help fraud.internetsecurity2011
Hi everybody! I got this malware and I tried to clean my pc with spybot. It cleaned almost everything in the registry but some entries that I can't delete even making spybot starting at boot. this is the results log of spybot:
--- Search result list ---
Fraud.InternetSecurity2011: [SBI $D14AADAC] Impostazioni (Chiave di registro, fixing failed)
HKEY_LOCAL_MACHINE\System\ControlSet001\Enum\Root\LEGACY_USERINIT\0000
Fraud.InternetSecurity2011: [SBI $D3A45776] Impostazioni (Chiave di registro, fixing failed)
HKEY_LOCAL_MACHINE\System\ControlSet002\Enum\Root\LEGACY_USERINIT\0000
Fraud.InternetSecurity2011: [SBI $95A8AE49] Impostazioni (Chiave di registro, fixing failed)
HKEY_LOCAL_MACHINE\System\ControlSet001\Enum\Root\LEGACY_USERINIT
Fraud.InternetSecurity2011: [SBI $DF31D93D] Impostazioni (Chiave di registro, fixing failed)
HKEY_LOCAL_MACHINE\System\ControlSet002\Enum\Root\LEGACY_USERINIT
--- Spybot - Search & Destroy version: 1.6.2 (build: 20090126) ---
2009-01-26 blindman.exe (1.0.0.8)
2009-01-26 SDFiles.exe (1.6.1.7)
2009-01-26 SDMain.exe (1.0.0.6)
2009-01-26 SDShred.exe (1.0.2.5)
2009-01-26 SDUpdate.exe (1.6.0.12)
2009-01-26 SpybotSD.exe (1.6.2.46)
2009-03-05 TeaTimer.exe (1.6.6.32)
2004-04-27 unins000.exe (51.13.0.0)
2009-04-05 unins001.exe (51.49.0.0)
2009-01-26 Update.exe (1.6.0.7)
2009-11-04 advcheck.dll (1.6.5.20)
2007-04-02 aports.dll (2.1.0.0)
2004-05-12 borlndmm.dll (7.0.4.453)
2004-05-12 delphimm.dll (7.0.4.453)
2008-06-14 DelZip179.dll (1.79.11.1)
2009-01-26 SDHelper.dll (1.6.2.14)
2008-06-19 sqlite3.dll
2009-01-26 Tools.dll (2.1.6.10)
2009-01-16 UninsSrv.dll (1.0.0.0)
2004-05-12 UnzDll.dll (1.73.1.1)
2004-05-12 ZipDll.dll (1.73.2.0)
2011-02-24 Includes\Adware.sbi (*)
2011-03-08 Includes\AdwareC.sbi (*)
2010-08-13 Includes\Cookies.sbi (*)
2010-12-14 Includes\Dialer.sbi (*)
2011-03-08 Includes\DialerC.sbi (*)
2011-02-24 Includes\HeavyDuty.sbi (*)
2010-11-30 Includes\Hijackers.sbi (*)
2011-03-08 Includes\HijackersC.sbi (*)
2010-09-15 Includes\iPhone.sbi (*)
2010-12-14 Includes\Keyloggers.sbi (*)
2011-03-08 Includes\KeyloggersC.sbi (*)
2004-11-29 Includes\LSP.sbi (*)
2011-02-24 Includes\Malware.sbi (*)
2011-03-08 Includes\MalwareC.sbi (*)
2011-02-24 Includes\PUPS.sbi (*)
2011-03-03 Includes\PUPSC.sbi (*)
2010-01-25 Includes\Revision.sbi (*)
2009-01-13 Includes\Security.sbi (*)
2011-03-08 Includes\SecurityC.sbi (*)
2008-06-03 Includes\Spybots.sbi (*)
2008-06-03 Includes\SpybotsC.sbi (*)
2011-02-24 Includes\Spyware.sbi (*)
2011-03-08 Includes\SpywareC.sbi (*)
2010-03-08 Includes\Tracks.uti
2010-12-28 Includes\Trojans.sbi (*)
2011-03-08 Includes\TrojansC-02.sbi (*)
2011-03-03 Includes\TrojansC-03.sbi (*)
2011-03-08 Includes\TrojansC-04.sbi (*)
2011-03-08 Includes\TrojansC-05.sbi (*)
2011-03-08 Includes\TrojansC.sbi (*)
2008-03-04 Plugins\Chai.dll
2008-03-05 Plugins\Fennel.dll
2008-02-26 Plugins\Mate.dll
2007-12-24 Plugins\TCPIPAddress.dll
--- System information ---
Windows XP (Build: 2600) Service Pack 2 (5.1.2600)
/ Windows XP / SP3: Windows Installer 3.1 (KB893803)
I even tried to run (as of posting instructions) DDS tool but it runs until about 3/4 of total and it freezes my pc and I have to reboot. Anyway I backed up my registry with ERUNT.
I even removed all the files as of instructions page http://forums.spybot.info/showthread.php?t=61708
Now the system is apparently clean but my dubt is that this malware has created other different files in the system with other names and above all I'm worrying about those registry entries I can't delete.
May anyone help me to resolve this problem?
Thanx.
Alessandro
p.s.
you can also contact me at