Needing help with this ASAP

Discussion in 'Malware Help (A Specialist Will Reply)' started by totalcompdummy, Dec 31, 2006.

  1. totalcompdummy

    totalcompdummy Private E-2

    I have found the following on my comp & can't get rid of them.
    What can I do (without reinstiling my windows to get rid of them?)

    I have:
    Emcodec is a Downloader Trojan
    MediaCodec This is a trojan downloader.

    I have Avast instilled along with ParetoLogic

    I have done a 'boot scan' with Avast & have done a scan with ParetoLogic. I did have 4 threats until I did a scan with ParetoLogic & then did a boot scan with Avast.

    That clean up 2 of them but am stuck with what to do with the remaining too. Anyone able to help me out?
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!


    I'm going to post two sets of instructions below. Each will be enclosed in separate Quote boxes. Make sure to complete the first one 100% before moving on to the second one.

    ATTACH THE FIRST LOG NOW BEFORE CONTINUING OR YOU WILL OVERWRITE IT!!!! And then immediately continue on to the below steps.

    How are things working now?
     
  3. totalcompdummy

    totalcompdummy Private E-2

    Hi yea

    Here is the Notepad thing that came up.
    You asked me to post it, so here it is.

    SmitFraudFix v2.132

    Scan done at 8:54:13.04, Mon 01/01/2007
    Run from C:\Documents and Settings\Penny\Desktop\SmitfraudFix\SmitfraudFix
    OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
    The filesystem type is NTFS
    Fix run in normal mode

    »»»»»»»»»»»»»»»»»»»»»»»» C:\


    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS


    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system


    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web


    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

    C:\WINDOWS\system32\cthkpcv.dll FOUND !

    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles


    »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Penny


    »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Penny\Application Data


    »»»»»»»»»»»»»»»»»»»»»»»» Start Menu

    C:\DOCUME~1\Penny\STARTM~1\Programs\Key Generator FOUND !

    »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\Penny\FAVORI~1


    »»»»»»»»»»»»»»»»»»»»»»»» Desktop


    »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

    C:\Program Files\Key Generator\ FOUND !

    »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys


    »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
    "Source"="About:Home"
    "SubscribedURL"="About:Home"
    "FriendlyName"="My Current Home Page"


    »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
    !!!Attention, following keys are not inevitably infected!!!

    SrchSTS.exe by S!Ri
    Search SharedTaskScheduler's .dll


    »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
    !!!Attention, following keys are not inevitably infected!!!

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
    "AppInit_DLLs"=""


    »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
    !!!Attention, following keys are not inevitably infected!!!

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
    "System"=""


    »»»»»»»»»»»»»»»»»»»»»»»» pe386-msguard-lzx32


    »»»»»»»»»»»»»»»»»»»»»»»» Scanning wininet.dll infection


    »»»»»»»»»»»»»»»»»»»»»»»» End

    If possible can you explain the above in English for me?
     
  4. totalcompdummy

    totalcompdummy Private E-2

    chaslang thanks for your help.

    I managed to get rid all everything including a couple of minor addware things with the program that you gave me.

    I think I will keep it & use when I both my anti virus software's can't remove things.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please remember that logs need to be attachments to messages! They should not be posted inline like you did.

    Also you only posted the first rapport.txt log. You need to attach the second which shows what it fixed.

    It is not a virus scanning program. It is only a tool designed to remove specific problems which are grouped into a family called SmitFraud. In additon the tool changes rapidly, sometime 5 times in a week. Thus you must always check for the current version before using. Also it is not a tool to use when you don't have a SmitFraud infection because it will remove your Desktop Wallpaper and change some other settings.
     
  6. totalcompdummy

    totalcompdummy Private E-2

    Sorry about the muck up with the thing that I did.

    Is there a way for me to tell if the virus or whatever is comes under the ones that will be fixed by the program?

    Do I just search for & then down load the tool when needed.

    I will attach the file that shows everything is fine (or so I hope).

    As I said I did a scan afterwards (the second safe mode) attempt. And nothing came up.

    Anyway here is the file that I saved for you.
    See I am a total dummy (when it comes to attaching things in here)

    Hopefully that worked. I know who to do attachments in emails & things like that. So I am guessing what I did worked.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not really! It is a specialty tool and not a virus scanner.

    You should only download and use this tool when recommended by an expert in a forum like this. It should not just be run for the heck of it or just as a guess at what is wrong.

    All the log shows is what the tool found and fixed. It is not a complete malware scanning and detection tool. As I said before it was designed for a special set of problems all related to the SmitFraud family of infections. If you want to know if you PC is free from malware you would need to do the below standard cleaning procedure we use.

     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds