Member Panel


Sponsors and Ads

Join the Team

Live Tag Cloud

PC Forum PC Help Forum » Security & Safety » [Fixed] Hijackthis! Logs » [Fixed] virus problem..!

[Fixed] Hijackthis! Logs - [Fixed] virus problem..! posted in the Security & Safety forums; After seaching trough the computer for virus with several anti-virus and anti-spam programs i still cant get this problem solved.. down in the left corner its blinking an icon with ...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #1  
Old 06-17-2006
z8n's Avatar
z8n z8n is offline
Bronze Member
 
Join Date: Jun 2006
Posts: 5
z8n - See this Members User comments on their Profile page
Default [Fixed] virus problem..!

After seaching trough the computer for virus with several anti-virus and anti-spam programs i still cant get this problem solved..
down in the left corner its blinking an icon with a virus-alert, and it wont go away.. When i open the internett browser its pops up a warning that my maskine have been affected by a virus called "w32.myzor.fkyf"... Problem is that i cant find it!!>.< hope you can find the problem.. I saw another tread with kinda the same problem, but i wanted to make sure i got rid of the right files so i made my own tread..

heres the other tread btw:
http://www.pchelpforum.com/spyware-a...ous-scans.html
Attached Files
File Type: txt hijackthis.txt (21.4 KB, 3 views)
File Type: txt Scan report_20060617.txt.txt (12.5 KB, 2 views)



Last edited by z8n; 06-17-2006 at 05:45 PM.
  #2  
Old 06-17-2006
sbowler's Avatar
Bronze Member
My PC
 
Join Date: Mar 2006
Location: west yorks. Leeds
Posts: 180
sbowler - See this Members User comments on their Profile page
Default

Have you booted in safe mode and ran all scans?


  #3  
Old 06-17-2006
z8n's Avatar
z8n z8n is offline
Bronze Member
 
Join Date: Jun 2006
Posts: 5
z8n - See this Members User comments on their Profile page
Default

Originally Posted by sbowler
Have you booted in safe mode and ran all scans?
yea.. tried it like 3 times now..


  #4  
Old 06-17-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,044
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Hya Z8n , welcome to PCHF.




Download SmitfraudFix (by S!Ri)
Extract the content (a folder named SmitfraudFix) to your Desktop.

Then boot up in safemode (hit f8 when booting up)

Once in Safe Mode, open the SmitfraudFix folder and double-click smitfraudfix.cmd
Select option #2 - Clean by typing 2 and press "Enter" to delete infected files.

You will be prompted : "Registry cleaning - Do you want to clean the registry ?"; answer "Yes" by typing Y and press "Enter" in order to remove the Desktop background and clean registry keys associated with the infection.

The tool will now check if wininet.dll is infected. You may be prompted to replace the infected file (if found); answer "Yes" by typing Y and press "Enter".

The tool may need to restart your computer to finish the cleaning process; if it doesn't, please restart it into Normal Windows.
A text file will appear onscreen, with results from the cleaning process; please attach that report to your next reply.
The report can also be found at the root of the system drive, usually at C:\rapport.txt


And i would also recommend to uninstall Logitech Desktop Messenger in add/remove programs.

When done , post a new hjt log , and the Smitfraud log (C:\rapport.txt ) please.


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #5  
Old 06-18-2006
z8n's Avatar
z8n z8n is offline
Bronze Member
 
Join Date: Jun 2006
Posts: 5
z8n - See this Members User comments on their Profile page
Default

Thanks for the help, and a quick reply!
I did as you said, and also removed the LogithecDeskopManager^^

Im recommending this site to my friends as i was very impressed by the logfile-system, and the fast and detailed replies.
Attached Files
File Type: txt hijackthis.txt (9.6 KB, 1 views)
File Type: txt rapport.txt (1.7 KB, 1 views)


  #6  
Old 06-18-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,044
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Thanks for the compliment.


You have uninstalled Spywaredocter it seems? If not , then it is probebly damaged and would need to be reinstalled.
But since you are already using Windows defender i wouldn't recommend to reinstall it as that could cause conflict and performence problems.


Boot in safemode (hit f8 when booting up)


Click Start>Run and type in: services.msc
Click OK
In the Services window find: PC Tools Spyware Doctor
Select/highlight and right click the entry, and choose: Properties
On the General tab, under Service Status click the Stop button
Beside: Startup Type, in the drop menu, select: Disabled
Click Apply, then OK

Open HJT and click config > misc tools > “delete an NT service”
Copy and past: SDhelper
Click OK.

Then fix these entrys with hjt:
(if still present)

O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll (file missing)
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll (file missing)
O2 - BHO: Great Offers Displayer - {CE05B815-6F98-4ADD-AEB7-60BB2D4264F1} - c:\WINDOWS\bh.dll (file missing)
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll (file missing)
O23 - Service: PC Tools Spyware Doctor (SDhelper) - Unknown owner - C:\Programfiler\Spyware Doctor\sdhelp.exe (file missing)
After that reboot , and post a new hjt log please.


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -


Last edited by joe5; 06-18-2006 at 01:29 AM.

Reply
Satellite TV on your PC - over 3000 Channels! Click Here!

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On


All times are GMT +1. The time now is 05:05 PM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top