Free PC Performance Scan

Member Panel



Join the PC Help Forum Team

Join PC Help Forum on Facebook

Join the PCHF Distributed Computing Teams

Try the NEW PC Help Forum Dark style

Link to PCHF from other parts of the Internet
[Fixed] Hijackthis! Logs - [Resolved] SpyMarshal posted in the Security & Safety forums; Alrighty, updates! Attached is what he sent me...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #8  
Old 01-10-2007
Not here.
 
Join Date: Sep 2005
Posts: 1,488
PC Experience: N/A
DarkLord7854 - See this Members User comments on their Profile page DarkLord7854 - See this Members User comments on their Profile page DarkLord7854 - See this Members User comments on their Profile page DarkLord7854 - See this Members User comments on their Profile page DarkLord7854 - See this Members User comments on their Profile page DarkLord7854 - See this Members User comments on their Profile page DarkLord7854 - See this Members User comments on their Profile page DarkLord7854 - See this Members User comments on their Profile page DarkLord7854 - See this Members User comments on their Profile page DarkLord7854 - See this Members User comments on their Profile page DarkLord7854 - See this Members User comments on their Profile page
Default

Alrighty, updates!

Attached is what he sent me


  #9  
Old 01-10-2007
chiaz's Avatar
Senior Security Analyst
 
Join Date: Jun 2006
Location: Singapore
Posts: 2,866
PC Experience: PC Guru
chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page
Default

You should now get your friend to print out these instructions, or copy them to a Notepad file for reading while in Safe Mode, because he will not be able to connect to the Internet to read from this site.

Please reboot the computer in Safe Mode by doing the following :
  • Restart the computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, a menu with options should appear;
  • Select the first option, to run Windows in Safe Mode, then press "Enter".
  • Choose the usual account.
Once in Safe Mode, open the SmitfraudFix folder again and double-click smitfraudfix.cmd
Select option #2 - Clean by typing 2 and press "Enter" to delete infected files.

There will be a prompt : "Registry cleaning - Do you want to clean the registry ?"; answer "Yes" by typing Y and press "Enter" in order to remove the Desktop background and clean registry keys associated with the infection.

The tool will now check if wininet.dll is infected. He may be prompted to replace the infected file (if found); answer "Yes" by typing Y and press "Enter".


The tool may need to restart the computer to finish the cleaning process; if it doesn't, please restart anyway into normal Windows. A text file will appear onscreen, with results from the cleaning process; please copy/paste the content of that report into your next reply along with a new HijackThis log.
The report can also be found at the root of the system drive, usually at C:\rapport.txt

Warning : running option #2 on a non infected computer will remove your Desktop background.


  #10  
Old 01-11-2007
Not here.
 
Join Date: Sep 2005
Posts: 1,488
PC Experience: N/A
DarkLord7854 - See this Members User comments on their Profile page DarkLord7854 - See this Members User comments on their Profile page DarkLord7854 - See this Members User comments on their Profile page DarkLord7854 - See this Members User comments on their Profile page DarkLord7854 - See this Members User comments on their Profile page DarkLord7854 - See this Members User comments on their Profile page DarkLord7854 - See this Members User comments on their Profile page DarkLord7854 - See this Members User comments on their Profile page DarkLord7854 - See this Members User comments on their Profile page DarkLord7854 - See this Members User comments on their Profile page DarkLord7854 - See this Members User comments on their Profile page
Default

Alright, he says everything is back to normal, BUT, SpyMarhsall re-installed itself again


Thanks for the help
Almost done w00t


Logs are attached


  #11  
Old 01-11-2007
chiaz's Avatar
Senior Security Analyst
 
Join Date: Jun 2006
Location: Singapore
Posts: 2,866
PC Experience: PC Guru
chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page
Default

Was the HijackThis log above ran before/after your friend reported that SpyMarshall reinstalled itself? I don't see any sign of the smitfraud installation in the new log that you posted...


  #12  
Old 01-12-2007
Not here.
 
Join Date: Sep 2005
Posts: 1,488
PC Experience: N/A
DarkLord7854 - See this Members User comments on their Profile page DarkLord7854 - See this Members User comments on their Profile page DarkLord7854 - See this Members User comments on their Profile page DarkLord7854 - See this Members User comments on their Profile page DarkLord7854 - See this Members User comments on their Profile page DarkLord7854 - See this Members User comments on their Profile page DarkLord7854 - See this Members User comments on their Profile page DarkLord7854 - See this Members User comments on their Profile page DarkLord7854 - See this Members User comments on their Profile page DarkLord7854 - See this Members User comments on their Profile page DarkLord7854 - See this Members User comments on their Profile page
Default

He said he did it after all the scans and doing everything you posted above


  #13  
Old 01-13-2007
chiaz's Avatar
Senior Security Analyst
 
Join Date: Jun 2006
Location: Singapore
Posts: 2,866
PC Experience: PC Guru
chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page
Default

eatu4tea has pmed me and inform me that he's unable to reply to this thread for some reason.

Please hold on - while I contact Hengis (the admin) to see if something can be resolved.



Reply
Satellite TV on your PC - over 3000 Channels! Click Here!

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On

All times are GMT +1. The time now is 08:34 AM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top