Redirecting to malware page!

I am showing a clean HJT log. Please scan with whatever programs (Panda?) that are showing anything and post the logs for me. Post any other information you think will help.

Try a Kaspersky scan:

http://www.kaspersky.com/virusscanner

Click on Kaspersky Online Scanner

You will be promted to install an ActiveX component from Kaspersky, Click Yes.

The program will launch and then start to download the latest definition files.

Once the scanner is installed and the definitions downloaded, click Next.

Now click on Scan Settings

In the scan settings make sure that the following are selected:

Scan using the following Anti-Virus database:

Extended (If available otherwise Standard)

Scan Options:

Scan Archives

Scan Mail Bases

Click OK

Now under select a target to scan select My Computer

The scan will take a while so be patient and let it run. Once the scan is complete it will display if your system has been infected.

Now click on the Save as Text button:

Save the file to your desktop.

Copy and paste that information in your next post.

Thanks
 
First a funny thing I've noticed is that everytime I go to google (offline mode) his inetexplorer isn't being redirected but if I go to www.dr.dk I'll be redirected EACH time...

Okay as I went online I logged online to msn where a script bug appeared, I said I didn't want to have scripts running from it. Then I installed firefox to see what happent. it didn't seem like it was infected so that might mean he can use that explorer instead... dunno. Then I went to the kaspersky webpage (with internet explorer, since I wasn't sure if he had to be using inetexplorer as you have to with panda) and did a full system scan.
I choosed extended scan method and scanned "my computer", also I updated the newest patches for xp that he didn't have (simultanously). I didn't have avg activated as I did the scan but ewido was activated (this might cause a problem as I noticed the first time I did a panda scan I got a popup with a virus which I then removed with avg but this time I didn't have it running so if something poppuped up that avg actually could remove, it didn't.

Well here is the report:

Saturday, July 15, 2006 3:49:39 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.83.0
Kaspersky Anti-Virus database last update: 15/07/2006
Kaspersky Anti-Virus database records: 207536
Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true
Scan Target My Computer
A:\
C:\
D:\
E:\
F:\
Scan Statistics
Total number of scanned objects 87269
Number of viruses found 1
Number of infected objects 6 / 0
Number of suspicious objects 0
Duration of the scan process 00:36:33

Infected Object Name Virus Name Last Action
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Lokale indstillinger\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Lokale indstillinger\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Lokale indstillinger\Oversigt\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Lokale indstillinger\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Lokale indstillinger\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Lokale indstillinger\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Theis Gaarsmand\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Theis Gaarsmand\Lokale indstillinger\Application Data\ApplicationHistory\cli.exe.843bf18c.ini.inuse Object is locked skipped
C:\Documents and Settings\Theis Gaarsmand\Lokale indstillinger\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Theis Gaarsmand\Lokale indstillinger\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Theis Gaarsmand\Lokale indstillinger\Oversigt\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Theis Gaarsmand\Lokale indstillinger\Temp\Perflib_Perfdata_56c.dat Object is locked skipped
C:\Documents and Settings\Theis Gaarsmand\Lokale indstillinger\Temp\Perflib_Perfdata_a1c.dat Object is locked skipped
C:\Documents and Settings\Theis Gaarsmand\Lokale indstillinger\Temp\Perflib_Perfdata_a28.dat Object is locked skipped
C:\Documents and Settings\Theis Gaarsmand\Lokale indstillinger\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Theis Gaarsmand\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Theis Gaarsmand\ntuser.dat.LOG Object is locked skipped
C:\Programmer\BitTorrent\uninstall.exe/stream/data0002 Infected: not-a-virus:RiskTool.Win32.PsKill.n skipped
C:\Programmer\BitTorrent\uninstall.exe/stream Infected: not-a-virus:RiskTool.Win32.PsKill.n skipped
C:\Programmer\BitTorrent\uninstall.exe NSIS: infected - 2 skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\Upload\BitTorrent-4.0.3.exe/stream/data0003 Infected: not-a-virus:RiskTool.Win32.PsKill.n skipped
C:\Upload\BitTorrent-4.0.3.exe/stream Infected: not-a-virus:RiskTool.Win32.PsKill.n skipped
C:\Upload\BitTorrent-4.0.3.exe NSIS: infected - 2 skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edbtmp.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\ACEEvent.evt Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
Scan process completed.


Also my littlebrother was smart enough to press restart while the scan was running but it continued till the scan ended. When it ended and the report was ended I wanted to see if I could use kaspersky to delete the infections so I clicked on the "all" button above the detail screen, then the computer suddenly just rebooted.
After the computer startet up it came with an windows error report, the files that caused the error was:

C:\DOCUME~1\THEISG~1\LOKALE~1\Temp\WERcf38.dir00\Mini071506-01.dmp
C:\DOCUME~1\THEISG~1\LOKALE~1\Temp\WERcf38.dir00\sysdata.xml

Also the error that accured in msn accured again and this is what it said:
This is translatet from danish:

An error accured in the script on the page
Line: 42
Symbol: 3
Error: An object was waitet
code: 0
URL: http://rad.msn.com/adsadclient31.dll?getad?og=imsdmd?sc=hf

Gotta go will do a panda scan later
 
Beginning to think you brother is right, Kaspersky really shows nothing that helps. Those two TEMP lines can be deleted, in fact you can delete the contents of those TEMP folders (not the folder)

I will look at the Panda scan when you post it to see if I spot anything, but I am out of ideas on this one.

I would address the question about this to MSN:
http://support.microsoft.com/default.aspx?scid=kb;en-us;823390

An error accured in the script on the page
Line: 42
Symbol: 3
Error: An object was waitet
code: 0
URL: http://rad.msn.com/adsadclient31.dll...g=imsdmd?sc=hf

Thanks
 
Panda scan gave following:

Incident Status Location

Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Theis Gaarsmand\Skrivebord\SmitfraudFix\Process.exe
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Theis Gaarsmand\Skrivebord\SmitfraudFix.zip[SmitfraudFix/Process.exe]
Virus:W32/Bagle.pwdzip Disinfected C:\download\SmitfraudFix.zip


Which bassically means nothing... I'm gonna reinstal if you don't have any more idears so just waiting for your reply ;)
 
Nope, that's all Smitfraud stuff, you can remove all things Smitfraud from your computer, it is updated almost daily. Here is the link to where the most current updates for that tool will be if you ever need it.
http://siri.urz.free.fr/Fix/SmitfraudFix_En.php

Tashi:) will close you in a few days.

Thanks...Phil
 
As the problem appears to be resolved this topic will be archived.

If you need it re-opened please send me a private message (pm) and provide a link to the thread.

Applies only to the original topic starter.

Glad we could help, cheers. :)
 
Back
Top