?
Hi Guys,
Can anyone tell me if they've ever run into a recovery partition with a virus? I did a re-installation with Gateways recovery, off the partition; I bought this computer: Gateway SX2800-01 with Vista Home Premium 64bit, from Best Buy. It was running slow so I reformatted and reinstalled the O.S. to see if I could speed it up a little. Noticed it was still running slow so ran a scan with Malwarebytes and it came up with this:

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 7
Registry Values Infected: 0
Registry Data Items Infected: 1
Folders Infected: 0
Files Infected: 2

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\TypeLib\{86676e13-d6d8-4652-9fcf-f2047f1fb000} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{83ff80f4-8c74-4b80-b5ba-c8ddd434e5c4} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Brows er Helper Objects\{83ff80f4-8c74-4b80-b5ba-c8ddd434e5c4} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\partner service (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\partner service (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\partner service (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\kt_bho.KettleBho (Trojan.BHO) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explo rer\NoActiveDesktopChanges (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
C:\ProgramData\Partner\partner.dll (Trojan.BHO) -> Quarantined and deleted successfully.
C:\ProgramData\Partner\partner.exe (Trojan.BHO) -> Quarantined and deleted successfully.

I attached what Spybot Search and Destroy found.
Attached Files
File Type: txt SpybotSD.Report.txt (958 Bytes, 11 views)

Last edited by jwv13 : 24-Sep-2009 11:20 AM.
knewton37's Avatar
Junior Member with 1 posts.
 
Join Date: Sep 2009
24-Sep-2009, 03:31 PM #2
Talking thanks
we just bought a gateway from best buy also and it has been a nightmare ever since. we did have to do the recovery and i have found this virus. thanks for your suggestions !
Byteman's Avatar
Moderator with 14,997 posts.
 
Join Date: Jan 2002
Location: NY
Experience: Junkware Jouster
24-Sep-2009, 07:15 PM #3
Hi,

What was found could be included in the software preloaded on your computer...I searched and could not begin to go through all the posts with the same items from June 2009 or so on.... These items are detected on the 64-bit version of Vista....I'm not sure if that would be ONLY on 64-bit, or more often....

http://forumserver.twoplustwo.com/48...d-help-531062/

http://www.malwarebytes.org/forums/i...howtopic=10910

In Post #4 there, a recognized worldover expert Tony Klein gives his take on these items- they are adware type things, and it is noted that they may pass info about your browsing etc....Google was built that way, it's no wonder they continue to!

This is what it looks like in an Hijackthis log>


O23 - Service: Google Desktop Manager 5.7.808.7150 (GoogleDesktopManager-080708-050100) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: Partner Service - Google Inc. - C:\Documents and Settings\All Users\Application Data\Partner\
partner.exe


In one post, a person UNinstalled Google apps on his computer, preferable the Google Toolbar.... or Chrome. I am not sure about Gmail, I use that myself, and have not have any ill effects.... All too often, people rush to delete items and are really upset about what they find on a brand new out of the store or box PC In all of the threads I looked at, people were confounded by the re-appearance of these same things.... either they came back after a format and Reocvery, or from their own backups....

Yes, the scanners find them, and probably rightly so> the scanners are very much detecting what items might be able to do (in this case a breach of privacy etc)


One thing> Sometimes, the detection of items like this will be changed or the files themselves will be...so, reporting things like this DOES do some good for us all.

I am not ranting that you are a nitwit or anything for posting about it...just would like to clear up.

A tip> You buy a new computer, it comes loaded with things you don't want, etc...go get this app:
http://www.pcdecrapifier.com/download

It will show you what you can UNinstall easily.

Last edited by Byteman : 25-Sep-2009 09:39 PM.
jwv13's Avatar
Computer Specs
Member with 96 posts.
 
Join Date: Aug 2008
Location: Akron
Experience: Advanced
24-Sep-2009, 11:08 PM #4
Thanks for the help guys. I appreciate it.
Closed Thread Bookmark and Share

THIS THREAD HAS EXPIRED.
Are you having the same problem? We have volunteers ready to answer your question, but first you'll have to join for free. Need help getting started? Check out our Welcome Guide.

Smart Search

Find your solution!



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
WELCOME TO TECH SUPPORT GUY! Are you looking for the solution to your computer problem? Join our site today to ask your question -- for free! Our site is run completely by volunteers who want to help you solve your computer problems. See our Welcome Guide to get started.

Thread Tools


You Are Using:
Server ID
Advertisements do not imply our endorsement of that product or service.
All times are GMT -5. The time now is 07:57 AM.
Copyright © 1996 - 2009 TechGuy, Inc. All rights reserved.
Powered by vBulletin, Copyright © 2000 - 2009, Jelsoft Enterprises Ltd.
Powered by Cermak Technologies, Inc.