Computers |
|
| | #1 (permalink) | |
| Junior Techie | Hey guys. Recently I've been doing tech-support for my in-laws as somehow their computer's been infected with something. I've run Anti-virus and Spybot (both fully up-to-date), I've run CCleaner (which thankfully sped up the machine and made it tolerable to work with). From what I can tell it's spyware, doing things like pop ups, changing the background to an anti-virus advert and all around making an already tedious experience (they're still surfing on dial-up) even more tedious. So I poked around the forums here and found the HijackThis link and thought I'd give it a try and see if you guys could help me out. Here's the Log: Quote:
![]() Thanks in advance for the help.
__________________ ![]() ![]() | |
| | |
| | #2 (permalink) |
| Super Techie | Well, with that much wrong with it, the malware has already had time to firmly attach itself to the system registry. The best bet at this point is to backup the machine, rebuild the system, and lock it down while it's clean and save a restore point. It sucks doing that I know.... but it'll be a lot less work than trying to clean that up. Hope that helps ![]() |
| | |
| | #3 (permalink) |
| Junior Techie | Well, I can't say I'm surprised. I told my mother-in-law just yesterday that that was likely to be the best solution. She said that that was Okay, it was just me that was hoping to save the system and what they have saved on it. Anyway, thanks for the help.
__________________ ![]() ![]() |
| | |
| | #4 (permalink) |
| Super Techie | Hello digital_ninja2k, There seems to be a great amount of infection in that computer so we are going to take some of it out in this post. We'll start gathering information later, as I suspect my log scanning tools won't work in these conditions. Just as a note your following infections that I have identified are as follows: Trojan.Zlob and Smitfraud Step1 Please download SDFix from HERE. Double click SDFix.exe and it will extract the files to %systemdrive% (Drive that contains the Windows Directory, typically C:\SDFix) Please then reboot your computer in Safe Mode by doing the following :
Step2 Please download SmitfraudFix (by S!Ri) to your Desktop. Double-click SmitfraudFix.exe Select option #1 - Search by typing 1 and press "Enter"; a text file will appear, which lists infected files (if present). Please copy/paste the content of that report into your next reply. **If the tool fails to launch from the Desktop, please move SmitfraudFix.exe directly to the root of the system drive (usually C:), and launch from there. Note : process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user. http://www.beyondlogic.org/consulting/proc...processutil.htm Step3 Does this company ring a bell for you: TELUS Communications Inc. Items Needed In Next Post ---------------------------- SDFix Log SmitFraud Fix Log Answer To Step 3 Question
__________________ Kind Regards, Techpro5238 Last edited by techpro5238; 05-10-2008 at 05:25 PM. Reason: Removal of ComboFix Sentence (Just Grammar) |
| | |
| | #6 (permalink) |
| Junior Techie | Great. Saving the system is the preferred method for me. If it comes to that my mother-in-law is prepared but I get 'Super-Techie-Son-in-Law' points if I can save it for her. As soon as I get the chance I'll run those scans and get back to you with the information. Do you have a link to download SDFix or should I just google it? (wanna make sure I get the right thing) As for #3, I can answer that. TELUS Communications does sound familiar, my wife's cell phone is through them I believe. Other than that I'm not really sure. TELUS seems to be a Canadian thing that I'd never even heard of until I came up here. Why, are they part of the problem?
__________________ ![]() ![]() |
| | |
| | #9 (permalink) |
| Lurker Techie | Spyware Removal Guide By Osiris Can also try this, as Osiris is making his own malware scanner (see how well it does; he wants feedback on it . ) Osiris Spyware Scanner Download Beta 1
__________________ Desktop: /Antec 900..................................Intel e6750 @ 3.53GHz\ /Arctic Cooling Freezer 7 Pro.....GigaByte GA-P35-DS3R mobo\ /2x1GB G.Skill/2x1GB OCZ Gold DDR2-800 @ 5-5-5-15, 441MHz\ \EVGA 8800GT 512MB @ 730/1000........OCZ GameXStream 700w/ \19" Hanns-G Widescreen LCD..............19" AOC Fullscreen CRT/ \SeaGate 500GB/320GB; Maxtor 160GB external; W.D. 160GB/ Laptop: Compaq C769US 3DMark06 Score: 13700 | carnageX | e6750 @ 3.53GHz | 8800GT 512MB @ 760/1080 | XP Home 32bit |
| | |
![]() |
| Thread Tools | |
| Display Modes | |
| |
Similar Threads | ||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Browser Bugs - Need someone to take a look | superair210 | HijackThis Logs (finished) | 10 | 04-26-2008 01:41 AM |
| Need steps for getting rid of SystemDefender.exe | Trotter | Virus - Spyware Protection / Detection | 16 | 04-07-2008 10:57 PM |
| Virus infected system! | hobo_man | Virus - Spyware Protection / Detection | 2 | 02-01-2008 11:26 PM |
| How Do The Professionals Remove Viruses From Infected Computer? | BKSinAZ | Virus - Spyware Protection / Detection | 5 | 05-14-2007 01:27 AM |