Thursday 30.10.2025 / 19:46 
		
			
		 
	 
					
					  
							
							  
	
		
		
			 
	
							
							
								
									
										
											
												afterdawn.com  > forums  > software, operating systems and more  > windows - virus and spyware problems  > virus jumped on gf's computer, here is the logfile  
											
												
	
	
						 				 	
	
	
	
		
			
			
			
		 
	
												 
															
															
	
			
			
				
					Virus Jumped On GF's computer, here is the logfile
				 
				
				
					
				 
				
			 
			
			
			
				
					
					
				 
			
			
			
			
			
				
				
					
				
				
				
				
					
						
							
								alcocerpi
							
							
								
									Suspended due to non-functional email address
								
							
							 
						3. May 2006 @ 19:10 Link to this message 
								  
								 
					
					
					
						
						
						
							
							Here is her log file
http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr7/*http://www... http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr7/*http://www... http://us.rd.yahoo.com/customize/ie/defaults/su/msgr7/*http://www... http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr7/*http://www... http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr7/*http://www... http://red.clientapps.yahoo.com/customize/ie/defaults/stp/ymsgr6/... http://us.rd.yahoo.com/customize/ie/defaults/su/msgr7/*http://www... http://www.creative.com/su/ocx/15015/CTSUEng.cab http://www.creative.com/su/ocx/15016/CTPID.cab  
							
						 
						
						
						
						 
					 
				
				
			
				
				
				
					
						
							Advertisement
							 
						 
					
						
							
							
						 
					 
				
				
				
					
						
							
								
							
							
								Senior Member
								
									
								
							
							 
						4. May 2006 @ 03:53 Link to this message 
								  
								 
					
					
					
						
						
						
							
							You don't have an antivirus on your computer. Download and install one antivirus.
http://www.grisoft.com http://www.avast.com Cleaning instructions: 
SmitfraudFix.zip  to your desktop -> http://siri.urz.free.fr/Fix/SmitfraudFix.zip SmitfraudFix  and doubleclick smitfraudfix.cmd 
Search  by typing 1  and pressing "Enter "; a textfile opens and lists the infected files (if those exist)
http://www.ewido.net/en/download ATF Cleaner  by Atribune to your desktop -> http://www.atribune.org/ccount/click.php?id=1 Viewpoint Manager, WeatherBug  if found
HijackThis  (run HijackThis , press "Do a system scan only", close all other windows, checkmark entries and press Fix checked):
 
http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr7/*http://www... http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr7/*http://www... http://us.rd.yahoo.com/customize/ie/defaults/su/msgr7/*http://www... http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr7/*http://www... http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr7/*http://www... http://red.clientapps.yahoo.com/customize/ie/defaults/stp/ymsgr6/... http://us.rd.yahoo.com/customize/ie/defaults/su/msgr7/*http://www...  
http://www.bleepingcomputer.com/tutorials/tutorial62.html http://www.pchell.com/support/safemode.shtml Viewpoint 
AWS 
winldra.exe 
related.htm 
iPODService.exe 
ATF Cleaner  -> Check select all  -> Press Empty selected 
HijackThis  log 
 
							
						 
						
						I have moved from AD, I won''t be taking new HijackThis logs from here. Reason: The AD''s Unsupportive athmosphere.
						
						 
					 
				
				
			
				
				
				
				
				
					
						
							
								alcocerpi
							
							
								
									Suspended due to non-functional email address
								
							
							 
						5. May 2006 @ 15:46 Link to this message 
								  
								 
					
					
					
						
						
						
							
							My GF's computer is a little slow but I did everything you suggested. Here are the latest logs. Thanks
HijackThis  v1.99.1
http://www.creative.com/su/ocx/15015/CTSUEng.cab http://www.creative.com/su/ocx/15016/CTPID.cab  
							
						 
						
						
						
						 
					 
				
				
			
				
				
				
				
				
					
						
							
								
							
							
								Senior Member
								
									
								
							
							 
						5. May 2006 @ 20:51 Link to this message 
								  
								 
					
					
					
						
						
						
							
							Ok, not clean yet.
Cleaning instructions: 
http://siri.urz.free.fr/Fix/SmitfraudFix.zip http://www.bleepingcomputer.com/tutorials/tutorial62.html http://www.pchell.com/support/safemode.shtml GMT 
WinTools 
SmitfraudFix  folder and doubleclick the file smitfraudfix.cmd 
Clean  by typing 2  and pressing "Enter " in order to remove the infected files.
Y  and press "Enter" in order to remove your desktop wallpaper and the infected registry keys.
wininet.dll  file is infected. You might be asked to replace the infected .dll (if found); answer "Yes" by typing Y  and press "Enter".
C:\rapport.txt. 
Warning  : Running option 2 in a clean computer will delete your desktop wallpaper.
 
							
						 
						
						I have moved from AD, I won''t be taking new HijackThis logs from here. Reason: The AD''s Unsupportive athmosphere.
						
							This message has been edited since posting. Last time this message was edited on 5. May 2006 @ 21:09 
						
						 
					 
				
				
			
				
				
				
				
				
					
						
							
								alcocerpi
							
							
								
									Suspended due to non-functional email address
								
							
							 
						6. May 2006 @ 07:38 Link to this message 
								  
								 
					
					
					
						
						
						
							
							Here they go
HijackThis  v1.99.1
http://www.creative.com/su/ocx/15015/CTSUEng.cab http://www.creative.com/su/ocx/15016/CTPID.cab  
							
						 
						
						
						
						 
					 
				
				
			
				
				
				
				
				
					
						
							
								
							
							
								Senior Member
								
									
								
							
							 
						6. May 2006 @ 09:57 Link to this message 
								  
								 
					
					
					
						
						
						
							
							Ok looking quite good but you still have the old version of smitfraudfix (2.38). Delete the old smitfraudfix.zip file and the smitfraudfix folder.
SmitfraudFix.zip (version 2.40) to your desktop -> http://siri.urz.free.fr/Fix/SmitfraudFix.zip SmitfraudFix  and doubleclick smitfraudfix.cmd 
Search  by typing 1  and pressing "Enter "; a textfile opens and lists the infected files (if those exist)
 
							
						 
						
						I have moved from AD, I won''t be taking new HijackThis logs from here. Reason: The AD''s Unsupportive athmosphere.
						
						 
					 
				
				
			
				
				
				
				
				
					
						
							
								alcocerpi
							
							
								
									Suspended due to non-functional email address
								
							
							 
						6. May 2006 @ 10:41 Link to this message 
								  
								 
					
					
					
						
						
						
							
							Here it is. Hey when you help clean my other computer a few days ago I used the old version too. Should I post you a log with this version?
 
							
						
						
						
						
						 
					 
				
				
			
				
				
				
					
						
							Advertisement
							 
						 
					
						
							
							  
					 
				
				
				
					
						
							
								
							
							
								Senior Member
								
									
								
							
							 
						6. May 2006 @ 10:46 Link to this message 
								  
								 
					
					
					
						
						
						
							
							Hi alcocerpi, this one is clean :)
http://update.microsoft.com/windowsupdate/  
							
						 
						
						I have moved from AD, I won''t be taking new HijackThis logs from here. Reason: The AD''s Unsupportive athmosphere.
						
						 
					 
				
				
			
			
			
			
			
		
		
	
			
			
		
	 
 
					
						
							afterdawn.com  > forums  > software, operating systems and more  > windows - virus and spyware problems  > virus jumped on gf's computer, here is the logfile