Welcome Guest ( Log In | Click here to Register a free account now! )
Welcome to Bleeping Computer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.When posting your problem, do not run and post a ComboFix logs. ComboFix is a tool that should only be run under the supervision of someone who has been trained in its use. Using it on your own can cause problems with your computer. Any posts containing CF Logs will be ignored.
To receive help, you should instead provide a detailed description of your problem, detailed word-for-word error messages that you are receiving, screenshots of strange behaviour, and your operating system. This information is much more useful to our helpers than a ComboFix log.
![]() ![]() |
Jan 6 2009, 08:36 AM
Post
#1
|
|
|
Member ![]() ![]() Group: Members Posts: 18 Joined: 5-January 09 Member No.: 278,670 |
Hi there I have Win XP and seem to have gotten lots of viruses onto the pc... but please bear with me as i am a bit of a computer novice! Having done a virus scan with AVG v.8, the results came up with many warnings, particularly ref. to viruses Trojan Zapchast, Aware Shorty, Adware Virtuemonde and Titan shield antispyware ( some of which I have researched to be SmitFrauds)...there are more though!! I looked on the Major geek website and went through their basic pc check list (downloaded and ran Super Anti spyware, CCleaner, Malwarebytes' Anti malware.. it suggested using ComboFix, but the instructions warn this is risky so i've left this for now). I'm not really sure if the AVG has rid of the viruses, although it has detected them. It has put them into a Virus Vault, but whether my pc is cured i don't know! I've done a few scans now and the same viruses keep coming up. The most obvious prob i'm still getting with my pc is when I do a web search for anything (i.e. shoes) the correct descriptions come up, but all the URL's are wrong, often pointing to advertising websites that seem suspect... I'm not sure how to show you the results of anything, or do a 'hijackthis' etc, so if that would help, please let me know how i can do this! Many thanks...really look forward to hearing from someone as i'm giving up doing endless seaches on these viruses! cheers |
|
|
|
Jan 6 2009, 12:51 PM
Post
#2
|
|
![]() Computer Masochist ![]() ![]() ![]() ![]() ![]() ![]() Group: Moderator Posts: 23,634 Joined: 27-January 07 From: Cleveland, Ohio Member No.: 108,618 |
Do not run Combofix or HJT unassisted
------------------------------------------------------------------ Please download Malwarebytes Anti-Malware and save it to your desktop.
I am moving this to Am I Infected? -------------------- Mark
why won't my laptop work? Having grandkids is God's way of giving you a 2nd chance because you were too busy working your butt off the 1st time around Do not send me PMs with problems that should be posted in the forums. Keep it in the forums, so everyone benefits Become a BleepingComputer fan: Facebook and Twitter |
|
|
|
Jan 6 2009, 01:52 PM
Post
#3
|
|
|
Member ![]() ![]() Group: Members Posts: 18 Joined: 5-January 09 Member No.: 278,670 |
thanks for your fast reply... i did the malwarebytes scan using the link you gave me, this came up with no viruses: results: Malwarebytes' Anti-Malware 1.32 Database version: 1625 Windows 5.1.2600 Service Pack 3 06/01/2009 18:41:03 mbam-log-2009-01-06 (18-41-03).txt Scan type: Quick Scan Objects scanned: 66625 Time elapsed: 5 minute(s), 26 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) However, the AVG v.8 scan shows hundreds of viruses...although these could have been destroyed by AVG i'm sure there is still something up because whenever I use any search engine (google, Yahoo etc) I get weird results...namely the description seems appropriate for the search, but the web address is wrong (usually an ad or something) e.g: Barratts Shoes - Welcome! Features a range of shoes, boots and sandals in styles ranging from casual to formal. Includes care products, bags, and accessories. freescan.antivirus.com/shoes.html - 67k - Cached - Similar pages that was using google to search.. but I have no idea why it's doing this! i've run quite a few other antivirus scans in the last 2 days and AVG is the only one showing up these viruses... many thanks! |
|
|
|
Jan 6 2009, 05:53 PM
Post
#4
|
|
![]() Computer Masochist ![]() ![]() ![]() ![]() ![]() ![]() Group: Moderator Posts: 23,634 Joined: 27-January 07 From: Cleveland, Ohio Member No.: 108,618 |
ATF
Please download ATF Cleaner by Atribune & save it to your desktop.
