Skip to main content

problem finishing AAWSE Personal scan hijackthis

Comments

4 comments

  • Customer


    {NB: Advisor Edit Ai_Tak Posted Yesterday, 01:53 PM

    Note (to lavasoft helpers/others):

    This is a fake codec trojan (aka wareout, aka zlob, aka trojan.flush, aka kedr) infection.}


     

    Huh what is the edit for and is it of any use for me? grtz

    0
  • Customer

    Yes, you are infected with the fake codec trojan (aka wareout, aka zlob, aka trojan.flush, aka kedr), but it was not me who edited this note into your post.

     

    Here is a tool that can deal with the fake codec trojan most of the time:

    http://downloads.subratam.org/Fixwareout.exe

    Post the log from it.

    0
  • Customer

    Mucht thanks Ai Tak!!

     

    Here is teh logfile you requested:

     

     

    Fixwareout

    Last edited 1/30/2007

    Post this report in the forums please

    ...

    Prerun check

    »»»»» HKLM run and Winlogon System values

    C:\WINDOWS\System32\kdsoh.exe will be moved to C:\WINDOWS\temp\kdsoh.ren at reboot.

     

    »»»»» System restarted

    Reg Entries that were deleted

    ...

    Random Runs removed from HKLM

    ...

     

    »»»»» Misc files.

     

    »»»»» Checking for older varients.

     

    »»»»» Postrun check

    »»»»» HKLM run

    »»»»» Winlogon System value

    "system"=""

    »»»»»

     

    PLEASE NOTE, There CAN be LEGITIMATE FILES LISTED IN THIS SECTION.

     

    This WILL/CAN also list Legit Files, Submit them at Virustotal

    Search five digit cs, dm kd and jb files.

    »»»»»

    »»»»» Current runs

     

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

    "ShStatEXE"="\"C:\\Program Files\\Network Associates\\VirusScan\\SHSTAT.EXE\" /STANDALONE"

    "NDSTray.exe"="NDSTray.exe"

    "McAfeeUpdaterUI"="\"C:\\Program Files\\Network Associates\\Common Framework\\UpdaterUI.exe\" /StartedFromRunKey"

    "NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"

     

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]

     

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]

    "Installed"="1"

     

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]

    "Installed"="1"

    "NoChange"="1"

     

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]

    "Installed"="1"

     

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

    "MsnMsgr"="\"C:\\Program Files\\MSN Messenger\\MsnMsgr.Exe\" /background"

    "ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"

     

    Hosts file was reset, If you use a custom hosts file please replace it

    0
  • Customer

    I think it is fixed because i do get the link i clicked after a google search otherwise i came on some freaking advertising site

     

    much much thx!! All heil Ai Tak hehe!

     

    grtz

    0

Please sign in to leave a comment.