Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

PSW.xVir trojan spyware Hijack this and combofix logs [RESOLVED]


  • This topic is locked This topic is locked

#16
ChristinaC

ChristinaC

    Member

  • Topic Starter
  • Member
  • PipPip
  • 11 posts
Seems kind of smaller than the others wasn't sure I did that right but here's what I found -


C:\Documents and Settings\Owner\Desktop\SmitfraudFix moved successfully.
C:\Documents and Settings\Owner\My Documents\Dylan's Business\setup.exe moved successfully.
C:\WINDOWS\Downloaded Program Files\otdcyqkv.exe moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\shlahsd.dll
C:\WINDOWS\system32\shlahsd.dll NOT unregistered.
C:\WINDOWS\system32\shlahsd.dll moved successfully.
C:\Program Files\America Online 9.0\cdegfr moved successfully.
C:\Program Files\America Online 9.0\wdcevf moved successfully.

Created on 01/26/2008 07:39:07
  • 0

Advertisements


#17
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
Yep that's right. :)

Please open Hijackthis and choose "do a system scan only"
Thne place a check mark next to this entry:

O22 - SharedTaskScheduler: aposiopetic - {91316323-2ad5-4794-9589-52a2eaa60a68} - (no file)

Then click on Fix Checked and then Close Hijackthis.
=================================
Time for some housekeeping
  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK
    Posted Image

Please then delete all other tools if any that I had you download.
Empty your recycle bin.
======================
After that Your log is clean. :)

To find out more information about how you got infected in the first place and some great guidelines to follow to prevent future infections you can read this article by Tony Klein ->Here
  • 0

#18
ChristinaC

ChristinaC

    Member

  • Topic Starter
  • Member
  • PipPip
  • 11 posts
Thank you so much! You are a pro at what you do....is there a physical address I can send a donation to to help you and this wonderful site continue to run???
  • 0

#19
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
Thank you and you are welcome :)

No, nothing personal but I don't give my personal address out.

You can click on my donation button in my signature or you can donate directly to the site if you wish.
But both go through PayPal.
  • 0

#20
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. :)

If your the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.
  • 0

#21
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. :)

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP