Malware and Virus RemovalProblems removing malware/viruses? Get help from our Malware removal experts.
Mission Statement
WindowsBBS is an online community dedicated to easily accessible technical support for those using Microsoft operating systems and other Windows software.
Our goal is to become the leading resource for computer users that require assistance with their day-to-day computer usage, including full support for networking PC's, virus & malware removal, system upgrades and general support questions.
Been quite a while since I have been here because I have been keeping my computer well protected, but I cannot say the same for my boss, who after letting her kids play on her computer unsupervised discovered tons of spy- and malware. So she dumped the computer of me, being the only guy in this small volunteer organisation who knows anything to do with computers.
Anyway, that is why I am here, along with a HijackThis logfile.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:52:23, on 16/11/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal
Download Malwarebytes' Anti-Malware (MBAM) from here or here and save the file to your desktop.
Double click mbam-setup.exe to install the application.
Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
If an update is found, it will download and install the latest version.
Once the program has loaded, select 'Perform Quick Scan', then click Scan.
The scan may take some time to finish,so please be patient.
When the scan is complete, click OK, then Show Results to view the results.
Make sure that everything is checked, and click Remove Selected.
When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Note below)
The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
Post the entire report in your next reply.
Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.
Things seem to be running smoothly now, here is the HijackThis log as requested.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:44:35, on 20/11/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal
Now close all windows other than HiJackThis, then click Fix Checked.
Close HJT.
Reboot your computer.
Now a on line scan.
If you have ATF Cleaner please run it, if not then download and run it.
Download ATF Cleaner by Atribune and save it to your Desktop.
This is a good tool to get rid of the temporary garbage you pick up while surfing the net.
Double click ATF-Cleaner.exe to run the program.
Check the boxes to the left of:
Windows Temp
Current User Temp
All Users Temp
Cookies
Temporary Internet Files
Prefetch
Java Cache
Recycle bin
The rest are optional - if you want it to remove everything check "Select All".
Finally, click Empty Selected. When you get the "Done Cleaning" message, click OK.
It's best to disable real time protection applications as they sometimes interfere with the scan.
Check this link for any applicable programs you may have.
Click on “Accept” If your pop –up blocker blocks any windows from opening.
Click Run on the window that opens. Windows Vista users you must open the web browser using the Run as Administrator command.
The program will launch and then begin downloading the latest definition files:
Under Scan on the left side.Click on My Computer
This will start the program and scan your system.
Click the “Scan Report” On the left side.
The scan will take a while so be patient and let it run.
Once the scan is complete it will display if your system has been infected.
Click the Save Report As button, and in the Browse dialog box, type a name for the scan report file that you want to create and select its type Text file. Click OK to save the file.:
Save the text file to your desktop.
Copy and paste that information in your next post.
--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7 REPORT
Saturday, November 22, 2008
Operating System: Microsoft Windows XP Home Edition Service Pack 3 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Saturday, November 22, 2008 06:45:04
Records in database: 1401709
--------------------------------------------------------------------------------
Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes
Scan area - My Computer:
C:\
D:\
Scan statistics:
Files scanned: 39850
Threat name: 6
Infected objects: 17
Suspicious objects: 0
Duration of the scan: 00:51:24
File name / Threat name / Threats count
C:\Documents and Settings\PSC\My Documents\My Music\jd\moonshine jay z.mp3 Infected: Trojan-Downloader.WMA.GetCodec.c 1
C:\Documents and Settings\PSC\Shared\amy whitehouse valerie.mp3 Infected: Trojan-Downloader.WMA.GetCodec.c 1
C:\Documents and Settings\PSC\Shared\amy whitehouse vivien.mp3 Infected: Trojan-Downloader.WMA.GetCodec.c 1
C:\Documents and Settings\PSC\Shared\bonified husler.mp3 Infected: Trojan-Downloader.WMA.GetCodec.c 1
C:\Documents and Settings\PSC\Shared\moonshine jay z.mp3 Infected: Trojan-Downloader.WMA.GetCodec.c 1
C:\Documents and Settings\PSC\Shared\my life tupac 192kb.mp3 Infected: Trojan-Downloader.WMA.GetCodec.f 1
C:\Documents and Settings\PSC\Shared\my life tupac.mp3 Infected: Trojan-Downloader.WMA.GetCodec.c 1
C:\Documents and Settings\PSC\Shared\one more time.mp3 Infected: Trojan-Downloader.WMA.GetCodec.c 1
C:\Documents and Settings\PSC\Shared\spinning right round doa.mp3 Infected: Trojan-Downloader.WMA.GetCodec.c 1
C:\Documents and Settings\PSC\Shared\up in air phill collins.mp3 Infected: Trojan-Downloader.WMA.GetCodec.c 1
C:\Documents and Settings\PSC\Shared\wonder why they call you bitch.mp3 Infected: Trojan-Downloader.WMA.GetCodec.c 1
C:\Program Files\MSN Messenger\msimg32.dll Infected: not-a-virus:AdTool.Win32.MyWebSearch.cg 1
C:\Program Files\MSN Messenger\riched20.dll Infected: not-a-virus:AdTool.Win32.MyWebSearch.cj 1
C:\Program Files\Windows Live\Messenger\msimg32.dll Infected: not-a-virus:AdTool.Win32.MyWebSearch.cg 1
C:\Program Files\Windows Live\Messenger\riched20.dll Infected: not-a-virus:AdTool.Win32.MyWebSearch.cj 1
C:\WINDOWS\system32\IEDFix.C.exe Infected: Hoax.Win32.Renos.esa 1
C:\WINDOWS\system32\install_plusclear_h.exe Infected: not-a-virus:AdWare.Win32.Agent.dng 1
Hi
OK, You still using P2P apps? you have been warned before on the use of file sharing.
Let me remind you.
Note: Please be advised that continued use of these programs after being warned of the danger of infections from them, may result in the discontinued help of future cleaning of your system here at Windowsbbs Malware and Virus removal.
These songs need to be removed, they are infected.
amy whitehouse vivien.mp3
bonified husler.mp3
moonshine jay z.mp3
my life tupac 192kb.mp3
my life tupac.mp3
one more time.mp3
spinning right round doa.mp3
up in air phill collins.mp3
wonder why they call you bitch.mp3
I suggest you start using iTunes or Rhapsody.
Using Windows Explorer (to get there right-click your Start button and go to "Explore"), please delete these files (if present):
Right now the computer has been on for a while after I did what you said and my brother has been using it to surf the web, no pop ups or spyware in site, looks like it did that trick, thanks.
Hi Bryn
OK. sorry about the P2P warning, I forgot it was not your PC.
Let me know if you think all is OK and I'll mark this one resolved.
Please look at this link for some preventive recommendations, It could keep you from ending up back here to the Malware and Virus Removal Forums. An ounce of prevention is worth a pound of cure
Ok I'll give it a day ot 2 to see if anything pops up, and it's good to see that she has installed a few of the programs that are in the recommendations, I will install some more then give it back to her.