Trojan Virus - Please Help (Log Attached)

Status
Not open for further replies.
open hijackthis and place a check next to the items below

O16 - DPF: {1A1F56AA-3401-46F9-B277-D57F3421F821} (FunGamesLoader Object) - http://mypoints.worldwinner.com/games/v47/shared/FunGamesLoader.cab
[/COLOR]

Also can you post the name of the viruses that avg found they should be located in the virus vault

-------------------------------------------------------

SmitfraudFix

  • Download SmitFraudFix to your deskop
  • reboot your computer in Safe Mode (before the Windows icon appears, tap the F8 key continually)
  • Double-click SmitfraudFix.exe
  • Select 2 and hit Enter to delete infect files.
  • You will be prompted: Do you want to clean the registry ? answer Y (yes) and hit Enter in order to remove the Desktop background and clean registry keys associated with the infection.
  • The tool will now check if wininet.dll is infected. You may be prompted to replace the infected file (if found): Replace infected file ? answer Y (yes) and hit Enter to restore a clean file.
  • A reboot may be needed to finish the cleaning process. The report can be found at the root of the system drive, usually at C:\rapport.txt (Attach the log to your next reply)
 
"";"";"Trojan horse Downloader.Generic7.XMT";"C:\WINDOWS\system32\olixds18\olixds182328.exe";"7/13/2008 9:08:52 AM";"olixds182328.exe";"32 KB"
"";"";"Trojan horse Generic10.BCCD";"C:\WINDOWS\system32\opnlKCSm.dll";"7/13/2008 9:02:47 AM";"opnlKCSm.dll";"275 KB"
"";"";"Trojan horse Generic10.BCCE";"C:\WINDOWS\system32\mpcdeymf.dll";"7/13/2008 9:03:00 AM";"mpcdeymf.dll";"79.5 KB"
"";"";"Trojan horse Generic10.BCJQ";"C:\QooBox\Quarantine\C\WINDOWS\system32\mslbigtg.dll.vir";"7/16/2008 9:42:45 AM";"mslbigtg.dll.vir";"99 KB"
"";"";"Trojan horse Generic10.BCJQ";"C:\QooBox\Quarantine\C\WINDOWS\system32\xfzplr.dll.vir";"7/16/2008 9:42:46 AM";"xfzplr.dll.vir";"99 KB"
"";"";"Trojan horse Generic10.BCJR";"C:\QooBox\Quarantine\C\WINDOWS\system32\yljtlxij.dll.vir";"7/16/2008 9:42:46 AM";"yljtlxij.dll.vir";"90 KB"
"";"";"Trojan horse Downloader.Generic7.XMT";"C:\WINDOWS\system32\olixds18\olixds182328.exe";"7/16/2008 9:42:46 AM";"olixds182328.exe";"32 KB"
"";"";"Trojan horse Generic10.BCGP";"C:\WINDOWS\system32\mlJdBSLC.dll";"7/14/2008 5:34:43 PM";"mlJdBSLC.dll";"31 KB"
"";"";"Trojan horse Downloader.Generic7.XMT";"C:\WINDOWS\system32\olixds18\olixds182328.exe";"7/12/2008 6:12:55 PM";"olixds182328.exe";"32 KB"
 
SmitFraudFix v2.329

Scan done at 22:54:21.76, Wed 07/16/2008
Run from C:\Documents and Settings\Meredith\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in safe mode

»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

»»»»»»»»»»»»»»»»»»»»»»»» Killing process


»»»»»»»»»»»»»»»»»»»»»»»» hosts

127.0.0.1 localhost

»»»»»»»»»»»»»»»»»»»»»»»» VACFix

VACFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix

S!Ri's WS2Fix: LSP not Found.


»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

GenericRenosFix by S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files


»»»»»»»»»»»»»»»»»»»»»»»» IEDFix

IEDFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri



»»»»»»»»»»»»»»»»»»»»»»»» 404Fix

404Fix
Credits: Malware Analysis & Diagnostic
Code: S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» DNS

HKLM\SYSTEM\CCS\Services\Tcpip\..\{34C855D7-56D8-40F1-8C67-7D50D17A235F}: DhcpNameServer=192.168.1.254
HKLM\SYSTEM\CS1\Services\Tcpip\..\{34C855D7-56D8-40F1-8C67-7D50D17A235F}: DhcpNameServer=192.168.1.254
HKLM\SYSTEM\CS3\Services\Tcpip\..\{34C855D7-56D8-40F1-8C67-7D50D17A235F}: DhcpNameServer=192.168.1.254
HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.254


»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files


»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""


»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

Registry Cleaning done.

