My poor computer got majorly infected and I'm trying to get it clean but I'm not sure if I got everything. I downloaded AVG Anti-Spyware 7.5 and I think it found a lot, but there is one entry called "Worm.VB.ao" coming from C:\\WINDOWS\System32\ismini.exe, and I just can't get rid of it. AVG keeps finding it and "cleaning/quarantining" it but then I scan again to double check and it's back. I probably shouldn't have, but I tried to delete it out of the file and it wouldn't let me, saying the file was protected or in use. I have no idea what to do or if I'm at risk. Can anyone help me get rid of this, and anything else bad on my computer?
Logfile of HijackThis v1.99.1
Scan saved at 1:49:32 PM, on 10/10/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Save it to your Desktop->>Rt Click->>Extract all->>and extract it to your desktop Open the Smitfraudfix folder Double-click smitfraudfix.cmd Select 1 and hit Enter to create a report of the infected files. The report can be found at the root of the system drive, usually at C:\rapport.txt Open that file, Ctrl+A to copy, and post a copy of that log as a reply to this thread
Hi bamajim, thank you for helping me! Here is the smitfraudfix scan report:
SmitFraudFix v2.109
Scan done at 11:02:37.93, Wed 10/11/2006
Run from C:\Documents and Settings\Laura Schick\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
Fix run in normal mode
»»»»»»»»»»»»»»»»»»»»»»»» C:\
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32
C:\WINDOWS\system32\ishost.exe FOUND !
C:\WINDOWS\system32\ismini.exe FOUND !
C:\WINDOWS\system32\components\flx?.dll FOUND !
C:\WINDOWS\system32\components\flx??.dll FOUND !
C:\WINDOWS\system32\components\flx???.dll FOUND !
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Laura Schick
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Laura Schick\Application Data
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, following keys are not inevitably infected!!!
First Reboot your PC into
Safe Mode This can be done by
Restart your PC, and after it starts, but before you see the Windows Splash screen Begin tapping the F8 key twice a second untill you reach another menu screen (black background with white menu choices) Use your arrow keys and select Safe Mode and then Enter
Next Open the
SmitfraudFix Folder, then double-click
smitfraudfix.cmd file to start the tool.
Select option #2 - Clean by typing 2 and press Enter. Wait for the tool to complete and disk cleanup to finish. You will be prompted : " Registry cleaning - Do you want to clean the registry ?" answer Yes by typing Y and hit Enter. The tool will also check if wininet.dll is infected. If a clean version is found, you will be prompted to replace wininet.dll. Answer Yes to the question " Replace infected file ?" by typing Y and hit Enter.
A reboot may be needed to finish the cleaning process, if your computer does not restart automatically please do it yourself manually. Reboot in
Safe Mode. To finish the cleaning
The tool will create a log named
rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed. Please post that log along with all others requested in your next reply.
Reboot your PC in
Normal mode->>Rerun Hijackthis and post a fresh hijackthis log
Your reply should include
your rapport.txt from Smitfraudfix a fresh Hijackthis log
»»»»»»»»»»»»»»»»»»»»»»»» After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» End
...And here is my new HijackThis log.
Logfile of HijackThis v1.99.1
Scan saved at 12:49:02 PM, on 10/11/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
1) Save it to the desktop and run it. 2) Select " Delete on Reboot", and then select "All files". 3) Copy the file name below to the clipboard by highlighting it and pressing Control-C:
C:\WINDOWS\system32\fkzggpb.dll
4) Return to Killbox, go to the File menu, and choose " Paste from Clipboard". 5) Click the red-and-white " Delete File" button. Click " Yes" at the Delete on Reboot prompt. Click " No" at the Pending Operations prompt.
Next Rerun Hijackthis and place checks beside the following entries
I ran Killbox and then Hijackthis, and fixed the checked boxes as per your instructions. Here is my new Hijack this log.
Logfile of HijackThis v1.99.1
Scan saved at 3:48:53 PM, on 10/11/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
It's possible the uninstaller is gone from AVG Antispyware.
First Using Windows Explorer
(Right click on "Start," select "Explore," and you will see the "tree' of file folders in the left side of the window. Click on the "+" next to any folder name to expand its contents)
Locate and delete this
folder
C:\Program Files\VSToolbar
Close windows explorer
Reboot your pc
Next Run an online virus scan called Kaspersky from
HERE.
1. Click on " Kaspersky Online Scanner" 2. A new smaller window will pop up. Press on " Accept". After reading the contents. 3. Now Kaspersky will update the anti-virus database. Let it run. 4. Click on " Next"->>" Scan Settings", and make sure the database is set to " extended". And check both the scan options. Then click OK. 5. Then click on " My Computer". And the scan will start. 6. Once finished, save a log as ". txt" to the desktop.
