Solved: AIM virus...zango

Status
This thread has been Locked and is not open to further replies. Please start a New Thread if you're having a similar issue. View our Welcome Guide to learn how to use this site.

emx620

Thread Starter
Joined
Dec 24, 2005
Messages
15
I sent a AIM virus to my friend as a joke, but he clicked on it. It downloaded, he ran it, it said something about zango, but he clicked cancel at this point. I didn't mean for him to actually click it. I have read some other posts on this forum, but it seems the case varies from person to person as they paste the log that programs pull up. I will be trying to fix this for him tomorrow night. What steps should I do first to fix this?
 

emx620

Thread Starter
Joined
Dec 24, 2005
Messages
15
Ok I can do that. I am also just considering deleting the partition and just formatting all togethor. If I follow your steps correctly, what are the chances of this "virus" being removed completely? I would like to fix it within one day, by the end of Monday hopefully. I will be able to start on it Sunday night. I really don't want to "fix it" and hand the computer back and have something come back later. Thanks.
 
Joined
Jul 8, 2002
Messages
14,681
It should not be too hard to remove. You may even be able to remove Zango from Add or Remove Programs in the Control Panel.
 

emx620

Thread Starter
Joined
Dec 24, 2005
Messages
15
My log is as follows:
Logfile of HijackThis v1.99.1
Scan saved at 4:26:28 PM, on 12/27/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\msvcrs.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Documents and Settings\Ben Dover\Desktop\HijackThis.exe

O2 - BHO: ATLDistrib Object - {93C6313C-9DB4-4694-8BD0-E378C573A9AD} - C:\WINDOWS\system32\urqrq.dll
O4 - HKLM\..\Run: [SmartGuardian] C:\Program Files\ITE\Smart Guardian\ITESmart.exe
O4 - HKLM\..\Run: [NVMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O20 - Winlogon Notify: urqrq - C:\WINDOWS\system32\urqrq.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Secure MSVS (MicroService32) - Unknown owner - C:\WINDOWS\msvcrs.exe
 
Joined
Jul 8, 2002
Messages
14,681
  • Please save or print these instructions for use in Safe Mode.
  • Save VundoFix.exe to your Desktop.
  • Double-click VundoFix.exe. This will create a folder called VundoFix.
  • Start your computer in Safe Mode.
  • Open the VundoFix folder and double-click KillVundo.bat
  • You will first be presented with a warning that looks like this:
    VundoFix V2.15 by Atri
    By using VundoFix you agree that you are doing so at your own risk
    Press enter to continue....
  • Press Enter once to continue.
  • Next you will see:
    Please Type in the filepath as instructed by the forum staff
    and then press enter:
  • Type the following file path exactly as it appears below:
    • C:\WINDOWS\system32\urqrq.dll
  • Press Enter to continue with the fix.
  • Next you will see:
    Please type in the second filepath as instructed by the forum
    staff then press enter:
  • Type the following file path exactly as it is written below:
    • C:\WINDOWS\system32\qrqru.*
  • Press Enter to continue.
  • If you have a script blocker running, you may get a warning about a malicious
    script. Allow the script to run.
  • At this point, HijackThis should open. If not, run HijackThis manually.
  • In HijackThis, put a check next to these entries and click Fix Checked:
    • O2 - BHO: ATLDistrib Object - {93C6313C-9DB4-4694-8BD0-E378C573A9AD} - C:\WINDOWS\system32\urqrq.dll[*]O20 - Winlogon Notify: urqrq - C:\WINDOWS\system32\urqrq.dll
  • Exit HijackThis.
  • Press Enter to exit the program.
  • Manually restart your computer by holding the power button down for about 5 seconds, then turning it back on.
    • Your computer may scan your disk for errors and take longer than normal to boot up. This is normal.
  • Download and install CleanUp!.
  • Click Options....
  • Move the arrow down to Custom CleanUp!.
  • Make sure only these options are checked:
    • Empty Recycle Bins
    • Delete Cookies
    • Delete Prefetch Files
    • Cleanup! All Users
  • Click OK then CleanUp!.
  • Choose No if asked to reboot your computer.
  • Run Kaspersky Online Scanner. Copy and paste the results here.
  • Post the contents of vundofix.txt from the VundoFix folder.
  • Post a new HijackThis log.
--Instructions generated by VundoFix.php
 

emx620

Thread Starter
Joined
Dec 24, 2005
Messages
15
Wow, detailed instructions. I actually just ended up formatting the hard drive just to be safe. I appreciate the long and detailed response though. If I ever have further problems, I will return (y)
 
Status
This thread has been Locked and is not open to further replies. Please start a New Thread if you're having a similar issue. View our Welcome Guide to learn how to use this site.

Users Who Are Viewing This Thread (Users: 0, Guests: 1)

As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 807,865 other people just like you!

Latest posts

Top