PDA

View Full Version : system alert pop-up (follow up)



ninjaflute
2007-03-19, 23:53
hi, i have been following the instruction given by shaba on this thread
http://forums.spybot.info/showthread.php?t=11691

when i ran SmitfraudFix.exe. i had one more thing shown in my infection results:

换换换换换换换换换换换换 Sharedtaskscheduler
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{634be415-da12-496b-b89e-329b73c4807f}"="cam"

[HKEY_CLASSES_ROOT\CLSID\{634be415-da12-496b-b89e-329b73c4807f}\InProcServer32]
@="C:\WINDOWS\system32\tvomnc.dll"

[HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{634be415-da12-496b-b89e-329b73c4807f}\InProcServer32]
@="C:\WINDOWS\system32\tvomnc.dll"

and after i did the online spyware check using Kaspersky Online Scanner. i found out that this tvomnc.dll in my system32 is a trojan downloader. actually that may not be the case because there were couple more.

however, the computer runs fine. but that System Alert! keeps poping up, weather left click or right click, it opens up a web-page http://spydawn.com/?aff=321. in the add/remove applications i can't remove the system alert popup. it is rather annoying...and it feels like this is a spyware/virus/malware/add-ware.

how do i get rid of it? please help.

regards

ninjaflute
2007-03-19, 23:54
also...i have ran apybot s&d, lava soft adware and norton anti vrius serval times. they couldn't detect anything.

Mr_JAk3
2007-03-21, 21:04
Hello ninjaflute and welcome to the Forums :)

YOu're infected.

Please post a HijackThis log to here: Click here (http://downloads.malwareremoval.com/HijackThis.exe) to download HijackThis.exe
Save HijackThis.exe to your desktop.
Create a new folder named HijackThis to your desktop. Move Hijackthis.exe into that folder.
Run HijackThis.exe
Click on the Do a system scan and save a log file button. It will scan and then ask you to save the log.
Click Save to save the log file and then the log will open in notepad.
Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log.
Come back here to this thread and Paste the log in your next reply.
DO NOT have Hijack This fix anything yet. Most of what it finds will be harmless or even required.

tashi
2007-03-27, 09:12
Due to lack of a response, this topic has been archived.

If you need it re-opened please send me a private message (pm) and provide a link to the thread. Applies only to the original poster, anyone else with similar problems please start a new topic.