Hi.
2 days ago I got some kind of a virus or something I don’t know. It is using windows live messenger to spread around. I don’t know how did it get in my computer but Avast can’t find it and I can’t get rid od it.
When you are using messenger and chat with someone in dialog window appears some kind of zip file and a text in english “this dude just crash his car…”. And then it asks if I want to accept, decline or cancel. I allways declined and somehow my computer got infected.
I ran thorough scan of the whole sistem and avast reports that there is no infected files, but the virus or something is still in my pc.
please help. What to do?
[*]Save HJTsetup.exe to your desktop.
[*]Doubleclick on the HJTsetup.exe icon on your desktop.
[*]By default it will install to C:\Program Files\Hijack This.
[*]Continue to click Next in the setup dialogue boxes until you get to the Select Addition Tasks dialogue.
[*]Put a check by Create a desktop icon then click Next again.
[*]Continue to follow the rest of the prompts from there.
[*]At the final dialogue box click Finish and it will launch Hijack This.
[*]Click on the Do a system scan and save a logfile button. It will scan and the log should open in notepad.
[*]Click on “Edit > Select All” then click on “Edit > Copy” to copy the entire contents of the log.
[*]Come back here to this thread and Paste the log in your next reply.
[*]DO NOT have Hijack This fix anything yet. Most of what it finds will be harmless or even required.
It is also advisable to have a mix of applications to provide a broader protection base, like anti-spyware/adware applications in combination with avast.
If you haven’t already got this software (freeware), download, install, update and run it, preferably in safe mode (for item 1 applications).
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:54:18 PM, on 9/18/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
[/b]Now close all windows other than HiJackThis, then click Fix Checked. Close HiJackThis.
Next
Please download the OTMoveIt by OldTimer.
[*] Save it to your desktop.
[*] Please double-click OTMoveIt.exe to run it.
[*]Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):
C:\WINDOWS\system32\servicer.exe
[*] Return to OTMoveIt, right click on the “Paste List of Files/Folders to be moved” window and choose Paste.
[*]Click the red Moveit! button.
[*]Copy everything on the Results window to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it on your next reply.
[*]Close OTMoveIt
If a file or folder cannot be moved immediately, you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine, choose Yes
**If a reboot was necessary or you needed to Exit before posting the log, you will find a copy of the log at the root of the drive where OTMoveIt is installed, usually at :
[b]C:_OTMoveIt\MovedFiles*_.log[/b]
(where “**_” is the “date_time”)
Click “Exit” to close OTMoveIt.
Finally
Download ComboFix from Here or Here to your Desktop.
[*]Double click combofix.exe and follow the prompts.
[*]When finished, it shall produce a log for you. Post that log and a HiJackthis log in your next reply
Note: Do not mouseclick combofix’s window while its running. That may cause it to stall
It won’t hurt to follow through with the processing to ensure it has truly gone and then the combofix tool to check for other possible infection.
It would have been useful if you had send a copy of the file (or any undetected malware found in this process) to avast to help improve detections.
Send the sample to virus@avast.com zipped and password protected with password in email body and undetected malware in the subject.
Or you can also add the file to the User Files (File, Add) section of the avast chest where it can do no harm and send it from there (select the file, right click, email to Alwil Software). No need to zip and PW protect when the sample is sent from chest. A copy of the file/s will remain in the original location, so any further action you take can remove that.
That is the advantage of OTMoveit it will quarantine the file for analysis if required. But continue with combofix there will be more than 1 file involved.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:50:09 PM, on 2/2/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal