virus problems.

Status
Not open for further replies.

dmalagon

Posts: 6   +0
I need to post 3 times in order to post my message. so here it goes.

I need to post 3 times in order to post my message. so here it goes.

I am almost done . Here is the final one.
 
Hello and welcome to Techspot.

I have merged your posts and moved it to it`s own thread.

Log files must be posted as attachments and not copy and pasted. See HERE for instructions.

Regards Howard :wave: :wave:

This thread is for the use of dmalagon only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
 
After this message I want to post my real thread. I have an issue with spyware.cyberlog-x as well. I tried posting my HJT txt but cannot do so, so I will copy and paste into thread.
 
Please continue to post in this thread.

Follow the instructions for attaching your HJT log.

Regards Howard :)

This thread is for the use of dmalagon only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
 
Here it is.

Okay, so when I start windows I get an initial message saying my pc is infected with spyware.cyberlog-x. Then I get an unlimited amount of windows that appear with http://adnetserver.com as the address. I tried spybot, adaware and smitfraudfix but to no avail. So I ran HJT and here is my results. Sorry but I had a problem attaching the log so here it is copy and pasted.
 
Having looked at your HJT log, I can see your system is infected with a variety of malware.

Very Important: Before deciding whether you should clean or reformat your system, go and read this thread HERE and decide what it is you want to do.

If after reading the above, you wish to clean your system, do the following.

Go and read the Viruses/Spyware/Malware, preliminary removal instructions. Follow all the instructions exactly.

Post fresh HJT, AVG Antispyware and Combofix logs as Attachments into this thread, only after doing the above.

Please note: Any copy and pasted log files will be deleted.

Also, let me know the results of the Panda Antirootkit scan.

Regards Howard :)

This thread is for the use of dmalagon only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
 
Okay, so I completed all of the steps minus the online virus scan, as I had problems with it. Here is my first and final hjt log as well as my smitfraud, vundo and combofix logs. I noticed this little sucker before I subscribed to this site and was not able to get rid of it (C:\WINDOWS\system32\lwbnudwm.dll) but virtumundo or vundo did the job. When I ran my final avg anti-spyware scan I had a few items still listed. I will log my avg antispyware log as well on next entry as I maxed out.

Thank you for all of your help so far. Please let me know if I need to do anything else.

I am not sure where the avg log is located and should I get rid of the combofix quarantined items? Thanks.
 
Go HERE, download and install the latest version of Java.

Once it`s installed, go to add remove programmes in your control panel and uninstall all previous versions of Java, except version 6 update 3. Close Control panel.


See HERE for AVG Antispyware instructions.

I don`t know why you found it necessary to post log files I didn`t ask for, or two HJT logs. In future, please try and follow the instructions exactly.

Open notepad and copy/paste the text in the code box below into it:
NOTE* make sure to only highlight and copy what is inside the quote box nothing out side of it.
Also ..

Pay particular attention to this :-

Make sure the word File:: is on the first line of the text file you save (no blank line above it, & no space in front of it)
Code:


File::
C:\Windows\xpupdate.exe
C:\Documents and Settings\Guest\DED53B0BB67C4244AE6AD6FD3C28D1EF.TMP
C:\WINDOWS\system32\cfefe.bak2
C:\WINDOWS\system32\lwbnudwm.dll.vir
C:\WINDOWS\system32\cfefe.bak1
C:\WINDOWS\system32\vbzip10.dll

Folder::
C:\VundoFix Backups
C:\Qoobox
Registry::
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows update loader]

Save this as CFScript.txt

Then drag the CFScript.txt into ComboFix.exe as you see in the screenshot below.

CFScript.gif


This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply together with a fresh HJT log, as well as an AVG Antispyware log.

Regards Howard :)

This thread is for the use of dmalagon only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
 
Yes Sir. No more attaching unwanted files. Here is the combofix, avg anti-spyware and hjt log. Please let me know if I need to complete any more steps. As of now I do not see any symptoms of viruses on my computer. After running combofix, does an IExplorer icon appear on the desktop? It appeared right after the reboot from combofix. That is the only awkward thing I see.
 
Well done, your log files look clean.

Turn off system restore.(XP/ME only) See how HERE.

Now, turn system restore back on. This will have deleted all your old restore points and any nasties that are in them. It will also have created a new, clean restore point.


If you have any further virus/spyware problems, please post in this thread.

Regards Howard :)

This thread is for the use of dmalagon only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
 
Done! Thank you for all of your help. You are doing a great public service. I hope congress consider malware and spyware a form of grand theft digital. Don't know much about the legalities of the cyber-world but crimes are being committed at a scary rate.

This thread is now closed: If you need this thread unlocking, please pm a moderator with a link to the thread.

Only the original thread starter can do this. Anyone else, will be ignored.
 
Status
Not open for further replies.
Back