Computing.Net > Forums > Security and Virus > new malware.j

new malware.j

Reply to Message Icon

Original Message
Name: charu_sagi
Date: December 1, 2006 at 09:35:13 Pacific
Subject: new malware.j
OS: windows xp
CPU/Ram: 256
Model/Manufacturer: customised
Comment:

HI,
My system is affected by new malware.j since i recieved a virus files some days back. Mc cafe is not deleting this file. pls help. i hav installed HTJ reading some of the forums, what next?

thanx in advance for help.
charu


Report Offensive Message For Removal

Response Number 1
Name: jabuck
Date: December 1, 2006 at 18:56:13 Pacific
Subject: new malware.j
Reply: (edit)

Please post your Hijack This log.

Please download SmitRemFix from this link http://siri.urz.free.fr/Fix/Smitfra... Then extract the contents to your desktop.
!!!! Only run option #1 as runing the other options on an uninfected computer will damage the desktop.!!!!
Open the "SmitfraudFix" folder and double-click "smitfraudfix.cmd"
Select option #1 - Search by typing 1 and press "Enter"; a text file will appear, which lists infected files (if present).
Please copy/paste the content of that report into your next reply.
Note : process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.


Report Offensive Follow Up For Removal

Response Number 2
Name: charu_sagi
Date: December 2, 2006 at 04:22:21 Pacific
Subject: new malware.j
Reply: (edit)

hi jabuck,
thnks. here is the report generated by cmd.exe

SmitFraudFix v2.126

Scan done at 17:50:05.92, Sat 12/02/2006
Run from C:\Documents and Settings\Administrator\Desktop\SmitfraudFix\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
Fix run in normal mode

»»»»»»»»»»»»»»»»»»»»»»»» C:\


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32


»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Administrator


»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Administrator\Application Data


»»»»»»»»»»»»»»»»»»»»»»»» Start Menu


»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\ADMINI~1\FAVORI~1


»»»»»»»»»»»»»»»»»»»»»»»» Desktop


»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files


»»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys


»»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""


»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""


»»»»»»»»»»»»»»»»»»»»»»»» pe386-msguard-lzx32


»»»»»»»»»»»»»»»»»»»»»»»» Scanning wininet.dll infection


»»»»»»»»»»»»»»»»»»»»»»»» End



Report Offensive Follow Up For Removal

Response Number 3
Name: charu_sagi
Date: December 2, 2006 at 04:25:05 Pacific
Subject: new malware.j
Reply: (edit)

SmitFraudFix v2.126

Scan done at 17:50:05.92, Sat 12/02/2006
Run from C:\Documents and Settings\Administrator\Desktop\SmitfraudFix\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
Fix run in normal mode

»»»»»»»»»»»»»»»»»»»»»»»» C:\


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32


»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Administrator


»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Administrator\Application Data


»»»»»»»»»»»»»»»»»»»»»»»» Start Menu


»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\ADMINI~1\FAVORI~1


»»»»»»»»»»»»»»»»»»»»»»»» Desktop


»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files


»»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys


»»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""


»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""


»»»»»»»»»»»»»»»»»»»»»»»» pe386-msguard-lzx32


»»»»»»»»»»»»»»»»»»»»»»»» Scanning wininet.dll infection


»»»»»»»»»»»»»»»»»»»»»»»» End


Report Offensive Follow Up For Removal

Response Number 4
Name: charu_sagi
Date: December 2, 2006 at 04:26:34 Pacific
Subject: new malware.j
Reply: (edit)

hey i am not able to post it here.my broadband ISP is not letting me post that report here. can i have ur email id.
rgds
charu


Report Offensive Follow Up For Removal

Response Number 5
Name: jabuck
Date: December 2, 2006 at 06:48:26 Pacific
Subject: new malware.j
Reply: (edit)

Sorry, posting an email address is to dangerous.Run Hijack This again. Click on the "Do a system scan and save a logfile" button. It will scan and the log should open in notepad.
Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log and post it in this thread. Click the upper right corner on the forum "Comments" window> the click "Paste".

If that does not work hold down the right button on the mouse and drag it across everything in the notepad window to highlight it> then click "Edit"> then click "Copy".

Next in the forums "Comments" window (where you post messages)in the upper right corner click once so that the cursor appears> then press "ctrl-v" (do not click the dash). That should copy the text from the Hijack This log to the forum.


Report Offensive Follow Up For Removal


Response Number 6
Name: kitty
Date: December 11, 2006 at 04:02:17 Pacific
Subject: new malware.j
Reply: (edit)

i posted this another time just tonight but here it is ill repeat what i did


Just a heads up i guess on this new malware.j trojan
I found it on my system too... i have mcafees, and i also use ccleaner, to get rid of unwanted things. as i was looking around i found a new item in the task manager listed as winlogon with my USER name as the user instead of SYSTEM like its suppose to, the system one was there also. i opened up my ccleaner and found in the tools section/startup a listing for nvchost, or something similar, i removed it and the msg that i had this trojan went away. i also decided to download avast free trial to use the preboot scan it has and it picked up 2 other trojans. hope this helps you all.... if you use the avast make sure u turn it back off once u reboot or it will conflict with your antivirus, as you cant have more than one on a system running...


Kitty


Report Offensive Follow Up For Removal






Use following form to reply to current message:

   Name: From My Computing.Net Settings
 E-Mail: From My Computing.Net Settings

Subject: new malware.j

Comments:

 


  Homepage URL (*): 
Homepage Title (*): 
         Image URL: 
 
Data Recovery Software