Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

PSW.xVir trojan spyware Hijack this and combofix logs [RESOLVED]


  • This topic is locked This topic is locked

#16
ChristinaC

ChristinaC

    Member

  • Topic Starter
  • Member
  • PipPip
  • 11 posts
Seems kind of smaller than the others wasn't sure I did that right but here's what I found -


C:\Documents and Settings\Owner\Desktop\SmitfraudFix moved successfully.
C:\Documents and Settings\Owner\My Documents\Dylan's Business\setup.exe moved successfully.
C:\WINDOWS\Downloaded Program Files\otdcyqkv.exe moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\shlahsd.dll
C:\WINDOWS\system32\shlahsd.dll NOT unregistered.
C:\WINDOWS\system32\shlahsd.dll moved successfully.
C:\Program Files\America Online 9.0\cdegfr moved successfully.
C:\Program Files\America Online 9.0\wdcevf moved successfully.

Created on 01/26/2008 07:39:07
  • 0

Advertisements


#17
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
Yep that's right. :)

Please open Hijackthis and choose "do a system scan only"
Thne place a check mark next to this entry:

O22 - SharedTaskScheduler: aposiopetic - {91316323-2ad5-4794-9589-52a2eaa60a68} - (no file)

Then click on Fix Checked and then Close Hijackthis.
=================================
Time for some housekeeping
  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK
    Posted Image

Please then delete all other tools if any that I had you download.
Empty your recycle bin.
======================
After that Your log is clean. :)

To find out more information about how you got infected in the first place and some great guidelines to follow to prevent future infections you can read this article by Tony Klein ->Here
  • 0

#18
ChristinaC

ChristinaC

    Member

  • Topic Starter
  • Member
  • PipPip
  • 11 posts
Thank you so much! You are a pro at what you do....is there a physical address I can send a donation to to help you and this wonderful site continue to run???
  • 0

#19
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
Thank you and you are welcome :)

No, nothing personal but I don't give my personal address out.

You can click on my donation button in my signature or you can donate directly to the site if you wish.
But both go through PayPal.
  • 0

#20
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. :)

If your the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.
  • 0

#21
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. :)

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP