Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

trojan-spy.html.smitfraud.c > desktop


  • This topic is locked This topic is locked

#1
Cleaner

Cleaner

    New Member

  • Member
  • Pip
  • 3 posts
Hi guys,

I've seen many topics on this trojan (trojan-spy.html.smitfraud.c) and I've successfully (I think) cleaned my system, but I have problem with restoring my desktop after I've deleted the bitmap "WP.BMP". In Control Panel / Display Settings I only have 2 tabs left and nowhere to set the wallpaper. Wonder if I missed anything during cleanup.

This is what I've done so far:

- Installed all the updates for IE and Windows XP;
- Installed and ran the following software:
* Norton Antivirus
* Spyware Doctor
* Ad-Aware
* SpyBot
* TDS-3
- Did online scan with "Panda"
- Reboot computer after each scan

Please find below the log from the HJT scan. Wonder if you can point me in the right direction as to how to deal with the desktop issue ;)

Logfile of HijackThis v1.99.1
Scan saved at 2:39:21 PM, on 8/05/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\brsvc01a.exe
C:\WINDOWS\System32\brss01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\IC\Card Reader Driver v1.9e3\Disk_Monitor.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe
C:\WINDOWS\SM1BG.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spyware Doctor\swdoctor.exe
C:\Program Files\OpenOffice.org1.1.3\program\soffice.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\System32\msiexec.exe
C:\Documents and Settings\Owner\My Documents\Downloads\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\Owner\LOCALS~1\Temp\se.dll/spage.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.encarta.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://global.acer.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\Owner\LOCALS~1\Temp\se.dll/spage.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://global.acer.com/
O1 - Hosts: 64.91.255.87 www.dcsresearch.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: (no name) - {726213BE-A537-44B5-8BB3-3615D305EED3} - C:\WINDOWS\System32\hkae.dll (file missing)
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [Disk Monitor] C:\Program Files\IC\Card Reader Driver v1.9e3\Disk_Monitor.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe"
O4 - HKLM\..\Run: [SM1BG] C:\WINDOWS\SM1BG.EXE
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O4 - Startup: OpenOffice.org 1.1.3.lnk = C:\Program Files\OpenOffice.org1.1.3\program\quickstart.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Microsoft AntiSpyware helper - {C5417B4B-10B3-4958-A097-D4E25DF53EB9} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {C5417B4B-10B3-4958-A097-D4E25DF53EB9} - (no file) (HKCU)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://global.acer.com/
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoft.../as5/asinst.cab
O18 - Filter: application/xhtml+xml - {32F66A26-7614-11D4-BD11-00104BD3F987} - C:\Program Files\Design Science\MathPlayer\MathMLMimer.dll
O18 - Filter hijack: text/xml - {32F66A26-7614-11D4-BD11-00104BD3F987} - C:\Program Files\Design Science\MathPlayer\MathMLMimer.dll
O18 - Filter: text/xml; charset=iso-8859-1 - {32F66A26-7614-11D4-BD11-00104BD3F987} - C:\Program Files\Design Science\MathPlayer\MathMLMimer.dll
O18 - Filter: text/xml; charset=utf-8 - {32F66A26-7614-11D4-BD11-00104BD3F987} - C:\Program Files\Design Science\MathPlayer\MathMLMimer.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\System32\brsvc01a.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

Thank you in advance,

Cleaner :tazz:
  • 0

Advertisements


#2
g2i2r4

g2i2r4

    retired HiJack Helper

  • Retired Staff
  • 5,080 posts
Welcome Cleaner to Geeks to Go!

Download about:buster by RubbeRDuckY Here.
Download CWShredder Here.
Download SpSeHjfix Here.
Download and install CleanUp! this link

Save all of these files somewhere you will remember like to the Desktop.

Unzip SpSeHjfix to its own folder (ie c:\SpSeHjfix)

Run the CleanUp! installer. You dont need to do anything with it right now.

Update About:Buster
  • Unzip the contents of AboutBuster.zip and an AboutBuster directory will be created.
  • Navigate to the AboutBuster directory and double-click on AboutBuster.exe.
  • Click "OK" at the prompt with instructions.
  • Click "Update" and then "Check For Update" to begin the update process.
  • If any updates exist please download them by clicking "Download Update" then click the X to close that window.
  • Now close About:Buster
Update CWShredder
  • Open CWShredder and click I AGREE
  • Click Check For Update
  • Close CWShredder
Boot into Safe Mode:
Restart your computer and as soon as it starts booting up again continuously tap F8. A menu should come up where you will be given the option to enter Safe Mode.

Please run About:Buster:
  • Click Start and then OK to allow AboutBuster to scan for Alternate Data Streams.
  • Click Yes to allow it to shutdown explorer.exe.
  • It will begin to check your computer for malicious files. If it asks if you would like to do a second pass, allow it to do so.
  • When it has finished, click Save Log. Make sure you save it as I may need a copy of it later.
  • Reboot your computer into safe mode again
Run about:buster again following the same instructions as above, this time without the restart at the end.

Now run CWShredder. Click I Agree, then Fix and then Next, let it fix everything it asks about.

Now run SpSeHjfix. A log will be saved in the same folder that you put the exe into. Please post the results of that log in your next reply.

Now run CleanUp! Click CleanUp and allow it to delete all the temporary files. Reboot your computer into normal windows.

Right click here and click Save Target As. Save the file to your desktop. Double click on the file you saved to run it. It will ask you if you want to merge it with your registry. Click Yes and then Ok on the confirmation. You will have to reboot for this to take effect.

Please run an on-line virus scan at Kaspersky OnLine Scan or if that doesnt work, you can use TrendMicro or BitDefender. (Please post the results of the scan(s) in your next reply)

Edited by g2i2r4, 08 May 2005 - 10:37 AM.

  • 0

#3
Cleaner

Cleaner

    New Member

  • Topic Starter
  • Member
  • Pip
  • 3 posts
Hi g2i2r4,

Thank you for the instructions.

It looks like after this clean-up the desktop is restored and the system runs well. I'm posting the log files for you to double check. Please let me know if there is anything else that has to be done.

>>> log for about:buster >>>>>>>>>>>>>>>>

Scanned at: 8:36:35 PM on: 9/05/2005


-- Scan 1 ---------------------------
About:Buster Version 4.0
Reference List : 26


ADS not scanned System(FAT)
Attempted Clean Of Temp folder.
Pages Reset... Done!

-- Scan 2 ---------------------------
About:Buster Version 4.0
Reference List : 26


ADS not scanned System(FAT)
Attempted Clean Of Temp folder.
Pages Reset... Done!






Scanned at: 8:40:24 PM on: 9/05/2005


-- Scan 1 ---------------------------
About:Buster Version 4.0
Reference List : 26


ADS not scanned System(FAT)
Attempted Clean Of Temp folder.
Pages Reset... Done!

-- Scan 2 ---------------------------
About:Buster Version 4.0
Reference List : 26


ADS not scanned System(FAT)
Attempted Clean Of Temp folder.
Pages Reset... Done!


>> log for SPSeHjFix >>>>>>>>>>>>>>>>>>>>>>>

(5/9/05 8:42:25 PM) SPSeHjFix started v1.1.2
(5/9/05 8:42:25 PM) OS: WinXP Service Pack 2 (5.1.2600)
(5/9/05 8:42:25 PM) Language: english
(5/9/05 8:42:25 PM) Win-Path: C:\WINDOWS
(5/9/05 8:42:25 PM) System-Path: C:\WINDOWS\system32
(5/9/05 8:42:25 PM) Temp-Path: C:\DOCUME~1\Owner\LOCALS~1\Temp\
(5/9/05 8:42:29 PM) Disinfection started
(5/9/05 8:42:29 PM) Bad-Dll(IEP): c:\docume~1\owner\locals~1\temp\se.dll
(5/9/05 8:42:29 PM) UBF: 8 - UBB: 5 - UBR: 11
(5/9/05 8:42:29 PM) UBF: 8 - UBB: 5 - UBR: 11
(5/9/05 8:42:29 PM) Bad IE-pages:
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, Search Bar: res://c:\docume~1\owner\locals~1\temp\se.dll/spage.html
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Search Bar: res://c:\docume~1\owner\locals~1\temp\se.dll/spage.html
deleted: HKLM\Software\Microsoft\Internet Explorer\Search, SearchAssistant: about:blank
(5/9/05 8:42:29 PM) Stealth-String not found
(5/9/05 8:42:29 PM) No locked Files to delete. End without Reboot
(5/9/05 8:42:47 PM) Disinfection started
(5/9/05 8:42:47 PM) Bad-Dll(IEP): c:\docume~1\owner\locals~1\temp\se.dll
(5/9/05 8:42:47 PM) UBF: 8 - UBB: 5 - UBR: 11
(5/9/05 8:42:47 PM) UBF: 8 - UBB: 5 - UBR: 11
(5/9/05 8:42:47 PM) Bad IE-pages: (none)
(5/9/05 8:42:47 PM) Stealth-String not found
(5/9/05 8:42:47 PM) No locked Files to delete. End without Reboot
(5/9/05 8:43:05 PM) Disinfection started
(5/9/05 8:43:05 PM) Bad-Dll(IEP): c:\docume~1\owner\locals~1\temp\se.dll
(5/9/05 8:43:05 PM) UBF: 8 - UBB: 5 - UBR: 11
(5/9/05 8:43:05 PM) UBF: 8 - UBB: 5 - UBR: 11
(5/9/05 8:43:05 PM) Bad IE-pages: (none)
(5/9/05 8:43:05 PM) Stealth-String not found
(5/9/05 8:43:05 PM) No locked Files to delete. End without Reboot


Thank you once again :tazz:
  • 0

#4
g2i2r4

g2i2r4

    retired HiJack Helper

  • Retired Staff
  • 5,080 posts
We need to repeat this till it's clean (which it's not yet).

Clean out temporary and TIF files. Go to Start > Run and type in the box: cleanmgr. Let it scan your system for files to remove. Make sure these 3 are checked and then press *ok* to remove:

Temporary Files
Temporary Internet Files
Recycle Bin


Reboot into safe mode.

Disconnect from the net and Close ALL OPEN PROGRAMS.
Run 'SpSeHjfix'. and click on "Start Disinfection".
When it's finished it will reboot your machine to finish the cleaning process.
Please make sure it reboots!
The tool creates a log of the fix which will appear in the folder.

Now run the Shredder - Hit The FIX button!

Reboot and repeat the process above.

Reboot and post the log that was created by 'SpSeHjfix'.[/b]
  • 0

#5
Cleaner

Cleaner

    New Member

  • Topic Starter
  • Member
  • Pip
  • 3 posts
Hi there,

Finally managed to repeat the process again. Please find the log below.

(5/9/05 8:42:25 PM) SPSeHjFix started v1.1.2
(5/9/05 8:42:25 PM) OS: WinXP Service Pack 2 (5.1.2600)
(5/9/05 8:42:25 PM) Language: english
(5/9/05 8:42:25 PM) Win-Path: C:\WINDOWS
(5/9/05 8:42:25 PM) System-Path: C:\WINDOWS\system32
(5/9/05 8:42:25 PM) Temp-Path: C:\DOCUME~1\Owner\LOCALS~1\Temp\
(5/9/05 8:42:29 PM) Disinfection started
(5/9/05 8:42:29 PM) Bad-Dll(IEP): c:\docume~1\owner\locals~1\temp\se.dll
(5/9/05 8:42:29 PM) UBF: 8 - UBB: 5 - UBR: 11
(5/9/05 8:42:29 PM) UBF: 8 - UBB: 5 - UBR: 11
(5/9/05 8:42:29 PM) Bad IE-pages:
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, Search Bar: res://c:\docume~1\owner\locals~1\temp\se.dll/spage.html
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Search Bar: res://c:\docume~1\owner\locals~1\temp\se.dll/spage.html
deleted: HKLM\Software\Microsoft\Internet Explorer\Search, SearchAssistant: about:blank
(5/9/05 8:42:29 PM) Stealth-String not found
(5/9/05 8:42:29 PM) No locked Files to delete. End without Reboot
(5/9/05 8:42:47 PM) Disinfection started
(5/9/05 8:42:47 PM) Bad-Dll(IEP): c:\docume~1\owner\locals~1\temp\se.dll
(5/9/05 8:42:47 PM) UBF: 8 - UBB: 5 - UBR: 11
(5/9/05 8:42:47 PM) UBF: 8 - UBB: 5 - UBR: 11
(5/9/05 8:42:47 PM) Bad IE-pages: (none)
(5/9/05 8:42:47 PM) Stealth-String not found
(5/9/05 8:42:47 PM) No locked Files to delete. End without Reboot
(5/9/05 8:43:05 PM) Disinfection started
(5/9/05 8:43:05 PM) Bad-Dll(IEP): c:\docume~1\owner\locals~1\temp\se.dll
(5/9/05 8:43:05 PM) UBF: 8 - UBB: 5 - UBR: 11
(5/9/05 8:43:05 PM) UBF: 8 - UBB: 5 - UBR: 11
(5/9/05 8:43:05 PM) Bad IE-pages: (none)
(5/9/05 8:43:05 PM) Stealth-String not found
(5/9/05 8:43:05 PM) No locked Files to delete. End without Reboot