»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» End
 
Is there something else I can try? I ran the Java Trend Micro thing on my computer and left it on all night (I have DSL) and it was never going to end. It did tell me I had 19 "infected" at the delete cookies stage (all in the IE Cache, e.g., IECache/247realmeadia.como, adrevolver.com, advertising.com, did-it.com, etc.)but then it spent like three hours trying to delete them before I finally gave up.
 
--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7 REPORT
Thursday, July 17, 2008
Operating System: Microsoft Windows XP Home Edition Service Pack 2 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Thursday, July 17, 2008 22:09:45
Records in database: 965401
--------------------------------------------------------------------------------

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
C:\
D:\

Scan statistics:
Files scanned: 86312
Threat name: 8
Infected objects: 17
Suspicious objects: 0
Duration of the scan: 01:40:56


File name / Threat name / Threats count
C:\Documents and Settings\Meredith\Desktop\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f 1
C:\Documents and Settings\Meredith\Desktop\SmitfraudFix.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f 1
C:\Documents and Settings\Meredith\DoctorWeb\Quarantine\A0041250.scr Infected: not-a-virus:AdTool.Win32.MyWebSearch 1
C:\Documents and Settings\Meredith\DoctorWeb\Quarantine\A0041253.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch 1
C:\Documents and Settings\Meredith\DoctorWeb\Quarantine\A0041256.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.au 1
C:\Documents and Settings\Meredith\DoctorWeb\Quarantine\A0041257.SCR Infected: not-a-virus:AdTool.Win32.MyWebSearch 1
C:\Documents and Settings\Meredith\DoctorWeb\Quarantine\A0041259.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch 1
C:\Documents and Settings\Meredith\DoctorWeb\Quarantine\A0041260.EXE Infected: not-a-virus:AdTool.Win32.MyWebSearch.a 1
C:\Documents and Settings\Meredith\DoctorWeb\Quarantine\A0041262.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.bh 1
C:\Documents and Settings\Meredith\DoctorWeb\Quarantine\A0041265.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.ax 1
C:\Documents and Settings\Meredith\DoctorWeb\Quarantine\A0041269.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch 1
C:\Documents and Settings\Meredith\DoctorWeb\Quarantine\A0041452.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.ba 1
C:\Documents and Settings\Meredith\DoctorWeb\Quarantine\A0041453.EXE Infected: not-a-virus:AdTool.Win32.MyWebSearch 1
C:\Documents and Settings\Meredith\DoctorWeb\Quarantine\A0041454.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch 1
C:\Documents and Settings\Meredith\DoctorWeb\Quarantine\A0042011.dll Infected: not-a-virus:AdTool.Win32.MyWebSearch.ba 1
C:\Documents and Settings\Shared\bad skin day bell x1.mp3 Infected: Trojan-Downloader.WMA.Wimad.n 1
C:\Documents and Settings\Shared\Redding, Otis - Hey hey baby.mp3 Infected: Trojan-Downloader.WMA.Wimad.n 1

The selected area was scanned.
 
Now we need to create a new System Restore point.

Click Start Menu > Run > type (or copy and paste)

%SystemRoot%\System32\restore\rstrui.exe

Press OK. Choose Create a Restore Point then click Next. Name it and click Create, when the confirmation screen shows the restore point has been created click Close.

Next goto Start Menu > Run > type

cleanmgr

Click OK, Disk Cleanup will open and start calculating the amount of space that can be freed, Once thats finished it will open the Disk Cleanup options screen, click the More Options tab then click Clean up on the system restore area and choose Yes at the confirmation window which will remove all the restore points except the one we just created.

To close Disk Cleanup and remove the Temporary Internet Files detected in the initial scan click OK then choose Yes on the confirmation window.

--------------------------------

Now run a full scan with AVG and post also I was not able to reply earlier I was at work
 
Thank you for writing me back! I ran AVG this morning, and here is what it gave me. Thanks again.

Test Result Complete Test (7/18/2008 07:04:39)
Result overview I Virus results
Item Name Item Value

General properties
Report name Complete Test
Start time 7/18/2008 07:04:39
End time 7/18/2008 08:20:34 (total 1:15:54.7 hrs)
Launch method Scanning launched manually
Scanning result No threats found
Report status Scanning completed successfully

Object summary
Scanned 152647
Threats Found 0
Cleaned 0
Moved to vault 0
Deleted 0
Errors 0
 
Ok it looks like your computer is clean. We just need to do some cleaning. How is your computer running now?

Uninstall ComboFix

  • Click Start then Run
  • Now Type Combofix /u in the runbox
  • Make sure there's a space between Combofix & /u
  • Then hit Enter

The above procedure will Delete the following:
  • ComboFix & it's associated files & folders.
  • Reset the clock settings.
  • Hide file extensions, if required.
  • Hide system/hidden files, if required.
  • Set a new, clean Restore Point.

------------------------------------------------------------------

OTCleanit! by Oldtimer

  • Download OTCleanIt
  • Click the CleanUp! button.
    (It will go thorugh the list & remove all of the tools it finds and then delete itself) Requiring a reboot

-----------------------------------------------------------------

Now we need to create a new System Restore point.

Click Start Menu > Run > type (or copy and paste)

%SystemRoot%\System32\restore\rstrui.exe

Press OK. Choose Create a Restore Point then click Next. Name it and click Create, when the confirmation screen shows the restore point has been created click Close.

Next goto Start Menu > Run > type

cleanmgr

Click OK, Disk Cleanup will open and start calculating the amount of space that can be freed, Once thats finished it will open the Disk Cleanup options screen, click the More Options tab then click Clean up on the system restore area and choose Yes at the confirmation window which will remove all the restore points except the one we just created.

To close Disk Cleanup and remove the Temporary Internet Files detected in the initial scan click OK then choose Yes on the confirmation window.

-------------------------------------------------

The following is a list of tools and utilities that I like to suggest to people. This list is full of great tools and utilities to help you understand how you got infected and how to keep from getting infected again.
  1. Spybot Search & Destroy - Uber powerful tool which can search and annhilate nasties that make it onto your system. Now with an Immunize section that will help prevent future infections.
  2. AdAware - Another very powerful tool which searches and kills nasties that infect your system. AdAware and Spybot Search & Destroy compliment each other very well.
  3. SpywareBlaster - Great prevention tool to keep nasties from installing on your system.
  4. SpywareGuard - Works as a Spyware "Shield" to protect your computer from getting malware in the first place.
  5. IE-SpyAd - puts over 5000 sites in your restricted zone so you'll be protected when you visit innocent-looking sites that aren't actually innocent at all.
  6. ATF Cleaner - Cleans temporary files from IE and Windows, empties the recycle bin and more. Great tool to help speed up your computer and knock out those nasties that like to reside in the temp folders.
  7. Windows Updates - It is very important to make sure that both Internet Explorer and Windows are kept current with the latest critical security patches from Microsoft. To do this just start Internet Explorer and select Tools > Windows Update, and follow the online instructions from there.
  8. Google Toolbar - Free google toolbar that allows you to use the powerful Google search engine from the bar, but also blocks pop up windows.
  9. Trillian or Miranda-IM - These are Malware free Instant Messenger programs which allow you to connect to multiple IM services in one program! (AOL, Yahoo, ICQ, IRC, MSN)
xxdanielxx
 
Thank you!!! Things seem to be running pretty well, as far as I can tell :):)

Don't know if it's ok to ask a couple of pesky questions, but I will try anyway:

1. I do have Ad-Aware and cc cleaner that I run pretty regularly, and Spy-bot (which I don't really run), Google toolbar, and I do always load the updates. Is that generally enough or are you recommending using all those programs?

2. I rebooted my computer, and my clock is still giving me "18:44," instead of "6:44." Anyway I can get my time back to how it used to be?

3. When my computer was infected, I didn't use my credit card or anything, but I did enter my e-mail password, etc. Should I reset my passwords, or is there any danger there?

Thanks again for all of your help!!!! I really really really appreciate it.
 
1) I like to use Avira for Anti-virus, Comodo firewall as my firewall and 3 or 4 spyware apps I like MBAM, Spybot S&D, Adaware

2)go to Start>Control Panel> Languages then click on customize then click the time tab and last change it from h:mm to hh:mm: then click apply and ok.

3)I did not see any keylogger but better safe then sorry
 
Status
Not open for further replies.
Back