View Single Post
Old 11-29-2007, 03:53 PM   #12 (permalink)
tetonbob
Manager, Security Center, TSF Academy; Analyst, Security Team
 
tetonbob's Avatar
 
Join Date: Jan 2005
Location: Transylvania County, North Carolina, USA
Posts: 35,151
OS: 2000 Pro; XP Pro; XP Home


Re: virus that tries to infect me with other malware

Sorry about that, I missed it.

As long as you know what it is, and it's a file of your making, that should be OK. Just curious....what does it do?

If you have any doubts, scan it at VirusTotal also.

------------------------------------------



Open notepad and copy/paste the text in the quotebox below into it:

Quote:
http://www.techsupportforum.com/security-center/hijackthis-log-help/197715-virus-tries-infect-me-other-malware-post1188722.html#post1188722

File::
C:\WINDOWS\system32\cfpgnnoq.dll
C:\WINDOWS\system32\iwjvjeib.dll
C:\WINDOWS\system32\vjcrrtdk.ini
C:\WINDOWS\system32\hnbdslmb.dll
C:\WINDOWS\system32\coiyiwox.ini
C:\WINDOWS\system32\oaoquwca.dll
C:\WINDOWS\system32\prnykmsp.ini
C:\WINDOWS\system32\gdpckulr.dll
C:\WINDOWS\system32\djlrjyri.ini
C:\WINDOWS\system32\kcwmlkrv.dll
C:\WINDOWS\system32\lylmmbgu.ini
C:\WINDOWS\system32\iuytwduf.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\aidaewvv.ini
C:\WINDOWS\system32\dktlfsqs.dll
C:\WINDOWS\system32\fmctsjeu.ini
C:\WINDOWS\system32\asivgnmu.dll
C:\WINDOWS\system32\dncwjpub.ini
C:\WINDOWS\system32\vspyafby.dll
C:\WINDOWS\system32\fdvevgxt.ini
C:\WINDOWS\system32\wiskejbp.ini
C:\WINDOWS\system32\ingymkuo.dll
C:\WINDOWS\system32\rnrelimf.ini
C:\WINDOWS\system32\hiwwxlpx.dll
C:\WINDOWS\system32\wekfflas.ini
C:\WINDOWS\system32\hftisxgu.dll
C:\WINDOWS\system32\iihalmyk.ini
C:\WINDOWS\system32\oondmyno.dll
C:\WINDOWS\system32\pbubbjbc.ini
C:\WINDOWS\system32\aniffnes.dll
C:\WINDOWS\system32\itndobim.ini
C:\WINDOWS\system32\ssvgakum.dll
C:\WINDOWS\system32\wecfrgvg.ini
C:\WINDOWS\system32\nibwkpxv.dll
C:\WINDOWS\system32\vhbyakhd.ini
C:\WINDOWS\system32\sfnpsnuo.dll
C:\WINDOWS\system32\sqydaakg.ini
C:\WINDOWS\system32\icjaaxsw.dll
C:\WINDOWS\system32\aonfvnqq.dll
C:\WINDOWS\system32\vggdibqb.ini
C:\WINDOWS\system32\oinqtsqm.dll
C:\WINDOWS\system32\kbijcpvd.dll
C:\WINDOWS\system32\cwbfltqe.ini
C:\WINDOWS\system32\ooktgwvg.ini
C:\WINDOWS\system32\raodqnxe.ini
C:\WINDOWS\system32\xjqfpule.ini
C:\WINDOWS\system32\dcnvdess.ini

Registry::
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\lstfasmy]

Collect::
C:\WINDOWS\system32\ytexsifn.dll
C:\WINDOWS\system32\issdroln.dll
C:\WINDOWS\system32\rskcrkjt.dll
C:\WINDOWS\system32\dduiuyau.dll



Save this as CFScript.txt




Refering to the picture above, drag CFScript.txt into ComboFix.exe

When finished, it shall produce a log for you, C:\ComboFix.txt. Post that log in your next reply.

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall


When CF finishes running, the ComboFix log will open along with a message box--do not be alarmed. With the above script, ComboFix will capture a file to submit for analysis.

Ensure you are connected to the internet and click OK. A browser will open. Simply follow the instructions to copy/paste/send the requested file.

---------------------------------------------------------------------------------------------

Open HijackThis and click on 'Do a System Scan and save a Logfile'. Save the log file and post it here.

---------------------------------------------------------------------------------------------
__________________
Practice Safe Surfing
Because what you don't know, CAN hurt you.
Proud Member of ASAP since 2005
Proud Member of UNITE since 2006

Microsoft MVP - Consumer Security 2009
tetonbob is offline