(5/11/05 8:32:09 PM) SPSeHjFix started v1.1.2
(5/11/05 8:32:09 PM) OS: WinXP Service Pack 2 (5.1.2600)
(5/11/05 8:32:09 PM) Language: english
(5/11/05 8:32:09 PM) Win-Path: C:\WINDOWS
(5/11/05 8:32:09 PM) System-Path: C:\WINDOWS\system32
(5/11/05 8:32:09 PM) Temp-Path: C:\DOCUME~1\Owner\LOCALS~1\Temp\
(5/11/05 8:32:13 PM) Disinfection started
(5/11/05 8:32:13 PM) Bad-Dll(IEP): (not found)
(5/11/05 8:32:13 PM) Bad-Dll(IEP) in BHO: (not found)
(5/11/05 8:32:13 PM) UBF: 8 - UBB: 5 - UBR: 11
(5/11/05 8:32:13 PM) UBF: 8 - UBB: 5 - UBR: 11
(5/11/05 8:32:13 PM) Bad IE-pages: (none)
(5/11/05 8:32:13 PM) Stealth-String not found
(5/11/05 8:32:13 PM) Not infected->END


(5/11/05 8:37:24 PM) SPSeHjFix started v1.1.2
(5/11/05 8:37:24 PM) OS: WinXP Service Pack 2 (5.1.2600)
(5/11/05 8:37:24 PM) Language: english
(5/11/05 8:37:24 PM) Win-Path: C:\WINDOWS
(5/11/05 8:37:24 PM) System-Path: C:\WINDOWS\system32
(5/11/05 8:37:24 PM) Temp-Path: C:\DOCUME~1\Owner\LOCALS~1\Temp\
(5/11/05 8:37:27 PM) Disinfection started
(5/11/05 8:37:27 PM) Bad-Dll(IEP): (not found)
(5/11/05 8:37:27 PM) Bad-Dll(IEP) in BHO: (not found)
(5/11/05 8:37:27 PM) UBF: 8 - UBB: 5 - UBR: 11
(5/11/05 8:37:27 PM) UBF: 8 - UBB: 5 - UBR: 11
(5/11/05 8:37:27 PM) Bad IE-pages: (none)
(5/11/05 8:37:27 PM) Stealth-String not found
(5/11/05 8:37:27 PM) Not infected->END


Please let me know what else has to be done.

Thank you kindly,


Cleaner :tazz:
  • 0

#6
g2i2r4

g2i2r4

    retired HiJack Helper

  • Retired Staff
  • 5,080 posts
Weldone :tazz:

Now please post me a fresh log using HijackThis.

EDIT:
As there has been no reply from the original poster for more than two weeks this topic is now closed.

If you are the original poster and still need assistance, please send me a PM.

Edited by g2i2r4, 31 May 2005 - 12:51 PM.

  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP