Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Malworm slowed my computer


  • This topic is locked This topic is locked
3 replies to this topic

#1 kurd

kurd

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:01:30 PM

Posted 06 December 2008 - 08:35 PM

I am a new member and this is the first time that I posting. Please forgive my lack of exp.I have scanned my computer and this smitfraud c malworm keeps showing up after each boot up. and I use spybot to remove it and shows up again. I have my hijakthis log for member of hijak this team to view it. Thanks

Attached Files



BC AdBot (Login to Remove)

 


#2 kurd

kurd
  • Topic Starter

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:01:30 PM

Posted 13 December 2008 - 07:26 PM

I am a new member and this is the first time that I posting. Please forgive my lack of exp.I have scanned my computer and this smitfraud c malworm keeps showing up after each boot up. and I use spybot to remove it and shows up again. I have my hijakthis log for member of hijak this team to view it. Thanks


SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 12/11/2008 at 09:37 PM

Application Version : 4.23.1006

Core Rules Database Version : 3671
Trace Rules Database Version: 1650

Scan type : Complete Scan
Total Scan Time : 04:40:03

Memory items scanned : 170
Memory threats detected : 0
Registry items scanned : 9365
Registry threats detected : 9
File items scanned : 102099
File threats detected : 41

Adware.MyWebSearch
HKU\S-1-5-21-1390067357-1935655697-682003330-1003

\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00A6FAF1-072E-44CF-8957-5838F569A31D}
HKU\S-1-5-21-1390067357-1935655697-682003330-1003\Software\Microsoft\Internet

Explorer\Toolbar\ShellBrowser#{07B18EA9-A523-4961-B6BB-170DE4475CCA}

Unclassified.Unknown Origin
HKU\S-1-5-21-1390067357-1935655697-682003330-1003

\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{13197ACE-6851-45C3-A7FF-C281324D5489}
HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{9B4AA442-9EBF-11D5-8C11

-0050DA4957F5}

Adware.IST/YourSiteBar
HKU\S-1-5-21-1390067357-1935655697-682003330-1003

\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{86227D9C-0EFE-4F8A-AA55-30386A3F5686}

Adware.Vundo Variant
HKU\S-1-5-21-1390067357-1935655697-682003330-1003

\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F919FBD3-A96B-4679-AF26-F551439BB5FD}

Adware.Tracking Cookie
C:\Documents and Settings\Atoofi\Cookies\atoofi@revsci[1].txt
C:\Documents and Settings\Atoofi\Cookies\atoofi@server.iad.liveperson[2].txt
C:\Documents and Settings\Atoofi\Cookies\atoofi@www.googleadservices[2].txt
C:\Documents and Settings\Atoofi\Cookies\atoofi@www.googleadservices[8].txt
C:\Documents and Settings\Atoofi\Cookies\atoofi@www.googleadservices[3].txt
C:\Documents and Settings\Atoofi\Cookies\atoofi@tacoda[2].txt
C:\Documents and Settings\Atoofi\Cookies\atoofi@www.googleadservices[11].txt
C:\Documents and Settings\Atoofi\Cookies\atoofi@CAEQSJGG.txt
C:\Documents and Settings\Atoofi\Cookies\atoofi@interclick[1].txt
C:\Documents and Settings\Atoofi\Cookies\atoofi@track.bestbuy[1].txt
C:\Documents and Settings\Atoofi\Cookies\atoofi@yadro[1].txt
C:\Documents and Settings\Atoofi\Cookies\atoofi@www.googleadservices[7].txt
C:\Documents and Settings\Atoofi\Cookies\atoofi@server.iad.liveperson[5].txt
C:\Documents and Settings\Atoofi\Cookies\atoofi@ads4.slickdeals[2].txt
C:\Documents and Settings\Atoofi\Cookies\atoofi@stat.onestat[2].txt
C:\Documents and Settings\Atoofi\Cookies\atoofi@adserver.easyadult[1].txt
C:\Documents and Settings\Atoofi\Cookies\atoofi@server.iad.liveperson[4].txt
C:\Documents and Settings\Atoofi\Cookies\atoofi@www.googleadservices[4].txt
C:\Documents and Settings\Atoofi\Cookies\atoofi@CA2TD9EK.txt
C:\Documents and Settings\Atoofi\Cookies\atoofi@CAME7XB5.txt
C:\Documents and Settings\Atoofi\Cookies\atoofi@trafficdashboard[2].txt
C:\Documents and Settings\Atoofi\Cookies\atoofi@CA8OJ0WK.txt
C:\Documents and Settings\Atoofi\Cookies\atoofi@CAAURPY0.txt
C:\Documents and Settings\Atoofi\Cookies\atoofi@indextools[2].txt
C:\Documents and Settings\Atoofi\Cookies\atoofi@www.belstat[1].txt
C:\Documents and Settings\Atoofi\Cookies\atoofi@ero-advertising[2].txt
C:\Documents and Settings\Atoofi\Cookies\atoofi@www.googleadservices[5].txt
C:\Documents and Settings\Atoofi\Cookies\atoofi@findarticles[2].txt
C:\Documents and Settings\Atoofi\Cookies\atoofi@ads.madisonavenue[2].txt
C:\Documents and Settings\Atoofi\Cookies\atoofi@www.googleadservices[6].txt
C:\Documents and Settings\Atoofi\Cookies\atoofi@www.googleadservices[9].txt
C:\Documents and Settings\Atoofi\Cookies\atoofi@www.googleadservices[1].txt
C:\Documents and Settings\Atoofi\Cookies\atoofi@www.justsexyvideos[1].txt
C:\Documents and Settings\Atoofi\Cookies\atoofi@www.googleadservices[10].txt
C:\Documents and Settings\Atoofi\Cookies\atoofi@adopt.euroclick[2].txt
C:\Documents and Settings\Atoofi\Cookies\atoofi@ads.crakmedia[2].txt
C:\Documents and Settings\Atoofi\Cookies\atoofi@a.findarticles[2].txt
C:\Documents and Settings\Atoofi\Cookies\atoofi@server.iad.liveperson[3].txt
C:\Documents and Settings\Atoofi\Cookies\atoofi@ads.imagebeaver[1].txt
C:\Documents and Settings\Atoofi\Cookies\atoofi@workersexpress[2].txt
C:\Documents and Settings\Atoofi\Cookies\atoofi@ads.madisonavenue[1].txt

Adware.MyWebSearch/FunWebProducts
HKCR\CLSID\{9AFB8248-617F-460d-9366-D71CDEDA3179}
HKCR\CLSID\{9AFB8248-617F-460d-9366-D71CDEDA3179}\TreatAs

Trojan.Unclassified/MSFox
HKU\S-1-5-21-1390067357-1935655697-682003330-1003

\Software\Microsoft\Windows\CurrentVersion\Run#MSFox [ C:\DOCUME~1\Atoofi\LOCALS~1

\Temp\video234.cfg.exe ]

#3 suebaby41

suebaby41

    W.A.M. (Women Against Malware)


  • Malware Response Team
  • 6,248 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:South Carolina, USA
  • Local time:02:30 PM

Posted 16 December 2008 - 09:16 AM

We apologize for the delay in responding to your request for help. We are volunteer staff at Bleeping Computer and get overwhelmed at times with the large number of users seeking help. We are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help.

If you have since resolved the original problem you were having, we would appreciate your letting us know. If not, please perform the following steps so we can have a look at the current condition of your computer. If you have not done so, include a description of your problem along with any steps you may have performed so far.

When you have completed the steps below, a staff member will review the log and provide instructions for you to get your computer clean and free of malware.

Thanks and we apologize for the delay.

We need to see current information on what is happening in your computer. Please perform the following scan:
  • Please download DDS by sUBs from one of the following links. Save it to your desktop.
  • After downloading the tool:
  • Double click on the DDS icon, allow it to run. Please note: If the scan fails to run, you may have to disable any script protection running.
  • A small box, which gives an explanation about the tool, will open. No input is needed, the scan is running.
  • Notepad will open with the results, click No to the Optional_Scan.
  • Follow the instructions that pop up for posting the results.
  • Close the program window and delete the program from your desktop.
  • Enable your antivirus and anti-spyware protection.
  • Reconnect to the Internet.

You don't stop laughing when you get old; you get old when you stop laughing.
A Member of U-N-I-T-E (Unified Network of Instructors and Trained Eliminators)
Malware Removal University Masters Graduate

Posted Image
Join The Fight Against Malware
No reply within 5 days will result in your topic being closed. If you need more time, please let me know by posting in this topic so that your topic will not be closed.

#4 suebaby41

suebaby41

    W.A.M. (Women Against Malware)


  • Malware Response Team
  • 6,248 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:South Carolina, USA
  • Local time:02:30 PM

Posted 21 December 2008 - 02:42 PM

This subject is now closed. If you need this topic reopened, please contact a member of the HJT Team and we will reopen it for you. Include the address of this thread in your request. If you should have a new issue, please start a new topic. This applies only to the original topic starter. Everyone else please begin a New Topic.
You don't stop laughing when you get old; you get old when you stop laughing.
A Member of U-N-I-T-E (Unified Network of Instructors and Trained Eliminators)
Malware Removal University Masters Graduate

Posted Image
Join The Fight Against Malware
No reply within 5 days will result in your topic being closed. If you need more time, please let me know by posting in this topic so that your topic will not be closed.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users