My computer got infected, I used both Kaspersky and AD-Aware SE to scan (more then once) and deleted alot of spywares and viruses, tho the computer still seems to be infected, I keep getting that windows massage and as well I can't change my sektop options (background etc...).
There's the log file:
Logfile of HijackThis v1.99.1 Scan saved at 00:16:41, on 19/10/2006 Platform: Windows XP (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Save it to your Desktop->>Rt Click->>Extract all->>and extract it to your desktop Open The Smitfraud folder Double-click smitfraudfix.cmd Select 1 and hit Enter to create a report of the infected files. The report can be found at the root of the system drive, usually at C:\rapport.txt Open that file, Ctrl+A to copy, and post a copy of that log as a reply to this thread
Scan done at 14:45:53.05, Thu 10/19/2006 Run from C:\Documents and Settings\AK\Desktop\SmitfraudFix\SmitfraudFix OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT Fix run in normal mode
»»»»»»»»»»»»»»»»»»»»»»»» C:\
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS
C:\WINDOWS\.protected FOUND ! C:\WINDOWS\xpupdate.exe FOUND !
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32
C:\WINDOWS\system32\dlh9jkdq?.exe FOUND ! C:\WINDOWS\system32\kernels8.exe FOUND ! C:\WINDOWS\system32\qvxgamet?.exe FOUND ! C:\WINDOWS\system32\vxgame?.exe FOUND !
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\AK
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\AK\Application Data
C:\Documents and Settings\AK\Application Data\Install.dat FOUND !
»»»»»»»»»»»»»»»»»»»»»»»» Start Menu
C:\DOCUME~1\AK\STARTM~1\Programs\Startup\.protected FOUND ! C:\DOCUME~1\ALLUSE~1\STARTM~1\Programs\Startup\.protected FOUND !
»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\AK\FAVORI~1
»»»»»»»»»»»»»»»»»»»»»»»» Desktop
»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files
»»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys
»»»»»»»»»»»»»»»»»»»»»»»» Desktop Components
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0] "Source"="About:Home" "SubscribedURL"="About:Home" "FriendlyName"="My Current Home Page"
»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler !!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs !!!Attention, following keys are not inevitably infected!!!
You may want to print out these instructions for reference
1. Go
here and Download
AVG Anti-Spyware (
30 day free trial version) Save it to Your Desktop
Double Click
AVG Anti-Spyware-setup (It will create its own folder)
Once the program starts You will be at the
Status menu
Under "Your computers Security" Click change status on Resident shield to inactive Click Update now (next to last update) After the update loads Under Automatic updates Uncheck download and install updates automatically(recommended) (you can always select maual updates the next day)
At the top toolbar Click
Scanner Then the
settings tab
Under How to act? Set default action for detected malwareTo Quarantine Under how to scan All boxes should be checked Under Possibly unwanted software All boxes should be checked Under reports Select Automatically generate report after every scan Uncheck Only if threats were found Under what to scan Scan every file should be highlited
Exit AVG(But do not run it yet)
2. Reboot into
Safe Mode This can be done by
Restart your PC, and after it starts, but before you see the Windows Splash screen Begin tapping the F8 key twice a second untill you reach another menu screen (black background with white menu choices) Use your arrow keys and select Safe Mode and then Enter
3. Open the
SmitfraudFix Folder, then double-click
smitfraudfix.cmd file to start the tool.
Select option #2 - Clean by typing 2 and press Enter. Wait for the tool to complete and disk cleanup to finish. You will be prompted : " Registry cleaning - Do you want to clean the registry ?" answer Yes by typing Y and hit Enter. The tool will also check if wininet.dll is infected. If a clean version is found, you will be prompted to replace wininet.dll. Answer Yes to the question " Replace infected file ?" by typing Y and hit Enter.
A reboot may be needed to finish the cleaning process, if your computer does not restart automatically please do it yourself manually. Reboot in
Safe Mode.
The tool will create a log named
rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed. Please post that log along with all others requested in your next reply.
4. Run AVG Anti-Spyware
Click scanner Select Complete system scan
Once the scan finishes
Select Apply all actions (The items found will be quarantined) Click save report as (Another window will open) Save it to your desktop (By default It will be saved in the AVG folder as) C:\Program Files\Grisoft\AVG anti-spyware 7.5\Reports
Exit AVG
Reboot your PC in
Normal Mode->>Re run Hijackthis and post a fresh Hijackthis log.
Double click the report-scan txt. you saved to your desktop It will open in Notepad Copy and paste that report as a reply to this thread
Your reply should include
a fresh hijackthis log your c:rapport.txt log from Smitfraudfix your report_scan.txt from AVG
You may have to post the results in more than one reply
Scan done at 17:57:19.67, Thu 10/19/2006
Run from C:\SmitfraudFix\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
Fix run in safe mode
»»»»»»»»»»»»»»»»»»»»»»»» Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
Second - I just wanted to point it that SmithfraudFix didn't asked anything about wininet.dll, after registry cleaning the log file opened (by itself) and another box about safe mode (asking if I want to use system restore).
And now for the log files, that's the hijackthis log:
Logfile of HijackThis v1.99.1
Scan saved at 18:33:08, on 19/10/2006
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
1) Save it to the desktop and run it. 2) Select " Delete on Reboot", and then select "All files". 3) Copy the file names below to the clipboard by highlighting them and pressing Control-C:
4) Return to Killbox, go to the File menu, and choose " Paste from Clipboard". 5) Click the red-and-white " Delete File" button. Click " Yes" at the Delete on Reboot prompt. Click " No" at the Pending Operations prompt.
Next Re Run Hijackthis (scan only) and place checks beside the following entries
I had some problems, first with KillBox..I couldn't delete the last 2 files, couldn't add them or anything.
Hijackthis - the last file (startup protected) - unable to delete.
Anyway, here is the log:
Logfile of HijackThis v1.99.1
Scan saved at 10:43:40, on 20/10/2006
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Run an online virus scan called Kaspersky from
HERE.
1. Click on " Kaspersky Online Scanner" 2. A new smaller window will pop up. Press on " Accept". After reading the contents. 3. Now Kaspersky will update the anti-virus database. Let it run. 4. Click on " Next"->>" Scan Settings", and make sure the database is set to " extended". And check both the scan options. Then click OK. 5. Then click on " My Computer". And the scan will start. 6. Once finished, save a log as ". txt" to the desktop.
Copy and post the results of the Kaspersky Online scan
Detected
--------
Status Object
------ ------
deleted: Trojan program Trojan-Downloader.Win32.Small.cxx File: C:\Documents and Settings\AK\Local Settings\Temp\1.dlb
deleted: Trojan program Trojan-Downloader.Win32.Small.dgk File: C:\Documents and Settings\AK\Local Settings\Temp\5.dlb/FSG
deleted: Trojan program Trojan.Win32.Dialer.ay File: C:\Documents and Settings\AK\Local Settings\Temp\maxdd1.game
deleted: Trojan program Trojan-Downloader.Win32.Small.dht File: C:\Documents and Settings\AK\Local Settings\Temp\vxt1.game
deleted: Trojan program Trojan-Downloader.Win32.Small.dwx File: C:\Documents and Settings\AK\Local Settings\Temp\vxt2.game
deleted: Trojan program Trojan-Downloader.Win32.Small.cyb File: C:\Documents and Settings\AK\Local Settings\Temp\vxt3.game
deleted: malware Constructor.Perl.Msdds.b File: C:\Documents and Settings\AK\Local Settings\Temporary Internet Files\Content.IE5\8TGN8N83\new3[1].htm
deleted: Trojan program Trojan-Downloader.Win32.Ani.c File: C:\Documents and Settings\AK\Local Settings\Temporary Internet Files\Content.IE5\8TGN8N83\sploit[1].anr
deleted: Trojan program Trojan-Downloader.Win32.Agent.acd File: C:\Documents and Settings\AK\Local Settings\Temporary Internet Files\Content.IE5\8TGN8N83\xpl[1].wmf
deleted: Trojan program Trojan-Clicker.HTML.Agent.a File: C:\Documents and Settings\AK\Local Settings\Temporary Internet Files\Content.IE5\AHW3I1A5\popup[1].php/popup[1]
deleted: Trojan program Trojan-Clicker.HTML.Agent.a File: C:\Documents and Settings\AK\Local Settings\Temporary Internet Files\Content.IE5\AHW3I1A5\popup[2].php
deleted: Trojan program Trojan-Downloader.Win32.Tibs.il File: C:\Documents and Settings\AK\Local Settings\Temporary Internet Files\Content.IE5\UJYVAP2Z\targ[1].chm/win32.exe
bamajim
10376 Posts
304
0
Posted October 19th, 2006 02:00
And Download SmitFraudFix by S!ri
Open The Smitfraud folder
Double-click smitfraudfix.cmd
Select 1 and hit Enter to create a report of the infected files. The report can be found at the root of the system drive, usually at C:\rapport.txt
Open that file, Ctrl+A to copy, and post a copy of that log as a reply to this thread
Do Not run option 2 until instructed to do so