Zlob aka SmitFraud - 17pholmes.exe

Discussion in 'Malware Help (A Specialist Will Reply)' started by willyneu, Feb 24, 2008.

  1. willyneu

    willyneu Private E-2

    Hello, My Desktop got hit by one or more trojan horses in the past few days. It started with "17pholmes.exe". Initially, both my desktop & task bar disappeared. My AVG Free Edition Anti Virus found "17pholmes.exe" & quarantined it. Spybot found some other thinks before finding SmitFraud on my most recent scan.

    The only way I could open any programs is using Windows Task Manager Run command. Until I openned My Computer the desktop & the Task bar keep disappearing. My Computer is open in the background. I just closed both My Computer & Explorer & the desktop icons are still there.

    I have taken the first step to run Rapport.txt. I do see "!!!Attention, following keys are not inevitable infected!!!". Can this be true?

    As soon as I attach the rapport.txt file I will go do the 2nd step.
    Thanks,
    Willy
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    After doing the second step and attaching the log....Please follow the instructions in the below link and attach the requested logs when you finish these instructions.

    READ & RUN ME FIRST. Malware Removal Guide
     
  3. willyneu

    willyneu Private E-2

    Thanks Tim. I printed out the read & run me first. I need to finish doing some of that is listed. I just attached the new rapport.txt to this thread.

    since running step 2 my desktop is back to normal. I am still getting a message on startup that the Task Scheduler did not run. I need to read how to get it activated.

    Willy
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let me know when you are ready ...:)
     
  5. willyneu

    willyneu Private E-2

    I have attached:
    SASLog-03-10-2008-21-15-11.txt (13.3 KB)
    ComboFix.txt (6.0 KB)
    MGlogs.zip (57.4 KB

    Thanks for the assistance,

    Willy
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Are you letting the scans run to completion? Combofix was truncated and there was no HJT log in the MGLogs.zip.

    In the meantime:
    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Find and delete:
    P:\WINDOWS\unins000.exe
    P:\WINDOWS\unins000.dat
    P:\WINDOWS\system32\abeeg.ini
    P:\Documents and Settings\Willyneu\UpdateBTCYugma_NOJVM.exe
    P:\Documents and Settings\WillyOnline\Application Data\.purple

    Now run the C:\MGtools\GetLogs.bat file and the ComboFix.exe by double clicking on it. Then attach the new C:\MGlogs.zip file and the COmboFix log. Make sure they run to completion.
     
  7. willyneu

    willyneu Private E-2

    Tim, to my knowledge I did not intentially stop Combofix or MGLogs.zip.
    I followed your outline below. It may be possible that I missed the HJT instructions the first time around. I did not look for it now. I can see if there was something about the HJT that I overlooked. May not be able to do that tonight.
    Thanks for the help, Willy

     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    When you run MGTools.exe....it will prompt you to agree to the HJT license...if you don't do that, it won't run.
     
  9. willyneu

    willyneu Private E-2

    i'm on a webinar so will run it later. I ran spybot this morning & it did not find anything.
    thanks,
    willy
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds