Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.
Posted 19 October 2010 - 04:34 PM
Edited by hamluis, 19 October 2010 - 06:14 PM.
Moved from XP forum to Am I Infected ~ Hamluis.
Posted 19 October 2010 - 05:21 PM
Posted 19 October 2010 - 05:43 PM
Posted 19 October 2010 - 08:56 PM
Backdoors and What They Mean to YouWhenever a system has been compromised by a backdoor payload, it is impossible to know if or how much the backdoor has been used to affect your system...There are only a few ways to return a compromised system to a confident security configuration. These include:
• Reimaging the system
• Restoring the entire system using a full system backup from before the backdoor infection
• Reformatting and reinstalling the system
The only way to clean a compromised system is to flatten and rebuild. That’s right. If you have a system that has been completely compromised, the only thing you can do is to flatten the system (reformat the system disk) and rebuild it from scratch (reinstall Windows and your applications).

Posted 19 October 2010 - 09:12 PM
There's a good chance that this is incurable, however after I post the standard warning please run the Kasp scan if you would.
http://www.bleepingcomputer.com/forums/topic353399.html/page__view__findpost__p__1974286
http://www.kaspersky.com/virusscanner
Please go to the Kaspersky website and perform an online antivirus scan.
Read through the requirements and privacy statement and click on Accept button.
It will start downloading and installing the Scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
When the downloads have finished, click on Settings.
Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
Spyware, Adware, Dialers, and other potentially dangerous programs
Archives
Click on My Computer under Scan.
Once the scan is complete, it will display the results. Click on View Scan Report.
You will see a list of infected items there. Click on Save Report As....
Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
Please post this log in your next reply.
Posted 19 October 2010 - 09:21 PM
Edited by Elusival, 19 October 2010 - 09:25 PM.
Posted 19 October 2010 - 09:40 PM

Posted 19 October 2010 - 10:09 PM
Posted 19 October 2010 - 11:41 PM
Edited by Elusival, 19 October 2010 - 11:43 PM.
Posted 20 October 2010 - 12:01 AM
Posted 20 October 2010 - 12:37 AM
Edited by Elusival, 20 October 2010 - 12:55 AM.
Posted 20 October 2010 - 01:05 AM
C:\Documents and Settings\computer\My Documents\My Music\other music\Oedipus.mp3 a variant of WMA/TrojanDownloader.GetCodec.gen trojan cleaned - quarantined
C:\Documents and Settings\computer\My Documents\My Music\Rock\One step Closer.mp3 a variant of WMA/TrojanDownloader.GetCodec.gen trojan cleaned - quarantined
Posted 20 October 2010 - 01:41 AM
C:\Documents and Settings\computer\My Documents\My Music\other music\Oedipus.mp3 a variant of WMA/TrojanDownloader.GetCodec.gen trojan cleaned - quarantined
C:\Documents and Settings\computer\My Documents\My Music\Rock\One step Closer.mp3 a variant of WMA/TrojanDownloader.GetCodec.gen trojan cleaned - quarantined
When you try to play these, they give you a popup to download a codec for media player which is really a trojan downloader, and there you are reinfected again.
http://www.magicaljellybean.com/keyfinder/ will retrieve your XP key
Edited by Elusival, 20 October 2010 - 01:51 AM.
Posted 20 October 2010 - 01:59 AM
Posted 20 October 2010 - 08:09 AM

0 members, 0 guests, 0 anonymous users