View Single Post
Join Date: Jul 2008
Posts: 2,818
Reputation: jholland1964 is a name known to all jholland1964 is a name known to all jholland1964 is a name known to all jholland1964 is a name known to all jholland1964 is a name known to all jholland1964 is a name known to all 
Solved Threads: 162
Featured Poster
jholland1964 jholland1964 is online now Online
Posting Maven

Re: help "Virus Alert"

 
0
  #8
Oct 13th, 2008
The MBA-M scan you just posted was done with an out of date database. The scan you posted shows the database version as 1226 and the database version on the date you did your scan was 1257 and today it is database version 1264 so there were a lot of new items added since you updated yours. You should have updated the program prior to this scan, in fact you should update it prior to EVERY scan you run with it as it has updates frequently, sometimes twice a day.

Your HJT log is still showing infections on the computer. You are showing at least one piece of malware, Mysee Alert and at least one worm. These show in the HJT log, there may be others which do not show. All infections DO NOT show in an HJT log but if some do show the likelyhood of others on the computer increases.

Now, I must caution you, the worm on the computer is known to come from P2P file sharing. It is very evident from the references to BitComet(a P2P program) your HJT log that this is something you do quite often. Since you have this worm on your computer it is very likely that you have also infected other's computer with the P2P file sharing also.
This is just one reason we do not condone or encourage this activity here at daniweb. The other reason is that it can be illegal by sharing copyrighted material, this is a felony.

Please print these instructions as they will be needed later when Internet access is not available.

Logon to your computer with an account that has Administrator privileges.

Download SDFix.exe from the following link and save it to your desktop: SDFix
Now, double-click on the SDFix icon that should now be residing on your desktop. If a Open File - Security Warning box opens, click on the Run button.

A window will open asking where you would like to install SDFix to.

Do not change anything and press the Install button. This will install the program into the default location of C:\SDFix. At this point, you should not run SDFix, but instead continue to the next step where you will reboot into safe mode.
Next, please reboot your computer into Safe Mode by doing the following:

1. Restart your computer

2. After hearing your computer beep once during startup, but before the Windows icon appears, press F8.

3. Instead of Windows loading as normal, a menu should appear

4. Select the first option, to run Windows in Safe Mode.

5. When you are at the logon prompt, log in as the same user that you had performed the previous steps as.

When your computer has started in safe mode, and you see the desktop, close all open Windows.

Click on the Start button, click on the Run menu option, and type the following into the Open: field:

C:\SDFix\RunThis.bat

Then press the OK button.

The SDFix window will open containing some brief info and a disclaimer on the use of the tool.
If you want to continue, please press the Y key on your keyboard and then press enter. Otherwise, you can press the N key to exit the program.

SDFix will now start scanning your computer for known infections
This process can take a while, so you may want to do something else and periodically check back on the status of SDFix.
When the scanning process has finished you will see a new screen stating that you need to restart your computer in order to continue.
# At this point you should press any key on your computer's keyboard in order to restart the computer.

When your computer reboots, you will be presented with a screen stating that SDFix has finished.

At this point you should press any key on your computer's keyboard in order to continue to your desktop.

When you are back at your Windows desktop, the SDFix log will automatically be opened in notepad.
Save this log for posting here.

You need to update your antivirus program and do a full system scan, with all unnecessary programs CLOSED and remove everything found. You need to update your MBA-M program, then close all unnecessary programs and do a full system scan and remove everything found. Then reboot the computer.

You should then also run the ESET Online Scanner and attach the ScanLog with your post for assistance.

* You will need to use Internet Explorer to to complete this scan.
* You will need to temporarily Disable your current Anti-virus program.
* Be sure the option to Remove found threats is checked and the option to Scan unwanted applications is Checked.
* When you have completed that scan, a scanlog ought to have been created and located at C:\Program Files\EsetOnlineScanner\log.txt. Please post that log for us as directed below.

AFTER you have done ALL of the above then run HJT again on a Full System Scan and place a check mark next to the following entries if they remain;

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www/search

O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll
O3 - Toolbar: peltodgx - {0FA15166-39DA-4DAB-9B1A-0DDDBACA8BD5} - C:\WINDOWS\peltodgx.dll (file missing)

O4 - HKLM\..\Run: [Mysee Alert] "C:\Program Files\GAOV\Mysee Alert\Mysee Alert.exe" -notray
O4 - HKLM\..\Run: [MsUpdate] C:\MsUpdate.exe

O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm

O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll/206 (file missing)

Once you have placed these check marks then click the Fix Checked button.
Exit HJT.
Reboot the computer and run one more scan with HJT and save the log.
Post back here with the SDFix log, the MBA-M log, the ESET scanner log and the new HJT log and we will see if other fixes are needed.
Judy
Reply With Quote