1. MolokoVeck

    MolokoVeck Private E-2

    I am trying to fix my girlfriend's computer. She ran pic1253.com that she got from an AIM message from a friend which was sent to her by someone on her list with the bug. A folder in Program Files was created called My Love, containing such files as 5972932.INS which is recognized as a trojan. If AIM is up messages are sent to people on the buddy list sending the link, you know how it works. I downloaded all of the programs on your site and followed the steps but the problem still exists. Here is what the cleaners came up with:
    BitDefender -
    Scanned Files 202320

    Infected Files 11

    Virus Detected -
    Backdoor.Sdbot.ADQ 2

    Trojan.Flood.22016 3

    Adware.Wheaterbug.A 2

    Win32.IRC.Kelebek 4

    RAV
    Scanning files...
    C:\Program Files\My Love\v1r1 - IRC/Generic* -> Suspicious
    C:\RECYCLER\NPROTECT\00271323 - IRC/Generic* -> Suspicious
    C:\RECYCLER\NPROTECT\00271345 - IRC/Generic* -> Suspicious

    Found
    ============================
    Viruses found: 0
    Suspicious files: 3
    Disinfected files: 0
    Mail files: 88

    Spybot deleted WildTangent and HS Remove said it removed 8 items. I hope you guys are willing to take a look at the HJ log, thanks!
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run this: AIM Fix

    Then follow the steps below:


    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. MolokoVeck

    MolokoVeck Private E-2

    Ok the AimFix did this just so you know:
    Registry key "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\strtas" removed
    Registry key "HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\strtas" removed
    Registry key "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices\strtas" removed
    Registry key "HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\load" removed

    I have also attached the logfile, thanks!
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You can have HJT fix the below remnants of the scans!

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)

    How are things working?
     
  5. MolokoVeck

    MolokoVeck Private E-2

    She reports that she hasn't had any problems since, thanks a lot!
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds