This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

VIRUS ALERT! infected XP pc

19 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi! This is the log from mbam Kaspersky still scanning, and doesn't seem to end soon. I will post the results when finished Cheers Malwarebytes' Anti-Malware 1.26 Database version: 1110 Windows 5.1.2600 Service Pack 3, v.3300 3/9/2008 10:00:12 μμ mbam-log-2008-09-03 (22-00-12).txt Scan type: Quick Scan Objects scanned: 51348 Time elapsed: 2 minute(s), 56 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 2 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CLASSES_ROOT\gksraemq.bgpd (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\gksraemq.toolbar.1 (Trojan.FakeAlert) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)

Yea Kaspersky takes longer


After 2 hours is still on 1%! It could take days! So i will get some sleep, because I am so tired with all this virus fighting! :wacko:
I will leave my pc scanning…

We will talk soon

Cheers!
One thing before i go to sleep.. After this infection that really scared me, what do you recommend for my safety and protection? What are the best antivirus and firewall? What should I put to guard me better? I would appreciate any suggestions on this subject!

Best leave it on over night


Ooops just found an infected object… :wacko:
Yes, I will leave it all night

I have turned off my Avast antivirus as kaspersky instructed. Is it safe for the night to leave it off?

Thanx

Bye for now :wavey:
Oh my god!!! Am I still infected? So many viruses :smack: I mean , I don't understand. Why some people want to heart us? :wacko: Here is the carspersky report ——————————————————————————– KASPERSKY ONLINE SCANNER 7 REPORT Friday, September 5, 2008 Operating System: Microsoft Windows XP Professional Service Pack 3, v.3300 (build 2600) Kaspersky Online Scanner 7 version: 7.0.25.0 Program database last update: Wednesday, September 03, 2008 20:17:25 Records in database: 1188827 ——————————————————————————– Scan settings: Scan using the following database: extended Scan archives: yes Scan mail databases: yes Scan area - My Computer: A:\ C:\ D:\ E:\ F:\ G:\ H:\ J:\ L:\ Scan statistics: Files scanned: 865752 Threat name: 19 Infected objects: 270 Suspicious objects: 2 Duration of the scan: 35:59:21 File name / Threat name / Threats count C:\DOWNLOADS\ALT\Networking Tools\MyShell-1.1.0.tar.gz Infected: Backdoor.PHP.PhpShell.n 1 C:\DOWNLOADS\ALT\Sp_Ra\RARPassGen.EXE Infected: Trojan-Downloader.Win32.Zlob.xnd 1 C:\DOWNLOADS\ALT\Sp_Ra\part02.rar Infected: Trojan-Downloader.Win32.Zlob.xnd 1 C:\DOWNLOADS\ALT\Sp_Ra\part04.rar Infected: Trojan-Downloader.Win32.Zlob.xnd 1 C:\DOWNLOADS\ALT\Sp_Ra\part06.rar Infected: Trojan-Downloader.Win32.Zlob.xnd 1 C:\DOWNLOADS\ALT\Sp_Ra\part08.rar Infected: Trojan-Downloader.Win32.Zlob.xnd 1 C:\DOWNLOADS\ALT\Sp_Ra\part11.rar Infected: Trojan-Downloader.Win32.Zlob.xnd 1 C:\DOWNLOADS\ALT\Sp_Ra\part13.rar Infected: Trojan-Downloader.Win32.Zlob.xnd 1 C:\DOWNLOADS\ALT\Sp_Ra\part15.rar Infected: Trojan-Downloader.Win32.Zlob.xnd 1 C:\DOWNLOADS\ALT\Sp_Ra\part18.rar Infected: Trojan-Downloader.Win32.Zlob.xnd 1 C:\DOWNLOADS\ALT\Sp_Ra\part20.rar Infected: Trojan-Downloader.Win32.Zlob.xnd 1 C:\DOWNLOADS\ALT\Sp_Ra\part22.rar Infected: Trojan-Downloader.Win32.Zlob.xnd 1 C:\DOWNLOADS\ALT\Sp_Ra\part24.rar Infected: Trojan-Downloader.Win32.Zlob.xnd 1 C:\DOWNLOADS\ALT\Sp_Ra\part27.rar Infected: Trojan-Downloader.Win32.Zlob.xnd 1 C:\DOWNLOADS\ALT\Sp_Ra\part29.rar Infected: Trojan-Downloader.Win32.Zlob.xnd 1 C:\DOWNLOADS\ALT\Sp_Ra\part31.rar Infected: Trojan-Downloader.Win32.Zlob.xnd 1 C:\DOWNLOADS\virusremoval\Fixes\SmitfraudFix.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f 1 C:\DOWNLOADS\virusremoval\rogueremoval.zip Infected: not-a-virus:RiskTool.Win32.Reboot.f 1 C:\E-MAILS\Inbox Infected: Email-Worm.Win32.NetSky.x 42 C:\SDFix\backups\backups.zip Infected: not-a-virus:FraudTool.Win32.Agent.bp 1 C:\SDFix\backups\backups.zip Infected: not-a-virus:FraudTool.Win32.Agent.bo 1 C:\SDFix\backups\backups.zip Infected: Trojan.Win32.Agent.abux 1 C:\SDFix\backups\backups.zip Infected: Trojan.Win32.Agent.abpr 1 C:\SDFix\backups\backups.zip Infected: not-a-virus:FraudTool.Win32.MSAntivirus.r 1 C:\SDFix\backups\backups.zip Infected: not-a-virus:FraudTool.Win32.MSAntivirus.t 1 C:\SDFix\backups\backups.zip Infected: Trojan-Downloader.Win32.Small.acri 1 C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\UPW9P26M\ac[1].htm Infected: Trojan-Downloader.JS.Agent.cnn 1 C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\UPW9P26M\ac[2].htm Infected: Trojan-Downloader.JS.Agent.cnn 1 C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\UPW9P26M\ac[3].htm Infected: Trojan-Downloader.JS.Agent.cnn 1 C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\UPW9P26M\ac[4].htm Infected: Trojan-Downloader.JS.Agent.cnn 1 D:\Users\Gro\Documents\gawret.rar Infected: not-a-virus:PSWTool.Win32.RAS.g 1 D:\Users\Gro\Documents\gawret.rar Infected: not-a-virus:PSWTool.Win32.RAS.a 1 D:\Users\Gro\Documents\wvbfgkgv.zip Infected: not-a-virus:PSWTool.Win32.RAS.g 1 D:\Users\Gro\Documents\wvbfgkgv.zip Infected: not-a-virus:PSWTool.Win32.RAS.a 1 D:\Users\Gro\Downloads\v9.1-TE.rar Infected: Backdoor.Win32.Kbot.by 1 D:\Users\Gro\Emails\RB\Inbox Infected: Email-Worm.Win32.NetSky.x 24 D:\Users\Gro\Emails\RM\Inbox Infected: Email-Worm.Win32.NetSky.x 53 D:\Users\Gro\Emails\RM\Trash Infected: Email-Worm.Win32.NetSky.x 24 D:\Users\Gro\Networking Tools\MyShell-1.1.0.tar.gz Infected: Backdoor.PHP.PhpShell.n 1 E:\DOWNLOADS\GAME.zip Infected: Trojan.BAT.Small.ai 1 E:\DOWNLOADS\GAME2.zip Infected: Trojan.BAT.Small.ai 1 E:\DOWNLOADS\card.zip Infected: Trojan.BAT.Small.ai 1 E:\DOWNLOADS\manual.zip Infected: Trojan.BAT.Small.ai 1 E:\DOWNLOADS\den_flix.zip Infected: Trojan.BAT.Small.ai 1 E:\DOWNLOADS\w22ft.zip Infected: Trojan.BAT.Small.ai 1 E:\DOWNLOADS\Networking Tools\MyShell-1.1.0.tar.gz Infected: Backdoor.PHP.PhpShell.n 1 E:\DOWNLOADS\downloads\EMAILBACKUP\Εισερχόμενα.dbx Suspicious: Exploit.HTML.Iframe.FileDownload 1 E:\DOWNLOADS\downloads\get.dbx Suspicious: Exploit.HTML.Iframe.FileDownload 1 E:\DOWNLOADS\LATESTDOWNLOADS\SiteGrinder.rar Infected: Trojan-Dropper.Win32.Delf.vt 1 L:\SATA\Emails\RB\Inbox Infected: Email-Worm.Win32.NetSky.x 24 L:\SATA\Emails\RM\Inbox Infected: Email-Worm.Win32.NetSky.x 43 L:\SATA\Emails\RM\Trash Infected: Email-Worm.Win32.NetSky.x 14 L:\ST\Ne_trial.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm 1 L:\ST\ne_photos_setup.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm 1 L:\ST\Ne\Toolbar.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm 1 The selected area was scanned.
Hello

Please download the OTMoveIt2 by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt2.exe to run it.
  • Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    [kill explorer]
    C:\DOWNLOADS\ALT
    D:\Users\Gro\Documents\gawret.rar
    D:\Users\Gro\Documents\wvbfgkgv.zip
    D:\Users\Gro\Downloads\v9.1-TE.rar 
    D:\Users\Gro\Networking Tools\MyShell-1.1.0.tar.gz
    E:\DOWNLOADS\GAME.zip 
    E:\DOWNLOADS\GAME2.zip
    E:\DOWNLOADS\card.zip
    E:\DOWNLOADS\manual.zip 
    E:\DOWNLOADS\den_flix.zip 
    E:\DOWNLOADS\w22ft.zip 
    E:\DOWNLOADS\Networking Tools\MyShell-1.1.0.tar.gz 
    E:\DOWNLOADS\downloads\get.dbx 
    E:\DOWNLOADS\LATESTDOWNLOADS\SiteGrinder.rar 
    L:\ST\Ne_trial.exe 
    L:\ST\ne_photos_setup.exe 
    L:\ST\Ne\Toolbar.exe
    purity 
    EmptyTemp
    [start explorer]
  • Return to OTMoveIt2, right click in the "Paste List of Files/Folders to Move" window (under the light Yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • A log of files and folders moved will be created in the c:\_OTMoveIt\MovedFiles folder in the form of Date and Time (mmddyyyy_hhmmss.log). Please open this log in Notepad and post its contents in your next reply.
  • Close OTMoveIt2
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.




1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

File::

DirLook::
C:\DOWNLOADS
D:\Users\Gro\Downloads
E:\DOWNLOADS

SkipFix::

Folder::

Registry::

Driver::


Save this as CFScript.txt, in the same location as ComboFix.exe


[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.
Hello and thanks a lot! :wavey: Before I continue this process, please tell me. When i will use this move it tool, it will move only the viruses or every folder from my directory? For example in C:DOWNLOADS/ALT I have more other folders Waiting for your reply
Do this instead, it wont delete the other folders

Please download the OTMoveIt2 by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt2.exe to run it.
  • Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    [kill explorer]
    C:\DOWNLOADS\ALT\Networking Tools\MyShell-1.1.0.tar.gz
    D:\Users\Gro\Documents\gawret.rar
    D:\Users\Gro\Documents\wvbfgkgv.zip
    D:\Users\Gro\Downloads\v9.1-TE.rar
    D:\Users\Gro\Networking Tools\MyShell-1.1.0.tar.gz
    E:\DOWNLOADS\GAME.zip
    E:\DOWNLOADS\GAME2.zip
    E:\DOWNLOADS\card.zip
    E:\DOWNLOADS\manual.zip
    E:\DOWNLOADS\den_flix.zip
    E:\DOWNLOADS\w22ft.zip
    E:\DOWNLOADS\Networking Tools\MyShell-1.1.0.tar.gz
    E:\DOWNLOADS\downloads\get.dbx
    E:\DOWNLOADS\LATESTDOWNLOADS\SiteGrinder.rar
    L:\ST\Ne_trial.exe
    L:\ST\ne_photos_setup.exe
    L:\ST\Ne\Toolbar.exe
    C:\DOWNLOADS\ALT\Sp_Ra
    purity 
    EmptyTemp
    [start explorer]
  • Return to OTMoveIt2, right click in the "Paste List of Files/Folders to Move" window (under the light Yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • A log of files and folders moved will be created in the c:\_OTMoveIt\MovedFiles folder in the form of Date and Time (mmddyyyy_hhmmss.log). Please open this log in Notepad and post its contents in your next reply.
  • Close OTMoveIt2
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI