"Your Computer Is Infected"

  1. #1
    10228c is offline Newbie

    Help Wanted For Infected Computer

    The OS security centre on my computer keeps making a "POP!" sound and displaying the infection warning.
    The red button with the white cross is always displayed on the bottom bar on desktop.
    On the 10th October, the online scanner of my avast! home edition had detected a virus. I had consigned that to the "chest". During a subsequent scan, more infected files were discovered. There were "errors" in moving/deleting these. After that, I repeatedly get virus warnings when I am online.
    I have done an online scan with another anti-virus site and that turned up a few files as well some of which I could delete manually and one with a dot htm extension could not be found.
    A scan by avast! with the computer booted in safe mode did not detect any infection.
    But the OS warning remains. Also, on pressing ctrl-alt-del I get the message that the admin has disabled the task manager whereas there's one user of this computer, me, and I have not disabled the task mgr.
    Could someone stage a remedy other than formatting?
    A log of the anti-virus software is as follows:
    10/10/2007 8:37:06 PM SYSTEM 1536 Sign of "CVE-2007-0038" has been found in "http://mediacount.net/strong/092/324123.html" file.
    10/10/2007 8:37:28 PM SYSTEM 1536 Sign of "Win32:Tibs-BBQ [Trj]" has been found in "C:\WINDOWS\system32\kernelw.sys" file.
    10/10/2007 8:38:06 PM SYSTEM 1536 Sign of "Win32:Tibs-BBQ [Trj]" has been found in "C:\WINDOWS\system32\kernelw.sys" file.
    10/10/2007 8:38:54 PM SYSTEM 1536 Sign of "Win32:Fakealert [Trj]" has been found in "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\37877A.dmp " file.
    10/10/2007 8:39:00 PM SYSTEM 1536 Sign of "Win32ialer-407 [Trj]" has been found in "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\ma1x1dd1v.game " file.
    10/10/2007 8:39:11 PM SYSTEM 1536 Sign of "Win32:Small-BLF [Trj]" has been found in "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\v5xd2.g3am e" file.
    10/10/2007 8:39:21 PM SYSTEM 1536 Sign of "Win32:Small-BLF [Trj]" has been found in "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\v5xd2.g3am e" file.
    10/10/2007 8:40:26 PM SYSTEM 1536 Sign of "Win32ialer-407 [Trj]" has been found in "C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\AQVHPR1J\gdnOT2904[1].exe" file.
    10/10/2007 9:42:55 PM Administrator 3720 Sign of "Win32:Xorpix-AZ [Trj]" has been found in "C:\WINDOWS\system32\vedxga4me1.exe\[Embedded#1660]\[Upack]" file.
    10/10/2007 9:43:05 PM Administrator 3720 Sign of "Win32:Xorpix-AZ [Trj]" has been found in "C:\WINDOWS\system32\vedxga4me1.exe\[Embedded#4a00]\[Embedded#1660]\[Upack]" file.
    10/10/2007 10:02:19 PM Administrator 3720 Sign of "Win32:Xorpix-AZ [Trj]" has been found in "C:\Documents and Settings\Administrator\Local Settings\Temp\v3xd1.g22me\[Embedded#1660]\[Upack]" file.
    10/10/2007 11:10:45 PM Administrator 3720 Sign of "Win32:Xorpix-AZ [Trj]" has been found in "C:\Documents and Settings\Administrator\Local Settings\Temp\v3xd1.g22me\[Embedded#4a00]\[Embedded#1660]\[Upack]" file.
    10/10/2007 11:50:12 PM Administrator 3720 Sign of "Win32:Xorpix-AZ [Trj]" has been found in "C:\System Volume Information\_restore{5D4F196F-2D3C-4C55-A79E-C9401AFB9CF4}\RP106\A0084048.exe\[Embedded#1660]\[Upack]" file.
    10/10/2007 11:50:23 PM Administrator 3720 Sign of "Win32:Xorpix-AZ [Trj]" has been found in "C:\System Volume Information\_restore{5D4F196F-2D3C-4C55-A79E-C9401AFB9CF4}\RP106\A0084048.exe\[Embedded#4a00]\[Embedded#1660]\[Upack]" file.
    11/10/2007 12:09:28 PM SYSTEM 1424 Sign of "Win32ownloader-gen [Trj]" has been found in "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\ma11x1dd12111v .game" file.
    11/10/2007 5:41:25 PM Administrator 1600 Sign of "Win32ownloader-gen [Trj]" has been found in "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\ma11x1dd12111v .game" file.
    11/10/2007 6:07:49 PM Administrator 1420 Sign of "Win32ownloader-gen [Trj]" has been found in "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\ma11x1dd12111v .game" file.
    11/10/2007 6:17:35 PM Administrator 1604 Sign of "Win32ownloader-gen [Trj]" has been found in "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\ma11x1dd12111v .game" file.
    11/10/2007 8:30:51 PM Administrator 1428 Sign of "Win32ownloader-gen [Trj]" has been found in "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\ma11x1dd12111v .game" file.
    12/10/2007 12:27:32 PM SYSTEM 1432 Sign of "Win32ownloader-gen [Trj]" has been found in "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\ma11x1dd12111v .game" file.
    12/10/2007 12:37:09 PM SYSTEM 1432 Sign of "Win32:CTX" has been found in "http://acs.pandasoftware.com/activescan/as5free/motor.cab\pskavs.DLL" file.
    12/10/2007 3:52:58 PM Administrator 1616 Sign of "Win32ownloader-gen [Trj]" has been found in "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\ma11x1dd12111v .game" file.
    12/10/2007 6:49:22 PM Administrator 1608 Sign of "Win32ownloader-gen [Trj]" has been found in "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\ma11x1dd12111v .game" file.
    12/10/2007 8:00:12 PM Administrator 1604 Sign of "Win32ownloader-gen [Trj]" has been found in "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\ma11x1dd12111v .game" file.
    12/10/2007 8:29:59 PM Administrator 1636 Sign of "Win32ownloader-gen [Trj]" has been found in "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\ma11x1dd12111v .game" file.
    13/10/2007 6:45:51 AM Administrator 1424 Sign of "Win32ownloader-gen [Trj]" has been found in "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\ma11x1dd12111v .game" file.
    13/10/2007 8:14:34 AM Administrator 1436 Sign of "Win32ownloader-gen [Trj]" has been found in "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\ma11x1dd12111v .game" file.
    Thanks in advance.
    Last edited by 10228c; 13-10-2007 at 04:57 PM.


  2. #2
    10228c is offline Newbie
    "jephree Bump your thread if you like.

    The guys should be back on tomorrow.

    Sorry for the delay".
    So I thought I'd bump the thread.

  3. #3
    Neal is offline Dedicated Member
    Save 20% on AVG Internet Security 2012 Suite!
    Welcome,


    What online scanner did you use?

    I need a hijackthis log, so in my signature is a link to hijackthis. Just scroll down until you find hijackthis and follow instructions on that and post the uninstall list also ploease.

+ Reply to Thread