Now SAS,may need an hour Please download and scan with SUPERAntiSpyware Free
Scan with SUPERAntiSpyware as follows:
-------------------- Mark
why won't my laptop work? Having grandkids is God's way of giving you a 2nd chance because you were too busy working your butt off the 1st time around Do not send me PMs with problems that should be posted in the forums. Keep it in the forums, so everyone benefits Become a BleepingComputer fan: Facebook and Twitter |
|
|
|
Jan 7 2009, 11:06 AM
Post
#5
|
|
![]() Computer Masochist ![]() ![]() ![]() ![]() ![]() ![]() Group: Moderator Posts: 23,634 Joined: 27-January 07 From: Cleveland, Ohio Member No.: 108,618 |
Topic reopened. Please post the results
-------------------- Mark
why won't my laptop work? Having grandkids is God's way of giving you a 2nd chance because you were too busy working your butt off the 1st time around Do not send me PMs with problems that should be posted in the forums. Keep it in the forums, so everyone benefits Become a BleepingComputer fan: Facebook and Twitter |
|
|
|
Jan 7 2009, 11:33 AM
Post
#6
|
|
|
Member ![]() ![]() Group: Members Posts: 18 Joined: 5-January 09 Member No.: 278,670 |
thanks.. results - nb. i also performed a superantispyware quick scan in normal mode after this one which detected and quarrantined one 'adware tracking cookie' virus... results for full scan in safe mode as follows: SUPERAntiSpyware Scan Log http://www.superantispyware.com Generated 01/07/2009 at 12:09 PM Application Version : 4.24.1004 Core Rules Database Version : 3688 Trace Rules Database Version: 1664 Scan type : Complete Scan Total Scan Time : 01:06:04 Memory items scanned : 177 Memory threats detected : 0 Registry items scanned : 5749 Registry threats detected : 0 File items scanned : 21000 File threats detected : 16 Adware.Tracking Cookie .atwola.com [ C:\Documents and Settings\Jane\Application Data\Mozilla\Firefox\Profiles\v6dgpaqh.default\cookies.txt ] .imrworldwide.com [ C:\Documents and Settings\Jane\Application Data\Mozilla\Firefox\Profiles\v6dgpaqh.default\cookies.txt ] .imrworldwide.com [ C:\Documents and Settings\Jane\Application Data\Mozilla\Firefox\Profiles\v6dgpaqh.default\cookies.txt ] .indextools.com [ C:\Documents and Settings\Jane\Application Data\Mozilla\Firefox\Profiles\v6dgpaqh.default\cookies.txt ] .keywordmax.com [ C:\Documents and Settings\Jane\Application Data\Mozilla\Firefox\Profiles\v6dgpaqh.default\cookies.txt ] .paypal.112.2o7.net [ C:\Documents and Settings\Jane\Application Data\Mozilla\Firefox\Profiles\v6dgpaqh.default\cookies.txt ] .roiservice.com [ C:\Documents and Settings\Jane\Application Data\Mozilla\Firefox\Profiles\v6dgpaqh.default\cookies.txt ] .xiti.com [ C:\Documents and Settings\Jane\Application Data\Mozilla\Firefox\Profiles\v6dgpaqh.default\cookies.txt ] anat.tacoda.net [ C:\Documents and Settings\Jane\Application Data\Mozilla\Firefox\Profiles\v6dgpaqh.default\cookies.txt ] server.iad.liveperson.net [ C:\Documents and Settings\Jane\Application Data\Mozilla\Firefox\Profiles\v6dgpaqh.default\cookies.txt ] server.iad.liveperson.net [ C:\Documents and Settings\Jane\Application Data\Mozilla\Firefox\Profiles\v6dgpaqh.default\cookies.txt ] server.iad.liveperson.net [ C:\Documents and Settings\Jane\Application Data\Mozilla\Firefox\Profiles\v6dgpaqh.default\cookies.txt ] sitestats.tiscali.co.uk [ C:\Documents and Settings\Jane\Application Data\Mozilla\Firefox\Profiles\v6dgpaqh.default\cookies.txt ] uk.sitestat.com [ C:\Documents and Settings\Jane\Application Data\Mozilla\Firefox\Profiles\v6dgpaqh.default\cookies.txt ] uk.sitestat.com [ C:\Documents and Settings\Jane\Application Data\Mozilla\Firefox\Profiles\v6dgpaqh.default\cookies.txt ] www.googleadservices.com [ C:\Documents and Settings\Jane\Application Data\Mozilla\Firefox\Profiles\v6dgpaqh.default\cookies.txt ] |
|
|
|
Jan 7 2009, 03:15 PM
Post
#7
|
|
![]() Computer Masochist ![]() ![]() ![]() ![]() ![]() ![]() Group: Moderator Posts: 23,634 Joined: 27-January 07 From: Cleveland, Ohio Member No.: 108,618 |
How is it running now?
-------------------------- Please reboot the computer Open MBAM and click Update tab, select Check for Updates,when done click Scanner tab,select FULL scan After scan click Remove Selected, Post new scan log for review -------------------- Mark
why won't my laptop work? Having grandkids is God's way of giving you a 2nd chance because you were too busy working your butt off the 1st time around Do not send me PMs with problems that should be posted in the forums. Keep it in the forums, so everyone benefits Become a BleepingComputer fan: Facebook and Twitter |
|
|
|
Jan 7 2009, 05:46 PM
Post
#8
|
|
|
Member ![]() ![]() Group: Members Posts: 18 Joined: 5-January 09 Member No.: 278,670 |
it seems to be running more smoothly thanks... no more peculiar results on internet search engines anyway! this was the result of the malware scan: Malwarebytes' Anti-Malware 1.32 Database version: 1629 Windows 5.1.2600 Service Pack 3 07/01/2009 22:28:14 mbam-log-2009-01-07 (22-28-14).txt Scan type: Full Scan (C:\|) Objects scanned: 140055 Time elapsed: 48 minute(s), 50 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) Assuming this means its all fixed (?) I had a few extra questions if thats ok - 1. should i run another superantispyware scan? 2. is it bad to have too many virus checks on a pc? 3. is linux immune to viruses? thanks again! |
|
|
|
Jan 7 2009, 09:07 PM
Post
#9
|
|
![]() Computer Masochist ![]() ![]() ![]() ![]() ![]() ![]() Group: Moderator Posts: 23,634 Joined: 27-January 07 From: Cleveland, Ohio Member No.: 108,618 |
t the current time Linux is not affected by viruses, but given time and increase popularity it will be inevitable
No it won't hurt anything Let's try this scan to make sure -------------------------------------------- Please download Dr.Web CureIt & save it to your desktop. DO NOT perform a scan yet. Reboot your computer in "Safe Mode" using the F8 method. To do this, restart your computer and after hearing your computer beep once during startup (but before the Windows icon appears) press the F8 key repeatedly. A menu will appear with several options. Use the arrow keys to navigate and select the option to run Windows in "Safe Mode". Scan with Dr.Web CureIt as follows:
-------------------- Mark
why won't my laptop work? Having grandkids is God's way of giving you a 2nd chance because you were too busy working your butt off the 1st time around Do not send me PMs with problems that should be posted in the forums. Keep it in the forums, so everyone benefits Become a BleepingComputer fan: Facebook and Twitter |
|
|
|
Jan 8 2009, 11:08 AM
Post
#10
|
|
|
Member ![]() ![]() Group: Members Posts: 18 Joined: 5-January 09 Member No.: 278,670 |
thanks...and sorry about the delayed reply - results: Process.exe;C:\Documents and Settings\Emily\Desktop\SmitfraudFix;Tool.Prockill;Incurable.Moved.; restart.exe;C:\Documents and Settings\Emily\Desktop\SmitfraudFix;Trojan.Shutdown.134;Deleted.; SDFix[1].exe\SDFix\apps\Process.exe;C:\Documents and Settings\Emily\Local Settings\Temporary Internet Files\Content.IE5\3O8SH2YY\SDFix[1].exe;Tool.Prockill;; SDFix[1].exe;C:\Documents and Settings\Emily\Local Settings\Temporary Internet Files\Content.IE5\3O8SH2YY;Archive contains infected objects;Moved.; SDFix[1].exe\SDFix\apps\Process.exe;C:\Documents and Settings\Emily\Local Settings\Temporary Internet Files\Content.IE5\GB2X3GUY\SDFix[1].exe;Tool.Prockill;; SDFix[1].exe;C:\Documents and Settings\Emily\Local Settings\Temporary Internet Files\Content.IE5\GB2X3GUY;Archive contains infected objects;Moved.; data002\32788R22FWJFW\psexec.cfexe;C:\Documents and Settings\Emily\My Documents\ComboFix.exe\data002;Program.PsExec.171;; data002;C:\Documents and Settings\Emily\My Documents\ComboFix.exe;Archive contains infected objects;; ComboFix.exe;C:\Documents and Settings\Emily\My Documents;Archive contains infected objects;Moved.; SDFix.exe\SDFix\apps\Process.exe;C:\Documents and Settings\Emily\My Documents\SDFix.exe;Tool.Prockill;; SDFix.exe;C:\Documents and Settings\Emily\My Documents;Archive contains infected objects;Moved.; Process.exe;C:\SDFix\apps;Tool.Prockill;Incurable.Moved.; |
|
|
|
Jan 8 2009, 05:06 PM
Post
#11
|
|
![]() Computer Masochist ![]() ![]() ![]() ![]() ![]() ![]() Group: Moderator Posts: 23,634 Joined: 27-January 07 From: Cleveland, Ohio Member No.: 108,618 |
How is it running now?
