Have been reading afterdawn newsletter for years but first time posting.
I am using Win XP SP3 with PcCillin Internet Security 2007 in my Desktop.
Yesterday while surfing the net, download and opened an infected file --> PcCillin found and removed the "Mal.Otorun2" virus in the C: & D:/autorun.inf file. Rescan with Pccillin and everything seems fine.
Then noticed that I got redirected to a spyware site (selling things)whenever I click on links to many antivirus downloading site. The Pccillin block this site from my access to protect me. I tried the same link in my laptop and could gain access to these antivirus downloading sites without a hitch. So my desktop PC IE6 got redirected (?DNSchanger)!
Installed and run the Spybot S&D, found the Zlob.DNSchanger.rtk trojan. Seem that it changes the registry. Successfully removed the trojan. Reboot the PC and rescanned with S&D. Nothing found. Rescan with Pccillin, all clear. BUT my IE6 and Firefox still could not access those virus scan downloading sites! The redirecting problem to the same spyware site persists. (My laptop browsing to the same sites works fine.)
Could anyone help? Should I do the scan and destroy once again in Safemode? Or do I need to run SmitfraudFix?
Have followed the instructions in this thread and did the ATF cleaner.
Then ran the Kapsersky scan. Below is the report:
--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7 REPORT
Monday, November 3, 2008
Operating System: Microsoft Windows XP Home Edition Service Pack 3 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Sunday, November 02, 2008 08:40:08
Records in database: 1367023
--------------------------------------------------------------------------------
Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes
Scan area - My Computer:
A:\
C:\
D:\
E:\
F:\
G:\
H:\
I:\
J:\
K:\
Scan statistics:
Files scanned: 120670
Threat name: 3
Infected objects: 1
Suspicious objects: 22
Duration of the scan: 03:02:50
File name / Threat name / Threats count
C:\Documents and Settings\Wan S H\Application Data\Mozilla\Profiles\shwan\w6jruyfh.slt\Mail\Local Folders\Trash Suspicious: Trojan-Spy.HTML.Fraud.gen 1
C:\Documents and Settings\Wan S H\Application Data\Mozilla\Profiles\shwan\w6jruyfh.slt\Mail\pop.netvigator.com\Mail\Old Mail 1_2003 Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\Documents and Settings\Wan S H\Application Data\Mozilla\Profiles\shwan\w6jruyfh.slt\Mail\pop.netvigator.com\Mail\Sent Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\Documents and Settings\Wan S H\Application Data\Mozilla\Profiles\shwan\w6jruyfh.slt\Mail\pop.netvigator.com\Old Mail 3 2007 Suspicious: Trojan-Spy.HTML.Fraud.gen 1
C:\Documents and Settings\Wan S H\Application Data\Mozilla\Profiles\shwan\w6jruyfh.slt\Mail\pop.netvigator.com\Sent Old 8_2006 Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\Program Files\Netscape\Users\shwan\Mail\Mail\Old Mail 1_2003 Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\Program Files\Netscape\Users\shwan\Mail\Mail\Sent Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\Program Files\Netscape\Users\shwan\Mail\Old Mail 1_2003 Suspicious: Exploit.HTML.Iframe.FileDownload 1
C:\Program Files\Netscape\Users\shwan\Mail\Sent Suspicious: Exploit.HTML.Iframe.FileDownload 1
D:\Backup C\Mail\pop.netvigator.com\Mail\Old Mail 1_2003 Suspicious: Exploit.HTML.Iframe.FileDownload 1
D:\Backup C\Mail\pop.netvigator.com\Mail\Sent Suspicious: Exploit.HTML.Iframe.FileDownload 1
D:\Backup C\Mail\pop.netvigator.com\Old Mail 1_2003 Suspicious: Exploit.HTML.Iframe.FileDownload 1
D:\Backup C\Mail\pop.netvigator.com\Sent Suspicious: Exploit.HTML.Iframe.FileDownload 1
D:\Backup C\Netscape\Users\shwan\Mail\Mail\Old Mail 1_2003 Suspicious: Exploit.HTML.Iframe.FileDownload 1
D:\Backup C\Netscape\Users\shwan\Mail\Mail\Sent Suspicious: Exploit.HTML.Iframe.FileDownload 1
D:\Backup C\Netscape\Users\shwan\Mail\Old Mail 1_2003 Suspicious: Exploit.HTML.Iframe.FileDownload 1
D:\Backup C\Netscape\Users\shwan\Mail\Sent Suspicious: Exploit.HTML.Iframe.FileDownload 1
D:\resycled\boot.com Infected: Trojan.Win32.Obfuscated.vmy 1
D:\Wan Netscape Backup\shwan\w6jruyfh.slt\Mail\pop.netvigator.com\Mail\Old Mail 1_2003 Suspicious: Exploit.HTML.Iframe.FileDownload 1
D:\Wan Netscape Backup\shwan\w6jruyfh.slt\Mail\pop.netvigator.com\Mail\Sent Suspicious: Exploit.HTML.Iframe.FileDownload 1
D:\Wan Netscape Backup\shwan\w6jruyfh.slt\Mail\pop.netvigator.com\Old Mail 1_2003 Suspicious: Exploit.HTML.Iframe.FileDownload 1
D:\Wan Netscape Backup\shwan\w6jruyfh.slt\Mail\pop.netvigator.com\Sent Suspicious: Exploit.HTML.Iframe.FileDownload 1
D:\Wan Netscape Backup\shwan\w6jruyfh.slt\Mail\pop.netvigator.com\Trash Suspicious: Trojan-Spy.HTML.Fraud.gen 1
Done the Hijackthis scan. Results as follows: Please kindly help. Much appreciaed:
Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 上午 08:23:09, on 2008/11/3
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Please download Superantispyware Free and install it. Follow the prompts and reboot if required.
Launch Superantispyware Free either by running C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.exe or right-click on the SuperAntispyware icon in your task bar (it looks like a bug) and click on Scan for Spyware, Adware, Malware...
Configuring SuperAntispyware
? Click on Preferences.
? In the tab General and Startup, make sure the box Start SuperAntispyware when Windows starts is unchecked. This will prevent SuperAntispyware from starting everytime, because it may interfere with other fixes that may be run.
? Navigate to the tab Scanning Control.
? Make sure only these boxes are checked:
Close browsers before scanning
Scan for tracking cookies
Terminate memory threats before quarantining
Scan Alternate Data Streams
Use Kernel Direct File Access (recommended)
Use Kernel Direct Registry Access (recommended)
Use Direct Disk Access (recommended)
? Click on Close.
Updating SuperAntispyware
? At the main window, click on Check for Updates....
? Wait for SuperAntispyware to be fully updated.
Scanning Time
? Boot into safe mode by repeatedly pressing the F8 key after you press the power button. If safe mode does not work, tell me and do the scan in normal mode.
? Launch SuperAntispyware.
? At the main window, click on Scan your Computer....
? Make sure all drives (excluding CD drives) are checked, select Perform Complete Scan, and then click on Next.
? Wait for the scan to complete, and then click on Next>. This will quarantine and remove all detected items.
? Reboot your computer.
Post A Log
? Launch SuperAntispyware
? Click on Preferences ? Navigate to the tab Statistics/Logs.
? Choose the latest scan log, and the click on View Log....
? Copy and paste the contents of the log here in your next post.
Life is but a dream; you dont feel any pain unless you want to or you fall off the bed. Success is relative; the more success the more relatives.
A computer once beat me at chess, but it was no match for me at kickboxing. To be or not to be; thats a dumb question.
I have run Ad-Aware freeware yesterday before reading your reply.
then followed your instruction.
Run the Superantispyware in Safemode. Scan time 5+hours.
Found some adware and 1 trojan.
Removed and Quarentined.
Reboot. Seems that I ahve lost my Samsung fax-printer driver.
Tried to go to the virus scan update download link again and everything seems ok now. No more redirection to the advertisement site!
Adware.Tracking Cookie
C:\Documents and Settings\Wan S H\Cookies\wan s h@serving-sys[2].txt
C:\Documents and Settings\Wan S H\Cookies\wan s h@bs.serving-sys[1].txt
C:\Documents and Settings\Wan S H\Cookies\wan s h@atdmt[2].txt
C:\Documents and Settings\Wan S H\Cookies\wan s h@doubleclick[1].txt
C:\Documents and Settings\Wan S H\Cookies\wan s h@adopt.euroclick[2].txt
------------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 上午 08:20:39, on 2008/11/4
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Forget what I said about following the instructions in the other thread. There's no need for that now.
We have one more step left to see if there's any malware left on your system.
Now, please download ComboFix.
With ComboFix, at the download window, please rename it to Combo-Fix(.exe) before downloading it.
Please disable all security programs, such as antiviruses, antispywares, and firewalls. Also disable your internet connection.
? Run Combo-Fix.exe and follow the prompts.
**Understand that things like your system clock changing and your desktop disappearing might happen. Do not worry, because all will be restored later. ? Wait for the scan to be completed.
? If it requires a reboot, please do it.
? After the scan has completed entirely, please post the log here. The log will be located at C:\ComboFix(.txt)
Do not click on the ComoboFix window, as it may cause it to stall.
Life is but a dream; you dont feel any pain unless you want to or you fall off the bed. Success is relative; the more success the more relatives.
A computer once beat me at chess, but it was no match for me at kickboxing. To be or not to be; thats a dumb question.
I try to download it but my Pccillin Antivirus stops me from access the website.
DO I need to diabale the Pccillin?
Will Combofix also try to delete any spyware? Or does it just do the scan only?
Life is but a dream; you dont feel any pain unless you want to or you fall off the bed. Success is relative; the more success the more relatives.
A computer once beat me at chess, but it was no match for me at kickboxing. To be or not to be; thats a dumb question.