PDA

View Full Version : Smitfraud-c AND virtumonde?



gilmourfam
2007-12-23, 22:04
I have been having lots of trouble lately with pop ups all the time. Most of them say powered by Zedo. I scanned with Spybot. It found Smitfraud-C and another virus called Command something. It didn't find anything about winfixer. It showed that these things were in my registry keys, my documents, and just about everywhere else. It couldn't remove these particular items for some reason. Then I re-started in safe mode and ran the Spybot S&D program again. This time it said successfully removed. When I re-started in normal mode a box came up that was like the computer was trying to find some files that were gone. (only saw that once or twice. It has since stopped). Anyway, though S&D says the infection has been removed, when I get online there are about a billion pop ups, the kind that try to trick you. When it says "Your computer could be infected by spyware, click here to run the scan". If you click cancel it goes to the webpage or starts the scan. Most of these say winfixer 2007. I ran Vundofix and it seems to have erased some of the files.

Please Please Please help. I have ran a Kopersky log and it is too long to post here.

Your help is greatly appreciated.

Shaba
2007-12-25, 11:14
Hi gilmourfam

Click here (http://www.trendsecure.com/portal/en-US/threat_analytics/HJTInstall.exe) to download HJTInstall.exe
Save HJTInstall.exe to your desktop.
Doubleclick on the HJTInstall.exe icon on your desktop.
By default it will install to C:\Program Files\Trend Micro\HijackThis .
Click on Install.
It will create a HijackThis icon on the desktop.
Once installed, it will launch Hijackthis.
Click on the Do a system scan and save a logfile button. It will scan and the log should open in notepad.
Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log.
Come back here to this thread and Paste the log in your next reply.
DO NOT use the AnalyseThis button, its findings are dangerous if misinterpreted.
DO NOT have Hijackthis fix anything yet. Most of what it finds will be harmless or even required.

Shaba
2008-01-01, 10:48
Due to the lack of feedback this Topic is closed.

If you need this topic reopened, please request this by sending the moderating team
a PM with the address of the thread. This applies only to the original topic starter.

If it had been 10 days or more since your last post, and especially if the helper assisting you posted a response to that post to which you did not reply, the topic will not be reopened.

In that situation, if you still require help, it would be best to start a new topic and include a fresh HijackThis log with a link to your original thread.

Everyone else please begin a New Topic.