-------------------- Mark
why won't my laptop work? Having grandkids is God's way of giving you a 2nd chance because you were too busy working your butt off the 1st time around Do not send me PMs with problems that should be posted in the forums. Keep it in the forums, so everyone benefits Become a BleepingComputer fan: Facebook and Twitter |
|
|
|
Jan 9 2009, 04:50 AM
Post
#12
|
|
|
Member ![]() ![]() Group: Members Posts: 18 Joined: 5-January 09 Member No.: 278,670 |
it's running well now i think, although its not letting me send emails or open some links..could this be something to do with the antispy progs i have running, or do i need to change a setting? Also i wasn't sure what 'moved' meant on the previous log - does this mean the viruses have gone? thanks again |
|
|
|
Jan 9 2009, 06:48 PM
Post
#13
|
|
![]() Computer Masochist ![]() ![]() ![]() ![]() ![]() ![]() Group: Moderator Posts: 23,634 Joined: 27-January 07 From: Cleveland, Ohio Member No.: 108,618 |
At one point in time, someone ran SD Fix and combofix. All of those files that say "moved" are leftovers from them
QUOTE antispy progs i have running Do any of the programs you use monitor registry changes, like Spybot S&D's Teatimer? They need to be disabled. ---------------------------------- Humor me and try this one more time Please reboot the computer Open MBAM and click Update tab, select Check for Updates,when done click Scanner tab,select FULL scan After scan click Remove Selected, Post new scan log for review -------------------- Mark
why won't my laptop work? Having grandkids is God's way of giving you a 2nd chance because you were too busy working your butt off the 1st time around Do not send me PMs with problems that should be posted in the forums. Keep it in the forums, so everyone benefits Become a BleepingComputer fan: Facebook and Twitter |
|
|
|
Jan 10 2009, 06:54 AM
Post
#14
|
|
|
Member ![]() ![]() Group: Members Posts: 18 Joined: 5-January 09 Member No.: 278,670 |
I previously ran SDFix, but wasn't sure if this worked properly, and had downloaded Combofix to the PC but never actually used it. I have Spybot S&D on pc - so should i remove it from pc altogether? I have now disabled Registry mechanic and am not using teatimer... results of MBAM: Malwarebytes' Anti-Malware 1.32 Database version: 1637 Windows 5.1.2600 Service Pack 3 10/01/2009 11:47:56 mbam-log-2009-01-10 (11-47-56).txt Scan type: Full Scan (C:\|) Objects scanned: 142992 Time elapsed: 50 minute(s), 27 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) So if these are leftovers, are the viruses now gone? cheers! |
|
|
|
Jan 10 2009, 11:48 AM
Post
#15
|
|
![]() Computer Masochist ![]() ![]() ![]() ![]() ![]() ![]() Group: Moderator Posts: 23,634 Joined: 27-January 07 From: Cleveland, Ohio Member No.: 108,618 |
QUOTE its not letting me send emails or open some links If you are still having these problems then I'm going to suggest that you follow the instructions and prepare a HJT log, here:http://www.bleepingcomputer.com/forums/topic34773.html Then post the log in the proper form here: http://www.bleepingcomputer.com/forums/forum22.html Our team members are rather busy, so it may take a while to get to you Be patient and good luck -------------------- Mark
why won't my laptop work? Having grandkids is God's way of giving you a 2nd chance because you were too busy working your butt off the 1st time around Do not send me PMs with problems that should be posted in the forums. Keep it in the forums, so everyone benefits Become a BleepingComputer fan: Facebook and Twitter |
|
|
|
![]() ![]() |
| Lo-Fi Version | Time is now: 21st November 2009 - 11:18 PM |