Copy and post the results of the Kaspersky Online scan
p.s. I went through my Add/Remove programs and found something called VSToolbar for Internet Explorer, which I don't remember installing and when I clicked "Change/Remove," nothing happened. I'm guessing that somehow I need to get rid of this too?
Hi bamajim,
Here is the log of my kapersky online scan. The website said something about making sure that you ran the program as an administrator, and I'm not sure if I did that right, but here's what I got.
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Wednesday, October 11, 2006 8:51:10 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.83.0
Kaspersky Anti-Virus database last update: 12/10/2006
Kaspersky Anti-Virus database records: 230865
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
C:\
D:\
E:\
Scan Statistics:
Total number of scanned objects: 122683
Number of viruses found: 4
Number of infected objects: 5 / 0
Number of suspicious objects: 1
Duration of the scan process: 01:21:19
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\cls\common.cls Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee.com\Agent\Logs\TaskScheduler\McTskshd001.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee.com\VSO\OASLogs\OAS.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\user.dmp Object is locked skipped
C:\Documents and Settings\Laura Schick\Application Data\Gtek\GTUpdate\AUpdate\DellSupport\DSAgnt.log Object is locked skipped
C:\Documents and Settings\Laura Schick\Application Data\Mozilla\Firefox\Profiles\lezw40yh.default\Cache\12CB9216d01 Object is locked skipped
C:\Documents and Settings\Laura Schick\Application Data\Mozilla\Firefox\Profiles\lezw40yh.default\Cache\_CACHE_001_ Object is locked skipped
C:\Documents and Settings\Laura Schick\Application Data\Mozilla\Firefox\Profiles\lezw40yh.default\Cache\_CACHE_002_ Object is locked skipped
C:\Documents and Settings\Laura Schick\Application Data\Mozilla\Firefox\Profiles\lezw40yh.default\Cache\_CACHE_003_ Object is locked skipped
C:\Documents and Settings\Laura Schick\Application Data\Mozilla\Firefox\Profiles\lezw40yh.default\Cache\_CACHE_MAP_ Object is locked skipped
C:\Documents and Settings\Laura Schick\Application Data\Mozilla\Firefox\Profiles\lezw40yh.default\cert8.db Object is locked skipped
C:\Documents and Settings\Laura Schick\Application Data\Mozilla\Firefox\Profiles\lezw40yh.default\history.dat Object is locked skipped
C:\Documents and Settings\Laura Schick\Application Data\Mozilla\Firefox\Profiles\lezw40yh.default\key3.db Object is locked skipped
C:\Documents and Settings\Laura Schick\Application Data\Mozilla\Firefox\Profiles\lezw40yh.default\parent.lock Object is locked skipped
C:\Documents and Settings\Laura Schick\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Laura Schick\Desktop\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\Laura Schick\Desktop\SmitfraudFix.zip/SmitfraudFix/Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\Laura Schick\Desktop\SmitfraudFix.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Laura Schick\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Laura Schick\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Laura Schick\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Laura Schick\Local Settings\History\History.IE5\MSHist012006101120061012\index.dat Object is locked skipped
C:\Documents and Settings\Laura Schick\Local Settings\Temp\MPC12.tmp Object is locked skipped
C:\Documents and Settings\Laura Schick\Local Settings\Temp\~DFF096.tmp Object is locked skipped
C:\Documents and Settings\Laura Schick\Local Settings\Temp\~DFF0A4.tmp Object is locked skipped
C:\Documents and Settings\Laura Schick\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Laura Schick\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Laura Schick\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Tony Schick\Local Settings\Temp\h7zcla50.wmf Suspicious: Exploit.Win32.IMG-WMF skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP401\A0049485.dll Infected: not-a-virus:AdWare.Win32.Softomate.u skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP401\A0049513.exe Infected: not-virus:Hoax.Win32.Renos.fh skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP403\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\pchealth\helpctr\Config\Cache\Personal_32_1033.dat Object is locked skipped
C:\WINDOWS\pchealth\helpctr\Config\CheckPoint\tmp.edb Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\DEFAULT Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\SOFTWARE Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SYSTEM Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
Double-click ATF-Cleaner.exe to run the program. Under Main choose: Select All Click the Empty Selected button.
If you use Firefox browser
Click Firefox at the top and choose: Select All Click the Empty Selected button. NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browser
Click Opera at the top and choose: Select All Click the Empty Selected button. NOTE: If you would like to keep your saved passwords, please click No at the prompt. Click Exit on the Main menu to close the program.
This will remove all files from the items that are checked so if you have some cookies you'd like to save. please move them to a different directory first.
Looks good so far, can I see one more Hijackthis log please :smileyhappy:
bamajim
1 Rookie
•
10376 Posts
222
0
Posted October 11th, 2006 14:00
And Download SmitFraudFix by S!ri
Do Not run option 2 until instructed to do so
bamajim Graduate of Malware Removal University