You have acquired a password stealing trojan:
http://www.castlecops.com/modules.ph...D-0E922121D03C
Downloadlink HaxFix:
http://users.telenet.be/marcvn/tools/haxfix.exe
Mirror:
http://download.bleepingcomputer.com/marckie/haxfix.exe
How to use HaxFix:
Double click on haxfix.exe to install the program. (standard installation path is
c:\program Files\haxfix and standard run file in that folder is
fix.bat)
Checkmark "Create a desktop icon".
Click "Next".
When the installation is completed, make sure that the checkmark "Launch haxfix" is placed.
Click "Finish".
A red "dos window" (dos box) will open with options:
1. Make logfile
2. Run auto fix
3. Run manual fix
E. Exit Haxfix
Close all other open windows since this step requires a reboot.
Select option
"2. Run auto fix" by typing 2 and then pressing Enter.
If an infection is found, you'll get a message to close all other open windows.
Close all open windows except the red dos window from Haxfix and then press Enter.
The computer will reboot.
After reboot a logfile will open. (
c:\haxfix.txt). Post that log back to this topic thread.
Next,
Please download
VundoFix.exe to your desktop.
- Double-click VundoFix.exe to run it.
- Click the Scan for Vundo button.
- Once it's done scanning, click the Remove Vundo button.
- You will receive a prompt asking if you want to remove the files, click YES
- Once you click yes, your desktop will go blank as it starts removing Vundo.
- When completed, it will prompt that it will reboot your computer, click OK.
- Please post the contents of C:\vundofix.txt and a new HiJackThis log.
Note: It is possible that VundoFix encountered a file it could not remove.
In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the
Scan for Vundo button." when VundoFix appears at reboot.